, 20 2009 . 17:54
+
, .
Intrusion.Win.NETAPI.buffer-overflow.exploit.
Net-Worm.Win32.Kido.
( ) autorun.inf RECYCLED\{SID<....>}\RANDOM_NAME.vmx
dll- , , c:\windows\system32\zorizr.dll
- , , knqdgsm.
445 , Windows MS08-067
( ):
http://www.getmyip.org
http://getmyip.co.uk
http://www.whatsmyipaddress.com
http://www.whatismyip.org
http://checkip.
http://schemas.xmlsoap.org/soap/envelope/
http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/
http://schemas.xmlsoap.org/soap/encoding/
http://trafficconverter.biz/4vir/antispyware/loadadv.exe
http://trafficconverter.biz
http://www.maxmind.com/download/geoip/database/GeoIP.dat.gz
, MS08-067. :
http://www.microsoft.com/technet/security/...n/MS08-067.mspx
. , Kaspersky Administration Kit.
:
klwk.zip ,
run_klwk.bat
klwk.zip .
Administration Kit klwk.com.
:
/path %WINDIR%\system32
.
, . klwk /y
/y /path %WINDIR%\system32
: Kaspersky.ru
-
, 09 2008 . 08:52
+
1- . , , "" . , . , , . ( - ), , , .
...
, 06 2008 . 23:33
+
, , , . , : , , , .
. , , .
? 1791 . , : . . , , , . . , , .
...
, 25 2008 . 10:55
+
? ? "", "", , , , , , ... . , 150 ...
, , , ? ?
... , , , .
- (, , ..) , ?
?"
...