This sample crashes rKu when you do a code hook scan. I call it GBOT because of the internal PDB paths of the 3 dropped files, some AV's label it as a FakeAV.
http://i56.tinypic.com/9jhd3t.png
http://i56.tinypic.com/9jhd3t.png
Attachments
Password: infected
(93.64 KiB) Downloaded 55 times
(93.64 KiB) Downloaded 55 times