- , . . . , , , , .
- , ,
: , ;
, . , , . . , .
. . , .
:
- : . , ,
- , , "" ,
.
- , .
- ,
- , . , . , ,
, 90% . . - , - , - : , - . IRC P2P , IRC P2P -. LAN .
|
|
, , :
, . , . Lovesan Sasser. , , , , .
, . : ( , ), - , .
:
.exe Windows. , ( WSOCK32.DLL) ( I-Worm.MTX WSOCK32.DLL , ( send). WSOCK32.DLL , ).
, , , Backdoor ( MyDoom - I-Worm.Mydoom.aa Windows tcp5424.dll, Backdoor- : HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32 {Default} = "%SysDir%\tcp5424.dll")
win.ini system.ini. Email-Worm.Win32.Toil Windows system.ini :
[boot]
shell=Explorer.exe % %
Windows ( Win9x/Me).
Email-Worm.Win32.Atak.h dec25.exe Windows win.ini - dec25.exe run [windows]:
|
|
[windows]
run=%SystemDir%\dec25.exe)
, system.ini [boot] [Drivers]
:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion Run, RunOnce, RunOnceEx, RunServices, RunServicesOnce -
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion Run.
, Email-Worm.Win32.Bagle.ax Windows, : HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Sysformat"="%System%\sysformat.exe
HKEY_CLASSES_ROOT\exefile\shell\open\command
I-Worm.Navidad. :
HKEY_CLASSES_ROOT\exefile\shell\open\command {Default} = %SystemDir%\wintask.exe %1 %*)
- wintask.exe. , wintask.exe , .exe.
HKEY_CLASSES_ROOT\txtfile\shell\open\command
Email-Worm.Win32.LovGate.ad HKCR\txtfile\shell\open\command {default}="Update_OB.exe %1", , .
, :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOW\boot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinLogon
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug