-

  • (45)
  • / (26)
  • (13)
  • (9)
  • (9)

 - e-mail

 

 -

   _

 -

 LiveInternet.ru:
: 28.02.2006
: 182
: 1228
: 1017

:


Win32:Padobot-I

, 30 2006 . 13:29 +
-Driada- lsass.exe
- Win32:Padobot-I

Worm.Win32.Padobot


-. Korgo. , LSASS Microsoft Windows. Microsoft Security Bulletin MS04-011.

C++. 10 , UPX.


Windows :

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinUpdate"="%system%\[ ]"
:

[HKLM\SOFTWARE\Microsoft\Wireless]
"Server"="1"
"10", "u2", "uterm5" .

, , LSASS, IP- .


"LSASS service failing", .

TCP 113, 3067 2041 .

IRC-:

brussels.be.eu.undernet.org
caen.fr.eu.undernet.org
flanders.be.eu.undernet.org
gaspode.zanet.org.za
graz.at.eu.undernet.org
irc.kar.net
lia.zanet.net
london.uk.eu.undernet.org
los-angeles.ca.us.undernet.org
moscow-advokat.ru
washington.dc.us.undernet.org
.

n0xwe11

- . 2 .

- , ,
system32 local Settings XXXXXXX[1],XXXXXXX[2] Ip . - ( ,=)))) , , , , , , NTFS System Volume Information, ,
D:\System Volume Information\_restore{D3C983F9-25D3-4481-8284-242F2CD2FB81}\RP53\A0027921.exe [L] Win32:Trojan-gen. {VC} (0)
...
, ntfs fat32 =)
- ))


/


1

: [1] []
 

:
: 

: ( )

:

  URL