Выполните скрипт в AVZ:
Код:
begin
DeleteFile('C:\ProgramData\Ecois\Hot-Fix.dll', '32');
DeleteFile('C:\ProgramData\Ecois\Kayfresh.dll', '32');
DeleteFile('C:\Users\sst\AppData\Local\Amigo\Application\amigo.exe', '32');
DeleteFile('C:\Program Files (x86)\IObit\Advanced', '32');
DeleteFile('C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe', '32');
DeleteFile('C:\Users\sst\AppData\Local\ComDev\ComDev.exe', '32');
DeleteFileMask('c:\programdata\ecois', '*', false);
DeleteFileMask('c:\users\sst\appdata\local\amigo', '*', true);
DeleteFileMask('c:\program files (x86)\iobit', '*', true);
DeleteFileMask('c:\users\sst\appdata\local\comdev', '*', true);
DeleteDirectory('c:\programdata\ecois');
DeleteDirectory('c:\users\sst\appdata\local\amigo');
DeleteDirectory('c:\program files (x86)\iobit');
DeleteDirectory('c:\users\sst\appdata\local\comdev');
ExecuteFile('schtasks.exe', '/delete /TN "ASC8_PerformanceMonitor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ASC8_SkipUac_sst" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ComDev" /F', 0, 15000, true);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
ExecuteSysClean;
ExecuteRepair(1);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(true);
end.
Компьютер перезагрузится.
Скачайте, распакуйте и запустите утилиту ClearLNK. Скопируйте текст ниже в окно утилиты и нажмите "Лечить".
Код:
>>> "C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk" -> ["C:\Program Files (x86)\Internet Explorer\iexplore.exe" =>> %SNP%]
>>> "C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk" -> ["C:\Program Files (x86)\Internet Explorer\iexplore.exe" =>> %SNP%]
>>> [HTTP][MASK][h][s] "C:\Users\sst\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk" -> ["C:\Windows\explorer.exe" =>> "hxxp://rigneda.ru/?utm_source=startlink03&utm_content=adbf052057e305ed7ecce74202676864&utm_term=5821305B20A4E27530AABDC01C8F8390&utm_d=20170107"]
>>> [HTTP][MASK][h][s] "C:\Users\sst\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Вoйти в Интeрнeт.lnk" -> ["C:\Windows\explorer.exe" =>> "hxxp://rigneda.ru/?utm_source=startlink03&utm_content=adbf052057e305ed7ecce74202676864&utm_term=5821305B20A4E27530AABDC01C8F8390&utm_d=20170107"]
>>> "C:\Users\sst\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk" -> ["C:\ProgramData\eigVvHepj\szGCKONtM5.bat"]
>>> "C:\Users\sst\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Yandex.lnk" -> ["C:\Users\sst\AppData\Local\Yandex\YandexBrowser\Application\browser.exe"]
>>> "C:\Users\sst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex\Yandex.lnk" -> ["C:\Users\sst\AppData\Local\Yandex\YandexBrowser\Application\browser.exe"]
>>> "C:\Users\sst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Приложения Амиго\Амиго.Музыка.lnk" -> ["C:\Users\sst\AppData\Local\Amigo\Application\amigo.exe" =>> --profile-directory=Default --app-id=mbipmajmbfjakbcfnjdldckninlnmhoe]
>>> "C:\Users\sst\Desktop\Амиго.lnk" -> ["C:\Users\sst\AppData\Local\Amigo\Application\amigo.exe"]
>>> "C:\Users\sst\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Амиго.lnk" -> ["C:\Users\sst\AppData\Local\Amigo\Application\amigo.exe"]
>>> "C:\Users\sst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Амиго.lnk" -> ["C:\Users\sst\AppData\Local\Amigo\Application\amigo.exe"]
Отчёт о работе прикрепите.
Сделайте лог Malwarebytes AdwCleaner.