Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le août 04, 2016, 17:03:30

Titre: NetStream
Posté par: chantal11 le août 04, 2016, 17:03:30
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

NetStream est un Trojan Dropper (https://blog.malwarebytes.com/threats/trojan-dropper/). Ce Cheval de Troie est conçu pour télécharger d’autres logiciels malveillants.
NetStream se présente comme un éditeur de PHP.

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FNetStream%2Fwarning4.png&key=0cfdf23815c8697cbe650a0feabf41d2fb2f2e86b355534b017162e9e5a0b04b)

(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FNetStream%2Fwarning1.png&key=8dbf47d96d6641b66f016edcb54e380631676d924947d38f40a47373b0011f3c)






**********

Détection de NetStream dans des rapports FRST :

Citer
NetStream 1.0 (HKCU\...\NetStream 1.0) (Version:  - )
FirewallRules: [{F88292C2-4D60-49C3-AE6C-6507FFB632CC}] => (Allow) C:\Windows\system32\rundll32.exe

(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
HKCU\...\Run: [pump64] => rundll32.exe "C:\Users\{Nom_Utilisateur}\AppData\Local\pump64.dll",pump64 <===== ATTENTION
C:\Users\{Nom_Utilisateur}\AppData\Local\pump64.dll
C:\Users\{Nom_Utilisateur}\AppData\Local\uninstall.exe
C:\Users\{Nom_Utilisateur}\AppData\Local\Temp\rein.dll

**********

Détecté et traité par Malwarebytes en tant que Trojan.Dropper

Citer
Trojan.Dropper
Trojan.Bunitu


Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


Source : Removal instructions for NetStream de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/186568-removal-instructions-for-netstream/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/