17 Jun 2011
Windows 7 Home Premium x64 SP1
Interesting Snowflake Worm:Win32/SnowFlake.A
There's a WinRAR file floating around in the Internet named "2012桌面雪花.rar"* (SHA1: 889cf7076d4c08637e8aeedf7a90dc4a3808f991), which can be downloaded or may be sent out as an attachment in an email message, that contains a program that claims to display beautiful snowflakes on your desktop. If you run the executable contained in the archive (file name "桌面雪花.exe" - SHA1: 7255f61cada0815bc0fa2fb12f5b3c89db7e786d), it does what it claims.
It is beautiful, right?
But wait, non-beautiful things are happening behind the scenes. As you can guess, it is malicious, and so it is interesting to me.
|My System Specs || |