Ïîñëå ïåðåçàãðóçêè ÏÊ âñå âðåìÿ ñáèâàåòñÿ ïàðîëü äëÿ âõîäà â èíòåðíåò.
Printable View
Ïîñëå ïåðåçàãðóçêè ÏÊ âñå âðåìÿ ñáèâàåòñÿ ïàðîëü äëÿ âõîäà â èíòåðíåò.
[URL="http://virusinfo.info/showthread.php?t=7239"]Âûïîëíèòå[/URL] ñêðèïò â AVZ
[CODE]begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\wt\webdriver\webdriver.dll','');
QuarantineFile('C:\WINDOWS\internt.exe','');
QuarantineFile('C:\WINDOWS\system32\system32.exe','');
QuarantineFile('c:\windows\system32\itunesff.exe','');
RebootWindows(false);
end.[/CODE]
Ïîñëå ïåðåçàãðóçêè ïðèøëèòå ôàéëû êàðàíòèíà ïî ïðàâèëàì ðàçäåëà "Ïîìîãèòå".
Ñêà÷àéòå íîâóþ âåðñèþ AVZ è îáíîâèòå ëîãè.
[QUOTE=MaXim;108747][URL="http://virusinfo.info/showthread.php?t=7239"]Âûïîëíèòå[/URL] ñêðèïò â AVZ
[/QUOTE]
Âäîãîíêó: Ïîôèêñèòå â HJT
[CODE]R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = x "ôhE²AŠ@B*5L ª!Ä)4@ˆZ^y¤T2^y"Eˆ�Qš˜¸0y^*'"Ç x!¨šbðH*‚" ‡E’Q˜Šñ™À2Œ{ºæŒÃ^Q’¨b¢ø
á^B¢ˆãx žˆÊ(<Bbñ#ö®æÈð^�‰(TCÊ2ölWÚ•Üè4…sÚ{;VŒx@�’¢=У:Gò^ÁГ¶…cËÞs6–ÍVæ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Væ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.50.164.196/search.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Væ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = x "ôhE²AŠ@B*5L ª!Ä)4@ˆZ^y¤T2^y"Eˆ�Qš˜¸0y^*'"Ç x!¨šbðH*‚" ‡E’Q˜Šñ™À2Œ{ºæŒÃ^Q’¨b¢ø
á^B¢ˆãx žˆÊ(<Bb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Væ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Væ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = x "ôhE²AŠ@B*5L ª!Ä)4@ˆZ^y¤T2^y"Eˆ�Qš˜¸0y^*'"Ç x!¨šbðH*‚" ‡E’Q˜Šñ™À2Œ{ºæŒÃ^Q’¨b¢ø
á^B¢ˆãx žˆÊ(<Bb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Væ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = Væ¡Þàq±½myDñ4VNVx¼‚|qA>PxB)ãAˆ¤*©M>
ె¬òb¸f\™™ˆS+ä³²'èˆÎÞi³¥.Þkí'èˆp`á—D"¤*©5Ç x¼„ž"¬ø<y�¢¦ÄÇ
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = x "ôhE²AŠ@B*5L ª!Ä)4@ˆZ^y¤T2^y"Eˆ�Qš˜¸0y^*'"Ç x!¨šbðH*‚" ‡E’Q˜Šñ™À2Œ{ºæŒÃ^Q’¨b¢ø
á^B¢ˆãx žˆÊ(<Bb
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ññûëêè
O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
O1 - Hosts: <HTML><HEAD>
O1 - Hosts: <TITLE>302 Found</TITLE>
O1 - Hosts: </HEAD><BODY>
O1 - Hosts: <H1>Found</H1>
O1 - Hosts: The document has moved <A HREF="http://pharmacyonlineshop.com/">here</A>.<P>
O1 - Hosts: <HR>
O1 - Hosts: <ADDRESS>Apache/1.3.33 Server at go-gi.com Port 80</ADDRESS>
O1 - Hosts: </BODY></HTML>
O4 - HKLM\..\Run: [system32.exe] C:\WINDOWS\system32\system32.exe
O4 - HKLM\..\Run: [itunesff] C:\WINDOWS\system32\itunesff.exe -go -c60 -w2
O16 - DPF: {33331111-1111-1111-1111-611111193423} -
O16 - DPF: {33331111-1111-1111-1111-611111193429} -
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
[/CODE]
è ñêàæèòå (ïî-ñåêðåòó ;) ) - ãäå ìîæíî òàêóþ êîëëåêöèþ äè÷è íàëîâèòü? :?
Ñïàñèáî!
internt.exe è itunesff.exe - [B]Trojan.Win32.LipGame.cj[/B]
Âûïîëíèòå ñêðèïò [B]â ñâåæåé âåðñèè AVZ[/B]:
[code]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFile('C:\WINDOWS\internt.exe');
DeleteFile('c:\windows\system32\itunesff.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.[/code]
Ïîñëå ïåðåçàãðóçêè ñäåëàéòå íîâûå ëîãè.
Ïîïðîáóéòå âðó÷íóþ íàéòè ôàéë [I]C:\WINDOWS\system32\system32.exe[/I].
Åñëè íàéäåòñÿ, ïðèøëèòå ïî ïðàâèëàì (ñì. ïðèëîæåíèå 2).
Ñòàòèñòèêà ïðîâåäåííîãî ëå÷åíèÿ:
[LIST][*]Ïîëó÷åíî êàðàíòèíîâ: [B]1[/B][*]Îáðàáîòàíî ôàéëîâ: [B]3[/B][*] õîäå ëå÷åíèÿ îáíàðóæåíû âðåäîíîñíûå ïðîãðàììû:
[LIST=1][*] c:\\windows\\internt.exe - [B]Trojan.Win32.LipGame.cj[/B] (DrWEB: Trojan.LipGame)[*] c:\\windows\\system32\\itunesff.exe - [B]Trojan.Win32.LipGame.cj[/B] (DrWEB: Trojan.LipGame)[/LIST][/LIST]