A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #5611  by EP_X0FF
 Thu Mar 24, 2011 3:24 am
shaheen wrote:2- Can it bypass VM?
What does the following mean?
 #5639  by EP_X0FF
 Fri Mar 25, 2011 4:07 am
shaheen wrote:1- Which anti-rootkit applications can detect this currently?
All. I mean antirootkits, not BSOD-generators or students works.
shaheen wrote:I mean: Can it bypass a Windows Virtual Machine to infect the windows host OS?
No.

Before asking any questions about this or any other particular rootkit it's better read first technical details which are widely available in internet, including even this thread.
 #5647  by shaheen
 Fri Mar 25, 2011 1:42 pm
Thank, actually I was just remembering to read something about this issue but I don,t remember where exactly I read that so I aksed. So I was mistaken I think.

Thanks
 #5655  by PX5
 Fri Mar 25, 2011 11:59 pm
This one is a bit more intense, lots of thought put into self preservation and is really a classic POS to remove without the pc in front of you.

I watched a *.nls file reinstall the whole infection after I THOUGHT i had cleaned it. :roll:
 #5682  by SUPERIOR
 Sun Mar 27, 2011 9:16 pm
guys i dont know if this mentioned before or not that matters but i noticed that this rootkit trying to install this rogue "InstallAntivirus2010.exe"
  • 1
  • 4
  • 5
  • 6
  • 7
  • 8
  • 38