Laboratoire antivirus Avira

‹ Retour

TR/BitCoinMiner.ME.1

Brève description
  • Nom
    TR/BitCoinMiner.ME.1
  • La date de la découverte
    9 déc. 2017
  • Version VDF
    7.14.37.152 (2017-12-09 09:16)
Description complète

Le terme « TR » désigne un cheval de Troie qui est en mesure d’espionner vos données, de porter atteinte à votre vie privée et qui peut effectuer des modifications indésirables sur le système.

  • VDF
    7.14.37.152 (2017-12-09 09:16)
  • Activité réseau
    Array
  • Processus
    Array
  • Fichiers
    Les fichiers suivants sont créés:
    • %TEMPDIR%\cudart32_65.dll
    • %WINDIR%\debug\lsmose.exe
    Les fichiers suivants sont modifiés:
    • %TEMPDIR%\cudart32_65.dll
    • %WINDIR%\debug\lsmose.exe
    Les pilotes suivants sont chargés:
    • %WINDIR%\Globalization\Sorting\sortdefault.nls
    • %TEMPDIR%\%executed_sample%
    • \??\C:
    • %TEMPDIR%\80EB2F5C
    • %TEMPDIR%\cudart32_65.dll
    • %WINDIR%\debug\lsmose.exe
    Les fichiers suivants sont exécutés:
    • %WINDIR%\Globalization\Sorting\sortdefault.nls
    • %TEMPDIR%\%executed_sample%
    • \??\C:
    • %TEMPDIR%\80EB2F5C
    • %TEMPDIR%\cudart32_65.dll
    • %WINDIR%\debug\lsmose.exe
  • Registre
    Les entrées de registre suivantes sont ajoutées:
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters ("Hostname": "")
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters ("Domain": "")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("EnableFileTracing": "0")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("EnableConsoleTracing": "0")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("FileTracingMask": "4294901760")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("ConsoleTracingMask": "4294901760")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("MaxFileSize": "1048576")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("FileDirectory": "%windir%\tracing")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections ("DefaultConnectionSettings": "<INVALID POINTER>")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections ("DefaultConnectionSettings": "F `Lq #3QO!  #3QO! 8(8( @e0.` `PH 40 ]b")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadDecisionReason": "1")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadDecisionTime": "`Lq")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadDecision": "3")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadNetworkName": "Network")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB}
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00 ("WpadDecisionReason": "1")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00 ("WpadDecisionTime": "`Lq")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00 ("WpadDecision": "3")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB}\0a-00-27-00-00-00
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad ("WpadLastNetwork": "{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB}")
    Les entrées de registre suivantes sont modifiées:
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters ("Hostname": "")
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
    • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters ("Domain": "")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("EnableFileTracing": "0")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("EnableConsoleTracing": "0")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("FileTracingMask": "4294901760")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("ConsoleTracingMask": "4294901760")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("MaxFileSize": "1048576")
    • HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\%executed_sample_name%_RASMANCS ("FileDirectory": "%windir%\tracing")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections ("DefaultConnectionSettings": "<INVALID POINTER>")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections ("DefaultConnectionSettings": "F `Lq #3QO!  #3QO! 8(8( @e0.` `PH 40 ]b")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadDecisionReason": "1")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadDecisionTime": "`Lq")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadDecision": "3")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB} ("WpadNetworkName": "Network")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB}
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00 ("WpadDecisionReason": "1")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00 ("WpadDecisionTime": "`Lq")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00 ("WpadDecision": "3")
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB}\0a-00-27-00-00-00
    • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad ("WpadLastNetwork": "{A9C7A8AA-FA05-4B0C-BF08-962D58BC6FFB}")
  • Alias
    Avast: Win32:Malware-gen
    Dr. Web: Trojan.BtcMine.1596
    ESET: a variant of Win32/Packed.EnigmaProtector.J potentially unwanted application
    G Data: Application.BitCoinMiner.XY
    Microsoft: Trojan:Win32/Smominru.A