Severny
30-08-2008, 22:20
Выполни скрипт.
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
SetServiceStart('pdfFactory Pro Dispatcher v2', 4);
DeleteService('pdfFactory Pro Dispatcher v2');
DeleteFile('C:\WINDOWS\system32\fppmon2.dll');
DeleteFile('C:\WINDOWS\system32\fppr232.dll');
DeleteFile('C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe');
DeleteFile('C:\WINDOWS\SkyTel.EXE');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
В Hijack пофикси строку:
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
SetServiceStart('pdfFactory Pro Dispatcher v2', 4);
DeleteService('pdfFactory Pro Dispatcher v2');
DeleteFile('C:\WINDOWS\system32\fppmon2.dll');
DeleteFile('C:\WINDOWS\system32\fppr232.dll');
DeleteFile('C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe');
DeleteFile('C:\WINDOWS\SkyTel.EXE');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
В Hijack пофикси строку:
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE