Pix
OK, so a while back I got pwned with sasser virus (infected lsass), I patched, AVG found it and quarantined it. But, then there are these damn IRC/Backdoor.SDBot.[1-9].[a-z] viri were found. Before the connections (see pix) were established, status were syn_sent. WTF? Delpart? Format? Shoot comp? For some reasons, I can't trace these damn routes, can some one do that for me? :cookie;
OK, so a while back I got pwned with sasser virus (infected lsass), I patched, AVG found it and quarantined it. But, then there are these damn IRC/Backdoor.SDBot.[1-9].[a-z] viri were found. Before the connections (see pix) were established, status were syn_sent. WTF? Delpart? Format? Shoot comp? For some reasons, I can't trace these damn routes, can some one do that for me? :cookie;