Отключите:
-ПК от интернета
-Все защитные приложения
Подключите:
-Диск E:\
-Диск D:\
Выполните скрипт в AVZ:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('D:\WINDOWS\system32\drivers\RKHit.sys','');
QuarantineFile('D:\WINDOWS\System32\poof','');
QuarantineFile('D:\WINDOWS\System32\kprof','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.48579.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.46506.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.44674.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.44253.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.43923.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.43392.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.41629.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.41379.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.40868.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.40618.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.39867.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.39647.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.33548.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.33488.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.32306.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31164.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31124.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31044.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31034.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30553.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30313.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30243.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30103.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.29662.exe','');
QuarantineFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.29151.exe','');
QuarantineFile('D:\WINDOWS\System32\pdmd53hdf.dll','');
QuarantineFile('D:\pagefile.pif','');
QuarantineFile('C:\autorun.inf','');
QuarantineFile('D:\autorun.inf','');
QuarantineFile('E:\autorun.inf','');
QuarantineFile('D:\WINDOWS\system32\dnsq.dll','');
DeleteFile('D:\WINDOWS\System32\kprof');
DeleteFile('D:\WINDOWS\System32\poof');
DeleteFile('D:\WINDOWS\system32\drivers\RKHit.sys');
DeleteFile('D:\WINDOWS\system32\dnsq.dll');
DeleteFile('E:\autorun.inf');
DeleteFile('D:\autorun.inf');
DeleteFile('C:\autorun.inf');
DeleteFile('D:\pagefile.pif');
DeleteFile('D:\WINDOWS\System32\pdmd53hdf.dll');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.29151.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.29662.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30103.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30243.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30313.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.30553.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31034.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31044.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31124.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.31164.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.32306.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.33488.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.33548.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.39647.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.39867.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.40618.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.40868.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.41379.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.41629.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.43392.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.43923.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.44253.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.44674.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.46506.exe');
DeleteFile('D:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\~.exe.48579.exe');
DelBHO('8D5849A2-93F3-429D-FF34-260A2068897C');
RegKeyStrParamWrite('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows NT\CurrentVersion\Windows', 'AppInit_DLLs', '');
BC_ImportAll;
ExecuteSysClean;
BC_DeleteSvc('kprof');
BC_DeleteSvc('poof');
BC_DeleteSvc('RkHit');
ExecuteWizard('TSW',2,3,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Затем выполните ещё один скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
И пришлите quarantine.zip из папки AVZ согласно правилам (через красную ссылку "Прислать запрошенный карантин" наверху темы).
Обновите базы AVZ (Файл->Обновление баз).
Сделайте повторные логи.