reboot:
Probably a fake defrager like hdd rescue who drop Alureon and a broken dll (for me) who is here for launch the fake defrager (assumption)
a file called InternetExplorerUpdate.exe is also dropped in %temp% and deleted after the infection.
http://www.virustotal.com/file-scan/rep ... 1299204960
https://www.virustotal.com/file-scan/re ... 1299205769
https://www.virustotal.com/file-scan/re ... 1299214973
http://www.threatexpert.com/report.aspx ... 2570d7d163
Attachments
See archive comment for password
(188.19 KiB) Downloaded 101 times
(188.19 KiB) Downloaded 101 times
See archive comment for password
(38.64 KiB) Downloaded 81 times
(38.64 KiB) Downloaded 81 times
See archive comment for password
(55.35 KiB) Downloaded 91 times
(55.35 KiB) Downloaded 91 times
Last edited by Xylitol on Fri Mar 04, 2011 5:08 am, edited 2 times in total.