Need help? Ask the community or hire an expert.
Go to Avira Answers
??:Worm/IRCBot.9609
CME ??:482
????:13/12/2012
??:??
????:?
????????????
??/?????????????
?? / ?????????
????:?
????:9.609 ??
MD5 ???:9928A1E6601CF00D0B7826D13FB556F0
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ????:
   • ????
    Messenger


??:
   •  Symantec: Backdoor.IRC.Bot
   •  Mcafee: IRC-Mocbot!MS06-040
   •  Kaspersky: Backdoor.Win32.IRCBot.st
   •  TrendMicro: WORM_IRCBOT.JK
   •  F-Secure: Backdoor.Win32.IRCBot.st


??/????:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ????????
   • ????????
   • ?????
   • ??????
   • ?????

 ?? ???????????:
   • %SYSDIR%\wgareg.exe



???????????????

 ??? ?????????????????????????:

[HKLM\SYSTEM\CurrentControlSet\Services\wgareg]
   • Type = 110
   • Start = 2
   • ErrorControl = 0
   • ImagePath = %SYSDIR%\wgareg.exe
   • DisplayName = Windows Genuine Advantage Registration Service
   • ObjectName = LocalSystem
   • FailureActions = %?????%
   • Description = Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability.

[HKLM\SYSTEM\CurrentControlSet\Services\wgareg\Security]
   • Security = %?????%

[HKLM\SYSTEM\CurrentControlSet\Services\wgareg\Enum]
   • 0 = Root\LEGACY_WGAREG\0000
   • Count = 1
   • NextInstance = 1



?????????:

[HKLM\SOFTWARE\Microsoft\Ole]
   ??:
   • EnableDCOM = %???????%
   ??:
   • EnableDCOM = n

[HKLM\SYSTEM\CurrentControlSet\Control\Lsa]
   ??:
   • restrictanonymous = %???????%
   • restrictanonymoussam = %???????%
   ??:
   • restrictanonymous = 1
   • restrictanonymoussam = 1

[HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters]
   ??:
   • autoshareserver = 0
   • autosharewks = 0

[HKLM\SOFTWARE\Microsoft\security center]
   ??:
   • antivirusdisablenotify = %???????%
   • antivirusoverride = %???????%
   • firewalldisablenotify = %???????%
   • firewalldisableoverride = %???????%
   ??:
   • antivirusdisablenotify = 1
   • antivirusoverride = 1
   • firewalldisablenotify = 1
   • firewalldisableoverride = 1

?? Windows ???:
[HKLM\SOFTWARE\Policies\Microsoft\windowsfirewall\domainprofile]
   ??:
   • enablefirewall = %???????%
   ??:
   • enablefirewall = 0

[HKLM\SOFTWARE\Policies\Microsoft\windowsfirewall\standardprofile]
   ??:
   • enablefirewall = %???????%
   ??:
   • enablefirewall = 0

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess]
   ??:
   • Start = %???????%
   ??:
   • Start = 4

 Messenger ???? Messenger ???? ?????????:

 AIM Messenger

 ???? ?????????????????????????????


????:
??????????:
 MS06-040 (?????????)

 IRC ????????????????????? IRC ???:

???: bniu.house**********
??: 18067
??: #n1
??: n1-%?????%
??: nert4mp1

???: ypgw.wall**********
??: 18067
??: #n1
??: n1-%?????%
??: nert4mp1


 ????????????:
     ?? DDoS SYN ????
     ?? DDoS UDP ????
    • ????
    • ????
     ??????

 ?? Mutex:
?????? Mutex:
   • wgareg

 ?????? ???????:
???????????????????????????????

Beschrijving ingevoegd door Philipp Wolf op zondag 13 augustus 2006
Beschrijving bijgewerkt door Andrei Gherman op maandag 14 augustus 2006

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.