Go Back   Technibble Forums > Technical Discussions > Security, Viruses and Trojans

  Technibble Sponsor

Reply
 
Thread Tools Display Modes
  #11  
Old 07-01-2012, 11:23 AM
ComputerRepairTech's Avatar
ComputerRepairTech ComputerRepairTech is offline
 
Join Date: Oct 2010
Location: Columbia, SC
Posts: 1,149
ComputerRepairTech will become famous soon enough
Default

Quote:
Originally Posted by ZPR View Post
Edit: I found it, it was hiding under Classes\U29G08004 with the name of AD0, N0AD0, U29G08004 searching for 4D,5A and there it was. I guess I now know how it became infected. But I still wonder how you would even execute it.

Edit 2: Part of it is gone, going to do some more searching to find out where the other part is.

Edit 3: After exporting the software hive into a new hive the exe header wasn't found. I will do a few more checks but that seamed to work. Thanks for the Guidance Foolish Tech, if I didn't do the mass registry export I could still be looking for it right now.
Probably uses a loader of some sort...probably some where in the AV history. It kind of looks like Virut but when I google the parts you put I come up with Bamital or Zapchast
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:46 AM.


Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Technibble.com is based out of MELBOURNE, AUSTRALIA.