A forum for reverse engineering, OS internals and malware analysis 

Discussion on reverse-engineering and debugging.
 #17434  by RoxinAz
 Sat Dec 29, 2012 7:58 am
I worked with 2 samples of W32/Crisis , but both of them needs BHDV.SYS (driver file) to work with. I couldn't found a place in W32/Crisis that belongs to dropping BHDV.sys...
Is this file dropped from JAR files which i didn't have it? Or W32/Crisis dropped it by itself?

If any1 know about it plz help me , Maybe I should see more samples in W32 ... then I want more samples ...