- Выполните скрипт в AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\cfdrive32.exe','');
QuarantineFile('C:\WINDOWS\system32\41.exe','');
QuarantineFile('E:\Soft\fraza\fraza.exe','');
QuarantineFile('C:\WINDOWS\system32\msvmiode.exe','');
QuarantineFile('C:\Documents and Settings\LeoNeed\Application Data\ltzqai.exe','');
DeleteFile('C:\Documents and Settings\LeoNeed\Application Data\ltzqai.exe');
DeleteFile('C:\WINDOWS\system32\msvmiode.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','MSODESNV7');
DeleteFile('C:\WINDOWS\system32\41.exe');
DeleteFile('C:\WINDOWS\cfdrive32.exe'); QuarantineFile('','');
QuarantineFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\25QCDPGV\hbf[1].exe','');
DeleteFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\25QCDPGV\hbf[1].exe');
QuarantineFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\45KXQA2H\xc[1].exe','');
DeleteFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\45KXQA2H\xc[1].exe');
QuarantineFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\45KXQA2H\xc[2].exe','');
DeleteFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\45KXQA2H\xc[2].exe');
QuarantineFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\E8AECQDH\xamp2[1].exe','');
DeleteFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\E8AECQDH\xamp2[1].exe');
QuarantineFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\E8AECQDH\xc[1].exe','');
DeleteFile('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\E8AECQDH\xc[1].exe');
QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5Q694IEZ\h[1].exe','');
DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5Q694IEZ\h[1].exe');
QuarantineFile('C:\RECYCLER\S-1-5-21-3156037374-9307860727-562927898-3743\syscr.exe','');
DeleteFile('C:\RECYCLER\S-1-5-21-3156037374-9307860727-562927898-3743\syscr.exe');
DeleteFileMask('C:\RECYCLER\S-1-5-21-3156037374-9307860727-562927898-3743', '*.*', true);
DeleteDirectory('C:\RECYCLER\S-1-5-21-3156037374-9307860727-562927898-3743');
QuarantineFile('C:\WINDOWS\Temp\05508.exe','');
DeleteFile('C:\WINDOWS\Temp\05508.exe');
QuarantineFile('C:\WINDOWS\Temp\3584114.exe','');
DeleteFile('C:\WINDOWS\Temp\3584114.exe');
QuarantineFile('C:\WINDOWS\Temp\370.exe','');
DeleteFile('C:\WINDOWS\Temp\370.exe');
QuarantineFile('C:\WINDOWS\Temp\4691.exe','');
DeleteFile('C:\WINDOWS\Temp\4691.exe');
QuarantineFile('C:\WINDOWS\Temp\511179.exe ','');
DeleteFile('C:\WINDOWS\Temp\511179.exe ');
QuarantineFile('C:\WINDOWS\Temp\596.exe','');
DeleteFile('C:\WINDOWS\Temp\596.exe');
QuarantineFile('C:\WINDOWS\Temp\6108783.exe','');
DeleteFile('C:\WINDOWS\Temp\6108783.exe');
QuarantineFile('C:\WINDOWS\Temp\639436.exe','');
DeleteFile('C:\WINDOWS\Temp\639436.exe');
QuarantineFile('C:\WINDOWS\Temp\76152.exe','');
DeleteFile('C:\WINDOWS\Temp\76152.exe');
QuarantineFile('C:\WINDOWS\Temp\94960.exe','');
DeleteFile('C:\WINDOWS\Temp\94960.exe');
QuarantineFile('C:\WINDOWS\Temp\9707.exe','');
DeleteFile('C:\WINDOWS\Temp\9707.exe');
DeleteFileMask('C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5', '*.*', true);
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman ');
BC_ImportAll;
ExecuteSysClean;
ExecuteRepair(11);
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки:
- выполните такой скрипт
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
- Файл quarantine.zip из папки AVZ загрузите по ссылке Прислать запрошенный карантин вверху темы
- удалите в MBAM, все что останется из этого
Код:
Зараженные параметры в реестре:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msodesnv7 (Trojan.FakeAlert.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft driver setup (Trojan.Backdoor) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\microsoft driver setup (Trojan.Backdoor) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Worm.Palevo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Worm.Palevo) -> No action taken.
Зараженные файлы:
C:\WINDOWS\system32\msvmiode.exe (Trojan.FakeAlert.H) -> No action taken.
C:\WINDOWS\cfdrive32.exe (Trojan.Backdoor) -> No action taken.
C:\Documents and Settings\LeoNeed\Application Data\ltzqai.exe (Worm.Autorun) -> No action taken.
C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\25QCDPGV\hbf[1].exe (Worm.Autorun) -> No action taken.
C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\45KXQA2H\xc[1].exe (Trojan.SpamTool) -> No action taken.
C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\45KXQA2H\xc[2].exe (Trojan.SpamTool) -> No action taken.
C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\E8AECQDH\xamp2[1].exe (Trojan.Backdoor) -> No action taken.
C:\Documents and Settings\LeoNeed\Local Settings\Temporary Internet Files\Content.IE5\E8AECQDH\xc[1].exe (Trojan.SpamTool) -> No action taken.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\5Q694IEZ\h[1].exe (Worm.Autorun) -> No action taken.
C:\RECYCLER\S-1-5-21-3156037374-9307860727-562927898-3743\syscr.exe (Worm.Autorun) -> No action taken.
C:\WINDOWS\system32\41.exe (Worm.Autorun) -> No action taken.
C:\WINDOWS\Temp\05508.exe (Trojan.SpamTool) -> No action taken.
C:\WINDOWS\Temp\3584114.exe (Trojan.SpamTool) -> No action taken.
C:\WINDOWS\Temp\370.exe (Worm.Autorun) -> No action taken.
C:\WINDOWS\Temp\4691.exe (Trojan.Backdoor) -> No action taken.
C:\WINDOWS\Temp\511179.exe (Trojan.SpamTool) -> No action taken.
C:\WINDOWS\Temp\596.exe (Trojan.Backdoor) -> No action taken.
C:\WINDOWS\Temp\6108783.exe (Trojan.SpamTool) -> No action taken.
C:\WINDOWS\Temp\639436.exe (Trojan.SpamTool) -> No action taken.
C:\WINDOWS\Temp\76152.exe (Trojan.SpamTool) -> No action taken.
C:\WINDOWS\Temp\94960.exe (Trojan.Backdoor) -> No action taken.
C:\WINDOWS\Temp\9707.exe (Trojan.Backdoor) -> No action taken.
E:\Soft\game soft\Mass effect2\keygen.exe (Trojan.Downloader) -> No action taken.
- Сделайте повторные логи по правилам п.2 и 3 раздела Диагностика.(virusinfo_syscheck.zip;hijackthis.log)
- Сделайте повторный лог MBAM