Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/Spy.ZBot.awgq
????:13/12/2012
??:?????
????:?
????????????????
??/????????
?? / ????????????
????:?
????:184.832 ??
MD5 ???:8142026d807be4faedaec15bc1256fb6
VDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe
IVDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe

 ???? ??:
   •  Mcafee: PWS-Spyeye
   •  Kaspersky: Trojan-Spy.Win32.Zbot.awgq
   •  Sophos: Mal/FakeAV-BW
   •  Bitdefender: Trojan.Generic.KD.95303
   •  Panda: Trj/SpyEyes.E
     GData: Trojan.Generic.KD.95303


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ??????
   • ?????
   • ????

 ?? ???????????:
   • C:\windowsxxx.exe\windowsxxx.exe



???????????????



??????:

C:\windowsxxx.exe\config.bin



??????????:

???:
   • C:\windowsxxx.exe\windowsxxx.exe

 ??? ????????????????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "windowsxxx.exe"="C:\windowsxxx.exe\windowsxxx.exe"



?????????????:

–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
   • AutoConfigURL
   • ProxyOverride
   • ProxyServer



?????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
   • "WarnOnIntranet"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\0]
   • "1409"=dword:0x00000003

[HKCU\Software\Microsoft\Internet Explorer\PhishingFilter]
   • "ShownServiceDownBalloon"=dword:0x00000000

[HKCU\Software\Microsoft\Internet Explorer\Recovery]
   • "ClearBrowsingHistoryOnExit"=dword:0x00000000



?????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\1]
   ??:
   • "1406"=dword:0x00000000
   • "1409"=dword:0x00000003
   • "1609"=dword:0x00000000

[HKCU\Software\Microsoft\Internet Explorer\PhishingFilter]
   ??:
   • "EnabledV8"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\0]
   ??:
   • "1406"=dword:0x00000000
   • "1609"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\2]
   ??:
   • "1406"=dword:0x00000000
   • "1409"=dword:0x00000003
   • "1609"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Lockdown_Zones\4]
   ??:
   • "1406"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Lockdown_Zones\1]
   ??:
   • "1406"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Lockdown_Zones\2]
   ??:
   • "1406"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Lockdown_Zones\3]
   ??:
   • "1406"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
   ??:
   • "EnableHttp1_1"=dword:0x00000001
   • "MigrateProxy"=dword:0x00000001
   • "ProxyEnable"=dword:0x00000000
   • "ProxyHttp1.1"=dword:0x00000001
   • "WarnOnPost"=hex:00,00,00,00
   • "WarnOnPostRedirect"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\3]
   ??:
   • "1406"=dword:0x00000000
   • "1409"=dword:0x00000003
   • "1609"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\4]
   ??:
   • "1406"=dword:0x00000000
   • "1409"=dword:0x00000003
   • "1609"=dword:0x00000000

 ???? ?????:
??????:
   • 94.228.22**********.67:9933 (TCP)
   • http://my-trust.net:81/var/**********?guid=%???%&ver=%??%&stat=%???%&ie=%???%&os=%???%&ut=%???%&cpu=%??%&ccrc=%???%&md5=%???%



???????????:
    • ?????
    • CPU ??
     ????
     ????????
     ???
     Windows ??????

 ?? ??????????:

?????????:
   • Mozilla Firefox
   • Internet Explorer

 ???? ???????????????????

    ???:
   • explorer.exe



???????????????????

???????????


 ??  ??????????? Internet ??:
   • http://www.microsoft.com


Mutex:
?????? Mutex:
   • __window__
   • __SPYNET_REPALREADYSENDED__

 ?????? ???????:
???????????????????????????????

Açıklamayı yerleştiren Petre Galan tarihinde 12 Nisan 2011 Salı
Açıklamayı güncelleyen: Petre Galan tarihinde 14 Nisan 2011 Perşembe

Geri . . . .
https:// Bu pencere güvenlik amacıyla şifrelenmiştir.