Не могу удалить RegCleanPro и куча остальной вирусни на компе, защитник постоянно крякает что нашел вирус, через каждых 3-5 мин, в инет выход заблокирован.
Не могу удалить RegCleanPro и куча остальной вирусни на компе, защитник постоянно крякает что нашел вирус, через каждых 3-5 мин, в инет выход заблокирован.
Уважаемый(ая) [B]spopovss[/B], спасибо за обращение на наш форум!
Помощь при заражении комьютера на VirusInfo.Info оказывается абсолютно бесплатно. Хелперы, в самое ближайшее время, ответят на Ваш запрос. Для оказания помощи необходимо предоставить логи сканирования утилитами АВЗ и HiJackThis, подробнее можно прочитать в [URL="http://virusinfo.info/pravila.html"]правилах оформления запроса о помощи[/URL].
Если наш сайт окажется полезен Вам и у Вас будет такая возможность - пожалуйста [URL="http://virusinfo.info/content.php?r=113-virusinfo.info-donate"]поддержите проект[/URL].
[QUOTE]SavePass 1.1
GoHD
advancedsystemprotector
settings manager[/QUOTE]удалите через Установку программ
Выполните скрипт в AVZ
[code]begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
QuarantineFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-6.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-5.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-4.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-11.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\f025b33d-4fe1-43d1-9072-60df121c2890.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-11.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-4.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-5.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-6.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-6.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-5.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-2.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-10.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-6.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-5.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-4.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-11.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-7.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-6.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-5.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-4.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-11.exe','');
QuarantineFile('C:\Program Files (x86)\GoHD\GoHD-codedownloader.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-7.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-6.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-4.exe','');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.exe','');
DelBHO('{11111111-1111-1111-1111-110611211180}');
DelBHO('{11111111-1111-1111-1111-110611341129}');
QuarantineFile('C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll','');
QuarantineFile('C:\Program Files (x86)\GoHD\GoHD-bho.dll','');
QuarantineFile('C:\Users\Виталий\AppData\Local\Win_update\Win_update.exe','');
QuarantineFile('C:\Program Files (x86)\Settings Manager\smdmf\x64\sysapcrt.dll','');
QuarantineFile('C:\Program Files (x86)\Settings Manager\smdmf\sysapcrt.dll','');
SetServiceStart('F06DEFF2-5B9C-490D-910F-35D3A9119622', 4);
DeleteService('F06DEFF2-5B9C-490D-910F-35D3A9119622');
QuarantineFile('C:\Program Files (x86)\Settings Manager\smdmf\SmdmFService.exe','');
SetServiceStart('SmdmFService', 4);
DeleteService('SmdmFService');
QuarantineFile('C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg','');
TerminateProcessByName('c:\program files (x86)\settings manager\smdmf\smdmfservice.exe');
QuarantineFile('c:\program files (x86)\settings manager\smdmf\smdmfservice.exe','');
TerminateProcessByName('C:\Program Files (x86)\ASP\clamunpack\clamscan.exe');
TerminateProcessByName('c:\program files (x86)\asp\advancedsystemprotector.exe');
TerminateProcessByName('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-64.exe');
QuarantineFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-64.exe','');
TerminateProcessByName('c:\program files (x86)\savepass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe');
QuarantineFile('c:\program files (x86)\savepass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe','');
DeleteFile('c:\program files (x86)\savepass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-64.exe','32');
DeleteFile('c:\program files (x86)\asp\advancedsystemprotector.exe','32');
DeleteFile('C:\Program Files (x86)\ASP\clamunpack\clamscan.exe','32');
DeleteFile('c:\program files (x86)\settings manager\smdmf\smdmfservice.exe','32');
DeleteFile('C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg','32');
DeleteFile('C:\Program Files (x86)\Settings Manager\smdmf\SmdmFService.exe','32');
DeleteFile('C:\Program Files (x86)\Settings Manager\smdmf\sysapcrt.dll','32');
DeleteFile('C:\Program Files (x86)\Settings Manager\smdmf\x64\sysapcrt.dll','32');
DeleteFile('C:\Program Files (x86)\GoHD\GoHD-bho.dll','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll','32');
DeleteFile('C:\WINDOWS\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-1.job','64');
DeleteFile('C:\WINDOWS\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.job','64');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-4.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.exe','32');
DeleteFile('C:\WINDOWS\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.job','64');
DeleteFile('C:\WINDOWS\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-4.job','64');
DeleteFile('C:\WINDOWS\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5_user.job','64');
DeleteFile('C:\WINDOWS\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-6.job','64');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-6.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-7.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe','32');
DeleteFile('C:\WINDOWS\Tasks\5432e15e-8b38-4917-9568-a8baef47582c.job','64');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-1.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\GoHD-codedownloader.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-11.exe','32');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-11.job','64');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-4.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-4.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-5.exe','32');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-5.job','64');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-5_user.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-6.exe','32');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-6.job','64');
DeleteFile('C:\WINDOWS\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-7.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\58b226dd-311c-43ee-9a0c-464a0b045f7c-7.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-11.exe','32');
DeleteFile('C:\WINDOWS\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-11.job','64');
DeleteFile('C:\WINDOWS\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-1.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-4.exe','32');
DeleteFile('C:\WINDOWS\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-4.job','64');
DeleteFile('C:\WINDOWS\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-5.job','64');
DeleteFile('C:\WINDOWS\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-5_user.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-5.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-6.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\a31e4313-6aaf-4ecb-b114-5b080bbe1753-7.exe','32');
DeleteFile('C:\WINDOWS\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-7.job','64');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-1.job','64');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-10_user.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-10.exe','32');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-2.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-2.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-5.exe','32');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-5.job','64');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-5_user.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-6.exe','32');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-6.job','64');
DeleteFile('C:\WINDOWS\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-7.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\d2d2d385-fa43-4f14-b2a2-c282b31a2500-7.exe','32');
DeleteFile('C:\WINDOWS\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-1.job','64');
DeleteFile('C:\WINDOWS\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-11.job','64');
DeleteFile('C:\WINDOWS\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-4.job','64');
DeleteFile('C:\WINDOWS\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-5.job','64');
DeleteFile('C:\WINDOWS\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-5_user.job','64');
DeleteFile('C:\WINDOWS\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-6.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-6.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-5.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-4.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\e183be95-5f95-4ace-9ff5-100d7c81dbdc-11.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\f025b33d-4fe1-43d1-9072-60df121c2890.exe','32');
DeleteFile('C:\WINDOWS\Tasks\f025b33d-4fe1-43d1-9072-60df121c2890.job','64');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-1.job','64');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-11.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-11.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-4.exe','32');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-4.job','64');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-5.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-5.exe','32');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-5_user.job','64');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-6.job','64');
DeleteFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-6.exe','32');
DeleteFile('C:\Program Files (x86)\GoHD\fe357432-87fc-47fa-aba3-8b7271a3e344-7.exe','32');
DeleteFile('C:\WINDOWS\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-7.job','64');
DeleteFile('C:\Program Files (x86)\RCP\RegCleanPro.exe','32');
DeleteFile('C:\Program Files (x86)\SavePass 1.1\SavePass','32');
DeleteFile('C:\WINDOWS\system32\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-1','64');
DeleteFile('C:\WINDOWS\Tasks\RegClean Pro_UPDATES.job','64');
DeleteFile('C:\WINDOWS\Tasks\RegClean Pro_DEFAULT.job','64');
DeleteFile('C:\WINDOWS\system32\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-11','64');
DeleteFile('C:\WINDOWS\system32\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-4','64');
DeleteFile('C:\WINDOWS\system32\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-7','64');
DeleteFile('C:\WINDOWS\system32\Tasks\5432e15e-8b38-4917-9568-a8baef47582c','64');
DeleteFile('C:\WINDOWS\system32\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-1','64');
DeleteFile('C:\WINDOWS\system32\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-11','64');
DeleteFile('C:\WINDOWS\system32\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-4','64');
DeleteFile('C:\WINDOWS\system32\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\58b226dd-311c-43ee-9a0c-464a0b045f7c-7','64');
DeleteFile('C:\WINDOWS\system32\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-1','64');
DeleteFile('C:\WINDOWS\system32\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-11','64');
DeleteFile('C:\WINDOWS\system32\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-4','64');
DeleteFile('C:\WINDOWS\system32\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\a31e4313-6aaf-4ecb-b114-5b080bbe1753-7','64');
DeleteFile('C:\WINDOWS\system32\Tasks\Advanced-System Protector_startup','64');
DeleteFile('C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-1','64');
DeleteFile('C:\WINDOWS\system32\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-2','64');
DeleteFile('C:\WINDOWS\system32\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\d2d2d385-fa43-4f14-b2a2-c282b31a2500-7','64');
DeleteFile('C:\WINDOWS\system32\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-1','64');
DeleteFile('C:\WINDOWS\system32\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-11','64');
DeleteFile('C:\WINDOWS\system32\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-4','64');
DeleteFile('C:\WINDOWS\system32\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\e183be95-5f95-4ace-9ff5-100d7c81dbdc-7','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-1','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-11','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-4','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-5','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-6','64');
DeleteFile('C:\WINDOWS\system32\Tasks\fe357432-87fc-47fa-aba3-8b7271a3e344-7','64');
DeleteFile('C:\WINDOWS\system32\Tasks\RegClean Pro','64');
DeleteFile('C:\WINDOWS\system32\Tasks\RegClean Pro_DEFAULT','64');
DeleteFile('C:\WINDOWS\system32\Tasks\RegClean Pro_UPDATES','64');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.[/code]Компьютер перезагрузится.
Пришлите карантин согласно [B]Приложения 2[/B] правил по красной ссылке [COLOR="Red"][U][B]Прислать запрошенный карантин[/B][/U][/COLOR] вверху темы
Сделайте новые логи
Сделайте лог [url="http://virusinfo.info/showthread.php?t=53070&p=1104657&viewfull=1#post1104657"]полного сканирования МВАМ[/url]
settings manager в установках не было
Поместите в карантин МВАМ всё, [B]кроме[/B]
[CODE]PUP.RiskwareTool.CK, D:\soft\adobe\Adobe Premiere Pro CC\Patch.exe, , [97badb1c9aefab8baf721aaa03fded13],
CrackTool.Agent, D:\soft\Sony.Vegas.Pro.10.2010.PC\Patch\vegas.pro.10.0a-MPT.exe, , [262b0cebe1a8ac8ae41fff4457aa2cd4],
CrackTool.Agent, D:\soft\Sony.Vegas.Pro.10.2011.PC\Crack\vegas.pro.10.0a-MPT.exe, , [1c3522d58bfe2412fb086fd47e83f30d],
PUP.RiskwareTool.CK, D:\soft\Stardock Start8 v1.31 Ml_Rus\Final\stardock.start8-patch.painter\stardock.start8-patch.painter.exe, , [4b06c7301e6bb77f0a1715af33cdc23e], [/CODE]
Сделано.
Сделайте логи [url="http://virusinfo.info/showthread.php?t=115256"]RSIT[/url]
есть
Удалите вручную
[QUOTE]C:\Users\Виталий\AppData\Roaming\systweak
C:\Program Files (x86)\globalUpdate[/QUOTE]
Что с проблемой?
Проблема ушла.
Удалите МВАМ
Статистика проведенного лечения:
[LIST][*]Получено карантинов: [B]1[/B][*]Обработано файлов: [B]5[/B][*]В ходе лечения обнаружены вредоносные программы:
[LIST=1][*] c:\program files (x86)\gohd\58b226dd-311c-43ee-9a0c-464a0b045f7c-64.exe - [B]not-a-virus:AdWare.NSIS.Adwapper.do[/B][*] c:\program files (x86)\settings manager\smdmf\smdmfservice.exe - [B]not-a-virus:WebToolbar.Win64.SearchSuite.e[/B] ( DrWEB: Adware.Bandoo.175, BitDefender: Adware.AztecMedia.G )[*] c:\program files (x86)\settings manager\smdmf\sysapcrt.dll - [B]not-a-virus:WebToolbar.Win64.SearchSuite.e[/B] ( BitDefender: Adware.AztecMedia.F )[*] c:\program files (x86)\settings manager\smdmf\x64\smdmfmgrc2.cfg - [B]not-a-virus:WebToolbar.Win64.SearchSuite.c[/B] ( DrWEB: Adware.Bandoo.173, BitDefender: Adware.AztecMedia.D )[*] c:\program files (x86)\settings manager\smdmf\x64\sysapcrt.dll - [B]not-a-virus:WebToolbar.Win64.SearchSuite.e[/B] ( BitDefender: Adware.AztecMedia.I )[/LIST][/LIST]