Закройте все открытые приложения, кроме АVZ и Internet Explorer.
Отключите
- ПК от интернета/локалки
- Антивирус и Файрвол.
- Системное восстановление.
- Выполните скрипт
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0001\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0001\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0001\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0002\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0002\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0002\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0003\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0003\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0003\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0004\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0004\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0004\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0005\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0005\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0005\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0006\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0006\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0006\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0007\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0007\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0007\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0008\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0008\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0008\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0009\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0009\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0009\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0000\w.ax','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0000\wb.vx','');
QuarantineFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0000\url.ax','');
QuarantineFile('C:\Documents and Settings\Design\Application Data\Opera\Opera\mail\lexicon\lexicon.ax','');
QuarantineFile('C:\Documents and Settings\Design\Application Data\Opera\Opera\mail\indexer\indexer.ax','');
QuarantineFile('C:\WINDOWS\system32\cssdll32.dll','');
DeleteFile('C:\WINDOWS\system32\cssdll32.dll');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0001\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0001\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0001\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0002\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0002\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0002\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0003\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0003\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0003\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0004\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0004\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0004\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0005\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0005\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0005\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0006\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0006\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0006\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0007\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0007\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0007\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0008\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0008\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0008\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0009\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0009\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0009\url.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0000\w.ax');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0000\wb.vx');
DeleteFile('C:\Documents and Settings\Design\Local Settings\Application Data\Opera\Opera\profile\vps\0000\url.ax');
DeleteFile('C:\Documents and Settings\Design\Application Data\Opera\Opera\mail\lexicon\lexicon.ax');
DeleteFile('C:\Documents and Settings\Design\Application Data\Opera\Opera\mail\indexer\indexer.ax');
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('Pcisp0rm');
BC_Activate;
RebootWindows(true);
end.
После перезагрузки:
- Очистите темп-папки, кэш проводников и корзину.
- Закройте все программы, включая Антивирус и Файрвол, Оставьте запущенным только Internet Explorer. Если он не запущен - запустите!!!
- Сделайте повторные логи по правилам.
- Включите Антвирус и Файрволл
- Подключите ПК к интернету/локалке
- Закачайте карантин по ссылке Прислать запрошенный карантин вверху темы.
- Прикрепите логи к новому сообщению.