Êîìïüþòåðíûé ôîðóì OSzone.net  

Êîìïüþòåðíûé ôîðóì OSzone.net (http://forum.oszone.net/index.php)
-   Ëå÷åíèå ñèñòåì îò âðåäîíîñíûõ ïðîãðàìì (http://forum.oszone.net/forumdisplay.php?f=87)
-   -   âèðóñû (http://forum.oszone.net/showthread.php?t=198664)

Nimur 05-02-2011 16:53 1605254

âèðóñû
 
Âëîæåíèé: 1
Ïîìîãèòå ïîæàëóéñòà. Îòêëþ÷àåòñÿ èíòåðíåò ïîñëå êîðîòêîãî âðåìåíè, ïðè ÷åì ñîïðîâîæäàåòñÿ ýòî ñìåíîé òåìû íà ñòàíäàðíóþ 95 è îáðàòíî.. Çíà÷êè ïîäêëþ÷åíèÿ íå ðåàãèðóþò, ïîìîãàåò ëèøü ïåðåçàãðóçêà.. Àíòèâèðóñû íè÷åãî íå íàõîäÿò.
Çàëåç â C:\WINDOWS\system32\ è îáíàðóæèë âîò ýòè ôàéëû...

goredey 05-02-2011 16:57 1605255

Nimur, âûïîëíèòå ïðàâèëà

Nimur 05-02-2011 17:01 1605265

ëîã

goredey 05-02-2011 17:39 1605290

Nimur,
Öèòàòà:

Öèòàòà Nimur
ëîã »

Ãäå?

Nimur 05-02-2011 18:02 1605304

ïðîñòèòå, íåâûëîæèëñÿ..
http://ifolder.ru/21726346
http://ifolder.ru/21726369

Nimur 05-02-2011 18:11 1605308

âîò.. âûøå ññûëêà íå ïðàâèëüíà.

goredey 05-02-2011 18:13 1605312

Nimur, âû âûëîæèëè êàðàíòèí!! Íóæíî virusinfo_syscure.zip è virusinfo_syscheck.zip !!!!

Nimur 05-02-2011 18:13 1605314

Âëîæåíèé: 1
è ïîñëåäíèé

goredey 05-02-2011 18:15 1605316

Nimur, ñìîòðþ

Nimur, ïåðåä òåì êàê âûïîëíèòü ñêðèïò îòêëþ÷èòå âîññòàíîâëåíèå ñèñòåìû!!!

Êîä:

Âîññòàíîâëåíèå ñèñòåìû: âêëþ÷åíî
AVZ, ìåíþ "Ôàéë - Âûïîëíèòü ñêðèïò" -- Ñêîïèðîâàòü íèæå íàïèñàííûé ñêðèïò-- Íàæàòü êíîïêó "Çàïóñòèòü".
Êîä:

begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
 ClearQuarantine;
 QuarantineFile('C:\WINDOWS\system32\88.exe','');
 QuarantineFile('C:\WINDOWS\system32\87.exe','');
 QuarantineFile('C:\WINDOWS\system32\86.exe','');
 QuarantineFile('C:\WINDOWS\system32\85.exe','');
 QuarantineFile('C:\WINDOWS\system32\82.exe','');
 QuarantineFile('C:\WINDOWS\system32\81.scr','');
 QuarantineFile('C:\WINDOWS\system32\81.exe','');
 QuarantineFile('C:\WINDOWS\system32\80.exe','');
 QuarantineFile('C:\WINDOWS\system32\78.exe','');
 QuarantineFile('C:\WINDOWS\system32\77.exe','');
 QuarantineFile('C:\WINDOWS\system32\74.exe','');
 QuarantineFile('C:\WINDOWS\system32\72.exe','');
 QuarantineFile('C:\WINDOWS\system32\70.exe','');
 QuarantineFile('C:\WINDOWS\system32\64.exe','');
 QuarantineFile('C:\WINDOWS\system32\63.exe','');
 QuarantineFile('C:\WINDOWS\system32\62.exe','');
 QuarantineFile('C:\WINDOWS\system32\61.exe','');
 QuarantineFile('C:\WINDOWS\system32\60.exe','');
 QuarantineFile('C:\WINDOWS\system32\58.exe','');
 QuarantineFile('C:\WINDOWS\system32\57.exe','');
 QuarantineFile('C:\WINDOWS\system32\56.exe','');
 QuarantineFile('C:\WINDOWS\system32\54.exe','');
 QuarantineFile('C:\WINDOWS\system32\52.exe','');
 QuarantineFile('C:\WINDOWS\system32\51.exe','');
 QuarantineFile('C:\WINDOWS\system32\50.exe','');
 QuarantineFile('C:\WINDOWS\system32\47.exe','');
 QuarantineFile('C:\WINDOWS\system32\44.exe','');
 QuarantineFile('C:\WINDOWS\system32\43.exe','');
 QuarantineFile('C:\WINDOWS\system32\41.exe','');
 QuarantineFile('C:\WINDOWS\system32\40.exe','');
 QuarantineFile('C:\WINDOWS\system32\37.exe','');
 QuarantineFile('C:\WINDOWS\system32\36.exe','');
 QuarantineFile('C:\WINDOWS\system32\35.exe','');
 QuarantineFile('C:\WINDOWS\system32\34.exe','');
 QuarantineFile('C:\WINDOWS\system32\32.exe','');
 QuarantineFile('C:\WINDOWS\system32\30.exe','');
 QuarantineFile('C:\WINDOWS\system32\28.exe','');
 QuarantineFile('C:\WINDOWS\system32\27.exe','');
 QuarantineFile('C:\WINDOWS\system32\25.exe','');
 QuarantineFile('C:\WINDOWS\system32\22.exe','');
 QuarantineFile('C:\WINDOWS\system32\18.exe','');
 QuarantineFile('C:\WINDOWS\system32\16.scr','');
 QuarantineFile('C:\WINDOWS\system32\16.exe','');
 QuarantineFile('C:\WINDOWS\system32\14.exe','');
 QuarantineFile('C:\WINDOWS\system32\13.exe','');
 QuarantineFile('C:\WINDOWS\system32\12.exe','');
 QuarantineFile('C:\WINDOWS\system32\11.exe','');
 QuarantineFile('C:\WINDOWS\system32\10.exe','');
 QuarantineFile('C:\WINDOWS\system32\08.exe','');
 QuarantineFile('C:\WINDOWS\system32\07.exe','');
 QuarantineFile('C:\WINDOWS\system32\06.exe','');
 QuarantineFile('C:\WINDOWS\system32\05.exe','');
 QuarantineFile('C:\WINDOWS\system32\02.exe','');
 QuarantineFile('C:\WINDOWS\system32\00.exe','');
 QuarantineFile('C:\RECYCLER\S-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe','');
 QuarantineFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe','');
 QuarantineFile('C:\WINDOWS\System32\Drivers\a6vrne8c.SYS','');
 QuarantineFile('c:\windows\ggdrive32.exe','');
 DeleteFile('c:\windows\ggdrive32.exe');
 DeleteFile('C:\WINDOWS\System32\Drivers\a6vrne8c.SYS');
 DeleteFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe');
 DeleteFile('C:\RECYCLER\S-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe');
 DeleteFile('C:\WINDOWS\system32\00.exe');
 DeleteFile('C:\WINDOWS\system32\02.exe');
 DeleteFile('C:\WINDOWS\system32\05.exe');
 DeleteFile('C:\WINDOWS\system32\06.exe');
 DeleteFile('C:\WINDOWS\system32\07.exe');
 DeleteFile('C:\WINDOWS\system32\08.exe');
 DeleteFile('C:\WINDOWS\system32\10.exe');
 DeleteFile('C:\WINDOWS\system32\11.exe');
 DeleteFile('C:\WINDOWS\system32\12.exe');
 DeleteFile('C:\WINDOWS\system32\13.exe');
 DeleteFile('C:\WINDOWS\system32\14.exe');
 DeleteFile('C:\WINDOWS\system32\16.exe');
 DeleteFile('C:\WINDOWS\system32\16.scr');
 DeleteFile('C:\WINDOWS\system32\18.exe');
 DeleteFile('C:\WINDOWS\system32\22.exe');
 DeleteFile('C:\WINDOWS\system32\25.exe');
 DeleteFile('C:\WINDOWS\system32\27.exe');
 DeleteFile('C:\WINDOWS\system32\28.exe');
 DeleteFile('C:\WINDOWS\system32\30.exe');
 DeleteFile('C:\WINDOWS\system32\32.exe');
 DeleteFile('C:\WINDOWS\system32\34.exe');
 DeleteFile('C:\WINDOWS\system32\35.exe');
 DeleteFile('C:\WINDOWS\system32\36.exe');
 DeleteFile('C:\WINDOWS\system32\37.exe');
 DeleteFile('C:\WINDOWS\system32\40.exe');
 DeleteFile('C:\WINDOWS\system32\41.exe');
 DeleteFile('C:\WINDOWS\system32\43.exe');
 DeleteFile('C:\WINDOWS\system32\44.exe');
 DeleteFile('C:\WINDOWS\system32\47.exe');
 DeleteFile('C:\WINDOWS\system32\50.exe');
 DeleteFile('C:\WINDOWS\system32\51.exe');
 DeleteFile('C:\WINDOWS\system32\52.exe');
 DeleteFile('C:\WINDOWS\system32\54.exe');
 DeleteFile('C:\WINDOWS\system32\56.exe');
 DeleteFile('C:\WINDOWS\system32\57.exe');
 DeleteFile('C:\WINDOWS\system32\58.exe');
 DeleteFile('C:\WINDOWS\system32\60.exe');
 DeleteFile('C:\WINDOWS\system32\61.exe');
 DeleteFile('C:\WINDOWS\system32\62.exe');
 DeleteFile('C:\WINDOWS\system32\63.exe');
 DeleteFile('C:\WINDOWS\system32\64.exe');
 DeleteFile('C:\WINDOWS\system32\70.exe');
 DeleteFile('C:\WINDOWS\system32\72.exe');
 DeleteFile('C:\WINDOWS\system32\74.exe');
 DeleteFile('C:\WINDOWS\system32\77.exe');
 DeleteFile('C:\WINDOWS\system32\78.exe');
 DeleteFile('C:\WINDOWS\system32\80.exe');
 DeleteFile('C:\WINDOWS\system32\81.exe');
 DeleteFile('C:\WINDOWS\system32\81.scr');
 DeleteFile('C:\WINDOWS\system32\82.exe');
 DeleteFile('C:\WINDOWS\system32\85.exe');
 DeleteFile('C:\WINDOWS\system32\86.exe');
 DeleteFile('C:\WINDOWS\system32\87.exe');
 DeleteFile('C:\WINDOWS\system32\88.exe');
 DelCLSID('{28ABC5C0-4FCB-11CF-AAX5-81CX1C635853}');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Driver Setup');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Driver Setup');
 RegKeyParamDel('HKEY_LOCAL_MACHINE, Software\Microsoft\Windows NT\CurrentVersion\Winlogon',' Taskman');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
 ExecuteRepair(11);
RebootWindows(true);
end.

Ïîñëå âûïîëíåíèÿ ñêðèïòà êîìïüþòåð ïåðåçàãðóçèòñÿ.

Êîä:

begin
 CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.


 ðåçóëüòàòå âûïîëíåíèÿ ñêðèïòà áóäåò ñôîðìèðîâàí êàðàíòèí quarantine.zip. Ïîëó÷åííûé àðõèâ îòïðàâüòå íà quarantine<at>virusnet.info (at=@) ñ óêàçàííîé ññûëêîé íà òåìó. , â íàçâàíèè òåìû óêàæèòå - "Ïðîâåðêà êàðàíòèíà".  òåëå ñîîáùåíèÿ óêàæèòå àäðåñ ñâîåé òåìû íà ôîðóìå. Ðåçóëüòàòû îòâåòà, ñîîáùèòå çäåñü, â òåìå.

vladlink.lan ýòî âàø ïðîâàéäåð?

Ïîâòîðèòå ëîãè ÀÂÇ
+

Ñêà÷àéòå RSIT èëè îòñþäà. Çàïóñòèòå, âûáåðèòå ïðîâåðêó ôàéëîâ çà ïîñëåäíèå òðè ìåñÿöà è íàæìèòå ïðîäîëæèòü. Äîëæíû îòêðûòüñÿ äâà îò÷åòà log.txt è info.txt. Ïðèêðåïèòå èõ ê ñëåäóþùåìó ñîîáùåíèþ. Åñëè âû èõ çàêðûëè, òî ëîãè ïî óìîë÷àíèþ ñîõðàíÿþòñÿ â îäíîèìåííîé ïàïêå (RSIT) â êîðíå ñèñòåìíîãî äèñêà.

Nimur 05-02-2011 18:35 1605336

Ïðè çàïóñêå ñêðèïòà Îøèáêà : Not enough actual parameters â ïîçèöèè 124:16

vladlink.lan ýòî ïðîâàéäåð

goredey 05-02-2011 19:44 1605391

Nimur, ïàðäîí èñïðàâèë
AVZ, ìåíþ "Ôàéë - Âûïîëíèòü ñêðèïò" -- Ñêîïèðîâàòü íèæå íàïèñàííûé ñêðèïò-- Íàæàòü êíîïêó "Çàïóñòèòü".
Êîä:

begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
 ClearQuarantine;
 QuarantineFile('C:\WINDOWS\system32\88.exe','');
 QuarantineFile('C:\WINDOWS\system32\87.exe','');
 QuarantineFile('C:\WINDOWS\system32\86.exe','');
 QuarantineFile('C:\WINDOWS\system32\85.exe','');
 QuarantineFile('C:\WINDOWS\system32\82.exe','');
 QuarantineFile('C:\WINDOWS\system32\81.scr','');
 QuarantineFile('C:\WINDOWS\system32\81.exe','');
 QuarantineFile('C:\WINDOWS\system32\80.exe','');
 QuarantineFile('C:\WINDOWS\system32\78.exe','');
 QuarantineFile('C:\WINDOWS\system32\77.exe','');
 QuarantineFile('C:\WINDOWS\system32\74.exe','');
 QuarantineFile('C:\WINDOWS\system32\72.exe','');
 QuarantineFile('C:\WINDOWS\system32\70.exe','');
 QuarantineFile('C:\WINDOWS\system32\64.exe','');
 QuarantineFile('C:\WINDOWS\system32\63.exe','');
 QuarantineFile('C:\WINDOWS\system32\62.exe','');
 QuarantineFile('C:\WINDOWS\system32\61.exe','');
 QuarantineFile('C:\WINDOWS\system32\60.exe','');
 QuarantineFile('C:\WINDOWS\system32\58.exe','');
 QuarantineFile('C:\WINDOWS\system32\57.exe','');
 QuarantineFile('C:\WINDOWS\system32\56.exe','');
 QuarantineFile('C:\WINDOWS\system32\54.exe','');
 QuarantineFile('C:\WINDOWS\system32\52.exe','');
 QuarantineFile('C:\WINDOWS\system32\51.exe','');
 QuarantineFile('C:\WINDOWS\system32\50.exe','');
 QuarantineFile('C:\WINDOWS\system32\47.exe','');
 QuarantineFile('C:\WINDOWS\system32\44.exe','');
 QuarantineFile('C:\WINDOWS\system32\43.exe','');
 QuarantineFile('C:\WINDOWS\system32\41.exe','');
 QuarantineFile('C:\WINDOWS\system32\40.exe','');
 QuarantineFile('C:\WINDOWS\system32\37.exe','');
 QuarantineFile('C:\WINDOWS\system32\36.exe','');
 QuarantineFile('C:\WINDOWS\system32\35.exe','');
 QuarantineFile('C:\WINDOWS\system32\34.exe','');
 QuarantineFile('C:\WINDOWS\system32\32.exe','');
 QuarantineFile('C:\WINDOWS\system32\30.exe','');
 QuarantineFile('C:\WINDOWS\system32\28.exe','');
 QuarantineFile('C:\WINDOWS\system32\27.exe','');
 QuarantineFile('C:\WINDOWS\system32\25.exe','');
 QuarantineFile('C:\WINDOWS\system32\22.exe','');
 QuarantineFile('C:\WINDOWS\system32\18.exe','');
 QuarantineFile('C:\WINDOWS\system32\16.scr','');
 QuarantineFile('C:\WINDOWS\system32\16.exe','');
 QuarantineFile('C:\WINDOWS\system32\14.exe','');
 QuarantineFile('C:\WINDOWS\system32\13.exe','');
 QuarantineFile('C:\WINDOWS\system32\12.exe','');
 QuarantineFile('C:\WINDOWS\system32\11.exe','');
 QuarantineFile('C:\WINDOWS\system32\10.exe','');
 QuarantineFile('C:\WINDOWS\system32\08.exe','');
 QuarantineFile('C:\WINDOWS\system32\07.exe','');
 QuarantineFile('C:\WINDOWS\system32\06.exe','');
 QuarantineFile('C:\WINDOWS\system32\05.exe','');
 QuarantineFile('C:\WINDOWS\system32\02.exe','');
 QuarantineFile('C:\WINDOWS\system32\00.exe','');
 QuarantineFile('C:\RECYCLER\S-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe','');
 QuarantineFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe','');
 QuarantineFile('C:\WINDOWS\System32\Drivers\a6vrne8c.SYS','');
 QuarantineFile('c:\windows\ggdrive32.exe','');
 DeleteFile('c:\windows\ggdrive32.exe');
 DeleteFile('C:\WINDOWS\System32\Drivers\a6vrne8c.SYS');
 DeleteFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe');
 DeleteFile('C:\RECYCLER\S-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe');
 DeleteFile('C:\WINDOWS\system32\00.exe');
 DeleteFile('C:\WINDOWS\system32\02.exe');
 DeleteFile('C:\WINDOWS\system32\05.exe');
 DeleteFile('C:\WINDOWS\system32\06.exe');
 DeleteFile('C:\WINDOWS\system32\07.exe');
 DeleteFile('C:\WINDOWS\system32\08.exe');
 DeleteFile('C:\WINDOWS\system32\10.exe');
 DeleteFile('C:\WINDOWS\system32\11.exe');
 DeleteFile('C:\WINDOWS\system32\12.exe');
 DeleteFile('C:\WINDOWS\system32\13.exe');
 DeleteFile('C:\WINDOWS\system32\14.exe');
 DeleteFile('C:\WINDOWS\system32\16.exe');
 DeleteFile('C:\WINDOWS\system32\16.scr');
 DeleteFile('C:\WINDOWS\system32\18.exe');
 DeleteFile('C:\WINDOWS\system32\22.exe');
 DeleteFile('C:\WINDOWS\system32\25.exe');
 DeleteFile('C:\WINDOWS\system32\27.exe');
 DeleteFile('C:\WINDOWS\system32\28.exe');
 DeleteFile('C:\WINDOWS\system32\30.exe');
 DeleteFile('C:\WINDOWS\system32\32.exe');
 DeleteFile('C:\WINDOWS\system32\34.exe');
 DeleteFile('C:\WINDOWS\system32\35.exe');
 DeleteFile('C:\WINDOWS\system32\36.exe');
 DeleteFile('C:\WINDOWS\system32\37.exe');
 DeleteFile('C:\WINDOWS\system32\40.exe');
 DeleteFile('C:\WINDOWS\system32\41.exe');
 DeleteFile('C:\WINDOWS\system32\43.exe');
 DeleteFile('C:\WINDOWS\system32\44.exe');
 DeleteFile('C:\WINDOWS\system32\47.exe');
 DeleteFile('C:\WINDOWS\system32\50.exe');
 DeleteFile('C:\WINDOWS\system32\51.exe');
 DeleteFile('C:\WINDOWS\system32\52.exe');
 DeleteFile('C:\WINDOWS\system32\54.exe');
 DeleteFile('C:\WINDOWS\system32\56.exe');
 DeleteFile('C:\WINDOWS\system32\57.exe');
 DeleteFile('C:\WINDOWS\system32\58.exe');
 DeleteFile('C:\WINDOWS\system32\60.exe');
 DeleteFile('C:\WINDOWS\system32\61.exe');
 DeleteFile('C:\WINDOWS\system32\62.exe');
 DeleteFile('C:\WINDOWS\system32\63.exe');
 DeleteFile('C:\WINDOWS\system32\64.exe');
 DeleteFile('C:\WINDOWS\system32\70.exe');
 DeleteFile('C:\WINDOWS\system32\72.exe');
 DeleteFile('C:\WINDOWS\system32\74.exe');
 DeleteFile('C:\WINDOWS\system32\77.exe');
 DeleteFile('C:\WINDOWS\system32\78.exe');
 DeleteFile('C:\WINDOWS\system32\80.exe');
 DeleteFile('C:\WINDOWS\system32\81.exe');
 DeleteFile('C:\WINDOWS\system32\81.scr');
 DeleteFile('C:\WINDOWS\system32\82.exe');
 DeleteFile('C:\WINDOWS\system32\85.exe');
 DeleteFile('C:\WINDOWS\system32\86.exe');
 DeleteFile('C:\WINDOWS\system32\87.exe');
 DeleteFile('C:\WINDOWS\system32\88.exe');
 DelCLSID('{28ABC5C0-4FCB-11CF-AAX5-81CX1C635853}');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Driver Setup');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Driver Setup');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
 ExecuteRepair(11);
RebootWindows(true);
end.

Ïîñëå âûïîëíåíèÿ ñêðèïòà êîìïüþòåð ïåðåçàãðóçèòñÿ.

Nimur 06-02-2011 01:50 1605663

Âëîæåíèé: 1
  • log.rar (6.10 KB, ñêà÷èâàíèé: 10)
íå ïîëó÷àåòñÿ îòïðàâèòü àðõèâ, òàêîãî àäðåñà íå ñóùåñòâóåò, ïèñüìà íàçàä âîçâðàùàþòñÿ, at= çàìåíÿë íà @.
ïðîðáëåìà òàê è îñòàëàñü, èíåò îòêëþ÷àåòñÿ ÷åðåç êàêîå-òî âðåìÿ.

Nimur 06-02-2011 03:15 1605688

íà virusnet.info íå îòïðàâëÿëîñü, îòïðàâèë íà safezone.cc

goredey 06-02-2011 12:06 1605836

Nimur, îòêëþ÷èòå âîñòàíîâëåíèå ñèñòåìû!!! Êàê ýòî ñäåëàòü îçíàêîìòåñü çäåñü

Òîëüêî ïîñëå ýòîãî ïðîëå÷èòåñü Dr.Web CureIt! . Ñêà÷àéòå íà çàâåäîìî "çäîðîâîì" êîìïüþòåðå, èíà÷å àêòèâíûé âèðóñ ïîâðåäèò óòèëèòó åù¸ äî çàïóñêà.

Ïîäãîòîâüòå ïîâòîðíûå ëîãè ÀÂÇ è RSIT

Nimur 06-02-2011 13:05 1605881

Âëîæåíèé: 1
  • log.rar (6.40 KB, ñêà÷èâàíèé: 10)
âîññòàíîâëåíèå ñèñòåìû îòêëþ÷åííî. âñå äåëàë êàê â èíñòðóêöèè.
ñäåëàë ïîëíîå ñêàíèðîâàíèå Dr.Web CureIt, îí íàøåë øòóê 19 âèðóñîâ, íåêîòîðîûå óäàëèë, íåêîòîðûå ïåðåìåñòèë. ìîãó ëîã ñêèíóòü.
âðîäå áû èíòåðíåò áîëüøå íå îòêëþ÷àåòñÿ, íî ýòè ôàéëû äî ñèõ ïîð ñèäÿò â âèí 32

goredey 06-02-2011 13:40 1605910

Nimur, AVZ, ìåíþ "Ôàéë - Âûïîëíèòü ñêðèïò" -- Ñêîïèðîâàòü íèæå íàïèñàííûé ñêðèïò-- Íàæàòü êíîïêó "Çàïóñòèòü".
Êîä:

begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
 ClearQuarantine;
 QuarantineFile('C:\WINDOWS\system32\87.exe','');
 QuarantineFile('C:\WINDOWS\system32\86.exe','');
 QuarantineFile('C:\WINDOWS\system32\82.exe','');
 QuarantineFile('C:\WINDOWS\system32\81.exe','');
 QuarantineFile('C:\WINDOWS\system32\80.exe','');
 QuarantineFile('C:\WINDOWS\system32\77.exe','');
 QuarantineFile('C:\WINDOWS\system32\76.scr','');
 QuarantineFile('C:\WINDOWS\system32\76.exe','');
 QuarantineFile('C:\WINDOWS\system32\74.exe','');
 QuarantineFile('C:\WINDOWS\system32\68.exe','');
 QuarantineFile('C:\WINDOWS\system32\66.scr','');
 QuarantineFile('C:\WINDOWS\system32\64.exe','');
 QuarantineFile('C:\WINDOWS\system32\63.exe','');
 QuarantineFile('C:\WINDOWS\system32\62.scr','');
 QuarantineFile('C:\WINDOWS\system32\62.exe','');
 QuarantineFile('C:\WINDOWS\system32\61.exe','');
 QuarantineFile('C:\WINDOWS\system32\60.exe','');
 QuarantineFile('C:\WINDOWS\system32\57.exe','');
 QuarantineFile('C:\WINDOWS\system32\53.exe','');
 QuarantineFile('C:\WINDOWS\system32\50.scr','');
 QuarantineFile('C:\WINDOWS\system32\47.exe','');
 QuarantineFile('C:\WINDOWS\system32\46.scr','');
 QuarantineFile('C:\WINDOWS\system32\46.exe','');
 QuarantineFile('C:\WINDOWS\system32\45.exe','');
 QuarantineFile('C:\WINDOWS\system32\43.exe','');
 QuarantineFile('C:\WINDOWS\system32\41.exe','');
 QuarantineFile('C:\WINDOWS\system32\38.exe','');
 QuarantineFile('C:\WINDOWS\system32\37.exe','');
 QuarantineFile('C:\WINDOWS\system32\35.exe','');
 QuarantineFile('C:\WINDOWS\system32\34.exe','');
 QuarantineFile('C:\WINDOWS\system32\33.exe','');
 QuarantineFile('C:\WINDOWS\system32\32.exe','');
 QuarantineFile('C:\WINDOWS\system32\31.exe','');
 QuarantineFile('C:\WINDOWS\system32\27.exe','');
 QuarantineFile('C:\WINDOWS\system32\24.exe','');
 QuarantineFile('C:\WINDOWS\system32\23.exe','');
 QuarantineFile('C:\WINDOWS\system32\22.exe','');
 QuarantineFile('C:\WINDOWS\system32\21.exe','');
 QuarantineFile('C:\WINDOWS\system32\17.exe','');
 QuarantineFile('C:\WINDOWS\system32\16.scr','');
 QuarantineFile('C:\WINDOWS\system32\16.exe','');
 QuarantineFile('C:\WINDOWS\system32\14.exe','');
 QuarantineFile('C:\WINDOWS\system32\13.exe','');
 QuarantineFile('C:\WINDOWS\system32\12.exe','');
 QuarantineFile('C:\WINDOWS\system32\08.exe','');
 QuarantineFile('C:\WINDOWS\system32\07.exe','');
 QuarantineFile('C:\WINDOWS\system32\06.exe','');
 QuarantineFile('C:\WINDOWS\system32\03.exe','');
 QuarantineFile('C:\WINDOWS\system32\00.exe','');
 QuarantineFile('c:\RECYCLER\S-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe','');
 QuarantineFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\winfixer.exe','');
 QuarantineFile('c:\windows\system32\txzrm.exe','');
 QuarantineFile('c:\windows\ggdrive32.exe','');
 DeleteFile('c:\windows\ggdrive32.exe');
 DeleteFile('c:\windows\system32\txzrm.exe');
 DeleteFile('c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\winfixer.exe');
 DeleteFile('c:\RECYCLER\S-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe');
 DeleteFile('C:\WINDOWS\system32\00.exe');
 DeleteFile('C:\WINDOWS\system32\03.exe');
 DeleteFile('C:\WINDOWS\system32\06.exe');
 DeleteFile('C:\WINDOWS\system32\07.exe');
 DeleteFile('C:\WINDOWS\system32\08.exe');
 DeleteFile('C:\WINDOWS\system32\12.exe');
 DeleteFile('C:\WINDOWS\system32\13.exe');
 DeleteFile('C:\WINDOWS\system32\14.exe');
 DeleteFile('C:\WINDOWS\system32\16.exe');
 DeleteFile('C:\WINDOWS\system32\16.scr');
 DeleteFile('C:\WINDOWS\system32\17.exe');
 DeleteFile('C:\WINDOWS\system32\21.exe');
 DeleteFile('C:\WINDOWS\system32\22.exe');
 DeleteFile('C:\WINDOWS\system32\23.exe');
 DeleteFile('C:\WINDOWS\system32\24.exe');
 DeleteFile('C:\WINDOWS\system32\27.exe');
 DeleteFile('C:\WINDOWS\system32\31.exe');
 DeleteFile('C:\WINDOWS\system32\32.exe');
 DeleteFile('C:\WINDOWS\system32\33.exe');
 DeleteFile('C:\WINDOWS\system32\34.exe');
 DeleteFile('C:\WINDOWS\system32\35.exe');
 DeleteFile('C:\WINDOWS\system32\37.exe');
 DeleteFile('C:\WINDOWS\system32\38.exe');
 DeleteFile('C:\WINDOWS\system32\41.exe');
 DeleteFile('C:\WINDOWS\system32\43.exe');
 DeleteFile('C:\WINDOWS\system32\45.exe');
 DeleteFile('C:\WINDOWS\system32\46.exe');
 DeleteFile('C:\WINDOWS\system32\46.scr');
 DeleteFile('C:\WINDOWS\system32\47.exe');
 DeleteFile('C:\WINDOWS\system32\50.scr');
 DeleteFile('C:\WINDOWS\system32\53.exe');
 DeleteFile('C:\WINDOWS\system32\55.exe');
 DeleteFile('C:\WINDOWS\system32\57.exe');
 DeleteFile('C:\WINDOWS\system32\58.exe');
 DeleteFile('C:\WINDOWS\system32\60.exe');
 DeleteFile('C:\WINDOWS\system32\61.exe');
 DeleteFile('C:\WINDOWS\system32\62.exe');
 DeleteFile('C:\WINDOWS\system32\62.scr');
 DeleteFile('C:\WINDOWS\system32\63.exe');
 DeleteFile('C:\WINDOWS\system32\64.exe');
 DeleteFile('C:\WINDOWS\system32\66.scr');
 DeleteFile('C:\WINDOWS\system32\68.exe');
 DeleteFile('C:\WINDOWS\system32\74.exe');
 DeleteFile('C:\WINDOWS\system32\76.exe');
 DeleteFile('C:\WINDOWS\system32\76.scr');
 DeleteFile('C:\WINDOWS\system32\77.exe');
 DeleteFile('C:\WINDOWS\system32\80.exe');
 DeleteFile('C:\WINDOWS\system32\81.exe');
 DeleteFile('C:\WINDOWS\system32\82.exe');
 DeleteFile('C:\WINDOWS\system32\86.exe');
 DeleteFile('C:\WINDOWS\system32\87.exe');
 DelCLSID('{28ABC5C0-4FCB-11CF-AAX5-81CX1C635853}');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Microsoft Driver Setup');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Microsoft Driver Setup');
 RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
 ExecuteRepair(11);
RebootWindows(true);
end.

Ïîñëå âûïîëíåíèÿ ñêðèïòà êîìïüþòåð ïåðåçàãðóçèòñÿ.

Êîä:

begin
 CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.


 ðåçóëüòàòå âûïîëíåíèÿ ñêðèïòà áóäåò ñôîðìèðîâàí êàðàíòèí quarantine.zip. Ïîëó÷åííûé àðõèâ îòïðàâüòå íà quarantine<at>virusnet.info (at=@) ñ óêàçàííîé ññûëêîé íà òåìó. , â íàçâàíèè òåìû óêàæèòå - "Ïðîâåðêà êàðàíòèíà".  òåëå ñîîáùåíèÿ óêàæèòå àäðåñ ñâîåé òåìû íà ôîðóìå. Ðåçóëüòàòû îòâåòà, ñîîáùèòå çäåñü, â òåìå.

Ïîâòîðèòå ëîãè ÀÂÇ

Nimur 06-02-2011 13:46 1605913

íà quarantine<at>virusnet.info íå îòïðàâëÿåòñÿ, òàêîãî àäðåññà íåò...

goredey 06-02-2011 13:48 1605918

Nimur,
Ïîëó÷åííûé àðõèâ îòïðàâüòå ïî ýòîé ôîðìå

Nimur 06-02-2011 14:15 1605938

âñå ñäåëàë.. èíåò ñíîâà íà÷àë îòêëþ÷àòñÿ

goredey 06-02-2011 14:24 1605943

Nimur,
Öèòàòà:Ñêà÷àéòå ComboFix çäåñü, çäåñü èëè çäåñü è ñîõðàíèòå íà ðàáî÷èé ñòîë.

1. Âíèìàíèå! Îáÿçàòåëüíî çàêðîéòå âñå áðàóçåðû, âðåìåííî âûêëþ÷èòå àíòèâèðóñ, firewall è äðóãîå çàùèòíîå ïðîãðàììíîå îáåñïå÷åíèå. Íå çàïóñêàéòå äðóãèõ ïðîãðàìì âî âðåìÿ ðàáîòû Combofix. Combofix ìîæåò îòêëþ÷èòü èíòåðíåò ÷åðåç íåêîòîðîå âðåìÿ ïîñëå çàïóñêà, íå ïåðåïîäêëþ÷àéòå èíòåðíåò ïîêà Combofix íå çàâåðøèò ðàáîòó. Åñëè èíòåðíåò íå ïîÿâèëñÿ ïîñëå îêîí÷àíèÿ ðàáîòû Combofix, ïåðåçàãðóçèòå êîìïüþòåð. Âî âðåìÿ ðàáîòû Combofix íå íàæèìàéòå êíîïêè ìûøè, ýòî ìîæåò ñòàòü ïðè÷èíîé çàâèñàíèÿ Combofix.
2. Çàïóñòèòå combofix.exe, êîãäà ïðîöåññ çàâåðøèòñÿ, ñêîïèðóéòå òåêñò èç C:\ComboFix.txt è âñòàâüòå â ñëåäóþùåå ñîîáùåíèå èëè çàïàêóéòå ôàéë C:\ComboFix.txt è ïðèêðåïèòå ê ñîîáùåíèþ.
Ïðèì:  ñëó÷àå, åñëè ComboFix íå çàïóñêàåòñÿ, ïåðåèìåíóéòå combofix.exe â combo-fix.exe

Ïîäðîáíåå â "ComboFix. Ðóêîâîäñòâî ïî ïðèìåíåíèþ."

Nimur 06-02-2011 14:50 1605956

Âëîæåíèé: 1
  • log.txt (15.10 KB, ñêà÷èâàíèé: 17)
Âûïîëíèë, âîò ëîã. Áðåíäìàóçåð ìîæíî âêëþ÷àòü îáðàòíî?

Nimur 06-02-2011 15:05 1605965

òàê æå ðóáèò èíòåðíåò..

goredey 06-02-2011 16:48 1606063

Öèòàòà:

Öèòàòà Nimur
Áðåíäìàóçåð ìîæíî âêëþ÷àòü îáðàòíî? »

Íà âðåìÿ ðàáîòû ñêðèïòîâ îòêëþ÷àéòå.

Âàì íåîáõîäèìî çàìåíèòü ñèñòåìíûé ôàéë.Âàø ïðîïàò÷åí.

Êîä:

c:\windows\regedit.exe
Êàê ýòî ñäåëàòü ìîæåòå ïðî÷èòàòü çäåñü

Ïðîâåðüòå íà Virustotal âîò ýòè ôàéëû


Êîä:

C:\browser.exe
C:\xdx.exe
c:\windows\system32\S753A751.EXE

Ññûëêó íà ðåçóëüòàò çàïîñòèòå çäåñü.

+

Ïîâòîðèòå ëîãè ÀÂÇ
+

Ñêà÷àéòå RSIT èëè îòñþäà. Çàïóñòèòå, âûáåðèòå ïðîâåðêó ôàéëîâ çà ïîñëåäíèå òðè ìåñÿöà è íàæìèòå ïðîäîëæèòü. Äîëæíû îòêðûòüñÿ äâà îò÷åòà log.txt è info.txt. Ïðèêðåïèòå èõ ê ñëåäóþùåìó ñîîáùåíèþ. Åñëè âû èõ çàêðûëè, òî ëîãè ïî óìîë÷àíèþ ñîõðàíÿþòñÿ â îäíîèìåííîé ïàïêå (RSIT) â êîðíå ñèñòåìíîãî äèñêà.
+


Ñêà÷àéòå Malwarebytes' Anti-Malware èëè ñ çåðêàëà, óñòàíîâèòå, îáíîâèòå áàçû, âûáåðèòå "Perform Full Scan", íàæìèòå "Scan", ïîñëå ñêàíèðîâàíèÿ - Ok - Show Results (ïîêàçàòü ðåçóëüòàòû) . Îòêðîéòå ëîã è ñêîïèðóéòå â ñîîáùåíèå.
Åñëè áàçû MBAM â àâòîìàòè÷åñêîì ðåæèìå îáíîâèòü íå óäàëîñü, îáíîâèòå èõ îòäåëüíî. Çàãðóçèòü îáíîâëåíèå MBAM.

Nimur 07-02-2011 11:19 1606626

Ñëîæíî.. À ìîæíî regedit.exe âçÿòü ñî çäîðîâîãî êîìïüþòåðà, è ñ ôëåøêè êàê íèáóäü çàïèñàòü âçàìåí ìîåãî?

Nimur 07-02-2011 12:14 1606684

http://www.virustotal.com/file-scan/...2af-1297069552

http://www.virustotal.com/file-scan/...f9a-1297069674

http://www.virustotal.com/file-scan/...0bf-1297069962


Àíàëèç ôàéëîâ:
C:\browser.exe
C:\xdx.exe
c:\windows\system32\S753A751.EXE

iskander-k 07-02-2011 13:37 1606757

c:\windows\regedit.exe - -ïðîâåðüòå íà http://www.virustotal.com ññûëêó íà ðåçóëüòàò â òåìó. (âîçìîæíî ëîæíîå ñðàáàòûâàíèå òàê êàê ó âàñ ñáîðêà)

Ïðîãðàììó c:\program files\SMSDV - âû ñàìè óñòàíàâëèâàëè ?

• Ñêîïèðóéòå òåêñò íèæå â áëîêíîò è ñîõðàíèòå êàê ôàéë ñ íàçâàíèåì CFScript.txt íà ðàáî÷èé ñòîë.
âðåìåííî âûêëþ÷èòå àíòèâèðóñ, firewall è äðóãîå çàùèòíîå ïðîãðàììíîå îáåñïå÷åíèå.
Êîä:

KillAll::

File::
c:\documents and settings\Admin\dq.exe
C:\vncutil.exe
C:\browser.exe
C:\xdx.exe
c:\windows\system32\S753A751.EXE
c:\windows\system32\ZH139.EXE
Driver::

Folder::

Registry::

FileLook::

DirLook::
c:\program files\SMSDV

Ïîñëå ñîõðàíåíèÿ ïåðåìåñòèòå CFScript.txt íà ïèêòîãðàììó ComboFix.exe.



Êîãäà ñîõðàíèòñÿ íîâûé îò÷¸ò ComboFix, ñêîïèðóéòå (Ctrl+A, Ctrl+C) òåêñò èç C:\ComboFix.txt è âñòàâüòå (Ctrl+V) â ñëåäóþùåå ñîîáùåíèå åñëè òåêñò íå óìåñòèòñÿ â îäíîì ñîîáùåíèè, ïðîäîëæèòå åãî â ñëåäóþùåì èëè çàïàêóéòå ôàéë C:\ComboFix.txt è ïðèêðåïèòå ê ñîîáùåíèþ.

IP âàø ?
109.126.0.67 109.126.1.67

Êîä:

109.126.0.67(cdns2.vladlink.net)
Ñòðàíà ïî äàííûì WhoIS: RU Russian Federation (Ðîññèÿ)
Ñòðàíà ïî äàííûì GeoIP: RU Russian Federation (Ðîññèÿ) Ãîðîä: Vladivostok


Nimur 07-02-2011 14:01 1606770

Âëîæåíèé: 1
Ðåçóëüòàò ñêàíèðîâàíèÿ Malwarebytes' Anti-Malware.
Íàøåë 91 âèðóñ. Ñâåðíóë, óäàëÿòü èëè çàêðûòü ïðîãðàììó äëÿ ìàíèïóëÿöèé ñ ComboFix?

http://www.virustotal.com/file-scan/...b85-1297076342

Smsdv ÿ ñàì óñòàíàâëèâàë.

Nimur 07-02-2011 14:02 1606773

IP ìîé

goredey 07-02-2011 14:09 1606779

ïîâòîð

Öèòàòà:

Öèòàòà Nimur
Ðåçóëüòàò ñêàíèðîâàíèÿ Malwarebytes' Anti-Malware.
Íàøåë 91 âèðóñ. »

Âûëîæèòå îò÷åò, à òàêæå îò÷åò êîìáîôèêñ

Nimur 07-02-2011 14:16 1606789

http://ifolder.ru/21753604 îò÷åò Malwarebytes'.
ñåé÷àñ áóäó âûïîëíÿòü äåéñòâèÿ ñ êîìáèôèêñ

goredey 07-02-2011 14:30 1606798

Nimur, óäàëèòå â ÌÂÀÌ ýòè ñòðî÷êè

Êîä:

Çàðàæ¸ííûå ïðîöåññû â ïàìÿòè:
c:\WINDOWS\system32\txzrm.exe (Trojan.Agent) -> 492 -> No action taken.
Çàðàæ¸ííûå êëþ÷è â ðååñòðå:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635853} (Backdoor.Agent) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635853} (Backdoor.Agent) -> No action taken.
Çàðàæ¸ííûå ïàïêè:
c:\RECYCLER\s-1-5-21-0243556031-888888379-781863308-1413 (Worm.AutoRun) -> No action taken.
c:\RECYCLER\r-1-5-21-1482476501-1644491937-682003330-1013 (Worm.AutoRun.Gen) -> No action taken.

Çàðàæ¸ííûå ôàéëû:
c:\WINDOWS\system32\txzrm.exe (Trojan.Agent) -> No action taken.
c:\RECYCLER\s-51-9-25-3434974274-1472494965-644317114-1374\bszhbt.exe (Backdoor.Agent) -> No action taken.
c:\vncutil.exe (Trojan.Agent) -> No action taken.
c:\xdx.exe (Worm.Zeroll) -> No action taken.
c:\documents and settings\Admin\dq.exe (Trojan.Autorun) -> No action taken.
c:\documents and settings\Admin\doctorweb\quarantine\avz00001.dta (Spyware.Passwords.XGen) -> No action taken.
c:\documents and settings\Admin\local settings\temporary internet files\Content.IE5\IZG308MB\dq[1].exe (Trojan.Autorun) -> No action taken.
c:\documents and settings\Admin\local settings\temporary internet files\Content.IE5\K1CTL969\dq[1].exe (Trojan.Autorun) -> No action taken.
c:\documents and settings\Admin\local settings\temporary internet files\Content.IE5\K1CTL969\zz[1].exe (Trojan.Agent) -> No action taken.
c:\documents and settings\Admin\local settings\temporary internet files\Content.IE5\LW253GTU\zz[1].exe (Trojan.Agent) -> No action taken.
c:\documents and settings\Admin\local settings\temporary internet files\Content.IE5\VGGK3QUJ\udv[1].exe (Worm.Zeroll) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\8G91UK58\app[1].exe (Trojan.Agent) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\DRP833PJ\udv[1].exe (Worm.Zeroll) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\X6L1ZMCE\udv[1].exe (Worm.Zeroll) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\X6L1ZMCE\udv[2].exe (Worm.Zeroll) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\X6L1ZMCE\zz[1].exe (Trojan.Agent) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\XGR0168X\r96[1].exe (Trojan.Autorun) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\XGR0168X\r96[2].exe (Trojan.Autorun) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\XGR0168X\r96[3].exe (Trojan.Autorun) -> No action taken.
c:\documents and settings\networkservice\local settings\temporary internet files\Content.IE5\XGR0168X\zz[1].exe (Trojan.Agent) -> No action taken.
c:\Qoobox\quarantine\C\RECYCLER\r-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe.vir (Worm.Zeroll) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\ggdrive32.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\11.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\18.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\25.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\28.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\40.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\42.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\44.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\48.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\51.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\52.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\53.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\58.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\62.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\70.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\71.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\73.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\83.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\86.exe.vir (Trojan.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\dp1.fne.vir (Worm.Autorun) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\system32\internet.fne.vir (HackTool.Patcher) -> No action taken.
c:\RECYCLER\r-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe (Worm.Zeroll) -> No action taken.
c:\system volume information\_restore{889235de-8705-469c-865d-f8cbf170dc24}\RP1\A0000004.exe (Trojan.Autorun) -> No action taken.
c:\system volume information\_restore{889235de-8705-469c-865d-f8cbf170dc24}\RP1\A0000020.exe (Trojan.Autorun) -> No action taken.
c:\system volume information\_restore{889235de-8705-469c-865d-f8cbf170dc24}\RP2\A0010748.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{889235de-8705-469c-865d-f8cbf170dc24}\RP3\A0011028.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{889235de-8705-469c-865d-f8cbf170dc24}\RP3\A0011029.exe (Trojan.Agent) -> No action taken.
c:\system volume information\_restore{889235de-8705-469c-865d-f8cbf170dc24}\RP4\A0011043.exe (Trojan.Agent) -> No action taken.
c:\WINDOWS\ggdrive32.exe (Trojan.Autorun) -> No action taken.
c:\WINDOWS\innounp.exe (Malware.Packer.Gen) -> No action taken.
c:\WINDOWS\system32\02.scr (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\06.exe (Trojan.Autorun) -> No action taken.
c:\WINDOWS\system32\07.scr (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\10.scr (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\67.scr (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\msvcp100.dll (Malware.Packer.Gen) -> No action taken.
c:\WINDOWS\system32\41.exe (Trojan.Autorun) -> No action taken.
c:\WINDOWS\system32\42.exe (Trojan.Autorun) -> No action taken.
c:\WINDOWS\system32\44.exe (Trojan.Autorun) -> No action taken.


Nimur 07-02-2011 14:38 1606807

http://ifolder.ru/21754041
ëîã êîìáèôèêñà

êàê ýòî ñäåëàòü? çàíîâà çàïóñòèòü ñêàíèðîâàíèå, à ïîòîì óäàëèòü ñòðîêè èç îò÷åòà?

goredey 07-02-2011 14:48 1606812

Öèòàòà:

Öèòàòà Nimur
êàê ýòî ñäåëàòü? »

Ïîñëå îêîí÷àíèÿ ñêàíèðîâàíèå îòìåòèòü óêàçàííûå ñòðî÷êè è íàæàòü óäàëèòü.

Ïîñëå òîãî êàê óäàëèòå ïîäãîòîâüòå êîíòðîëüíûå ëîãè ÀÂÇ è RSIT

Nimur 07-02-2011 15:43 1606856

http://ifolder.ru/21755399
íîâûé ëîã ÌÂÀÌ, òåïåðü íàøåë 96 âèðóñîâ, ïîñìîòðèòå ïîæàëóéñòà ìîæåò íîâûå äîáàâèòü â ñòðîêè äëÿ óäàëåíèÿ? ÿ ïîêà íå áóäó óäàëÿòü, ÷òîáû çàíîâî íå ñêàíèðîâàòü...

goredey 07-02-2011 16:24 1606885

Nimur, óäàëèòå âñå,êðîìå
Êîä:

c:\miranda im pilot pack 7.5.3\msvcp100.dll (Malware.Packer.Gen) -> No action taken.
c:\WINDOWS\system32\msvcp100.dll (Malware.Packer.Gen) -> No action taken.


Nimur 07-02-2011 16:24 1606886

Âëîæåíèé: 1
  • log.rar (7.20 KB, ñêà÷èâàíèé: 9)
Ïðîëå÷èëñÿ ÌÂÀÌ.
Âîò ëîãè ÀÂÇ è RSIT

Nimur 07-02-2011 16:25 1606890

áëèí, c:\WINDOWS\system32\msvcp100.dll (Malware.Packer.Gen) -> No action taken. óæå óäàëèë... ýòî íå ñìåðòåëüíî?

goredey 07-02-2011 18:07 1606985

Öèòàòà:

Öèòàòà Nimur
ýòî íå ñìåðòåëüíî? »

Íåò íå ñìåðòåëüíî)))

 ïðåäîñòàâëåííûõ ëîãàõ âèðóñíîé àêòèâíîñòè íåò. Óñòàíîâèòå IE8 äàæå åñëè íå ïîëüçóåòåñü!



Äåèíñòàëëèðóéòå ComboFix:íàæìèòå Ïóñê => Âûïîëíèòü â îêíå íàáåðèòå êîìàíäó Combofix /Uninstall, íàæìèòå êíîïêó "ÎÊ"



Ñêà÷àéòå OTCleanIt èëè ñ çåðêàëà, çàïóñòèòå, íàæìèòå Clean up

Ñîçäàéòå íîâóþ êîíòðîëüíóþ òî÷êó âîññòàíîâëåíèÿ è óäàëèòå çàðàæåííóþ:
1. Íàæìèòå Ïóñê - Ïðîãðàììû – Ñòàíäàðòíûå – Ñëóæåáíûå – Î÷èñòêà äèñêà, âûáåðèòå ñèñòåìíûé äèñê, íà âêëàäêå Äîïîëíèòåëüíî - Âîññòàíîâëåíèå ñèñòåìû íàæìèòå Î÷èñòèòü
2. Íàæìèòå Ïóñê- Ïðîãðàììû – Ñòàíäàðòíûå – Ñëóæåáíûå – Âîññòàíîâëåíèå ñèñòåìû, âûáåðèòå Ñîçäàòü òî÷êó âîññòàíîâëåíèÿ, íàæìèòå Äàëåå, ââåäèòå èìÿ òî÷êè âîññòàíîâëåíèÿ è íàæìèòå Ñîçäàòü.

Ñêà÷àéòå ATF Cleaner , çàïóñòèòå, ïîñòàâüòå ãàëî÷êó íàïðîòèâ Select All è íàæìèòå Empty Selected.
åñëè âû èñïîëüçóåòå Firefox, íàæìèòå Firefox - Select All - Empty Selected
íàæìèòå No, åñëè âû õîòèòå îñòàâèòü âàøè ñîõðàíåííûå ïàðîëè
åñëè âû èñïîëüçóåòå Opera, íàæìèòå Opera - Select All - Empty Selected
íàæìèòå No, åñëè âû õîòèòå îñòàâèòü âàøè ñîõðàíåííûå ïàðîëè.

Nimur 08-02-2011 02:18 1607307

Âûïîëíèë! Ñïàñèáî âàì ðåáÿòà! Íå çíàþ êàê âûðàæàåòñÿ áëàãîäàðíîñòü íà ôàøåì ôîðóìå, ïëþñîâ ÿ íå óâèäåë, òàê ÷òî âñåì îãðîìíîå ÷åëîâå÷åñêîå ñïàñèáî!

iskander-k 08-02-2011 08:41 1607392

Öèòàòà:

Öèòàòà Nimur
Âûïîëíèë! Ñïàñèáî âàì ðåáÿòà! Íå çíàþ êàê âûðàæàåòñÿ áëàãîäàðíîñòü íà ôàøåì ôîðóìå, ïëþñîâ ÿ íå óâèäåë, òàê ÷òî âñåì îãðîìíîå ÷åëîâå÷åñêîå ñïàñèáî! »

Ïîä êàæäûì ñîîáùåíèåì åñòü Ññûëêà " Ïîëåçíîå ñîîáùåíèå " -ýòî è åñòü ïëþñèê ÷åëîâåêó êîòîðûé îêàçûâàë âàì ïîìîùü è åãî ñîîáùåíèå îêàçàëîñü âàì ïîëåçíûì.

thyrex 15-02-2011 23:43 1613988

Óñòàíîâèòå âñå íîâûå îáíîâëåíèÿ äëÿ Windows

Åñëè ýòîãî íå ñäåëàòü, ñàìîõîäíûé ÷åðâÿê ñíîâà áóäåò ó Âàñ ãîñòèòü


Âðåìÿ: 17:34.

Âðåìÿ: 17:34.
© OSzone.net 2001-