Posted 18 November 2007 - 08:51 AM
Fallout :
C:\Program Files\*RANDOM*\*RANDOM*.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"*RANDOM*"="rundll32.exe \"C:\\Program Files\\*RANDOM*\\*RANDOM*.dll\",Init"
HJT :
O4 - HKLM\..\Run: [*RANDOM*] rundll32.exe "C:\Program Files\*RANDOM*\*RANDOM*.dll",Init
Now for the good news , the dll has a static MD5 for a period of about 24 hours at a time .
MD5 : FB0865B1E6635ED5E864EFE74FD397E0
Bruce Harrison
Vice President of Research
Follow us:
Twitter, Become a fan:
Facebook