Удалите браузер FreeU.
Выполните скрипт в AVZ:
Код:
begin
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
StopService('SvcHost Service Host');
QuarantineFile('C:\Program Files\tortoise svn\tortoisesvn.dll', '');
QuarantineFile('C:\Program Files\UBar\UbarDriver.sys', '');
QuarantineFile('C:\Users\Yulia Kashka\AppData\Local\Amigo\Application\amigo.exe', '');
QuarantineFile('C:\Users\Yulia Kashka\appdata\local\comdev\comdev.exe', '');
QuarantineFile('C:\Users\Yulia Kashka\AppData\Local\yc\Application\yc.exe', '');
QuarantineFile('c:\windows\microsoft\svchost.exe', '');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe', '');
QuarantineFile('C:\Windows\system32\Ea3Host.exe', '');
DeleteFile('C:\Program Files\tortoise svn\tortoisesvn.dll', '32');
DeleteFile('C:\Program Files\UBar\UbarDriver.sys', '32');
DeleteFile('C:\Users\Yulia Kashka\AppData\Local\Amigo\Application\amigo.exe', '32');
DeleteFile('C:\Users\Yulia Kashka\appdata\local\comdev\comdev.exe', '32');
DeleteFile('C:\Users\Yulia Kashka\AppData\Local\yc\Application\yc.exe', '32');
DeleteFile('c:\windows\microsoft\svchost.exe', '32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe', '32');
DeleteFile('C:\Windows\system32\Ea3Host.exe', '32');
DeleteService('Ea3Host');
DeleteService('SvcHost Service Host');
DeleteService('UbarCalloutDriver');
DeleteFileMask('c:\program files\tortoise svn', '*', true);
DeleteFileMask('c:\program files\ubar', '*', true);
DeleteFileMask('c:\users\yulia kashka\appdata\local\amigo', '*', true);
DeleteFileMask('c:\users\yulia kashka\appdata\local\comdev', '*', true);
DeleteFileMask('c:\users\yulia kashka\appdata\local\yc', '*', true);
DeleteDirectory('c:\program files\tortoise svn');
DeleteDirectory('c:\program files\ubar');
DeleteDirectory('c:\users\yulia kashka\appdata\local\amigo');
DeleteDirectory('c:\users\yulia kashka\appdata\local\comdev');
DeleteDirectory('c:\users\yulia kashka\appdata\local\yc');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'gdvwxuyumd');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\amigo', 'command');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ycAutoLaunch_74F3527587245EDCA4EBA30C89D9CB4A', 'command');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.
В папке с AVZ появится архив карантина quarantine.zip, отправьте этот файл по ссылке "Прислать запрошенный карантин" над над первым сообщением в теме.
Скачайте, распакуйте и запустите утилиту ClearLNK. Скопируйте текст ниже в окно утилиты и нажмите "Лечить".
Код:
>>> [HTTP][MASK][h][s] "C:\Users\Yulia Kashka\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk" -> ["C:\Windows\explorer.exe" =>> "hxxp://tizmo.ru/?utm_source=startlink03&utm_content=2753a5e64a795df4d5bb09494b382189&utm_term=59859710B61A3EE58E24F05207E92ABD&utm_d=20171110"]
>>> "C:\Users\Yulia Kashka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Панель запуска приложений Chrome.lnk" -> ["C:\ProgramData\glrGwzyOmGdzXvz\nxgHVtgI0.bat" =>> --show-app-list]
>>> "C:\Users\Yulia Kashka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Панель запуска приложений Chrome.lnk" -> ["C:\ProgramData\glrGwzyOmGdzXvz\nxgHVtgI0.bat" =>> --show-app-list]
>>> "C:\Users\Yulia Kashka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Driver Booster 2 (2).lnk" -> ["C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2\Driver Booster 2.lnk" -> ["C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2\Деинсталлировать Driver Booster 2.lnk" -> ["C:\Program Files (x86)\IObit\Driver Booster\unins000.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\DupKiller.lnk" -> ["D:\Install\DupKiller\DupKiller.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\Запустить в безопасном режиме.lnk" -> ["D:\Install\DupKiller\DupKiller.exe" =>> -r]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\История.lnk" -> ["D:\Install\DupKiller\History.txt"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\Лицензионное соглашение.lnk" -> ["D:\Install\DupKiller\License.txt"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\Удалить DupKiller.lnk" -> ["D:\Install\DupKiller\Uninstall.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\Справка (на английском).lnk" -> ["D:\Install\DupKiller\Help\Eng\help.html"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DupKiller\Справка (на русском).lnk" -> ["D:\Install\DupKiller\Help\Rus\help.html"]
>>> "C:\Users\Yulia Kashka\Desktop\DupKiller.lnk" -> ["D:\Install\DupKiller\DupKiller.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP2\AIMP2.lnk" -> ["C:\Program Files (x86)\AIMP2\AIMP2.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP2\AIMP2 Home.lnk" -> ["C:\Program Files (x86)\AIMP2\AIMP2.url"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP2\AIMP2 Utilities.lnk" -> ["C:\Program Files (x86)\AIMP2\AIMP2u.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP2\Uninstall.lnk" -> ["C:\Program Files (x86)\AIMP2\UnInstall.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\18 Wheels of Steel American Long Haul\Play 18 Wheels of Steel American Long Haul.lnk" -> ["H:\Games\18 Wheels of Steel American Long Haul\alh.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\18 Wheels of Steel American Long Haul\Configure Graphics Options.lnk" -> ["H:\Games\18 Wheels of Steel American Long Haul\alh.exe" =>> /c]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\18 Wheels of Steel American Long Haul\Help.lnk" -> ["H:\Games\18 Wheels of Steel American Long Haul\help.html"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\18 Wheels of Steel American Long Haul\Uninstall.lnk" -> ["H:\Games\18 Wheels of Steel American Long Haul\uninst.exe"]
>>> "C:\Users\Yulia Kashka\AppData\Local\Microsoft\Windows\GameExplorer\{3FEBF390-F74B-4DBB-B43B-A3B97DB17055}\PlayTasks\0\Играть.lnk" -> ["D:\MY\games\GTA San Andreas\gta_sa.exe"]
>>> "C:\Users\Yulia Kashka\Favorites\Links\Интернет.url" -> hxxp://tizmo.ru/?utm_source=favorites03&utm_content=aea8d3344cf60282e12da408b8f78494&utm_term=59859710B61A3EE58E24F05207E92ABD&utm_d=20171110
Отчёт о работе прикрепите.
Сделайте новый лог Autologger.
Сделайте лог Malwarebytes AdwCleaner.