Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/Scar.cfmv
????:13/12/2012
??:?????
????:?
????????????????
??/????????????
?? / ????????????
????:?
????:575.488 ??
MD5 ???:65feb504a274110a513dce6d1b6a640d
VDF ??:7.11.53.216 - 2012년 12월 13일 목요일
IVDF ??:7.11.53.216 - 2012년 12월 13일 목요일

 ???? ????:
    ??????Autorun??


??:
   •  Bitdefender: Trojan.Generic.4010642
   •  Panda: Trj/Thed.V


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ??????
   • ??????
   • ?????

 ?? ???????????:
   • %???%\%?????%
   • %ALLUSERSPROFILE%\Application Data\srtserv\%?????%



??????:

%???%\aUtoRuN.iNF ???????????????????:
   • %????????%

%ALLUSERSPROFILE%\Application Data\srtserv\sdata.dll ?????????????????? ???: Worm/Autorun.hdf

%ALLUSERSPROFILE%\Application Data\srtserv\set.dat



??????????:

????????:
   • http://psynergi.dk/data/**********
   • http://kubusse.ru/data/**********
   • http://s-elisa.ru/data/**********
   • http://eda.ru/data/**********


????????:
   • http://vesterm.freehostia.com/**********
   • http://6cb498fe.freehostia.com/**********
   • http://c7e1c722.110mb.com/**********
   • http://ef1b7dc6.x10hosting.com/**********




??????????:

???:
   • "%ALLUSERSPROFILE%\Application Data\srtserv\%?????%" -wait

 ??? ?????????????:

–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • srtserv

–  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • srtserv



?????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\MSrtn]
   • "value1"="%?????%"
   • "value2"=dword:0x000007d4

 ?? ?? Internet ???
   • http://vesterm.freehostia.com
   • http://psynergi.dk/data
   • http://kubusse.ru/data
   • http://s-elisa.ru/data
   • http://eda.ru/data
   • http://psynergi.dk/data
   • http://pushnik.freehostia.com


Mutex:
?????? Mutex:
   • YCS0mRtQ316
   • KAENA_HOOK

 ?????? ????:
????????? Delphi ????


???????:
???????????????????????????????

설명 삽입자 Petre Galan   2010년 11월 19일 금요일
설명 업데이트 Petre Galan   2010년 11월 19일 금요일

뒤로 . . . .
https:// 이 창은 보안을 위해 암호화되었습니다.