Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/Buzus.cptr
????:13/12/2012
??:?????
????:?
????????????????
??/????????????
?? / ?????????
????:?
????:262.144 ??
MD5 ???:20f60d32f26b0bcc1b17aa994ddeed14
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ????:
    ??????Autorun??


??:
   •  Mcafee: W32/Palack.worm
   •  Sophos: W32/AutoRun-AVL
   •  Panda: W32/P2PWorm.EK.worm
   •  Eset: Win32/AutoRun.IRCBot.DI
   •  Bitdefender: Trojan.Dropper.VB


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ??????
   • ?????
   • ?????

 ?? ???????????:
   • %SYSDIR%\wmispm.exe
   • %???%\RECDIR-5902\data.sys



???????????????



??????:
   • %TEMPDIR%\melt.bat



??????:

%???%\autorun.inf ???????????????????:
   • %????????%

%TEMPDIR%\melt.bat ???????????? ?????????????



??????????:

???:
   • net stop avg8wd


???:
   • "%SYSDIR%\wmispm.exe"


???:
   • net1 stop AntiVirService


???:
   • CMD /C sc stop SbPF.Launcher


???:
   • sc stop avg8wd


???:
   • CMD /C sc config "avast! Antivirus" start= disabled


???:
   • sc stop NOD32krn


???:
   • CMD /C sc config AntiVirService start= disabled


???:
   • "C:\WORK\!ITW
   • 44.exe"


???:
   • CMD /C sc config avg8wd start= disabled


???:
   • cmd /c ""%TEMPDIR%\melt.bat" "


???:
   • sc config avg8wd start= disabled


???:
   • CMD /C sc delete "avast! Antivirus"


???:
   • CMD /C sc stop "avast! Antivirus"


???:
   • sc delete AntiVirService


???:
   • CMD /C del /F /S /Q *.zip


???:
   • CMD /C sc delete PASRV


???:
   • sc stop SbPF.Launcher


???:
   • CMD /C sc stop avg8wd


???:
   • CMD /C sc stop AntiVirService


???:
   • net1 stop VSSERV


???:
   • CMD /C net stop VSSERV


???:
   • net stop SbPF.Launcher


???:
   • CMD /C del /F /S /Q *.scr


???:
   • sc config SbPF.Launcher start= disabled


???:
   • sc delete SbPF.Launcher


???:
   • CMD /C sc delete VSSERV


???:
   • net stop NOD32krn


???:
   • sc delete PASRV


???:
   • net stop AntiVirService


???:
   • sc delete VSSERV


???:
   • CMD /C net stop SbPF.Launcher


???:
   • sc config "avast! Antivirus" start= disabled


???:
   • net1 stop "avast! Antivirus"


???:
   • sc config AntiVirService start= disabled


???:
   • CMD /C del /F /S /Q *.com


???:
   • CMD /C sc delete AntiVirService


???:
   • CMD /C sc delete SbPF.Launcher


???:
   • CMD /C sc stop VSSERV


???:
   • sc config VSSERV start= disabled


???:
   • CMD /C sc config NOD32krn start= disabled


???:
   • CMD /C sc stop NOD32krn


???:
   • CMD /C net stop SPF4


???:
   • CMD /C sc config PASRV start= disabled


???:
   • CMD /C net stop PASRV


???:
   • CMD /C net stop "avast! Antivirus"


???:
   • CMD /C net stop AntiVirService


???:
   • sc stop PASRV


???:
   • CMD /C sc stop PASRV


???:
   • sc delete "avast! Antivirus"


???:
   • net1 stop SbPF.Launcher


???:
   • net1 stop avg8wd


???:
   • sc delete avg8wd


???:
   • sc config NOD32krn start= disabled


???:
   • sc stop VSSERV


???:
   • CMD /C sc stop SPF4


???:
   • CMD /C net stop NOD32krn


???:
   • sc stop "avast! Antivirus"


???:
   • net stop VSSERV


???:
   • net stop PASRV


???:
   • sc delete NOD32krn


???:
   • CMD /C sc config VSSERV start= disabled


???:
   • sc stop AntiVirService


???:
   • CMD /C sc delete avg8wd


???:
   • CMD /C sc config SbPF.Launcher start= disabled


???:
   • CMD /C net stop avg8wd


???:
   • net stop "avast! Antivirus"


???:
   • net1 stop PASRV


???:
   • sc config PASRV start= disabled


???:
   • CMD /C sc delete NOD32krn


???:
   • net1 stop NOD32krn

 ??? ???????????????????????:

  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "ctfmon.exe"="ctfmon.exe"



?????????????:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
   Image File Execution Options\ctfmon.exe]
   • "Debugger"="wmispm.exe"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\
   Layers]
   • "%SYSDIR%\wmispm.exe"="DisableNXShowUI"



?????????:

[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal]
   ??:
   • "ctfmon.exe"="ctfmon.exe"

[HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]
   ??:
   • "ctfmon.exe"="ctfmon.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions]
   ??:
   • "GON"="%?????%"

 IRC ????????????????????? IRC ???:

???: ascend.sr**********.info
??: 31960
??: #w1sd0m
??: [00|USA|XP|%??%]

 ?????? ????:
????????? Visual Basic ????

Beschrijving ingevoegd door Petre Galan op donderdag 8 april 2010
Beschrijving bijgewerkt door Petre Galan op donderdag 8 april 2010

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.