, 23 2009 . 10:31
+

. , \"\". , \"\". , . , - .
, Net-Worm.Win32.Kido.bt
, . Windows (PE DLL-). 155 165 . UPX.
Windows : %System%\\
.dll, - .
, Windows. :
[HKLM\\SYSTEM\\CurrentControlSet\\Services\\netsvcs]
:
[HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SvcHost] \"netsvcs\" = \"< > %System%\\.dll\"
HTTP TCP , .
IP , , MS08-067 ( : www.microsoft.com). RPC-, wcscpy_s netapi32.dll, -, . .
, , . : http://icomservice.ucoz.ru/publ/2-1-0-29
:
kaspersky
win32
kido
net-worm