Закройте/выгрузите все программы кроме AVZ и Internet Explorer.
Отключите
- ПК от интернета/локалки
- Антивирус и Файрвол.
- Системное восстановление.
- Выполните скрипт
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
StopService('Winxd26');
StopService('Winty73');
StopService('Winty40');
StopService('Winty16');
StopService('Winta84');
StopService('Winrw62');
StopService('Winrw61');
StopService('Winqv84');
StopService('Winqv15');
StopService('Winpu72');
StopService('Winpu51');
StopService('Winpu05');
StopService('Winns16');
StopService('Winmr62');
StopService('Winlq83');
StopService('Winjp16');
StopService('Winin26');
StopService('Winhm84');
StopService('Wingl27');
StopService('Winej84');
StopService('Windi40');
StopService('Winch84');
StopService('Winch16');
StopService('Winaf38');
StopService('Winaf05');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winye84.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winye72.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winxd26.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winty73.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winty40.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winty16.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winta84.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winrw62.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winrw61.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winqv84.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winqv15.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winpu72.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winpu51.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winpu05.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winot38.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winns16.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winmr62.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winlq83.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winjp16.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winin62.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winin26.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winhm84.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Wingl27.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winej84.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Windi40.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winch84.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winch16.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winaf38.sys','');
QuarantineFile('C:\WINDOWS\System32\Drivers\Winaf05.sys','');
QuarantineFile('C:\Documents and Settings\User\Мои документы\Илья1\Скрипт\TTKKP5\TTKKP5\TTKKP5\IJconfigurator5.exe','');
QuarantineFile('C:\BUX\IJconfigurator5.exe','');
DeleteService('Winye84');
DeleteService('Winye72');
DeleteService('Winxd26');
DeleteService('Winty73');
DeleteService('Winty40');
DeleteService('Winty16');
DeleteService('Winta84');
DeleteService('Winrw62');
DeleteService('Winrw61');
DeleteService('Winqv84');
DeleteService('Winqv15');
DeleteService('Winpu72');
DeleteService('Winpu51');
DeleteService('Winpu05');
DeleteService('Winot38');
DeleteService('Winns16');
DeleteService('Winmr62');
DeleteService('Winlq83');
DeleteService('Winjp16');
DeleteService('Winin62');
DeleteService('Winin26');
DeleteService('Winhm84');
DeleteService('Wingl27');
DeleteService('Winej84');
DeleteService('Windi40');
DeleteService('Winch84');
DeleteService('Winaf38');
DeleteService('Winaf05');
DeleteFile('C:\WINDOWS\System32\Drivers\Winye84.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winye72.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winxd26.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winty73.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winty40.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winty16.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winta84.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winrw62.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winrw61.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winqv84.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winqv15.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winpu72.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winpu51.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winpu05.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winot38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winns16.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winmr62.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winlq83.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winjp16.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winin62.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winin26.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winhm84.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wingl27.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winej84.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Windi40.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winch84.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winch16.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winaf38.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Winaf05.sys');
BC_ImportAll;
ExecuteSysClean;
bc_deletesvc('Winye84');
bc_deletesvc('Winye72');
bc_deletesvc('Winxd26');
bc_deletesvc('Winty73');
bc_deletesvc('Winty40');
bc_deletesvc('Winty16');
bc_deletesvc('Winta84');
bc_deletesvc('Winrw62');
bc_deletesvc('Winrw61');
bc_deletesvc('Winqv84');
bc_deletesvc('Winqv15');
bc_deletesvc('Winpu72');
bc_deletesvc('Winpu51');
bc_deletesvc('Winpu05');
bc_deletesvc('Winot38');
bc_deletesvc('Winns16');
bc_deletesvc('Winmr62');
bc_deletesvc('Winlq83');
bc_deletesvc('Winjp16');
bc_deletesvc('Winin62');
bc_deletesvc('Winin26');
bc_deletesvc('Winhm84');
bc_deletesvc('Wingl27');
bc_deletesvc('Winej84');
bc_deletesvc('Windi40');
bc_deletesvc('Winch84');
bc_deletesvc('Winaf38');
bc_deletesvc('Winaf05');
BC_Activate;
RebootWindows(true);
end.
После перезагрузки:
- Очистите темп-папки, кэш проводников и корзину.
- Закройте все программы, включая Антивирус и Файрвол, Оставьте запущенным только Internet Explorer. Если он не запущен - запустите!!!
- Сделайте повторные логи
Код:
virusinfo_syscure.zip
virusinfo_syscheck.zip
hijackthis.log
- Включите Антвирус и Файрволл
- Подключите ПК к интернету/локалке
- Закачайте карантин по ссылке Прислать запрошенный карантин вверху темы (Приложение 3 правил).
- Прикрепите логи к новому сообщению.