(Conficker, Downadup, Win32.HLLW.Autorunner.5555, Win32.HLLW.Shadow.based ) , Kido , , MS08-67 MS Windows. «» , ( ) («»): Kido autorun.inf, «» - , . , , , . Kido . F-Secure - . , - . , « - . , », — F-Secure - (Patrik Runald).
, . Windows (PE DLL-). 165840 . UPX.
HTTP TCP , .
IP , , MS08-067 «» ( :
www.microsoft.com). RPC-, wcscpy_s netapi32.dll, -, . .
"" : ; ; Documents and Settings; .
:
, :
1 :
http://www.kaspersky.ru/support/wks6mp3/error?qid=208636215
http://data2.kaspersky-labs.com:8080/special/KidoKiller_v3.1.zip
2 « »:
http://news.drweb.com/show/?i=204&c=5&p=0
ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe
3 Windows XP2 Windows XP3:
MS08-067 (
http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx);
MS08-068 (
http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx);
MS09-001 (
http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx);
( ) "" .