Пойманы в разделе Помогите, отчет за период 20.05.2010 - 21.05.2010
[LIST][*][thread=78988]Backdoor.Win32.Cetorp.gr[/thread] -> c:\documents and settings\mtisiz\local settings\temporary internet files\content.ie5\klqngxyj\2ba[2].zip ( DrWEB: BackDoor.Tofsee, BitDefender: Trojan.Generic.3686051 )[*][thread=78829]Backdoor.Win32.IRCBot.pes[/thread] -> c:\winxp\mmw.exe ( DrWEB: Trojan.PWS.Panda.307, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\056.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\016.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\029.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\431.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\306.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\890.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\temp\083.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78341]Email-Worm.Win32.Joleee.evd[/thread] -> h:\windows\system32\msupio32.exe ( DrWEB: Trojan.Packed.20264, AVAST4: Win32:Malware-gen )[*][thread=78986]not-a-virus:RemoteAdmin.Win32.RAdmin.22[/thread] -> c:\windows\system32\r_server.exe ( DrWEB: Program.RemoteAdmin.167 )[*][thread=78841]not-a-virus:RiskTool.Win32.HideWindows[/thread] -> c:\windows\system32\cmdow.exe[*][thread=78982]Packed.Win32.Krap.gx[/thread] -> c:\documents and settings\all users\systems.exe ( DrWEB: Trojan.Winlock.1718 )[*][thread=78988]Rootkit.Win32.Agent.aaew[/thread] -> c:\system volume information\_restore{358da98f-c4c1-4b11-a825-b823ed4f6225}\rp660\a0111168.sys ( DrWEB: BackDoor.Bulknet.448, BitDefender: Rootkit.Kobcka.Patched.Gen, NOD32: Win32/Protector.F virus, AVAST4: Win32:Cutwail-Y [Rtk] )[*][thread=79006]Trojan-Clicker.Win32.Delf.dpl[/thread] -> c:\windows\winexp.exe ( DrWEB: Trojan.Click1.6560, AVAST4: Win32:Malware-gen )[*][thread=78995]Trojan-Downloader.Win32.Agent.btlp[/thread] -> c:\documents and settings\администратор\doctorweb\quarantine\system.exe ( DrWEB: BackDoor.Bulknet.419, BitDefender: Worm.Generic.221677, AVAST4: Win32:Agent-QTR [Trj] )[*][thread=78995]Trojan-Downloader.Win32.Agent.btlp[/thread] -> c:\windows\system32\system.exe ( DrWEB: BackDoor.Bulknet.419, BitDefender: Worm.Generic.221677, AVAST4: Win32:Agent-QTR [Trj] )[*][thread=78995]Trojan-Downloader.Win32.Agent.btlp[/thread] -> c:\system volume information\_restore{3fa198c2-c40a-4b29-ac5d-d8731bf2e824}\rp147\a0446639.exe ( DrWEB: BackDoor.Bulknet.419, BitDefender: Worm.Generic.221677, AVAST4: Win32:Agent-QTR [Trj] )[*][thread=78995]Trojan-Downloader.Win32.Agent.btlp[/thread] -> c:\windows\userinit.exe ( DrWEB: BackDoor.Bulknet.419, BitDefender: Worm.Generic.221677, AVAST4: Win32:Agent-QTR [Trj] )[*][thread=78929]Trojan-Downloader.Win32.Agent.dqwf[/thread] -> d:\windows\system32\qaetsvstart.dll ( DrWEB: Trojan.DownLoad1.59971, BitDefender: DeepScan:Generic.Peed.B4AB7383, AVAST4: Win32:Malware-gen )[*][thread=79006]Trojan-Downloader.Win32.Delf.abnu[/thread] -> c:\windows\winlogin.exe ( BitDefender: DeepScan:Generic.Malware.SFYBVg.50D038C0, AVAST4: Win32:Lapsavok [Drp] )[*][thread=79006]Trojan-Downloader.Win32.Delf.abnv[/thread] -> c:\windows\taskmsgr.exe[*][thread=78988]Trojan-Downloader.Win32.Small.kmj[/thread] -> c:\windows\temp\tmp1983.exe ( DrWEB: Trojan.MulDrop1.15734, BitDefender: Trojan.Generic.3688172, AVAST4: Win32:Malware-gen )[*][thread=78988]Trojan-Downloader.Win32.Small.kmj[/thread] -> c:\system volume information\_restore{358da98f-c4c1-4b11-a825-b823ed4f6225}\rp660\a0117666.exe ( DrWEB: Trojan.MulDrop1.15734, BitDefender: Trojan.Generic.3688172, AVAST4: Win32:Malware-gen )[*][thread=78988]Trojan-Downloader.Win32.Small.kmj[/thread] -> c:\documents and settings\networkservice\wuaucldt.exe ( DrWEB: Trojan.MulDrop1.15734, BitDefender: Trojan.Generic.3688172, AVAST4: Win32:Malware-gen )[*][thread=78988]Trojan-Downloader.Win32.Small.kmj[/thread] -> c:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\wkz54oky\mg32[1].exe ( DrWEB: Trojan.MulDrop1.15734, BitDefender: Trojan.Generic.3688172, AVAST4: Win32:Malware-gen )[*][thread=78341]Trojan-Dropper.Win32.VB.anra[/thread] -> h:\recycler\s-1-5-21-7725606275-4322606439-691238279-3522\syscr.exe ( DrWEB: Win32.HLLW.VBNA.2, BitDefender: Worm.Generic.245742, AVAST4: Win32:Malware-gen )[*][thread=78988]Trojan-PSW.Win32.Agent.qpp[/thread] -> c:\windows\system32\implayok.exe ( DrWEB: Trojan.Siggen.64400, BitDefender: Trojan.Generic.3692232, NOD32: Win32/Wigon.HT trojan, AVAST4: Win32:Malware-gen )[*][thread=78988]Trojan-PSW.Win32.Agent.qpp[/thread] -> c:\documents and settings\networkservice\implayok.exe ( DrWEB: Trojan.Siggen.64400, BitDefender: Trojan.Generic.3692232, NOD32: Win32/Wigon.HT trojan, AVAST4: Win32:Malware-gen )[*][thread=78973]Trojan-PSW.Win32.Kates.ha[/thread] -> c:\docume~1\7ffe~1\locals~1\temp\qavovq.old[*][thread=78982]Trojan-PSW.Win32.WebMoner.tm[/thread] -> c:\program files\common files\system\webcheck.dll ( DrWEB: Trojan.PWS.Webmonier.350, BitDefender: Trojan.Generic.3793945, NOD32: Win32/Checkweb.AB trojan )[*][thread=78816]Trojan-Ransom.Win32.PinkBlocker.bhq[/thread] -> \systems.exe ( DrWEB: Trojan.Winlock.1563 )[*][thread=78956]Trojan-Ransom.Win32.PinkBlocker.bia[/thread] -> c:\documents and settings\all users\systems.exe ( DrWEB: Trojan.Winlock.1724 )[*][thread=78955]Trojan-Ransom.Win32.XBlocker.acx[/thread] -> \qwe.dll ( DrWEB: Trojan.AdultBan.25, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=78955]Trojan-Ransom.Win32.XBlocker.acx[/thread] -> c:\windows\inf\scsi.inf:q8c0r4shlxo6mb:$data ( DrWEB: Trojan.AdultBan.25, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=78953]Trojan-Spy.Win32.Agent.bftg[/thread] -> c:\windows\system32\mssfc.dll ( AVAST4: Win32:WinSpy-FP [Trj] )[*][thread=78931]Trojan-Spy.Win32.Zbot.roh[/thread] -> c:\windows\system32\~.exe ( DrWEB: Trojan.PWS.Panda.22, BitDefender: Backdoor.Bot.91981, AVAST4: Win32:Zbot-APD [Trj] )[*][thread=78988]Trojan.Win32.Agent.dthx[/thread] -> c:\windows\system32\wmicvrts.exe ( DrWEB: Trojan.MulDrop1.15573, BitDefender: Backdoor.Tofsee.Gen, AVAST4: Win32:IRCBot-DRF [Trj] )[*][thread=78913]Trojan.Win32.AutoRun.oc[/thread] -> f:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AF [Wrm] )[*][thread=78953]Trojan.Win32.BHO.ext[/thread] -> c:\windows\system32\drivers\vrxrodhn.sys ( DrWEB: Trojan.NtRootKit.1652, BitDefender: Rootkit.17589, NOD32: Win32/BHO.EXT trojan, AVAST4: Win32:Agent-PSI [Rtk] )[*][thread=78988]Trojan.Win32.Buzus.dwin[/thread] -> c:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\8325o1gf\n1b[2].zip ( DrWEB: Trojan.Packed.20052, BitDefender: Backdoor.Tofsee.Gen, AVAST4: Win32:IRCBot-DRF [Trj] )[*][thread=79006]Trojan.Win32.Scar.cgdm[/thread] -> \\?\globalroot\systemroot\system32\jufulhk.exe ( DrWEB: Trojan.DownLoad.64043 )[*][thread=79006]Trojan.Win32.Scar.cgex[/thread] -> \\?\globalroot\systemroot\system32\cspiycn.exe ( DrWEB: Trojan.PWS.Ibank.39 )[*][thread=78992]Trojan.Win32.Vilsel.adnj[/thread] -> c:\system volume information\whistler\smss.exe ( DrWEB: Win32.HLLC.Asdas.8, BitDefender: Trojan.Generic.3846055, AVAST4: Win32:Unruy-E [Trj] )[*][thread=78992]Trojan.Win32.Vilsel.adnt[/thread] -> c:\system volume information\whistler\svchost.exe ( DrWEB: Win32.HLLC.Asdas.8, BitDefender: Trojan.Generic.3846262, AVAST4: Win32:Unruy-E [Trj] )[*][thread=78853]Worm.Win32.NeKav.ck[/thread] -> \nmzzkyo.dll ( DrWEB: Trojan.Winlock.1686, AVAST4: Win32:Malware-gen )[*][thread=78816]Worm.Win32.NeKav.ck[/thread] -> c:\windows\system32\reyhup.dll ( DrWEB: Trojan.Winlock.1686, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.Peda.d[/thread] -> h:\windows\system32\60.scr ( DrWEB: BackDoor.IRC.Bot.200, BitDefender: Trojan.Generic.3922018, NOD32: Win32/AutoRun.IRCBot.FC worm, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\972.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\838.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\324.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\233.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\483.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\218.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\temp\224.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[*][thread=78341]Worm.Win32.VBNA.b[/thread] -> h:\windows\wndrive32.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Backdoor.Bot.122151, AVAST4: Win32:Malware-gen )[/LIST]