Message de propagation :
Creo que esto son sus fotos del! hxxp://gallery.host.sk/gallery.php?=
L'infection ajoute la ligne suivante sur HijackThis :
O4 - HKLM\..\Run: [Windows UDP Control Center] auth.exe
Creo que esto son sus fotos del! hxxp://gallery.host.sk/gallery.php?=
O4 - HKLM\..\Run: [Windows UDP Control Center] auth.exe
VirSCAN.org Scanned Report :
Scanned time : 2008/08/17 21:59:54 (CEST)
Scanner results: 25% Scanner(9/36) found malware!
File Name : gallery.php
File Size : 374868 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 294d62b62e3002ed298aea6858535811
SHA1 : 8ed7642ee4cc6930a0ca5bed696db350fe7eb216
Online report : http://virscan.org/report/aedec626791a0 ... 0c4f3.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 3.5.0.22 2008.08.17 2008-08-17 4.27 -
AhnLab V3 2008.08.15.00 2008.08.15 2008-08-15 1.52 -
AntiVir 7.8.1.19 7.0.6.24 2008-08-16 2.19 TR/Crypt.CFI.Gen
Arcavir 1.0.5 200808171633 2008-08-17 1.41 -
AVAST! 3.0.1 080817-0 2008-08-17 0.02 Win32:Trojan-gen {Other}
AVG 7.5.51.442 270.6.4/1617 2008-08-17 1.55 SHeur.CCZK
BitDefender 7.60825.1556497 7.20559 2008-08-18 3.14 Trojan.Crypt.ED
CA (VET) 9.0.0.143 31.6.6035 2008-08-15 9.06 -
ClamAV 0.93.3 8051 2008-08-16 0.23 -
Comodo 2.11 2.0.0.619 2008-08-17 2.40 -
CP Secure 1.1.0.715 2008.08.18 2008-08-18 6.26 -
Dr.Web 4.44.0.9170 2008.08.17 2008-08-17 3.28 -
ewido 4.0.0.2 2008.08.17 2008-08-17 5.61 -
F-Prot 4.4.4.56 20080817 2008-08-17 1.05 W32/DelfInject.A.gen!Eldorado (generic, not disinfectable)
F-Secure 5.51.6100 2008.08.17.01 2008-08-17 0.33 -
Fortinet 2.81-3.11 9.436 2008-08-18 1.94 -
ViRobot 20080816 2008.08.16 2008-08-16 0.69 -
Ikarus T3.1.01.34 2008.08.17.71292 2008-08-17 3.43 BehavesLike.Win32.SMTP-Mailer
JiangMin 11.0.706 2008.08.17 2008-08-17 2.27 -
Kaspersky 5.5.10 2008.08.17 2008-08-17 0.25 -
KingSoft 2008.1.14.15 2008.8.17.15 2008-08-17 0.66 -
McAfee 5.2.00 5362 2008-08-15 3.79 -
Microsoft 1.3807 2008.08.17 2008-08-17 6.96 VirTool:Win32/DelfInject.gen!X
mks_vir 2.01 2008.08.17 2008-08-17 2.77 -
Norman 5.93.01 5.93.00 2008-08-15 4.95 -
Panda 9.05.01 2008.08.17 2008-08-17 5.55 -
Trend Micro 8.700-1004 5.482.22 2008-08-17 0.08 -
Quick Heal 9.50 2008.08.16 2008-08-16 2.77 -
Rising 20.0 20.57.62.00 2008-08-17 0.97 -
Sophos 2.77.0 4.32 2008-08-18 2.04 -
Sunbelt 3.1.1546.1 2193 2008-08-14 0.73 -
Symantec 1.3.0.24 20080817.003 2008-08-17 0.16 -
nProtect 2008-08-14.01 1801264 2008-08-14 12.36 Trojan.Crypt.ED
The Hacker 6.2.96 v00396 2008-08-11 0.53 -
VBA32 3.12.8.3 20080816.1123 2008-08-16 1.33 Trojan.Win32.Buzus.qzn
VirusBuster 4.5.11.10 10.84.3/598170 2008-08-17 1.53 -
Complete scanning result of "gallery.php", processed in VirusTotal at 08/18/2008 13:51:56 (CET).
[ file data ]
* name..: gallery.php
* size..: 374868
* md5...: 294d62b62e3002ed298aea6858535811
* sha1..: 8ed7642ee4cc6930a0ca5bed696db350fe7eb216
* peid..: -
[ scan result ]
AhnLab-V3 2008.8.15.0/20080818 found nothing
AntiVir 7.8.1.19/20080818 found [TR/Crypt.CFI.Gen]
Authentium 5.1.0.4/20080818 found nothing
Avast 4.8.1195.0/20080817 found [Win32:Trojan-gen {Other}]
AVG 8.0.0.161/20080818 found [SHeur.CCZK]
BitDefender 7.2/20080818 found [Trojan.Crypt.ED]
CAT-QuickHeal 9.50/20080816 found nothing
ClamAV 0.93.1/20080818 found nothing
DrWeb 4.44.0.09170/20080818 found nothing
eSafe 7.0.17.0/20080817 found [Suspicious File]
eTrust-Vet 31.6.6035/20080815 found nothing
Ewido 4.0/20080818 found nothing
F-Prot 4.4.4.56/20080818 found [W32/DelfInject.A.gen!Eldorado]
Fortinet 3.14.0.0/20080818 found [PossibleThreat]
GData 2.0.7306.1023/20080818 found [Trojan.Win32.Buzus.rux]
Ikarus T3.1.1.34.0/20080818 found [BehavesLike.Win32.SMTP-Mailer]
K7AntiVirus 7.10.417/20080818 found nothing
Kaspersky 7.0.0.125/20080818 found [Trojan.Win32.Buzus.rux]
McAfee 5362/20080815 found nothing
Microsoft 1.3807/20080818 found [VirTool:Win32/DelfInject.gen!X]
NOD32v2 3364/20080818 found nothing
Norman 5.80.02/20080815 found nothing
Panda 9.0.0.4/20080817 found nothing
PCTools 4.4.2.0/20080817 found nothing
Rising 20.58.02.00/20080818 found nothing
Sophos 4.32.0/20080818 found nothing
Sunbelt 3.1.1546.1/20080815 found nothing
Symantec 10/20080818 found nothing
TheHacker 6.3.0.5.053/20080818 found nothing
TrendMicro 8.700.0.1004/20080818 found nothing
VBA32 3.12.8.3/20080818 found [Trojan.Win32.Buzus.qzn]
ViRobot 2008.8.18.1339/20080818 found [Spyware.Buzus.374868]
VirusBuster 4.5.11.0/20080818 found nothing
Webwasher-Gateway 6.6.2/20080818 found [Trojan.Crypt.CFI.Gen]