reboot:
Probably a fake defrager like hdd rescue who drop Alureon and a broken dll (for me) who is here for launch the fake defrager (assumption)
a file called InternetExplorerUpdate.exe is also dropped in %temp% and deleted after the infection.
http://www.virustotal.com/file-scan/rep ... 1299204960
https://www.virustotal.com/file-scan/re ... 1299205769
https://www.virustotal.com/file-scan/re ... 1299214973
http://www.threatexpert.com/report.aspx ... 2570d7d163
Attachments
See archive comment for password
(188.19 KiB) Downloaded 100 times
(188.19 KiB) Downloaded 100 times
See archive comment for password
(38.64 KiB) Downloaded 80 times
(38.64 KiB) Downloaded 80 times
See archive comment for password
(55.35 KiB) Downloaded 90 times
(55.35 KiB) Downloaded 90 times
Last edited by Xylitol on Fri Mar 04, 2011 5:08 am, edited 2 times in total.