- Выполните в АВЗ:
Код:
begin
QuarantineFile('C:\PROGRA~3\Mozilla\axhwwsj.exe','');
QuarantineFile('c:\programdata\house of soft\gs-enabler\GS-Enabler.exe','');
QuarantineFile('c:\programdata\house of soft\gs-enabler\993492499.ini','');
QuarantineFile('C:\Program Files\Zaxar\ZaxarLoader.exe','');
QuarantineFile('C:\Windows\system32\drivers\adgnetworktdi.sys','');
QuarantineFile('C:\Users\Елена\AppData\Roaming\newnext.me\nengine.dll','');
QuarantineFile('c:\progra~2\gs-ena~1\assist~1.dll','');
QuarantineFile('c:\progra~2\gs-ena~1\AssistantSvc.dll','');
DeleteFile('c:\progra~2\gs-ena~1\AssistantSvc.dll','32');
DeleteFile('c:\progra~2\gs-ena~1\assist~1.dll','32');
DeleteFile('C:\Users\Елена\AppData\Roaming\newnext.me\nengine.dll','32');
DeleteFile('C:\Program Files\Internet Explorer\iexplore.url','32');
DeleteFile('C:\Program Files\Zaxar\ZaxarLoader.exe','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','NextLive');
DeleteFile('C:\Windows\system32\Tasks\GS-Enabler-S-993492499.job','64');
DeleteFile('C:\Windows\system32\Tasks\GS-Enabler-S-993492499','64');
DeleteFile('c:\programdata\house of soft\gs-enabler\993492499.ini','32');
DeleteFile('c:\programdata\house of soft\gs-enabler\GS-Enabler.exe','32');
DeleteFile('C:\Windows\system32\Tasks\uysxdeb','64');
DeleteFile('C:\PROGRA~3\Mozilla\axhwwsj.exe','32');
DeleteFileMask('C:\PROGRA~3\Mozilla','*',true);
DeleteDirectory('C:\PROGRA~3\Mozilla');
DeleteFileMask('c:\programdata\house of soft','*',true);
DeleteDirectory('c:\programdata\house of soft');
DeleteFileMask('C:\Program Files\Zaxar','*',true);
DeleteDirectory('C:\Program Files\Zaxar');
DeleteFileMask('C:\Users\Елена\AppData\Roaming\newnext.me','*',true);
DeleteDirectory('C:\Users\Елена\AppData\Roaming\newnext.me');
DeleteFileMask('c:\progra~2\gs-ena~1','*',true);
DeleteDirectory('c:\progra~2\gs-ena~1');
ExecuteSysClean;
RebootWindows(true);
end.
Компьютер перезагрузится
После перезагрузки:
- Выполните в АВЗ:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Файл quarantine.zip из папки AVZ загрузите по ссылке "Прислать запрошенный карантин" вверху темы.
- Повторите логи virusinfo_syscheck.zip и hijackthis.log.