Sa présence peut être découverte par l'existance d'un ou de plusieurs des fichiers suivants :
UDefender_Installer[1].exe
udefender_installer[1].exe
%appdata%\58256af6.exe
%local_settings%\temp\tinst3.exe
%program_files%\ultimate defender\app.exe
%program_files%\ultimate defender\iesafe.exe
installer.exe
ucleaner_45aTq2V13X[1].exe
udefender_45aTq2V13X[1].exe
udefender_installer.exe
Selon Symantec, et selon le nom sous lequel ce parasite s'est installé, vous devriez trouver :
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Start 1stAntiVirus.lnk
C:\Documents and Settings\Administrator\Desktop\1stAntiVirus.lnk
C:\Documents and Settings\Administrator\Desktop\1stAntiVirus.pkg
C:\Documents and Settings\Administrator\Start Menu\Programs\1stAntiVirus\Register 1stAntiVirus.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\1stAntiVirus\Start 1stAntiVirus.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\1stAntiVirus\Uninstall 1stAntiVirus.lnk
%ProgramFiles%\1stAntiVirus\App.exe
%ProgramFiles%\1stAntiVirus\drv\securedisk.dcc
%ProgramFiles%\1stAntiVirus\drv\xpdriver.sys
%ProgramFiles%\1stAntiVirus\extensions.pkg
%ProgramFiles%\1stAntiVirus\program.info
%ProgramFiles%\1stAntiVirus\Uninstall.exe
%ProgramFiles%\1stAntiVirus\Update.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Start KillSpy.net.lnk
%UserProfile%\Desktop\KillSpy.net.lnk
%UserProfile%\Desktop\KillSpy.net.pkg
%Userrofile%\Start Menu\Programs\KillSpy.net\Register KillSpy.net.lnk
%UserProfile%\Start Menu\Programs\KillSpy.net\Start KillSpy.net.lnk
%UserProfile%\Start Menu\Programs\KillSpy.net\Uninstall KillSpy.net.lnk
%ProgramFiles%\KillSpy.net\App.exe
%ProgramFiles%\KillSpy.net\drv\securedisk.dcc
%ProgramFiles%\KillSpy.net\drv\xpdriver.sys
%ProgramFiles%\KillSpy.net\extensions.pkg
%ProgramFiles%\KillSpy.net\logs\1144058126.log
%ProgramFiles%\KillSpy.net\program.info
%ProgramFiles%\KillSpy.net\Uninstall.exe
%ProgramFiles%\KillSpy.net\Update.exe
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Start SpyDeface.lnk
C:\Documents and Settings\Administrator\Desktop\SpyDeface.lnk
C:\Documents and Settings\Administrator\Desktop\SpyDeface.pkg
C:\Documents and Settings\Administrator\Start Menu\Programs\SpyDeface\Register SpyDeface.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\SpyDeface\Start SpyDeface.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\SpyDeface\Uninstall SpyDeface.lnk
C:\Program Files\SpyDeface\App.exe C:\Program Files\SpyDeface\drv\securedisk.dcc
C:\Program Files\SpyDeface\drv\xpdriver.sys
C:\Program Files\SpyDeface\extensions.pkg
C:\Program Files\SpyDeface\logs\1144150040.log
C:\Program Files\SpyDeface\logs\1144150054.log
C:\Program Files\SpyDeface\program.info
C:\Program Files\SpyDeface\Uninstall.exe
C:\Program Files\SpyDeface\Update.exe
Ou par l'existence de l'une ou plusieurs des clés suivantes dans la base de registre :
hklm\software\Microsoft\Windows\CurrentVersion\Uninstall\1stAntiVirus
hkcu\software\XXI\1stAntiVirus
hklm\software\Microsoft\Windows\CurrentVersion\Uninstall\KillSpy.net
hkcu\software\XXI\KillSpy.net
hklm\software\Microsoft\Windows\CurrentVersion\Uninstall\SpyDeface
HKEY_USERS\S-1-5-21-220523388-1844823847-682003330-500\Software\XXI\SpyDeface
HKEY_USERS\S-1-5-21-220523388-1844823847-682003330-500\Software\XXI\SpyDeface.com
Une Analyse
HijackThis donnera une ligne de type/
O4 - HKCU\..\Run: [Ultimate Defender.install] "C:\Documents and Settings\Utilisateur\Local Settings\Temporary Internet Files\Content.IE5\U5ELMHSF\UDefender_Installer[1].exe"
Le téléchargement n'est pas celui du logiciel lui-même (Ultimate Defender...) mais d'un
Downloader (UDefender_Installer.exe ...) lui-même suspect :
Analyse avec
VirusTotal (28 antivirus) :
