В AVZ выполните скрипт:
Код:
begin
QuarantineFile('c:\documents and settings\all users\application data\seekservice\seekservice189.exe', 'MBAM: Adware.Agent.ZGen');
QuarantineFile('c:\documents and settings\OEM\my documents\amazingcdburnerfree.exe', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\advuninst.exe', 'MBAM: Trojan.Agent');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\components\memedia_ff.dll', 'MBAM: Adware.AdVantage');
QuarantineFile('c:\documents and settings\OEM\application data\avdrn.dat', 'MBAM: Malware.Trace');
QuarantineFile('c:\documents and settings\skydancer\application data\wiaserva.log', 'MBAM: Malware.Trace');
QuarantineFile('c:\WINDOWS\system32\calck.exe', 'MBAM: Trojan.Fkantakte');
QuarantineFile('c:\WINDOWS\system32\fjhdyfhsn.bat', 'MBAM: Malware.Trace');
QuarantineFile('c:\WINDOWS\system32\skynetplookhit.dat', 'MBAM: Rootkit.TDSS');
QuarantineFile('c:\WINDOWS\system32\skynetubptqkup.dat', 'MBAM: Rootkit.TDSS');
QuarantineFile('c:\documents and settings\all users\firefox.exe', 'MBAM: Rootkit.Dropper');
QuarantineFile('c:\program files\advantage\ffext.mod', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\advantage.db', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\advantage.htm', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\user.db', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome.manifest', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\install.js', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\install.rdf', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\vssver2.scc', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\advantage.png', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\contents.rdf', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\overlay.js', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\overlay.xul', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\vssver2.scc', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US\overlay.dtd', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US\vssver2.scc', 'MBAM: Adware.Advantage');
QuarantineFile('c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\components\imemedia_ff.xpt', 'MBAM: Adware.Advantage');
QuarantineFile('c:\documents and settings\all users\application data\seekservice\seekservice193.exe', 'MBAM: Adware.SeekService');
QuarantineFile('c:\documents and settings\all users\application data\seekservice\seekservice197.exe', 'MBAM: Adware.SeekService');
QuarantineFile('c:\program files\seekservice\uninstall.exe', 'MBAM: Adware.SeekService');
QuarantineFileF('c:\documents and settings\all users\application data\seekservice', '*.*', true,'', 0, 0, '', '');
BC_ImportAll;
BC_Activate;
RebootWindows(true);
end.
После перезагрузки
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Пришлите карантин quarantine.zip по красной ссылке Прислать запрошенный карантин вверху темы.
Удалите в МВАМ все, кроме
Код:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
c:\documents and settings\OEM\my documents\office_professional\keygen.exe (RiskWare.Tool.CK) -> No action taken.
c:\program files\lucas art\star wars battlefront ii\GameData\Mount.exe (Malware.Packer.Gen) -> No action taken.
c:\program files\lucas art\lineage ii abyss\system\gameguard.des (Trojan.Agent) -> No action taken.
c:\program files\lucas art\lineage ii gracia\system-nash\NWindow.dll (Malware.Packer.T) -> No action taken.
c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe (Risktool.Crack) -> No action taken.
c:\скачивание\grand.theft.auto.iv\launchgtaiv.exe (Risktool.Crack) -> No action taken.
d:\program files\lucas art\lineage ii abyss\system\gameguard.des (Trojan.Agent) -> No action taken.
c:\documents and settings\all users\firefox.exe (Rootkit.Dropper) -> No action taken.
Повторите лог mbam