Îáíàðóæèë áàíåð, ÑÌÑ íà íîìåð 5121, òåêñò 1011400. Óáðàë êîäîì [COLOR="Red"]123839687[/COLOR].Õîòåë áû ïî÷èñòèòü êîìï. Ñòîèò AVP Workstations 6.0.3.837 c ïîñëåäíèìè îáíîâëåíèÿìè.
Printable View
Îáíàðóæèë áàíåð, ÑÌÑ íà íîìåð 5121, òåêñò 1011400. Óáðàë êîäîì [COLOR="Red"]123839687[/COLOR].Õîòåë áû ïî÷èñòèòü êîìï. Ñòîèò AVP Workstations 6.0.3.837 c ïîñëåäíèìè îáíîâëåíèÿìè.
C:\WINDOWS\system32\cmdow.exe- ñàìè ñòàâèëè?
- [URL="http://virusinfo.info/showthread.php?t=7239"]Âûïîëíèòå ñêðèïò â AVZ[/URL]
[CODE]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\cmdow.exe','');
QuarantineFile('C:\Documents and Settings\Âèêòîð\Application Data\netprotocol.exe','');
DeleteService('Netprotocol');
DeleteFile('C:\Documents and Settings\Âèêòîð\Application Data\netprotocol.exe');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
BC_Activate;
RebootWindows(true);
end.[/CODE]
Ïîñëå ïåðåçàãðóçêè:
- âûïîëíèòå òàêîé ñêðèïò
[CODE]begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.[/CODE]
- Ôàéë [B][COLOR="Red"]quarantine.zip[/COLOR][/B] èç ïàïêè AVZ çàãðóçèòå ïî ññûëêå [B][COLOR="Red"]Ïðèñëàòü çàïðîøåííûé êàðàíòèí[/COLOR][/B] ââåðõó òåìû
- Ñäåëàéòå ïîâòîðíûå ëîãè ïî [URL="http://virusinfo.info/pravila_old.html"]ïðàâèëàì[/URL] ï.2 è 3 ðàçäåëà Äèàãíîñòèêà.(virusinfo_syscheck.zip; hijackthis.log;)
cmdow.exe íå ñòàâèë
Ëîãè âûñûëàòü?
äà
Âîò íîâûå ëîãè.
- [URL="http://virusinfo.info/showthread.php?t=7239"]Âûïîëíèòå ñêðèïò â AVZ[/URL]
[CODE]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFile('C:\WINDOWS\system32\cmdow.exe');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.[/CODE]
Ïîñëå ïåðåçàãðóçêè:
- Ñäåëàéòå ïîâòîðíûé ëîã virusinfo_syscheck.zip;
Ñêðèïò âûïîëíèë. Ëîã âûñûëàþ.
÷èñòî.
Îñòàëîñü îáíîâèòü ñèñòåìó
- Óñòàíîâèòå [URL="http://www.microsoft.com/rus/windows/internet-explorer/default.aspx"]Internet-Explorer 8[/URL].(äàæå åñëè Âû åãî íå èñïîëüçóåòå)
- Ïîñòàâòå âñå ïîñëåäíèå îáíîâëåíèÿ ñèñòåìû Windows - [URL="http://www.update.microsoft.com"]òóò[/URL]
- Îáíîâèòå [URL="http://www.java.com/ru/download/manual.jsp"]Java [/URL].
- ïîñòàâòå [URL="http://www.adobe.com/go/EN_UK-H-GET-READER"]Adobe Reader 9.3[/URL] èëè óäàëèòå ñòàðûé.
- Ïðîâåäèòå ïðîöåäóðó, êîòîðàÿ îïèñàíà â ïåðâîì ñîîáùåíèè [URL="http://virusinfo.info/showthread.php?t=3519"]òóò[/URL].
Âñå âûïîëíèë. Polword, áîëüøîå ñïàñèáî!
[size="1"][color="#666686"][B][I]Äîáàâëåíî ÷åðåç 21 ìèíóòó[/I][/B][/color][/size]
Ôàéë ñîõðàí¸í êàê 100531_112819_virusinfo_files_E76694FB3A40472_4c03651321fce.zip
Ðàçìåð ôàéëà 5975936
MD5 3ce4bf5a31d12b9c3059c954cf5b1388
Ñòàòèñòèêà ïðîâåäåííîãî ëå÷åíèÿ:
[LIST][*]Ïîëó÷åíî êàðàíòèíîâ: [B]1[/B][*]Îáðàáîòàíî ôàéëîâ: [B]6[/B][*] õîäå ëå÷åíèÿ îáíàðóæåíû âðåäîíîñíûå ïðîãðàììû:
[LIST=1][*] c:\windows\system32\cmdow.exe - [B]not-a-virus:RiskTool.Win32.HideWindows[/B][/LIST][/LIST]