Пойманы в разделе Помогите, отчет за период 10.03.2011 - 11.03.2011
[LIST][*][thread=99195]Backdoor.Win32.Floder.e[/thread] -> c:\recycler\r-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe ( DrWEB: Win32.HLLW.Siggen.1592, BitDefender: Trojan.Generic.KD.152836, AVAST4: Win32:Trojan-gen )[*][thread=99195]Backdoor.Win32.Floder.e[/thread] -> c:\xdx.exe ( DrWEB: Win32.HLLW.Siggen.1592, BitDefender: Trojan.Generic.KD.152643, AVAST4: Win32:Trojan-gen )[*][thread=99195]Backdoor.Win32.Floder.f[/thread] -> c:\documents and settings\admin\96.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Trojan.Generic.KD.152496, AVAST4: Win32:Kolab-DZ [Trj] )[*][thread=99195]Backdoor.Win32.Floder.f[/thread] -> c:\windows\system32\53.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Trojan.Generic.KD.152496, AVAST4: Win32:Downloader-FWH [Trj] )[*][thread=99195]Backdoor.Win32.Floder.f[/thread] -> c:\windows\ggdrive32.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Trojan.Generic.KD.152496, AVAST4: Win32:Downloader-FWH [Trj] )[*][thread=99195]Backdoor.Win32.Floder.f[/thread] -> c:\windows\system32\11.exe ( DrWEB: BackDoor.IRC.Bot.166, BitDefender: Trojan.Generic.KD.152496, AVAST4: Win32:Downloader-FWH [Trj] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\networkservice.nt authority\local settings\application data\winlogon.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\user.grafor-5460dd70\local settings\application data\services.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\7668-nendangbro.com ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\windows\shellnew\rakyatkelaparan.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\windows\kesenjangansosial.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\networkservice.nt authority\local settings\application data\br4743on.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\user.grafor-5460dd70\главное меню\программы\автозагрузка\empty.pif ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\user.grafor-5460dd70\local settings\application data\br14577on.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\user.grafor-5460dd70\local settings\application data\lsass.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\networkservice.nt authority\главное меню\программы\автозагрузка\empty.pif ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\user.grafor-5460dd70\local settings\application data\winlogon.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\windows\system32\cmd-brontok.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\networkservice.nt authority\local settings\application data\services.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99150]Email-Worm.Win32.Brontok.q[/thread] -> c:\documents and settings\networkservice.nt authority\local settings\application data\lsass.exe ( DrWEB: BackDoor.Generic.2033, BitDefender: Win32.Generic.5643, NOD32: Win32/Brontok.BR worm, AVAST4: Win32:Brontok-CE [Wrm] )[*][thread=99165]Net-Worm.Win32.Kido.ih[/thread] -> c:\windows\system32\odwkx.dll ( DrWEB: Win32.HLLW.Shadow.based, BitDefender: Win32.Worm.Downadup.Gen, NOD32: Win32/Conficker.AI worm, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=99110]not-a-virus:RemoteAdmin.Win32.RAdmin.20[/thread] -> c:\windows\system32\config\svchost.exe ( DrWEB: Program.RemoteAdmin, BitDefender: Trojan.Generic.5475307 )[*][thread=99069]Trojan-Ransom.Win32.Gimemo.zj[/thread] -> d:\windows\temp\0.2850546848893666.exe ( DrWEB: Trojan.Winlock.2741, BitDefender: Trojan.Generic.KDV.152720, AVAST4: Win32:Malware-gen )[*][thread=99195]Trojan.Win32.FakeAv.bheq[/thread] -> c:\recycler\s-1-5-21-0243556031-888888379-781863308-1413\syitm.exe ( DrWEB: Win32.HLLW.Autoruner.17766, BitDefender: Gen:Variant.Kazy.15167, AVAST4: Win32:FakeSysdef-DY [Trj] )[*][thread=99195]Trojan.Win32.FakeAv.bhes[/thread] -> c:\documents and settings\admin\betd.exe ( DrWEB: Trojan.Proxy.2751, BitDefender: Gen:Variant.Kazy.15181, AVAST4: Win32:FakeSysdef-DY [Trj] )[*][thread=99171]Trojan.Win32.Pakes.orb[/thread] -> c:\windows\system32\snvhdlk.dll ( DrWEB: Trojan.Siggen.64645, BitDefender: Gen:Variant.Buzy.1642, AVAST4: Win32:Malware-gen )[*][thread=99162]Trojan.Win32.Zapchast.ezx[/thread] -> c:\windows\system32\cddpdne.dll ( DrWEB: Trojan.Siggen.64625, BitDefender: Gen:Variant.Buzy.1642, AVAST4: Win32:Malware-gen )[*][thread=99175]Trojan.Win32.Zapchast.fae[/thread] -> c:\windows\system32\pthiwcf.dll ( DrWEB: Trojan.Siggen.64645, BitDefender: Gen:Variant.Buzy.1642, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=99188]Trojan.Win32.Zapchast.fae[/thread] -> c:\windows\system32\zmxbxkd.dll ( BitDefender: Gen:Variant.Buzy.1642 )[/LIST]