а не сохраненные в браузерах пароли тоже надо менять ?
Желательно.
Н-да, машина герой

или полигон
Скачайте
OTM by OldTimer и сохраните на рабочий стол.
Запустите OTM (в ОС Windows Vista необходимо запускать через правую кн. мыши от имени администратора)
временно выключите антивирус, firewall и другое защитное программное обеспечение. Выделите и скопируйте текст ниже (Ctrl+C)
:Files
C:\Program Files\Antivirus 2009\av2009.exe
C:\Documents and Settings\LEXUS\sys32_nov.exe
C:\WINDOWS\system32\mset.exe
C:\Program Files\plugin.exe
C:\WINDOWS\system32\regedit.exe
C:\WINDOWS\system32\setup2.exe
c:\documents and settings\all users\systems.exe
C:\Documents and Settings\LEXUS\Start Menu\Programs\Startup\ikowin32.exe
:Reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Generic Host for Win32 Services]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\21903633775001181759022298508056]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\braviax]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mset]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plugin]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Regedit32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup2.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shell]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sys32_nov]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysgif32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LEXUS^Start Menu^Programs^Startup^ikowin32.exe]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Documents and Settings\LEXUS\Local Settings\Temp\~os1D.tmp\ossproxy.exe"=-
"C:\Documents and Settings\LEXUS\Desktop\rtmpdump-2.2d\rtmpgw.exe"=-
"C:\Documents and Settings\LEXUS\Desktop\rtmpdump-2.2d\rtmpsrv.exe"=-
"C:\Documents and Settings\LEXUS\Local Settings\Temp\~osB.tmp\rlvknlg.exe"=-
"c:\program files\relevantknowledge\rlvknlg.exe"=-
"H:\DIR64.JPG.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\kogw.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winrwlap.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winkglfrw.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winuvxiia.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winwnji.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\sxpsdp.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wef6a821.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winjmfc.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\whrtt.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winigkq.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\ffljxc.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\nlrqs.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\pabjee.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winvhgmj.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\mcumqa.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\windstlbx.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wincedfj.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\w2cc398.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winfnyw.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winxnypqc.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\hhphr.exe"="-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\rogk.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\w83522.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wincloa.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\jiddv.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\xmee.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winanegn.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\pmsgn.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\fwsmrs.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winiuiv.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wa1646.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winsqfxy.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\w1a42a8.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winieofbq.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wfaf03.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winefcc.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wbc108.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wingdnoue.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\ugxi.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winxgxo.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\dcul.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winbvbwkt.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winvenc.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wfxfvb.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wdqd.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winuuid.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\cksyfn.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winusgje.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winhrfco.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winvluuq.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winndwh.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\wc3f50.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winykyu.exe"=-
"C:\DOCUME~1\LEXUS\LOCALS~1\Temp\winceakk.exe"=-
:Commands
[purity]
[emptytemp]
[Reboot]
В OTM под панелью
"Paste Instructions for Items to be Moved" (под
желтой панелью) вставьте скопированный текст и нажмите кнопку
"MoveIt!".
Компьютер перезагрузится.
После перезагрузки откройте папку
"C:\_OTM\MovedFiles", найдите последний .log файл (лог в формате
mmddyyyy_hhmmss.log), откройте и скопируйте текст из него в следующее сообщение.
Если выполнение перезагрузки зависнет, сделайте принудительную перезагрузку.