Классика
В AVZ выполните скрипт:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\documents and settings\user.grafor-5460dd70\local settings\application data\lsass.exe');
TerminateProcessByName('c:\documents and settings\networkservice.nt authority\local settings\application data\lsass.exe');
TerminateProcessByName('c:\documents and settings\networkservice.nt authority\local settings\application data\services.exe');
TerminateProcessByName('c:\documents and settings\user.grafor-5460dd70\local settings\application data\services.exe');
TerminateProcessByName('c:\documents and settings\user.grafor-5460dd70\local settings\application data\winlogon.exe');
TerminateProcessByName('c:\documents and settings\networkservice.nt authority\local settings\application data\winlogon.exe');
QuarantineFile('7668-NendangBro.com','');
QuarantineFile('cmd-brontok.exe','');
QuarantineFile('C:\WINDOWS\KesenjanganSosial.exe','');
QuarantineFile('C:\Documents and Settings\user.GRAFOR-5460DD70\Главное меню\Программы\Автозагрузка\Empty.pif','');
QuarantineFile('C:\Documents and Settings\user.GRAFOR-5460DD70\Local Settings\Application Data\br14577on.exe','');
QuarantineFile('C:\Documents and Settings\NetworkService.NT AUTHORITY\Главное меню\Программы\Автозагрузка\Empty.pif','');
QuarantineFile('C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\br4743on.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\ifp700.sys','');
QuarantineFile('C:\Program Files\Evernote\Evernote\LibPCRE.dll','');
QuarantineFile('C:\Program Files\Evernote\Evernote\Intl\EvernoteClipper.ru-RU.dll','');
QuarantineFile('c:\documents and settings\networkservice.nt authority\local settings\application data\winlogon.exe','');
QuarantineFile('c:\documents and settings\user.grafor-5460dd70\local settings\application data\winlogon.exe','');
QuarantineFile('c:\documents and settings\user.grafor-5460dd70\local settings\application data\services.exe','');
QuarantineFile('c:\documents and settings\networkservice.nt authority\local settings\application data\services.exe','');
QuarantineFile('c:\documents and settings\networkservice.nt authority\local settings\application data\lsass.exe','');
QuarantineFile('c:\documents and settings\user.grafor-5460dd70\local settings\application data\lsass.exe','');
QuarantineFile('C:\WINDOWS\ShellNew\RakyatKelaparan.exe','');
QuarantineFile('C:\Documents and Settings\user.GRAFOR-5460DD70\главное меню\программы\автозагрузка\empty.pif','');
QuarantineFile('C:\WINDOWS\kesenjangansosial.exe','');
QuarantineFile('C:\WINDOWS\system32\cmd-brontok.exe','');
DeleteFile('C:\WINDOWS\system32\cmd-brontok.exe');
DeleteFile('C:\WINDOWS\kesenjangansosial.exe');
DeleteFile('C:\Documents and Settings\user.GRAFOR-5460DD70\главное меню\программы\автозагрузка\empty.pif');
DeleteFile('C:\WINDOWS\ShellNew\RakyatKelaparan.exe');
DeleteFile('c:\documents and settings\user.grafor-5460dd70\local settings\application data\lsass.exe');
DeleteFile('c:\documents and settings\networkservice.nt authority\local settings\application data\lsass.exe');
DeleteFile('c:\documents and settings\networkservice.nt authority\local settings\application data\services.exe');
DeleteFile('c:\documents and settings\user.grafor-5460dd70\local settings\application data\services.exe');
DeleteFile('c:\documents and settings\user.grafor-5460dd70\local settings\application data\winlogon.exe');
DeleteFile('c:\documents and settings\networkservice.nt authority\local settings\application data\winlogon.exe');
DeleteFile('C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\br4743on.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','Tok-Cirrhatus-1860');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Tok-Cirrhatus-1860');
DeleteFile('C:\Documents and Settings\NetworkService.NT AUTHORITY\Главное меню\Программы\Автозагрузка\Empty.pif');
DeleteFile('C:\Documents and Settings\user.GRAFOR-5460DD70\Local Settings\Application Data\br14577on.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Tok-Cirrhatus-6777');
DeleteFile('C:\Documents and Settings\user.GRAFOR-5460DD70\Главное меню\Программы\Автозагрузка\Empty.pif');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Bron-Spizaetus');
DeleteFile('C:\WINDOWS\KesenjanganSosial.exe');
DeleteFile('cmd-brontok.exe');
DeleteFile('7668-NendangBro.com');
DeleteFile('c:\windows\Tasks\At1.job');
DeleteFile('c:\windows\Tasks\At2.job');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(6);
ExecuteWizard('TSW',2,2,true);
BC_Activate;
ExecuteRepair(8);
ExecuteRepair(11);
ExecuteRepair(16);
ExecuteRepair(17);
RebootWindows(true);
end.
После перезагрузки
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Пришлите карантин quarantine.zip по красной ссылке Прислать запрошенный карантин вверху темы.
Логи повторите.