Need help? Ask the community or hire an expert.
Go to Avira Answers
??:BDS/IRCBot.EW.16
????:13/12/2012
??:???????
????:?
????????????????
??/????????
?? / ?????????
????:?
????:83.456 ??
MD5 ???:d9b45ea0b23efa5acf702f10992c0ecb
VDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe
IVDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe

 ???? ??:
   •  Kaspersky: Backdoor.Win32.Rosex.k
   •  F-Secure: Backdoor.Win32.Rosex.k
   •  Bitdefender: Trojan.Generic.KDV.138188
     GData: Trojan.Generic.KDV.138188
     DrWeb: Trojan.DownLoader2.12743


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???:
   • ?????
   • ??????
   • ????????
   • ?????

 ?? ???????????:
   • %HOME%\Application Data\Microsoft\exploiter.exe

 ??? ????????????????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "Microsoft Windows Hosting Service Login"="%HOME%\Application Data\Microsoft\exploiter.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "Microsoft Windows Hosting Service Login"="%HOME%\Application Data\Microsoft\exploiter.exe"



???????????? Windows XP ???:

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile\AuthorizedApplications\List]
   • "Microsoft Windows Hosting Service Login"="%HOME%\Application
      Data\Microsoft\exploiter.exe"

 IRC ????????????????????? IRC ???:

???: gangbang.low**********.org
??: 25343
??: #!zer0
??: [USA|XP|%?????%]

 ?? Mutex:
?????? Mutex:
   • 6jtgkfgjuhiggggkjkfh

 ?????? ????:
????????? MS Visual C++ ????


???????:
???????????????????????????????

Açıklamayı yerleştiren Petre Galan tarihinde 3 Haziran 2011 Cuma
Açıklamayı güncelleyen: Andrei Ivanes tarihinde 10 Haziran 2011 Cuma

Geri . . . .
https:// Bu pencere güvenlik amacıyla şifrelenmiştir.