Switch off:
- Antivirus and, if you have - Firewall.
- System Restore
- Execute following script
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('lm13');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\wathe9.sys','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\wcdbwxbmnk.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\ViBus.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\ultra.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\uhfaqzr.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\t2f9nf5z3m.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\nvgts.sys','');
QuarantineFile('C:\WINDOWS\system32\npkycryp.sys','');
QuarantineFile('C:\WINDOWS\system32\npkcrypt.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\mvsata.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\mv61xx.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\hptmv6.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\HpCISSm2.sys','');
QuarantineFile('C:\WINDOWS\System32\DRIVERS\gh6hqbz.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\fttxr52P.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\e8vryemo7.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\Cpq32fs2.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\bl4y0r7.sys','');
QuarantineFile('c:\root\it\wdfmgr.exe','');
QuarantineFile('C:\WINDOWS\System32\Drivers\azsi3p16.SYS','');
QuarantineFile('c:\documents and settings\administrator\application data\ppstream\bin\1.0.0.2\vodrc.dll','');
QuarantineFile('c:\program files\common files\autodesk shared\service\adskscsrv.exe','');
QuarantineFile('d:\360safe\safemon\360tray.exe','');
DeleteFile('c:\root\it\wdfmgr.exe');
DeleteService('lm13');
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('lm13');
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Remove Bonjour Service
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProg
- Close all the programs and start only Internet Explorer!!!
- Repeat 3 log files in accordance with the rules.
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the quarantine over the link Upload quarantined files on the top of this page.
- Attach 3 logs to your new post..