Все сделал - карантин отправлен, логи выложены.
Какие будут дальнейшие инструкции?+)
Все сделал - карантин отправлен, логи выложены.
Какие будут дальнейшие инструкции?+)
Выполните скрипт в AVZ
Компьютер перезагрузится.Код:begin SearchRootkit(true, true); SetAVZGuardStatus(True); DeleteFile('E:\igsugg.exe'); DeleteFile('E:\autorun.inf'); ExecuteSysClean; RebootWindows(true); end.
Обновите базы AVZ
Сделайте новые логи
Microsoft MVP 2012-2016 Consumer Security
Microsoft MVP 2016 ReconnectАнтивирусная помощь
Собсна, вот вся выписка из журнала Аваста - со момента, как появился вирус, и по сей день.
Не знаю, пригодится ли, но все же.
02.09.2009 15:14:17 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\ykthrx.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:18:36 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\ykthrx.exe\AutoIt.script" file.
02.09.2009 15:19:12 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ykthrx.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:19:16 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ykthrx.exe\AutoIt.script" file.
02.09.2009 1530 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\xtmwjy.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 1534 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\xtmwjy.exe\AutoIt.script" file.
02.09.2009 1541 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
02.09.2009 15:21:04 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\xtmwjy.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:21:39 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\xtmwjy.exe\AutoIt.script" file.
02.09.2009 15:22:07 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\xtmwjy.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:22:23 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\xtmwjy.exe\AutoIt.script" file.
02.09.2009 15:22:27 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\mwqeej.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:22:30 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\mwqeej.exe\AutoIt.script" file.
02.09.2009 15:24:17 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "C:\autorun.inf" file.
02.09.2009 15:24:32 SYSTEM 1680 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\tdfxaj.exe" file.
02.09.2009 15:24:57 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
02.09.2009 15:25:10 SYSTEM 1680 Sign of "Win32:Agent-AEEP [Trj]" has been found in "D:\tdfxaj.exe" file.
02.09.2009 15:25:16 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
02.09.2009 15:25:40 SYSTEM 1680 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\tdfxaj.exe" file.
02.09.2009 15:35:21 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:37:21 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\blyyqx.exe\AutoIt.script" file.
02.09.2009 15:37:37 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:37:37 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\blyyqx.exe\AutoIt.script" file.
02.09.2009 15:37:54 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:38:00 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\blyyqx.exe\AutoIt.script" file.
02.09.2009 15:38:16 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\blyyqx.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 15:38:54 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\blyyqx.exe\AutoIt.script" file.
02.09.2009 17:29:35 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 17:29:40 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\ufbjbc.exe\AutoIt.script" file.
02.09.2009 17:29:59 SYSTEM 1684 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
02.09.2009 17:30:15 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 17:30:21 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\ufbjbc.exe\AutoIt.script" file.
02.09.2009 17:30:40 SYSTEM 1684 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
02.09.2009 17:30:53 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 17:31:23 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\ufbjbc.exe\AutoIt.script" file.
02.09.2009 17:32:26 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ufbjbc.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 17:36:56 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\ufbjbc.exe\AutoIt.script" file.
02.09.2009 18:08:11 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\cwehtv.exe" file.
02.09.2009 18:08:33 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "D:\cwehtv.exe" file.
02.09.2009 18:08:48 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\cwehtv.exe" file.
02.09.2009 18:09:07 SYSTEM 1684 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\All Users\Документы\cwehtv.exe" file.
02.09.2009 18:10:23 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:10:26 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:10:44 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:10:46 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:10:50 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:10:52 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:11:05 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:11:07 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:11:11 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:11:13 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:11:34 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:11:37 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:30:05 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Архивы\CMI8738_WDM_0639XP\CMUNINST.E XE" file.
02.09.2009 18:30:27 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Архивы\CMI8738_WDM_0639XP\MIXER. EXE" file.
02.09.2009 18:30:38 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Архивы\CMI8738_WDM_0639XP\Setup. exe" file.
02.09.2009 18:30:41 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Downloads\Программы\dmaster[2].exe" file.
02.09.2009 18:30:47 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\daemon347.exe" file.
02.09.2009 18:31:02 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\eauninstall.exe" file.
02.09.2009 18:31:08 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\launcher.exe" file.
02.09.2009 18:31:12 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\nfsrun.exe" file.
02.09.2009 18:31:16 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\safemode_inst.exe" file.
02.09.2009 18:31:20 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\sd4hide.exe" file.
02.09.2009 18:31:23 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\shell_inst.exe" file.
02.09.2009 18:31:28 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\speed.exe" file.
02.09.2009 18:31:31 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\Support\EasyInfo.exe" file.
02.09.2009 18:31:37 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\Need For Speed\Most Wanted\Support\EReg.exe" file.
02.09.2009 18:35:58 SYSTEM 1684 Sign of "Win32:Tenga" has been found in "C:\Games\TimeZero\unins000.exe" file.
02.09.2009 18:36:59 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:37:03 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 18:56:00 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:56:26 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
02.09.2009 18:56:30 SYSTEM 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 18:56:32 SYSTEM 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
02.09.2009 19:29:52 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\jyyaoi.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 19:29:59 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\jyyaoi.exe\AutoIt.script" file.
02.09.2009 23:24:59 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\guorgs.exe\>>>AUTOIT SCRIPT<<<" file.
02.09.2009 23:25:06 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\guorgs.exe\AutoIt.script" file.
03.09.2009 10:38:31 SYSTEM 1488 Sign of "BV:AutoRun-G [Wrm]" has been found in "J:\Autorun.inf" file.
03.09.2009 17:49:19 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
03.09.2009 18:07:46 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00002.dta" file.
03.09.2009 18:07:56 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00003.dta" file.
03.09.2009 18:07:58 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
03.09.2009 18:08:01 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
03.09.2009 19:21:49 SYSTEM 1488 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\rqxppc.exe" file.
03.09.2009 19:26:36 SYSTEM 1488 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\rqxppc.exe" file.
03.09.2009 21:03:37 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00002.dta" file.
03.09.2009 21:03:45 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00003.dta" file.
03.09.2009 21:03:47 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
03.09.2009 21:03:48 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Downloads\avz4\Quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
03.09.2009 22:25:05 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
03.09.2009 23:55:52 SYSTEM 1488 Sign of "HTML:Iframe-inf" has been found in "http://l2stat.cn/ip/\{gzip}" file.
04.09.2009 0:06:49 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00002.dta" file.
04.09.2009 0:07:03 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00002.dta" file.
04.09.2009 0:07:09 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00003.dta" file.
04.09.2009 0:07:13 SYSTEM 1488 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00003.dta" file.
04.09.2009 0:07:15 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 0:07:17 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
04.09.2009 0:07:21 SYSTEM 1488 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 0:07:22 SYSTEM 1488 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\downloads\avz4\quarantine\2009-09-02\avz00004.dta\AutoIt.script" file.
04.09.2009 0:21:06 SYSTEM 1652 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
04.09.2009 0:32:58 SYSTEM 1652 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
04.09.2009 0:38:22 SYSTEM 1652 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_1156_1.t mp" file.
04.09.2009 0:53:10 Алексей Владимирович 1640 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_852_1.tm p" file.
04.09.2009 1:00:56 Алексей Владимирович 1640 Sign of "Win32:Agent-AEEP [Trj]" has been found in "C:\Documents and Settings\All Users\Документы\rqxppc.exe" file.
04.09.2009 15:28:15 SYSTEM 1836 Sign of "BV:AutoRun-W" has been found in "C:\autorun.inf" file.
04.09.2009 15:29:12 SYSTEM 1836 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\umgezn.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 15:29:17 SYSTEM 1836 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\umgezn.exe\AutoIt.script" file.
04.09.2009 15:29:25 SYSTEM 1836 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
04.09.2009 15:53:51 SYSTEM 1680 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
04.09.2009 15:58:29 SYSTEM 1680 Sign of "BV:AutoRun-AA [Wrm]" has been found in "C:\autorun.inf" file.
04.09.2009 15:58:47 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 15:58:51 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\pktsdr.exe\AutoIt.script" file.
04.09.2009 15:58:57 SYSTEM 1680 Sign of "BV:AutoRun-AA [Wrm]" has been found in "D:\autorun.inf" file.
04.09.2009 15:59:13 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 15:59:16 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\pktsdr.exe\AutoIt.script" file.
04.09.2009 15:59:18 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 15:59:21 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\pktsdr.exe\AutoIt.script" file.
04.09.2009 15:59:29 SYSTEM 1680 Sign of "BV:AutoRun-AA [Wrm]" has been found in "E:\autorun.inf" file.
04.09.2009 15:59:44 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 15:59:52 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\pktsdr.exe\AutoIt.script" file.
04.09.2009 16:00:09 SYSTEM 1680 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\pktsdr.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 16:00:13 SYSTEM 1680 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\pktsdr.exe\AutoIt.script" file.
04.09.2009 21:22:34 SYSTEM 1828 Sign of "BV:AutoRun-W" has been found in "C:\autorun.inf" file.
04.09.2009 21:23:00 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:24:21 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\igsugg.exe\AutoIt.script" file.
04.09.2009 21:24:28 SYSTEM 1828 Sign of "BV:AutoRun-W" has been found in "D:\autorun.inf" file.
04.09.2009 21:24:40 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:24:43 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
04.09.2009 21:24:46 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:24:57 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
04.09.2009 21:25:00 SYSTEM 1828 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
04.09.2009 21:25:11 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:25:13 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\igsugg.exe\AutoIt.script" file.
04.09.2009 21:25:16 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:25:17 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\igsugg.exe\AutoIt.script" file.
04.09.2009 21:25:32 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:25:36 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
04.09.2009 21:25:38 SYSTEM 1828 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 21:25:40 SYSTEM 1828 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
04.09.2009 22:19:05 SYSTEM 1688 Sign of "BV:AutoRun-W" has been found in "E:\autorun.inf" file.
04.09.2009 22:21:46 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 22:21:56 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
04.09.2009 22:23:29 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 22:23:33 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
04.09.2009 22:24:36 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 22:24:38 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
04.09.2009 22:24:55 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "E:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 22:24:57 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "E:\igsugg.exe\AutoIt.script" file.
04.09.2009 22:25:20 SYSTEM 1688 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_556_1.tm p" file.
04.09.2009 23:36:15 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 23:36:19 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\AutoIt.script" file.
04.09.2009 23:36:23 SYSTEM 1688 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\>>>AUTOIT SCRIPT<<<" file.
04.09.2009 23:36:25 SYSTEM 1688 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\AutoIt.script" file.
05.09.2009 0:52:09 Алексей Владимирович 1684 Sign of "Win32:Spyware-gen [Trj]" has been found in "C:\DOCUME~1\E113~1\LOCALS~1\Temp\avz_1784_1.t mp" file.
05.09.2009 14:13:03 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\>>>AUTOIT SCRIPT<<<" file.
05.09.2009 14:13:07 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\khefrc.exe\AutoIt.script" file.
05.09.2009 14:13:08 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
05.09.2009 14:13:09 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "C:\Documents and Settings\All Users\Документы\igsugg.exe\AutoIt.script" file.
05.09.2009 14:13:23 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A2 [Wrm]" has been found in "D:\igsugg.exe\>>>AUTOIT SCRIPT<<<" file.
05.09.2009 14:13:24 Алексей Владимирович 1684 Sign of "AutoIt:Balero-A [Wrm]" has been found in "D:\igsugg.exe\AutoIt.script" file.
Господа хэлперы, вы про меня не забыли?+)
Буду дома - сделаю новые логи с зараженной машины.
Доброго времени суток+)
Извините, что так долго не было - проблемы с инетом.
Так же прошу прощения за лог антивируса прямо в теме. Знаю, не просили, но я, так сказать, отчаялся уже+)
Снес avast!, поставил КIS, почистил с ним комп.
Удалил dc-менеджер.
На данный момент не вижу вирусной активности.
Пожалуйста, если вас не затруднит, поглядите логи.
Статистика проведенного лечения:
- Получено карантинов: 2
- Обработано файлов: 12
- В ходе лечения обнаружены вредоносные программы:
- c:\program files\common files\system\scvhost\dnetc.exe - not-a-virus:NetTool.Win32.Calc-DNet.a ( DrWEB: Program.DNetClient, BitDefender: Spyware.Calc.Dnet.A )
- d:\autorun.inf - Worm.Win32.AutoRun.gra ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )
- d:\autorun.inf - Trojan.Win32.AutoRun.bi ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-W )
- e:\autorun.inf - Worm.Win32.AutoRun.gra ( BitDefender: Trojan.AutorunINF.Gen, AVAST4: BV:AutoRun-AA [Wrm] )
- e:\jyyaoi.exe - Packed.Win32.Klone.bj ( DrWEB: archive: archive: Win32.HLLW.Autoruner.based )
Уважаемый(ая) no_war, наши специалисты оказали Вам всю возможную помощь по вашему обращению.
В целях поддержания безопасности вашего компьютера настоятельно рекомендуем:
Чтобы всегда быть в курсе актуальных угроз в области информационной безопасности и сохранять свой компьютер защищенным, рекомендуем следить за последними новостями ИТ-сферы портала Anti-Malware.ru:
Надеемся больше никогда не увидеть ваш компьютер зараженным!
Если Вас не затруднит, пополните пожалуйста нашу базу безопасных файлов.