Выполните скрипт в AVZ:
Код:
begin
TerminateProcessByName('c:\program files (x86)\solution real\updatesolutionreal.exe');
TerminateProcessByName('C:\Program Files (x86)\Solution Real\bin\SolutionReal.PurBrowse64.exe');
TerminateProcessByName('c:\program files (x86)\solution real\bin\solutionreal.expext.exe');
TerminateProcessByName('C:\Program Files (x86)\Solution Real\bin\SolutionReal.BrowserAdapter64.exe');
TerminateProcessByName('c:\program files (x86)\solution real\bin\solutionreal.browseradapter.exe');
QuarantineFile('C:\Users\Babushka\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE', '');
QuarantineFile('C:\Program Files (x86)\Solution Real\SolutionRealbho.dll', '');
QuarantineFile('C:\PROGRA~3\{90327~1\171~1.0\foco.dll', '');
QuarantineFile('C:\Windows\system32\drivers\{6e9af5d3-a8f9-4461-ad38-1433888f55dc}Gw64.sys', '');
QuarantineFile('c:\program files (x86)\solution real\updatesolutionreal.exe', '');
QuarantineFile('C:\Program Files (x86)\Solution Real\bin\SolutionReal.PurBrowse64.exe', '');
QuarantineFile('c:\program files (x86)\solution real\bin\solutionreal.expext.exe', '');
QuarantineFile('C:\Program Files (x86)\Solution Real\bin\SolutionReal.BrowserAdapter64.exe', '');
QuarantineFile('c:\program files (x86)\solution real\bin\solutionreal.browseradapter.exe', '');
DeleteFile('c:\program files (x86)\solution real\bin\solutionreal.browseradapter.exe', '32');
DeleteFile('C:\Program Files (x86)\Solution Real\bin\SolutionReal.BrowserAdapter64.exe', '32');
DeleteFile('c:\program files (x86)\solution real\bin\solutionreal.expext.exe', '32');
DeleteFile('C:\Program Files (x86)\Solution Real\bin\SolutionReal.PurBrowse64.exe', '32');
DeleteFile('c:\program files (x86)\solution real\updatesolutionreal.exe', '32');
DeleteFile('C:\Program Files (x86)\Solution Real\bin\6e9af5d3a8f94461ad38.dll', '32');
DeleteFile('C:\Program Files (x86)\Solution Real\bin\6e9af5d3a8f94461ad381433888f55dc.dll', '32');
DeleteFile('C:\Program Files (x86)\Solution Real\bin\SolutionReal.expextdll.dll', '32');
DeleteFile('C:\Windows\system32\drivers\{6e9af5d3-a8f9-4461-ad38-1433888f55dc}Gw64.sys', '32');
DeleteFile('C:\PROGRA~3\{90327~1\171~1.0\foco.dll', '32');
DeleteFile('C:\Program Files (x86)\Solution Real\SolutionRealbho.dll', '32');
DeleteFile('C:\Users\Babushka\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE', '32');
DeleteFile('C:\Windows\system32\Tasks\LaunchSignup', '64');
DeleteFile('C:\Windows\system32\Tasks\WSE_Vosteran', '64');
DeleteFileMask('C:\Users\Babushka\AppData\Roaming\WSE_VO~1', '*', true);
DeleteFileMask('C:\Program Files (x86)\Solution Real', '*', true);
DeleteFileMask('C:\PROGRA~3\{90327~1\171~1.0', '*', true);
DeleteDirectory('C:\Users\Babushka\AppData\Roaming\WSE_VO~1');
DeleteDirectory('C:\Program Files (x86)\Solution Real');
DeleteDirectory('C:\PROGRA~3\{90327~1\171~1.0');
DelBHO('{1bb456da-878f-44a5-b013-4bfe0ae02fce}');
ExecuteSysClean;
ExecuteWizard('TSW', 2, 2, true);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.
Выполните в AVZ скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
В папке с AVZ появится архив карантина quarantine.zip, отправьте этот файл по ссылке "Прислать запрошенный карантин" над над первым сообщением в теме.
Выполните 2-й стандартный скрипт в AVZ и прикрепите к своему следующему сообщению файл virusinfo_syscheck.zip.
Сделайте лог AdwCleaner (by Xplode).