1.Пофиксить в HijackThis следующие строчки ( http://virusinfo.info/showthread.php?t=4491 )
Код:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - HKLM\..\Run: [buritos] buritos.exe
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - WLCtrl32.dll (file missing)
Без перезагрузки выполните.
2.AVZ, меню "Файл - Выполнить скрипт" -- Скопировать ниже написанный скрипт-- Нажать кнопку "Запустить".
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\ntos.exe','');
QuarantineFile('C:\DOCUME~1\User\LOCALS~1\Temp\loader.exe','');
QuarantineFile('C:\WINDOWS\system32\blphcp1ej0e73t.scr','');
QuarantineFile('C:\WINDOWS\system32\braviax.exe','');
QuarantineFile('C:\WINDOWS\System32\drivers\Winuy03.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Wae71.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Vcf36.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Txb82.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Rvy71.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Rvy25.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Qwb47.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Quy70.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Ptx70.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Ptw35.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Mru82.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Mqu46.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Lor71.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Inq58.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Hln03.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Hkn14.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Eim14.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Bfi60.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Adh25.sys','');
QuarantineFile('C:\WINDOWS\system32\hblogon.dll','');
QuarantineFile('c:\windows\system32\buritos.exe','');
TerminateProcessByName('c:\windows\system32\buritos.exe');
DeleteFile('c:\windows\system32\buritos.exe');
DeleteFile('c:\windows\system32\vhosts.exe');
DeleteFile('C:\WINDOWS\System32\drivers\Adh25.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Bfi60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Eim14.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Hkn14.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Hln03.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Inq58.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Lor71.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Mqu46.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Mru82.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Ptw35.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Ptx70.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Quy70.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Qwb47.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Rvy25.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Rvy71.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Txb82.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Vcf36.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Wae71.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Winuy03.sys');
DeleteFile('C:\WINDOWS\system32\braviax.exe');
DeleteFile('C:\WINDOWS\system32\blphcp1ej0e73t.scr');
DeleteFile('C:\DOCUME~1\User\LOCALS~1\Temp\loader.exe');
DeleteFile('C:\WINDOWS\system32\ntos.exe');
BC_ImportAll;
BC_DeleteSvc('wuauservNtLmSsp');
BC_DeleteSvc('WebClientCryptSvcSchedule');
BC_DeleteSvc('TlntSvrose');
BC_DeleteSvc('SysmonLogNetDDEdsdm');
BC_DeleteSvc('SwPrvVSS');
BC_DeleteSvc('NlaCryptSvcSchedule');
BC_DeleteSvc('NetmanSSDPSRV');
BC_DeleteSvc('msupdate');
BC_DeleteSvc('CryptSvcSchedule');
BC_DeleteSvc('CiSvcUPSNetDDEdsdm');
BC_DeleteSvc('CiSvcUPS');
BC_DeleteSvc('6to46to4');
BC_DeleteSvc('Winuy03');
BC_DeleteSvc('Wae71');
BC_DeleteSvc('Vcf36');
BC_DeleteSvc('Txb82');
BC_DeleteSvc('Rvy25');
BC_DeleteSvc('Qwb47');
BC_DeleteSvc('Quy70');
BC_DeleteSvc('Ptx70');
BC_DeleteSvc('Ptw35');
BC_DeleteSvc('Mru82');
BC_DeleteSvc('Mqu46');
BC_DeleteSvc('Lor71');
BC_DeleteSvc('Inq58');
BC_DeleteSvc('Hln03');
BC_DeleteSvc('Hkn14');
BC_DeleteSvc('Eim14');
BC_DeleteSvc('Bfi60');
BC_DeleteSvc('Adh25');
ExecuteSysClean;
ExecuteRepair(5);
ExecuteRepair(6);
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.
Прислать карантин согласно приложения 3 правил .
Загружать по ссылке: http://virusinfo.info/upload_virus.php?tid=30745
Повторите логи.