Warning: ob_start() [ref.outcontrol]: output handler 'ob_gzhandler' conflicts with 'zlib output compression' in /home/antispyware/public_html/wp-includes/functions.php on line 336
2007 Marec · Spyware, malware a v?rusy - AntiSpyware.sk

Archive for Marec, 2007

Win32/Fujacks.S

Pondelok, Marec 19th, 2007

Aliasy:
Worm.Win32.Fujack.g (Kaspersky), W32/Fujacks.l (McAfee), W32.Fujacks.E (Symantec)

Typ infiltr??cie:
v?rus

VeĞkos??:
pribli?ne 74 kB

Zasiahnut? platformy:
Microsoft Windows

Verzia v?rusovej datab??zy:
1979

Kr??tky popis:
Win32/Fujacks.S je v?rus, ktor?? svoje telo prip??ja pred k??d hostiteĞa. Dok???e sa ???ri?? zdieĞan??mi priečinkami a na vymeniteĞn??ch m?di??ch.

In??tal??cia
Pri spusten? infikovan?ho s??boru sa p?vodn?? program zap???e do dočasn?ho s??boru a spust?. V?rus sa skop?ruje na nasleduj??ce miesto:

%windir%\drivers\spoclsv.exe
Sp??????anie pri ka?dom ??tarte syst?mu […]

Win32/Sality.NAJ

Pondelok, Marec 19th, 2007

Aliasy:
Virus.Win32.Sality.q (Kaspersky), W32/Sality.x (McAfee), W32.Sality.U (Symantec)

Typ infiltr??cie:
v?rus

VeĞkos??:
20480 B

Zasiahnut? platformy:
Microsoft Windows

Verzia v?rusovej datab??zy:
1.1694

Kr??tky popis:
Win32/Sality.NAJ je polymorfn?? s??borov?? v?rus. Dok???e sa ???ri?? zdieĞan??mi priečinkami.

In??tal??cia
Do priečinku %windir% zap???e nasleduj??ci s??bor:

vcmgcd32.dll
Kni?nicu nač?ta a vlo?? do v??etk??ch be?iacich procesov.
V datab??ze Registry nastav? nasleduj??cu polo?ku:[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
“GlobalUserOffline” = 0

V?rus modifikuje nasleduj??ci s??bor:

%windir%\system.ini

V?rusov?? aktualiz??cia pre NOD32 2126 (20070319)

Pondelok, Marec 19th, 2007

W97M/TrojanDropper.Agent.L, Win32/Agent.QT, Win32/DiskFill.I, Win32/DNSChanger.HK (2), Win32/Locksky.BU (2), Win32/Nuwar.gen, Win32/PSW.Agent.NCC (2), Win32/PSW.Delf.UX, Win32/PSW.LdPinch.BOB, Win32/PSW.LdPinch.BRA (2), Win32/PSW.QQShou.NAU (2), Win32/Sality.T, Win32/Small.FB (2), Win32/Spy.Banbra.NED, Win32/Spy.Banker.ANV, Win32/Spy.Banker.AWA, Win32/Spy.Banker.CHC, Win32/Spy.Banker.NTB, Win32/TrojanClicker.Agent.NBL (3), Win32/TrojanClicker.VB.QP, Win32/TrojanDownloader.Banload.BXU (2), Win32/TrojanDownloader.Banload.NNP (2), Win32/TrojanDownloader.Delf.ACC, Win32/TrojanDownloader.Delf.NHL, Win32/TrojanDownloader.Delf.NJH, Win32/TrojanDownloader.Small.EEJ, Win32/TrojanDownloader.Zlob.ATP (10), WM/Twno

TOPlist