The virus on VT:
https://www.virustotal.com/en/file/8f35 ... 432362743/
The virus inject many process like it:
but I cann't found how it autostart.
When OS restarted, it start itself via explorer.exe, but I do not know how it auto started.
log:
2015/05/23 15:54:55 c:\windows\explorer.exe Create new process c:\users\test\appdata\roaming\mozilla\firefox\profiles\4ude5xz7.default\storage\permanent\xulstore.exe Cmd line: "C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\4ude5xz7.default\storage\permanent\xulstore.exe"
https://www.virustotal.com/en/file/8f35 ... 432362743/
The virus inject many process like it:
but I cann't found how it autostart.
When OS restarted, it start itself via explorer.exe, but I do not know how it auto started.
log:
2015/05/23 15:54:55 c:\windows\explorer.exe Create new process c:\users\test\appdata\roaming\mozilla\firefox\profiles\4ude5xz7.default\storage\permanent\xulstore.exe Cmd line: "C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\4ude5xz7.default\storage\permanent\xulstore.exe"
Attachments
pass: infected
(121.35 KiB) Downloaded 124 times
(121.35 KiB) Downloaded 124 times