EP_X0FF wrote:DragonMaster Jay wrote:Looks like Sirefef is opening files from a device driver...Current version has no devices drivers.
then writing MD5 strings in C...what gives? Changing device driver code?No it don't. This is Universally Unique Identifier (UUID) generation for Sirefef folder name. It calcs MD5 for system volume creation time value and converts it in UUID format. It is obvious from code posted above.
how many time is required for full sirefef dropper+payload reconstruction? theoretically?