xors wrote:Found from a dropperYou're right, sort of Andromeda, http://vms.drweb.com/virus/?_is=1&i=7974964&lng=en Maybe it's Chtonic (Andromeda clone) new variant.
I think that it is Andromeda. Can anyone confirm ?
r u n a s c m d . e x e / c % s % l uPlease next time use password for archives. Posts moved.
Test - OK /test yahoo.com google.com bing.com update.microsoft.com microsoft.com 80 C o n t e n t - T y p e : a p p l i c a t i o n / o c t e t - s t r e a m
C o n n e c t i o n : c l o s e P O S T C o n n e c t i o n : c l o s e K B % 0 8 l u . e x e % T E M P % \ % T M P % \ {"id":%lu,"tid":%lu,"err":%lu,"w32":%lu} \ s y s t e m 3 2 \ m s i e x e c . e x e \ S y s W O W 6 4 \ m s i e x e c . e x e M o z i l l a / 4 . 0 ntdll.dll @ Ђ @ As o f t w a r e \ m i c r o s o f t \ w i n d o w s \ c u r r e n t v e r s i o n \ p o l i c i e s \ s y s t e m E n a b l e L U A s o f t w a r e \ m i c r o s o f t \ w i n d o w s \ c u r r e n t v e r s i o n \ R u n s o f t w a r e \ m i c r o s o f t \ w i n d o w s n t \ c u r r e n t v e r s i o n \ W i n d o w s s o f t w a r e \ m i c r o s o f t \ w i n d o w s \ c u r r e n t v e r s i o n \ P o l i c i e s \ E x p l o r e r \ R u n U S E R P R O F I L E A P P D A T A A L L U S E R S P R O F I L E L o a d D:(A;;KA;;;WD) D:(A;;KRWD;;;WD) : Z o n e . I d e n t i f i e r m s % s . e x e \ % l u H i d d e n s o f t w a r e \ m i c r o s o f t \ w i n d o w s \ c u r r e n t v e r s i o n \ e x p l o r e r \ a d v a n c e d S h o w S u p e r H i d d e n pool.ntp.org africa.pool.ntp.org oceania.pool.ntp.org asia.pool.ntp.org south-america.pool.ntp.org north-america.pool.ntp.org europe.pool.ntp.org 123 aReport aUpdate DllRegisterServer aStart \ c d o % l u . d l l T E M P T M P \ s y s t e m 3 2 \ c d o s y s . d l l \ S y s W O W 6 4 \ c d o s y s . d l l c d o % l u . d l l : % l u NtMapViewOfSection cdosys.dll software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe Debugger WinDefend MpsSvc SharedAccess wuauserv wscsvc H i d e S C A H e a l t h T a s k b a r N o N o t i f i c a t i o n s o f t w a r e \ m i c r o s o f t \ w i n d o w s \ c u r r e n t v e r s i o n \ p o l i c i e s \ E x p l o r e r s o f t w a r e \ p o l i c i e s i s _ n o t _ v m 1 2 7 . 0 . 0 . 1 GetAddrInfoW ws2_32.dll
Ring0 - the source of inspiration