Domination & Submission. St. Petersburg

, ! .



- .

1 2 2

1

http://s9.uploads.ru/t/0Yue4.gif
( , ). , , ( -). . , . - - .
, , , . , , . , Windows, .
, . ( ). , , . .
, , (, ).
. .

1.
Dr.Web Windows (). , . ( ), . . , , .

2. avz
1. ( ).
2. .
3. ( F8 ). .
4. , .
5. .
6. explorer enter.
7. .
8. avz.exe.
9. - , . , , . .
10. : , , .
11. , ( ).
12. , AVZ. , , .
13. IE .
14. , .
, , AZV .

3. .
1. ( ).
2. .
3. ( F8 ). .
4. , .
5. .
6. explorer enter.
7. .
8. avz.exe.
9. .
10. .
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Documents and Settings\_\Local Settings\Temporary Internet Files\Content.IE5\FNM62GT9\lexa2[1].exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe','');
QuarantineFile('C:\Program Files\AskBarDis\bar\bin\askBar.dll','');
DelBHO('{638E9359-625E-4E8A-AA5B-824654C3239B}');
DelBHO('{1A16EC86-94A1-47D5-A725-49F5970E335D}');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\zsglib.dll','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\phnlib.dll','');
QuarantineFile('Explorer.exe csrcs.exe','');
QuarantineFile('C:\WINDOWS\System32\drivers\68ed4e7b.sys','');
DeleteFile('C:\WINDOWS\System32\drivers\68ed4e7b.sys');
DeleteFile('Explorer.exe csrcs.exe');
DeleteFile('C:\Documents and Settings\All Users\Application Data\phnlib.dll');
DeleteFile('C:\Documents and Settings\All Users\Application Data\zsglib.dll');
DeleteFile('C:\Program Files\AskBarDis\bar\bin\askBar.dll');
DeleteFile('C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe');
DeleteFile('C:\Documents and Settings\_\Local Settings\Temporary Internet Files\Content.IE5\FNM62GT9\lexa2[1].exe');
DelBHO('{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}');
DelBHO('{3041d03e-fd4b-44e0-b742-2d9b88305f98}');
DelBHO('{201f27d4-3704-41d6-89c1-aa35e39143ed}');
DelCLSID('{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}');
DeleteFileMask('C:\Documents and Settings\_\Local Settings\Temporary Internet Files\Content.IE5', '*.*', true);
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
: _ . administrator, user, andrey, petya - , , Windows.
1. , .
2. , . , AZV .

4
. , , , . Delete BIOS. , . , ( ) . . .

5. LiveCD.
LiveCD Dr.Web. , .
LiveCD .
. . , . :
1. ;
2. - SCD Writer.
3. LiveCD.
4. SCD Writer, , . LiveCD, .
, , CD. BIOS ( Delete). Boot ( ). , . . , , , . ( BIOS ). , .
. , . Dr.WebScanner, . .

6. Kaspersky Virus Removal Tool.
.
1. ( ).
2. Kaspersky Virus Removal Tool .
3. ( F8 ). .
4. , .
5. .
6. explorer enter.
7. .
8. Kaspersky Virus Removal Tool.
9. , . ! , , , , . .
begin
SearchRootkit(true, true);
QuarantineFile('Base.sys', 'CHQ=N');
QuarantineFile('explorer.ex', 'CHQ=N');
QuarantineFile('hpt3xx.sys', 'CHQ=N');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\AVGIDS Shim.Sys', 'CHQ=S');
QuarantineFile('C:\WINDOWS\system32\drivers\cmudau .sys', 'CHQ=S');
QuarantineFile('C:\WINDOWS\System32\Drivers\dump_n vatabus.sys', 'CHQ=S');
QuarantineFile('C:\WINDOWS\system32\Drivers\SPT2Sp 50.sys', 'CHQ=S');
QuarantineFile('C:\WINDOWS\system32\Drivers\usbVM3 1b.sys', 'CHQ=S');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\wg111v 2.sys', 'CHQ=S');
QuarantineFile('C:\DOCUME~1\FE66~1\LOCALS~1\Temp\Y KI224.tmp', 'CHQ=S');
BC_QrFile('C:\WINDOWS\System32\Drivers\dump_nvatab us.sys');
BC_QrFile('C:\WINDOWS\system32\Drivers\SPT2Sp50.sy s');
BC_QrFile('C:\WINDOWS\system32\Drivers\usbVM31b.sy s');
BC_QrFile('C:\WINDOWS\system32\DRIVERS\wg111v2.sys ');
BC_QrFile('C:\DOCUME~1\FE66~1\LOCALS~1\Temp\YKI224 .tmp');
BC_Activate;
RebootWindows(true);
end.

var
qfolder: string;
qname: string;
begin
qname := GetAVZDirectory + '..\Quarantine\quarantine.zip';
qfolder := ExtractFilePath(qname);
if (not DirectoryExists(qfolder)) then CreateDirectory(qfolder);
CreateQurantineArchive(qname);
ExecuteFile('explorer.exe', qfolder, 1, 0, false);
end.

begin
Executerepair(16);
ExecuteWizard('TSW', 2, 2, true);
RebootWindows(true);
end.

begin
ExecuteStdScr(3);
RebootWindows(true;
end.
10. , . , .

7.
. , , . - , - . . . .
Windows . , 5: , , CD. BIOS ( Delete). Boot ( ). , . . , , , . ( BIOS ). , .
, R. . , ( 1 Enter; , , Y Enter). FIXBOOT FIXMBR. :
http://s9.uploads.ru/t/Z7fcP.jpg http://s9.uploads.ru/t/FZhYW.jpg
. , . , , , , . .

LiveCD
, . LiveCD , , .
, , . , , . -.
, , .


, . . , . , , . - , , . .
, , , CD. Windows , .
:
( ).
. Windows PE, , , . , .
. , . , . , .
, , SCD Writer ( ). , ISO-. , .
. , , CD. BIOS ( Delete). Boot ( ). , . . , , , . ( BIOS ). , .
.
1, WindowsPE. (, ). .
-. . , ntuser.dat , . : C:\DocumentsandSettings\_\ntuser.dat, _ Windows. , ntuser.dat . , , . , . , .
( ). , . , , HKEY_LOCAL_MACHINE(), (), (W_IN_C). , , , (HKEY_LOCAL_MACHINE_W_IN_C). , .
HKEY_LOCAL_MACHINE()\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. Winlogon, . Shell , , explorer.exe ( ). userinit. C:\WINDOWS\system32\userinit.exe, ( , C:\, ). ! , .
: windows/system. user32. . (C, D , ) autorun.inf .exe. dr.web cureit .
, , BIOS, (HDD). BIOS Windows.
. , .
, avz, . , . . , .

2



|