, 30 2006 . 13:29
+
-Driada-
lsass.exe
- Win32:Padobot-I
Worm.Win32.Padobot
-. Korgo. , LSASS Microsoft Windows. Microsoft Security Bulletin MS04-011.
C++. 10 , UPX.
Windows :
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinUpdate"="%system%\[ ]"
:
[HKLM\SOFTWARE\Microsoft\Wireless]
"Server"="1"
"10", "u2", "uterm5" .
, , LSASS, IP- .
"LSASS service failing", .
TCP 113, 3067 2041 .
IRC-:
brussels.be.eu.undernet.org
caen.fr.eu.undernet.org
flanders.be.eu.undernet.org
gaspode.zanet.org.za
graz.at.eu.undernet.org
irc.kar.net
lia.zanet.net
london.uk.eu.undernet.org
los-angeles.ca.us.undernet.org
moscow-advokat.ru
washington.dc.us.undernet.org
.
n0xwe11
- . 2 .
- , ,
system32 local Settings XXXXXXX[1],XXXXXXX[2] Ip . - ( ,=)))) , , , , , , NTFS System Volume Information, ,
D:\System Volume Information\_restore{D3C983F9-25D3-4481-8284-242F2CD2FB81}\RP53\A0027921.exe [L] Win32:Trojan-gen. {VC} (0)
...
, ntfs fat32 =)
- ))
1