. |
, :)
, . , , .. :)
Backdoor.Subot. .
: 12 2004
Backdoor.Subot - , Serv-U FTP IRC .
: 196,096 5,358
: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Backdoor.Subot .dll , Serv-U FTP . serv-u.ini :
[EXTERNAL]
EventHookDll1 = sub0t.dll
ClientCheckDLL1 = sub0t.dll
Backdoor.Subot , :
1. IRC . Serv-U FTP .
2. , IRC , sub0t.ini. .
sub0t.ini.
[BOT]
BotActive = 1
Log = 0
IrcServer = irc.neurozone.ath.cx
Channel = #passion
ChannelKey = 94230
IrcPort = 6667
IrcPassword = 94230
Nick = oursin
: Symantec Security Response
Candid Wueest
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.subot.html
Trojan.Conycspa.
: 13 2004
Trojan.Conycspa - , adware, dialers, spamming Trojan . .
: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
:
1. %Windir%inetgservices.exe.
* %Windir% , Windows. C:Windows C:Winnt.
2. :
"xp_system" = "%Windir%inetgservices.exe"
:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
Windows.
3. :
"xp_system" = "%Windir%inetgservices.exe"
:
HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun
Windows.
4. :
"run" = "%Windir%inetgservices.exe"
:
HKEY_CURRENT_USERSOFTWAREMicrosoftWindows NTCurrentVersionWindows
Windows.
5. :
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{5321E378-FFAD-4999-8C62-03CA8155F0B3}
6. %Windir%system.ini .
load=%Windir%inetgservices.exe
7. Windows Address Book. E-mail :
From: girl@worldgirls.com
Subject: Re: hot pics
Body:
Hello, mate!
Just found this hot teen girl, if you want you can see here:
[Link to the domain nude-teens-bodies.com]
sweet body and hot tits!
reply me what you think about
e-mail conyc.com
8. conyc.com .
9. %System%q123.vbs
10. %System%sm.exe
11. commands.ini conyc.com. conyc.com, :
Trojan.Adclicker.A
Adware.CWSConyc
Dialer.Webview
Dialer.Thehun
Adware.CWSConyc
Trojan.Conycspa
: Symantec Security Response
Kaoru Hayashi
http://securityresponse.symantec.com/avcenter/venc/data/trojan.conycspa.html
Backdoor.Ranky.N . .
: 13 2004
Backdoor.Ranky.N - , .
: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Backdoor.Ranky.N, :
1. :
"MSSGisg" = "[file path to back door]"
:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
Windows.
2. TCP 10100
168.251.73.0
45.190.80.3
37.123.146.2
165.148.65.20
237.208.143.5
38.37.87.87
113.212.18.80
78.22.234.0
69.28.235.18
3. .
: Symantec Security Response
John Canavan
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.n.html
W32.Qeds@mm.
: 13 2004
W32.Qeds@mm - , e-mail .
.
: 14,848
: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
W32.Qeds@mm :
1. %System%Inetdbs.exe.
2. :
"Inet DataBase" = "%System%Inetdbs.exe"
:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
Windows.
3. :
tenship.com
freehost23.websamba.com
4. Backdoor.PowerSpider.B .
5. e-mail .
E-mail :
From: ( )
Subject: ( )
Message: ( )
Attachment: [ ].zip
: Symantec Security Response
Kaoru Hayashi
http://securityresponse.symantec.com/avcenter/venc/data/w32.qeds@mm.html