-
Èíôîðìåð 3pic
Ïîâèñ áàííåð èíôîðìåðà 3PIC. Ïðîñèò ÑÌÑ. Ýêñïëîðåð è Ôàéåðôîêñ íå çàïóñêàþòñÿ. NOD åãî íå âèäèò. Âûïîëíåíèå ñêðèïòîâ îêàçàëîñü âîçìîæíî òîëüêî â áåçîïàñíîì ðåæèìå.  èíòåðíåò âîøåë òîëüêî çàãðóçèâøèñü ÑÄ. Ñêà÷àííûå àíòèâèðóñíûå óòèëèòû (íåñêîëüêî ðàç) íå çàïóñêàþòñÿ - ïèøåò áèòûå àðõèâû.
-
Çàêðîéòå âñå ïðîãðàììû. Çàïóñòèòå AVZ. Âûïîëíèòå ñêðèïò ÷åðåç ìåíþ Ôàéë:
[code]begin
SetAVZGuardStatus(True);
SetAVZPMStatus(True);
ExecuteRepair(20);
ExecuteWizard('TSW', 2, 2, true);
QuarantineFile('C:\Program Files\ConnectionServices\ConnectionServices.dll','');
QuarantineFile('C:\WINDOWS\system32\sdra64.exe','');
QuarantineFile('C:\Documents and Settings\All Users\systems.exe','');
DeleteFile('C:\Documents and Settings\All Users\systems.exe');
DeleteFile('C:\WINDOWS\system32\sdra64.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.[/code]
Êîìïüþòåð ïåðåçàãðóçèòñÿ.
[B]Çàãðóçèòå åãî â íîðìàëüíîì ðåæèìå[/B].
Ïðèøëèòå ôàéëû èç êàðàíòèíà AVZ (ñì. ïðèëîæåíèå 3 Ïðàâèë), èñïîëüçóÿ ññûëêó [color=red][b]Ïðèñëàòü çàïðîøåííûé êàðàíòèí[/b][/color], ââåðõó ýòîé òåìû.
Ñäåëàéòå íîâûå ëîãè AVZ è ïðèëîæèòå ê ýòîé òåìå.
-
Çàãðóçèëñÿ â íîðìàëüíûé ðåæèì. Íà ïåðâûé âçãëÿä âðîäå âñå â ïîðÿäêå. Áîëüøîå ñïàñèáî çà ïîìîùü.
PS Äà, ò.ê. áûë çàãðóæåí ñ ÑÄ êîìï àâòîìàòè÷åñêè íå ïåðåçàãðóçèëñÿ. Òàê è äîëæíî áûëî áûòü?
-
Âîçìîæíî.
[url=http://virusinfo.info/showthread.php?t=4491]Ïîôèêñòå[/url] â HijackThis ñëåäóþùèå ñòðîêè:
[quote]
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O4 - HKCU\..\Run: [Shell] C:\Documents and Settings\All Users\systems.exe
[/quote]
Ïîñëå ïåðåçàãðóçêè ñäåëàéòå íîâûé ëîã HijackThis è ïðèëîæèòå ñþäà.
-
Ñäåëàë. Ïîêà âðîäå âñå ÎÊ.
-
Çëîäåé - C:\Documents and Settings\All Users\systems.exe - [B]Packed.Win32.Krap.gx [/B]([B]Trojan.Winlock.1477[/B]).
-
Èòîã ëå÷åíèÿ
Ñòàòèñòèêà ïðîâåäåííîãî ëå÷åíèÿ:
[LIST][*]Ïîëó÷åíî êàðàíòèíîâ: [B]1[/B][*]Îáðàáîòàíî ôàéëîâ: [B]1[/B][*] õîäå ëå÷åíèÿ îáíàðóæåíû âðåäîíîñíûå ïðîãðàììû:
[LIST=1][*] c:\documents and settings\all users\systems.exe - [B]Packed.Win32.Krap.gx[/B] ( DrWEB: Trojan.Winlock.1477, AVAST4: Win32:Rootkit-gen [Rtk] )[/LIST][/LIST]
Page generated in 0.00514 seconds with 10 queries