Détection win32:Lager-Q TR/Proxy.Lager.AQ.1
Les fichiers utilisés par le malware sont :
C:\Windows\system32\taskdir.exe et C:\Windows\system32\taskdir.dll
ainsi que C:\Windows\zlbw.dll
Exemple de log avec
HijackThis
:
O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no
file)
O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no
file)
O2 - BHO: (no name) - {00000000-F09C-02B4-6EC2-AD0300000000} - (no
file)
O2 - BHO: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - (no
file)
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no
file)
O2 - BHO: (no name) - {7b55bb05-0b4d-44fd-81a6-b136188f5deb} - (no
file)
O2 - BHO: (no name) - {8333c319-0669-4893-a418-f56d9249fca6} - (no
file)
O2 - BHO: (no name) - {9c691a33-7dda-4c2f-be4c-c176083f35cf} - (no
file)
O2 - BHO: (no name) - {ffd2825e-0785-40c5-9a41-518f53a8261f} - (no
file)
O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\system32\susp.exe
O4 - HKCU\..\Run:
[taskdir] C:\WINDOWS\system32\taskdir.exe