cmd.exe lance un ftp.exe depuis aujourd'hui!?

cmd.exe lance un ftp.exe depuis aujourd'hui!? - Sécurité - Windows & Software

Marsh Posté le 01-05-2004 à 13:22:58    

Bonjour, mon problème est le suivant , depuis aujourd'hui, mon antivirus bitdefender détecte  que le programme ftp.exe essaie de se connecter quand je suis sur le web (programme lancé par un cmd.exe), mais quand je lance un scan sur mon ordi, bitdefender ne trouve pas de virus (et il est a jour).Donc je refuse l accès du programme au web, est ce que quelqu'un peut me dire si il s'agit d'un virus ou un trojan? merci

Reply

Marsh Posté le 01-05-2004 à 13:22:58   

Reply

Marsh Posté le 01-05-2004 à 13:26:16    

ça ressemble à netsky :
 

32.Netsky.V@mm is a mass-mailing worm that sends itself to the email addresses that it gathers from the files on the computer. This variant does not send an attachment with its email messages, but instead sends a link to an infected computer, attempting to download and run the worm's executable.
 
Replication Process
The replication is provided using the mechanism of known vulnerabilities, as shown in the diagram below:
 
 
   1. W32.Netsky.V@mm constructs a message body using the Microsoft Internet Explorer XML Page Object Type Validation vulnerability (described in Microsoft Security Bulletin MS03-040). This vulnerability could allow a malicious object to be trusted, installed, and then executed on a targeted computer.
 
      The email body contains the object that points to the following source:
 
      http /%infected_computer_ip%:5557/index.html
 
      where %infected_computer_ip% is the IP address of an infected computer.
 
   2. The targeted computer will request the index.html page on an infected computer, accessing the HTTP server listening on port 5557.
 
   3. The HTTP server creates an index.html page that exploits the Microsoft IE5 ActiveX "Object for constructing type libraries for scriptlets" vulnerability (described in Microsoft Security Bulletin MS99-032).
 
   4. The viral index.html file will launch ftp.exe, which is the default FTP client in Windows.
 
      Ftp.exe will connect to the FTP server listening on port 5556 on an infected computer, and then request the worm executable.
 
   5. The worm executable is sent to the targeted computer and then executed.


 
 
test : http://www.symantec.com/securitycheck/


---------------
Cherche geekette | Traquez vos billets d'€ | Don du sang | Don de moelle osseuse
Reply

Sujets relatifs:

Leave a Replay

Make sure you enter the(*)required information where indicate.HTML code is not allowed