Need help? Ask the community or hire an expert.
Go to Avira Answers
??:Worm/Kolabc.WN
????:13/12/2012
??:??
????:?
????????????
??/?????????
?? / ?????????
????:?
????:52.624 ??
MD5 ???:65cf5d3bc5efd0d4ffcf83bfb59ba33b
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ????:
   • ????
   • ???????


??:
   •  Symantec: W32.IRCbot
   •  Mcafee: Puper
   •  Kaspersky: Net-Worm.Win32.Kolabc.wn
   •  F-Secure: Net-Worm.Win32.Kolabc.wn
   •  Panda: W32/Sdbot.LUQ.worm
   •  VirusBuster: Worm.Poebot.OA
   •  Eset: Win32/Poebot.NBF
   •  Bitdefender: Backdoor.IRCBot.ACGJ


??/????:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ??????
   • ?????
   • ????
   • ?????

 ?? ???????????????????:
???: %SYSDIR%\ ??????:
   • winamp.exe
   • winIogon.exe
   • firewall.exe
   • spooIsv.exe
   • spoolsvc.exe
   • Isass.exe
   • lssas.exe
   • algs.exe
   • logon.exe
   • iexplore.exe




??????:

%????????%:\%?????????%.bat ???????????? ?????????????



??????????:

???????:
   • http://alwayssam**********
???????????????: %SYSDIR%\%?????%.exe ???????? ??????????????????

???????:
   • http://alwayssam**********
???????????????: %SYSDIR%\%?????%.exe ???????? ??????????????????

???????:
   • http://alwayssam**********
???????????????: %SYSDIR%\%?????%.exe ???????? ??????????????????

???????:
   • http://zonetech**********
???????????????: %SYSDIR%\%?????%.exe ???????? ?????????????????? ?????????????

 ??? ????????????????????????:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • Windows Network Firewall="%SYSDIR%\firewall.exe"

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Microsoft Internet Explorer"="%SYSDIR%\iexplore.exe"

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Winamp Agent"="%SYSDIR%\winamp.exe"

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Client Server Runtime Process"="%SYSDIR%\csrs.exe"

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Spooler SubSystem App"="%SYSDIR%\spoolsvc.exe"

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Windows Logon Application"="%SYSDIR%\winIogon.exe"

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Windows Logon Application"="%SYSDIR%\logon.exe"

 ???? ?????????????????????????????

??????????????????:
   • IPC$
   • print$
   • C$\Documents and Settings\All Users\Documents\$
   • admin$
   • Admin$\system32
   • c$\windows\system32
   • c$\winnt\system32
   • c$\windows
   • c$\winnt
   • e$\shared
   • d$\shared
   • c$\shared


?????????????????:

???????:
   • staff; teacher; owner; student; intranet; lan; main; office; control;
      siemens; compaq; dell; cisco; ibm; oracle; sql; data; access;
      database; domain; god; backup; technical; mary; katie; kate; george;
      eric; none; guest; chris; ian; neil; lee; brian; susan; sue; sam;
      luke; peter; john; mike; bill; fred; joe; jen; bob; wwwadmin; oemuser;
      user; homeuser; home; internet; www; web; root; server; linux; unix;
      computer; adm; admin; admins; administrat; administrateur;
      administrador; administrator

??????:
   • winpass; blank; nokia; orainstall; sqlpassoainstall; databasepassword;
      databasepass; dbpassword; dbpass; domainpassword; domainpass; hello;
      hell; love; money; slut; bitch; fuck; exchange; loginpass; login; qwe;
      zxc; asd; qaz; win2000; winnt; winxp; win2k; win98; windows;
      oeminstall; oem; accounting; accounts; letmein; sex; outlook; mail;
      qwerty; temp123; temp; null; default; changeme; demo; test; secret;
      payday; deadline; work; pwd; pass; pass1234; dba; passwd; password;
      password1



????:
??????????? TFTP ? FTP ??????????????????

 IRC ????????????????????? IRC ???:

???: hub.54**********
??: 1863
??: #las6;#rs2;#fox;# 63;# kok6
??: Cyzuzeof
??: stseelkvyyrucnss

???: xx.ka3**********
??: 5190
??: #las6;#rs2;#fox;# 63;# kok6
??: Cyzuzeof

???: p.ircs**********
??: 8080
??: #las6;#rs2;#fox;# 63;# kok6
??: Cyzuzeof

???: n.ircs**********
??: 5555
??: #las6;#rs2;#fox;# 63;# kok6
??: Cyzuzeof

???: xx.sql**********
??: 7000
??: las6;#rs2;#fox;# 63;# kok6
??: Cyzuzeof



 ??????????????????:
    • ????
    • ??????
    • ????
    • ????????
    • ???????
    • ???
    • Windows ??????


 ????????????:
     ??? IRC ???
     ? IRC ???????
    • ?? IRC ??
    • ?? IRC ??
    • ????

 ?? ??????????:
 ?????????????
 ??????????????

?????????:
   • UnrealIRCD
   • Steam
   • World Of Warcraft
   • Conquer Online

?????????????????:
   • irc operator; paypal; paypal.com; cd key; cd-key; cdkey; passwort;
      auth; sxt; login; pass=; login=; password=; username=; passwd=; :auth;
      identify; oper; MailPass; pass; unknown; user

 ?????? ????:
????????? MS Visual C++ ????


???????:
????????????????????????????????:
   • WinUpack

Beschrijving ingevoegd door Alexandru Dinu op woensdag 30 juli 2008
Beschrijving bijgewerkt door Alexandru Dinu op woensdag 30 juli 2008

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.