Hi freyr,
I have some files such as spr.dll and lnk.dat but not sock.dll from TDL4
cfg.ini
Code: Select all[main]
version=0.03
aid=68
sid=1
builddate=351
installdate=5.7.2011 18:25:59
rnd=1993962763
knt=1310143600
[inject]
*=cmd.dll
* (x64)=cmd64.dll
svchost.exe=spr.dll
[cmd]
srv=https://i0m71gmak01.com/;https://0imh17agcla.com/;https://jna0-0akq8x.com/
wsrv=http://u-a-d-1come.com/;http://z0a-adotcom.com/;http://61zra71kf-a.com/
psrv=http://amazeyapcell.com/;http://8hqka--acom.com/
version=0.1763
bsh=aa7af9760337d794b85c357ca354aa8be42dbd51
delay=3600
spr.dll
MD5 : 02be880e5f7d7dd01531f6cae8112e01
SHA1 : 1a0b55c194cf34772a3846a1b5274fd84629b9f8
SHA256: cb151f40b776fe85761fa6bdcbb509c2f6e557a6c46bb6c2a128bf74c55f856b
virustotal:
http://www.virustotal.com/file-scan/rep ... 1310656130
freyr wrote:Hi, can anyone share socks.dll, r.dll, kad.dll from TDL4?
file name - TDL4.7z
Password - malware
Regards,
rough_spear