A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #13780  by DocR3d
 Wed Jun 06, 2012 8:25 pm
Hey guys,

I'm looking for a sample of what I believe is a new variant to a Fake AV that in the past had nuked the BFE / BFF registry keys, although this one nukes those and more.

I think this Virus Total report might be the same one with hashes for the infection.
A) I think the name of the program, which resides in appdata\local was named 'srlithw'
B) Link to VirusTotal: https://www.virustotal.com/file/8711146 ... /analysis/

The infection I am looking for is killing all / most of these services:
Code: Select all
[u]Entire Services Entry Missing/Deleted[/u]
AppInfo
BFE
FontCache
IpHlpSvc
MpsSvc
Netman
Netprofm
nsi
PlugPlay
PNRPsvc
QWAVE
Seclogon
Sens
SessionEnv
SharedAccess (Potentially Vista Only)
SLUINotify (Vista Only)
SysMain
UPNPhost
wcncsvc
wcsPlugInService
Windefend
WinHttpAutoProxySvc
WscSvc
wuauserv
WwanSvc

[u]Just ServiceDll Entry Missing/Deleted[/u]
WebClient
RasMan
SensrSvc
WPDBusEnum
Thanks!
 #13781  by Xylitol
 Wed Jun 06, 2012 9:02 pm
DocR3d wrote:Hey guys,

I'm looking for a sample of what I believe is a new variant to a Fake AV that in the past had nuked the BFE / BFF registry keys, although this one nukes those and more.

I think this Virus Total report might be the same one with hashes for the infection.
A) I think the name of the program, which resides in appdata\local was named 'srlithw'
B) Link to VirusTotal: https://www.virustotal.com/file/8711146 ... /analysis/

The infection I am looking for is killing all / most of these services:
Code: Select all
[u]Entire Services Entry Missing/Deleted[/u]
AppInfo
BFE
FontCache
IpHlpSvc
MpsSvc
Netman
Netprofm
nsi
PlugPlay
PNRPsvc
QWAVE
Seclogon
Sens
SessionEnv
SharedAccess (Potentially Vista Only)
SLUINotify (Vista Only)
SysMain
UPNPhost
wcncsvc
wcsPlugInService
Windefend
WinHttpAutoProxySvc
WscSvc
wuauserv
WwanSvc

[u]Just ServiceDll Entry Missing/Deleted[/u]
WebClient
RasMan
SensrSvc
WPDBusEnum
Thanks!
same hash of vt in attach
Attachments