Need help? Ask the community or hire an expert.
Go to Avira Answers
??:Worm/IrcBot.19968.20
????:13/12/2012
??:??
????:?
????????????????
??/????????????
?? / ?????????
????:?
????:19.968 ??
MD5 ???:175528310Da902dbbe27f005815a2b79
VDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe
IVDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe

 ???? ????:
    Messenger


??:
   •  Mcafee: W32/IRCbot.gen.a
   •  Kaspersky: Backdoor.Win32.IRCBot.cud
   •  F-Secure: Backdoor.Win32.IRCBot.cud
   •  Grisoft: BackDoor.Ircbot.EDV
   •  Eset: Win32/IRCBot
   •  Bitdefender: Backdoor.IRCBot.ABYQ


??/????:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ??????????
   • ??????????
   • ?????
   • ?????

 ?? ???????????:
   • %SYSDIR%\initserv.exe



???????????????

 ??? ????????????????????????:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
   • Microsoft Initialization Services="initserv.exe"

 Messenger ???? Messenger ???? ?????????:

Windows Live Messenger


???:
??????????

 IRC ????????????????????? IRC ???:

???: nagasaki.japancorporation.**********
??: 9103
?????: su1c1d3
??: #net
??: \00\USA\%10 ????????%
??: n3t!



 ??????????????????:
    • ?? ID
    • Windows ??????


 ????????????:
     ??? IRC ???
    • ????
    • ?????
    • ????
    • ?? IRC ??
     ??????
     ????

 ?? ???????????????:

???????????????

?????????:
   • jayloden.com
   • www.jayloden.com
   • www.spywareinfo.com
   • spywareinfo.com
   • www.spybot.info
   • spybot.info
   • kaspersky.com
   • kaspersky-labs.com
   • www.kaspersky.com
   • www.majorgeeks.com
   • majorgeeks.com
   • securityresponse.symantec.com
   • symantec.com
   • www.symantec.com
   • updates.symantec.com
   • liveupdate.symantecliveupdate.com
   • liveupdate.symantec.com
   • customer.symantec.com
   • update.symantec.com
   • www.sophos.com
   • sophos.com
   • www.virustotal.com
   • virustotal.com
   • www.mcafee.com
   • mcafee.com
   • rads.mcafee.com
   • mast.mcafee.com
   • download.mcafee.com
   • dispatch.mcafee.com
   • us.mcafee.com
   • www.trendsecure.com
   • trendsecure.com
   • www.viruslist.com
   • viruslist.com
   • www.hijackthis.de
   • hijackthis.de
   • f-secure.com
   • www.f-secure.com
   • Merijn.org
   • www.Merijn.org
   • www.avp.com
   • avp.com
   • analysis.seclab.tuwien.ac.at
   • www.bleepingcomputer.com
   • bleepingcomputer.com
   • trendmicro.com
   • www.trendmicro.com
   • www.safer-networking.org
   • safer-networking.org
   • grisoft.com
   • www.grisoft.com




????hosts ???????:


 Rootkit ?? ????????????? ????????????????????????????????????????


??????:
– ??????

 ?????? ????:
????????? MS Visual C++ ????


???????:
????????????????????????????????:
   • UPX

Açıklamayı yerleştiren Monica Ghitun tarihinde 7 Ağustos 2008 Perşembe
Açıklamayı güncelleyen: Andrei Gherman tarihinde 20 Ağustos 2008 Çarşamba

Geri . . . .
https:// Bu pencere güvenlik amacıyla şifrelenmiştir.