- Скачайте "OSAM" Online Solutions Autorun Manager тут. В меню драйверов правой кнопкой по sdvstu и выберите "Turn Run Off". Перезагрузку подтвердите.
- Выполните скрипт в AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
RegKeyStrParamWrite('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon','UserInit', GetEnvironmentVariable ('WinDir')+'\System32\userinit.exe,');
QuarantineFile('C:\WINDOWS\system32\Drivers\sdvstu.sys','');
QuarantineFile('C:\WINDOWS\system32\syssec32.exe','');
QuarantineFile('C:\WINDOWS\system32\ouickl.exe','');
QuarantineFile('C:\WINDOWS\system32\f06dd448.exe','');
QuarantineFile('C:\WINDOWS\system32\ehbxqe.exe','');
QuarantineFile('C:\WINDOWS\system32\6360d008.exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\mvvpymqq.sys','');
DeleteService('mvvpymqq');
QuarantineFile('C:\WINDOWS\TEMP\5520afd5af7c','');
DeleteService('fa7b4d75c8ed702a');
DeleteService('eb743624380d1702');
DeleteService('dc585ed28a7f8dc8');
DeleteService('d04ee41c9c0a430c');
QuarantineFile('C:\WINDOWS\TEMP\5520da7556bc','');
QuarantineFile('C:\WINDOWS\TEMP\5520ae1c5384','');
DeleteService('cc8470ba0e4f9793');
DeleteService('b1b537ddc736943d');
DeleteService('ac8995da3ea337a3');
QuarantineFile('C:\WINDOWS\TEMP\556043d1a590','');
QuarantineFile('C:\WINDOWS\TEMP\56008eea7580','');
DeleteService('a9c85ab8d8f383ff');
DeleteService('a438b61362a4bf6e');
DeleteService('a3f509843c2891c6');
DeleteService('9264c55313bb6994');
QuarantineFile('C:\WINDOWS\TEMP\5520251ce134','');
QuarantineFile('C:\WINDOWS\TEMP\5520854d0338','');
QuarantineFile('C:\WINDOWS\TEMP\5600cd87ce70','');
QuarantineFile('C:\WINDOWS\TEMP\5560c2a960','');
QuarantineFile('C:\WINDOWS\TEMP\5520f5a28730','');
QuarantineFile('C:\WINDOWS\TEMP\5600153187c4','');
QuarantineFile('C:\WINDOWS\TEMP\5640a04295c','');
QuarantineFile('C:\WINDOWS\TEMP\5520e782cf3c','');
QuarantineFile('C:\WINDOWS\TEMP\56002f4fef04','');
QuarantineFile('C:\WINDOWS\TEMP\55203ac3d4b0','');
QuarantineFile('C:\WINDOWS\TEMP\552082bac88','');
DeleteService('7be4a28872a8019a');
DeleteService('766c5aff545e591f');
DeleteService('51075a852cb2435c');
DeleteService('46d9e1af036386f3');
DeleteService('444cf24ff15b4dfe');
DeleteService('2aeae007bcc26b97');
DeleteService('22b5b87511914f23');
DeleteService('1eea3be5145c0a50');
DeleteService('1e95bedd4436c807');
DeleteService('0bd55cac7b49d130');
DeleteService('0ad22bb8aae42093');
DeleteService('06b37c5a27ac5891');
QuarantineFile('c:\program files\lovivkontakte\lovivkontakte.exe','');
DeleteFile('C:\WINDOWS\TEMP\552082bac88');
DeleteFile('C:\WINDOWS\TEMP\55203ac3d4b0');
DeleteFile('C:\WINDOWS\TEMP\56002f4fef04');
DeleteFile('C:\WINDOWS\TEMP\5520e782cf3c');
DeleteFile('C:\WINDOWS\TEMP\5640a04295c');
DeleteFile('C:\WINDOWS\TEMP\5600153187c4');
DeleteFile('C:\WINDOWS\TEMP\5520f5a28730');
DeleteFile('C:\WINDOWS\TEMP\560094b15f68');
DeleteFile('C:\WINDOWS\TEMP\5640d82bada4');
DeleteFile('C:\WINDOWS\TEMP\5560c2a960');
DeleteFile('C:\WINDOWS\TEMP\5600cd87ce70');
DeleteFile('C:\WINDOWS\TEMP\5520854d0338');
DeleteFile('C:\WINDOWS\TEMP\5520251ce134');
DeleteFile('C:\WINDOWS\TEMP\56008eea7580');
DeleteFile('C:\WINDOWS\TEMP\5640f1579a24');
DeleteFile('C:\WINDOWS\TEMP\5560c53d2930');
DeleteFile('C:\WINDOWS\TEMP\556043d1a590');
DeleteFile('C:\WINDOWS\TEMP\55206231ea68');
DeleteFile('C:\WINDOWS\TEMP\560048cac070');
DeleteFile('C:\WINDOWS\TEMP\5520ae1c5384');
DeleteFile('C:\WINDOWS\TEMP\5520da7556bc');
DeleteFile('C:\WINDOWS\TEMP\5520333130b0');
DeleteFile('C:\WINDOWS\TEMP\5520afd5af7c');
DeleteFile('C:\WINDOWS\system32\drivers\mvvpymqq.sys');
DeleteFile('C:\WINDOWS\system32\6360d008.exe');
DeleteFile('C:\WINDOWS\system32\ehbxqe.exe');
DeleteFile('C:\WINDOWS\system32\f06dd448.exe');
DeleteFile('C:\WINDOWS\system32\ouickl.exe');
DeleteFile('C:\WINDOWS\system32\syssec32.exe');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','Secure Star');
DeleteFile('C:\WINDOWS\system32\Drivers\sdvstu.sys');
BC_ImportAll;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
После перезагрузки:
- выполните такой скрипт
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
- Файл quarantine.zip из папки AVZ загрузите по ссылке Прислать запрошенный карантин вверху темы
- Сделайте повторные логи по правилам п.2 и 3 раздела Диагностика.(virusinfo_syscheck.zip;hijackthis.log)