 #570  by STRELiTZIA
 Wed Apr 07, 2010 7:55 am
Old PE infector drops rootkit...
See attachement:
WinRAR Archives password: malware
1- Virus.Win32.Alman.b_Dropper.rar contains :-->> Protected.
- Infected file.
- Original file.
- Disinfected file.

2- linkinfo.dll_Alias_Virus.Win32.Agent.bu.rar -->> Protected.
3- IsDrv122.sys_Alias_Virus.Win32.Alman.b.rar -->> Protected.
4- linkinfo.dll_Listing.txt
5- linkinfo.dll_strings.txt
6- Report.txt
7- IsDrv122_IDA_Data-base-file.idb -->> Ida database file.

http://www.virustotal.com/fr/analisis/8 ... 1270626442

http://www.virustotal.com/fr/analisis/d ... 1270626586

http://www.virustotal.com/fr/analisis/9 ... 1270626598
 #572  by EP_X0FF
 Wed Apr 07, 2010 9:22 am

I don't remember if it is the same Alman I have analyzed in 2008, but it had on board specific code against Rootkit Unhooker v1.x/2.x (hardcoded RkU driver signature).



Yep, the same ;)
