Close/disable all the applications excluded AVZ and Internet Explorer.
- Disconnect your PC from network (internet/intranet)
- Disable antivirus, firewall and other memory resident security tools
- Disable System Restore
-Fix with Hijackthis
Код:
F2 - REG:system.ini: UserInit=Userinit.exe,
O2 - BHO: (no name) - {93d3a7ff-88f0-48a8-8a46-775e1b730cd7} - dububute.dll (file missing)
O20 - AppInit_DLLs: huzuvaha.dll c:\windows\system32\yimazitu.dll
O21 - SSODL: bunafesum - {2666c2d6-0719-47b1-a196-d4b3e1397fd3} - c:\windows\system32\yimazitu.dll
O22 - SharedTaskScheduler: kupuhivus - {2666c2d6-0719-47b1-a196-d4b3e1397fd3} - c:\windows\system32\yimazitu.dll
- Execute following script
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
QuarantineFile('C:\SYSPREP\PEDrv.sys','');
QuarantineFile('1.exe','');
DelBHO('{93d3a7ff-88f0-48a8-8a46-775e1b730cd7}');
DelBHO('{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}');
DelBHO('{92780B25-18CC-41C8-B9BE-3C9C571A8263}');
DelBHO('{700259D7-1666-479a-93B1-3250410481E8}');
DelBHO('{58ECB495-38F0-49cb-A538-10282ABF65E7}');
QuarantineFile('c:\windows\system32\yimazitu.dll','');
QuarantineFile('C:\WINDOWS\uxadutodigipa.dll','');
QuarantineFile('C:\WINDOWS\system32\bekagepe.dll','');
QuarantineFile('C:\WINDOWS\system32\dububute.dll','');
DeleteFile('C:\WINDOWS\system32\bekagepe.dll');
DeleteFile('C:\WINDOWS\system32\dububute.dll');
DeleteFile('C:\WINDOWS\uxadutodigipa.dll');
DeleteFile('c:\windows\system32\yimazitu.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Wrosuli');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','tolilabas');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler','{2666c2d6-0719-47b1-a196-d4b3e1397fd3}');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad','bunafesum');
DeleteFile('1.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Yahoo! Pager');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
SetAVZPMStatus(True);
RebootWindows(true);
end.
If the system after reboot would try to install any unknown hardware, abort the installtion and remove unknown hardware over hardware manager
After reboot:
execute following script
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Remove Bonjour
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProg
- Upload the C:\quarantine.zip over the link Upload quarantined files on the top of this page.
- Make new logs and attach them to the new posting.