Нужен совет? Обратитесь за помощью к сообществу или специалистам.
Перейти к Avira Answers
???:DR/Autoit.I.2
?????????:16/10/2007
???:????????? ?????????
? ???????? ????????:??
?????????? ????? ?????????:?? ??????? ?? ????????
????????? ???????????????:?? ??????? ?? ????????
????????? ???????????:???????
???? ??????????:??
?????? ?????:215.456 ????.
??????????? ????? MD5:3b5cf70876ef2e58a30dfa85c16b49bd
?????? IVDF:7.00.00.94 - вторник, 16 октября 2007 г.

 ????? ????? ???????????????:
Autorun feature (ru)


?????????? (?liases):
   •  Mcafee: W32/Autorun.worm.h virus
   •  Sophos: W32/SillyFDC-AP
   •  Panda: W32/Autorun.SF
   •  Eset: Win32/Autoit.AC
   •  Bitdefender: Worm.Generic.77741


???????????? ???????:
   • Windows 2000
   • Windows XP
   • Windows 2003


???????????:
   • ????????? ??????????? ?????
   • ??????? ??????????? ?????
   • ??????? ??????? ???????? ????????????
   • ????????? ???????

 ????? ????????? ??????????? ?????:
   • %SYSDIR%\msmsgs.exe
   • %????%\system.exe
   • %????%\%random directories%.exe



???? ????? ?????????.
%PROGRAM FILES%\ESET\nod32.exe

?? ????????? ??????????:
   • %??????????? ????%




????????? ????????? ?????:
   • %PROGRAM FILES%\ESET\nod32.exe
   • %PROGRAM FILES%\ESET\nod32kui.exe
   • %PROGRAM FILES%\ESET\nod32krn.exe



????????? ????????? ?????:

%WINDIR%\autorun.inf ???? ???????? ?????????? ????????? ?????? ?? ????????? ??????????:
   •

%????%\autorun.inf ???? ???????? ?????????? ????????? ?????? ?? ????????? ??????????:
   •




??????? ???????? ????????? ??????:

????????? URL:
   • http://ppt.th.gs/web-p/pt/file/**********
?? ?????? ???????? ?????? ???? ?? ??? ????????.

????????? URL:
   • http://ppt.th.gs/web-p/pt/file/**********
?? ?????? ???????? ?????? ???? ?? ??? ????????.

????????? URL:
   • http://ppt.th.gs/web-p/pt/file/**********
?? ?????? ???????? ?????? ???? ?? ??? ????????.

 ?????? ??? ?????????? ??????? ???????? ????? ???????????? ??????? ???? ?? ????????? ???????? ??????????? ? ????? ???????.

  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "Msmsgs"="%SYSDIR%\Msmsgs.exe"
   • "SYS1"="%SYSDIR%\system.exe"
   • "SYS2"="%SYSDIR%\bad1.exe"
   • "SYS3"="%SYSDIR%\bad2.exe"
   • "SYS4"="%SYSDIR%\bad3.exe"



????????? ???????? ????????? ?????? ???????:

–  [HKCU\Software\Microsoft\Internet Explorer\Main]
   • "Window Title"

–  [HKLM\SYSTEM\ControlSet001\Services\NOD32krn]
   • "ImagePath"

–  [HKLM\SYSTEM\ControlSet001\Services\nod32drv]
   • "ImagePath"



????????? ??? ???????? ?????????? ????? ??????? ? ??? ?????????:
   • [HKCR\lnkfile\isShortcut]



??????????? ????????? ???? ???????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\system]
   • "DisableRegistryTools"=dword:0x00000001
   • "DisableTaskMgr"=dword:0x00000001



?????????? ????????? ????? ???????:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
   ????? ????????:
   • "GlobalUserOffline"=dword:0x00000000

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\TaskManager]
   ????? ????????:
   • "Preferences"=hex:9C,02,00,00,E8,03,00,00,02,00,00,00,01,00,00,00,01,00,00,00,5A,02,00,00,02,00,00,00,FA,04,00,00,18,03,00,00,01,00,00,00,00,00,00,00,02,00,00,00,03,00,00,00,04,00,00,00,FF,FF,FF,FF,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,00,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,04,00,00,00,06,00,00,00,0B,00,00,00,0E,00,00,00,FF,FF,FF,FF,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,02,00,00,00,6B,00,00,00,32,00,00,00,6B,00,00,00,23,00,00,00,46,00,00,00,46,00,00,00,3C,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,6B,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,03,00,00,00,04,00,00,00,05,00,00,00,06,00,00,00,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,FF,6F,00,00,00,00,00,00,00,00,00,00,00,01,00,00,00

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
   ????? ????????:
   • "Hidden"=dword:0x00000002
   • "HideFileExt"=dword:0x00000001
   • "ShowSuperHidden"=dword:0x00000000
   • "SuperHidden"=dword:0x00000000

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
   ????? ????????:
   • "NoDriveTypeAutoRun"=dword:0x0000005b
   • "NoFind"=dword:0x00000001
   • "NoFolderOptions"=dword:0x00000001

 ?????????? ???????? ?????? ??????????? ?????????:
   • winsystem.exe
   • handydriver.exe
   • kerneldrive.exe
   • Wscript.exe
   • cmd.exe
   • nod32krn.exe
   • nod32kui.exe


 ?????? ????? ????????:
??? ?????????? ??????????? ? ?????????? ??????? ????? ?? ??? ????????? ????????? ??????????:

Описание добавил Petre Galan в(о) понедельник, 14 декабря 2009 г.
Описание обновил Petre Galan в(о) понедельник, 14 декабря 2009 г.

Назад . . . .
https:// Это окно зашифровано для вашей безопасности.