. , .
Firefox , . Google Chrome . Internet Explorer " -". Opera - " ".
Printable View
. , .
Firefox , . Google Chrome . Internet Explorer " -". Opera - " ".
() [B]volsterm[/B], !
VirusInfo.Info . , , . HiJackThis, [URL="http://virusinfo.info/pravila.html"] [/URL].
- [URL="http://virusinfo.info/content.php?r=113-virusinfo.info-donate"] [/URL].
AVZ
[code]begin
ShowMessage('! AVZ .' + #13#10 + ' .');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DelCLSID('{82C885EE-6B87-4D51-9EF4-0CFE9FADA900}');
QuarantineFile('C:\WINDOWS\system32\sdra64.exe','');
QuarantineFile('C:\Documents and Settings\USER\Application Data\AdSubscribe\AdSubscribe.dll','');
QuarantineFile('C:\WINDOWS\system32\ahwmdye.dll','');
DeleteFile('C:\WINDOWS\system32\ahwmdye.dll');
DeleteFile('C:\Documents and Settings\USER\Application Data\AdSubscribe\AdSubscribe.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{82C885EE-6B87-4D51-9EF4-0CFE9FADA900}');
DeleteFile('C:\WINDOWS\system32\sdra64.exe');
RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','userinit');
RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','userinit');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end. [/code] .
[B] 3[/B] [COLOR="Red"][U][B] [/B][/U][/COLOR]
.
.
[url="http://virusinfo.info/showpost.php?p=457118&postcount=1"] [/url]
AVZ
[code]begin
ShowMessage('! AVZ .' + #13#10 + ' .');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\WINDOWS\$NtUninstallKB969947_0$\hostperf.dll','');
BC_ImportAll;
BC_Activate;
RebootWindows(true);
end. [/code] .
[B] 3[/B] [COLOR="Red"][U][B] [/B][/U][/COLOR]
[url="http://virusinfo.info/showpost.php?p=493584&postcount=2"] [/url] [b] [/b] [code] : 5
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Backdoor.Bot) -> .
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Backdoor.Bot) -> .
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494E6CEC-7483-A4EE-0938-895519A84BC7} (Backdoor.Bot) -> .
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494E6CEC-7483-A4EE-0938-895519A84BC7} (Backdoor.Bot) -> .
HKLM\SOFTWARE\StimulProfit (Adware.Agent) -> .
: 3
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM|Shell (Hijack.Shell.Gen) -> : explorer.exe,RunDll32 "C:\WINDOWS\$NtUninstallKB969947_0$\hostperf.dll",Init -> .
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|SysDebug32 (Trojan.Agent) -> : Ύ'}ep,V>Fto,=!HhR7"V-fPCGp`/ t% t% t% t% t% t%qM#pU2CVH{ɞ t% t% t% t% t% t% t% t% t% t%3X_gH t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t%N/ -> .
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network|UID (Malware.Trace) -> : FLAT191_000FB79E -> .
: 2
C:\Documents and Settings\USER\Application Data\FieryAds (Adware.FieryAds) -> .
C:\WINDOWS\system32\lowsec (Stolen.data) -> .
: 20
C:\Documents and Settings\USER\Application Data\elro.exe (Trojan.Dropper) -> .
C:\Documents and Settings\USER\Local Settings\Temp\jar_cache7810470934985772948.tmp (Malware.Packer.GenX) -> .
C:\Documents and Settings\USER\Application Data\fieryads.dat (Adware.FieryAds) -> .
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> .
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> .
C:\WINDOWS\system32\lowsec\user.ds.lll (Stolen.data) -> .[/code]
?
?
. !
:
[LIST][*] : [B]2[/B][*] : [B]9[/B][*] :
[LIST=1][*] c:\\windows\\system32\\ahwmdye.dll - [B]Trojan-Ransom.Win32.Cidox.evg[/B] ( DrWEB: Trojan.Mayachok.1, BitDefender: Gen:Variant.Zusy.3671, NOD32: Win32/Agent.SFM trojan, AVAST4: Win32:Vundo-QT [Trj] )[/LIST][/LIST]