Выполните скрипт в AVZ:
Код:
BEGIN
ClearQuarantine;
QuarantineFile('C:\Program Files (x86)\WinSaber\WinSaber.exe','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
QuarantineFile('C:\ProgramData\UvConverter\UvConverter.exe','');
QuarantineFile('C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe','');
QuarantineFile('C:\Program Files (x86)\Lomity\krtcorelrn.exe','');
QuarantineFile('C:\Program Files (x86)\98BF7F72-1472425598-11E3-BEA6-48D224249FF3\kns6006.tmp','');
QuarantineFile('c:\programdata\tencent\qq\qmdr\qmdr.dll','');
QuarantineFile('C:\PROGRA~3\102e60e\603ee1a2.dll','');
QuarantineFile('C:\Users\user\AppData\Roaming\SyManager\updater\python\pythonw.exe','');
QuarantineFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','');
DelBHO('{8E8F97CD-60B5-456F-A201-73065652D099}');
DeleteService('winsaber');
DeleteService('UvConverter');
DeleteService('SoEasySvc');
DeleteService('krtcorelrn.exe');
DeleteService('jegywefozbt');
DeleteFile('c:\programdata\tencent\qq\qmdr\qmdr.dll','32');
DeleteFile('C:\Program Files (x86)\98BF7F72-1472425598-11E3-BEA6-48D224249FF3\kns6006.tmp','32');
DeleteFile('C:\Program Files (x86)\Lomity\krtcorelrn.exe','32');
DeleteFile('C:\Program Files (x86)\SoSoEasy\SoSoEasySvc.exe','32');
DeleteFile('C:\ProgramData\UvConverter\UvConverter.exe','32');
DeleteFile('C:\Program Files (x86)\WinSaber\WinSaber.exe','32');
DeleteFile('C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe','32');
DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP3.job','32');
DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP2.job','32');
DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP1.job','32');
DeleteFile('C:\Program Files (x86)\Banglamp\Update\BanglampUpdate.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\BanglampUpdateTaskMachineUA','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Kuraty Core','64');
DeleteFile('C:\Users\user\AppData\Roaming\SyManager\updater\python\pythonw.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SyManager','64');
DeleteFile('C:\WINDOWS\system32\Tasks\{59116434-61E0-50BD-9E77-6B2D1E161F40}','64');
DeleteFile('C:\PROGRA~3\102e60e\603ee1a2.dll','32');
DeleteFileMask('C:\Program Files (x86)\Lomity','*',true);
DeleteFileMask('C:\Program Files (x86)\SoSoEasy','*',true);
DeleteFileMask('C:\Program Files (x86)\WinSaber','*',true);
DeleteFileMask('C:\Program Files (x86)\Banglamp','*',true);
DeleteDirectory('C:\Program Files (x86)\Lomity');
DeleteDirectory('C:\Program Files (x86)\SoSoEasy');
DeleteDirectory('C:\Program Files (x86)\WinSaber');
DeleteDirectory('C:\Program Files (x86)\Banglamp');
ExecuteSysClean;
ExecuteWizard('SCU',2,2,true);
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
RebootWindows(true);
END.
Компьютер будет перезагружен.
Используйте ссылку "Прислать запрошенный карантин", которая находится над первым сообщением этой темы, чтобы прислать quarantine.zip.
Повторите действия, указанные в правилах и подготовьте новые отчеты AVZ и ADWCleaner.