Здравствуйте !!!
Выполните скрипт в AVZ:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\Users\User\PowerModule.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\xjd59ll.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\WPB39lYEkbMeNFm2jQeBewa.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\jZLxkmZv.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\hCrafQ4L3762kw58K2Ll.exe','');
QuarantineFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnеt Ехplоrеr Вrоwsеr.lnk','');
QuarantineFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk','');
QuarantineFile('C:\ProgramData\ZaAExMvv\cSoNYncD5.bat','');
QuarantineFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk','');
QuarantineFile('C:\ProgramData\RdDIlQuVIoNdjnM\vMKRWAdX0.bat','');
QuarantineFile('C:\Users\User\PowerShellUpdate\PowerModule.exe','');
QuarantineFile('C:\Program Files (x86)\Oursoft\PQeeHn.exe','');
DeleteFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnеt Ехplоrеr Вrоwsеr.lnk');
DeleteFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk');
DeleteFile('C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk');
DeleteFile('C:\Users\User\PowerShellUpdate\PowerModule.exe','32');
DeleteFile('C:\ProgramData\RdDIlQuVIoNdjnM\vMKRWAdX0.bat','32');
DeleteFile('C:\ProgramData\ZaAExMvv\cSoNYncD5.bat','32');
DeleteFile('C:\Users\User\AppData\Roaming\hCrafQ4L3762kw58K2Ll.exe','32');
DeleteFile('C:\Windows\Tasks\hCrafQ4L3762kw58K2Ll.job','32');
DeleteFile('C:\Users\User\AppData\Roaming\jZLxkmZv.exe','32');
DeleteFile('C:\Windows\Tasks\jZLxkmZv.job','32');
DeleteFile('C:\Windows\Tasks\Uninstaller_SkipUac_User.job','32');
DeleteFile('C:\Users\User\AppData\Roaming\WPB39lYEkbMeNFm2jQeBewa.exe','32');
DeleteFile('C:\Windows\Tasks\WPB39lYEkbMeNFm2jQeBewa.job','32');
DeleteFile('C:\Users\User\AppData\Roaming\xjd59ll.exe','32');
DeleteFile('C:\Windows\Tasks\xjd59ll.job','32');
DeleteFile('C:\Windows\system32\Tasks\hCrafQ4L3762kw58K2Ll','64');
DeleteFile('C:\Windows\system32\Tasks\jZLxkmZv','64');
DeleteFile('C:\Windows\system32\Tasks\PowerShellUpdate','64');
DeleteFile('C:\Windows\system32\Tasks\Uninstaller_SkipUac_User','64');
DeleteFile('C:\Users\User\PowerModule.exe','32');
DeleteFile('C:\Windows\system32\Tasks\UserModuleUpdate','64');
DeleteFile('C:\Windows\system32\Tasks\WPB39lYEkbMeNFm2jQeBewa','64');
DeleteFile('C:\Windows\system32\Tasks\xjd59ll','64');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','PowerShellUpdate');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки выполните скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Загрузите quarantine.zip из папки AVZ по красной ссылке вверху темы Прислать запрошенный карантин
- Сделайте повторные логи по правилам п.2 и 3 раздела Диагностика.(virusinfo_syscheck.zip;hijackthis.log )