- Remove Bonjour: http://virusinfo.info/showthread.php?t=42263
Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Cure
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\windows\temp\1973270796.exe');
TerminateProcessByName('c:\windows\temp\1859052046.exe');
TerminateProcessByName('c:\windows\system32\3361\svchost.exe');
TerminateProcessByName('c:\windows\dhcp\svchost.exe');
TerminateProcessByName('c:\program files\thunmail\testabd.exe');
TerminateProcessByName('c:\program files\bonjour\mdnsresponder.exe');
TerminateProcessByName('c:\docume~1\sandy\locals~1\temp\1095959750.exe');
StopService('restore');
StopService('protect');
StopService('Bonjour Service');
QuarantineFile('C:\WINDOWS\TEMP\fg7nymikb6.exe','');
QuarantineFile('c:\windows\temp\1973270796.exe','');
QuarantineFile('C:\WINDOWS\TEMP\1859052046.exe','');
QuarantineFile('c:\windows\temp\1859052046.exe','');
QuarantineFile('C:\WINDOWS\system32\userinit.exe','');
QuarantineFile('C:\WINDOWS\System32\svchost.exe','');
QuarantineFile('C:\WINDOWS\system32\jksahfo93wjfkd.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\restore.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\protect.sys','');
QuarantineFile('C:\WINDOWS\system32\Drivers\NDIS.sys','');
QuarantineFile('C:\WINDOWS\system32\3361\SVCHOST.exe','');
QuarantineFile('c:\windows\system32\3361\svchost.exe','');
QuarantineFile('c:\windows\dhcp\svchost.exe','');
QuarantineFile('c:\program files\thunmail\testabd.exe','');
QuarantineFile('c:\progra~1\ThunMail\testabd.dll','');
QuarantineFile('C:\DOCUME~1\Sandy\LOCALS~1\Temp\1095959750.exe','');
QuarantineFile('c:\docume~1\sandy\locals~1\temp\1095959750.exe','');
DeleteService('restore');
DeleteService('protect');
DeleteService('Bonjour Service');
DeleteFile('C:\WINDOWS\TEMP\fg7nymikb6.exe');
DeleteFile('c:\windows\temp\1973270796.exe');
DeleteFile('c:\windows\temp\1859052046.exe');
DeleteFile('C:\WINDOWS\TEMP\1859052046.exe');
DeleteFile('C:\WINDOWS\System32\svchost.exe');
DeleteFile('C:\WINDOWS\system32\jksahfo93wjfkd.dll');
DeleteFile('C:\WINDOWS\system32\drivers\restore.sys');
DeleteFile('C:\WINDOWS\System32\drivers\protect.sys');
DeleteFile('c:\windows\system32\3361\svchost.exe');
DeleteFile('C:\WINDOWS\system32\3361\SVCHOST.exe');
DeleteFile('c:\windows\dhcp\svchost.exe');
DeleteFile('c:\program files\thunmail\testabd.exe');
DeleteFile('c:\program files\bonjour\mdnsresponder.exe');
DeleteFile('C:\Program Files\Bonjour\mDNSResponder.exe');
DeleteFile('C:\Program Files\Bonjour\mdnsNSP.dll');
DeleteFile('c:\progra~1\ThunMail\testabd.dll');
DeleteFile('c:\docume~1\sandy\locals~1\temp\1095959750.exe');
DeleteFile('C:\DOCUME~1\Sandy\LOCALS~1\Temp\1095959750.exe');
DelCLSID('{B600E6E9-553B-4A19-8696-335E5C896153}');
DelBHO('{B2BA40A2-74F0-42BD-F434-12345A2C8953}');
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('restore');
BC_DeleteSvc('protect');
BC_DeleteSvc('Bonjour Service');
ExecuteRepair(13);
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Cure
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProg
- Close all the programs and start only Internet Explorer!!!
- Repeat a log file.
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=43845
- Attach a new log to your new post..