, , ? |
1. , , WINDOWS, , system32, drivers, etc, etc hosts , .
hosts , .
( ). 腻

.

ʻ .

2. , :

# localhost name resolution is handled within DNS itself
# 127.0.0. localhost
- .
3., . .

" , ":
1 - .
2 - !
...
47 - Autorun
48 - , , !
49 - , , ?
50 - Snatch.exe
51 -
52 - Windows
53 - ( )
54 - PR?
|
: |
. |
. 2
FotoSalon 3.25

- , , . , . : , , , , . . Adobe Photoshop .
. , ! , . !
, Adobe Photoshop. . .
:
, . .
:
: 30mb.
FotoSalon
http://letitbit.net/download/3599.38542997764278a3042316b05/FotoSalon.zip.html
http://depositfiles.com/ru/gold/remote.php?show=all
2009 / MegaContacts 2009 ( )
|
: |
csrcs.exe |
.1
csrcs.exe . , . csrss.exe!!! , .
, , . , , .
csrcs.exe C:\WINDOWS\system32, , . csrcs.exe, . . , AVZ.
, .
, -, .. .
( ):
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('E:\dSMTyv.EXE','');
QuarantineFile('E:\DSmTYV.eXE','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('C:\WINDOWS\system32\csrcs.exe','');
DeleteFile('C:\WINDOWS\system32\csrcs.exe');
DeleteFile('E:\autorun.inf');
DeleteFile('E:\DSmTYV.eXE');
DeleteFile('E:\dSMTyv.EXE');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
E:\ , .
, > , .2., , .
.2
, , - , TEMP .. .., , TEMP, , Internet Explorer , TEMP, Opera .., .
, .
AVZ, , , .
, ![]()
1. csrss.exe .
2. C:\WINDOWS\system32\ csrcs.exe ( csrss.exe), , .. .
3. :
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
csrcs.exe.
4. :
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell csrcs.exe, .. Shell Explorer.exe.
5. .
.
" , . .":
1 - .
2 - All-in-One:
...
8 - -
9 - - , ! , .
10 - csrcs.exe? , .
11 -
12 - .
...
19 - .
20 - 99
21 - on-line !
|
: |
, , ? |
1. , , WINDOWS, , system32, drivers, etc, etc hosts , .
hosts , .
( ). 腻

.

ʻ .

2. , :

# localhost name resolution is handled within DNS itself
# 127.0.0. localhost
- .
3., . .

" , ":
1 - .
2 - !
...
47 - Autorun
48 - , , !
49 - , , ?
50 - Snatch.exe
51 -
52 - Windows
53 - ( )
54 - PR?
|
: |
- |
|
: |
| : | [1] |