Need help? Ask the community or hire an expert.
Go to Avira Answers
??:Worm/Scano.S
????:13/12/2012
??:??
????:?
????????????
??/?????????
?? / ????????????
????:?
????:18.060 ??
MD5 ???:47675f28642b095db99b2eae6ecec2bb
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ????:
   • ????


??:
   •  Mcafee: W32/Areses.h
   •  TrendMicro: WORM_ARESES.AC
   •  Sophos: W32/Areses-F
   •  VirusBuster: I-Worm.Scano.O
   •  Eset: Win32/Scano.NAK
   •  Bitdefender: Win32.Scano.N@mm


??/????:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ????
   • ???????????
   • ?????

 ?? ???????????:
   • %WINDIR%\csrss.exe



?????????????????:
   • %TEMPDIR%\Message.zip




??????????:

???????:
   • http://207.46.250.119/g/**********
???????????????????

???????:
   • http://www.microsoft.com/g/**********
???????????????????

???????:
   • http://84.22.161.192/s/**********
???????????????????



??????????:

???:
   • %SYSDIR%\services.exe
?????????: %WINDIR%\csrss.exe
?????????????

???:
   • %SYSDIR%\svchost.exe
?????????: %WINDIR%\csrss.exe

 ??? ????????????????????????:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
   Image File Execution Options\explorer.exe
   • "Debugger"="%WINDIR%\csrss.exe"



?????????????:

–  HKLM\SYSTEM\ControlSet002\Control\Session Manager\
   PendingFileRenameOperations
–  HKLM\SYSTEM\ControlSet002\Control\Session Manager\BootExecute

 ???? ?????? SMTP ???????????? ?????????????? ?????????:


???:
?????????


???:
– ????????????????????
 ? WAB (Windows ???) ??????????


??:
??????:
   • ????????, ??? ???? ????
   • ?????
   • ??????, ?? ????
   • ??????, ?????? ???!!!
   • ??????! ?????? ?????? ?!
   • ??!
   • ?????
   • Re: ?????? ???!
   • Re: ??????? ???!
   • Re: ?? ????
   • Re: ????? ?? ??? ???????
   • Re: ??? ???????????
   • Re: ??? ???????????



??:
??????????????


??????????????:
   • ??????! ? ??????? ??? ??
   • ??????? ? ????????? ??
   • ????? ??? ?????????
   • ????????!!! ??? ????????


??:
?????????????:
   • Message.zip
   • File.zip
   • Document.zip
   • README.zip
   • Passwords.zip
   • Readme.zip
   • Important.zip
   • New.zip
   • COOL.zip
   • Archive.zip
   • Fotos.zip
   • private.zip
   • confidential.zip
   • secret.zip
   • images.zip
   • your_documents.zip
   • backup.zip

??????????????????

 ?? ????:
????????????????:
   • .adb; .asp; .cfg; .cgi; .mra; .dbx; .dhtm; .eml; .htm; .html; .jsp;
      .mbx; .mdx; .mht; .mmf; .msg; .nch; .ods; .oft; .php; .pl; .sht;
      .shtm; .stm; .tbb; .txt; .uin; .wab; .wsh; .xls; .xml; .dhtml


????:
??????????????????????:
   • @microsoft; rating@; f-secur; news; update; .qmail; .gif; anyone@;
      bugs@; contract@; feste; gold-certs@; help@; info@; nobody@; noone@;
      0000; Mailer-Daemon@; @subscribe; kasp; admin; icrosoft; support;
      ntivi; unix; bsd; linux; listserv; certific; torvalds@; sopho; @foo;
      @iana; free-av; @messagelab; winzip; google; winrar; samples; spm111@;
      .00; abuse; panda; cafee; spam; pgp; @avp.; noreply; local; root@;
      postmaster@

 ?????? ???????:
???????????????????????????????

Beschrijving ingevoegd door Irina Boldea op maandag 30 oktober 2006
Beschrijving bijgewerkt door Irina Boldea op maandag 6 november 2006

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.