Switch your Antivirus and Firewall OFF!!!
Switch the System Recovery off
Run Hijackthis and Fix
Код:
O2 - BHO: (no name) - {164DBEE2-7074-4C63-B6AF-066852EDFB95} - c:\windows\system32\cnvfatr.dll
O2 - BHO: (no name) - {2A722E69-CFE6-495F-8CE1-719F8F9383D1} - C:\WINDOWS\system32\dpnhpastw.dll
O20 - Winlogon Notify: yznfncmh - C:\WINDOWS\SYSTEM32\cnvfatr.dll
Run the script
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteService('ouwwfedk');
QuarantineFile('C:\WINDOWS\System32\bcmwlpkt.dll','');
QuarantineFile('C:\WINDOWS\System32\bcm1xsup.dll','');
QuarantineFile('C:\WINDOWS\system32\dpnhpastw.dll','');
QuarantineFile('c:\windows\system32\cnvfatr.dll','');
QuarantineFile('C:\WINDOWS\system32\Drivers\ouwwfedk.sys','');
QuarantineFile('C:\WINDOWS\system32\dpnhpastw.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\ouwwfedk.sys','');
DelBHO('{2A722E69-CFE6-495F-8CE1-719F8F9383D1}');
DelBHO('{164DBEE2-7074-4C63-B6AF-066852EDFB95}');
DelBHO('ID');
DelBHO('{2A722E69-CFE6-495F-8CE1-719F8F9383D1}');
DeleteFile('C:\WINDOWS\system32\drivers\ouwwfedk.sys');
DeleteFile('C:\WINDOWS\system32\dpnhpastw.dll');
DeleteFile('C:\WINDOWS\system32\Drivers\ouwwfedk.sys');
DeleteFile('c:\windows\system32\cnvfatr.dll');
DeleteFile('C:\WINDOWS\system32\dpnhpastw.dll');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(1);
ExecuteRepair(6);
EcecuteRepair(7);
RebootWindows(true);
end.
After re-boot upload a quarantine file following red the link on the top of the page and make/attach 3 new logfiles.