Пофиксите в HijackThis:
Код:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyudnS-Ow-abULoVUBxxDwm-nJ1u98zUwfI-20_ulcNjpyoHeqn9I34kah6Z21WO22zjWfCDxsyWx3basCMyZ3WTsT6uVTa-0jH7qNFlYpWpR-AfsFUVNI9zf46DSXU_5Ka2HYgYaOrd5VOWiTlud3Wp-vS6205a&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyudnS-Ow-abULoVUBxxDwm-nJ1u98zUwfI-20_ulcNjpyoHeqn9I34kah6Z21WO22zjWfCDxsyWx3basCMyZ3WTsT6uVTa-0jH7qNFlYpWpR-AfsFUVNI9zf46DSXU_5Ka2HYgYaOrd5VOWiTlud3Wp-vS6205a&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyudnS-Ow-abULoVUBxxDwm-nJ1u98zUwfI-20_ulcNjpyoHeqn9I34kah6Z21WO22zjWfCDxsyWx3basCMyZ3WTsT6uVTa-0jH7qNFlYpWpR-AfsFUVNI9zf46DSXU_5Ka2HYgYaOrd5VOWiTlud3Wp-vS6205a&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyudnS-Ow-abULoVUBxxDwm-nJ1u98zUwfI-20_ulcNjpyoHeqn9I34kah6Z21WO22zjWfCDxsyWx3bavJnSOHjr5-gqTY6fPQjq3vKtDWoXMP-bQhHsrKfFM6hAFr326ITtbOpB2uWIuKFhsxDWhVqLw8aHpAbp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=90098758_hao_pg
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyudnS-Ow-abULoVUBxxDwm-nJ1u98zUwfI-20_ulcNjpyoHeqn9I34kah6Z21WO22zjWfCDxsyWx3basCMyZ3WTsT6uVTa-0jH7qNFlYpWpR-AfsFUVNI9zf46DSXU_5Ka2HYgYaOrd5VOWiTlud3Wp-vS6205a&q={searchTerms}
O3 - Toolbar: (no name) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
O15 - Trusted Zone: http://*.baidu.com
Выполните скрипт в AVZ:
Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.'+#13#10+'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\programdata\pwinpp\wfini.exe');
TerminateProcessByName('c:\users\Сергей\appdata\roaming\tsv\tsvr.exe');
TerminateProcessByName('c:\programdata\vrexjvx\protect\protect.exe');
SetServiceStart('vreXjvX_update', 4);
SetServiceStart('BugreportW', 4);
SetServiceStart('WdMan', 4);
SetServiceStart('vreXjvX_protect', 4);
SetServiceStart('IhPul', 4);
StopService('WdMan');
StopService('vreXjvX_protect');
StopService('IhPul');
QuarantineFile('C:\Program Files\Dravsynlether\Drvcoretsk.exe','');
QuarantineFile('C:\Program Files\QQBrowser\Update\7636CC9F1D40BC0841B39D5C8F2D6961\Update\BrowserUpdate.exe','');
QuarantineFile('C:\Program Files\vreXjvX\vreXjvX\chrome.exe','');
QuarantineFile('C:\ProgramData\sulpnar\Indigo-Lax.dll','');
QuarantineFile('C:\Program Files\vreXjvX\vreXjvX\bin\vreXjvX_server.exe','');
QuarantineFile('C:\Program Files\Dravsynlether\Drvcoresrv.exe','');
QuarantineFile('C:\Program Files\hohobnd\reekge.exe','');
QuarantineFile('c:\programdata\pwinpp\wfini.exe','');
QuarantineFile('c:\users\Сергей\appdata\roaming\tsv\tsvr.exe','');
QuarantineFile('c:\programdata\vrexjvx\protect\protect.exe','');
DeleteFile('C:\ProgramData\vreXjvX\protect\protect.exe','32');
DeleteFile('C:\ProgramData\PwinpP\WFini.exe','32');
DeleteFile('C:\Program Files\hohobnd\reekge.exe','32');
DeleteFile('C:\Program Files\vreXjvX\vreXjvX\bin\vreXjvX_server.exe','32');
DeleteFile('C:\ProgramData\sulpnar\Indigo-Lax.dll','32');
DeleteFile('C:\Program Files\vreXjvX\vreXjvX\chrome.exe','32');
DeleteFile('C:\Program Files\QQBrowser\Update\7636CC9F1D40BC0841B39D5C8F2D6961\Update\BrowserUpdate.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Browser Updater Task(Core)','32');
DeleteFile('C:\Windows\system32\Tasks\vreXjvXBrowserUpdateCore','32');
DeleteFile('C:\Windows\system32\Tasks\vreXjvXBrowserUpdateUA','32');
DeleteFile('C:\Windows\system32\Tasks\vreXjvXCheckTask','32');
DeleteFile('C:\Users\Сергей\appdata\roaming\tsv\tsvr.exe','32');
DelBHO('{91397D20-1446-11D4-8AF4-0040CA1127B6}');
DeleteService('vreXjvX_update');
DeleteService('BugreportW');
DeleteService('WdMan');
DeleteService('vreXjvX_protect');
DeleteService('IhPul');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
RebootWindows(true);
end.
После перезагрузки выполните скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Загрузите quarantine.zip из папки AVZ по красной ссылке вверху темы Прислать запрошенный карантин
- Сделайте повторные логи по правилам п.2 и 3 раздела Диагностика.(virusinfo_syscheck.zip;hijackthis.log )