оставте один антивирус два - очень много ...
выполните скрипт ...
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\drivers\rsrvmon.exe','');
QuarantineFile('C:\WINDOWS\system32\ntos.exe','');
DeleteService('Yoy68');
DeleteService('XDva092');
DeleteService('Winkh58');
DeleteService('Vtv61');
DeleteService('Vssk57');
DeleteService('Uck81');
DeleteService('Tkm60');
DeleteService('Tic50');
DeleteService('tcpsr');
QuarantineFile('C:\WINDOWS\System32\drivers\tcpsr.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Stn83.sys','');
DeleteService('Stn83');
DeleteService('Src47');
QuarantineFile('C:\WINDOWS\System32\drivers\Src47.sys','');
QuarantineFile('C:\WINDOWS\system32\DRIVERS\smtpdrv.sys','');
DeleteService('smtpdrv');
DeleteService('Sis81');
QuarantineFile('C:\WINDOWS\System32\drivers\Sis81.sys','');
DeleteService('Sak81');
QuarantineFile('C:\WINDOWS\System32\drivers\rxA46.sys','');
DeleteService('rxA46');
DeleteService('riK36');
QuarantineFile('C:\WINDOWS\System32\drivers\riK36.sys','');
DeleteService('protect');
QuarantineFile('C:\WINDOWS\System32\drivers\protect.sys','');
DeleteService('Pfh36');
QuarantineFile('C:\WINDOWS\System32\drivers\Pfh36.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Nsu60.sys','');
DeleteService('Nsu60');
DeleteService('noskrnl.sys');
QuarantineFile('C:\WINDOWS\system32\noskrnl.sys','');
DeleteService('Muf36');
QuarantineFile('C:\WINDOWS\System32\drivers\Muf36.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Mrd52.sys','');
DeleteService('Mrd52');
DeleteService('Ljl36');
QuarantineFile('C:\WINDOWS\System32\drivers\Ljl36.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Lhj68.sys','');
DeleteService('Lhj68');
DeleteService('lcM60');
QuarantineFile('C:\WINDOWS\System32\drivers\lcM60.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Kyb36.sys','');
DeleteService('Kyb36');
QuarantineFile('C:\WINDOWS\System32\drivers\kiK60.sys','');
DeleteService('kiK60');
QuarantineFile('C:\WINDOWS\System32\drivers\Kfp58.sys','');
DeleteService('Kfp58');
DeleteService('Kac82');
QuarantineFile('C:\WINDOWS\System32\drivers\Kac82.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Jyb82.sys','');
DeleteService('Jyb82');
DeleteService('jxI25');
QuarantineFile('C:\WINDOWS\System32\drivers\jxI25.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Jrd26.sys','');
DeleteService('Jrd26');
DeleteService('Iqs60');
QuarantineFile('C:\WINDOWS\System32\drivers\Iqs60.sys','');
DeleteService('Ieo57');
QuarantineFile('C:\WINDOWS\System32\drivers\Ieo57.sys','');
DeleteService('hoY60');
QuarantineFile('C:\WINDOWS\System32\drivers\hoY60.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Fmw02.sys','');
DeleteService('Fmw02');
DeleteService('Elv02');
QuarantineFile('C:\WINDOWS\System32\drivers\Elv02.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Ddf25.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\dcM14.sys','');
DeleteService('dcM14');
DeleteService('dcE14');
QuarantineFile('C:\WINDOWS\System32\drivers\dcE14.sys','');
DeleteService('Cmg83');
QuarantineFile('C:\WINDOWS\System32\drivers\Cmg83.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\cbL45.sys','');
DeleteService('cbL45');
DeleteService('Brt60');
QuarantineFile('C:\WINDOWS\System32\drivers\Brt60.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Bpr70.sys','');
DeleteService('Bpr70');
DeleteService('Bik58');
QuarantineFile('C:\WINDOWS\System32\drivers\Bik58.sys','');
QuarantineFile('C:\WINDOWS\System32\drivers\Awh37.sys','');
DeleteService('Awh37');
DeleteFile('C:\WINDOWS\System32\drivers\Awh37.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Bik58.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Bpr70.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Brt60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\cbL45.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Cmg83.sys');
DeleteFile('C:\WINDOWS\System32\drivers\dcE14.sys');
DeleteFile('C:\WINDOWS\System32\drivers\dcM14.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Ddf25.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Elv02.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Fmw02.sys');
DeleteFile('C:\WINDOWS\System32\drivers\ggI61.sys');
DeleteFile('C:\WINDOWS\System32\drivers\hoY60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Ieo57.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Iqs60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Jrd26.sys');
DeleteFile('C:\WINDOWS\System32\drivers\jxI25.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Jyb82.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Kac82.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Kfp58.sys');
DeleteFile('C:\WINDOWS\System32\drivers\kiK60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Kyb36.sys');
DeleteFile('C:\WINDOWS\System32\drivers\lcM60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Lhj68.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Ljl36.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Mrd52.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Muf36.sys');
DeleteFile('C:\WINDOWS\system32\noskrnl.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Nsu60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Pfh36.sys');
DeleteFile('C:\WINDOWS\System32\drivers\protect.sys');
DeleteFile('C:\WINDOWS\System32\drivers\riK36.sys');
DeleteFile('C:\WINDOWS\System32\drivers\rxA46.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Sak81.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Sis81.sys');
DeleteFile('C:\WINDOWS\system32\DRIVERS\smtpdrv.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Src47.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Stn83.sys');
DeleteFile('C:\WINDOWS\System32\drivers\tcpsr.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Tic50.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Tku14.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Tkm60.sys');
DeleteFile('C:\WINDOWS\System32\drivers\tjL03.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Uck81.sys');
DeleteFile('Vssk57.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Vtv61.sys');
DeleteFile('C:\WINDOWS\System32\drivers\Winkh58.sys');
DeleteFile('C:\WINDOWS\system32\XDva092.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Yoy68.sys');
DeleteFile('C:\WINDOWS\system32\ntos.exe');
DeleteFile('C:\WINDOWS\system32\drivers\rsrvmon.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
пришлите карантин согласно приложения 3 правил ....
повторите логи ....