Перед выполнением всех операций Outpost лучше отключить
Пофиксить в HiJack
Код:
O4 - HKLM\..\Run: [netmon] C:\WINDOWS\system\netmon.exe
O4 - HKLM\..\Run: [Microsoft(R) System Manager] C:\WINDOWS\system32\49d265.exe
O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\system32\csrs.exe
O4 - HKCU\..\Run: [msmacro32] C:\WINDOWS\msmacro64.exe
O4 - HKCU\..\Run: [] C:\Documents and Settings\Светлана\.exe /i
O4 - HKCU\..\Run: [Светлана] C:\Documents and Settings\Светлана\Светлана.exe /i
Выполните скрипт в AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteService('xwkqtkuch');
DeleteService('xjgide');
DeleteService('ws2_32sik');
DeleteService('wkjnvuan');
DeleteService('wbjwllqju');
DeleteService('vfwoqvlf');
DeleteService('tswqhctp');
DeleteService('teazhaly');
DeleteService('systemntmi');
DeleteService('swiysgpj');
DeleteService('securentm');
DeleteService('sakoc');
DeleteService('rmaezd');
DeleteService('ribij');
DeleteService('qrlvx');
DeleteService('qlyhadh');
DeleteService('qetupxpew');
DeleteService('pyvlv');
DeleteService('port135sik');
DeleteService('oiamvf');
DeleteService('nyruweji');
DeleteService('nqcpwr');
DeleteService('nkzayi');
DeleteService('nicsk32');
DeleteService('netsik');
DeleteService('mrxasb');
DeleteService('mhiasjoie');
DeleteService('mavixh');
DeleteService('kvnuvsn');
DeleteService('ksi32sk');
DeleteService('jgtxpnqsm');
DeleteService('jfnqkgopk');
DeleteService('ixfkphw');
DeleteService('ibzwth');
DeleteService('i386si');
DeleteService('hqqzm');
DeleteService('hlgmviu');
DeleteService('hgivtxnzp');
DeleteService('hddsxy');
DeleteService('goitq');
DeleteService('fueuxnl');
DeleteService('fqzvwgjbn');
DeleteService('fips32cup');
DeleteService('evxjicg');
DeleteService('emmnundh');
DeleteService('eleywxs');
DeleteService('ebueaz');
DeleteService('ddoznp');
DeleteService('cfxnmen');
DeleteService('caqwcngw');
DeleteService('avkisa');
DeleteService('ati64si');
DeleteService('anailuir');
DeleteService('amd64si');
DeleteService('acpi32');
QuarantineFile('C:\WINDOWS\system32\smiqxjz.dll','');
DeleteFile('C:\WINDOWS\system32\smiqxjz.dll');
QuarantineFile('C:\WINDOWS\system32\drivers\acpi32.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\securentm.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\nicsk32.sys','');
QuarantineFile('C:\WINDOWS\system32\073.tmp','');
QuarantineFile('C:\WINDOWS\system32\042.tmp','');
QuarantineFile('C:\WINDOWS\system32\drivers\port135sik.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\systemntmi.sys','');
QuarantineFile('C:\WINDOWS\system32\02A.tmp','');
QuarantineFile('C:\WINDOWS\system32\drivers\netsik.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\amd64si.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\i386si.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys','');
QuarantineFile('H:\autorun.inf','');
QuarantineFile('C:\WINDOWS\system32\drivers\fips32cup.sys','');
QuarantineFile('C:\WINDOWS\system32\csrs.exe','');
QuarantineFile('C:\WINDOWS\system32\49d265.exe','');
QuarantineFile('C:\WINDOWS\system\netmon.exe','');
QuarantineFile('C:\WINDOWS\msmacro64.exe','');
QuarantineFile('C:\Documents and Settings\Светлана\Светлана.exe','');
QuarantineFile('C:\Documents and Settings\Светлана\.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\ksi32sk.sys','');
QuarantineFile('C:\WINDOWS\system32\01.tmp','');
QuarantineFile('C:\WINDOWS\system32\drivers\ati64si.sys','');
DeleteFile('C:\WINDOWS\system32\drivers\acpi32.sys');
DeleteFile('C:\WINDOWS\system32\drivers\amd64si.sys');
DeleteFile('C:\WINDOWS\system32\02A.tmp');
DeleteFile('C:\WINDOWS\system32\drivers\ati64si.sys');
DeleteFile('C:\WINDOWS\system32\01.tmp');
DeleteFile('C:\WINDOWS\system32\drivers\fips32cup.sys');
DeleteFile('C:\WINDOWS\system32\drivers\i386si.sys');
DeleteFile('C:\WINDOWS\system32\drivers\ksi32sk.sys');
DeleteFile('C:\WINDOWS\system32\drivers\netsik.sys');
DeleteFile('C:\WINDOWS\system32\drivers\nicsk32.sys');
DeleteFile('C:\WINDOWS\system32\drivers\port135sik.sys');
DeleteFile('C:\WINDOWS\system32\073.tmp');
DeleteFile('C:\WINDOWS\system32\042.tmp');
DeleteFile('C:\WINDOWS\system32\drivers\securentm.sys');
DeleteFile('C:\WINDOWS\system32\drivers\systemntmi.sys');
DeleteFile('C:\WINDOWS\system32\drivers\ws2_32sik.sys');
DeleteFile('C:\Documents and Settings\Светлана\.exe');
DeleteFile('C:\Documents and Settings\Светлана\Светлана.exe');
DeleteFile('C:\WINDOWS\msmacro64.exe');
DeleteFile('C:\WINDOWS\system32\49d265.exe');
DeleteFile('C:\WINDOWS\system32\csrs.exe');
DeleteFile('C:\WINDOWS\system\netmon.exe');
DeleteFile('H:\autorun.inf');
RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('xwkqtkuch');
BC_DeleteSvc('xjgide');
BC_DeleteSvc('ws2_32sik');
BC_DeleteSvc('wkjnvuan');
BC_DeleteSvc('wbjwllqju');
BC_DeleteSvc('vfwoqvlf');
BC_DeleteSvc('tswqhctp');
BC_DeleteSvc('teazhaly');
BC_DeleteSvc('systemntmi');
BC_DeleteSvc('swiysgpj');
BC_DeleteSvc('securentm');
BC_DeleteSvc('sakoc');
BC_DeleteSvc('rmaezd');
BC_DeleteSvc('ribij');
BC_DeleteSvc('qrlvx');
BC_DeleteSvc('qlyhadh');
BC_DeleteSvc('qetupxpew');
BC_DeleteSvc('pyvlv');
BC_DeleteSvc('port135sik');
BC_DeleteSvc('oiamvf');
BC_DeleteSvc('nyruweji');
BC_DeleteSvc('nqcpwr');
BC_DeleteSvc('nkzayi');
BC_DeleteSvc('nicsk32');
BC_DeleteSvc('netsik');
BC_DeleteSvc('mrxasb');
BC_DeleteSvc('mhiasjoie');
BC_DeleteSvc('mavixh');
BC_DeleteSvc('kvnuvsn');
BC_DeleteSvc('ksi32sk');
BC_DeleteSvc('jgtxpnqsm');
BC_DeleteSvc('jfnqkgopk');
BC_DeleteSvc('ixfkphw');
BC_DeleteSvc('ibzwth');
BC_DeleteSvc('i386si');
BC_DeleteSvc('hqqzm');
BC_DeleteSvc('hlgmviu');
BC_DeleteSvc('hgivtxnzp');
BC_DeleteSvc('hddsxy');
BC_DeleteSvc('goitq');
BC_DeleteSvc('fueuxnl');
BC_DeleteSvc('fqzvwgjbn');
BC_DeleteSvc('fips32cup');
BC_DeleteSvc('evxjicg');
BC_DeleteSvc('emmnundh');
BC_DeleteSvc('eleywxs');
BC_DeleteSvc('ebueaz');
BC_DeleteSvc('ddoznp');
BC_DeleteSvc('cfxnmen');
BC_DeleteSvc('caqwcngw');
BC_DeleteSvc('avkisa');
BC_DeleteSvc('ati64si');
BC_DeleteSvc('anailuir');
BC_DeleteSvc('amd64si');
BC_DeleteSvc('acpi32');
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Пришлите карантин согласно Приложения 3 правил по красной ссылке Прислать запрошенный карантин вверху темы
Очистите темп-папки, кэш проводников и корзину.
Сделайте новые логи
Дополнительно сделать такой лог http://virusinfo.info/showthread.php?t=40118