-

 -

  • - - - -
  •    : - , . , "
  •     - - . : Internet Explorer 6, Fire Fox 1.5, Opera 9.5, Safari 3.1.1 JavaScript.

 -

   Gafarov-91

 -

( : 3) For_the_diary _ __
( : 2) - _

 -

 LiveInternet.ru:
: 02.07.2009
:
:
: 1314

:

(1)

,

, 21 2009 . 15:24 +
,


, :

Hybris, MTX, Wscript.KakWorm, NetMonitor,GirlFriend, Acid Shiver, Deep Throat 1.0, Deep Throat 2.0

,

Hybris

. . WSOCK32.DLL, (). DLL- "" .

"connect", "recv", "send", , .

, http://pleiku.vietmedia.com/bye/, . Win32-.

: AVP.

MTX

. , , -backdoor. -exe "Entry Point Obscuring". , . , , , . , . , . , .

-. WSOCK32.DLL , . Web-. , -backdoor , , : - . Win32-.

: AVP.

WScript.KakWorm

Java Script, MS Outlook Express.

HTML-. , , JavaScript. - , .. HTML- (, ..), - . Windows , . HTA. KAK.HTM html- .

: HTA- (HTML Application) - , MS Internet Explorer 5.0. HTA- HTML- -, Internet Explorer, . ( ), -.

, MS Outlook Express, - " ". "KAK.HTM".

, HTML ( MS Outlook Express), , . Outlook Express "KAK.HTM", .. - , , . , RTF "Plain text", ( ). , - , .

.
, , . . , (, , ).

, AVP Script Checker.

. Internet Explorer 5.0. Microsoft , : http://support.microsoft.com/support/ kb/articles/Q240/3/08.ASP.

NetMonitor

:

NetMonitor.exe -
NetSpy.exe -

. backdoor.

GirlFriend

GirlFriend() , . , - PC : , "" , (, login ..); , "" .
: ("system" messages) ; ; ( BMP); ; ; ; GF Client BOSSKEY=F12; ; ( ); ( CD-Rom) GF .

Acid Shiver

Acid Shiver - , , , .
:
ACiD Setup.exe - ,
ACiD Shivers.exe - .
: .
: (telnet).


Deep Throat 1.0

.

: , : Windows, , , HKEY_LOCAL_MACHINE
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemDLL32.

Deep Throat 2.0

- . systray.exe Windows HKEY_LOCAL_MACHINE
Software\Microsoft\Windows\CurrentVersion\Run Systemtray SystTray.Exe [WinPath]\systray.exe, WinPath Windows ( c:\Windows\)



: RealNeo


:  

 : [1]