-

  • (45)
  • / (26)
  • (13)
  • (9)
  • (9)

 - e-mail

 

 -

   _

 -

 LiveInternet.ru:
: 28.02.2006
: 182
: 1228
: 1017

:

/ .


: (9), (45), (9), (13)
(0)

DVDsig. , .

, 03 2010 . 14:24 +
Alfizik (_) , () . , , .

, ( , ). , , ( ) . , .

, " " , , , .

( ) .., 1,5-, , , .

( , , Bad). ! ;)

DVDsig ( , 10 !), ( portable) .

 (321x87, 5Kb)

Dariusz Stanislawek:
DVDsig DVD, CD . DVDsig - MD5 . DVDsig , . DVDsig - , .


, DVDsig. - ,

DVDsig . - http://members.ozemail.com.au/~nulifetv/freezip/freeware/

===============================================================
/

:  
(174)

? .

, 16 2009 . 15:38 +
Alfizik (_) Rost [ + !]

?



:

:
: ... .

, .
? ? , , . ? , . . . , .

?

Juick Nibb13, .

LI 5.09.15

/

(4)

SMS- , . NOD !!!

, 06 2009 . 15:39 +
Alfizik (_) . SMS- , Windows. ! SMS, 300 .
 (653x551, 89Kb)
, )))

, , , ( ), . Win+L, . , . ))

:
1. C:\Documents and Settings\\Local Settings\Temp\922.exe
2. C:\Documents and Settings\\Local Settings\Temporary Internet Files\Content.IE5\HO9NMBT5\aa[1].exe
3. C:\WINDOWS\mfo.exe
44544 MD5 : E7A247CE628D8F455D5E895DBEF71976

:
AntiVir - TR/LockScreen.E.1
Avast - Win32:Malware-gen
AVG - SHeur2.BPQG
Comodo - Heur.Suspicious
DrWeb - Trojan.Winlock.428
Kaspersky - Trojan-Ransom.Win32.SMSer.rk
Panda - Trj/CI.A
Symantec - Trojan.Ransomlock.C
NOD !!! , !


.
LiveCD . LiveCD USB- ( Alkid Live CD iNFR@ CD). portable Dr.Web - Dr.Web CureIt!, . - http://www.freedrweb.com/cureit/
AVZ ( ), . . - http://www.z-oleg.com/secur/avz/download.php

AVZ ( )

( ).
: 13616. . , . ( ---> - , Regedit) :

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ Desktop \ SafeMode
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ System \ ControlSet003 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ SafeBoot

1 ( ). , , Windows, F8. - " ". .


/

:  
(8)

, 26 2009 . 17:18 +
Alfizik (_) , , . .

, , , , .

1. (Ctrl+Alt+Delete)
 (314x126, 26Kb)
Windows :
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] REG_DWORD DisableTaskMgr 1.

.

* > > : regedit > OK > .

2.
 (405x126, 30Kb)
? ))
Windows :
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] REG_DWORD DisableRegistryTools 1.

.

3. , (explorer-).
, , , ! , , , . Windows ))
explorer Windows :
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]
Debugger %Windir%\csrss.exe

.

P.S.



))

, .

, > > : gpedit.msc > OK > > > > > > ( ) : > > ( ) > >OK.

. ( , Windows+D), F5 ( , ).

Windows, (,RegOrganazer), [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] REG_DWORD DisableRegistryTools.

explorer, , . , autorun TotalComander ( explorer ) Windows ( Totala regedit), , RegOrganazer Debugger [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]

:)


/

(0)

QIP ver.8094 Win32/Induc.A

, 19 2009 . 13:29 +
Alfizik (_) Win32/Induc.A ( CodeGear Delphi) Delphi, : QIP, AIMP ( Skype, Total Commander, ).

, Delphi , , SysConst.dcu ( SysConst.bak), Delphi, , Delphi , .


Virus.Win32.Induc.a , Delphi. , .dcu-, Windows .

, Delphi 4.0-7.0. , Virus.Win32.Induc.a Delphi Sysconst.pas , Sysconst.dcu.

Delphi "use SysConst", . , Sysconst.dcu, , , . pas- .

, 8094 QIP ( QIP ). , - Runtime error 3, HKEY_LOCAL_MACHINE\SOFTWARE\Borland\Delphi\x.0 (x 4 7) RootDir ( ).


, . , .
QIP , 8095, :)

(!) ( IE8) ;)

, - QIP, .dcu- Virus.Win32.Induc.a .


Delphi , SysConst.bak, :
1. SysConst.dcu
2. SysConst.bak SysConst.dcu. , , SysConst.bak .

, . Win32/Induc.A : Avast, Kaspersky, NOD32.

/

(5)

, 10 2008 . 11:19 +
Alfizik (_) , , , . ? , , ( )? . !

 (252x107, 5Kb)
VirusTotal - , , , , .






:
*
*
*
*
*

VirusTotal - , Hispasec Sistemas, IT , , , .

32 (!) :
AhnLab (V3)
Aladdin (eSafe)
ALWIL (Avast! Antivirus)
Authentium (Command Antivirus)
Avira (AntiVir)
Bit9 (FileAdvisor)
Cat Computer Services (Quick Heal)
ClamAV (ClamAV)
CA Inc. (Vet)
Doctor Web, Ltd. (DrWeb)
Eset Software (ESET NOD32)
ewido networks (ewido anti-malware)
Fortinet (Fortinet)
FRISK Software (F-Prot)
F-Secure (F-Secure)
AVG Technologies (AVG)
Hacksoft (The Hacker)
Ikarus Software (Ikarus)
Kaspersky Lab (AVP)
McAfee (VirusScan)
Microsoft (Malware Protection)
Norman (Norman Antivirus)
Panda Security (Panda Platinum)
Prevx (Prevx1)
Rising Antivirus (Rising)
Secure Computing (Webwasher)
Softwin (BitDefender)
Sophos (SAV)
Sunbelt Software (Antivirus)
Symantec (Norton Antivirus)
VirusBlokAda (VBA32)
VirusBuster (VirusBuster)

17 , :)

 (638x416, 40Kb)

- VirusTotal
/

(4)

" "?

, 28 2007 . 23:23 +
StoneCold (_) , .
, "-"
.
Disk Write Copy "", .
- , ?

/

(7)

FTP

, 08 2007 . 08:08 +
coyc (_) 1 ....
IP FTP .
- FTP .

/

:  
(37)

, 19 2007 . 13:13 +
Maranii (_) 1. ?
2. , . , ?


/

(7)

Joner

, 09 2007 . 20:16 +
coyc (_) :)
1 .
Jonerom - ( )
HEX - . :(
/

(2)

FAQ Proxy

, 02 2007 . 17:25 +

/

(6)

HELP!!!

, 13 2007 . 18:23 +
_21-_ (_) , ... , , , !!! , , ! , , , ... , - - !!! , , , - )) , , ... , ... ... , !!! , -, ... , !!! ... ... (((

P.S. , ... ... , , , !!! ...
/

(12)

, 05 2007 . 18:04 +
 (_) ...
*.mkv ... , . , "K-Lite Codec Pack"
, ...

=( , - !
/

(12)

, 10 2007 . 15:07 +
4 (_) . ... Worm - Helkern... ... ...

.. . =)

/

(13)

?

, 10 2007 . 13:44 +
Bad_Kpoxa (_) ... ???




/

(9)

, 08 2007 . 21:20 +
Espectro (_)

, " dll- ". . , . , . , ...


- ?

/

0 !

, 28 2006 . 01:42 +
 (_)

0 ! 00 !

0 mail.ru ???

=))

 

/

(2)

, 15 2006 . 16:44 +
Espectro (_) , , .
. "", , Windows . - .
?
/

(2)

Wi-Fi

, 25 2006 . 00:49 +
/


 : [2] 1