Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/VBKrypt.dhzd
????:13/12/2012
??:?????
????:?
????????????
??/????????
?? / ?????????
????:536.064 ??
MD5 ???:737C8ADD80E92CA17FEEDB27E205189D
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ????:
   • ???????


??:
   •  Mcafee: W32/Autorun.worm.h
   •  Kaspersky: Trojan.Win32.VBKrypt.dhzd
     Avast: Win32:VB-UXG [Trj]


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Server 2008


???:
   • ????????
   • ????
   • ????????
   • ?????
   • ????

 ?? ???????????:
   • %APPDATA%\Adobee\Protect.exe
   • %APPDATA%\%??%.exe



??????:

%TEMPDIR%\ETpDS.bat ??????????????????
%APPDATA%\data.dat ???????????



??????????:

???:
   • REG
?????????: ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "run32.exe" /t REG_SZ /d "%APPDATA%\Adobee\Protect.exe" /f


???:
   • REG
?????????: ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f ([32] %SYSDIR%\cmd.exe)


???:
   • REG
?????????: ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "C:\Documents and Settings\User101\Application Data\Adobee\Protect.exe" /t REG_SZ /d "C:\Documents and Settings\User101\Application Data\Adobee\Protect.exe:*:Enabled:Windows Messanger" /f ([33] %SYSDIR%\cmd.exe)


???:
   • REG
?????????: ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v "DoNotAllowExceptions" /t REG_DWORD /d "0" /f ([35] %SYSDIR%\cmd.exe)


???:
   • REG
?????????: ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "C:\Documents and Settings\User101\Application Data\3.exe" /t REG_SZ /d "C:\Documents and Settings\User101\Application Data\3.exe:*:Enabled:Windows Messanger" /f ([37] %SYSDIR%\cmd.exe)

 ??? ????????????????????????????????

  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\
   run]
   • "Win Defender"="%APPDATA%\%??%.exe"

  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "Win Defender"="%APPDATA%\%??%.exe"

  [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Win Defender"="%APPDATA%\%??%.exe"

  [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "run32.exe"="%APPDATA%\Adobee\Protect.exe"



?????????????:

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile]
   • "DoNotAllowExceptions"=dword:00000000

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile\AuthorizedApplications\List]
   • "%APPDATA%\Adobee\Protect.exe"="%APPDATA%\Adobee\Protect.exe:*:Enabled:Windows Messanger"
   • "%APPDATA%\%??%.exe"="%APPDATA%\%??%.exe:*:Enabled:Windows Messanger"

 ???? ???????:

svchost.exe ? UDP ??? 1033


?????:
????:
   • xdanx3.no-ip.**********

??????????????????

???????????:
     Windows ??????


??????:
     ?? DDoS ??
     ??????

 ???? ???????????????????

    ??????:
   • svchost.exe
   • explorer.exe


 ?????? ????:
????????? Visual Basic ????


???????:
????????????????????????????????:
   • UPX

Beschrijving ingevoegd door Andrei Ilie op maandag 1 augustus 2011
Beschrijving bijgewerkt door Andrei Ilie op dinsdag 2 augustus 2011

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.