!
... AVZ
Printable View
!
... AVZ
1. AVZ:
[code]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Windows\System32\Drivers\Xbq26.sys','');
DeleteFile('C:\Windows\System32\Drivers\Xbq26.sys');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.[/code]
2. :
[url]http://virusinfo.info/showthread.php?t=10387[/url]
HijackThis.
[COLOR=silver][B]1. AVZ// [/B] - #1 - [/COLOR][B][COLOR=silver][/COLOR] [/B][URL="http://virusinfo.info/attachment.php?attachmentid=20346&stc=1&d=1192698198"]avz_log.txt[/URL]
[COLOR=silver][B]2. / [/B] - [I] " "[/I] [B]" "[/B] -[/COLOR][B][COLOR=silver]/ [/COLOR][COLOR=blue] [/COLOR][/B][COLOR=blue][URL="http://virusinfo.info/attachment.php?attachmentid=20345&stc=1&d=1192698198"]avz_sysinfo.zip[/URL][/COLOR]
safe mode
ESC UP55bus.sys, ( )
[size="1"][color="#666686"][B][I] 8 [/I][/B][/color][/size]
sfc /scannow
[QUOTE]
:
: Windows File Protection
:
: 64020
: 17.10.2007
: 1:13:11
: /
:
:
Windows , c:\windows\system32\photowiz.dll . . 5.1.2600.2180.
[/QUOTE]
[QUOTE]
:
: Windows File Protection
:
: 64004
: 17.10.2007
: 1:01:25
: /
:
:
, c:\windows\system32\winlogon.exe. 5.1.2600.2180 : 0x800b0100 [ .
].[/QUOTE]
[QUOTE]
:
: Windows File Protection
:
: 64020
: 17.10.2007
: 1:01:24
: /
:
:
Windows , c:\windows\system32\winlogon.exe . . 5.1.2600.2180.
[/QUOTE]
[QUOTE]
:
: Windows File Protection
:
: 64004
: 17.10.2007
: 1:12:32
: /
:
:
, c:\windows\system32\ntsd.exe. 5.1.2600.0 : 0x800b0100 [ .
].
[/QUOTE]
[size="1"][color="#666686"][B][I] 4 [/I][/B][/color][/size]
[url]http://virusinfo.info/showthread.php?t=13321[/url]
winlogon.exe TEMP
...
[code]
O20 - Winlogon Notify: - (file missing)
O20 - Winlogon Notify: - (file missing)
O20 - Winlogon Notify: - (file missing)
O20 - Winlogon Notify: ( - ( (file missing)
O20 - Winlogon Notify: @ - @ (file missing)
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O20 - Winlogon Notify: instcat- - C:\WINDOWS\SYSTEM32\instcat.dll
O20 - Winlogon Notify: P - P (file missing)
O20 - Winlogon Notify: X - X (file missing)
O20 - Winlogon Notify: ` - ` (file missing)
O20 - Winlogon Notify: * ( - * ( (file missing)
O20 - Winlogon Notify: ˜ - ˜ (file missing)
O20 - Winlogon Notify: * - * (file missing)
[/code]
....
[code]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('instcat.dll','');
QuarantineFile('System32\DRIVERS\smtpdrv.sys','');
QuarantineFile('\??\C:\WINDOWS\system32\poof','');
QuarantineFile('\??\C:\WINDOWS\system32\kprof','');
DeleteFile('\??\C:\WINDOWS\system32\kprof');
DeleteFile('\??\C:\WINDOWS\system32\poof');
DeleteFile('System32\DRIVERS\smtpdrv.sys');
DeleteFile('C:\Windows\System32\Drivers\Xbq26.sys');
DeleteFile('Xbq26.sys');
DeleteFile('instcat.dll');
BC_ImportDeletedList;
BC_DeleteSvc('kprof');
BC_DeleteSvc('poof');
BC_DeleteSvc('smtpdr');
BC_DeleteSvc('Xbq26');
BC_Activate;
ExecuteSysClean;
RebootWindows(true);
end.
[/code]
...
:
[code]begin
BC_QrFile('C:\WINDOWS\system32\Drivers\ippflt.sys');
BC_QrFile('C:\WINDOWS\system32\Drivers\System.sys');
BC_QrFile('C:\WINDOWS\system32\System.sys');
BC_QrFile('C:\WINDOWS\System.sys');
BC_QrFile('System.sys');
BC_DeleteSvc('kprof');
BC_DeleteSvc('poof');
BC_DeleteSvc('smtpdrv');
BC_DeleteSvc('Xbq26');
BC_Activate;
RebootWindows(true);
end.[/code]
.
AVZ:
[code]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFile('C:\WINDOWS\system32\AppCert\wsil32.dll');
DeleteFile('C:\WINDOWS\system32\AppCert\wnl32.dll');
DeleteFile('C:\WINDOWS\system32\Drivers\ippflt.sys');
DeleteFile('C:\WINDOWS\system32\instcat.dll');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.[/code]
HijackThis:
[code]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://evmhedf.footchild.cn/?262495014733
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://evmhedf.footchild.cn/?262495014733
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://evmhedf.footchild.cn/?262495014733
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://evmhedf.footchild.cn/?262495014733
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (file missing)
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (file missing)
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O20 - Winlogon Notify: 8 - 8 (file missing)
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O20 - Winlogon Notify: - (file missing)
[/code]
+ .
[size="1"][color="#666686"][B][I] 10 [/I][/B][/color][/size]
Xbq26.sys - [b]Rootkit.Win32.Agent.it[/b]
instcat.dll - [b]Email-Worm.Win32.Locksky.bh[/b]
wnl32.dll - [b]Trojan-Downloader.Win32.Agent.dng[/b]
+ , ...
[b]system.sys[/b] . . , #1 () system.sys - . - .
.
, , , , .. ( ) Up55Bus.sys
, .
AVZ (.8-10 ).
system.sys?
system.sys 1 (\ )
AVZ
1. UP55 , - (DT, Alcohol ..).
2. , .8-10 ( !).
3. AVZ:
[code]
begin
ClearQuarantine;
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\DRIVERS\nwrdr.sys','');
BC_ImportQuarantineList;
BC_Activate;
RebootWindows(true);
end.[/code]
.
- - .
...
...
C:\WINDOWS\system32\drivers\symavc32.sys [B]Rootkit.Win32.Agent.it[/B]
....
....
[code]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
DeleteFile('C:\WINDOWS\system32\drivers\symavc32.sys ');
BC_ImportDeletedList;
BC_DeleteSvc('symavc32');
BC_Activate;
ExecuteSysClean;
RebootWindows(true);
end.
[/code]
C:\WINDOWS\system32\DRIVERS\nwrdr.sys AVZ- ...
...
...
[QUOTE]C:\WINDOWS\system32\DRIVERS\nwrdr.sys AVZ- ...[/QUOTE]
2 DllCache
... ... :\WINDOWS\system32\DRIVERS\
C:\WINDOWS\system32\DRIVERS\nwrdr.sys - ....
[quote=V_Bond;143566]C:\WINDOWS\system32\DRIVERS\nwrdr.sys - ....[/quote]
?
[size="1"][color="#666686"][B][I] 40 [/I][/B][/color][/size]
:
[LIST][*] : [B]5[/B][*] : [B]30[/B][*] :
[LIST=1][*] c:\\recycler\\s-1-5-21-57989841-1343024091-839522115-1003\\dc16.exe - [B]Trojan-Dropper.Win32.Agent.bzd[/B] (DrWEB: BackDoor.Bulknet.71)[*] c:\\system volume information\\_restore{9c27793b-3be3-4e5b-9711-8044f6af738d}\\rp1\\a0006266.sys - [B]Rootkit.Win32.Agent.it[/B] (DrWEB: Trojan.NtRootKit.371)[*] c:\\windows\\system32\\appcert\\wnl32.dll - [B]Trojan-Downloader.Win32.Agent.dng[/B] (DrWEB: Trojan.DownLoader.35858)[*] c:\\windows\\system32\\drivers\\symavc32.sys - [B]Rootkit.Win32.Agent.it[/B] (DrWEB: Trojan.NtRootKit.371)[*] c:\\windows\\system32\\drivers\\xbq26.sys - [B]Rootkit.Win32.Agent.it[/B] (DrWEB: Trojan.NtRootKit.371)[*] c:\\windows\\system32\\instcat.dll - [B]Email-Worm.Win32.Locksky.bh[/B] (DrWEB: Trojan.Proxy.1870)[/LIST][/LIST]