-
Junior Member
- Вес репутации
- 63
Подозоение на Троян
Я снял логи с компа и в соответствии с курсом попытался проанализировать логи. Еще ничего не предпринимал. посмотрите. HHijackThis нет логов так как не я логи снимал как сниму прикреплю.
begin
QuarantineFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp','');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Temp\~DFD2ED.tmp' );
DeleteFile('C:\Documents and Settings\Александр\AppData\Local\Temp\~DFE1FE.tmp' );
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Temp\~DFD2ED.tmp');
DeleteFile('C:\Documents and Settings\Александр\Local Settings\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Appli cation Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\ ~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\AppData\Local\Temp\ ~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Application Data\Temp\~DFE1FE.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Temp\~DFD2ED.tmp');
DeleteFile('C:\Users\Александр\Local Settings\Temp\~DFE1FE.tmp');
end.
Последний раз редактировалось eppa; 22.10.2010 в 13:08.
-
Будь в курсе!
Будь в курсе!
Надоело быть жертвой? Стань профи по информационной безопасности, получай самую свежую информацию об угрозах и средствах защиты от ведущего российского аналитического центра Anti-Malware.ru:
-
Ничего необычного.
Займитесь уборкой
Microsoft MVP 2012-2016 Consumer Security
Microsoft MVP 2016 Reconnect
-