Message de propagation :
looooook :p
loooooooooooool
omg check this out man this is funny
you got to see this
L'infection ajoute la ligne suivante sur HijackThis :
O4 - HKLM\..\Run: [secdrive.exe] C:\WINDOWS\pchealth\helpctr\binaries\secdrive.exe
Complete scanning result of "Photo_13308.jpg-www.hotmail.com", processed in VirusTotal at 06/30/2008 14:43:15 (CET).
[ file data ]
* name..: Photo_13308.jpg-www.hotmail.com
* size..: 139522
* md5...: edd92d9e9200e7d6c0215a705e45e294
* sha1..: f2cd9ab9e6f4ceb1883c06eb8499afc0cd432f6b
* peid..: EXE Shield v0.1b - v0.3b, v0.3 -> SMoKE
[ scan result ]
AhnLab-V3 2008.6.27.1/20080630 found nothing
AntiVir 7.8.0.59/20080630 found [Worm/SdBot.139522]
Authentium 5.1.0.4/20080629 found nothing
Avast 4.8.1195.0/20080628 found [Win32:IRCBot-AND]
AVG 7.5.0.516/20080630 found nothing
BitDefender 7.2/20080630 found nothing
CAT-QuickHeal 9.50/20080628 found nothing
ClamAV 0.93.1/20080630 found nothing
DrWeb 4.44.0.09170/20080630 found nothing
eSafe 7.0.17.0/20080629 found [Suspicious File]
eTrust-Vet 31.6.5914/20080630 found nothing
Ewido 4.0/20080627 found nothing
F-Prot 4.4.4.56/20080629 found nothing
F-Secure 7.60.13501.0/20080626 found nothing
Fortinet 3.14.0.0/20080630 found nothing
GData 2.0.7306.1023/20080630 found [Backdoor.Win32.SdBot.esy]
Ikarus T3.1.1.26.0/20080630 found [Virus.Win32.IRCBot.AND]
Kaspersky 7.0.0.125/20080630 found [Backdoor.Win32.SdBot.esy]
McAfee 5327/20080627 found nothing
Microsoft 1.3704/20080630 found [Worm:Win32/Neeris.O]
NOD32v2 3226/20080630 found [IRC/SdBot]
Norman 5.80.02/20080627 found nothing
Panda 9.0.0.4/20080629 found nothing
Prevx1 V2/20080630 found nothing
Rising 20.51.02.00/20080630 found nothing
Sophos 4.30.0/20080630 found [Mal/Packer]
Sunbelt 3.0.1176.1/20080626 found nothing
Symantec 10/20080630 found [W32.Spybot.Worm]
TheHacker 6.2.96.364/20080628 found nothing
TrendMicro 8.700.0.1004/20080630 found nothing
VBA32 3.12.6.8/20080630 found [Backdoor.Win32.SdBot.esy]
VirusBuster 4.5.11.0/20080630 found nothing
Webwasher-Gateway 6.6.2/20080630 found [Worm.SdBot.139522]
[ notes ]
packers (Avast): RLPack