Credits to : bxlcity
Released Date : 05 April 2015
Version Worm (Usb Spead -> data.exe)
Scan :
nj7d Crypyed
Filename: Crypted.exe
Type: File
Filesize: 344576 bytes
Date: 05/04/2015 - 04:45 GMT+2
MD5: 0ab34ad37d683951bf6904fb0804cad6
SHA1: 8b52dc321ba6bafa80602e4f60b82702524710d7
Status: Infected
Result: 3/35
AVG Free - OK
Avast - MSIL:GenMalicious-BKQ [Trj]
AntiVir (Avira) - TR/Dropper.MSIL.Gen
BitDefender - OK
Clam Antivirus - OK
COMODO Internet Security - OK
Dr.Web - OK
eTrust-Vet - OK
F-PROT Antivirus - OK
F-Secure Internet Security - OK
G Data - OK
IKARUS Security - OK
Kaspersky Antivirus - OK
McAfee - OK
MS Security Essentials - OK
ESET NOD32 - OK
Norman - OK
Norton Antivirus - OK
Panda Security - OK
A-Squared - OK
Quick Heal Antivirus - Malware.Generic.Dnt621115
Solo Antivirus - OK
Sophos - OK
Trend Micro Internet Security - OK
VBA32 Antivirus - OK
Zoner AntiVirus - OK
Ad-Aware - OK
BullGuard - OK
FortiClient - OK
K7 Ultimate - OK
NANO Antivirus - OK
Panda CommandLine - OK
SUPERAntiSpyware - OK
Twister Antivirus - OK
VIPRE - OK
Scan Result: http://v2.scan.majyx.net/?page=results&sid=509805
Death1.4
Filename: Crypted.exe
Type: File
Filesize: 230912 bytes
Date: 05/04/2015 - 04:49 GMT+2
MD5: ac336bf71755d178ff710f9da6d73380
SHA1: 5f4ea5ea98bcd7eb56c67f27c88e5d4824ff8a37
Status: Infected
Result: 3/35
AVG Free - OK
Avast - MSIL:GenMalicious-BKQ [Trj]
AntiVir (Avira) - TR/Dropper.MSIL.Gen
BitDefender - OK
Clam Antivirus - OK
COMODO Internet Security - OK
Dr.Web - OK
eTrust-Vet - OK
F-PROT Antivirus - OK
F-Secure Internet Security - OK
G Data - OK
IKARUS Security - OK
Kaspersky Antivirus - OK
McAfee - OK
MS Security Essentials - OK
ESET NOD32 - OK
Norman - OK
Norton Antivirus - OK
Panda Security - OK
A-Squared - OK
Quick Heal Antivirus - Malware.Generic.Dnt621115
Solo Antivirus - OK
Sophos - OK
Trend Micro Internet Security - OK
VBA32 Antivirus - OK
Zoner AntiVirus - OK
Ad-Aware - OK
BullGuard - OK
FortiClient - OK
K7 Ultimate - OK
NANO Antivirus - OK
Panda CommandLine - OK
SUPERAntiSpyware - OK
Twister Antivirus - OK
VIPRE - OK
Scan Result: http://v2.scan.majyx.net/?page=results&sid=509812
Analyse server crypted :
Defined Autostart file created: C:\autorun.inf
Defined Autostart file created: D:\autorun.inf
Defined Autostart file created: Q:\autorun.inf
Defined file type created: C:\data.exe
Defined file type created: C:\Users\-\AppData\Local\Temp\server.exe
Defined file type created: D:\data.exe
Defined file type created: E:\data.exe
Defined file type created: Q:\data.exe
Hid file from user: C:\autorun.inf
Hid file from user: C:\data.exe
Hid file from user: D:\autorun.inf
Hid file from user: D:\data.exe
Hid file from user: Q:\autorun.inf
Hid file from user: Q:\data.exe
DOWNLOAD HERE