-
: 4
-
() [B]dreadful[/B], !
VirusInfo.Info . , , . HiJackThis, [URL="http://virusinfo.info/pravila.html"] [/URL].
- [URL="http://virusinfo.info/content.php?r=113-virusinfo.info-donate"] [/URL].
-
AVZ
[code]begin
ShowMessage('! AVZ .' + #13#10 + ' .');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\windows\system32\machineupdate32.exe','');
QuarantineFile('C:\windows\TEMP\machineupdate32.exe','');
QuarantineFile('C:\windows\system32\zojzwbk.dll','');
DeleteFile('C:\windows\system32\zojzwbk.dll');
DeleteFile('C:\windows\TEMP\machineupdate32.exe');
DeleteFile('C:\windows\system32\machineupdate32.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Windows Debugger 32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Windows Debugger 32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end. [/code] .
[B] 2[/B] [COLOR="Red"][U][B] [/B][/U][/COLOR]
[url="http://virusinfo.info/showpost.php?p=457118&postcount=1"] [/url]
-
120329_183532_virus_4f74ab74a6432.zip
537175
MD5 693df65432c715c70bcd7882dab3eea7
-
: 3
-
HijackThis:
[code]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.smaxxi.biz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smaxxi.biz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.smaxxi.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smaxxi.biz
O9 - Extra button: (no name) - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - (no file)
[/code]
.
?
-
[url="http://virusinfo.info/showpost.php?p=457118&postcount=1"] [/url]
-
: 1
[QUOTE=thyrex;880213] [url="http://virusinfo.info/showpost.php?p=457118&postcount=1"] [/url][/QUOTE]
. ?
-
[QUOTE=Bratez;880185] HijackThis:
[code]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.smaxxi.biz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smaxxi.biz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.smaxxi.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smaxxi.biz
O9 - Extra button: (no name) - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - (no file)
[/code]
.
?[/QUOTE]
.
, )))
.
-
mbam :
[CODE] : 1
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|SysDebug32 (Trojan.Agent) -> : Ύ'}ep,V>Fto,=!HhR7"V t% t% t% t% t% t% t% t%D}ΓH qINq./
: t% t% t% t% t% t% t% t% t%^Kw#4k=Цh& t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t% t%՚͟I -> .
[/CODE]
AVZ :
[code]
begin
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
ClearQuarantine;
QuarantineFile('C:\Users\\AppData\Roaming\elro.exe', 'MBAM: Trojan.Dropper');
DeleteFile('C:\Users\\AppData\Roaming\elro.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
[/code]
[code]
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
[/code]
[b]quarantine.zip[/b] [B][COLOR="Red"][U] [/U][/COLOR][/B] .
mbam.
-
120330_140648_quarantine_4f75bdf8c5ac0.zip
610
MD5 c5e2c24a5742b5fd575a770ee2dca970
[size="1"][color="#666686"][B][I] 19 [/I][/B][/color][/size]
-
: 1
-
-
[QUOTE=thyrex;880490] , ?[/QUOTE]
[size="1"][color="#666686"][B][I] 5 [/I][/B][/color][/size]
?
-
-
: 1
-
-
-
:
[LIST][*] : [B]2[/B][*] : [B]11[/B][*] :
[LIST=1][*] c:\\windows\\system32\\machineupdate32.exe - [B]Trojan-Dropper.Win32.Dapato.aopi[/B] ( DrWEB: Trojan.AuxSpy.414, BitDefender: Gen:Variant.Barys.2666, AVAST4: Win32:Injector-AMY [Trj] )[*] c:\\windows\\system32\\zojzwbk.dll - [B]Trojan-Ransom.Win32.Cidox.gfy[/B] ( DrWEB: Trojan.Mayachok.552, BitDefender: Gen:Variant.Zusy.3678, NOD32: Win32/Agent.SFM trojan, AVAST4: Win32:Vundo-QT [Trj] )[*] c:\\windows\\temp\\machineupdate32.exe - [B]Trojan-Dropper.Win32.Dapato.aopi[/B] ( DrWEB: Trojan.AuxSpy.414, BitDefender: Gen:Variant.Barys.2666, AVAST4: Win32:Injector-AMY [Trj] )[/LIST][/LIST]
Page generated in 0.00883 seconds with 10 queries