Cureit. |
, .
, . , .
.
, , . Temp,
C:\Documents and Settings\-- --\Local Settings\Temp
-- – . .
, .
,
,
, .
,
C:\windows\system32,
C:\Documents and Settings\-- --\Local Settings\Temp
windows
, . , , , .
sfc /scannow –
,
Cureit
C:\Documents and Settings\-- --\Local Settings\Temp
«»
. . , , . , , .
1.
) F8 ( ). F8.
)
C:\Documents and Settings\-- --\Local Settings\Temp
,
2
) – regedit.
- F282BBC8-53EAAA18-1BA0D6DE-8F7658EC
, , Temp
, - …
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\0]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\ AF624C78-9A5FC7A8-1BB5F380-FC240888""
Type"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\1]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\F282BBC8-53EAAA18-1BA0D6DE-8F7658EC""
Type"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\2]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\B2BF0D90-5A15F356-94FDCF61-59D15A23""
Type"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\3]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\15EAB006-22675FB2-A2726C62-4A8E6744""
Type"=dword:00000001
)
,
,
- .
.
3
,
\ . « » \ – \
) u02Rk.exe RootKit Unhooker
Code Hooks / Scan
DwProt.sys
C:/Windows/System32/DwProt.sys
, . .
- u02Rk.exe Code Hooks / Scan / UnHook All
)
C:/Windows/System32/DwProt.sys
.
) ,
) ()
C:\Documents and Settings\-- --\Local Settings\Temp
DwProt.sys, , .
Doctor Web, .
, DwProt.sys DwProt, .
. :)