Hi All,
Fake AV Advanced PC Shield 2012 With necurs rootkit.This rootkit declares it's driver of "BOOT BUS EXTENDER" driver group which has precedence over antivirus fsfilter driver group. Necurs's driver installation style reminds me of famous Bubnix rootkit.
This time i dont have web link. :cry:
6f4c.exe
File size - 292 KB
VT link -
http://www.virustotal.com/file-scan/rep ... 1317313161
MD5 : 09e2a15e9ed0a3e165d9ead2faa61d8a
SHA1 : 3210d561767f03934bbd51d92de1b361859ddfeb
SHA256: 64d31dd3816763464d5ad5b73c7084741acce53fab89ed4dcdc40b9bb84d7081
ssdeep: 6144:eFG2DDfc/vtDqH/uL2/ytzSwF18VoiNsGwes:yHOtefuL2szDypG1e
147.sys
File Size - 35 KB.
VT link -
http://www.virustotal.com/file-scan/rep ... 1317306213
MD5 : ec44ddcec6418a6bcd83b02ae38f1b09
SHA1 : 051e02c4fb169e2a6dd529ade0d44dc4d0857f5e
SHA256: cc6d4a41c78d21c492ed8bacbb08a2db9f8881ca212c13e03dc6bbea006e93d1
ssdeep: 384:ceKpRkFXO3adQ8wqRJ7R6HdZsEtXvybFs0dnfmSpt/WVSD5cjU2vmZNO5DqiXVWv:cVszpAdpXvOBVfmMrATbpNXEb//4qbB
Advanced PC Shield 2012-1.jpg (106.48 KiB) Viewed 2403 times
Advanced PC Shield 2012-2.jpg (125.3 KiB) Viewed 2403 times
Regards,
rough_spear. ;)