by Naathim
Fri Aug 29, 2014 12:13 pm
Topic: Win32/Poweliks
Re: Win32/Poweliks

Hello. Looks like there is some nev variant of Poweliks, which infects another CLSID (or maybe it's just the XP speciality), which I'm fighting here: Aside of forged run subkey, there is another one: [HKLM\Software\Classes\...