Пофиксите в hijackthis:
Код:
O20 - AppInit_DLLs: ss12b60096dll.dll,ss12d50000dll.dll,ss12a70096dll.dll,ar12a80099dll.dll,ss12c40088dll.dll
O23 - Service: trseb (Aetrsx) - Unknown owner - C:\WINDOWS\Avx.exe (file missing)
O23 - Service: Application Layer Gateway Servicd (ALB) - Unknown owner - C:\WINDOWS\system32\alb.exe (file missing)
O23 - Service: Ati Hotf (Ati2ef) - Unknown owner - C:\WINDOWS\Ati2ef.exe (file missing)
O23 - Service: Ati HotK (Ati2ev) - Unknown owner - C:\WINDOWS\Ati2ev.exe (file missing)
O23 - Service: Ati Hotes (Aties) - Unknown owner - C:\WINDOWS\Aties.exe (file missing)
O23 - Service: Test (cld) - Unknown owner - C:\WINDOWS\file.exe (file missing)
O23 - Service: ·юОсНР№Ь Internet ГЬФїЅ»»»(IKE)єНЙн·ЭСйЦ¤ Internet Р*Тй(AuthIP)јьїШДЈїйЎЈ1.6 (Description1.6) - Unknown owner - C:\WINDOWS\system32\IDFYCEFMDZ\H001.exe (file missing)
O23 - Service: ·юОсНР№Ь Internet ГЬФїЅ»»»(IKE)єНЙн·ЭСйЦ¤ Internet Р*Тй(AuthIP)јьїШДЈїйЎЈHero (DescriptionHero) - Unknown owner - C:\WINDOWS\system32\z\P001.exe (file missing)
Выполните скрипт в AVZ (AVZ, Меню Файл\Выполнить скрипт. Подробнее...):
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\WINDOWS\system32\fgukf.dll','');
QuarantineFile('C:\WINDOWS\system32\RmmxtqC.dll','');
QuarantineFile('C:\WINDOWS\TEMP\tro1261042518.exe','');
QuarantineFile('C:\WINDOWS\TEMP\regular.sys','');
QuarantineFile('C:\WINDOWS\system32\alb.exe','');
QuarantineFile('C:\WINDOWS\Ati2ef.exe','');
QuarantineFile('C:\WINDOWS\Ati2ev.exe','');
QuarantineFile('C:\WINDOWS\Aties.exe','');
QuarantineFile('C:\WINDOWS\file.exe','');
QuarantineFile('C:\WINDOWS\system32\IDFYCEFMDZ\H001.exe','');
QuarantineFile('C:\WINDOWS\system32\z\P001.exe','');
QuarantineFile('C:\WINDOWS\dsfs.exe','');
QuarantineFile('C:\WINDOWS\resdx.exe','');
QuarantineFile('C:\WINDOWS\system32\OYCMTV8E9S\D001.exe','');
QuarantineFile('C:\WINDOWS\system32\akqaw.exe','');
QuarantineFile('C:\WINDOWS\system32\JYPVJJYIVV\J002.exe','');
QuarantineFile('C:\WINDOWS\system32\OYCMTV8E9S\J002.exe','');
QuarantineFile('C:\WINDOWS\system32\z\G001.exe','');
QuarantineFile('C:\WINDOWS\system32\P1BEG2OLP5\M001.exe','');
QuarantineFile('C:\WINDOWS\vfx.exe','');
DeleteService('regul1r');
DeleteService('s');
DeleteService('tt');
DeleteService('vf');
DeleteService('vfs');
DeleteService('vsx');
DeleteService('Mindaek360');
DeleteService('gcbg');
DeleteService('fs');
DeleteService('dsafds');
DeleteService('DescriptionHero');
DeleteService('Description1.6');
DeleteService('cld');
DeleteService('Aties');
DeleteService('Ati2ev');
DeleteService('Ati2ef');
DeleteService('ALB');
QuarantineFile('C:\WINDOWS\Avx.exe','');
DeleteService('Aetrsx');
QuarantineFile('c:\windows\system32\fgukf.dll','');
DeleteFile('c:\windows\system32\fgukf.dll');
DeleteFile('C:\WINDOWS\Avx.exe');
DeleteFile('C:\WINDOWS\vfx.exe');
DeleteFile('C:\WINDOWS\system32\P1BEG2OLP5\M001.exe');
DeleteFile('C:\WINDOWS\system32\z\G001.exe');
DeleteFile('C:\WINDOWS\system32\OYCMTV8E9S\J002.exe');
DeleteFile('C:\WINDOWS\system32\JYPVJJYIVV\J002.exe');
DeleteFile('C:\WINDOWS\system32\akqaw.exe');
DeleteFile('C:\WINDOWS\system32\OYCMTV8E9S\D001.exe');
DeleteFile('C:\WINDOWS\resdx.exe');
DeleteFile('C:\WINDOWS\dsfs.exe');
DeleteFile('C:\WINDOWS\system32\z\P001.exe');
DeleteFile('C:\WINDOWS\system32\IDFYCEFMDZ\H001.exe');
DeleteFile('C:\WINDOWS\file.exe');
DeleteFile('C:\WINDOWS\Aties.exe');
DeleteFile('C:\WINDOWS\Ati2ev.exe');
DeleteFile('C:\WINDOWS\Ati2ef.exe');
DeleteFile('C:\WINDOWS\system32\alb.exe');
DeleteFile('C:\WINDOWS\TEMP\regular.sys');
DeleteFile('C:\WINDOWS\TEMP\tro1261042518.exe');
DeleteFile('C:\WINDOWS\system32\RmmxtqC.dll');
DeleteFile('C:\WINDOWS\system32\fgukf.dll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\ПµНіІ№¶Ў\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\ias\Parameters','ServiceDll');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После выполнения скрипта компьютер перезагрузится.
После перезагрузки пришлите попавшие в карантин файлы согласно правилам
Сделайте новые логи