-

   Voldar

 - e-mail

 

 -

( : 3) _ _ Dormion


Cureit.

, 18 2011 . 15:53 +

, .
, . , .

.

, , . Temp,

C:\Documents and Settings\-- --\Local Settings\Temp

-- – . .

, .

,
,

, .

,
C:\windows\system32,
C:\Documents and Settings\-- --\Local Settings\Temp
windows

, . , , , .

sfc /scannow

,
Cureit
C:\Documents and Settings\-- --\Local Settings\Temp


«»

 

. . , , . , , .

1.
) F8 ( ). F8.

)

C:\Documents and Settings\-- --\Local Settings\Temp


,

 

2
) regedit.

- F282BBC8-53EAAA18-1BA0D6DE-8F7658EC
, , Temp

, - …

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\0]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\ AF624C78-9A5FC7A8-1BB5F380-FC240888""
Type"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\1]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\F282BBC8-53EAAA18-1BA0D6DE-8F7658EC""
Type"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\2]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\B2BF0D90-5A15F356-94FDCF61-59D15A23""
Type"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DwProt\Parameters\Files\3]"
Volume"=hex:d2,39,d3,39,00,7e,00,00,00,00,00,00"
Name"="\\Documents and Settings\\*******\\Local Settings\\Temp\\15EAB006-22675FB2-A2726C62-4A8E6744""
Type"=dword:00000001

 


)
,

,
- .
.

3

,
\ . « » \ – \

) u02Rk.exe RootKit Unhooker

Code Hooks / Scan

DwProt.sys
C:/Windows/System32/DwProt.sys

 

, . .

- u02Rk.exe Code Hooks / Scan / UnHook All

)

C:/Windows/System32/DwProt.sys
.

) ,

) ()

C:\Documents and Settings\-- --\Local Settings\Temp

DwProt.sys, , .
Doctor Web, .

, DwProt.sys DwProt, .

. :)

 

Vladimir Voldar

:  

: [1] []
 

:
: 

: ( )

:

  URL