Прочитайте тут и удалите через опцию force delete
Код:
C:\WINDOWS\SYSTEM32\WinCtrl32.dll
C:\WINDOWS\SYSTEM32\WLCtrl32.dll
1.Отключите ПК от сети.
2.Отключите Антивирус.
3.Отключите системное востановление.
4. Пофиксите
Код:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O4 - HKLM\..\Run: [advap32] C:\WINDOWS\TEMP\7B48.tmp/r
O4 - HKLM\..\Run: [runwinlogon] C:\WINDOWS\winlogon.exe
O4 - HKCU\..\Run: [userinit] C:\WINDOWS\system32\ntos.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Ïåòð\cftmon.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{066018EC-614F-4F77-8AD2-FB45F19EA7AB}: NameServer = 85.255.113.194,85.255.112.177
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.194 85.255.112.177
O17 - HKLM\System\CS1\Services\Tcpip\..\{066018EC-614F-4F77-8AD2-FB45F19EA7AB}: NameServer = 85.255.113.194,85.255.112.177
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.194 85.255.112.177
O17 - HKLM\System\CS2\Services\Tcpip\..\{066018EC-614F-4F77-8AD2-FB45F19EA7AB}: NameServer = 85.255.113.194,85.255.112.177
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.194 85.255.112.177
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O21 - SSODL: SysRun - {D7FFD784-5276-42D1-887B-00267870A4C7} - (no file)
5. Выполните скрипт
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\buffoon.exe');
DeleteService('cgJ60');
DeleteService('Jnr50');
DeleteService('aeH36');
DeleteService('chK60');
DeleteService('Rvy04');
QuarantineFile('C:\WINDOWS\SYSTEM32\WLCtrl32.dll','');
QuarantineFile('C:\WINDOWS\SYSTEM32\WinCtrl32.dll','');
QuarantineFile('C:\Buffoon.exe','');
QuarantineFile('c:\buffoon.exe','');
QuarantineFile('C:\WINDOWS\system32\Drivers\Jnr50.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\cgJ60.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Jnr50.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\aeH36.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\chK60.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Rvy04.sys','');
QuarantineFile('C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe','');
QuarantineFile('C:\Documents and Settings\Петр\cftmon.exe','');
QuarantineFile('C:\WINDOWS\TEMP\7B48.tmp/r','');
QuarantineFile('C:\WINDOWS\system32\drivers\spools.exe','');
QuarantineFile('C:\WINDOWS\system32\ntos.exe','');
QuarantineFile('C:\WINDOWS\winlogon.exe','');
QuarantineFile('C:\WINDOWS\system32\kdgdi.exe','');
QuarantineFile('kdgdi.exe','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\PavProc.sys','');
QuarantineFile('Lch30.sys','');
QuarantineFile('C:\autorun.inf','');
QuarantineFile('D:\autorun.inf','');
DeleteFile('D:\autorun.inf');
DeleteFile('C:\WINDOWS\SYSTEM32\WLCtrl32.dll');
DeleteFile('Lch30.sys');
DeleteFile('C:\WINDOWS\system32\DRIVERS\PavProc.sys');
DeleteFile('kdgdi.exe');
DeleteFile('C:\WINDOWS\system32\kdgdi.exe');
DeleteFile('WinCtrl32.dll');
DeleteFile('C:\WINDOWS\winlogon.exe');
DeleteFile('C:\WINDOWS\system32\ntos.exe');
DeleteFile('C:\WINDOWS\system32\drivers\spools.exe');
DeleteFile('C:\WINDOWS\TEMP\7B48.tmp/r');
DeleteFile('C:\Documents and Settings\Петр\cftmon.exe');
DeleteFile('C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe');
DeleteFile('C:\WINDOWS\System32\Drivers\Rvy04.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\chK60.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\aeH36.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Jnr50.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\cgJ60.sys');
DeleteFile('C:\WINDOWS\system32\Drivers\Jnr50.sys');
DeleteFile('C:\WINDOWS\SYSTEM32\WinCtrl32.dll');
DeleteFile('c:\buffoon.exe');
DeleteFile('C:\Buffoon.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки:
6. Очистите темп-папки и кэш проводников.
7. Закачайте карантин по красной ссылке вверху темы
8. Повторите логи.