На время выполнения скриптов, отключитесь от сети и отключите антивирусный монитор.
Пофиксите с помощью Hijackthis строку:
Код:
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
Программа AVZ - файл - выполнить скрипт - выполните следующий скрипт:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Documents and Settings\Usser\Local Settings\Temp\winzlGpO8gE3U.exe','');
QuarantineFile('C:\Documents and Settings\Usser\Local Settings\Temp\winHW6bSkMc49pznB.exe','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winxf27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winxe74.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winxe28.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winxd38.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winwe30.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winwd27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winwd05.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winve65.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winvc51.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winvc41.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Wintb38.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winta85.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winta30.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winsy51.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winsb06.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winqv62.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winpx41.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winou28.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winnt27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winms74.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winkq30.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winkq28.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winjr62.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winiq52.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winhn73.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winhn52.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Wingn85.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Wingm73.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winfn53.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winfl62.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Windk38.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Windj85.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Windj70.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Windi16.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Wincj41.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winci52.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winci28.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winag73.sys','');
QuarantineFile('C:\DOCUME~1\Usser\LOCALS~1\Temp\4\svchost.exe','');
DeleteFile('C:\DOCUME~1\Usser\LOCALS~1\Temp\4\svchost.exe');
BC_DeleteFile('C:\DOCUME~1\Usser\LOCALS~1\Temp\4\svchost.exe');
DeleteFile('C:\WINDOWS\System32\Drivers\Winag73.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winag73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winbg51.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winbg51.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winci28.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winci28.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winci52.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winci52.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wincj41.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Wincj41.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Windi16.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Windi16.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Windj70.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Windj70.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Windj85.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Windj85.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Windk38.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Windk38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winfl62.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winfl62.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winfn53.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winfn53.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wingm73.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Wingm73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wingn85.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Wingn85.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winhn52.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winhn52.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winhn73.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winhn73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winiq52.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winiq52.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winjr62.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winjr62.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winkq28.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winkq28.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winkq30.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winkq30.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winms74.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winms74.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winnt27.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winnt27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winou28.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winou28.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winov73.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winov73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winpx41.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winpx41.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winqv62.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winqv62.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winsb06.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winsb06.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winsy51.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winsy51.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winta30.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winta30.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winta85.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winta85.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wintb38.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Wintb38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winvc41.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winvc41.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winvc51.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winvc51.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winve65.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winve65.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winwd05.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winwd05.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winwd27.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winwd27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winwe30.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winwe30.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winxd38.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winxd38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winxe28.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winxe28.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winxe74.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winxe74.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winxf27.sys');
BC_DeleteFile('C:\WINDOWS\System32\Drivers\Winxf27.sys');
DeleteFile('C:\Documents and Settings\Usser\Local Settings\Temp\winzlGpO8gE3U.exe');
DeleteFile('C:\Documents and Settings\Usser\Local Settings\Temp\winHW6bSkMc49pznB.exe');
BC_DeleteFile('C:\Documents and Settings\Usser\Local Settings\Temp\winzlGpO8gE3U.exe');
BC_DeleteFile('C:\Documents and Settings\Usser\Local Settings\Temp\winHW6bSkMc49pznB.exe');
DeleteFile('WinCtrl32.dll');
Delwinlogonnotifybykeyname('WinCtrl32');
DeleteService('RasMan');
DeleteService('Winag73');
DeleteService('Winbg51');
DeleteService('Winci28');
DeleteService('Winci52');
DeleteService('Wincj41');
DeleteService('Windi16');
DeleteService('Windj70');
DeleteService('Windj85');
DeleteService('Windk38');
DeleteService('Winfl62');
DeleteService('Winfn53');
DeleteService('Wingm73');
DeleteService('Wingn85');
DeleteService('Winhn52');
DeleteService('Winhn73');
DeleteService('Winiq52');
DeleteService('Winjr62');
DeleteService('Winkq28');
DeleteService('Winkq30');
DeleteService('Winms74');
DeleteService('Winnt27');
DeleteService('Winou28');
DeleteService('Winov73');
DeleteService('Winpx41');
DeleteService('Winqv62');
DeleteService('Winsb06');
DeleteService('Winsy51');
DeleteService('Winta30');
DeleteService('Winta85');
DeleteService('Wintb38');
DeleteService('Winvc41');
DeleteService('Winvc51');
DeleteService('Winve65');
DeleteService('Winwd05');
DeleteService('Winwd27');
DeleteService('Winwe30');
DeleteService('Winxd38');
DeleteService('Winxe28');
DeleteService('Winxe74');
DeleteService('Winxf27');
BC_DeleteSVC('RasMan');
BC_DeleteSVC('Winag73');
BC_DeleteSVC('Winbg51');
BC_DeleteSVC('Winci28');
BC_DeleteSVC('Winci52');
BC_DeleteSVC('Wincj41');
BC_DeleteSVC('Windi16');
BC_DeleteSVC('Windj70');
BC_DeleteSVC('Windj85');
BC_DeleteSVC('Windk38');
BC_DeleteSVC('Winfl62');
BC_DeleteSVC('Winfn53');
BC_DeleteSVC('Wingm73');
BC_DeleteSVC('Wingn85');
BC_DeleteSVC('Winhn52');
BC_DeleteSVC('Winhn73');
BC_DeleteSVC('Winiq52');
BC_DeleteSVC('Winjr62');
BC_DeleteSVC('Winkq28');
BC_DeleteSVC('Winkq30');
BC_DeleteSVC('Winms74');
BC_DeleteSVC('Winnt27');
BC_DeleteSVC('Winou28');
BC_DeleteSVC('Winov73');
BC_DeleteSVC('Winpx41');
BC_DeleteSVC('Winqv62');
BC_DeleteSVC('Winsb06');
BC_DeleteSVC('Winsy51');
BC_DeleteSVC('Winta30');
BC_DeleteSVC('Winta85');
BC_DeleteSVC('Wintb38');
BC_DeleteSVC('Winvc41');
BC_DeleteSVC('Winvc51');
BC_DeleteSVC('Winve65');
BC_DeleteSVC('Winwd05');
BC_DeleteSVC('Winwd27');
BC_DeleteSVC('Winwe30');
BC_DeleteSVC('Winxd38');
BC_DeleteSVC('Winxe28');
BC_DeleteSVC('Winxe74');
BC_DeleteSVC('Winxf27');
BC_Activate;
ExecuteSysClean;
SetAVZPMStatus(True);
RebootWindows(true);
end.
После перезагрузки, карантин AVZ загрузите по ссылке http://virusinfo.info/upload_virus.php?tid=32826 , как написано в прил.2 правил, и повторите логи.