Код:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dspp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dspp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hppp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=dspp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=dspp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hppp&ts=1427650535&from=face&uid=ST1000DM003-1CH162_Z1D6BRESXXXXZ1D6BRES
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O4 - HKLM\..\Policies\Explorer\Run: [Adobe Flash Player NPAPI] "C:\Program Files (x86)\Common Files\Adobe\OOBA\PDApp\NPAPI\FlashUtil32_16_plugin.exe" --getupdate-npapi-plugin
O4 - HKLM\..\Policies\Explorer\Run: [SafeBrowser] "C:\Users\Tracktor\AppData\Local\Microsoft\Extensions\safebrowser.exe" /S
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Users\Tracktor\appdata\local\smartweb\__u.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\istartsurf\UninstallManager.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Local\SmartWeb\SmartWebHelper.exe','');
QuarantineFile('C:\ProgramData\KRB Updater Utility\krbupdater-utility.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Local\Microsoft\Extensions\extsetup.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\RMJPES.exe','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunch Internet Ехрlоrеr Вrоwser.lnk','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\Browsers\exe.erolpxei.bat','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооgle Chrоme.lnk','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\Browsers\exe.emorhc.bat','');
QuarantineFile('C:\Users\Tracktor\AppData\Local\Microsoft\Extensions\safebrowser.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Local\Kometa\kometaup.exe','');
QuarantineFile('C:\Users\Tracktor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk','');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunch Internet Ехрlоrеr Вrоwser.lnk');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооgle Chrоme.lnk');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk');
DeleteFile('C:\Users\Tracktor\AppData\Local\Kometa\kometaup.exe','32');
DeleteFile('C:\Users\Tracktor\AppData\Local\Microsoft\Extensions\safebrowser.exe','32');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\Browsers\exe.emorhc.bat','32');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\Browsers\exe.erolpxei.bat','32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\Windows\Tasks\APSnotifierPP1.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP2.job','64');
DeleteFile('C:\Windows\Tasks\APSnotifierPP3.job','64');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\RMJPES.exe','32');
DeleteFile('C:\Windows\Tasks\RMJPES.job','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP1','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP2','64');
DeleteFile('C:\Windows\system32\Tasks\APSnotifierPP3','64');
DeleteFile('C:\Windows\system32\Tasks\extsetup','64');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater-utility.exe','32');
DeleteFile('C:\Windows\system32\Tasks\KRB Updater Utility','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\KRBUUS\KRB Updater Utility Service','64');
DeleteFile('C:\Windows\system32\Tasks\Safebrowser','64');
DeleteFile('C:\Users\Tracktor\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
DeleteFile('C:\Windows\system32\Tasks\SmartWeb Upgrade Trigger Task','64');
DeleteFile('C:\Users\Tracktor\AppData\Roaming\istartsurf\UninstallManager.exe','32');
DeleteFile('C:\Windows\system32\Tasks\{A4171430-5C7E-415E-BCDC-9CB10271B2E6}','64');
DeleteFile('C:\Users\Tracktor\appdata\local\microsoft\extensions\extsetup.exe','32');
DeleteFile('C:\Users\Tracktor\appdata\local\smartweb\__u.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\kometaup','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','SafeBrowser');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('TSW',2,2,true);
RebootWindows(true);
end.
После перезагрузки выполните скрипт: