???????
????????
????????? ?????????????
??? ??? ??????????
???? ??? ???????? ?????
???????? ???????
??????
????? ??? Grand Theft Auto: Vice City
????? ??? Winamp'a
????
??????
??????? ?????
??????
?????????????? ??????? ?????????
|
Email-Worm.Win32.Bagle.bo
?????????? ?????? ???? ????? ?????? ???? ???? ? ?? ????? ???? ??????, ???? ???????? ???????????? ????? ? ??? ????????. ???? ????? ??????????? ? ?????? ? ???? ?????? ? ZIP-????? ???????? ????? 17 ??.
?????? ??????????? ????????? ??????? ?? ?????????? ??????????? (??? ??? ?????????? ??????????? ??????????? ??? ?????? Email-Worm.Win32.Bagle.bo).
??? ??????????? ????? ??????? ? ????????? ???????? Windows ????? ? ??????? winshost.exe ? wiwshost.exe:
%System%\winshost.exe
%System%\wiwshost.exe
????? ????? ???????????? ???? ? ????? ??????????? ?????????? ???????:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"winshost.exe"="%System%\winshost.exe"
???????????????
?????? ??????????? ????? ?????????????? ?? ????????????. ??? ???? ????????? ?? ????-????????.
????? ???????? ? ???? ??????? ?????? URL, ??????? ??????????? ?? ??????? ??????. ? ?????? ???? ?? ??????-?? ?? ???? ??????? ????? ???????? ????, ?? ????? ???????? ? ??????? ? ???????. ???????? ?????????? ????????? ????????? ???????? ????? ?? ????? ????? ??? ?? ????????????? ? ??????? ????? ?????? ??????????? ?????????.
????????
????? ???????? ???? %System%\drivers\etc\hosts ? ?????????? ? ???? ??????????? ???? ?????, ???????? ?????? ? ????????????? ? ??? ?????? ???????????.
? ????? ???????????? ??????? ??????????? ? ?????????? ??????? ????? ??????? ????????? ????? ???????:
[HKLM\SOFTWARE\Agnitum]
[HKLM\SOFTWARE\KasperskyLab]
[HKLM\SOFTWARE\McAfee]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\APVXDWIN]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\avg7_cc]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\avg7_emc]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ccApp]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KAV50]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\McAfee Guardian]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\McAfee.InstantUpdate.Monitor]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NAV CfgWiz]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SSC_UserPrompt]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Symantec NetDriver Monitor]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Zone Labs Client]
[HKLM\SOFTWARE\Panda Software]
[HKLM\SOFTWARE\Symantec]
[HKLM\SOFTWARE\Zone Labs]
????? ????????? ?? ?????? ??????? ????????? ????????, ??????????????? ????????? ???????????? ?????????? ? ?????????? ???????.
|
|
|