Anatomie d'une attaque virale

yom@yom-laptop:/home/virlab/labo$ clamscan -v cartaodeamor5487.exe 
Scanning cartaodeamor5487.exe
cartaodeamor5487.exe: OK

----------- SCAN SUMMARY -----------
Known viruses: 111194
Engine version: 0.90.2
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 0.10 MB
Time: 2.676 sec (0 m 2 s)
yom@yom-laptop:/home/virlab/labo$ 
ZYYd
c:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE http://ocarteiro.click21.com.br/democartao.php?cat=AB1
c:\windll.exe
http://www.felicidadeinstantanea.com/postcards/tensin.exe
c:\windll.exe
c:\windll2.exe
c:\windll2.exe
yom@yom-laptop:/home/virlab/labo$ clamscan -v tensin.exe 
Scanning tensin.exe
tensin.exe: OK

----------- SCAN SUMMARY -----------
Known viruses: 111396
Engine version: 0.90.2
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 2.76 MB
Time: 2.973 sec (0 m 2 s)
kernel32.dll
user32.dll
GetModuleHandleA
MessageBoxA
scanner name="AntiVir Workstation" application_version="2.1.10-36" signature_file_version="6.38.1.26">
<classification>TR/Delphi.Downloader.Gen]</classification>
<additional_info/>
</scanner>
<connection transportprotocol="TCP" remoteaddr="200.226.246.67" remoteport="80" protocol="HTTP" connectionestablished="1" socket="1664">
	<http_data>
<http_cmd method="GET" url="/postcards/tensin.exe" http_version="HTTP/1.1"/>
</http_data>
</connection>
<scanner name="AntiVir Workstation" application_version="2.1.10-36" signature_file_version="6.38.1.26">
<classification>TR/Spy.Banker.Gen]</classification>
<additional_info/>
</scanner>

  1. “C'est une blague bien sûr !” © A. Montebourg.
  2. Là je suis sérieux par contre…