You've got Sality, first of all you have to heal your system with Live CD from Dr. Web: http://www.freedrweb.com/livecd/?lng=en
After healing:
Close/unload all the programs excepted AVZ and Internet Explorer
Switch off:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script in Manual Healing
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\windows\system32\chgservice.exe');
QuarantineFile('C:\RECYCLER\S-1-5-21-6010588012-1972695393-938844294-8176\wnzip32.exe,C:\RECYCLER\S-1-5-21-7911114985-5736847207-370379298-0617\sysdate.exe,explorer.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-6010588012-1972695393-938844294-8176\wnzip32.exe','');
QuarantineFile('C:\RECYCLER\S-1-5-21-7911114985-5736847207-370379298-0617\sysdate.exe','');
StopService('aic32p');
DeleteService('aic32p');
BC_DeleteSvc('aic32p');
QuarantineFile('C:\WINDOWS\system32\drivers\lkkpsn.sys','');
QuarantineFile('xfhcmona.sys','');
QuarantineFile('c:\windows\system32\chgservice.exe','');
DeleteFile('c:\windows\system32\chgservice.exe');
DeleteFile('C:\WINDOWS\system32\drivers\lkkpsn.sys');
DeleteFile('C:\RECYCLER\S-1-5-21-6010588012-1972695393-938844294-8176\wnzip32.exe,C:\RECYCLER\S-1-5-21-7911114985-5736847207-370379298-0617\sysdate.exe,explorer.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-6010588012-1972695393-938844294-8176\wnzip32.exe');
DeleteFile('C:\RECYCLER\S-1-5-21-6010588012-1972695393-938844294-8176\sysdate.exe');
executerepair(6);
executerepair(8);
executerepair(9);
executerepair(11);
executerepair(16);
executerepair(17);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
After reboot:
- Execute following script in Manual Healing
Код:
begin
CreateQurantineArchive('C:\quarantine.zip');
end.
- Upload the C:\quarantine.zip here: http://virusinfo.info/upload_virus_eng.php?tid=73863
- Repeat a log file of AVPTool
- Make a log file with Hijackthis:http://www.bleepingcomputer.com/tuto...utorial94.html