Выполните скрипт в AVZ
Код:
begin
QuarantineFileF('C:\Program Files (x86)\SFXMaker\plugins', '*.*', true,'', 0, 0, '', '');
QuarantineFileF('C:\Temp\sys doc', '*.*', true,'', 0, 0, '', '');
QuarantineFileF('C:\Temp\srsys', '*.*', true,'', 0, 0, '', '');
QuarantineFileF('C:\Users\Inna\AppData\Roaming\nscrypt', '*.*', true,'', 0, 0, '', '');
QuarantineFile('C:\Program Files (x86)\SFXMaker\plugins\7zS.sfx','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\CBFB.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\3D05.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\6EA7.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\94EE.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\BD5E.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\BF9B.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\D752.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Local\Temp\E05E.tmp','');
QuarantineFile('C:\Users\Inna\AppData\Roaming\nscrypt\engine2.exe','');
QuarantineFile('C:\ProgramData\Windows\csrss.exe','');
QuarantineFile('C:\Temp\srsys\crihost.exe','');
QuarantineFile('C:\Temp\srsys\m\9010','');
QuarantineFile('C:\Temp\srsys\m\smsrvs64.exe','');
QuarantineFile('C:\Temp\sys doc\5\arch','');
QuarantineFile('C:\Temp\sys doc\5\minerd.exe','');
QuarantineFile('C:\Temp\sys dosc\2\colhoste.exe','');
QuarantineFile('C:\Temp\sys dosc\2\arch','');
QuarantineFile('C:\Temp\sys dosc\3\colhoste.exe','');
QuarantineFile('C:\Temp\sys dosc\3\arch','');
QuarantineFile('C:\Temp\srsys\srvrs','');
QuarantineFile('C:\Temp\srsys\charle.exe','');
QuarantineFile('C:\Temp\srsys\rupfile.exe','');
QuarantineFile('C:\Temp\srsys\srchost.exe','');
QuarantineFile('C:\Temp\srsys\sysis.exe','');
QuarantineFile('C:\Temp\srsys\m\8868','');
QuarantineFile('C:\Temp\srsys\m\smsrvs64.exe','');
QuarantineFile('C:\Temp\srsys\m2\smrvs64.exe','');
QuarantineFile('C:\Temp\srsys\m2\Taskmgr.exe','');
QuarantineFile('C:\WINDOWS\system32\gnbpbgl.dll','');
QuarantineFile('C:\WINDOWS\system32\gnbpbgl.dll','');
QuarantineFile('C:\WINDOWS\system32\gnbpbgl.dll','');
QuarantineFile('C:\WINDOWS\system32\gnbpbgl.dll','');
QuarantineFile('C:\WINDOWS\system32\gnbpbgl.dll','');
BC_ImportAll;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.
Пришлите карантин согласно Приложения 3 правил по красной ссылке Прислать запрошенный карантин вверху темы
Поместите в карантин МВАМ всё, кроме
Код:
Registry Data: 3
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|AntiVirusDisableNotify, 1, Good: (0), Bad: (1),,[4ac892884a40122499f158591bea7888]
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|FirewallDisableNotify, 1, Good: (0), Bad: (1),,[fc16a17958322a0cc9c2c7ea0ff625db]
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|UpdatesDisableNotify, 1, Good: (0), Bad: (1),,[ef238892acdebd79fe8e337eab5ac43c]