Nod периодически находит fjhdyfhsn.bat BAT/KillFiles.NCB trojan и svhost грузит на 50% ЦП.
Нод начал переодически находить эту гадость fjhdyfhsn.bat BAT/KillFiles.NCB trojan и svhost грузит цп
[I] на 50%.Кусок лога нода приведен.[/I]
[I][COLOR=darkslategray]09.03.2010 12:20:10 Real-time file system protection file C:\WINDOWS\system32\fjhdyfhsn.bat BAT/KillFiles.NCB trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\cmd.exe.
25.02.2010 13:56:45 Real-time file system protection file C:\WINDOWS\system32\fjhdyfhsn.bat BAT/KillFiles.NCB trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\cmd.exe.
24.02.2010 13:28:58 Real-time file system protection file C:\WINDOWS\system32\fjhdyfhsn.bat BAT/KillFiles.NCB trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\cmd.exe.
23.02.2010 15:04:02 Real-time file system protection file C:\WINDOWS\system32\drivers\aec.sys a variant of Win32/Rootkit.Kryptik.AF trojan unable to clean NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\IEXPLORE.EXE.
23.02.2010 15:03:48 Real-time file system protection file C:\WINDOWS\system32\fjhdyfhsn.bat BAT/KillFiles.NCB trojan cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\system32\cmd.exe.[/COLOR][/I]
После запуска стандартного скрипта в AVZ нашелся один вирус в автозагрузке и svhost уже не грузит цп.Не могли бы вы подсказать остались ли еще хвосты?Логи привожу.Спасибо!