В AVZ выполните скрипт:
Код:
begin
ClearQuarantine;
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
TerminateProcessByName('c:\program files\askpartnernetwork\toolbar\apnmcp.exe');
TerminateProcessByName('c:\program files\askpartnernetwork\toolbar\updater\tbnotifier.exe');
DelBHO('{D8278076-BC68-4484-9233-6E7F1628B56C}');
QuarantineFile('C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll','');
DelBHO('{92780B25-18CC-41C8-B9BE-3C9C571A8263}');
DelBHO('{ffbb88a9-c663-4b9b-9170-70fa0a5a2786}');
QuarantineFile('C:\Program Files\BrowseSmart\BrowseSmartBHO.dll','');
DelBHO('{4F524A2D-5350-4500-76A7-7A786E7484D7}');
QuarantineFile('C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll','');
DelBHO('{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}');
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\APPLIC~1\Linkey\IEEXTE~1\iedll.dll','');
DelBHO('{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7}');
QuarantineFile('C:\Program Files\Speed Test 127\ScriptHost.dll','');
DeleteService('bonanzadealslivem');
DeleteService('bonanzadealslive');
DeleteService('APNMCP');
QuarantineFile('c:\program files\askpartnernetwork\toolbar\updater\tbnotifier.exe','');
QuarantineFile('c:\program files\askpartnernetwork\toolbar\apnmcp.exe','');
QuarantineFile('C:\Program Files\Mobogenie\DaemonProcess.exe','');
QuarantineFile('C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe','');
QuarantineFile('rhvstrxx.sys','');
Bc_QrSvc('rhvstrxx');
QuarantineFile('C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe','');
QuarantineFile('C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe','');
DeleteFile('C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe','32');
DeleteFile('C:\Program Files\Mobogenie\DaemonProcess.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','mobilegeni daemon');
DeleteFile('c:\program files\askpartnernetwork\toolbar\apnmcp.exe','32');
DeleteFile('c:\program files\askpartnernetwork\toolbar\updater\tbnotifier.exe','32');
DeleteFile('C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe','32');
DeleteFile('C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','ApnTBMon');
DeleteFile('C:\Program Files\Speed Test 127\ScriptHost.dll','32');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\APPLIC~1\Linkey\IEEXTE~1\iedll.dll','32');
DeleteFile('C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll','32');
DeleteFile('C:\Program Files\BrowseSmart\BrowseSmartBHO.dll','32');
DeleteFile('C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll','32');
DeleteFile('C:\WINDOWS\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job','32');
DeleteFile('C:\WINDOWS\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job','32');
DeleteFileMask('C:\Program Files\Speed Test 127', '*', true);
DeleteDirectory('C:\Program Files\Speed Test 127');
DeleteFileMask('C:\Program Files\BonanzaDealsLive', '*', true);
DeleteDirectory('C:\Program Files\BonanzaDealsLive');
DeleteFileMask('c:\program files\askpartnernetwork', '*', true);
DeleteDirectory('c:\program files\askpartnernetwork');
DeleteFileMask('C:\Program Files\BrowseSmart', '*', true);
DeleteDirectory('C:\Program Files\BrowseSmart');
DeleteFileMask('C:\Program Files\Mobogenie', '*', true);
DeleteDirectory('C:\Program Files\Mobogenie');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Пришлите карантин quarantine.zip по красной ссылке Прислать запрошенный карантин вверху темы.
Логи повторите.