A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #6570  by Meriadoc
 Sat May 28, 2011 3:29 pm
Creates rootkit component in %Windir%\system32\drivers\random.sys, BHO in %Windir%\system32\random.dll.

Installs rootkit as service, registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\random, installs BHO, backdoor, changes home page from list.

VT - http://www.virustotal.com/file-scan/rep ... 1306590843

http://www.virustotal.com/file-scan/rep ... 1306593871

.sys - http://www.virustotal.com/file-scan/rep ... 1306594826

.dll - http://www.virustotal.com/file-scan/rep ... 1306595781
Attachments
pass=malware
(225.88 KiB) Downloaded 75 times