Отключите до перезагрузки все экраны Avast.
Перетащите лог Check_Browsers_LNK.log из папки Autologger на утилиту ClearLNK. Отчёт о работе прикрепите.
Запустите HijackThis, расположенный в папке Autologger и пофиксите только эти строки:
Код:
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE (user missing)
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\bkuEDqiNwGRnsylXdWU" /ENABLE (user missing)
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\bkuwbUhgLXvJgoAVApl" /ENABLE (user missing)
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\bkuwGBfjeZqvJjSXKVS" /ENABLE (user missing)
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE (user missing)
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE (user missing)
O22 - Tasks: (damaged) (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\My top apps" /ENABLE (user missing)
O22 - Tasks: (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\bkuEDqiNwGRnsylXdWU" /ENABLE
O22 - Tasks: (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\bkuwbUhgLXvJgoAVApl" /ENABLE
O22 - Tasks: (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\bkuwGBfjeZqvJjSXKVS" /ENABLE
O22 - Tasks: (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE
O22 - Tasks: (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE
O22 - Tasks: (disabled) \Avast Software\Gaming mode Task Scheduler recovery - C:\Windows\system32\schtasks.exe /Change /TN "\My top apps" /ENABLE
Выполните скрипт в AVZ из папки Autologger\AV\av_z.exe:
Код:
begin
DeleteFile('C:\Users\admin\AppData\Local\Temp\20b06be6.sys', '64');
DeleteFile('C:\Windows\System32\drivers\dwprot.sys', '64');
DeleteFile('C:\Windows\TEMP\101B10CA.sys', '64');
DeleteFile('C:\Windows\TEMP\107863AA.sys', '64');
DeleteFile('C:\Windows\TEMP\BFmGefQDUHXpsWJF\ibBpwHzvnXWCIGEQ.exe', '32');
DeleteFile('C:\Windows\TEMP\BFmGefQDUHXpsWJF\ibBpwHzvnXWCIGEQ.exe', '64');
DeleteFile('C:\Windows\TEMP\fCKFBlGXvCUwjWIE\CDDAETaGCJZisyzt.exe', '32');
DeleteFile('C:\Windows\TEMP\fCKFBlGXvCUwjWIE\CDDAETaGCJZisyzt.exe', '64');
DeleteFile('C:\Windows\TEMP\uSFvreRjqIAScwlV\ttWRpIGdKUvaViZM.exe', '32');
DeleteFile('C:\Windows\TEMP\uSFvreRjqIAScwlV\ttWRpIGdKUvaViZM.exe', '64');
DeleteService('101B10CA');
DeleteService('107863AA');
DeleteService('2511f0233d95488a');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\World of Tanks (1)', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\World of Tanks', 'x64');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
DeleteSchedulerTask('bkuEDqiNwGRnsylXdWU');
DeleteSchedulerTask('bkuwbUhgLXvJgoAVApl');
DeleteSchedulerTask('bkuwGBfjeZqvJjSXKVS');
DeleteSchedulerTask('C:\Windows\Task\bkuEDqiNwGRnsylXdWU.job');
DeleteSchedulerTask('C:\Windows\Task\bkuwbUhgLXvJgoAVApl.job');
DeleteSchedulerTask('C:\Windows\Task\bkuwGBfjeZqvJjSXKVS.job');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(false);
end.
Компьютер перезагрузится.
Удалите программу Auslogics BoostSpeed.
Сделайте лог Malwarebytes AdwCleaner.