:\ ! ( ) - . 22-45 ( , ~2000, ).
3 - - , , , , . .
. system32/drivers (KIS ).
: ? AVZ & HijackThis. .
7. . .. ...
.
Printable View
:\ ! ( ) - . 22-45 ( , ~2000, ).
3 - - , , , , . .
. system32/drivers (KIS ).
: ? AVZ & HijackThis. .
7. . .. ...
.
outpost .... outpost - ..
...
[code]
O2 - BHO: Google Module - {E1290342-AAFF-4f7c-9F45-D665E4BF1A00} - ktask.dll (file missing)
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Artyom\LOCALS~1\Temp\winlogon.exe
O4 - HKLM\..\Policies\Explorer\Run: [system] C:\WINDOWS\csrss.exe
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
[/code]
[code]
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DelBHO('{E1290342-AAFF-4f7c-9F45-D665E4BF1A00}');
QuarantineFile('ktask.dll','');
QuarantineFile('C:\WINDOWS\system32\cxscheca001.dll','');
QuarantineFile('ke32paag.dll','');
QuarantineFile('C:\DOCUME~1\Artyom\LOCALS~1\Temp\winlogon.exe','');
QuarantineFile('C:\WINDOWS\csrss.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys','');
DeleteFile('C:\WINDOWS\csrss.exe');
DeleteFile('C:\DOCUME~1\Artyom\LOCALS~1\Temp\winlogon.exe');
DeleteFile('ke32paag.dll');
DeleteFile('C:\WINDOWS\system32\cxscheca001.dll');
DeleteFile('ktask.dll');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
[/code]
3 ...
.
.
- ? ?
? - ?
.
...
[quote=wise-wistful;201473] .
...[/quote]
( ).
4 . (.. ! )
..: : ? ( - ?)
, .. , , temp\winlogon.exe - [b]Trojan-Proxy.Win32.Small.hu[/b], WINDOWS\csrss.exe [b]Email-Worm.Win32.Scano.ac[/b], cxscheca001.dll - [b]Trojan-PSW.Win32.Agent.im[/b] , . .
TrafficCompressor - ?
[b]Ip6Fw.sys[/b] - -- , , 2.
temp\winlogon.exe
WINDOWS\csrss.exe
cxscheca001.dll
. .. .
TrafficCompressor - .
Ip6Fw.sys - . Ip6Fw.sys.tmp .
[QUOTE=asp1r1n;201682]temp\winlogon.exe
WINDOWS\csrss.exe
cxscheca001.dll
. [/QUOTE]
... ...
Ip6Fw.sys.tmp - 3 ...
Ip6Fw.sys.tmp - 3
...
[quote=V_Bond;201920] ...[/quote]
7 :
: Invader : 煴ᓯ粐ഀ뫛本ᓯ趘뢀跌뢀 ( )
.
- - ?
... ....
- ...
....
hijackthis - .
[code]O20 - Winlogon Notify: ke32paag - C:\WINDOWS\[/code]
system ( svchost.exe system - system, ...
svchost.exe system , windows
"" - . ?
-... C:\Documents and Settings\Artyom\Local Settings\Temp\ file***.exe ( ). 3. . . - ( ). % . ...
? 3 ...
.... - ?
, Maxthon, .
?
. .... .
.
[quote=asp1r1n;204585], Maxthon, .
?
. .... .[/quote]
. . !
ktask.dll - [b]Trojan-Spy.Win32.Banker.jnj[/b]
, .... .
[size="1"][color="#666686"][B][I] 59 [/I][/B][/color][/size]
.
ktask.dll - Trojan-Spy.Win32.Banker.jnj
, .... .
--------------------
? .... ? ...
(***.)
file849.exe_ - [b]Backdoor.Win32.Agent.fxa[/b]
, .
.
C:\Documents and Settings\Artyom\Local Settings\Temp\
2 .
file849.exe_ - Backdoor.Win32.Agent.fxa - ? ?
[quote] , , , , , DoS-, , , , , .[/quote]
.
2 CureIT? ...
[size="1"][color="#666686"][B][I] 1 [/I][/B][/color][/size]
. ... .
[QUOTE=asp1r1n;206293] .
2 CureIT? ...[/QUOTE]
, Cureit!, , .
pqntdrv.sys c:\windows\system32\drivers Trojan.Spambot.2419 .
....
, . - ?
- - .
. , . .
. (.. ). , ...
...
- win.exe umatno.ru ( ....), , .
- .
, - " . Windows ME - Vista" [url]http://security-advisory.virusinfo.info/[/url]
:)
, , - [url]http://virusinfo.info/showthread.php?t=3519[/url]
:
[LIST][*] : [B]3[/B][*] : [B]6[/B][*] :
[LIST=1][*] c:\\windows\\system32\\ktask.dll - [B]Trojan-Banker.Win32.Banker.jnj[/B] (DrWEB: Trojan.PWS.Finanz)[*] \\file849.exe - [B]Backdoor.Win32.Agent.fxa[/B] (DrWEB: BackDoor.FireOn)[/LIST][/LIST]