, 07 2009 . 01:29
+
Kido. 9 000 000 PC!
(Conficker, Downadup, Win32.HLLW.Autorunner.5555, Win32.HLLW.Shadow.based ) , Kido , , MS08-67 MS Windows. , ( ) (): Kido autorun.inf, - , . , , , . Kido . F-Secure - . , - . , - . , , F-Secure - (Patrik Runald).
, . Windows (PE DLL-). 165840 . UPX.
HTTP TCP , .
IP , , MS08-067 ( :
www.microsoft.com). RPC-, wcscpy_s netapi32.dll, -, . .
"" : ; ; Documents and Settings; .
:
, :
1 :
http://www.kaspersky.ru/support/wks6mp3/error?qid=208636215
http://data2.kaspersky-labs.com:8080/special/KidoKiller_v3.1.zip
2 :
http://news.drweb.com/show/?i=204&c=5&p=0
ftp://ftp.drweb.com/pub/drweb/cureit/launch.exe
3 Windows XP2 Windows XP3:
MS08-067 (
http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx);
MS08-068 (
http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx);
MS09-001 (
http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx);
( ) "" .
Microsoft Windows XP2/XP3 RUS - Dr.Web CureIt! 01.02.2009 KidoKiller v.3.1
ReUpRus.rar OpenFile.ru
: