C:\Program Files\Kaspersky Lab\Копия Kaspersky Internet Security 2010\45.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\55.exe
Пробовали переименовывать?
Выполните скрипт в AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\Temp\051926.exe','');
QuarantineFile('C:\WINDOWS\Temp\051158.exe','');
QuarantineFile('C:\WINDOWS\system32\dllcache\lsasvc.dll','');
QuarantineFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\GPH765SS\158[2].exe','');
QuarantineFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\GPH765SS\158[1].exe','');
QuarantineFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\GPH765SS\155[1].exe','');
QuarantineFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\DBWC5OXC\05[1].exe','');
QuarantineFile('C:\WINDOWS\system32\drivers\rrhfg.sys','');
DeleteService('abp470n5');
QuarantineFile('Remote Switch.sys','');
QuarantineFile('xmlprov.sys','');
QuarantineFile('C:\Program Files\51Rem\51Rem.exe','');
DeleteService('Nationalyqc Instruments Domain');
QuarantineFile('C:\WINDOWS\system32\z\J001.exe','');
DeleteService('feag');
QuarantineFile('Cmbuhsrvc.sys','');
DeleteService('Cmbuhsrvc');
QuarantineFile('C:\WINDOWS\system32\YXGARD4WJL\D001.exe','');
DeleteService('bk');
StopService('te_Server_2008');
QuarantineFile('C:\WINDOWS\TEMP\NtHid.sys','');
QuarantineFile('C:\WINDOWS\TEMP\Entor.sys','');
QuarantineFile('c:\windows\system32\rpcss.dll','');
QuarantineFile('c:\windows\system32\qmgr.dll','');
QuarantineFile('c:\windows\system32\ntmssvc.dll','');
QuarantineFile('C:\WINDOWS\system32\kb91220421.dll','');
QuarantineFile('C:\WINDOWS\system32\kb8122049.dll','');
QuarantineFile('C:\WINDOWS\system32\kb41220358.dll','');
QuarantineFile('C:\WINDOWS\system32\kb181220545.dll','');
QuarantineFile('C:\WINDOWS\system32\kb01220349.dll','');
QuarantineFile('C:\WINDOWS\system32\t322023.dll','');
QuarantineFile('C:\WINDOWS\system32\t329078.dll','');
QuarantineFile('c:\windows\system32\wmitpfs.dll','');
QuarantineFile('C:\WINDOWS\Tasks\EfEPEaD4ZpVMUXrDbS.inf','');
QuarantineFile('c:\docume~1\alluse~1.win\drm\upebh.dll','');
DeleteFile('c:\docume~1\alluse~1.win\drm\upebh.dll');
DeleteFile('C:\WINDOWS\Tasks\EfEPEaD4ZpVMUXrDbS.inf');
DeleteFile('c:\windows\system32\wmitpfs.dll');
DeleteFile('C:\WINDOWS\system32\t329078.dll');
DeleteFile('C:\WINDOWS\system32\t322023.dll');
DeleteFile('C:\WINDOWS\system32\YXGARD4WJL\D001.exe');
DeleteFile('Cmbuhsrvc.sys');
DeleteFile('C:\WINDOWS\system32\z\J001.exe');
DeleteFile('C:\Program Files\51Rem\51Rem.exe');
DeleteFile('C:\WINDOWS\system32\drivers\rrhfg.sys');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\nwcworkstation\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\wmitpfs\Parameters','ServiceDll');
DeleteFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\DBWC5OXC\05[1].exe');
DeleteFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\GPH765SS\155[1].exe');
DeleteFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\GPH765SS\158[1].exe');
DeleteFile('C:\Documents and Settings\NetworkService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\GPH765SS\158[2].exe');
DeleteFile('C:\WINDOWS\system32\dllcache\lsasvc.dll');
DeleteFile('C:\WINDOWS\Temp\051158.exe');
DeleteFile('C:\WINDOWS\Temp\051926.exe');
DeleteFileMask('%Tmp%', '*.*', true);
DeleteFileMask('%userprofile%\Local Settings\Temporary Internet Files\Content.IE5', '*.*', true);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(9);
RebootWindows(true);
end.
Компьютер перезагрузится.
Пришлите карантин согласно Приложения 3 правил по красной ссылке Прислать запрошенный карантин вверху темы
Сделайте новые логи