Trojan/PWS - Infostealer
Initial reporting credited to @diocyde - IOC should detect resident files & fully infected boxes.
Keith Gilbert
2011-12-22T23:54:36
Trojan
http://md5.virscan.org/92410cc3a4f6e623478a4711fe3fcb7a
http://jsunpack.jeek.org/dec/go?report=0570e7ae0c3616bf52fcae74868c7f1fcf5202c7
92410cc3a4f6e623478a4711fe3fcb7a
ATxBtCuy.exe
Temp\HIMYM.dll
7A607567F727D56F76C45E11790202A9
CURRENTVERSION\Run
Disker
rundll32.exe
HIMYM.DLL