Нужен совет? Обратитесь за помощью к сообществу или специалистам.
Перейти к Avira Answers
???:TR/Kazy.331776
?????????:20/05/2011
???:????????? ?????????
? ???????? ????????:??
?????????? ????? ?????????:??????
????????? ???????????????:??????
????????? ???????????:?? ??????? ?? ????????
???? ??????????:??
?????? ?????:331.776 ????.
??????????? ????? MD5:25601D8D71A9C410F6C29AF2BF8DD027
?????? VDF:7.11.08.85 - пятница, 20 мая 2011 г.
?????? IVDF:7.11.08.85 - пятница, 20 мая 2011 г.

 ????? ????? ???????????????:
   • ??? ??????????? ????????? ???????????????


?????????? (?liases):
   •  TrendMicro: TROJ_FAKEAL.SMQP
   •  Sophos: Mal/FakeAV-JR
     Microsoft: Rogue:Win32/FakeRean


???????????? ???????:
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows 7


???????????:
   • ????????? ?????? ? ???-????????? IT-security ????????
   • ??????? ?????
   • ??????? ??????? ???????? ????????????
   • ????????? ???????


????? ??????? ???????? ????????? ??????????:


 ????? ????????? ??????????? ?????:
   • %HOME%\Local Settings\Application Data\%????????? ????????? ??????????%.exe



??????????? ????? ????????? ?????????.



????????? ????????? ?????:

%TEMPDIR%\%????????? ????????? ??????????%
%ALLUSERSPROFILE%\Application Data\%????????? ????????? ??????????%
%HOME%\Local Settings\Application Data\%????????? ????????? ??????????%
%TEMPDIR%\%????????? ????????? ??????????%
%HOME%\Templates\%????????? ????????? ??????????%

 ?????? ??????????? ????????? ????? ???????:

[HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\
   FirewallPolicy\StandardProfile]
   • "DoNotAllowExceptions"=dword:00000000
   • "EnableFirewall"=dword:00000000
   • "DisableNotifications"=dword:00000001

[HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\
   FirewallPolicy\DomainProfile]
   • "EnableFirewall"=dword:00000000
   • "DoNotAllowExceptions"=dword:00000000
   • "DisableNotifications"=dword:00000001

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "ctfmon.exe"="%SYSDIR%\ctfmon.exe"

[HKCR\.exe\shell\open\command]
   • "(Default)"="\"%HOME%\Local Settings\Application Data\\%????????? ????????? ??????????%.exe\" -a \"%1\" %*"
   • "IsolatedCommand"="\"%1\" %*"

[HKCR\exefile\shell\open\command]
   • "(Default)"="\"%HOME%\Local Settings\Application Data\\%????????? ????????? ??????????%.exe\" -a \"%1\" %*"
   • "IsolatedCommand"="\"%1\" %*"

[HKCR\exefile\shell\runas\command]
   • "(Default)"="\"%1\" %*"
   • "IsolatedCommand"="\"%1\" %*"

[HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\
   command]
   • "(Default)"="\"%HOME%\Local Settings\Application Data\\%????????? ????????? ??????????%.exe\" -a \"%PROGRAM FILES%\Intern"



?????????? ????????? ???? ???????:

[HKLM\SOFTWARE\Microsoft\Security Center]
   ????? ????????:
   • "AntiVirusDisableNotify"=dword:00000001
   • "FirewallDisableNotify"=dword:00000001
   • "FirewallOverride"=dword:00000001
   • "UpdatesDisableNotify"=dword:00000001
   • "AntiVirusOverride"=dword:00000001

 ????????????? ??????????? ? ??????? ? ???????? ?????????? ???????????? ??????.

    ??? ????????:
   • iexplore.exe


 ?????? ?????? ? ????????-????????:
   • **********ihudamaqyr.com/%?????????
      ???????????? ?????%
;
      **********adovykavo.com/%?????????
      ???????????? ?????%
;
      **********ehukalyna.com/%?????????
      ???????????? ?????%
;
      **********yrizyp.com/%?????????
      ???????????? ?????%
;
      **********ovajisem.com/%?????????
      ???????????? ?????%
;
      **********erecus.com/%?????????
      ???????????? ?????%
;
      **********yzykuboqo.com/%?????????
      ???????????? ?????%
;
      **********otarohoc.com/%?????????
      ???????????? ?????%
;
      **********ynefusawi.com/%?????????
      ???????????? ?????%
;
      **********ehujosyp.com/%?????????
      ???????????? ?????%
;
      **********anipuw.com/%?????????
      ???????????? ?????%
;
      **********agexyz.com/%?????????
      ???????????? ?????%
;
      **********ebenirahu.com/%?????????
      ???????????? ?????%
;
      **********ukopomiva.com/%?????????
      ???????????? ?????%
;
      **********ireracy.com/%?????????
      ???????????? ?????%
;
      **********anatapum.com/%?????????
      ???????????? ?????%
;
      **********support-2011.com/%?????????
      ???????????? ?????%
;
      **********mium-support2011.com/%?????????
      ???????????? ?????%
;
      **********upport-2011.com/%?????????
      ???????????? ?????%
;
      **********ivirussupport2011.com/%?????????
      ???????????? ?????%
;
      **********ivirus-support2011.com/%?????????
      ???????????? ?????%
;
      **********support2011.com/%?????????
      ???????????? ?????%
;
      **********upport2011.com/%?????????
      ???????????? ?????%
;
      **********hukyq.com/%?????????
      ???????????? ?????%
;
      **********cewyfyxut.com/%?????????
      ???????????? ?????%
;
      **********walulas.com/%?????????
      ???????????? ?????%
;
      **********mokowe.com/%?????????
      ???????????? ?????%
;
      **********okowe.com/%?????????
      ???????????? ?????%
;
      **********okowe.com/%?????????
      ???????????? ?????%
;
      **********okowe.com/%?????????
      ???????????? ?????%
;
      **********ilezavyxiro.com/%?????????
      ???????????? ?????%
;
      **********ovatywo.com/%?????????
      ???????????? ?????%
;
      **********akidukojoz.com/%?????????
      ???????????? ?????%
;
      **********agyjaj.com/%?????????
      ???????????? ?????%
;
      **********ojafadezy.com/%?????????
      ???????????? ?????%
;
      **********evaviqopoci.com/%?????????
      ???????????? ?????%
;
      **********otyger.com/%?????????
      ???????????? ?????%
;
      **********afiduzipame.com/%?????????
      ???????????? ?????%
;
      **********ojewedowigo.com/%?????????
      ???????????? ?????%
;
      **********yxepomer.com/%?????????
      ???????????? ?????%
;
      **********ahanybyvu.com/%?????????
      ???????????? ?????%
;
      **********akydugudi.com/%?????????
      ???????????? ?????%
;
      **********ugypenihyf.com/%?????????
      ???????????? ?????%
;
      **********ybobik.com/%?????????
      ???????????? ?????%
;
      **********okatahinery.com/%?????????
      ???????????? ?????%
;
      **********icaraso.com/%?????????
      ???????????? ?????%
;
      **********osahule.com/%?????????
      ???????????? ?????%
;
      **********uzajylot.com/%?????????
      ???????????? ?????%
;
      **********onevetode.com/%?????????
      ???????????? ?????%
;
      **********atesomyz.com/%?????????
      ???????????? ?????%
;
      **********ofymela.com/%?????????
      ???????????? ?????%
;
      **********uponip.com/%?????????
      ???????????? ?????%
;
      **********ovasuced.com/%?????????
      ???????????? ?????%
;
      **********oduhisegu.com/%?????????
      ???????????? ?????%
;
      **********editacif.com/%?????????
      ???????????? ?????%
;
      **********emehypuq.com/%?????????
      ???????????? ?????%
;
      **********yxaqunowy.com/%?????????
      ???????????? ?????%
;
      **********ovexidysopy.com/%?????????
      ???????????? ?????%
;
      **********ecebyt.com/%?????????
      ???????????? ?????%
;
      **********esexyzobuz.com/%?????????
      ???????????? ?????%
;
      **********ijinymut.com/%?????????
      ???????????? ?????%
;
      **********evanyxora.com/%?????????
      ???????????? ?????%
;
      **********ixydyf.com/%?????????
      ???????????? ?????%
;
      **********usaseda.com/%?????????
      ???????????? ?????%
;
      **********udizoni.com/%?????????
      ???????????? ?????%
;
      **********ejutyhyfu.com/%?????????
      ???????????? ?????%
;
      **********ygizeq.com/%?????????
      ???????????? ?????%
;
      **********ehiqino.com/%?????????
      ???????????? ?????%
;
      **********ynufyk.com/%?????????
      ???????????? ?????%
;
      **********ibipaj.com/%?????????
      ???????????? ?????%
;
      **********ityvik.com/%?????????
      ???????????? ?????%
;
      **********olalat.com/%?????????
      ???????????? ?????%
;
      **********yziriryvi.com/%?????????
      ???????????? ?????%
;
      **********idehecyty.com/%?????????
      ???????????? ?????%
;
      **********uwemixonav.com/%?????????
      ???????????? ?????%
;
      **********inolecowary.com/%?????????
      ???????????? ?????%
;
      **********upowibi.com/%?????????
      ???????????? ?????%
;
      **********isesyf.com/%?????????
      ???????????? ?????%
;
      **********exynogemi.com/%?????????
      ???????????? ?????%
;
      **********evepapucof.com/%?????????
      ???????????? ?????%
;
      **********igomyqeg.com/%?????????
      ???????????? ?????%
;
      **********emolezala.com/%?????????
      ???????????? ?????%
;
      **********unemymyko.com/%?????????
      ???????????? ?????%
;
      **********onabubi.com/%?????????
      ???????????? ?????%
;
      **********oripuqoxyl.com/%?????????
      ???????????? ?????%
;
      **********elaticik.com/%?????????
      ???????????? ?????%
;
      **********exyhun.com/%?????????
      ???????????? ?????%
;
      **********ofociv.com/%?????????
      ???????????? ?????%
;
      **********ebihyku.com/%?????????
      ???????????? ?????%
;
      **********yjajutava.com/%?????????
      ???????????? ?????%



???????:
????????? ???????:
   • ir4cnxm3oi333

Описание добавил Andrei Ilie в(о) пятница, 26 августа 2011 г.
Описание обновил Andrei Ilie в(о) пятница, 26 августа 2011 г.

Назад . . . .
https:// Это окно зашифровано для вашей безопасности.