Posted May 16, 200817 yr Trojan-Downloader.Win32.Small or Win32/PolyCrypt AnalysisPolyCrypt is spreaded through infected Websites by using Exploits or every other form of abusive Download mechanism. PolyCrypt is weakly Packer Protected, so with VMUnpack we can suddenly obtain the full working unpacked copy.Trojan_DownloaderWin32Small.pdfTed.
May 24, 200817 yr That's all? It ends right before the analysis of msstub.dll...isn't there a second paper? Thanks.
May 24, 200817 yr That's all? It ends right before the analysis of msstub.dll...isn't there a second paper?Uhm seems that the paper has lost a part of the original paper, the entire paper is here http://evilcodecave.wordpress.com/2008/05/...rypt-reversing/Regards,Evilcry Edited May 24, 200817 yr by evilcry
Create an account or sign in to comment