Вообщем словил вирус, braviax, нужна помощь!!!
Printable View
Вообщем словил вирус, braviax, нужна помощь!!!
Делали так ? [url]http://virusinfo.info/showthread.php?t=12112[/url]
Если нет, то сделайте ;)
Если да, но всё равно не выходит- тогда нужно отключить антивирус полностью и интернет :
[code]begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\winivstr.exe','');
QuarantineFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\0PDLR06Y\Installer2[2].exe','');
QuarantineFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\0PDLR06Y\Installer2[1].exe','');
QuarantineFile('C:\Documents and Settings\Алексей\Local Settings\Temp\uninst.exe','');
QuarantineFile('C:\WINDOWS\system32\cru629.dat','');
QuarantineFile('C:\Program Files\Brother\ControlCenter2\brctrcen.exe','');
QuarantineFile('C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\KCOM.SYS','');
QuarantineFile('C:\WINDOWS\system32\Drivers\mchInjDrv.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Beep.SYS','');
QuarantineFile('C:\WINDOWS\system32\univrs32.dat','');
TerminateProcessByName('c:\windows\system32\braviax.exe');
QuarantineFile('c:\windows\system32\braviax.exe','');
DeleteFile('c:\windows\system32\braviax.exe');
DeleteFile('C:\WINDOWS\system32\univrs32.dat');
DeleteFile('C:\WINDOWS\system32\cru629.dat');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temp\uninst.exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\0PDLR06Y\Installer2[1].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\0PDLR06Y\Installer2[2].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\5WX2YOPW\Installer2[10].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\5WX2YOPW\Installer2[11].exe');
DeleteFile('C:\WINDOWS\system32\winivstr.exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\XO0B55W5\Installer2[5].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\XO0B55W5\Installer2[4].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\XO0B55W5\Installer2[3].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\XO0B55W5\Installer2[2].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\XO0B55W5\Installer2[1].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\5WX2YOPW\Installer2[9].exe');
DeleteFile('C:\Documents and Settings\Алексей\Local Settings\Temporary Internet Files\Content.IE5\5WX2YOPW\Installer2[8].exe');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(6);
ExecuteRepair(8);
BC_Activate;
RebootWindows(true);
end.
[/code]
...карантин на [url]http://virusinfo.info/upload_virus.php?tid=20667[/url]
в любом случае: почистить временные файлы и сделать новые логи после лечения.
вирус braviax-делает так, что, неодин антивирусник не фурычит!!
скрипт написал;) отключите антивирус.
не помогло, braviax перебрался из windows/system32 в windows!!
Сделайте и прикрепите новый лог из пункта 10 правил и новый лог Hijackthis.
Прикрепил!!
Карантин где?
сори, я вроде загружал0_о!
Перезалил!!!
и что, никто, нечем не можит мне помочь?!
[url=http://virusinfo.info/showthread.php?t=7239]Выполните скрипт в AVZ[/url]:
[code]begin
ClearQuarantine;
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\cru629.dat','');
QuarantineFile('C:\WINDOWS\system32\Drivers\Beep.sys','');
QuarantineFile('C:\WINDOWS\system32\sfrem01.exe','');
QuarantineFile('C:\WINDOWS\system32\Drivers\mchInjDrv.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\KCOM.SYS','');
QuarantineFile('C:\WINDOWS\system32\univrs32.dat','');
QuarantineFile('C:\WINDOWS\system32\PnkBstrB.exe','');
QuarantineFile('C:\WINDOWS\system32\PnkBstrA.exe','');
QuarantineFile('C:\WINDOWS\braviax.exe','');
DeleteFile('c:\windows\braviax.exe');
DeleteFile('C:\WINDOWS\system32\cru629.dat');
BC_ImportALL;
ExecuteSysClean;
BC_QrSvc('Beep');
BC_QrSvc('PnkBstrB');
BC_QrSvc('PnkBstrA');
BC_Activate;
RebootWindows(true);
end.[/code]
Компьютер перезагрузится.
Пришлите карантин согласно приложению №3 [url=http://virusinfo.info/showthread.php?t=1235]правил[/url] (загружать здесь: [url]http://virusinfo.info/upload_virus.php?tid=20667[/url] ).
[url=http://virusinfo.info/showthread.php?t=4491]Пофиксите в HijackThis[/url]:
[code]O20 - AppInit_DLLs: cru629.dat[/code]
AVZ => Файл => Мастер поиска и устранения проблем. Категория проблемы - поставьте "Системные проблемы", степень опасности - "Все проблемы". Нажмите "Пуск". Всё найденное следует пометить и пофиксить. Данную операцию повторить для категории "Настройки и твики браузера".
spyware doctor - я бы порекомендовал деинсталлировать, AVZ и антивируса в этом плане достаточно.
Сделайте новые логи.
Статистика проведенного лечения:
[LIST][*]Получено карантинов: [B]1[/B][*]Обработано файлов: [B]88[/B][*]В ходе лечения обнаружены вредоносные программы:
[LIST=1][*] \\bcqr00011.dta - [B]Trojan.Win32.Patched.bz[/B][*] \\bcqr00012.dta - [B]Trojan.Win32.Patched.bz[/B][*] \\bcqr00013.dta - [B]Trojan.Win32.Patched.bz[/B][*] \\bcqr00014.dta - [B]Trojan.Win32.Patched.bz[/B][*] \\bcqr00019.dta - [B]Backdoor.Win32.UltimateDefender.a[/B] (DrWEB: Trojan.Fakealert.458)[*] \\bcqr00020.dta - [B]Backdoor.Win32.UltimateDefender.a[/B] (DrWEB: Trojan.Fakealert.458)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\xo0b55w5\\installer2[1].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\xo0b55w5\\installer2[2].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\xo0b55w5\\installer2[3].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\xo0b55w5\\installer2[4].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\xo0b55w5\\installer2[5].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\0pdlr06y\\installer2[1].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\0pdlr06y\\installer2[2].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[10].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[11].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[12].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[13].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[14].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[15].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[16].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[17].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[18].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[19].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[2].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[20].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[21].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[22].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[23].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[24].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[25].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[26].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[27].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[28].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[29].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[3].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[30].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[31].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[32].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[33].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[34].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[35].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[36].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[38].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[39].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[4].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[40].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[41].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[42].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[5].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[6].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[7].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[8].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temporary internet files\\content.ie5\\5wx2yopw\\installer2[9].exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\documents and settings\\алексей\\local settings\\temp\\uninst.exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[*] c:\\program files\\brother\\brmfl04g\\brstdvpt.exe - [B]Trojan.Win32.Patched.bz[/B][*] c:\\program files\\brother\\controlcenter2\\brctrcen.exe - [B]Trojan.Win32.Patched.bz[/B][*] c:\\windows\\system32\\braviax.exe - [B]Hoax.Win32.Renos.bje[/B] (DrWEB: Trojan.Packed.568)[*] c:\\windows\\system32\\cru629.dat - [B]Backdoor.Win32.Small.cbo[/B] (DrWEB: Trojan.Proxy.1739)[*] c:\\windows\\system32\\drivers\\beep.sys - [B]Backdoor.Win32.UltimateDefender.a[/B] (DrWEB: Trojan.Fakealert.458)[*] c:\\windows\\system32\\univrs32.dat - [B]not-a-virus:AdWare.Win32.Agent.zo[/B] (DrWEB: Trojan.Click.5043)[*] c:\\windows\\system32\\winivstr.exe - [B]not-a-virus:FraudTool.Win32.Reanimator.a[/B] (DrWEB: Trojan.Fakealert.452)[/LIST][/LIST]