|
.1
csrcs.exe . , . csrss.exe!!! , .
, , . , , .
csrcs.exe C:\WINDOWS\system32, , . csrcs.exe, . . , AVZ.
, .
, -, .. .
( ):
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('E:\dSMTyv.EXE','');
QuarantineFile('E:\DSmTYV.eXE','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('C:\WINDOWS\system32\csrcs.exe','');
DeleteFile('C:\WINDOWS\system32\csrcs.exe');
DeleteFile('E:\autorun.inf');
DeleteFile('E:\DSmTYV.eXE');
DeleteFile('E:\dSMTyv.EXE');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
E:\ , .
, > , .2., , .
.2
, , - , TEMP .. .., , TEMP, , Internet Explorer , TEMP, Opera .., .
, .
AVZ, , , .
,
1. csrss.exe .
2. C:\WINDOWS\system32\ csrcs.exe ( csrss.exe), , .. .
3. :
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
csrcs.exe.
4. :
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell csrcs.exe, .. Shell Explorer.exe.
5. .
.
" , . .":
1 - .
2 - All-in-One:
...
8 - -
9 - - , ! , .
10 - csrcs.exe? , .
11 -
12 - .
...
47 -
48 - , ,
49 - :
: | , , |