PCの修理が必要ですか?
専門家に頼む
????Worm/Yahos.lx
????26/01/2011
??????
????????
?????
???????
????????????
?????????????
????????94.208 ???
MD5???????26B84DFB2F3ECBF5DFF168A593F512D9
VDF???????7.10.08.59
IVDF???????7.11.01.251 - 2011年1月26日水曜日

 ???? ????
   • ????????????


??
   •  Kaspersky: IM-Worm.Win32.Yahos.lx
   •  F-Secure: IM-Worm.Win32.Yahos.lx
   •  Eset Win32/Yimfoca.AA worm
     DrWeb: Win32.HLLW.Oscar.14


????????/OS?
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7


???
   • ???????????
   • ????????????????
   • ???????????
   • ?????????
    Web ????? Web ??????

 ???? ??????????????????
   • %WINDIR%\nvsvc32.exe



???????????????

??????????
   • %WINDIR%\ndl.dl
   • %WINDIR%\wiybr.png
   • %WINDIR%\wibrf.jpg




??????????????????

?????????????????????????
   • %SYSDIR%\net.exe


?????????????????????????
   • %SYSDIR%\netsh.exe
???????????????????????????? firewall add allowedprogram 1.exe 1 ENABLE


?????????????????????????
   • %SYSDIR%\ntvdm.exe
???????????????????????????? -f -i1


?????????????????????????
   • %SYSDIR%\ntvdm.exe
???????????????????????????? -f -i2


?????????????????????????
   • %SYSDIR%\sc.exe
???????????????????????????? config wuauserv start= disabled


?????????????????????????
   • %SYSDIR%\sc.exe
???????????????????????????? sc config MsMpSvc start= disabled


?????????????????????????
   • %WINDIR%\explorer.exe
???????????????????????????? http://browseusers.myspa**********.com/Browse/Browse.aspx

 ????? ??????????????????????????????????????????

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "NVIDIA driver monitor"="%WINDIR%\\nvsvc32.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "NVIDIA driver monitor"="%WINDIR%\\nvsvc32.exe"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\
   Install\Software\Microsoft\Windows\CurrentVersion\Run]
   • "NVIDIA driver monitor"="%WINDIR%\\nvsvc32.exe"



??????XP?????????????????????????????????

[HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile\AuthorizedApplications\List]
   • "%?????????????????%\\%??????%"="%WINDIR%\\nvsvc32.exe:*:Enabled:NVIDIA
      driver monitor"



???????????????????

Internet Explorer???????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   ZoneMap]
   ???
   • "ProxyBypass"=%?????%
   • "IntranetName"=%?????%
   • "UNCAsIntranet"=%?????%
   ????
   • "ProxyBypass"=dword:00000001
   • "IntranetName"=dword:00000001
   • "UNCAsIntranet"=dword:00000001

Internet Explorer???????????????:

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings]
   ???
   • "MigrateProxy"=%?????%
   • "ProxyEnable"=%?????%
   • "ProxyServer"=%?????%
   • "ProxyOverride"=%?????%
   • "AutoConfigURL"=%?????%
   ????
   • "MigrateProxy"=dword:00000001
   • "ProxyEnable"=dword:00000000
   • "ProxyServer"=-
   • "ProxyOverride"=-
   • "AutoConfigURL"=-

Internet Explorer???????????????:

[HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\
   Internet Settings]
   ???
   • "ProxyEnable"=%?????%
   ????
   • "ProxyEnable"=dword:00000000

[HKCR\TypeLib\%CLSID%\1.1\0\win32]
   ????
   • "(Default)"="oleacc.dll"

 IRC ?????????????????????????????????IRC??????????

??? %IRC???%
???? 1234
????????? xxx
????? #!nn! test/mask>
?????? NEW-[GBR|00|**********|%???????%]


 ????????????????????????
     IRC??????????
     IRC??????????????
    • IRC??????????

 ??? ?????????

???????????
   • astro.ic.**********.uk
   • ale.pakibiliv.com
   • versatek.com
   • journalofaccountancy.com
   • api.albertoshistory.info
   • journalofaccountancy.com
   • transnationale.org
   • mas.0730ip.com
   • mas.0730ip.com
   • www.facebook.com
   • stayontime.info
   • www.shearman.com
   • insidehighered.com
   • ate.lacoctelera.net
   • websitetrafficspy.com
   • qun.51.com
   • summer-uni-sw.eesp.ch
   • shopstyle.com
   • xxx.stopklatka.pl
   • xxx.stopklatka.pl
   • browseusers.myspace.com
   • www.myspace.com
   • x.myspacecdn.com
??????? ?????????? :
   • http://www.facebo**********.com/home.php;
      http://www.facebo**********.com/login.php;
      http://browseusers.myspa**********.com/Browse/Browse.aspx;
      http://www.myspa**********.com/browse/people;
      http://www.myspa**********.com/help/browserunsupported;
      http://x.myspace**********.com/modules/splash/static/img/cornersSheet.png;
      http://x.myspa**********.com/images/BrowserUpgrade/bg_infobox.jpg;
      http://x.myspa**********.com/images/BrowserUpgrade/icon_information.gif;
      http://x.myspace**********.com/images/BrowserUpgrade/bg_browserSection.jpg;
      http://x.myspace**********.com/images/BrowserUpgrade/browserLogos_med.jpg;
      http://208.43.102.**********/index.php

 ??????? ???????:
?????????????MS Visual C++?????????


???????????
??? 25/01/2011
??? 14:46:52

説明の挿入者 Alexander Bauer の 2011年1月27日木曜日
説明の更新者 Alexander Bauer の 2011年1月27日木曜日

戻る . . . .
https:// このウィンドウは暗号化されています。