Страница 2 из 2 Первая 12
Показано с 21 по 28 из 28.

avast! находит, но не лечит (AutoIt:Balero-A2 [Wrm]) (заявка № 53535)

  1. #21
    Junior Member Репутация
    Регистрация
    02.09.2009
    Сообщений
    16
    Вес репутации
    59
    Все сделал - карантин отправлен, логи выложены.

    Какие будут дальнейшие инструкции?+)
    Вложения Вложения

  2. Будь в курсе!
    Реклама на VirusInfo

    Надоело быть жертвой? Стань профи по информационной безопасности, получай самую свежую информацию об угрозах и средствах защиты от ведущего российского аналитического центра Anti-Malware.ru:

    Anti-Malware Telegram
     

  3. #22
    Невымерший Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для thyrex
    Регистрация
    07.03.2009
    Адрес
    Soligorsk, Belarus
    Сообщений
    99,211
    Вес репутации
    3109
    Выполните скрипт в AVZ
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
    DeleteFile('E:\igsugg.exe');
     DeleteFile('E:\autorun.inf');
    ExecuteSysClean;
    RebootWindows(true);
    end.
    Компьютер перезагрузится.

    Обновите базы AVZ
    Сделайте новые логи
    Microsoft MVP 2012-2016 Consumer Security
    Microsoft MVP 2016 Reconnect

  4. #23
    Junior Member Репутация
    Регистрация
    02.09.2009
    Сообщений
    16
    Вес репутации
    59
    Цитата Сообщение от thyrex Посмотреть сообщение
    Обновите базы AVZ
    Обновил, как только Вы сказали - в первый же раз+)
    Вложения Вложения

  5. #24
    Junior Member Репутация
    Регистрация
    02.09.2009
    Сообщений
    16
    Вес репутации
    59
    Собсна, вот вся выписка из журнала Аваста - со момента, как появился вирус, и по сей день.
    Не знаю, пригодится ли, но все же.
    02.09.2009 15:14:17 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\ykthrx.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:18:36 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\ykthrx.exe\AutoIt.script" file.
    02.09.2009 15:19:12 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ykthrx.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:19:16 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ykthrx.exe\AutoIt.script" file.
    02.09.2009 1530 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\xtmwjy.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 1534 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\xtmwjy.exe\AutoIt.script" file.
    02.09.2009 1541 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
    02.09.2009 15:21:04 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\xtmwjy.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:21:39 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\xtmwjy.exe\AutoIt.script" file.
    02.09.2009 15:22:07 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\xtmwjy.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:22:23 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\xtmwjy.exe\AutoIt.script" file.
    02.09.2009 15:22:27 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\mwqeej.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:22:30 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\mwqeej.exe\AutoIt.script" file.
    02.09.2009 15:24:17 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "C:\autorun.inf" file.
    02.09.2009 15:24:32 SYSTEM 1680 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\tdfxaj.exe" file.
    02.09.2009 15:24:57 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
    02.09.2009 15:25:10 SYSTEM 1680 Sign of "Win32:Agent-AEEP [Trj]" has been found in "D:\tdfxaj.exe" file.
    02.09.2009 15:25:16 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
    02.09.2009 15:25:40 SYSTEM 1680 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\tdfxaj.exe" file.
    02.09.2009 15:35:21 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:37:21 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\blyyqx.exe\AutoIt.script" file.
    02.09.2009 15:37:37 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:37:37 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\blyyqx.exe\AutoIt.script" file.
    02.09.2009 15:37:54 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:38:00 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\blyyqx.exe\AutoIt.script" file.
    02.09.2009 15:38:16 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 15:38:54 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\blyyqx.exe\AutoIt.script" file.
    02.09.2009 17:29:35 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 17:29:40 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\ufbjbc.exe\AutoIt.script" file.
    02.09.2009 17:29:59 SYSTEM 1684 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
    02.09.2009 17:30:15 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 17:30:21 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\ufbjbc.exe\AutoIt.script" file.
    02.09.2009 17:30:40 SYSTEM 1684 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
    02.09.2009 17:30:53 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 17:31:23 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\ufbjbc.exe\AutoIt.script" file.
    02.09.2009 17:32:26 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 17:36:56 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ufbjbc.exe\AutoIt.script" file.
    02.09.2009 18:08:11 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\cwehtv.exe" file.
    02.09.2009 18:08:33 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "D:\cwehtv.exe" file.
    02.09.2009 18:08:48 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\cwehtv.exe" file.
    02.09.2009 18:09:07 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\All Users\Документы\cwehtv.exe" file.
    02.09.2009 18:10:23 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:10:26 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:10:44 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:10:46 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:10:50 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:10:52 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:11:05 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:11:07 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:11:11 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:11:13 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:11:34 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:11:37 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:30:05 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Архивы\CMI8738_WDM_0639XP\CMUNINST.E XE" file.
    02.09.2009 18:30:27 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Архивы\CMI8738_WDM_0639XP\MIXER. EXE" file.
    02.09.2009 18:30:38 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Архивы\CMI8738_WDM_0639XP\Setup. exe" file.
    02.09.2009 18:30:41 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Программы\dmaster[2].exe" file.
    02.09.2009 18:30:47 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\daemon347.exe" file.
    02.09.2009 18:31:02 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\eauninstall.exe" file.
    02.09.2009 18:31:08 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\launcher.exe" file.
    02.09.2009 18:31:12 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\nfsrun.exe" file.
    02.09.2009 18:31:16 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\safemode_inst.exe" file.
    02.09.2009 18:31:20 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\sd4hide.exe" file.
    02.09.2009 18:31:23 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\shell_inst.exe" file.
    02.09.2009 18:31:28 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\speed.exe" file.
    02.09.2009 18:31:31 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\Support\EasyInfo.exe" file.
    02.09.2009 18:31:37 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\Support\EReg.exe" file.
    02.09.2009 18:35:58 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\TimeZero\unins000.exe" file.
    02.09.2009 18:36:59 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:37:03 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 18:56:00 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:56:26 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
    02.09.2009 18:56:30 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 18:56:32 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
    02.09.2009 19:29:52 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 19:29:59 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\jyyaoi.exe\AutoIt.script" file.
    02.09.2009 23:24:59 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\guorgs.exe\>>>AUTOIT SCRIPT<<<" file.
    02.09.2009 23:25:06 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\guorgs.exe\AutoIt.script" file.
    03.09.2009 10:38:31 SYSTEM 1488 Sign of "BV:AutoRun-G [Wrm]" has been found in "J:\Autorun.inf" file.
    03.09.2009 17:49:19 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
    03.09.2009 18:07:46 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00002.dta" file.
    03.09.2009 18:07:56 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00003.dta" file.
    03.09.2009 18:07:58 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
    03.09.2009 18:08:01 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
    03.09.2009 19:21:49 SYSTEM 1488 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\rqxppc.exe" file.
    03.09.2009 19:26:36 SYSTEM 1488 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\rqxppc.exe" file.
    03.09.2009 21:03:37 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00002.dta" file.
    03.09.2009 21:03:45 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00003.dta" file.
    03.09.2009 21:03:47 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
    03.09.2009 21:03:48 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
    03.09.2009 22:25:05 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
    03.09.2009 23:55:52 SYSTEM 1488 Sign of "HTML:Iframe-inf" has been found in "http://l2stat.cn/ip/\{gzip}" file.
    04.09.2009 0:06:49 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00002.dta" file.
    04.09.2009 0:07:03 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00002.dta" file.
    04.09.2009 0:07:09 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00003.dta" file.
    04.09.2009 0:07:13 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00003.dta" file.
    04.09.2009 0:07:15 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 0:07:17 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
    04.09.2009 0:07:21 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 0:07:22 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
    04.09.2009 0:21:06 SYSTEM 1652 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
    04.09.2009 0:32:58 SYSTEM 1652 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
    04.09.2009 0:38:22 SYSTEM 1652 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_1156_1.t mp" file.
    04.09.2009 0:53:10 Алексей Владимирович 1640 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_852_1.tm p" file.
    04.09.2009 1:00:56 Алексей Владимирович 1640 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\rqxppc.exe" file.
    04.09.2009 15:28:15 SYSTEM 1836 Sign of "BV:AutoRun-W" has been found in "C:\autorun.inf" file.
    04.09.2009 15:29:12 SYSTEM 1836 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\umgezn.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 15:29:17 SYSTEM 1836 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\umgezn.exe\AutoIt.script" file.
    04.09.2009 15:29:25 SYSTEM 1836 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
    04.09.2009 15:53:51 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
    04.09.2009 15:58:29 SYSTEM 1680 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\autorun.inf" file.
    04.09.2009 15:58:47 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 15:58:51 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\pktsdr.exe\AutoIt.script" file.
    04.09.2009 15:58:57 SYSTEM 1680 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
    04.09.2009 15:59:13 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 15:59:16 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\pktsdr.exe\AutoIt.script" file.
    04.09.2009 15:59:18 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 15:59:21 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\pktsdr.exe\AutoIt.script" file.
    04.09.2009 15:59:29 SYSTEM 1680 Sign of "BV:AutoRun-AA [Wrm]" has been found in "E:\autorun.inf" file.
    04.09.2009 15:59:44 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 15:59:52 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\pktsdr.exe\AutoIt.script" file.
    04.09.2009 16:00:09 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 16:00:13 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\pktsdr.exe\AutoIt.script" file.
    04.09.2009 21:22:34 SYSTEM 1828 Sign of "BV:AutoRun-W" has been found in "C:\autorun.inf" file.
    04.09.2009 21:23:00 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:24:21 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\igsugg.exe\AutoIt.script" file.
    04.09.2009 21:24:28 SYSTEM 1828 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
    04.09.2009 21:24:40 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:24:43 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
    04.09.2009 21:24:46 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:24:57 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
    04.09.2009 21:25:00 SYSTEM 1828 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
    04.09.2009 21:25:11 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:25:13 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\igsugg.exe\AutoIt.script" file.
    04.09.2009 21:25:16 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:25:17 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\igsugg.exe\AutoIt.script" file.
    04.09.2009 21:25:32 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:25:36 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
    04.09.2009 21:25:38 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 21:25:40 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
    04.09.2009 22:19:05 SYSTEM 1688 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
    04.09.2009 22:21:46 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 22:21:56 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
    04.09.2009 22:23:29 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 22:23:33 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
    04.09.2009 22:24:36 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 22:24:38 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
    04.09.2009 22:24:55 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 22:24:57 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\igsugg.exe\AutoIt.script" file.
    04.09.2009 22:25:20 SYSTEM 1688 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_556_1.tm p" file.
    04.09.2009 23:36:15 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 23:36:19 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\AutoIt.script" file.
    04.09.2009 23:36:23 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\>>>AUTOIT SCRIPT<<<" file.
    04.09.2009 23:36:25 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\AutoIt.script" file.
    05.09.2009 0:52:09 Алексей Владимирович 1684 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_1784_1.t mp" file.
    05.09.2009 14:13:03 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\>>>AUTOIT SCRIPT<<<" file.
    05.09.2009 14:13:07 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\AutoIt.script" file.
    05.09.2009 14:13:08 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    05.09.2009 14:13:09 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
    05.09.2009 14:13:23 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
    05.09.2009 14:13:24 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.

  6. #25
    Junior Member Репутация
    Регистрация
    02.09.2009
    Сообщений
    16
    Вес репутации
    59
    Господа хэлперы, вы про меня не забыли?+)

    Буду дома - сделаю новые логи с зараженной машины.

  7. #26
    Junior Member Репутация
    Регистрация
    02.09.2009
    Сообщений
    16
    Вес репутации
    59
    Доброго времени суток+)
    Извините, что так долго не было - проблемы с инетом.
    Так же прошу прощения за лог антивируса прямо в теме. Знаю, не просили, но я, так сказать, отчаялся уже+)

    Снес avast!, поставил КIS, почистил с ним комп.
    Удалил dc-менеджер.

    На данный момент не вижу вирусной активности.
    Пожалуйста, если вас не затруднит, поглядите логи.
    Вложения Вложения

  8. #27
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для AndreyKa
    Регистрация
    08.01.2005
    Адрес
    Россия
    Сообщений
    13,632
    Вес репутации
    1320
    Чисто.

  9. #28
    Cybernetic Helper Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация
    Регистрация
    29.12.2008
    Сообщений
    48,233
    Вес репутации
    982

    Итог лечения

    Статистика проведенного лечения:
    • Получено карантинов: 2
    • Обработано файлов: 12
    • В ходе лечения обнаружены вредоносные программы:
      1. c:\program files\common files\system\scvhost\dnetc.exe - not-a-virus:NetTool.Win32.Calc-DNet.a ( DrWEB: Program.DNetClient, BitDefender: Spyware.Calc.Dnet.A )
      2. d:\autorun.inf - Worm.Win32.AutoRun.gra ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )
      3. d:\autorun.inf - Trojan.Win32.AutoRun.bi ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-W )
      4. e:\autorun.inf - Worm.Win32.AutoRun.gra ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )
      5. e:\jyyaoi.exe - Packed.Win32.Klone.bj ( DrWEB: archive: archive: Win32.HLLW.Autoruner.based )


  • Уважаемый(ая) no_war, наши специалисты оказали Вам всю возможную помощь по вашему обращению.

    В целях поддержания безопасности вашего компьютера настоятельно рекомендуем:

     

     

    Чтобы всегда быть в курсе актуальных угроз в области информационной безопасности и сохранять свой компьютер защищенным, рекомендуем следить за последними новостями ИТ-сферы портала Anti-Malware.ru:

     

     

    Anti-Malware VK

     

    Anti-Malware Telegram

     

     

    Надеемся больше никогда не увидеть ваш компьютер зараженным!

     

    Если Вас не затруднит, пополните пожалуйста нашу базу безопасных файлов.

  • Страница 2 из 2 Первая 12

    Похожие темы

    1. autoit: Balero-e
      От Xeromant в разделе Помогите!
      Ответов: 4
      Последнее сообщение: 19.03.2011, 11:12
    2. Помогите удалить AutoIt:Balero-C и др.
      От maxon7777 в разделе Помогите!
      Ответов: 6
      Последнее сообщение: 20.03.2010, 14:25
    3. Логи ноута, подозрение на AutoIt:Balero-A2
      От almaz86 в разделе Помогите!
      Ответов: 10
      Последнее сообщение: 20.12.2009, 13:54
    4. AVAST [AutoIt:Balero-A [Wrm]//AutoIt:Balero-A2 [Wrm]]
      От alexandr1187 в разделе Помогите!
      Ответов: 5
      Последнее сообщение: 04.09.2009, 13:53
    5. AutoIt:Balero-A [Wrm]
      От fox1984 в разделе Помогите!
      Ответов: 7
      Последнее сообщение: 29.08.2009, 19:02

    Метки для этой темы

    Свернуть/Развернуть Ваши права в разделе

    • Вы не можете создавать новые темы
    • Вы не можете отвечать в темах
    • Вы не можете прикреплять вложения
    • Вы не можете редактировать свои сообщения
    •  
    Page generated in 0.00318 seconds with 17 queries