Смените все пароли
Выполните скрипт в AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('c:\WINDOWS\system32\jWJqWx9.exe','');
QuarantineFile('c:\WINDOWS\system32\u5jZcBq.exe','');
QuarantineFile('c:\WINDOWS\system32\eHZL1Dl.exe','');
QuarantineFile('c:\WINDOWS\system32\EGB98hz.exe','');
QuarantineFile('c:\WINDOWS\system32\qMfRVhK.exe','');
QuarantineFile('c:\WINDOWS\system32\cggyn3t.exe','');
QuarantineFile('c:\WINDOWS\system32\7wGntYH.exe','');
QuarantineFile('c:\WINDOWS\system32\6oXHDO1.exe','');
QuarantineFile('c:\WINDOWS\system32\4rxsz9b.exe','');
QuarantineFile('c:\WINDOWS\system32\i948Sba.exe','');
QuarantineFile('c:\WINDOWS\system32\hSOtX0I.exe','');
QuarantineFile('c:\WINDOWS\system32\HsE9Rma.exe','');
QuarantineFile('c:\WINDOWS\system32\ZRwmh9Q.exe','');
QuarantineFile('c:\WINDOWS\system32\Zf7R7qk.exe','');
QuarantineFile('c:\WINDOWS\system32\ZEFAZXC.exe','');
QuarantineFile('c:\WINDOWS\system32\YRC53PE.exe','');
QuarantineFile('c:\WINDOWS\system32\MbSwZgZ.exe','');
QuarantineFile('c:\WINDOWS\system32\lnjPsh6.exe','');
QuarantineFile('c:\WINDOWS\system32\NXvrb6b.exe','');
QuarantineFile('c:\WINDOWS\system32\hpKs9Zw.exe','');
QuarantineFile('c:\WINDOWS\system32\dbiRCsX.exe','');
QuarantineFile('c:\WINDOWS\system32\dAfko4c.exe','');
QuarantineFile('c:\WINDOWS\system32\BZ4Ups1.exe','');
QuarantineFile('c:\WINDOWS\system32\l06gVOY.exe','');
QuarantineFile('c:\WINDOWS\system32\gPkE4MB.exe','');
QuarantineFile('c:\WINDOWS\system32\qhMURM5.exe','');
QuarantineFile('c:\WINDOWS\system32\BJYXndD.exe','');
QuarantineFile('c:\WINDOWS\system32\B5EUMUS.exe','');
QuarantineFile('c:\WINDOWS\system32\CoYgZdV.exe','');
QuarantineFile('c:\WINDOWS\system32\v40IIx0.exe','');
QuarantineFile('c:\WINDOWS\system32\tPWAch1.exe','');
QuarantineFile('c:\WINDOWS\system32\sZkkTBq.exe','');
QuarantineFile('c:\WINDOWS\system32\SWEANux.exe','');
QuarantineFile('c:\WINDOWS\system32\S5IVsm8.exe','');
QuarantineFile('c:\WINDOWS\system32\kbhTkTr.exe','');
QuarantineFile('c:\WINDOWS\system32\p6BnVSo.exe','');
QuarantineFile('c:\WINDOWS\system32\OuJ0Ga4.exe','');
QuarantineFile('c:\WINDOWS\system32\de0e40a.exe','');
QuarantineFile('c:\WINDOWS\system32\AE3YoRh.exe','');
QuarantineFile('c:\WINDOWS\system32\4hHOaoR.exe','');
QuarantineFile('c:\WINDOWS\system32\3yVQFQK.exe','');
BC_ImportAll;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Пришлите карантин согласно Приложения 3 правил по красной ссылке Прислать запрошенный карантин вверху темы
Удалите в МВАМ
Код:
Заражённые ключи в реестре:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Backdoor.Bot) -> No action taken.
Заражённые параметры в реестре:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\option_1 (Rootkit.Agent) -> Value: option_1 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\option_2 (Rootkit.Agent) -> Value: option_2 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\option_3 (Rootkit.Agent) -> Value: option_3 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Value: UID -> No action taken.
Заражённые папки:
c:\program files\common files\wm\keys (Trojan.KeyLog) -> No action taken.
c:\WINDOWS\system32\lowsec (Stolen.data) -> No action taken.
Заражённые файлы:
c:\documents and settings\Dim\рабочий стол\avz4\Infected\2010-12-07\avz00008.dta (Trojan.Meredrop) -> No action taken.
c:\WINDOWS\system32\3yVQFQK.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\4hHOaoR.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\AE3YoRh.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\de0e40a.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\OuJ0Ga4.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\p6BnVSo.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\kbhTkTr.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\S5IVsm8.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\SWEANux.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\sZkkTBq.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\tPWAch1.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\v40IIx0.exe (Trojan.Scar) -> No action taken.
c:\WINDOWS\system32\CoYgZdV.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\B5EUMUS.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\BJYXndD.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\qhMURM5.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\gPkE4MB.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\l06gVOY.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\BZ4Ups1.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\dAfko4c.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\dbiRCsX.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\hpKs9Zw.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\NXvrb6b.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\lnjPsh6.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\MbSwZgZ.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\YRC53PE.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\ZEFAZXC.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\Zf7R7qk.exe (Trojan.Scar) -> No action taken.
c:\WINDOWS\system32\ZRwmh9Q.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\HsE9Rma.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\hSOtX0I.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\i948Sba.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\4rxsz9b.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\6oXHDO1.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\7wGntYH.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\cggyn3t.exe (Trojan.Scar) -> No action taken.
c:\WINDOWS\system32\qMfRVhK.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\EGB98hz.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\eHZL1Dl.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\u5jZcBq.exe (Heuristics.Shuriken) -> No action taken.
c:\WINDOWS\system32\jWJqWx9.exe (Heuristics.Shuriken) -> No action taken.
c:\program files\common files\keylog.txt (Malware.Trace) -> No action taken.
c:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> No action taken.
c:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> No action taken.
c:\WINDOWS\system32\lowsec\user.ds.lll (Stolen.data) -> No action taken.