A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12765  by thisisu
 Tue Apr 17, 2012 5:15 pm
Windows Safety Manager
FakeVimes - MD5: 45a8a976e37f3035c9fc7d029faff405
https://www.virustotal.com/file/9f3214a ... /analysis/

Kind of interesting to me (and perhaps to you) that these last 2 FakeVimes infections only provide the Protector-????.exe. It used to be a seperate installer (around 2.03MB) that would extract the Protector-????.exe to %appdata%. However, some of the "installers" did not function correctly even on live machines so I think they just decided to use the direct .exe - no "installer" file. :)
Attachments
pass: infected
(1.78 MiB) Downloaded 51 times
  • 1
  • 12
  • 13
  • 14
  • 15
  • 16
  • 46