Xylitol wrote:rofl :lol:Code: Select allwhat the...0040103F |> /6A 00 /PUSH 0 ; /Style = MB_OK|MB_APPLMODAL 00401041 |. |68 9F354000 |PUSH 40359F ; |Title = "Please bitchz, I'm fabulous" 00401046 |. |68 BB354000 |PUSH 4035BB ; |Text = "I love u Xylitol" 0040104B |. |68 28FCFFFF |PUSH -3D8 ; |hOwner = FFFFFC28 00401050 |. |E8 1D000000 |CALL 00401072 ; \MessageBoxA
Looks like it encrypts files too. Not sure of the encryption method used. Probably new.
Lock screen seems very similar to Gendarmerie France.
If using FRST to get back into Windows, fixlist.txt will look something like this:
Code: Select all
HKU\thisisu\...\Run: [B49EB6EB] C:\Documents and Settings\thisisu\Application Data\Lannnnnnfn\C51A1E85B49EB6EB8528.exe [34477 2012-05-26] (The Code::Blocks Team)
HKU\thisisu\...\Policies\system: [DisableRegistryTools] 1
HKU\thisisu\...\Policies\system: [DisableRegedit] 1
HKU\thisisu\...\Policies\system: [DisableTaskMgr] 1
HKLM\...\Winlogon: [Userinit] C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\473F756CB49EB6EB3793.exe, [34477 2012-05-26] (The Code::Blocks Team)
IMEO\msconfig.exe: [Debugger] P9KDMF.EXE
IMEO\regedit.exe: [Debugger] P9KDMF.EXE
IMEO\taskmgr.exe: [Debugger] P9KDMF.EXE
2012-05-26 14:51 - 2012-05-26 14:51 - 0034477 ___AH (The Code::Blocks Team) C:\Windows\System32\473F756CB49EB6EB3793.exe
2012-05-26 14:51 - 2012-05-26 14:51 - 0000000 ____D C:\Documents and Settings\thisisu\Application Data\Lannnnnnfn
2012-05-26 14:51 - 2012-05-12 02:50 - 0481078 ____A C:\Windows\System32\winsh323
2012-05-26 14:51 - 2012-05-12 02:50 - 0481078 ____A C:\Windows\System32\winsh322
2012-05-26 14:51 - 2012-05-12 02:50 - 0481078 ____A C:\Windows\System32\winsh321
2012-05-26 14:51 - 2012-05-12 02:50 - 0481078 ____A C:\Windows\System32\winsh320
2012-05-26 14:51 - 2012-04-26 23:38 - 0481078 ____A C:\Windows\System32\winsh325
2012-05-26 14:51 - 2012-04-26 23:37 - 0481078 ____A C:\Windows\System32\winsh324