-

  • (45)
  • / (26)
  • (13)
  • (9)
  • (9)

 - e-mail

 

 -

   _

 -

 LiveInternet.ru:
: 28.02.2006
: 182
: 1228
: 1017

:

.


: (9), (45), / (26), (13)
(4)

SMS- , . NOD !!!

, 06 2009 . 15:39 +
Alfizik (_) . SMS- , Windows. ! SMS, 300 .
 (653x551, 89Kb)
, )))

, , , ( ), . Win+L, . , . ))

:
1. C:\Documents and Settings\\Local Settings\Temp\922.exe
2. C:\Documents and Settings\\Local Settings\Temporary Internet Files\Content.IE5\HO9NMBT5\aa[1].exe
3. C:\WINDOWS\mfo.exe
44544 MD5 : E7A247CE628D8F455D5E895DBEF71976

:
AntiVir - TR/LockScreen.E.1
Avast - Win32:Malware-gen
AVG - SHeur2.BPQG
Comodo - Heur.Suspicious
DrWeb - Trojan.Winlock.428
Kaspersky - Trojan-Ransom.Win32.SMSer.rk
Panda - Trj/CI.A
Symantec - Trojan.Ransomlock.C
NOD !!! , !


.
LiveCD . LiveCD USB- ( Alkid Live CD iNFR@ CD). portable Dr.Web - Dr.Web CureIt!, . - http://www.freedrweb.com/cureit/
AVZ ( ), . . - http://www.z-oleg.com/secur/avz/download.php

AVZ ( )

( ).
: 13616. . , . ( ---> - , Regedit) :

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ Desktop \ SafeMode
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ System \ ControlSet003 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ SafeBoot

1 ( ). , , Windows, F8. - " ". .


/

:  
(37)

, 19 2007 . 13:13 +
Maranii (_) 1. ?
2. , . , ?


/

(2)

, 15 2007 . 12:00 +
sya-sya (_) ... ... ??????????????????????


(11)

!

, 11 2007 . 20:09 +
_Fire_Lady_ (_)   " " icq ( )
, .
!
2 !
:
11166262
:
274748736
!!!



(13)

?

, 10 2007 . 13:44 +
Bad_Kpoxa (_) ... ???




/

(3)

, 05 2006 . 07:53 +
 (_) ,

Trojan.Encoder.6. , , . , .

readme.txt :
Some files are coded by RSA method.
To buy decoder mail: k47674@mail.ru
with subject: REPLY

, , , -. , , , , , , .

Trojan.Encoder, , , Windows. , (, , ), , , , .

. , 260 , .

, - . .

, Trojan.Encoder.6. , . Dr.Web, .

, .decr. .

2006 . , , . Trojan.Encoder Win32.HLLM.Perf, Email-Worm.Win32.Bagle.fw, New Malware.aj, PSW.Ldpinch.AWF, TSPY_LDPINCH.IT, Trojan-PSW.Win32.LdPinch.hk, Trojan.Pinch.A@m, Trojan.Win32.Inject.z. - , , .

Trojan.Encoder.6, , . . , , .

, .

. , , , . , , , .


(0)

Win32:Padobot-I

, 30 2006 . 13:29 +
-Driada- (_) lsass.exe
- Win32:Padobot-I

Worm.Win32.Padobot


-. Korgo. , LSASS Microsoft Windows. Microsoft Security Bulletin MS04-011.

C++. 10 , UPX.


Windows :

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinUpdate"="%system%\[ ]"
:

[HKLM\SOFTWARE\Microsoft\Wireless]
"Server"="1"
"10", "u2", "uterm5" .

, , LSASS, IP- .


"LSASS service failing", .

TCP 113, 3067 2041 .

IRC-:

brussels.be.eu.undernet.org
caen.fr.eu.undernet.org
flanders.be.eu.undernet.org
gaspode.zanet.org.za
graz.at.eu.undernet.org
irc.kar.net
lia.zanet.net
london.uk.eu.undernet.org
los-angeles.ca.us.undernet.org
moscow-advokat.ru
washington.dc.us.undernet.org
.

n0xwe11

- . 2 .

- , ,
system32 local Settings XXXXXXX[1],XXXXXXX[2] Ip . - ( ,=)))) , , , , , , NTFS System Volume Information, ,
D:\System Volume Information\_restore{D3C983F9-25D3-4481-8284-242F2CD2FB81}\RP53\A0027921.exe [L] Win32:Trojan-gen. {VC} (0)
...
, ntfs fat32 =)
- ))


/

(0)

Trojan-Downloader.Win32.Adload.j

, 02 2006 . 22:20 +
 (_) -. , . Windows (PE EXE-). Visual Basic.

10 25 .



:

c:\drsmart\load1.exe
, , URL:

http://promo.dollarrevenue.com/****le/drsmartload.exe


c:\drsmart\load1.exe
, .



:
c:\drsmart\load1.exe


Trojan-Downloader.Win32.Adload.j ( ) : Generic Downloader.s (McAfee), Trojan.DownLoader.4805 (Doctor Web), Troj/Drsmartl-A (Sophos), TR/Dldr.VB.QR (H+BEDV), Trojan.Downloader.Adload.J (SOFTWIN), Trojan.Downloader.Adload-4 (ClamAV), Adware/Ucmore (Panda), Win32/TrojanDownloader.Adload.J (Eset)

/

(0)

Trojan-Downloader.Win32.IstBar.or

, 02 2006 . 21:25 +
 (_) -. Windows (PE EXE-), UPX. 32 256 . 90 . Visual C++.

www.ysbweb.com.

, .

:


Complete :

ISTdownloadMuTEX .
, :
istsvc.exe (19 456 ).
Trojan-Downloader.Win32.IstBar.gen.
: %Program Files%\ISTsvc\.
istbarcm.dll (91 136 ).
Trojan-Downloader.Win32.IstBar.kg.
: %Program Files%\ISTBar\
optimize.exe (52 104 ).
Trojan-Downloader.Win32.Dyfuca.ei.
: %Program Files%\InternetOptimizer\
<6 >.exe
: bnaoqc.exe (10 240 ).
Trojan-Downloader.Win32.IstBar.ij.
: %WinDir%\
saferscan.exe (91 136 )
: %Program Files%\SaferScan\
SAcc.exe (110 592 )
: %Program Files%\SurfAccuracy\
SAccU.exe (16 384 )
: %Program Files%\SurfAccuracy\
<8 >.exe
: fowkxcmy.exe (52 104 ).
: %WinDir%\
:

http://www.ysbweb.com
http://www.surfaccuracy.com
http://www.tbcode.com
http://www.slotch.com
:
[HKCU\Software\SaferScan]
"account_id"="0"

[HKCU\Software\IST]
"account_id"="dword:00000000"
"config"=""
"exe_start"="dword:00000001"
"InstallDate"="%date% %time%"
"Recover"="!ZpHc:"

[HKLM\Software\ISTbar]
"installTitle"="SlotchBar"
"barTitle"="SlotchBar"
"serverpath"="http://cache.slotch.com/ist/bars/istbar_cm/"
"urlAfterInstall"="http://www.ysbweb.com/install/welcome.html"
"gUpdate"="0"
"TBRowMode"="dword:00000000"
"xml_istbar.xml"="-206472906"
"imagemap_normal.bmp"="-942107825"
"imagemap_over.bmp"="-942107825"
"showcorrupted"="1"
"updatever"=""
"refreshscope"="1440"
"allowupdate"="0"
"LastCheckTime"="dword:4400260c"
"version.txt"="-186917087"
"UpdateBegin"="0"

[HKLM\Software\ISTbar\Historyfiles]
"C:\Program Files\ISTbar\xml_istbar.xml"="dword:00000001"
"C:\Program Files\ISTbar\imagemap_normal.bmp"="dword:00000001"
"C:\Program Files\ISTbar\imagemap_over.bmp"="dword:00000001"
"C:\Program Files\ISTbar\version.txt"="dword:00000001"

[HKLM\Software\ISTsvc]

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ISTsvc]
"DisplayName"="ISTsvc"
"UninstallString"="C:\PROGRAM FILES\ISTSVC\ISTSVC.EXE /remove"
"NoModify"="dword:00000001"

[HKLM\Software\SAcc]
"accid"="104"
"subaccid"="0"
"Version"="dword:0x480"
"InstallDate"="dword:0x44002606"
"DbgInfo"="|2006-02-25 10:50:22 GetInetFile - CInternetException produced error 12029."
"srecovery"="!ZpH..."
"CfgReloadAttempts"="dword:00000001"

[HKLM\Software\Policies\Microsoft\Windows\Safer]

COM- ISTbar:
[HKCR\IstBar.BarObj]
"CLSID"={FAA356E4-D317-42a6-AB41-A3021C6E7D52}

[HKCR\CLSID\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}]
"ProgId"="ISTbar.BarObj"

:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"IST Service"="C:\Program Files\ISTsvc\istsvc.exe"
"aKCSidSjW"="%WinDir%\bnaoqc.exe"
"SurfAccuracy"="C:\Program Files\SurfAccuracy\SAcc.exe"
"Internet Optimizer"="C:\Program Files\Internet Optimizer\optimize.exe"
"SaferScan"=""C:\Program Files\SaferScan\saferscan.exe" /aid:0"
"ReJf5vH"="%WinDir%\fowkxcmy.exe"
:
http://www.ysbweb.com/install/welcome.html


:
bnaoqc.exe
istsvc.exe
optimize.exe
Sacc.exe
saferscan.exe
:
[HKCU\Software\SaferScan]
[HKCU\Software\IST]
[HKCU\Software\ISTbar]
[HKCU\Software\ISTsvc]
[HKLM\Software\SAcc]
[HKLM\Software\Policies\Microsoft\Windows\Safer]
[HKCR\IstBar.BarObj]
[HKCR\CLSID\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}]
:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"IST Service"
"aKCSidSjW" - ( 9 )
"SurfAccuracy"
"Internet Optimizer"
"SaferScan"
"ReJf5vH" - ( 7 )
:
%Program Files%\ISTBar\
%Program Files%\ISTsvc\
%Program Files%\InternetOptimizer\
%Program Files%\SaferScan\
%Program Files%\SurfAccuracy\
%WinDir%\<8 >.exe
%WinDir%\<6 >.exe

/


 : [1]