Trojan Microjoin peut charger ce rogue aussi.
Download initial :
Code : Tout sélectionner
1258396648.587 2013 192.168.1.63 TCP_MISS/200 1407767 GET http://xrenutap.com//getexe.php?spl=mdac - DIRECT/217.23.12.147 application/octet-stream
Exemple de détection :
File load_22_.exe received on 2009.11.16 16:26:27 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 15/41 (36.59%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.11.16 Packed.Win32.Krap!IK
AhnLab-V3 5.0.0.2 2009.11.16 -
AntiVir 7.9.1.65 2009.11.16 TR/Agent.AH.521
Antiy-AVL 2.0.3.7 2009.11.16 Packed/Win32.Krap
Authentium 5.2.0.5 2009.11.16 -
Avast 4.8.1351.0 2009.11.16 -
AVG 8.5.0.425 2009.11.16 SHeur2.BRYO
BitDefender 7.2 2009.11.16 -
CAT-QuickHeal 10.00 2009.11.16 -
ClamAV 0.94.1 2009.11.16 -
Comodo 2957 2009.11.15 -
DrWeb 5.0.0.12182 2009.11.16 Trojan.Packed.683
eSafe 7.0.17.0 2009.11.16 -
eTrust-Vet 35.1.7122 2009.11.16 -
F-Prot 4.5.1.85 2009.11.16 -
F-Secure 9.0.15370.0 2009.11.11 Suspicious:W32/Malware!Gemini
Fortinet 3.120.0.0 2009.11.16 -
GData 19 2009.11.16 -
Ikarus T3.1.1.74.0 2009.11.16 Packed.Win32.Krap
Jiangmin 11.0.800 2009.11.16 -
K7AntiVirus 7.10.897 2009.11.16 -
Kaspersky 7.0.0.125 2009.11.16 Packed.Win32.Krap.ah
McAfee 5803 2009.11.15 -
McAfee+Artemis 5803 2009.11.15 Artemis!DB2C11916287
McAfee-GW-Edition 6.8.5 2009.11.16 Trojan.Agent.AH.521
Microsoft 1.5202 2009.11.16 VirTool:Win32/Obfuscator.HG
NOD32 4612 2009.11.16 a variant of Win32/Kryptik.BCR
Norman 6.03.02 2009.11.16 -
nProtect 2009.1.8.0 2009.11.16 -
Panda 10.0.2.2 2009.11.15 Suspicious file
PCTools 7.0.3.5 2009.11.16 -
Prevx 3.0 2009.11.16 Medium Risk Malware
Rising 22.22.00.08 2009.11.16 -
Sophos 4.47.0 2009.11.16 Sus/EncPk-LT
Sunbelt 3.2.1858.2 2009.11.12 -
Symantec 1.4.4.12 2009.11.16 -
TheHacker 6.5.0.2.071 2009.11.16 -
TrendMicro 9.0.0.1003 2009.11.16 -
VBA32 3.12.10.11 2009.11.15 -
ViRobot 2009.11.16.2039 2009.11.16 -
VirusBuster 4.6.5.0 2009.11.16 -
Additional information
File size: 1407488 bytes
MD5...: db2c11916287bd58a5b688ebec897d9d
SHA1..: 11e582329a5bbc2f9a17881c45e133ad25725442
puis vas chercher le pack au complet :
Code : Tout sélectionner
1258396905.438 1836 192.168.1.26 TCP_MISS/200 1490735 GET http://plugininput.com/123.exe - DIRECT/217.23.12.147 application/octet-stream
1258396941.491 550 192.168.1.63 TCP_MISS/200 23368 GET http://downloadavr9.com/dfghfghgfj.dll - DIRECT/91.207.116.55 application/x-msdownload
1258396945.637 1668 192.168.1.63 TCP_MISS/200 795683 GET http://downloadavr9.com/cgi-bin/download.pl?code=0000093 - DIRECT/91.207.116.55 application/octet-stream
1258396949.311 623 192.168.1.90 TCP_MISS/200 105213 GET http://testavrdown.com/cgi-bin/get.pl?l= - DIRECT/91.207.116.55 application/octet-stream
1258396949.789 916 192.168.1.63 TCP_MISS/200 105213 GET http://testavrdown.com/cgi-bin/get.pl?l= - DIRECT/91.207.116.55 application/octet-stream
123.exe est le pack Trojan.MicroJoin ~1,3 MO
Le reste sont les fichiers relatives au rogue Advanced Virus Remover

de détection :
File 123.exe received on 2009.11.16 16:31:16 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 14/41 (34.15%)
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.11.16 Packed.Win32.Krap!IK
AhnLab-V3 5.0.0.2 2009.11.16 -
AntiVir 7.9.1.65 2009.11.16 TR/Agent.AH.532
Antiy-AVL 2.0.3.7 2009.11.16 Packed/Win32.Krap
Authentium 5.2.0.5 2009.11.16 -
Avast 4.8.1351.0 2009.11.16 -
AVG 8.5.0.425 2009.11.16 -
BitDefender 7.2 2009.11.16 Trojan.Generic.2676560
CAT-QuickHeal 10.00 2009.11.16 -
ClamAV 0.94.1 2009.11.16 -
Comodo 2957 2009.11.15 -
DrWeb 5.0.0.12182 2009.11.16 Trojan.Packed.683
eSafe 7.0.17.0 2009.11.16 -
eTrust-Vet 35.1.7122 2009.11.16 -
F-Prot 4.5.1.85 2009.11.16 -
F-Secure 9.0.15370.0 2009.11.11 -
Fortinet 3.120.0.0 2009.11.16 -
GData 19 2009.11.16 Trojan.Generic.2676560
Ikarus T3.1.1.74.0 2009.11.16 Packed.Win32.Krap
Jiangmin 11.0.800 2009.11.16 -
K7AntiVirus 7.10.897 2009.11.16 -
Kaspersky 7.0.0.125 2009.11.16 Packed.Win32.Krap.ah
McAfee 5803 2009.11.15 -
McAfee+Artemis 5803 2009.11.15 Artemis!806A07CB0974
McAfee-GW-Edition 6.8.5 2009.11.16 Trojan.Agent.AH.532
Microsoft 1.5202 2009.11.16 VirTool:Win32/Obfuscator.HG
NOD32 4612 2009.11.16 a variant of Win32/Kryptik.BCR
Norman 6.03.02 2009.11.16 -
nProtect 2009.1.8.0 2009.11.16 -
Panda 10.0.2.2 2009.11.15 Suspicious file
PCTools 7.0.3.5 2009.11.16 -
Prevx 3.0 2009.11.16 -
Rising 22.22.00.08 2009.11.16 -
Sophos 4.47.0 2009.11.16 Sus/EncPk-LT
Sunbelt 3.2.1858.2 2009.11.12 -
Symantec 1.4.4.12 2009.11.16 -
TheHacker 6.5.0.2.071 2009.11.16 -
TrendMicro 9.0.0.1003 2009.11.16 -
VBA32 3.12.10.11 2009.11.15 -
ViRobot 2009.11.16.2039 2009.11.16 -
VirusBuster 4.6.5.0 2009.11.16 -
Additional information
File size: 1490432 bytes
MD5...: 806a07cb0974415836939ec845f162df
SHA1..: 617fdcfeb5b535080ce50ed23d8e862bb27d7b55
Lignes
HiJackThis ajoutées par l'infection :
O4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass.exe
O4 - HKLM\..\Run: [netc] C:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [odby] C:\WINDOWS\odb.exe
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
O4 - HKLM\..\Run: [servicelayer] C:\WINDOWS\servicelayer.exe
O4 - HKLM\..\Run: [wdmon] C:\WINDOWS\wdmon.exe
O4 - HKLM\..\Run: [netw] C:\WINDOWS\svw.exe
O4 - HKLM\..\Run: [netx] C:\WINDOWS\svx.exe
Pour rappel, Trojan.MicroJoin est
du type Trojan.Clicker (voir aussi :
http://forum.malekal.com/antivirus-2009 ... ml#p114918 )
Le malware surf, de manière intensives, sur des sites en fond pour augmenter le ranking etc... ces sites sont souvent très peu catholiques, exemples :
