Закройте все открытые приложения, кроме АVZ и Internet Explorer.
Отключите
- ПК от интернета/локалки
- Антивирус и Файрвол.
- Системное восстановление.
- Выполните скрипт
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\mail\indexer\indexer.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\mail\lexicon\lexicon.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0000\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0000\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0000\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0001\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0001\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0001\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0002\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0002\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0002\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0003\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0003\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0003\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0004\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0004\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0004\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0005\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0005\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0005\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0006\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0006\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0006\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0007\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0007\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0007\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0008\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0008\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0008\wb.vx','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0009\url.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0009\w.ax','');
QuarantineFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0009\wb.vx','');
QuarantineFile('C:\CCProxy\CCProxy.exe','');
QuarantineFile('C:\WINDOWS\JYACRRCB.exe','');
QuarantineFile('C:\WINDOWS\system32\webcheck.dll','');
DelBHO('{0026439F-A980-4f18-8C95-4F1CBBF9C1D8}');
DelBHO('{201f27d4-3704-41d6-89c1-aa35e39143ed}');
DeleteFile('C:\Program Files\AskBarDis\bar\bin\askBar.dll');
DeleteFile('C:\WINDOWS\JYACRRCB.exe');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\mail\indexer\indexer.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\mail\lexicon\lexicon.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0000\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0000\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0000\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0001\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0001\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0001\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0002\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0002\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0002\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0003\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0003\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0003\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0004\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0004\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0004\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0005\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0005\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0005\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0006\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0006\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0006\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0007\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0007\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0007\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0008\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0008\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0008\wb.vx');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0009\url.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0009\w.ax');
DeleteFile('C:\Documents and Settings\Ya\Local Settings\Application Data\Opera\Opera\profile\vps\0009\wb.vx');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки:
- Очистите темп-папки, кэш проводников и корзину.
- Закройте все программы, включая Антивирус и Файрвол, Оставьте запущенным только Internet Explorer. Если он не запущен - запустите!!!
- Сделайте повторные логи по правилам.
- Включите Антвирус и Файрволл
- Подключите ПК к интернету/локалке
- Закачайте карантин по ссылке Прислать запрошенный карантин вверху темы (Приложение 2 правил).
- Прикрепите логи к новому сообщению.