<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="hr">
	<id>https://croatianschoolsydney.com/index.php?action=history&amp;feed=atom&amp;title=VBS.Runauto.F</id>
	<title>VBS.Runauto.F - Povijest promjena</title>
	<link rel="self" type="application/atom+xml" href="https://croatianschoolsydney.com/index.php?action=history&amp;feed=atom&amp;title=VBS.Runauto.F"/>
	<link rel="alternate" type="text/html" href="https://croatianschoolsydney.com/index.php?title=VBS.Runauto.F&amp;action=history"/>
	<updated>2026-06-16T14:07:13Z</updated>
	<subtitle>Povijest promjena ove stranice na wikiju</subtitle>
	<generator>MediaWiki 1.36.2</generator>
	<entry>
		<id>https://croatianschoolsydney.com/index.php?title=VBS.Runauto.F&amp;diff=118358&amp;oldid=prev</id>
		<title>WikiSysop: Bot: Automatski unos stranica</title>
		<link rel="alternate" type="text/html" href="https://croatianschoolsydney.com/index.php?title=VBS.Runauto.F&amp;diff=118358&amp;oldid=prev"/>
		<updated>2021-09-13T22:32:52Z</updated>

		<summary type="html">&lt;p&gt;Bot: Automatski unos stranica&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Nova stranica&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;!--'''VBS.Runauto.F'''--&amp;gt;'''VBS.Runauto.F''' je [[računalni crv]] otkriven [[19. svibnja]] [[2009.]] godine. Zaražava računala koja rade pod operativnim sustavom Microsoft Windows ([[Windows 98]], [[Windows 95]], [[Windows XP]], [[Windows Me]], [[Windows Vista]], [[Windows NT]], [[Windows Server 2003]], [[Windows 2000]]).&lt;br /&gt;
&lt;br /&gt;
== Djelovanje ==&lt;br /&gt;
Crv se kopira kao datoteke %System%\winjpg.jpg i %SystemDrive%\winfile.jpg. Također pravi datoteku %SystemDrive%\autorun.inf koja se aktivira kad korisnik pristupi %SystemDrive%-u te onda ubacuje komponentu [[backdoor]]a u datoteku %System%\winxp.exe. &lt;br /&gt;
&lt;br /&gt;
U [[Windows Registry]] VBS.Runauto.F dodaje vrijednost &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&amp;quot;CTFMON&amp;quot; = &amp;quot;%System%\wscript.exe /E:vbs %System%\winjpg.jpg&amp;quot;&amp;lt;/code&amp;gt; kako bi se mogao pokretati tijekom sljedećih podizanja sustava, te &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&amp;quot;regdiit&amp;quot; = &amp;quot;%System%\winxp.exe&amp;quot;&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&amp;quot;abu salem&amp;quot; = &amp;quot;43 00 3A 00 5C 00 57 00 49 00 4E 00 44 00 4F 00 57 00 53 00 5C 00 73 00 79 00 73 00 74 00 65 00 6D 00 33 00 32 00 5C 00 77 00 69 00 6E 00 78 00 70 00 2E 00 65 00 78 00 65 00&amp;lt;/code&amp;gt; za pokretanje backdora, također za vrijeme sljedećih podizanja sustava.&lt;br /&gt;
&lt;br /&gt;
Crv mijenja vrijednosti &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwinxp.exe\&amp;quot;Debugger&amp;quot; = &amp;quot;%System%\winxp.exe&amp;quot;&amp;lt;/code&amp;gt;,&amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSConfig.exe\&amp;quot;Debugger&amp;quot; = &amp;quot;%System%\wscript.exe /E:vbs %System%\winjpg.jpg&amp;quot;&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe\&amp;quot;Debugger&amp;quot; = &amp;quot;\winxp.exe&amp;quot;&amp;lt;/code&amp;gt;,&amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe\&amp;quot;Debugger&amp;quot; = &amp;quot;%System%\wscript.exe /E:vbs %System%\winjpg.jpg&amp;quot;&amp;lt;/code&amp;gt; kako bi se on sam pokrenuo umjesto traženih aplikacija.&lt;br /&gt;
&lt;br /&gt;
VBS.Runauto.F umanjuje [[računalna sigurnost|sigurnost računala]] mijenjanjem vrijednosti &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\&amp;quot;Enabled&amp;quot; = &amp;quot;1&amp;quot;&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\&amp;quot;AntiVirusOverride&amp;quot; = &amp;quot;1&amp;quot;&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\&amp;quot;CheckedValue&amp;quot; = &amp;quot;1&amp;quot;&amp;lt;/code&amp;gt;,&lt;br /&gt;
&amp;lt;code&amp;gt;HKEY_USERS\S-1-5-21-1110976373-127614085-1323839693-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\&amp;quot;NoDriveTypeAutoRun&amp;quot; = &amp;quot;0&amp;quot;&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Crv se širi tako što se kopira na sve izmjenjive diskove (''removable drives'') kao datoteka %DriveLetter%\winfile.jpg te pravi datoteku %DriveLetter%\autorun.inf koja se aktivira kad korisnik pristupi izmjenjivim driverima.&lt;br /&gt;
&lt;br /&gt;
== Izvor ==&lt;br /&gt;
* [http://www.symantec.com/security_response/writeup.jsp?docid=2009-051918-1008-99&amp;amp;tabid=2 Symantec.com]&lt;br /&gt;
&lt;br /&gt;
[[Kategorija:Računalni crvi]]&lt;/div&gt;</summary>
		<author><name>WikiSysop</name></author>
	</entry>
</feed>