Вложений: 1
Был процесс MicrosoftHost.exe который тормозил систему и много разных NT Kernel [Trojan.Win32.ShadowBrokers.t, HackTool.Win32.ShadowBrokers.k]
Здравствуйте. Был процесс MicrosoftHost.exe который тормозил систему и много разных NT Kernel.
Не давало запустить ни AVZ ни касперский - окно открывалось и тут же закрывалось. Кое как запустил Dr.Web CureIT. Он нашел какое то количество троянов. После этого получилось собрать статистику virusinfo. Помогите пожалуйста.
=C8=F2=EE=E3 =EB=E5=F7=E5=ED=E8=FF
=D1=F2=E0=F2=E8=F1=F2=E8=EA=E0 =EF=F0=EE=E2=E5=E4=E5=ED=ED=EE=E3=EE =EB=
=E5=F7=E5=ED=E8=FF:
[LIST][*]=CF=EE=EB=F3=F7=E5=ED=EE =EA=E0=F0=E0=ED=F2=E8=ED=EE=E2: [B]1[/B][*]=CE=E1=F0=E0=E1=EE=F2=E0=ED=EE =F4=E0=E9=EB=EE=E2: [B]87[/B][*]=C2 =F5=EE=E4=E5 =EB=E5=F7=E5=ED=E8=FF =EE=E1=ED=E0=F0=F3=E6=E5=ED=FB=
=E2=F0=E5=E4=EE=ED=EE=F1=ED=FB=E5 =EF=F0=EE=E3=F0=E0=EC=EC=FB:
[LIST=3D1][*] c:\programdata\install\utorrent.exe - [B]Trojan-PSW.Win32.Delf.=
aidq[/B][*] c:\programdata\rundll\adfw.dll - [B]Trojan.Win32.ShadowBrokers.=
p[/B] ( AVAST4: Win32:Malware-gen )[*] c:\programdata\rundll\adfw-2.dll - [B]Trojan.Win32.ShadowBroker=
s.t[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\cnli-0.dll - [B]Trojan.Win32.ShadowBroker=
s.am[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\cnli-1.dll - [B]Trojan.Win32.ShadowBroker=
s.ao[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\coli-0.dll - [B]Trojan.Win32.ShadowBroker=
s.u[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\crli-0.dll - [B]Trojan.Win32.ShadowBroker=
s.at[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\dmgd-1.dll - [B]Trojan.Win32.ShadowBroker=
s.aw[/B][*] c:\programdata\rundll\dmgd-4.dll - [B]Trojan.Win32.ShadowBroker=
s.ay[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\doublepulsar-1.3.1.exe - [B]Backdoor.Win3=
2.ShadowBrokers.f[/B] ( AVAST4: Sf:WNCryLdr-A [Trj] )[*] c:\programdata\rundll\esco-0.dll - [B]Trojan.Win32.ShadowBroker=
s.v[/B][*] c:\programdata\rundll\etchcore-0.x64.dll - [B]Exploit.Win64.Sha=
dowBrokers.c[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\etchcore-0.x86.dll - [B]Exploit.Win32.Sha=
dowBrokers.aa[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\etch-0.dll - [B]Exploit.Win32.ShadowBroke=
rs.z[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\etebcore-2.x64.dll - [B]Exploit.Win64.Sha=
dowBrokers.d[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\etebcore-2.x86.dll - [B]Exploit.Win32.Sha=
dowBrokers.ad[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\eteb-2.dll - [B]Exploit.Win32.ShadowBroke=
rs.ab[/B] ( AVAST4: Sf:WNCryLdr-A [Trj] )[*] c:\programdata\rundll\eternalblue-2.2.0.exe - [B]Exploit.Win32.=
ShadowBrokers.ae[/B] ( AVAST4: Sf:WNCryLdr-A [Trj] )[*] c:\programdata\rundll\exma.dll - [B]Trojan.Win32.ShadowBrokers.=
w[/B] ( AVAST4: Win32:Malware-gen )[*] c:\programdata\rundll\exma-1.dll - [B]Trojan.Win32.ShadowBroker=
s.x[/B][*] c:\programdata\rundll\iconv.dll - [B]Trojan.Win32.ShadowBrokers=
=2Ect[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\libcurl.dll - [B]Trojan.Win32.EquationDru=
g.jf[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\libeay32.dll - [B]HackTool.Win32.ShadowBr=
okers.n[/B] ( AVAST4: Win32:Rootkit-gen [Rtk] )[*] c:\programdata\rundll\libiconv-2.dll - [B]HackTool.Win32.Shadow=
Brokers.l[/B] ( AVAST4: Win32:Malware-gen )[*] c:\programdata\rundll\libxml2.dll - [B]HackTool.Win32.ShadowBro=
kers.k[/B][*] c:\programdata\rundll\pcla-0.dll - [B]Trojan.Win32.ShadowBroker=
s.y[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\pcrecpp-0.dll - [B]Trojan.Win32.ShadowBro=
kers.av[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\pcreposix-0.dll - [B]Trojan.Win32.ShadowB=
rokers.au[/B][*] c:\programdata\rundll\pcre-0.dll - [B]Trojan.Win32.ShadowBroker=
s.ax[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\posh.dll - [B]Trojan.Win32.ShadowBrokers.=
aa[/B] ( AVAST4: Win32:Malware-gen )[*] c:\programdata\rundll\posh-0.dll - [B]Trojan.Win32.ShadowBroker=
s.ab[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\riar.dll - [B]Trojan.Win32.ShadowBrokers.=
ar[/B] ( AVAST4: Win32:Stuxnet-C [Wrm] )[*] c:\programdata\rundll\riar-2.dll - [B]Trojan.Win32.ShadowBroker=
s.as[/B] ( AVAST4: Win32:Stuxnet-C [Wrm] )[*] c:\programdata\rundll\rundll.exe - [B]UDS:DangerousObject.Multi=
=2EGeneric[/B][*] c:\programdata\rundll\ssleay32.dll - [B]Trojan.Win32.ShadowBrok=
ers.cz[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\tibe.dll - [B]Trojan.Win32.ShadowBrokers.=
ac[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\tibe-1.dll - [B]Trojan.Win32.ShadowBroker=
s.bb[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\tibe-2.dll - [B]Trojan.Win32.ShadowBroker=
s.ad[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\trch.dll - [B]Trojan.Win32.ShadowBrokers.=
ae[/B] ( AVAST4: Win32:Malware-gen )[*] c:\programdata\rundll\trch-0.dll - [B]Trojan.Win32.ShadowBroker=
s.af[/B][*] c:\programdata\rundll\trch-1.dll - [B]Trojan.Win32.ShadowBroker=
s.ag[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\trfo.dll - [B]Trojan.Win32.ShadowBrokers.=
an[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\trfo-0.dll - [B]Trojan.Win32.ShadowBroker=
s.aq[/B][*] c:\programdata\rundll\trfo-2.dll - [B]Trojan.Win32.ShadowBroker=
s.ap[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\tucl.dll - [B]Trojan.Win32.ShadowBrokers.=
ah[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\tucl-1.dll - [B]Trojan.Win32.ShadowBroker=
s.ai[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\ucl.dll - [B]Trojan.Win32.Shadowbrokers.c=
o[/B][*] c:\programdata\rundll\xdvl-0.dll - [B]Trojan.Win32.ShadowBroker=
s.ak[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\x64.dll - [B]HEUR:Trojan.Win32.Blouiroet.=
gen[/B] ( AVAST4: Win64:Malware-gen )[*] c:\programdata\rundll\x86.dll - [B]HEUR:Trojan.Win32.Blouiroet.=
gen[/B] ( BitDefender: Gen:Trojan.Heur.LP.fu4@aKVfA7ei, AVAST4: Win32:=
Trojan-gen )[*] c:\programdata\rundll\zibe.dll - [B]Trojan.Win32.ShadowBrokers.=
al[/B] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\rundll\zlib1.dll - [B]Trojan.Win32.EquationDrug.=
dp[/B] ( AVAST4: Win32:Malware-gen )[*] c:\programdata\rundll\2x64.dll - [B]HEUR:Trojan.Win32.Blouiroet=
=2Egen[/B] ( AVAST4: Win64:Malware-gen )[*] c:\programdata\rundll\2x86.dll - [B]HEUR:Trojan.Win32.Blouiroet=
=2Egen[/B] ( BitDefender: Gen:Trojan.Heur.LP.fu4@aKVfA7ei, AVAST4: Win=
32:Trojan-gen )[*] c:\programdata\setup\update.exe - [B]UDS:DangerousObject.Multi.=
Generic[/B][*] c:\programdata\windows\install.bat - [B]Trojan.BAT.Agent.bhf[/B=
] ( AVAST4: Other:Malware-gen [Trj] )[*] c:\programdata\windowstask\amd.exe - [B]HEUR:Trojan.Win32.Miner=
=2Egen[/B] ( AVAST4: Win64:CoinminerX-gen [Trj] )[*] c:\programdata\windowstask\microsofthost.exe - [B]HEUR:Trojan.W=
in32.Miner.gen[/B] ( AVAST4: Win64:CoinminerX-gen [Trj] )[*] c:\rdp\rdpwinst.exe - [B]not-a-virus:RemoteAdmin.Win32.RDPWrap.h=
[/B][/LIST][/LIST]
=D0=E5=EA=EE=EC=E5=ED=E4=E0=F6=E8=E8:
[LIST=3D1][*]=CE=E1=ED=E0=F0=F3=E6=E5=ED=FB =F2=F0=EE=FF=ED=F1=EA=E8=E5 =EF=F0=EE=
=E3=F0=E0=EC=EC=FB =EA=EB=E0=F1=F1=E0 Trojan-PSW/Trojan-Spy - =ED=E0=F1=
=F2=EE=FF=F2=E5=EB=FC=ED=EE =F0=E5=EA=EE=EC=E5=ED=E4=F3=E5=F2=F1=FF =EF=
=EE=EC=E5=ED=FF=F2=FC =E2=F1=E5 =EF=E0=F0=EE=EB=E8 ![/LIST]