Hi,
Following the different responses, I got from the sites you directed me,
The backdoor is
"Backdoor.beasty.Fami" or "Backdoor.beastdoor.202" aka "Backdoor-AMQ"
The library informations don't give exactly the same infection profile as I
had. The filenames are different and the mode the virus modified the
registry is slightly different as well.
I have probably a variant of one of above. The antivirus aren't yet updated
and I'm proposed beta signatures.
However my evening readings led me to find another file:
Windows\system\ulwy.blf. I think it's the log the virus wrote in prevision
to send it to the remote site.
Your recommendations have been widely helpful. Thanks again to all who
answered.
Now begins another story: Why didn't ZoneAlarm rename the PIF file ?
"Nick FitzGerald" <nick.TakeThisOut@virus-l.demon.co.uk> a écrit dans le message news:
3fa0ab20.TakeThisOut@clear.net.nz...
> "Buffalo" <eric(nospam)@nada.com.invalid> replied to "Zantafio":
>
> > > I did it today.
> > >
> > Great move. Good for you and probably it will be good for me also.
> >
>
> Yep -- as I hinted earlier in teh thread, to an "outsider" it may be quite
> surprising how much stuff has detection added because of initial "from the
> field" sample submissions such as this. The sooner a user who suspects
> something gets it to the vendors the better for _all_.
>
>
> --
> Nick FitzGerald
>
> >> Stay informed about: Strange virus/trojan not detected