Switch off/Disable:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual disinfection
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ClearQuarantine;
TerminateProcessByName('c:\windows\msa.exe');
TerminateProcessByName('c:\windows\ccdrive32.exe');
TerminateProcessByName('c:\nmwsrvm.exe');
TerminateProcessByName('c:\lsass.exe');
TerminateProcessByName('c:\docume~1\faraz\locals~1\temp\xv1.exe');
StopService('beiwzfbt');
QuarantineFile('c:\windows\system32\sshnas21.dll','');
QuarantineFile('C:\WINDOWS\system32\Drivers\smwypc.sys','');
QuarantineFile('C:\WINDOWS\system32\drivers\beiwzfbt.sys','');
QuarantineFile('c:\windows\msa.exe','');
QuarantineFile('c:\windows\ccdrive32.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-6427390614-5871298602-143923584-1408\wnzip32.exe','');
QuarantineFile('c:\nmwsrvm.exe','');
QuarantineFile('c:\lsass.exe','');
QuarantineFile('c:\docume~1\faraz\locals~1\temp\xv1.exe','');
DeleteService('beiwzfbt');
DeleteFile('c:\windows\system32\sshnas21.dll');
DeleteFile('C:\WINDOWS\system32\Drivers\smwypc.sys');
DeleteFile('C:\WINDOWS\system32\drivers\beiwzfbt.sys');
DeleteFile('c:\windows\msa.exe');
DeleteFile('c:\windows\ccdrive32.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-6427390614-5871298602-143923584-1408\wnzip32.exe');
DeleteFile('c:\nmwsrvm.exe');
DeleteFile('c:\lsass.exe');
DeleteFile('c:\docume~1\faraz\locals~1\temp\xv1.exe');
DelBHO('{92780B25-18CC-41C8-B9BE-3C9C571A8263}');
DelBHO('{2670000A-7350-4f3c-8081-5663EE0C6C49}');
DelBHO('{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}');
DeleteService('smwypc');
RegKeyResetSecurity('HKLM','SYSTEM\CurrentControlSet\Services\smwypc');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
RegKeyIntParamWrite( 'HKLM', 'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum', '{BDEADF00-C265-11D0-BCED-00A0C90AB50F}', 1);
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
BC_DeleteSvc('beiwzfbt');
ExecuteRepair(6);
ExecuteRepair(8);
ExecuteRepair(9);
ExecuteRepair(11);
ExecuteRepair(16);
ExecuteRepair(17);
SetAVZPMStatus(True);
RebootWindows(true);
end.
After reboot execute following script in Manual disinfection
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
and upload the C:\quarantine.zip over the link Upload quarantined files on the top of this page.
- Clean Temp-Maps, Cache of Browsers, Recycler. Use Windows service tool cleanmgr or CCleaner or ClearProg
- Close all the programs and start only Internet Explorer!!!
- Repeat a log file of AVPTool.
- Make a log file with Hijackthis ( Analysis, p.3 for further informations).
- Switch Antivirus and, if you have - Firewall, on.
- Go On-Line
- Attach both logs to your new post..