Need help? Ask the community or hire an expert.
Go to Avira Answers
??:WORM/Cycbot.S.4
????:13/12/2012
??:??
????:?
????????????????
??/????????
?? / ????????????
????:?
????:171.520 ??
MD5 ???:D2954496B08A6308BE4EE669C261BD3A
VDF ??:7.11.53.216 - donderdag 13 december 2012
IVDF ??:7.11.53.216 - donderdag 13 december 2012

 ???? ??:
   •  Kaspersky: Trojan.Win32.Menti.hirs
   •  TrendMicro: BKDR_CYCBOT.SMIB
     Microsoft: Backdoor:Win32/Cycbot.B


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ?????

 ?? ???????????:
   • %HOME%\Application Data\Microsoft\conhost.exe



??????:

%HOME%\Application Data\C826.657

 ??? ????????????????????????:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "conhost"="%HOME%\Application Data\Microsoft\conhost.exe"



?????????????:

[HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\
   Internet Settings]
   • "ProxyEnable"=dword:00000001



?????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
   ??:
   • "MigrateProxy"=dword:00000001
   • "ProxyEnable"=dword:00000001
   • "ProxyServer"="http=127.0.0.1:%??%"
   • "ProxyOverride"=-
   • "AutoConfigURL"=-

 ??  ??????????? Internet ??:
   • http://www.google.com
?? Internet ???
   • http://crazyleafdesign.com/blog/images/share/**********?v84=%??%&tq=%???%
   • http://zonetf.com/**********?tq=%???%
   • http://zoneoc.com/blog/images/**********?v50=%??%&tq=%???%
   • http://smallautosite.com/blog/images/**********?v32=%??%&tq=%???%


Mutex:
?????? Mutex:
   • {7791C364-DE4E-4000-9E92-9CCAFDDD90DC}
   • {A5B35993-9674-43cd-8AC7-5BC5013E617B}
   • {B37C48AF-B05C-4520-8B38-2FE181D5DC78}
   • {61B98B86-5F44-42b3-BCA1-33904B067B81}

 ?????? ????:
????????? MS Visual C++ ????


???????:
????????????????????????????????:
   • UPX

Beschrijving ingevoegd door Andrei Ilie op dinsdag 1 november 2011
Beschrijving bijgewerkt door Andrei Ilie op woensdag 2 november 2011

Terug . . . .
https:// Dit venster is voor uw veiligheid gecodeerd.