A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #14518  by EP_X0FF
 Sun Jul 08, 2012 3:29 pm
markusg wrote:from infected pc
This is Ramnit bundled with SdtRestore driver.
c:\project\demetra\loader~1\drivers\ssdt\driver~1\objfre_win7_x86\i386\SdtRestore.pdb
Attached decrypted dropper. Posts moved.
Attachments
pass: malware
(64.49 KiB) Downloaded 97 times
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10