blabberer
January 21st, 2008, 12:48
attached here with is a malware that kills cmd.exe probably sets hklm\\...\\..\policies (disabling regedit , taskmgr disabling folder options and shit the usual crap tricks possibly spawns NEW FOLDER.exe multiple times
and sets up a reg key as yahoo messenger in various places for autoruns)
scvhost.exe c:\windows\scvhost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
it seems to be an autoit v3 executable
password is malware
it is a rar archieve renamed as zip
for anyone wishing to retrieve the autoit script
and sets up a reg key as yahoo messenger in various places for autoruns)
scvhost.exe c:\windows\scvhost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
it seems to be an autoit v3 executable
password is malware
it is a rar archieve renamed as zip
for anyone wishing to retrieve the autoit script
