Отчет за период 12.09.2009 - 13.09.2009
[LIST][*][thread=54607]Backdoor.Win32.Kbot.sn[/thread] -> c:\windows\system32\vhosts.exe ( BitDefender: Application.Generic.180462, AVAST4: Win32:MalOb-H [Cryp] )[*][thread=54286]Backdoor.Win32.SdBot.otr[/thread] -> g:\windows\mslsrv32.exe ( DrWEB: Win32.HLLW.Recycler.6, BitDefender: Backdoor.Bot.105873, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54615]Backdoor.Win32.SdBot.owb[/thread] -> c:\windows\w7services.exe ( DrWEB: BackDoor.IRC.Letmein.13, NOD32: IRC/SdBot trojan )[*][thread=54635]Backdoor.Win32.SdBot.owj[/thread] -> c:\windows\usb_mgr.exe ( DrWEB: BackDoor.IRC.Sdbot.5096, BitDefender: Trojan.Generic.2389923, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=54632]Backdoor.Win32.TDSS.atb[/thread] -> c:\windows\system32\tdssriqp.dll ( DrWEB: Trojan.Packed.365, BitDefender: Backdoor.Generic.204137, NOD32: Win32/Agent.OIK trojan, AVAST4: Win32:Fasec [Trj] )[*][thread=54632]Backdoor.Win32.TDSS.blh[/thread] -> c:\windows\system32\tdssoiqh.dll ( DrWEB: Trojan.Packed.365, BitDefender: Trojan.TDss.AB, NOD32: Win32/Agent.ODG trojan, AVAST4: Win32:Fasec [Trj] )[*][thread=54550]Packed.Win32.Tdss.c[/thread] -> c:\windows\system32\rotscxmdtikosi.dll ( AVAST4: Win32:Alureon-CX [Rtk] )[*][thread=54550]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxkqwxyqxi.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Backdoor.Generic.209057, NOD32: Win32/Olmarik.MF trojan, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=54550]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\rotscxpuyrwowb.sys ( AVAST4: Win32:Alureon-CX [Rtk] )[*][thread=54550]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxqjwysibc.dll ( AVAST4: Win32:Alureon-CX [Rtk] )[*][thread=54671]P2P-Worm.Win32.Palevo.jaj[/thread] -> c:\autorun.inf ( BitDefender: Win32.Worm.Autorun.SS, NOD32: Win32/Peerfrag.CP worm )[*][thread=54671]P2P-Worm.Win32.Palevo.jaj[/thread] -> d:\autorun.inf ( BitDefender: Win32.Worm.Autorun.SS, NOD32: Win32/Peerfrag.CP worm )[*][thread=54644]P2P-Worm.Win32.Palevo.jpb[/thread] -> c:\recycler\s-1-5-21-6803665609-8181983029-328930339-4102\nissan.exe ( DrWEB: Win32.HLLW.Lime.18 )[*][thread=54632]Rootkit.Win32.TDSS.dbg[/thread] -> c:\windows\system32\tdssxfum.dll ( DrWEB: Trojan.Packed.365, BitDefender: Trojan.TDss.AT, NOD32: Win32/Olmarik.AW trojan, AVAST4: Win32:Fasec [Trj] )[*][thread=54641]Trojan-GameThief.Win32.Magania.caxa[/thread] -> c:\i.cmd ( DrWEB: Trojan.PWS.Wsgame.4983, BitDefender: Trojan.PWS.OnlineGames.KBXG, NOD32: Win32/PSW.OnLineGames.NMY trojan, AVAST4: Win32:JunkPoly [Cryp] )[*][thread=54641]Trojan-GameThief.Win32.Magania.caxa[/thread] -> e:\i.cmd ( DrWEB: Trojan.PWS.Wsgame.4983, BitDefender: Trojan.PWS.OnlineGames.KBXG, NOD32: Win32/PSW.OnLineGames.NMY trojan, AVAST4: Win32:JunkPoly [Cryp] )[*][thread=54641]Trojan-GameThief.Win32.Magania.caxa[/thread] -> d:\i.cmd ( DrWEB: Trojan.PWS.Wsgame.4983, BitDefender: Trojan.PWS.OnlineGames.KBXG, NOD32: Win32/PSW.OnLineGames.NMY trojan, AVAST4: Win32:JunkPoly [Cryp] )[*][thread=54641]Trojan-GameThief.Win32.Magania.caxa[/thread] -> c:\windows\system32\olhrwef.exe ( DrWEB: Trojan.PWS.Wsgame.4983, BitDefender: Trojan.PWS.OnlineGames.KBXG, NOD32: Win32/PSW.OnLineGames.NMY trojan, AVAST4: Win32:JunkPoly [Cryp] )[*][thread=54663]Trojan-Ransom.Win32.Hexzone.ide[/thread] -> c:\documents and settings\user\application data\msmedia.dll ( DrWEB: Trojan.BrowseBan.67, NOD32: Win32/Adware.Agent.NMG application )[*][thread=54615]Trojan.Win32.Agent.cwjw[/thread] -> c:\recycler\s-1-5-21-5519943831-5930381680-140875108-4773\mwau.exe ( DrWEB: BackDoor.IRC.Letmein.13, NOD32: Win32/Peerfrag.DR worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54649]Trojan.Win32.Buzus.byxy[/thread] -> c:\windows\system32\sdra64.exe ( DrWEB: Trojan.PWS.Panda.122, BitDefender: Trojan.Generic.CJ.WLC, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=54635]Worm.Win32.AInfBot.o[/thread] -> c:\windows\system32\drivers\lbtw.exe ( DrWEB: BackDoor.IRC.Bot.132, BitDefender: Worm.Generic.86870 )[*][thread=54286]Worm.Win32.AInfBot.x[/thread] -> g:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=47933]Worm.Win32.Bezopi.fh[/thread] -> c:\program files\microsoft common\svchost.exe[/LIST]
Отчет за период 13.09.2009 - 14.09.2009
[LIST][*][thread=54703]Backdoor.Win32.Bredolab.bv[/thread] -> c:\documents and settings\комп\главное меню\программы\автозагрузка\ikowin32.exe ( DrWEB: Trojan.Botnetlog.11, BitDefender: Trojan.Generic.2261336, NOD32: Win32/TrojanDownloader.Bredolab.AA trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54399]Backdoor.Win32.Hupigon.iavy[/thread] -> c:\windows\system32\winhelp32.exe ( AVAST4: Win32:Gamona [Trj] )[*][thread=54722]Backdoor.Win32.SdBot.owb[/thread] -> c:\windows\w7services.exe ( DrWEB: BackDoor.IRC.Letmein.13, NOD32: IRC/SdBot trojan )[*][thread=37678]not-a-virus:RiskTool.VBS.AutorunStub.a[/thread] -> \virus\usb_anti_autorun\usb.wsf ( DrWEB: archive: Win32.HLLW.Autoruner.7592, NOD32: VBS/AutoRun.CI worm )[*][thread=54698]not-a-virus:RiskTool.VBS.AutorunStub.a[/thread] -> \usb_anti_autorun\usb.wsf ( DrWEB: archive: Win32.HLLW.Autoruner.7592, NOD32: VBS/AutoRun.CI worm )[*][thread=37678]not-a-virus:RiskTool.VBS.AutorunStub.a[/thread] -> \virus\usb.wsf ( DrWEB: archive: Win32.HLLW.Autoruner.7592, NOD32: VBS/AutoRun.CI worm )[*][thread=54698]not-a-virus:RiskTool.VBS.AutorunStub.a[/thread] -> \usb_anti_autorun\usb_anti_autorun\usb.wsf ( DrWEB: archive: Win32.HLLW.Autoruner.7592, NOD32: VBS/AutoRun.CI worm )[*][thread=54694]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\gasfkyrgntjdvw.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Backdoor.Generic.209057, NOD32: Win32/Olmarik.MF trojan, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=54512]P2P-Worm.Win32.Palevo.guk[/thread] -> c:\recycler\s-1-5-21-3561974035-9232942039-383800058-2207\sysdate.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Vaklik.AY, AVAST4: Win32:DrWal [Drp] )[*][thread=54722]P2P-Worm.Win32.Palevo.jpa[/thread] -> c:\recycler\s-1-5-21-8068493398-4926836244-531453793-8292\mwau.exe ( DrWEB: BackDoor.IRC.Letmein.13, NOD32: Win32/Peerfrag.DR worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54677]P2P-Worm.Win32.Palevo.jpf[/thread] -> c:\recycler\s-1-5-21-5857086222-4067279526-333162075-0165\sysdate.exe ( DrWEB: Win32.HLLW.Lime.19, BitDefender: Worm.P2P.Palevo.H, NOD32: Win32/Peerfrag.DT worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=49563]P2P-Worm.Win32.Palevo.jpf[/thread] -> \s-1-5-21-5453707403-8761797174-281696498-4653\sysdate.exe ( DrWEB: Win32.HLLW.Lime.19, BitDefender: Worm.P2P.Palevo.H, NOD32: Win32/Peerfrag.DT worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54710]P2P-Worm.Win32.Palevo.jpf[/thread] -> e:\recycler\s-1-5-21-1672114350-5278355148-923043557-9948\sysdate.exe ( DrWEB: Win32.HLLW.Lime.19, BitDefender: Worm.P2P.Palevo.H, NOD32: Win32/Peerfrag.DT worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54727]P2P-Worm.Win32.Palevo.jph[/thread] -> c:\recycler\s-1-5-21-0001482296-1591076469-131033834-0862\nissan.exe ( DrWEB: Win32.HLLW.Lime.18 )[*][thread=54723]P2P-Worm.Win32.Palevo.jph[/thread] -> c:\recycler\s-1-5-21-5002001591-6870233537-910821766-1336\nissan.exe ( DrWEB: Win32.HLLW.Lime.18 )[*][thread=54741]Trojan-Downloader.Win32.Small.kfc[/thread] -> c:\windows\system32\tftp.msc[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\documents and settings\elena\рабочий стол\!!!!\пэмби.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\system volume information\_restore{4466cdec-dea6-4e19-9fb2-fdaf28677c06}\rp26\a0009512.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\documents and settings\elena\рабочий стол\!!!!\210709.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\documents and settings\elena\рабочий стол\!!!!\шмерко нск.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\documents and settings\elena\рабочий стол\!!!!\поступление.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\documents and settings\elena\рабочий стол\!!!!\230709.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\recycler\s-1-5-21-2602205876-890530419-3466218589-1005\dc547.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54447]Trojan-Downloader.Win32.VB.hkq[/thread] -> c:\windows\system32\xp-547b41f5.exe ( DrWEB: Win32.HLLW.Autoruner.2855, BitDefender: Trojan.Autorun.WW, NOD32: Win32/FlyStudio.NNJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54380]Trojan-Dropper.Win32.Pincher.vp[/thread] -> c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\nagxydgb\pin[1].exe ( DrWEB: Trojan.PWS.LDPinch.4308, AVAST4: Win32:Preald-AL [Drp] )[*][thread=54380]Trojan-Dropper.Win32.Pincher.vp[/thread] -> c:\windows\temp\rdl1a2.tmp.exe ( DrWEB: Trojan.PWS.LDPinch.4308, AVAST4: Win32:Preald-AL [Drp] )[*][thread=54669]Trojan-PSW.Win32.Small.ka[/thread] -> c:\windows\system32\msvcrt57.dll[*][thread=54708]Trojan.Win32.Autoit.xp[/thread] -> c:\documents and settings\admin.wertu-bd0fc2712\doctorweb\quarantine\hwfztf.exe ( DrWEB: Win32.HLLW.Autoruner.6013, BitDefender: Trojan.Packed.54986, AVAST4: Win32:Agent-AEEP [Trj] )[*][thread=54722]Trojan.Win32.Refroso.kaf[/thread] -> c:\dll32.exe ( DrWEB: BackDoor.IRC.Letmein.13, BitDefender: IRC-Worm.Generic.6582, NOD32: Win32/TrojanProxy.Agent.NEL trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54694]Trojan.Win32.Tdss.aqvb[/thread] -> c:\windows\system32\drivers\gasfkyyufvumnm.sys[*][thread=54666]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\32.scr ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54722]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\86.scr ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54666]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54722]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54722]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\drivers\lbtw.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54669]Worm.Win32.Bezopi.fj[/thread] -> c:\program files\microsoft common\svchost.exe ( DrWEB: Win32.HLLW.Autoruner.6326, AVAST4: Win32:Rootkit-gen [Rtk] )[/LIST]
Отчет за период 14.09.2009 - 15.09.2009
[LIST][*][thread=54755]Backdoor.Win32.HareBot.mm[/thread] -> c:\windows\system32\drivers\agp440.sys ( DrWEB: BackDoor.Siggen.784, BitDefender: Rootkit.Kobcka.Patched.Gen, AVAST4: Win32:Cutwail-Y [Trj] )[*][thread=54764]Backdoor.Win32.Knokk.p[/thread] -> c:\windows\system32\msmgr.exe[*][thread=54819]Backdoor.Win32.Knokk.q[/thread] -> c:\windows\system32\msmgr.exe ( DrWEB: BackDoor.Tasker.15, NOD32: Win32/Knock.AB trojan, AVAST4: Win32:Knock [Trj] )[*][thread=54640]Backdoor.Win32.Poison.adgn[/thread] -> c:\windows\system32\mssrv32.exe ( DrWEB: Trojan.MulDrop.32131, BitDefender: Trojan.Generic.2188210, AVAST4: Win32:VB-LWR [Drp] )[*][thread=54761]Backdoor.Win32.SdBot.mcv[/thread] -> c:\windows\system32\drivers\regvi.exe ( DrWEB: BackDoor.IRC.Sdbot.4859, BitDefender: Application.Generic.208334, NOD32: Win32/AutoRun.IRCBot.AM worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54755]Backdoor.Win32.UltimateDefender.igv[/thread] -> c:\windows\system32\drivers\beep.sys ( DrWEB: Trojan.NtRootKit.3206, BitDefender: Generic.Malware.P!.0EDB1150, AVAST4: Win32:FakeAV-NO [Rtk] )[*][thread=54843]Email-Worm.Win32.Joleee.dmc[/thread] -> c:\windows\system32\servises.exe ( DrWEB: Trojan.Spambot.4429, BitDefender: Gen:Packed.cqW@bScYB@mc, AVAST4: Win32:Walivun [Trj] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_42158.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_72864.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_51044.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_25325.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_45314.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_17101.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\temp\eraseme_45861.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dkg[/thread] -> c:\windows\system32\drivers\winlogon.exe ( DrWEB: Trojan.Packed.2483, BitDefender: Application.Generic.200100, NOD32: IRC/SdBot trojan, AVAST4: Win32:Inject-UU [Drp] )[*][thread=54826]Net-Worm.Win32.Kolab.dlw[/thread] -> c:\temp\eraseme_66236.exe ( DrWEB: BackDoor.IRC.Bot.127, BitDefender: Application.Generic.201775, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54826]Net-Worm.Win32.Kolab.dlw[/thread] -> c:\temp\eraseme_78600.exe ( DrWEB: BackDoor.IRC.Bot.127, BitDefender: Application.Generic.201775, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54826]Net-Worm.Win32.Kolab.dlw[/thread] -> c:\temp\eraseme_31785.exe ( DrWEB: BackDoor.IRC.Bot.127, BitDefender: Application.Generic.201775, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54819]Packed.Win32.Krap.x[/thread] -> c:\windows\system32\winagent.exe ( DrWEB: Trojan.Click.27621, BitDefender: Trojan.Dropper.Preald.B )[*][thread=54784]Packed.Win32.TDSS.z[/thread] -> \\?\globalroot\systemroot\system32\kbiwkmuvamdbxv.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Backdoor.Generic.209057, NOD32: Win32/Olmarik.MF trojan, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=54801]P2P-Worm.Win32.Palevo.jpn[/thread] -> c:\recycler\s-1-5-21-9284525706-8862203108-654221542-2596\sysdate.exe ( DrWEB: Win32.HLLW.Lime.20 )[*][thread=54784]Rootkit.Win32.Agent.pnr[/thread] -> c:\windows\system32\rgadta.sys ( DrWEB: Trojan.PWS.GoldSpy.2793, BitDefender: Rootkit.25030, AVAST4: Win32:Haxdoor-KI [Rtk] )[*][thread=54784]Rootkit.Win32.Agent.pnr[/thread] -> c:\windows\system32\drivers\ssport.sys ( DrWEB: Trojan.PWS.GoldSpy.2793, BitDefender: Rootkit.25030, AVAST4: Win32:Haxdoor-KI [Rtk] )[*][thread=54640]Trojan-Banker.Win32.Banker.ainr[/thread] -> c:\windows\system32\mmbank.exe ( DrWEB: Trojan.Pandora.15, BitDefender: Gen:Trojan.Heur.qmKfrXvpFjgcD, NOD32: Win32/Spy.Banker.QZC trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54764]Trojan.BAT.VKhost.u[/thread] -> c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\khuz05uz\11111111111[1].exe[*][thread=54819]Trojan-Clicker.Win32.Agent.ijt[/thread] -> c:\windows\system32\drivers\svchost.exe ( DrWEB: Trojan.Click.25482, BitDefender: Trojan.Dropper.Preald.B )[*][thread=54640]Trojan-Clicker.Win32.Delf.cij[/thread] -> c:\windows\system32\hiseav.exe ( DrWEB: Trojan.Click.26134, BitDefender: Trojan.Generic.1828663, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54755]Trojan-Downloader.Win32.Agent.cpqa[/thread] -> c:\windows\system32\sys32_nov.exe ( DrWEB: Trojan.DownLoad.41506, BitDefender: Trojan.Downloader.Cutwail.O, NOD32: Win32/TrojanDownloader.Bredolab.AA trojan )[*][thread=54755]Trojan-Downloader.Win32.FraudLoad.wraj[/thread] -> c:\windows\braviax.exe ( DrWEB: Trojan.Fakealert.5013, BitDefender: Trojan.Generic.2416549, NOD32: Win32/TrojanDownloader.FakeAlert.GU trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54755]Trojan-Downloader.Win32.FraudLoad.wraj[/thread] -> c:\windows\system32\braviax.exe ( DrWEB: Trojan.Fakealert.5013, BitDefender: Trojan.Generic.2416549, NOD32: Win32/TrojanDownloader.FakeAlert.GU trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54757]Trojan-Dropper.Win32.Agent.bchj[/thread] -> g:\windows\system32\drivers\kmixer.sys[*][thread=54757]Trojan-Dropper.Win32.Agent.bchj[/thread] -> g:\windows\system32\dllcache\kmixer.sys[*][thread=54819]Trojan-PSW.Win32.LdPinch.gzj[/thread] -> c:\windows\temp\rdl309.tmp.exe ( DrWEB: Trojan.PWS.LDPinch.4308, BitDefender: Trojan.Dropper.Preald.B, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54755]Trojan-Spy.Win32.Zbot.aaul[/thread] -> c:\documents and settings\administrator\start menu\programs\startup\ikowin32.exe ( DrWEB: Trojan.Botnetlog.11 )[*][thread=54796]Trojan-Spy.Win32.Zbot.aauq[/thread] -> c:\windows\system32\ntos.exe ( AVAST4: Win32:Trojan-gen {Other} )[*][thread=54826]Trojan.Win32.Agent.ctqf[/thread] -> c:\temp\eraseme_35473.exe ( DrWEB: BackDoor.IRC.Letmein.12, BitDefender: Backdoor.Bot.103721, NOD32: Win32/IRCBot.AOZ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54826]Trojan.Win32.Agent.ctqf[/thread] -> c:\temp\eraseme_66228.exe ( DrWEB: BackDoor.IRC.Letmein.12, BitDefender: Backdoor.Bot.103721, NOD32: Win32/IRCBot.AOZ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54826]Trojan.Win32.Agent.ctqf[/thread] -> c:\temp\eraseme_81583.exe ( DrWEB: BackDoor.IRC.Letmein.12, BitDefender: Backdoor.Bot.103721, NOD32: Win32/IRCBot.AOZ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54826]Trojan.Win32.Agent.ctqf[/thread] -> c:\temp\eraseme_86230.exe ( DrWEB: BackDoor.IRC.Letmein.12, BitDefender: Backdoor.Bot.103721, NOD32: Win32/IRCBot.AOZ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54790]Trojan.Win32.Buzus.bzba[/thread] -> c:\windows\w7services.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Generic.2424259, NOD32: Win32/Peerfrag.DR worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54790]Trojan.Win32.Buzus.bzba[/thread] -> c:\recycler\s-1-5-21-2459147434-8996691049-656440992-3979\mwau.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Generic.2424259, NOD32: Win32/Peerfrag.DR worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54780]Trojan.Win32.Patched.fr[/thread] -> c:\windows\system32\sfcfiles.dll ( DrWEB: Trojan.WinSpy.253, NOD32: Win32/Patched.FR virus, AVAST4: Win32:Patched-KP [Trj] )[*][thread=54790]Trojan.Win32.Refroso.kaf[/thread] -> c:\windows\system32\sysmgr.exe ( DrWEB: BackDoor.IRC.Letmein.13, BitDefender: IRC-Worm.Generic.6582, NOD32: Win32/TrojanProxy.Agent.NEL trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=37678]Trojan.Win32.Scar.sgk[/thread] -> \noautorun.exe ( DrWEB: Win32.HLLW.Autoruner.7593, BitDefender: Trojan.Generic.2418226, AVAST4: Win32:Delf-MNL [Trj] )[*][thread=54784]Trojan.Win32.TDSS.angk[/thread] -> c:\windows\system32\drivers\kbiwkmviqkospi.sys ( AVAST4: Win32:Alureon-CM [Rtk] )[*][thread=54286]Worm.Win32.AInfBot.x[/thread] -> g:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54844]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54730]Worm.Win32.AutoRun.gsp[/thread] -> c:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )[*][thread=54764]Worm.Win32.Bezopi.fn[/thread] -> c:\program files\microsoft common\svchost.exe[*][thread=54819]Worm.Win32.Bezopi.fp[/thread] -> c:\program files\microsoft common\svchost.exe ( DrWEB: Win32.HLLW.Autoruner.6326, BitDefender: Trojan.Dropper.Preald.B )[/LIST]
Отчет за период 15.09.2009 - 16.09.2009
[LIST][*][thread=54896]Backdoor.Win32.Knokk.q[/thread] -> c:\windows\system32\msmgr.exe ( DrWEB: BackDoor.Tasker.15, NOD32: Win32/Knock.AB trojan, AVAST4: Win32:Knock [Trj] )[*][thread=54822]Backdoor.Win32.SdBot.luy[/thread] -> c:\windows\system32\drivers\regv.bak ( DrWEB: BackDoor.IRC.Sdbot.4826, BitDefender: Application.Generic.203247, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54822]Email-Worm.Win32.Nyxem.bh[/thread] -> c:\windows\system32\mswinsck.ocx ( AVAST4: Win32:Trojan-gen {Other} )[*][thread=54925]Net-Worm.Win32.Kolab.dkv[/thread] -> g:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, NOD32: INF/Autorun virus, AVAST4: BV:AutoRun-X [Wrm] )[*][thread=54925]Net-Worm.Win32.Kolab.dkv[/thread] -> f:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, NOD32: INF/Autorun virus, AVAST4: BV:AutoRun-X [Wrm] )[*][thread=54792]Net-Worm.Win32.Kolab.dwa[/thread] -> c:\windows\system\wuauclt.exe ( DrWEB: BackDoor.IRC.Sdbot.4885, BitDefender: Trojan.Dropper.SVX, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54917]not-a-virus:AdWare.Win32.Reklosoft.v[/thread] -> c:\windows\system32\2rs23595.dll ( DrWEB: Adware.Reklosoft.4, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54894]not-a-virus:RemoteAdmin.Win32.RAdmin.20[/thread] -> c:\windows\system32\lsass32.exe ( DrWEB: Program.RemoteAdmin.75, BitDefender: Application.Generic.189840 )[*][thread=54822]Packed.Win32.Krap.x[/thread] -> c:\windows\system32\54.tmp ( DrWEB: Trojan.Spambot.2424, BitDefender: Trojan.Spammer.Tedroo.BV, AVAST4: Win32:Preald-AJ [Drp] )[*][thread=54822]Packed.Win32.Krap.x[/thread] -> c:\windows\system32\14.tmp ( DrWEB: Trojan.Spambot.2424, BitDefender: Trojan.Spammer.Tedroo.BV, AVAST4: Win32:Preald-AJ [Drp] )[*][thread=54516]P2P-Worm.Win32.Palevo.guk[/thread] -> c:\recycler\s-1-5-21-2201001760-1869113575-745208202-6502\sysdate.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Vaklik.AY, AVAST4: Win32:DrWal [Drp] )[*][thread=54822]Rootkit.Win32.Agent.jj[/thread] -> c:\windows\system32\drivers\protect.sys ( DrWEB: Trojan.NtRootKit.429, BitDefender: Trojan.Generic.2206884, NOD32: Win32/SpamTool.Agent.NAJ trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54898]Rootkit.Win32.Agent.rxs[/thread] -> c:\windows\system32\drivers\gdjlmplgjs.sys ( DrWEB: Trojan.NtRootKit.3492, BitDefender: Rootkit.Agent.AIZT, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=54896]Trojan-PSW.Win32.LdPinch.gzj[/thread] -> c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\c9yf8nmr\pin[1].exe ( DrWEB: Trojan.PWS.LDPinch.4308, BitDefender: Trojan.Dropper.Preald.B, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54730]Trojan.Win32.AutoRun.cr[/thread] -> c:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-W )[*][thread=54730]Trojan.Win32.AutoRun.cr[/thread] -> d:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-W )[*][thread=54844]Trojan.Win32.Buzus.byxb[/thread] -> c:\b4v9m7s9p9i3.exe ( DrWEB: Dialer.Zonect, BitDefender: Dialer.Generic.48229, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54886]Trojan.Win32.Buzus.bzba[/thread] -> c:\recycler\s-1-5-21-1142101419-7307829908-243288815-8388\mwau.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Generic.2424259, NOD32: Win32/Peerfrag.DR worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=51657]Trojan.Win32.Buzus.caah[/thread] -> c:\restore\k-1-3542-4232123213-7676767-8888886\rundll.exe ( DrWEB: Dialer.Siggen.121, BitDefender: Win32.Worm.Slenfbot.CU, NOD32: Win32/Agent.OZI trojan, AVAST4: Win32:Delf-LXZ [Drp] )[*][thread=54866]Trojan.Win32.Patched.fr[/thread] -> c:\windows\system32\sfcfiles.dll ( AVAST4: Win32:Patched-KP [Trj] )[*][thread=54886]Trojan.Win32.Refroso.kaf[/thread] -> c:\dll32.exe ( DrWEB: BackDoor.IRC.Letmein.13, BitDefender: IRC-Worm.Generic.6582, NOD32: Win32/TrojanProxy.Agent.NEL trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54822]Virus.Win32.Virut.ce[/thread] -> c:\windows\system\winrsc.exe ( DrWEB: Win32.Virut.56, BitDefender: Win32.Virtob.Gen.12, NOD32: Win32/Virut.NBP virus, AVAST4: Win32:Vitro )[*][thread=54917]Worm.VBS.Autorun.fw[/thread] -> e:\onlinetv.vbs ( DrWEB: VBS.Siggen.7355 )[*][thread=54917]Worm.VBS.Autorun.fw[/thread] -> c:\onlinetv.vbs ( DrWEB: VBS.Siggen.7355 )[*][thread=54917]Worm.VBS.Autorun.fw[/thread] -> d:\onlinetv.vbs ( DrWEB: VBS.Siggen.7355 )[*][thread=54844]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132 )[*][thread=54822]Worm.Win32.AutoRun.ftp[/thread] -> c:\windows\system32\drivers\sysdrv32.sys ( DrWEB: Tool.TcpZ, AVAST4: Win32:Tcpz [Tool] )[*][thread=54886]Worm.Win32.AutoRun.gsk[/thread] -> c:\docume~1\9335~1\locals~1\temp\883.exe ( DrWEB: Win32.HLLW.Lime.18, NOD32: Win32/AutoRun.IRCBot.CN worm )[*][thread=54886]Worm.Win32.AutoRun.gsk[/thread] -> c:\recycler\s-1-5-21-9705383016-2519638002-922274444-4842\mwau.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Win32.Worm.Autorun.TR )[*][thread=54886]Worm.Win32.AutoRun.gsk[/thread] -> c:\docume~1\9335~1\locals~1\temp\513.exe ( DrWEB: Win32.HLLW.Lime.18, NOD32: Win32/AutoRun.IRCBot.CN worm )[*][thread=54886]Worm.Win32.AutoRun.gsk[/thread] -> c:\windows\w7services.exe ( DrWEB: Win32.HLLW.Lime.18, NOD32: Win32/AutoRun.IRCBot.CN worm )[*][thread=54896]Worm.Win32.Bezopi.fx[/thread] -> c:\program files\microsoft common\svchost.exe ( DrWEB: Win32.HLLW.Autoruner.6326, BitDefender: Trojan.Dropper.Preald.B )[/LIST]
Отчет за период 16.09.2009 - 17.09.2009
[LIST][*][thread=54947]Net-Worm.Win32.Kido.ih[/thread] -> c:\windows\system32\ilhsez.dll ( DrWEB: Win32.HLLW.Shadow.based, BitDefender: Application.Generic.189897, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54942]Packed.Win32.Krap.w[/thread] -> c:\windows\media\sound.exe[*][thread=54942]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\rotscxvqpetsfa.sys ( AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=54951]P2P-Worm.Win32.Palevo.jqm[/thread] -> \turska475.exe[*][thread=54951]P2P-Worm.Win32.Palevo.jqn[/thread] -> \turska555.exe[*][thread=54986]Rootkit.Win32.Agent.rxs[/thread] -> c:\windows\system32\drivers\pfdpxpehkiqkw.sys ( DrWEB: Trojan.NtRootKit.3492, BitDefender: Rootkit.Agent.AIZT, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=54936]Rootkit.Win32.Agent.rxu[/thread] -> c:\windows\system32\drivers\fjuwyo.sys ( DrWEB: Trojan.NtRootKit.3417, BitDefender: Trojan.CryptRedol.Gen.3, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54936]Rootkit.Win32.Pakes.yf[/thread] -> c:\windows\system32\drivers\xwoarh.sys ( DrWEB: Trojan.NtRootKit.3418, BitDefender: Trojan.CryptRedol.Gen.3, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=54951]Trojan-Downloader.Win32.Small.anhx[/thread] -> \kajgana.exe ( DrWEB: Win32.HLLW.Autoruner.7552 )[*][thread=54950]Trojan-Ransom.Win32.Hexzone.idj[/thread] -> c:\documents and settings\michurin\application data\msmedia.dll ( DrWEB: Trojan.BrowseBan.67 )[*][thread=54322]Trojan-Spy.Win32.BZub.hhf[/thread] -> c:\windows\system32\chknt32.exe ( DrWEB: Trojan.PWS.Webmonier.178, BitDefender: Gen:Trojan.Heur.Hype.gmZ@ayikyLo, AVAST4: Win32:Fasec [Trj] )[*][thread=54942]Trojan.Win32.Autoit.xp[/thread] -> c:\documents and settings\администратор\doctorweb\quarantine\iwgfnt.exe ( DrWEB: Win32.HLLW.Autoruner.6013, BitDefender: Worm.Generic.42211, AVAST4: Win32:Agent-AEEP [Trj] )[*][thread=54983]Trojan.Win32.Patched.fr[/thread] -> c:\windows\system32\sfcfiles.dll ( DrWEB: Trojan.SfcPatch.6, AVAST4: Win32:Patched-KP [Trj] )[*][thread=37678]Trojan.Win32.Scar.sgk[/thread] -> c:\denis\antivir\!\noautorun.exe ( DrWEB: Win32.HLLW.Autoruner.7593, BitDefender: Trojan.Generic.2418226, AVAST4: Win32:Delf-MNL [Trj] )[*][thread=54885]Trojan.Win32.Shutdowner.dyc[/thread] -> c:\windows\system32\script.exe[*][thread=54924]Virus.Win32.Sality.aa[/thread] -> e:\wwvlcw.pif ( DrWEB: Win32.Sector.17, BitDefender: Win32.Sality.OG, NOD32: Win32/Sality.NAU virus, AVAST4: Win32:Sality )[*][thread=54924]Worm.Win32.AutoRun.awjw[/thread] -> e:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, NOD32: INF/Autorun.gen trojan, AVAST4: BV:AutoRun-AC [Wrm] )[/LIST]
Отчет за период 17.09.2009 - 18.09.2009
[LIST][*][thread=54642]Net-Worm.Win32.Kolab.dze[/thread] -> c:\windows\w7services.exe ( DrWEB: BackDoor.IRC.Letmein.13 )[*][thread=55045]not-a-virus:AdWare.Win32.AdSubscribe.h[/thread] -> c:\documents and settings\shedogubov\application data\adsubscribe\adsubscribe.dll ( DrWEB: Trojan.AdSubscribe.73 )[*][thread=55041]Packed.Win32.Klone.bj[/thread] -> c:\windows\system32\csrcs.exe ( DrWEB: Win32.HLLW.Autohit.10031 )[*][thread=55041]Packed.Win32.Klone.bj[/thread] -> c:\windows\system32\csrcs.bak ( DrWEB: Win32.HLLW.Autohit.10031 )[*][thread=55064]Packed.Win32.Krap.w[/thread] -> c:\program files\internet explorer\connection wizard\icwsetup.exe ( BitDefender: Trojan.Generic.2432140 )[*][thread=55000]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\kbiwkmxrlrnbvl.sys ( DrWEB: BackDoor.Tdss.407, BitDefender: Trojan.Generic.2305122, AVAST4: Win32:Alureon-CU [Rtk] )[*][thread=55035]Packed.Win32.TDSS.z[/thread] -> \\?\globalroot\systemroot\system32\gasfkyadwqxylk.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Trojan.Generic.2438994, NOD32: Win32/Olmarik.MF trojan, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=54990]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\gasfkyrjikbqvd.sys[*][thread=55025]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\gasfkyqdueemri.sys ( DrWEB: BackDoor.Tdss.516 )[*][thread=54642]P2P-Worm.Win32.Palevo.jpm[/thread] -> c:\recycler\s-1-5-21-8754583107-1122078727-421864223-7266\csvcs.exe ( DrWEB: Trojan.Packed.471, BitDefender: Trojan.Patched.BI, AVAST4: Win32:Patched-JZ [Trj] )[*][thread=55035]P2P-Worm.Win32.Palevo.jqy[/thread] -> c:\recycler\s-1-5-21-3078743177-7570837646-015386957-4778\nissan.exe ( DrWEB: Win32.HLLW.Lime.18 )[*][thread=54642]Trojan-Downloader.Win32.Pher.air[/thread] -> c:\windows\ntdrive32.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Generic.2434443, AVAST4: Win32:Inject-UZ [Trj] )[*][thread=55041]Trojan-Ransom.Win32.VB.ap[/thread] -> c:\windows\ctfmon.exe ( DrWEB: Trojan.Winlock.277 )[*][thread=55067]Trojan.Win32.AutoRun.cu[/thread] -> f:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, NOD32: INF/Autorun.gen trojan, AVAST4: BV:AutoRun-AB [Wrm] )[*][thread=55025]Trojan.Win32.Buzus.caaf[/thread] -> c:\windows\temp\uoriyfuwxd.exe ( DrWEB: Trojan.Siggen.4415 )[*][thread=54642]Trojan.Win32.Delf.owo[/thread] -> c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1859\ls888.exe ( DrWEB: BackDoor.Ack.12 )[*][thread=55064]Trojan.Win32.FraudPack.twm[/thread] -> c:\windows\system32\_scui.cpl[*][thread=55059]Trojan.Win32.Inject.aizt[/thread] -> c:\salu\know\tan.exe ( DrWEB: Win32.HLLW.Autoruner.7448, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54822]Trojan.Win32.Obfuscated.ahvq[/thread] -> c:\windows\system32\23.tmp ( DrWEB: Trojan.DownLoad.44766, BitDefender: Backdoor.Hupigon.166818, AVAST4: Win32:Hupigon-LIE [Trj] )[*][thread=55013]Worm.Win32.AInfBot.x[/thread] -> c:\windows\system32\drivers\ddwin.exe ( DrWEB: BackDoor.IRC.Bot.132, BitDefender: Trojan.Generic.2434469 )[*][thread=55000]Worm.Win32.AutoRun.gtd[/thread] -> h:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )[*][thread=41161]Worm.Win32.Emold.nr[/thread] -> c:\program files\microsoft common\svchost.exe[/LIST]
Отчет за период 18.09.2009 - 19.09.2009
[LIST][*][thread=55126]Packed.Win32.Klone.bj[/thread] -> c:\windows\system32\csrcs.exe ( DrWEB: Win32.HLLW.Autohit.7474, BitDefender: Gen:Trojan.Heur.AutoIT.Xq3@bSXP@YpO, AVAST4: Win32:Trojan-gen {Other} )[*][thread=54994]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxxdesmfyy.dll ( DrWEB: BackDoor.Tdss.476, AVAST4: Win32:Alureon-CX [Rtk] )[*][thread=55098]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\gasfkykdmejcxi.sys[*][thread=55126]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\hjgruimxonbfpm.sys ( BitDefender: Trojan.CryptRedol.Gen.3, AVAST4: Win32:Alureon-CB [Rtk] )[*][thread=55128]Trojan-Downloader.Win32.Pher.and[/thread] -> d:\windows\system32\com\comservices.exe ( DrWEB: Trojan.DownLoad.47367, BitDefender: Trojan.Generic.2446720, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55000]Trojan-Ransom.Win32.VB.ap[/thread] -> c:\windows\ctfmon.exe ( DrWEB: Trojan.Winlock.277 )[*][thread=55135]Trojan-Spy.Win32.KeyLogger.cjn[/thread] -> c:\windows\system32\mshknlernm.dll[*][thread=55078]Trojan-Spy.Win32.Zbot.abbv[/thread] -> c:\windows\system32\sdra64.exe[*][thread=55099]Trojan.Win32.AutoRun.t[/thread] -> h:\autorun.inf[*][thread=55099]Trojan.Win32.Refroso.cgd[/thread] -> h:\winamp_cache_0001\ehthumbs.exe ( DrWEB: Win32.HLLW.Autoruner.7323, BitDefender: Backdoor.Bot.104464, AVAST4: Win32:Refroso-C [Trj] )[*][thread=55100]Trojan.Win32.Scar.wxa[/thread] -> \manin192.exe ( DrWEB: Win32.HLLW.Autoruner.7612, BitDefender: Gen:Trojan.Heur.jmtarX7vEJhib, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55128]Worm.Win32.AutoRun.gsk[/thread] -> d:\recycler\s-1-5-21-4398215352-2228108331-447682143-1552\mwau.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Win32.Worm.Autorun.TR )[*][thread=55000]Worm.Win32.AutoRun.gtd[/thread] -> h:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )[/LIST]
Отчет за период 19.09.2009 - 20.09.2009
[LIST][*][thread=55147]Backdoor.Win32.Agent.aknv[/thread] -> c:\windows\system32\abcver.exe ( AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.opi[/thread] -> e:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\jnd3qkzk\compiled[1].exe ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: IRC-Worm.Generic.6585, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.opi[/thread] -> e:\windows\system32\05.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: IRC-Worm.Generic.6585, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.opi[/thread] -> e:\windows\system32\07.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: IRC-Worm.Generic.6585, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.opi[/thread] -> e:\windows\system32\41.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: IRC-Worm.Generic.6585, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.opi[/thread] -> e:\windows\system32\66.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: IRC-Worm.Generic.6585, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.opi[/thread] -> e:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\k1ajodu7\compiled[1].exe ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: IRC-Worm.Generic.6585, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.oqa[/thread] -> e:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\kl678den\repo[1].exe ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Trojan.Generic.2418523, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.oqa[/thread] -> e:\windows\system32\26.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Trojan.Generic.2418523, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.oqq[/thread] -> e:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\pwooyp75\ness[1].exe ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Worm.Generic.85732, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.oqq[/thread] -> e:\windows\system32\36.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Worm.Generic.85732, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.ore[/thread] -> e:\windows\system32\74.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Worm.Generic.79138, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.ore[/thread] -> e:\windows\system32\10.scr ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Worm.Generic.79138, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55130]Backdoor.Win32.SdBot.ore[/thread] -> e:\documents and settings\networkservice\local settings\temporary internet files\content.ie5\jnd3qkzk\faya[1].exe ( DrWEB: BackDoor.IRC.Sdbot.5190, BitDefender: Worm.Generic.79138, NOD32: IRC/SdBot trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55128]Net-Worm.Win32.Kolab.eaa[/thread] -> d:\windows\usbmngr.exe ( DrWEB: Win32.HLLW.Siggen.237, BitDefender: Trojan.Generic.2431897, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55140]Net-Worm.Win32.Kolab.eaa[/thread] -> c:\windows\usbmngr.exe ( DrWEB: Win32.HLLW.Siggen.237, BitDefender: Trojan.Generic.2431897, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55196]not-a-virus:AdWare.Win32.AdSubscribe.ag[/thread] -> c:\docume~1\7655~1\applic~1\fieryads\fieryads.dll ( DrWEB: Adware.FieryAds.22, BitDefender: Gen:Adware.Heur.OO8aQi0LgcAk )[*][thread=55153]not-a-virus:AdWare.Win32.AdSubscribe.h[/thread] -> c:\documents and settings\alex\application data\adsubscribe\adsubscribe.dll ( DrWEB: Trojan.AdSubscribe.73 )[*][thread=55196]not-a-virus:AdWare.Win32.AdSubscribe.h[/thread] -> c:\documents and settings\катя\application data\adsubscribe\adsubscribe.dll ( DrWEB: Trojan.AdSubscribe.73 )[*][thread=55205]not-a-virus:FraudTool.Win32.XPAntivirus.fkd[/thread] -> c:\program files\antiviruspro_2010\antiviruspro_2010.exe[*][thread=55035]Packed.Win32.TDSS.z[/thread] -> \\?\globalroot\systemroot\system32\gasfkyadwqxylk.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Trojan.Generic.2438994, NOD32: Win32/Olmarik.MF trojan, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=55035]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\gasfkyyiteolec.sys[*][thread=55035]P2P-Worm.Win32.Palevo.jqy[/thread] -> c:\recycler\s-1-5-21-3078743177-7570837646-015386957-4778\nissan.exe ( DrWEB: Win32.HLLW.Lime.18 )[*][thread=55195]P2P-Worm.Win32.Palevo.jrv[/thread] -> c:\recycler\s-1-5-21-1775402278-4981332992-294074916-1822\nissan.exe[*][thread=55182]Rootkit.Win32.Small.alq[/thread] -> h:\windows\system32\drivers\ndisvvan.sys ( BitDefender: Application.Generic.218059, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55153]Trojan-Downloader.Win32.Banload.ajed[/thread] -> c:\windows\system32\xwr38547.dll[*][thread=55205]Trojan-Downloader.Win32.FraudLoad.foz[/thread] -> c:\windows\system32\braviax.exe ( DrWEB: Trojan.Fakealert.5049 )[*][thread=55128]Trojan-Downloader.Win32.Pher.and[/thread] -> d:\windows\system32\com\comservices.exe ( DrWEB: Trojan.DownLoad.47367, BitDefender: Trojan.Generic.2446720, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55140]Trojan-Downloader.Win32.Pher.and[/thread] -> f:\usb\recycler\1.exe ( DrWEB: Trojan.DownLoad.47367, BitDefender: Trojan.Generic.2446720, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55140]Trojan-Downloader.Win32.Pher.and[/thread] -> c:\windows\system32\com\comservices.exe ( DrWEB: Trojan.DownLoad.47367, BitDefender: Trojan.Generic.2446720, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55196]Trojan-Downloader.Win32.Pher.nm[/thread] -> c:\windows\system32\sysmgr.exe ( DrWEB: Trojan.Spambot.3480, BitDefender: IRC-Worm.Generic.6290, NOD32: Win32/IRCBot trojan, AVAST4: Win32:Small-NBC [Drp] )[*][thread=55153]Trojan.Win32.Agent.cwxz[/thread] -> c:\windows\system32\ctfmon_lu.exe[*][thread=55140]Trojan.Win32.Buzus.caen[/thread] -> f:\recycler\s-51-9-25-3434476501-1644491933-601013336-1214\lbt.exe ( DrWEB: BackDoor.Bifrost, NOD32: Win32/Dialer.NGB trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55140]Trojan.Win32.Delf.owo[/thread] -> c:\windows\temp\932.exe ( DrWEB: BackDoor.Ack.12 )[*][thread=55140]Trojan.Win32.Delf.owo[/thread] -> c:\windows\temp\097.exe ( DrWEB: BackDoor.Ack.12 )[*][thread=55140]Trojan.Win32.Delf.owo[/thread] -> c:\windows\temp\284.exe ( DrWEB: BackDoor.Ack.12 )[*][thread=55140]Trojan.Win32.Delf.owo[/thread] -> c:\windows\temp\431.exe ( DrWEB: BackDoor.Ack.12 )[*][thread=55205]Trojan.Win32.FraudPack.uae[/thread] -> c:\windows\system32\_scui.cpl[*][thread=55160]Trojan.Win32.Sasfis.aub[/thread] -> c:\windows\sorry.exe ( NOD32: Win32/Spy.Zbot.JF trojan, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55147]Trojan.Win32.Scar.wws[/thread] -> c:\windows\system32\haid.exe ( DrWEB: BackDoor.Beizhu.2801 )[*][thread=55147]Trojan.Win32.Scar.wws[/thread] -> c:\windows\system32\panp8.exe ( DrWEB: BackDoor.Beizhu.2801 )[*][thread=55163]Virus.Win32.Sality.aa[/thread] -> c:\program files\java\jre6\bin\jqs.exe ( DrWEB: Win32.Sector.17, BitDefender: Win32.Sality.OG, NOD32: Win32/Sality.NAU virus, AVAST4: Win32:Sality )[*][thread=55140]Worm.Win32.AutoRun.gtl[/thread] -> f:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen )[/LIST]
Отчет за период 20.09.2009 - 21.09.2009
[LIST][*][thread=55267]Email-Worm.Win32.Joleee.dpc[/thread] -> c:\windows\system32\servises.dll ( BitDefender: Gen:Trojan.Heur.TDSS.bC5@gCp2mme )[*][thread=55278]not-a-virus:AdWare.Win32.AdSubscribe.aq[/thread] -> c:\documents and settings\вадя\application data\adriver\adriver.dll ( DrWEB: BackDoor.BlackHole.3666 )[*][thread=55278]not-a-virus:AdWare.Win32.AdSubscribe.at[/thread] -> c:\docume~1\7634~1\applic~1\fieryads\fieryads.dll ( DrWEB: Adware.FieryAds.22, BitDefender: Gen:Adware.Heur.OO8aQGP!0sAk )[*][thread=55257]Packed.Win32.Klone.bj[/thread] -> c:\windows\system32\csrcs.exe ( DrWEB: archive: archive: Win32.HLLW.Autoruner.based )[*][thread=55267]Packed.Win32.Krap.i[/thread] -> c:\windows\system32\servises.exe ( BitDefender: Gen:Trojan.Heur.TDSS.cyW@gyy5jxf, AVAST4: Win32:Gaoprd [Trj] )[*][thread=55257]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\rotscxiqjtphex.sys ( DrWEB: BackDoor.Tdss.512, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=55215]Trojan-GameThief.Win32.Magania.camm[/thread] -> c:\dogyx90.exe ( DrWEB: Trojan.PWS.Wsgame.12661, BitDefender: Trojan.PWS.OnlineGames.KCUR, NOD32: Win32/PSW.OnLineGames.NNU trojan, AVAST4: Win32:Kamso [Trj] )[*][thread=55215]Trojan-GameThief.Win32.Magania.camm[/thread] -> d:\dogyx90.exe ( DrWEB: Trojan.PWS.Wsgame.12661, BitDefender: Trojan.PWS.OnlineGames.KCUR, NOD32: Win32/PSW.OnLineGames.NNU trojan, AVAST4: Win32:Kamso [Trj] )[*][thread=55215]Trojan-GameThief.Win32.Magania.camm[/thread] -> e:\dogyx90.exe ( DrWEB: Trojan.PWS.Wsgame.12661, BitDefender: Trojan.PWS.OnlineGames.KCUR, NOD32: Win32/PSW.OnLineGames.NNU trojan, AVAST4: Win32:Kamso [Trj] )[*][thread=55247]Trojan-Proxy.Win32.Small.ack[/thread] -> c:\windows\temp\wpv771253178221.exe[*][thread=55215]Trojan.Win32.AutoRun.cc[/thread] -> c:\autorun.inf ( BitDefender: Trojan.PWS.Onlinegames.KCUS, NOD32: Win32/PSW.OnLineGames.NNU trojan )[*][thread=55215]Trojan.Win32.AutoRun.cc[/thread] -> e:\autorun.inf ( BitDefender: Trojan.PWS.Onlinegames.KCUS, NOD32: Win32/PSW.OnLineGames.NNU trojan )[*][thread=55215]Trojan.Win32.AutoRun.cc[/thread] -> d:\autorun.inf ( BitDefender: Trojan.PWS.Onlinegames.KCUS, NOD32: Win32/PSW.OnLineGames.NNU trojan )[*][thread=55100]Trojan.Win32.AutoRun.cx[/thread] -> c:\autorun.inf[*][thread=55013]Trojan.Win32.AutoRun.db[/thread] -> e:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, NOD32: INF/Autorun.gen trojan, AVAST4: BV:AutoRun-AB [Wrm] )[*][thread=55248]Trojan.Win32.Buzus.caco[/thread] -> c:\recycler\s-1-5-21-7319233450-2936121267-166107555-5882\mwau.exe ( DrWEB: BackDoor.IRC.Letmein.13, BitDefender: Trojan.Generic.2445799 )[*][thread=55249]Trojan.Win32.Buzus.caen[/thread] -> c:\windows\system32\drivers\lbt.exe ( DrWEB: BackDoor.Bifrost, NOD32: Win32/Dialer.NGB trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55013]Trojan.Win32.Scar.rfv[/thread] -> c:\windows\system32\drivers\dfwin.exe ( DrWEB: BackDoor.Bifrost, BitDefender: Backdoor.Generic.212103 )[*][thread=55013]Trojan.Win32.Scar.rfv[/thread] -> e:\recycler\s-51-9-25-3434476501-1644491933-601013336-1214\dfwin.exe ( DrWEB: BackDoor.Bifrost, BitDefender: Backdoor.Generic.212103 )[*][thread=55100]Worm.Win32.AutoRun.gte[/thread] -> c:\program files.exe ( DrWEB: Win32.HLLW.Autoruner.7612, BitDefender: Gen:Trojan.Heur.jmtarX7vEJhib, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55100]Worm.Win32.AutoRun.gte[/thread] -> c:\manin192.exe ( DrWEB: Win32.HLLW.Autoruner.7612, BitDefender: Gen:Trojan.Heur.jmtarX7vEJhib, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55214]Worm.Win32.VBNA.hxy[/thread] -> c:\documents and settings\admin\viuoru.exe ( DrWEB: Trojan.Siggen.4099, NOD32: Win32/AutoRun.VB.GA worm )[/LIST]
Отчет за период 21.09.2009 - 22.09.2009
[LIST][*][thread=55140]Net-Worm.Win32.Kolab.eaa[/thread] -> c:\windows\usbmngr.exe ( DrWEB: Win32.HLLW.Siggen.237, BitDefender: Trojan.Generic.2431897, AVAST4: Win32:SlenfBot-F [Wrm] )[*][thread=55310]not-a-virus:AdWare.Win32.Agent.llv[/thread] -> c:\program files\common files\target marketing agency\tmagent\extension\components\fftma.dll ( DrWEB: Adware.TMAgent.31, BitDefender: Gen:Adware.Heur.gu8@Qqd3QMbc, NOD32: Win32/Adware.TMAagent application )[*][thread=55368]Packed.Win32.Krap.x[/thread] -> c:\windows\system32\msvcrt57.dll[*][thread=55257]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxxmklrqvu.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Trojan.Generic.2438994, NOD32: Win32/Olmarik.MF trojan, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=55257]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxtlidiesd.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Backdoor.Generic.211794, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=55257]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxprnjspmy.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Backdoor.Generic.211785, AVAST4: Win32:Alureon-CY [Rtk] )[*][thread=55365]Trojan-Downloader.Win32.Banload.ajed[/thread] -> c:\windows\system32\xwr59656.dll ( DrWEB: Trojan.Siggen.4610 )[*][thread=55258]Trojan-Downloader.Win32.ConHook.elm[/thread] -> c:\windows\system32\vtuts.exe ( DrWEB: Trojan.MulDrop.6181, BitDefender: Trojan.Downloader.ConHook.AI )[*][thread=55310]Trojan-GameThief.Win32.OnLineGames.yky[/thread] -> c:\windows\system32\amvo0.dll ( DrWEB: Trojan.PWS.Wsgame.3604, BitDefender: Trojan.PWS.OnlineGames.WGR, NOD32: Win32/PSW.OnLineGames.NMP trojan, AVAST4: Win32:Oliga [Trj] )[*][thread=55304]Trojan-Proxy.Win32.Small.aci[/thread] -> c:\windows\temp\wpv711253309382.exe ( BitDefender: Gen:Trojan.Heur.Hype.cy0@aaUwfAhi )[*][thread=55360]Trojan-Spy.Win32.Agent.baaf[/thread] -> c:\windows\system32\jvmod32.dll[*][thread=55336]Trojan-Spy.Win32.Zbot.rua[/thread] -> c:\windows\system32\twex.exe ( DrWEB: Trojan.Packed.366, BitDefender: Trojan.Generic.1460556, AVAST4: Win32:Falder [Trj] )[*][thread=55365]Trojan.Win32.Agent.cwxz[/thread] -> c:\windows\system32\ctfmon_lu.exe[*][thread=55312]Virus.Win32.Sality.aa[/thread] -> k:\vstjno.exe ( DrWEB: Win32.Sector.17, BitDefender: Win32.Sality.OG, NOD32: Win32/Sality.NAU virus, AVAST4: Win32:Sality )[*][thread=55310]Worm.Win32.AutoRun.dvw[/thread] -> c:\autorun.inf ( DrWEB: Win32.HLLP.Whboy.19, BitDefender: Trojan.Autorun.WO, NOD32: Win32/Fujacks.BH virus, AVAST4: VBS:Malware-gen )[*][thread=55310]Worm.Win32.AutoRun.dvw[/thread] -> d:\autorun.inf ( DrWEB: Win32.HLLP.Whboy.19, BitDefender: Trojan.Autorun.WO, NOD32: Win32/Fujacks.BH virus, AVAST4: VBS:Malware-gen )[*][thread=55312]Worm.Win32.AutoRun.gtt[/thread] -> k:\autorun.inf ( BitDefender: Trojan.AutorunINF.Gen, NOD32: INF/Autorun.gen trojan )[*][thread=55310]Worm.Win32.Fujack.cr[/thread] -> c:\windows\system32\drivers\txplatform.exe ( DrWEB: Win32.HLLP.Whboy.101, BitDefender: Worm.Fujacks.N, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55310]Worm.Win32.Fujack.cr[/thread] -> d:\ўўўўўў.exe ( DrWEB: Win32.HLLP.Whboy.101, BitDefender: Worm.Fujacks.N, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55310]Worm.Win32.Fujack.cr[/thread] -> c:\ўўўўўў.exe ( DrWEB: Win32.HLLP.Whboy.101, BitDefender: Worm.Fujacks.N, AVAST4: Win32:Rootkit-gen [Rtk] )[/LIST]
Отчет за период 22.09.2009 - 23.09.2009
[LIST][*][thread=55415]not-a-virus:AdWare.Win32.Cinmus.aizh[/thread] -> c:\windows\system32\drivers\pnpmem.sys ( BitDefender: Gen:Rootkit.Heur.jCZ@cCapodm, AVAST4: Win32:Cinmus-J [Rtk] )[*][thread=55415]not-a-virus:AdWare.Win32.Cinmus.aizh[/thread] -> c:\windows\temp\acpidisk.sys ( DrWEB: Trojan.DownLoader.origin, BitDefender: Gen:Rootkit.Heur.jyZ@cuHYMgd, AVAST4: Win32:Cinmus-J [Rtk] )[*][thread=55415]not-a-virus:AdWare.Win32.Cinmus.heur[/thread] -> c:\windows\microsoft\winsys.dll ( BitDefender: DeepScan:Generic.Adw.Cinmus.2.848573A4, AVAST4: Win32:Cinmus-AU [Adw] )[*][thread=55429]Packed.Win32.Krap.x[/thread] -> c:\windows\system32\msvcrt57.dll ( DrWEB: Trojan.DownLoad.5244, BitDefender: Trojan.Dropper.Preald.B )[*][thread=55421]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\alil.dll ( DrWEB: BackDoor.Tdss.345, BitDefender: Trojan.CryptRedol.Gen.2, AVAST4: Win32:Alureon-CH [Rtk] )[*][thread=54999]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxwvwulqon.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Trojan.Generic.2371860, AVAST4: Win32:Alureon-CX [Rtk] )[*][thread=55421]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\rotscxpixfvidx.sys ( DrWEB: Trojan.NtRootKit.3433, BitDefender: Trojan.Generic.2373817, AVAST4: Win32:Alureon-CU [Rtk] )[*][thread=55390]Packed.Win32.TDSS.z[/thread] -> \\?\globalroot\systemroot\system32\gasfkysxttyiib.dll ( DrWEB: Trojan.Packed.2788, AVAST4: Win32:Alureon-DA [Rtk] )[*][thread=54999]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\rotscxbyevspre.dll ( DrWEB: Trojan.Packed.2788, BitDefender: Trojan.Generic.2372003, AVAST4: Win32:Alureon-CX [Rtk] )[*][thread=55255]P2P-Worm.Win32.Palevo.jsv[/thread] -> c:\recycler\s-1-5-21-5097733036-7679898657-991239519-9544\nissan.exe ( DrWEB: Win32.HLLW.Lime.18 )[*][thread=55386]Rootkit.Win32.Pakes.tx[/thread] -> c:\windows.0\system32\drivers\pjcllxtt.sys ( DrWEB: Trojan.NtRootKit.2682, BitDefender: Backdoor.Rootkit.X, NOD32: Win32/Agent.NWF trojan, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55386]Rootkit.Win32.Pakes.tx[/thread] -> c:\windows.0\system32\drivers\uszcxktn.sys ( DrWEB: Trojan.NtRootKit.2682, BitDefender: Backdoor.Rootkit.X, NOD32: Win32/Agent.NWF trojan, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55386]Rootkit.Win32.Pakes.tx[/thread] -> c:\windows.0\system32\drivers\svqobczw.sys ( DrWEB: Trojan.NtRootKit.2682, BitDefender: Backdoor.Rootkit.X, NOD32: Win32/Agent.NWF trojan, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55326]Rootkit.Win32.Small.ut[/thread] -> c:\program files\microsoft common\svchost.exe[*][thread=55314]Rootkit.Win32.Small.ut[/thread] -> g:\autorun.exe[*][thread=55314]Rootkit.Win32.Small.ut[/thread] -> c:\program files\microsoft common\svchost.exe[*][thread=55415]Rootkit.Win32.Zybr.x[/thread] -> c:\windows\system32\drivers\cdmtn.sys ( DrWEB: Trojan.RKDoor.56, BitDefender: Gen:Rootkit.Heur.bqW@hGFSIPb, NOD32: Win32/Koutodoor.EH trojan, AVAST4: Win32:RtkDL [Rtk] )[*][thread=55415]Trojan-Downloader.Win32.Agent.cqel[/thread] -> c:\windows\system32\blbrunsrv.dll ( DrWEB: Trojan.DownLoad.47520 )[*][thread=55395]Trojan-Downloader.Win32.Small.anhp[/thread] -> \avz00003.dta ( DrWEB: Trojan.DownLoad.47167, NOD32: Win32/Oficla.F trojan, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan-Dropper.Win32.Agent.bben[/thread] -> c:\recycler\s-1-5-21-8175887972-1683311007-518635221-1716\csvcs.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Dropper.TEC, NOD32: Win32/Peerfrag.AU worm, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55386]Trojan-Dropper.Win32.Agent.bben[/thread] -> c:\recycler\s-1-5-21-5740467155-7048588607-606387015-4000\csvcs.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Dropper.TEC, NOD32: Win32/Peerfrag.AU worm, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55386]Trojan-Dropper.Win32.Agent.bben[/thread] -> c:\documents and settings\networkservice.nt authority\local settings\temporary internet files\content.ie5\23r7m3np\b82[1].exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Dropper.TEC, NOD32: Win32/Peerfrag.AU worm, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55386]Trojan.Win32.Agent.cwsg[/thread] -> c:\documents and settings\администратор.microsof-53c7e3\tuaxmww.exe ( DrWEB: Trojan.Packed.154, BitDefender: Trojan.Generic.2421994, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55386]Trojan.Win32.Buzus.camn[/thread] -> c:\windows.0\iexplorer7.exe ( DrWEB: BackDoor.IRC.Letmein.13 )[*][thread=55386]Trojan.Win32.Delf.owo[/thread] -> c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1859\ls888.exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\администратор.microsof-53c7e3\local settings\temp\244.exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\администратор.microsof-53c7e3\local settings\temporary internet files\content.ie5\3sp539oq\vs8[1].exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\администратор.microsof-53c7e3\local settings\temp\421.exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\администратор.microsof-53c7e3\local settings\temp\217.exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55388]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\artcell\local settings\temp\360.exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\администратор.microsof-53c7e3\local settings\temp\220.exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55388]Trojan.Win32.Delf.owo[/thread] -> c:\documents and settings\artcell\local settings\temporary internet files\content.ie5\7erz6jpx\vs8[1].exe ( DrWEB: BackDoor.Ack.12, BitDefender: Trojan.Generic.2454005, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55386]Trojan.Win32.Inject.ajfn[/thread] -> c:\recycler\s-1-5-21-1606411818-6195225655-987190387-7691\mwau.exe ( DrWEB: Trojan.Packed.154, BitDefender: Worm.Generic.89330, NOD32: Win32/Peerfrag.DY worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55395]Trojan.Win32.Patched.fr[/thread] -> \avz00004.dta ( AVAST4: Win32:Patched-KP [Trj] )[*][thread=55415]Trojan.Win32.Scar.xpz[/thread] -> c:\windows\system32\i\g001.exe ( DrWEB: Trojan.DownLoad.47368, BitDefender: Trojan.Rincux.AW, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55314]Worm.Win32.AutoRun.fac[/thread] -> g:\autorun.inf ( DrWEB: Win32.HLLW.Autoruner.6317, NOD32: Win32/AutoRun.FakeAlert.AF worm, AVAST4: VBS:Malware-gen )[*][thread=55429]Worm.Win32.Bezopi.fj[/thread] -> c:\system volume information\_restore{d1401922-cf20-4469-ad2f-3f725f972f7c}\rp73\a0030130.exe ( DrWEB: Win32.HLLW.Autoruner.6326, BitDefender: Application.Generic.216493, AVAST4: Win32:MalOb-M [Cryp] )[*][thread=55310]Worm.Win32.Fujack.cr[/thread] -> c:\ўўўўўў.exe ( DrWEB: Win32.HLLP.Whboy.101, BitDefender: Worm.Fujacks.N, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55310]Worm.Win32.Fujack.cr[/thread] -> c:\windows\system32\drivers\txplatform.exe ( DrWEB: Win32.HLLP.Whboy.101, BitDefender: Worm.Fujacks.N, AVAST4: Win32:Rootkit-gen [Rtk] )[/LIST]
Отчет за период 23.09.2009 - 24.09.2009
[LIST][*][thread=37678]not-a-virus:AdWare.Win32.AdSubscribe.bq[/thread] -> c:\docume~1\999~1\applic~1\fieryads\fieryads.dll ( DrWEB: Adware.FieryAds.22, BitDefender: Gen:Adware.Heur.OO8aQKBi1Nvk )[*][thread=55429]Packed.Win32.Krap.x[/thread] -> c:\windows\system32\msvcrt57.dll ( DrWEB: Trojan.DownLoad.5244, BitDefender: Trojan.Dropper.Preald.B )[*][thread=55390]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\drivers\gasfkyqenqkovy.sys[*][thread=55390]Packed.Win32.TDSS.z[/thread] -> \\?\globalroot\systemroot\system32\gasfkysxttyiib.dll ( DrWEB: Trojan.Packed.2788, AVAST4: Win32:Alureon-DA [Rtk] )[*][thread=55390]Packed.Win32.TDSS.z[/thread] -> c:\windows\system32\gasfkysxttyiib.dll ( DrWEB: Trojan.Packed.2788, AVAST4: Win32:Alureon-DA [Rtk] )[*][thread=55415]Rootkit.Win32.Agent.txl[/thread] -> c:\windows\system32\drivers\pcidump.sys[*][thread=55477]Rootkit.Win32.Pakes.tx[/thread] -> c:\windows\system32\drivers\bcsjcmmb.sys ( DrWEB: Trojan.NtRootKit.2682, BitDefender: Backdoor.Rootkit.X, NOD32: Win32/Agent.NWF trojan, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55477]Rootkit.Win32.Pakes.tx[/thread] -> c:\windows\system32\drivers\lmdzwast.sys ( DrWEB: Trojan.NtRootKit.2682, BitDefender: Backdoor.Rootkit.X, NOD32: Win32/Agent.NWF trojan, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=37678]Trojan-Downloader.Win32.Agent.mis[/thread] -> c:\windows\system32\drivers\alg.exe ( DrWEB: Trojan.Sniff, BitDefender: Trojan.Downloader.Agent.AAIW, NOD32: Win32/Xorer.NAF virus, AVAST4: Win32:Trojan-gen {Other} )[*][thread=37678]Trojan-Downloader.Win32.Agent.mis[/thread] -> c:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156343.exe ( DrWEB: Trojan.Sniff, BitDefender: Trojan.Downloader.Agent.AAIW, NOD32: Win32/Xorer.NAF virus, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55445]Trojan-Downloader.Win32.FraudLoad.wsoq[/thread] -> c:\documents and settings\first\application data\svcst.exe[*][thread=55445]Trojan-Downloader.Win32.FraudLoad.wsoq[/thread] -> c:\documents and settings\first\application data\seres.exe[*][thread=37678]Trojan-GameThief.Win32.OnLineGames.mix[/thread] -> c:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156336.exe ( DrWEB: Trojan.Sniff, BitDefender: Trojan.Arposon.A, NOD32: Win32/Xorer.NAF virus )[*][thread=55477]Trojan.Win32.Agent.cwsg[/thread] -> c:\documents and settings\admin\kpfm.exe ( DrWEB: Trojan.Packed.154, BitDefender: Trojan.Generic.2421994, AVAST4: Win32:Rootkit-gen [Rtk] )[*][thread=55449]Trojan.Win32.Autoit.xp[/thread] -> c:\windows\system32\csrcs.exe ( DrWEB: Win32.HLLW.Autoruner.5957, BitDefender: Gen:Trojan.Heur.AutoIT.vmNfbeaEsLdc, AVAST4: Win32:Agent-AEEP [Trj] )[*][thread=55388]Trojan.Win32.Buzus.camn[/thread] -> c:\windows\iexplorer7.exe ( DrWEB: BackDoor.IRC.Letmein.13 )[*][thread=55477]Trojan.Win32.Buzus.camn[/thread] -> c:\windows\iexplorer7.exe ( DrWEB: BackDoor.IRC.Letmein.13 )[*][thread=55388]Trojan.Win32.Buzus.casf[/thread] -> c:\recycler\s-1-5-21-5745967341-2400785129-099043710-8735\csvcs.exe ( DrWEB: Win32.HLLW.Lime.18, BitDefender: Trojan.Generic.2458012, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55388]Trojan.Win32.Inject.ajfn[/thread] -> c:\recycler\s-1-5-21-6387259983-4986000569-938192817-9077\mwau.exe ( DrWEB: Trojan.Packed.154, BitDefender: Worm.Generic.89330, NOD32: Win32/Peerfrag.DY worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55477]Trojan.Win32.Inject.ajfn[/thread] -> c:\recycler\s-1-5-21-9144308407-2697480220-039855389-3914\mwau.exe ( DrWEB: Trojan.Packed.154, BitDefender: Worm.Generic.89330, NOD32: Win32/Peerfrag.DY worm, AVAST4: Win32:Trojan-gen {Other} )[*][thread=55477]Trojan.Win32.Refroso.kqt[/thread] -> c:\windows\system32\winpsvc.exe ( DrWEB: BackDoor.IRC.Letmein.13, BitDefender: Trojan.Dropper.Refroso.B )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp17\a0000428.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.25937.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp5\a0000279.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\dnsq.dll ( DrWEB: Win32.HLLP.Rox, BitDefender: Trojan.Generic.161552, AVAST4: Win32:Xorer-H )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp23\a0000566.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.28656.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.28843.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp23\a0001526.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> d:\pagefile.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156257.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> e:\pagefile.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp23\a0002526.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> d:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp215\a0156124.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{59f5ca68-51ba-4cbe-b206-462ac9c82650}\rp60\a0021562.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp14\a0000350.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156260.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.24000.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.28156.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp1\a0000042.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> e:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp215\a0156125.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.29078.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp19\a0000475.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.24234.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\pagefile.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> d:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156258.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{59f5ca68-51ba-4cbe-b206-462ac9c82650}\rp61\a0021606.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp3\a0000094.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp215\a0156126.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp7\a0000300.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp3\a0000153.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{f2e8e09b-d50f-4c80-a6b9-25f34cf01c44}\rp3\a0000110.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\system volume information\_restore{59f5ca68-51ba-4cbe-b206-462ac9c82650}\rp62\a0021658.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> f:\pagefile.pif ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Virus.Win32.Xorer.ed[/thread] -> c:\windows\system32\config\systemprofile\главное меню\программы\автозагрузка\~.exe.24671.exe ( DrWEB: Win32.HLLP.Rox.7, BitDefender: Trojan.Agent.AHAQ, AVAST4: Win32:Xorer-G )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> e:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp215\a0156112.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> e:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156210.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> f:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156211.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> f:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp215\a0156113.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> d:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp215\a0156111.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> d:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156209.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=37678]Worm.Win32.AutoRun.dck[/thread] -> c:\system volume information\_restore{f3fce362-b141-4939-b865-c8ccb550acb1}\rp216\a0156208.inf ( DrWEB: Win32.HLLW.Autoruner.868, BitDefender: Trojan.Harnig.WA, NOD32: INF/Autorun virus, AVAST4: INF:AutoRun-R [Wrm] )[*][thread=55429]Worm.Win32.Bezopi.fj[/thread] -> c:\system volume information\_restore{d1401922-cf20-4469-ad2f-3f725f972f7c}\rp73\a0030130.exe ( DrWEB: Win32.HLLW.Autoruner.6326, BitDefender: Application.Generic.216493, AVAST4: Win32:MalOb-M [Cryp] )[/LIST]