,
, :
Hybris, MTX, Wscript.KakWorm, NetMonitor,GirlFriend, Acid Shiver, Deep Throat 1.0, Deep Throat 2.0
,
Hybris
. . WSOCK32.DLL, (). DLL- "" .
"connect", "recv", "send", , .
,
http://pleiku.vietmedia.com/bye/, . Win32-.
: AVP.
MTX
. , , -backdoor. -exe "Entry Point Obscuring". , . , , , . , . , . , .
-. WSOCK32.DLL , . Web-. , -backdoor , , : - . Win32-.
: AVP.
WScript.KakWorm
Java Script, MS Outlook Express.
HTML-. , , JavaScript. - , .. HTML- (, ..), - . Windows , . HTA. KAK.HTM html- .
: HTA- (HTML Application) - , MS Internet Explorer 5.0. HTA- HTML- -, Internet Explorer, . ( ), -.
, MS Outlook Express, - " ". "KAK.HTM".
, HTML ( MS Outlook Express), , . Outlook Express "KAK.HTM", .. - , , . , RTF "Plain text", ( ). , - , .
.
, , . . , (, , ).
, AVP Script Checker.
. Internet Explorer 5.0. Microsoft , :
http://support.microsoft.com/support/ kb/articles/Q240/3/08.ASP.
NetMonitor
:
NetMonitor.exe -
NetSpy.exe -
. backdoor.
GirlFriend
GirlFriend() , . , - PC : , "" , (, login ..); , "" .
: ("system" messages) ; ; ( BMP); ; ; ; GF Client BOSSKEY=F12; ; ( ); ( CD-Rom) GF .
Acid Shiver
Acid Shiver - , , , .
:
ACiD Setup.exe - ,
ACiD Shivers.exe - .
: .
: (telnet).
Deep Throat 1.0
.
: , : Windows, , , HKEY_LOCAL_MACHINE
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemDLL32.
Deep Throat 2.0
- . systray.exe Windows HKEY_LOCAL_MACHINE
Software\Microsoft\Windows\CurrentVersion\Run Systemtray SystTray.Exe [WinPath]\systray.exe, WinPath Windows ( c:\Windows\)
: RealNeo