Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/Spy.ZBot.pcp
????:13/12/2012
??:?????
????:?
????????????????
??/????????
?? / ????????????
????:?
????:118272 ??
MD5 ???:8603e529ee23ac7e1213d5b5e14c66d7
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ????:
   • ???????


??:
   •  Kaspersky: Trojan.Win32.Scar.cndh
   •  TrendMicro: TROJ_MEREDROP.SY
   •  F-Secure: Trojan.Win32.Scar.cndh
   •  Eset: Win32/Spy.Zbot.YW


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ????????
   • ????
   • ????
   • ?????

 ?? ???????????:
   • %SYSDIR%\sdra64.exe



????????:
   • %SYSDIR%\lowsec



??????:

?????:
   • %SYSDIR%\lowsec\user.ds
   • %SYSDIR%\lowsec\local.ds
   • %SYSDIR%\lowsec\user.ds.lll




????????:

???????:
   • http://113.11.194.175/us/**********

 ??? ????????????????????????:

[HKLM\software\microsoft\windows nt\currentversion\winlogon]
   • "userinit"="%SYSDIR%\userinit.exe,,%SYSDIR%\sdra64.exe,"



?????????????:

[HKCU\software\microsoft\windows\currentversion\explorer\
   {35106240-D2F0-DB35-716E-127EB80A0299}\
   {33373039-3132-3864-6B30-303233343434}]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network]
   • "UID"="%?????%_B4DF76112BF9218C"

[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network]
   • "UID"="%?????%_B4DF76112BF9218C"

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
   • "ParseAutoexec"="1"



?????????:

?? Windows ???:

[HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile]
   ??:
   • "EnableFirewall"=dword:00000000

?? Windows ???:

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile]
   ??:
   • "EnableFirewall"=dword:00000000

 ???? ???????????????????

    ???:
   • svchost.exe



???????????????????

    ???:
   • services.exe


 ?????? ???????:
???????????????????????????????

Beschrijving ingevoegd door Ana Maria Niculescu op donderdag 16 september 2010
Beschrijving bijgewerkt door Ana Maria Niculescu op donderdag 16 september 2010

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.