Buckrogers wrote:Initially I thought it was the dropper, but apparently this dir is created and deleted on every boot.It is hidden by NtQueryDirectoryFile hook in Explorer.
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
Buckrogers wrote:Initially I thought it was the dropper, but apparently this dir is created and deleted on every boot.It is hidden by NtQueryDirectoryFile hook in Explorer.
gritland wrote:http://www.virustotal.com/file-scan/rep ... 1312635892Equal to this, multipacked recrypt.
gritland wrote:http://www.virustotal.com/file-scan/report.html?id=c37427fb19d01c8b3eb657cd7e322c272772506545f87733ea0230cb9c67d292-1312720402Equal to this and this.
hxxp://www.solodiyi.com/main/gate.php;100
hxxp://www.verdumnn.com/main/gate.php;100
hxxp://www.aaggrreesssor.com/main/gate.php;100
hxxp://www.trressuryy.com/main/gate.php;100
hxxp://banistabank.ru/ko.php;300Plugins: customconnector, ccgrabber.
hxxp://eewtoopqq.ru/www5.php;300
gritland wrote:http://www.virustotal.com/file-scan/rep ... 1313272926The same as http://www.kernelmode.info/forum/viewto ... 6382#p6382, re-crypt with new servers list.