Need help? Ask the community or hire an expert.
Go to Avira Answers
??:TR/Reveton.A.432
????:13/12/2012
??:?????
????:?
????????????????
??/????????
?? / ????????
????:213.016 ??
MD5 ???:f91cc13a0D484e3b9ce1d244edb52035
VDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe
IVDF ??:7.11.53.216 - 13 Aralık 2012 Perşembe

 ???? ????:
   • ???????


??:
   •  Mcafee: Generic.evx!bu
   •  Kaspersky: HEUR:Trojan.Win32.Generic
   •  Bitdefender: Trojan.Reveton.E
     Microsoft: Trojan:Win32/Reveton.A
   •  Grisoft: Generic27.ATPP
   •  Eset: a variant of Win32/Kryptik.ACQF trojan
     GData: Trojan.Reveton.E
     DrWeb: Trojan.Siggen3.52657


??/????:
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7


???:
    ???????????????????????
   • ????
   • ????
   • ?????

 ?? ??????:

?????:
   • %HOMEPATH%\Start Menu\Programs\Startup\sample.exe.lnk

 ??? ?????????????????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\0]
   • "2500"=dword:00000003

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\1]
   • "2500"=dword:00000003

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\2]
   • "2500"=dword:00000003

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\3]
   • "2500"=dword:00000003

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\4]
   • "2500"=dword:00000003

[HKCU\Software\Microsoft\Internet Explorer\Main]
   • "NoProtectedModeBanner"=dword:00000001



?????????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
   • "DisableTaskMgr"=dword:00000001



?????????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\0]
   ??:
   • "1609"=dword:00000001
   ??:
   • "1609"=dword:00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\1]
   ??:
   • "1609"=dword:00000001
   ??:
   • "1609"=dword:00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\2]
   ??:
   • "1609"=dword:00000001
   ??:
   • "1609"=dword:00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\3]
   ??:
   • "1609"=dword:00000001
   ??:
   • "1609"=dword:00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
   Zones\4]
   ??:
   • "1609"=dword:00000001
   ??:
   • "1609"=dword:00000000

 ?? ?????:
??????????????? DNS ???:
   • http://91.217.**********.**********/**********.rar


?????? (Event Handler):
??????????:
   • StartMenuForceRefresh
   • ImageList_ReplaceIcon
   • WaitForSingleObject
   • DisableShowAtLogon
   • StartupHasBeenRun
   • GetAsyncKeyState
   • TrackMouseEvent
   • TaskbarCreated

Açıklamayı yerleştiren Wensin Lee tarihinde 16 Mart 2012 Cuma
Açıklamayı güncelleyen: Wensin Lee tarihinde 19 Mart 2012 Pazartesi

Geri . . . .
https:// Bu pencere güvenlik amacıyla şifrelenmiştir.