Выловил с помощью Security Essentials, вот лог:
» Спойлер (нажмите, чтобы прочесть) «
Категория: Вирус-червь
Описание: Эта опасная программа самостоятельно распространяется по сети.
Рекомендуемое действие: Немедленно удалите это программное обеспечение.
Программой Security Essentials обнаружены программы, из-за которых могут подвергаться опасности конфиденциальные данные или возможно повреждение компьютера. Можно сохранить доступ к файлам, используемым этими программами, не удаляя их (не рекомендуется). Для доступа к этим файлам выберите действие "Разрешить" и нажмите кнопку "Применить действия". Если этот параметр недоступен, войдите в систему как администратор или обратитесь за помощью к администратору безопасности.
Элементы:
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00064D16_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00064D25_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000660F3_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00066103_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000674D1_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000678E6_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00067D1B_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00068130_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00068555_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00068880_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006908B_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000694B0_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000698D5_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00069C2F_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00069C3E_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006A044_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006A469_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006AC84_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006AFED_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006B00C_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006B422_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006B856_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006BC8A_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006C0BF_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006C3BB_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006C3CB_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006CFCC_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006D3F1_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006D789_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006D799_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006DBAE_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006DFD3_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006E407_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006EB67_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006EB76_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006F372_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006F7A6_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006FBDB_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006FF35_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0006FF44_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007034A_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007076F_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00071303_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00071F14_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000726B2_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007388D_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00073E95_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00073EB4_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00075263_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007C18A_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007D529_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007D538_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007DA95_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007EFCA_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007EFDA_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0007F4AA_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00081FFE_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008200D_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00083B79_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000853AB_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000853BA_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00085BC5_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008737A_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00088F15_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00088F24_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000893C6_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008A765_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008A784_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008BF29_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008BF58_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008C754_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0008E13A_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00090C9D_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00090CAD_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00092451_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00092461_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00092876_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0009401B_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000957C0_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000957CF_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000957DF_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00095C71_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00097416_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00098B9C_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00098BAB_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\00099472_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0009A811_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0009A820_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0009BFB6_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\0009BFC5_crypt_copy.tmp
file:C:\ProgramData\Kaspersky Lab\AVP11\Temp\crypt\000A1B3D_crypt_copy.tmp
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{09DEBED3-8450-4EBE-8602-C56381387F9A}-весна 2011.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{2E36B56F-CC3E-4EAC-981C-6727AD339A75}-Интерны 2011.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{31941479-65FD-4D42-B48F-7586FD4CE6F4}-fish.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{4F3B71D6-3526-4C77-B80D-A8172003667C}-хрень.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{523CB2DF-BEF3-46BD-A2E7-A46EF1E70CCF}-boot.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{56B5BD39-92B6-43B3-B3CF-4E2BE4203160}-AVZ.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{5CD07011-A51D-4C6E-A7E1-F640A6025765}-fish.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{75AAFEC8-2598-4B2C-9D5B-4BC3DEB86C62}-2011 06 13.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{8125DD3D-EE36-4EA3-AA8C-FB45C59FDC36}-Диплом _Рубцова.lnk
file:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{898E58BC-EE9C-45C7-AE24-741890F5DBA6}-AVZ.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{98193A77-E1DF-4838-93EE-7BD830EB09CB}-сезон 5.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{A6258FCE-AC23-423C-A6C6-53ECDD4C6D1D}-13 06 2011 сад Прогресс т1 т2 т3 т4.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{B63928FD-77DF-470A-B542-D67DA6918F08}-Учебники.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{B7226B05-1BC6-48BF-8940-777A0AF77954}-Курсовая.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{BDA99D37-47E5-4CE1-8727-14CE825A1630}-2011 06 13.lnk
file:C:\ProgramData\Microsoft\MICROSOFT ANTIMALWARE\LocalCopy\{D671ECBE-AF1B-4A52-B9E2-8918AE7F9948}-13 06 2011 сад Прогресс т1 т2 т3 т4.lnk
file:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{F7710E50-F23E-41C3-A859-A1F77250C869}-boot.lnk
file:N:\13 06 2011 сад Прогресс т1 т2 т3 т4.lnk
file:N:\2011 06 13.lnk
file:N:\AVZ.lnk
file:N:\boot.lnk
file:N:\fish.lnk
file:N:\весна 2011.lnk
file:N:\Диплом _Рубцова.lnk
file:N:\Интерны 2011.lnk
file:N:\Курсовая.lnk
file:N:\сезон 5.lnk
file:N:\Учебники.lnk
file:N:\хрень.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{01A71FF1-CDA4-48E8-B5DB-9371813AD34A}-Интерны 2011.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{0EEA6B7E-FAA3-466E-8454-10974C178F7D}-boot.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{18EF7959-7FDC-483C-BA79-4283ACE41A72}-хрень.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{24BA970B-773E-4228-A1BF-64AC309CBC6E}-сезон 5.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{4CB64F42-AD84-4898-ABD0-862B997AD49E}-Диплом _Рубцова.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{5C8D5EF5-8E46-46B9-ABE9-38F9E83F9551}-13 06 2011 сад Прогресс т1 т2 т3 т4.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{60CF3E7D-4FEC-43BB-AC16-C76BA54821BE}-fish.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{60F51DE7-507A-48FC-9ECC-B2D7868783FA}-Учебники.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{8C535658-567C-4524-AC97-3A8F398DA555}-Интерны 2011.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{A0D7C810-CC70-4726-94D7-C0FADA22DBF6}-хрень.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{B90A1B3D-1C17-4756-BE4B-A8892B4AB902}-AVZ.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{BD108A76-107A-4932-AD77-20DCDF8ED45D}-Курсовая.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{C78D0A84-C1A8-420A-A7D9-71295DD2D4C7}-весна 2011.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{CA3C8621-52F1-41CD-BF36-7ACE50588654}-Диплом _Рубцова.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{D96F42B2-6386-440D-880E-5660DB219C2F}-весна 2011.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{DF6B1BF1-AE1E-4B95-80FA-FC69F8B401D9}-Учебники.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{E2935DDA-3965-4C0C-8BE1-D17E3D01C790}-Курсовая.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{E61B6E7D-A009-442D-91DF-DAAD1AD59681}-2011 06 13.lnk
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{FB2CF9BC-0408-4D17-A566-499D9D75B678}-сезон 5.lnk
Самое интересное kis 2011 пропустил. Диск N флешка.
Вот описание вируса, который я подловил:
http://www.microsoft.com/security/portal/T...atid=2147646212Сначала удалил средствами антивируса, затем подчистил в ручную. Вот только все ли удалил?
Сейчас качаю Microsoft Safety Scanner, за одно проверю как работает)
Сообщение отредактировал MotoArhangel - 14.7.2011, 18:27