2012/08/12

[4481] Trojan WinLock


MD5: 2EB70294D9A0E8BC6946995786D12423 
                        SHA1:eae66e04635b010376cabf0ea85e566205d07c5d


 Values Created :
CU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GlobalUserOffline
LM\Software\Microsoft\Windows\CurrentVersion\Run\SMBHelper"C:\Documents and Settings\User\Local Settings
\Application Data\Microsoft\Windows\4481\SMBHelper.exe"

Directories Created :
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\VSComponents
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\4481  

Files Created :
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\4481\e4a341e1
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\4481\SMBHelper.exe 

DOWNLOAD SAMPLE:
Password: malwaresniper
 Members www.malware-sniper.blogspot.com no responsibility for any damage caused by malware. It is used at your own risk!

No comments:

Post a Comment