Пофиксите
Код:
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\system32\smfo472.exe"
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll
O4 - HKLM\..\Run: [runwinlogon] C:\WINDOWS\winlogon.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\User\cftmon.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\User\cftmon.exe
O4 - HKCU\..\Run: [WintelUpdate] C:\DOCUME~1\User\LOCALS~1\Temp\1BCD.tmp.exe
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [system] C:\WINDOWS\sys.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [system] C:\WINDOWS\sys.exe (User 'Default user')
O20 - Winlogon Notify: WinNt32 - C:\WINDOWS\SYSTEM32\WinNt32.dll
O23 - Service: Google Online Services - Unknown owner - C:\Documents and Settings\User\ie_updates3r.exe
O23 - Service: Machine Debug Manager MDMPlugPlay (MDMPlugPlay) - Unknown owner - C:\WINDOWS\system32\ALSNDMGRr.exe
O23 - Service: QoS RSVP RSVPProtectedStorage (RSVPProtectedStorage) - Unknown owner - C:\WINDOWS\system32\ahuiu.exe
O23 - Service: Ïëàíèðîâùèê çàäàíèé (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Îïðåäåëåíèå îáîðóäîâàíèÿ îáîëî÷êè ShellHWDetectionRemoteRegistry (ShellHWDetectionRemoteRegistry) - Unknown owner - C:\WINDOWS\system32\3com_dmim.exe
Выполните скрипт
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\windows\system32\smfo472.exe');
TerminateProcessByName('c:\documents and settings\user\ie_updates3r.exe');
TerminateProcessByName('c:\documents and settings\user\cftmon.exe');
StopService('Agl38');
DeleteService('Agl38');
StopService('tcpsr');
DeleteService('tcpsr');
StopService('RSVPProtectedStorage');
DeleteService('RSVPProtectedStorage');
StopService('Schedule');
DeleteService('Schedule');
StopService('Ygl84');
DeleteService('Ygl84');
StopService('Chm51');
DeleteService('Chm51');
StopService('Chm38');
DeleteService('Chm38');
StopService('Mrw73');
DeleteService('Mrw73');
StopService('Gmr27');
DeleteService('Gmr27');
StopService('qandr');
DeleteService('qandr');
StopService('Oty27');
DeleteService('Oty27');
StopService('ShellHWDetectionRemoteRegistry');
DeleteService('ShellHWDetectionRemoteRegistry');
StopService('Google Online Services');
DeleteService('Google Online Services');
StopService('MDMPlugPlay');
DeleteService('MDMPlugPlay');
StopService('Tye73');
DeleteService('Tye73');
StopService('Rwc27');
DeleteService('Rwc27');
StopService('Pua40');
DeleteService('Pua40');
QuarantineFile('C:\WINDOWS\System32\Drivers\Tye73.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Rwc27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Pua40.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Oty27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Mrw73.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Gmr27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Chm51.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Chm38.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Agl38.sys','');
QuarantineFile('qandr.sys','');
QuarantineFile('C:\WINDOWS\system32\3com_dmim.exe','');
QuarantineFile('C:\WINDOWS\system32\ALSNDMGRr.exe','');
QuarantineFile('C:\WINDOWS\system32\ahuiu.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\spools.exe','');
QuarantineFile('C:\WINDOWS\System32\drivers\tcpsr.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\qandr.sys','');
DelBHO('{36DBC179-A19F-48F2-B16A-6A3E19B42A87}');
QuarantineFile('WinNt32.dll','');
QuarantineFile('C:\WINDOWS\sys.exe','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Xej27.sys','');
QuarantineFile('C:\WINDOWS\winlogon.exe','');
QuarantineFile('C:\WINDOWS\system32\WinNt32.dll','');
QuarantineFile('C:\WINDOWS\system32\smfo472.exe','');
QuarantineFile('C:\WINDOWS\system32\apcupsa.dll','');
QuarantineFile('C:\WINDOWS\system32\alrsvce.dll','');
QuarantineFile('C:\Documents and Settings\User\ie_updates3r.exe','');
QuarantineFile('C:\Documents and Settings\User\cftmon.exe','');
QuarantineFile('c:\windows\winlogon.exe','');
TerminateProcessByName('c:\windows\winlogon.exe');
QuarantineFile('c:\windows\system32\smfo472.exe','');
QuarantineFile('c:\documents and settings\user\ie_updates3r.exe','');
QuarantineFile('c:\documents and settings\user\cftmon.exe','');
DeleteFile('c:\documents and settings\user\cftmon.exe');
DeleteFile('c:\documents and settings\user\ie_updates3r.exe');
DeleteFile('c:\windows\system32\smfo472.exe');
DeleteFile('c:\windows\winlogon.exe');
DeleteFile('C:\Documents and Settings\User\cftmon.exe');
DeleteFile('C:\Documents and Settings\User\ie_updates3r.exe');
DeleteFile('C:\WINDOWS\system32\alrsvce.dll');
DeleteFile('C:\WINDOWS\system32\apcupsa.dll');
DeleteFile('C:\WINDOWS\system32\ipv6monl.dll');
DeleteFile('C:\WINDOWS\system32\smfo472.exe');
DeleteFile('C:\WINDOWS\system32\WinNt32.dll');
DeleteFile('C:\WINDOWS\winlogon.exe');
DeleteFile('C:\WINDOWS\System32\drivers\tcpsr.sys');
DeleteFile('C:\WINDOWS\system32\drivers\spools.exe');
DeleteFile('C:\WINDOWS\system32\ahuiu.exe');
DeleteFile('C:\WINDOWS\system32\ALSNDMGRr.exe');
DeleteFile('C:\WINDOWS\system32\3com_dmim.exe');
DeleteFile('qandr.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Agl38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Chm38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Chm51.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Gmr27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Mrw73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Oty27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Pua40.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Rwc27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Tye73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Xej27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ygl84.sys');
DeleteFile('C:\WINDOWS\sys.exe');
DeleteFile('Explorer.exe C:\WINDOWS\system32\smfo472.exe');
DeleteFile('C:\WINDOWS\SYSTEM32\WinNt32.dll');
DeleteFile('C:\WINDOWS\system32\drivers\qandr.sys');
DeleteFile('F:\autorun.inf');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки повторите логи и закачайте карантин.