Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/VB.aga.167
????:13/12/2012
??:?????
????:?
????????????????
??/????????
?? / ????????????
????:?
????:47.104 ??
MD5 ???:45bcbb56dcfb68200719163a933c4f6c
VDF ??:7.11.53.216 - 2012년 12월 13일 목요일
IVDF ??:7.11.53.216 - 2012년 12월 13일 목요일

 ???? ??:
   •  Kaspersky: Backdoor.Win32.VB.nmc
   •  Bitdefender: Backdoor.Generic.634112
     GData: Backdoor.Generic.634112


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ??????
   • ?????
   • ??????
CVE-2007-1204
MS07-019

 ?? ???????????:
   • %TEMPDIR%\2ubrc.exe



?????????
%SYSDIR%\drivers\etc\hosts



???????????????



??????:
   • %TEMPDIR%\mdinstall.inf



??????:

%TEMPDIR%\mdinstall.inf
%TEMPDIR%\MouseDriver.bat
%SYSDIR%\pdpv99.log
%TEMPDIR%\iaohblsg.bat



??????????:

???:
   • net.exe stop "Security Center"


???:
   • %TEMPDIR%\2ubrc.exe -d6D7EB75D9C5B904FF8096542E0A41712AD38B1C10062EB22D4B88EF8B3653850007C160B3A4688D69EEACE6196A82B03CF0C2AC2F853DD81734A54287906A3D186CF29860B03F61AB0F184C3B04B23291720C08CEA5BF2F278CA781072868600762191832C32843432F47B2C5B9877221BA6B380114A


???:
   • "%SYSDIR%\grpconv.exe" -o


???:
   • sc config wscsvc start= DISABLED


???:
   • net.exe stop "Windows Firewall/Internet Connection Sharing (ICS)"


???:
   • sc config SharedAccess start= DISABLED


???:
   • net1 stop "Security Center"


???:
   • %TEMPDIR%\2ubrc.exe


???:
   • net1 stop "Windows Firewall/Internet Connection Sharing (ICS)"


???:
   • Rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 %TEMPDIR%\mdinstall.inf


???:
   • cmd /c %TEMPDIR%\iaohblsg.bat

 ??? ????????????????????????:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
   Run]
   • "wa59"="%TEMPDIR%\2ubrc.exe"



?????????????:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
   • "GrpConv"=""



?????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\GrpConv]
   ??:
   • "Log"="Uninit Application."

[HKLM\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command]
   ??:
   • "@"="%SYSDIR%\grpconv.exe %1"

[HKLM\SOFTWARE\Classes\MSProgramGroup]
   ??:
   • "@"="Microsoft Program Group"

[HKLM\SOFTWARE\Classes\.grp]
   ??:
   • "@"="MSProgramGroup"

 ?? ???????????????:

???????????????

????????????????:
   • 127.0.0.1 localhost


 ???? ?????:
????:
   • http://w.nucleardiscover.com:888/**********?c=%???%&v=%??%&t=%???%


 ?? Mutex:
?????? Mutex:
   • 2ubrc.exewa59dmode
   • 2ubrc.exewa59

 ?????? ???????:
???????????????????????????????

설명 삽입자 Petre Galan   2011년 7월 13일 수요일
설명 업데이트 Petre Galan   2011년 7월 13일 수요일

뒤로 . . . .
https:// 이 창은 보안을 위해 암호화되었습니다.