Выполните рекомендации после лечения.
Выполните скрипт в AVZ:
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\program files\smart file advisor\sfaupdater.exe');
TerminateProcessByName('c:\program files\004\rqpbhevlkc32.exe');
TerminateProcessByName('c:\program files\quiknowledge\service\qksvc.exe');
TerminateProcessByName('c:\program files\coupondownloader\coupondownloaderservice.exe');
QuarantineFile('C:\Program Files\Quiknowledge\IE\QuiknowledgeClientIE.dll','');
QuarantineFile('C:\Program Files\Smart File Advisor\sfa.exe','');
QuarantineFile('c:\Program Files\CouponDownloader\nfapi.dll','');
QuarantineFile('c:\Program Files\CouponDownloader\ProtocolFilters.dll','');
QuarantineFile('c:\program files\smart file advisor\sfaupdater.exe','');
QuarantineFile('c:\program files\004\rqpbhevlkc32.exe','');
QuarantineFile('c:\program files\quiknowledge\service\qksvc.exe','');
QuarantineFile('c:\program files\coupondownloader\coupondownloaderservice.exe','');
DeleteFile('c:\program files\coupondownloader\coupondownloaderservice.exe','32');
DeleteFile('c:\program files\quiknowledge\service\qksvc.exe','32');
DeleteFile('c:\program files\004\rqpbhevlkc32.exe','32');
DeleteFile('c:\Program Files\CouponDownloader\ProtocolFilters.dll','32');
DeleteFile('c:\Program Files\CouponDownloader\nfapi.dll','32');
DeleteFile('C:\Program Files\Smart File Advisor\SFAUpdater.exe','32');
DeleteFile('C:\Program Files\Smart File Advisor\sfa.exe','32');
DeleteFile('c:\progra~1\suptab\search~1.dll','32');
DeleteFile('C:\Program Files\Quiknowledge\IE\QuiknowledgeClientIE.dll','32');
DeleteFile('C:\Windows\system32\Tasks\{26F11EC7-93A0-4720-85CF-DC670F82F524}','32');
DelBHO('{ae07101b-46d4-4a98-af68-0333ea26e113}');
DelBHO('{323C6E6D-1621-470F-8A52-4FDEC4E75E40}');
DeleteFileMask('C:\Program Files\Quiknowledge','*',true);
DeleteFileMask('C:\Program Files\Smart File Advisor','*',true);
DeleteFileMask('c:\Program Files\CouponDownloader','*',true);
DeleteFileMask('c:\program files\004','*',true);
DeleteFileMask('c:\progra~1\suptab','*',true);
DeleteDirectory('C:\Program Files\Quiknowledge');
DeleteDirectory('C:\Program Files\Smart File Advisor');
DeleteDirectory('c:\Program Files\CouponDownloader');
DeleteDirectory('c:\program files\004');
DeleteDirectory('c:\progra~1\suptab');
BC_ImportDeletedList;
ExecuteSysClean;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU',2,2,true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Выполните в AVZ скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
В папке с AVZ появится архив карантина quarantine.zip, отправьте этот файл по ссылке "Прислать запрошенный карантин" над над первым сообщением в теме.
Выполните 2-й стандартный скрипт в AVZ и прикрепите к своему следующему сообщению файл virusinfo_syscheck.zip.
Сделайте лог AdwCleaner (by Xplode).