-

 -

 - e-mail

 

 -

   Master_Snake

 -

 LiveInternet.ru:
: 07.08.2003
: 188
: 609
: 716

:


.

, 18 2005 . 16:33 +
Bonitka

, :)


, . , , .. :)



Backdoor.Subot. .


: 12 2004

Backdoor.Subot - , Serv-U FTP IRC .

: 196,096 5,358

: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Backdoor.Subot .dll , Serv-U FTP . serv-u.ini :

[EXTERNAL]

EventHookDll1 = sub0t.dll
ClientCheckDLL1 = sub0t.dll

Backdoor.Subot , :

1. IRC . Serv-U FTP .

2. , IRC , sub0t.ini. .

sub0t.ini.

[BOT]

BotActive = 1
Log = 0
IrcServer = irc.neurozone.ath.cx
Channel = #passion
ChannelKey = 94230
IrcPort = 6667
IrcPassword = 94230
Nick = oursin

: Symantec Security Response

Candid Wueest
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.subot.html




Trojan.Conycspa.


: 13 2004

Trojan.Conycspa - , adware, dialers, spamming Trojan . .

: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

:

1. %Windir%inetgservices.exe.
* %Windir% , Windows. C:Windows C:Winnt.

2. :

"xp_system" = "%Windir%inetgservices.exe"

:

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun

Windows.

3. :

"xp_system" = "%Windir%inetgservices.exe"

:

HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun

Windows.

4. :

"run" = "%Windir%inetgservices.exe"

:

HKEY_CURRENT_USERSOFTWAREMicrosoftWindows NTCurrentVersionWindows

Windows.

5. :

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{5321E378-FFAD-4999-8C62-03CA8155F0B3}

6. %Windir%system.ini .

load=%Windir%inetgservices.exe

7. Windows Address Book. E-mail :

From: girl@worldgirls.com

Subject: Re: hot pics

Body:
Hello, mate!
Just found this hot teen girl, if you want you can see here:
[Link to the domain nude-teens-bodies.com]
sweet body and hot tits!
reply me what you think about

e-mail conyc.com

8. conyc.com .

9. %System%q123.vbs

10. %System%sm.exe

11. commands.ini conyc.com. conyc.com, :

Trojan.Adclicker.A
Adware.CWSConyc
Dialer.Webview
Dialer.Thehun
Adware.CWSConyc
Trojan.Conycspa

: Symantec Security Response

Kaoru Hayashi
http://securityresponse.symantec.com/avcenter/venc/data/trojan.conycspa.html





Backdoor.Ranky.N . .


: 13 2004

Backdoor.Ranky.N - , .

: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


Backdoor.Ranky.N, :

1. :

"MSSGisg" = "[file path to back door]"

:

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun

Windows.

2. TCP 10100

168.251.73.0
45.190.80.3
37.123.146.2
165.148.65.20
237.208.143.5
38.37.87.87
113.212.18.80
78.22.234.0
69.28.235.18

3. .

: Symantec Security Response

John Canavan
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.ranky.n.html




W32.Qeds@mm.


: 13 2004

W32.Qeds@mm - , e-mail .

.

: 14,848

: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

W32.Qeds@mm :

1. %System%Inetdbs.exe.

2. :

"Inet DataBase" = "%System%Inetdbs.exe"

:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun

Windows.

3. :

tenship.com
freehost23.websamba.com

4. Backdoor.PowerSpider.B .

5. e-mail .

E-mail :

From: ( )

Subject: ( )

Message: ( )

Attachment: [ ].zip


: Symantec Security Response

Kaoru Hayashi
http://securityresponse.symantec.com/avcenter/venc/data/w32.qeds@mm.html



: [1] []
 

:
: 

: ( )

:

  URL