Здравствуйте !!!
отключите антивирусную программу
Выполните скрипт в AVZ:
Код:
begin
ExecuteAVUpdate;
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\MyApp.exe','');
QuarantineFile('C:\Program Files\bmskb\bmskbPro.exe','');
QuarantineFile('C:\Program Files\bmskb\bmskb.exe','');
QuarantineFile('C:\Program Files\bfcmpa\bfcmpasrv.exe','');
QuarantineFile('C:\Program Files\bfcloud\bfcloader.exe','');
QuarantineFile('C:\Program Files\Y73ЦЦЧУЛСЛчЙсЖч\Y73Server.exe','');
QuarantineFile('C:\Documents and Settings\User\AppData\Local\Baidu\BaiduClient\1.8.0.821\Baidu.exe','');
QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.10.16443.223\QMUdisk.sys','');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe','');
QuarantineFile('C:\Program Files\anote\anote.exe','');
DeleteFile('C:\Program Files\anote\anote.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16443.223\QMUdisk.sys','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\sockd20158114\TablacusExplorer.exe','32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\zhibo20158144\MPlayer.exe','32');
DeleteFile('C:\Documents and Settings\User\AppData\Local\Baidu\BaiduClient\1.8.0.821\Baidu.exe','32');
DeleteFile('C:\Documents and Settings\User\Application Data\Ysac\mego.exe','32');
DeleteFile('C:\Program Files\JiSuZhuShou\JSZS.exe','32');
DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.10.16443.223\QQPCTray.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\sdkik','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HealthyHome','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BaiduClient','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Heexan','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\JiSuZhuShou','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MTview','command');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ QQPCTray','command');
DeleteService('QMUdisk');
DeleteService('HWDeviceService.exe');
DeleteService('noteupdateservice');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
ExecuteRepair(3);
ExecuteWizard('SCU',2,2,true);
RebootWindows(true);
end.
После перезагрузки выполните скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Загрузите quarantine.zip из папки AVZ по красной ссылке вверху темы Прислать запрошенный карантин
- Сделайте повторные логи по правилам п.2 и 3 раздела Диагностика.(virusinfo_syscheck.zip;hijackthis.log )