Jump to content

Malwarebytes

codec_setup.exe ~46k


2 replies to this topic

#1
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,399 posts
  • Location:Northampton, MA USA
Found by Fatdcuk , thanks . :angry:

Movie Pages :

http://newvideogalleries.com/hosted/3735/8kBWwlHi1C/


Direct downloads :

http://88.208.19.147/get/download/codec_setup.exe
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#2
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,399 posts
  • Location:Northampton, MA USA
Fallout :

C:\Program Files\*RANDOM*\*RANDOM*.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"*RANDOM*"="rundll32.exe \"C:\\Program Files\\*RANDOM*\\*RANDOM*.dll\",Init"


HJT :

O4 - HKLM\..\Run: [*RANDOM*] rundll32.exe "C:\Program Files\*RANDOM*\*RANDOM*.dll",Init


Now for the good news , the dll has a static MD5 for a period of about 24 hours at a time .

MD5 : FB0865B1E6635ED5E864EFE74FD397E0
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,399 posts
  • Location:Northampton, MA USA
Fallout :

C:\Program Files\*RANDOM*\*RANDOM*.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"*RANDOM*"="rundll32.exe \"C:\\Program Files\\*RANDOM*\\*RANDOM*.dll\",Init"


HJT :

O4 - HKLM\..\Run: [*RANDOM*] rundll32.exe "C:\Program Files\*RANDOM*\*RANDOM*.dll",Init

MD5 : 61D37AC92C195182AB5E57D9D0E5D217
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us