Запустите HijackThis, расположенный в папке Autologger и пофиксите (в Windows Vista/7/8/10 необходимо запускать через правую кнопку мыши Запуск от имени администратора)):
Код:
O17 - HKLM\System\CCS\Services\Tcpip\..\{74BB7EA0-E383-419E-AFCC-0A2CCBDEFAD6}: [NameServer] = 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\..\{74BB7EA0-E383-419E-AFCC-0A2CCBDEFAD6}: [NameServer] = 82.163.143.176
O17 - HKLM\System\CCS\Services\Tcpip\..\{9305AF14-74D4-45A5-A8BD-72F211694179}: [NameServer] = 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\..\{9305AF14-74D4-45A5-A8BD-72F211694179}: [NameServer] = 82.163.143.176
O17 - HKLM\System\CCS\Services\Tcpip\..\{B45BBB0D-4740-419E-ABC7-AA118977EB7B}: [NameServer] = 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\..\{B45BBB0D-4740-419E-ABC7-AA118977EB7B}: [NameServer] = 82.163.143.176
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2797D34-9911-48DC-B3CF-404925A49EAC}: [NameServer] = 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2797D34-9911-48DC-B3CF-404925A49EAC}: [NameServer] = 82.163.143.176
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: [NameServer] = 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: [NameServer] = 82.163.143.176
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{74BB7EA0-E383-419E-AFCC-0A2CCBDEFAD6}: [NameServer] = 82.163.142.178
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{74BB7EA0-E383-419E-AFCC-0A2CCBDEFAD6}: [NameServer] = 82.163.143.176
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{9305AF14-74D4-45A5-A8BD-72F211694179}: [NameServer] = 82.163.142.178
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{9305AF14-74D4-45A5-A8BD-72F211694179}: [NameServer] = 82.163.143.176
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{B45BBB0D-4740-419E-ABC7-AA118977EB7B}: [NameServer] = 82.163.142.178
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{B45BBB0D-4740-419E-ABC7-AA118977EB7B}: [NameServer] = 82.163.143.176
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{F2797D34-9911-48DC-B3CF-404925A49EAC}: [NameServer] = 82.163.142.178
O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{F2797D34-9911-48DC-B3CF-404925A49EAC}: [NameServer] = 82.163.143.176
O17 - HKLM\System\ControlSet002\Services\Tcpip\Parameters: [NameServer] = 82.163.142.178
O17 - HKLM\System\ControlSet002\Services\Tcpip\Parameters: [NameServer] = 82.163.143.176
Выполните скрипт в AVZ:
Код:
begin
SearchRootkit(true, true);
QuarantineFile('C:\PROGRA~3\620bdb86\2e9fd7ff.dll', '');
QuarantineFile('C:\Users\Strel\AppData\Local\879F87~1\{2E9FD~1', '');
QuarantineFile('C:\Users\Strel\AppData\Local\879F87~1\{2E9FD~1.', '');
DeleteFile('C:\PROGRA~3\620bdb86\2e9fd7ff.dll', '32');
DeleteFile('C:\Users\Strel\AppData\Local\879F87~1\{2E9FD~1', '32');
DeleteFile('C:\Users\Strel\AppData\Local\879F87~1\{2E9FD~1.', '32');
ExecuteFile('ipconfig.exe', '/flushdns', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{797E0447-0C0B-0F0F-0F11-087E7E091109}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "{8BE70333-4BB5-5C86-3223-674D5F311E3A}" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "D7A02800-F8F4-8B43-00D8-1F22A3382EFA" /F', 0, 15000, true);
DeleteFileMask('c:\progra~3\620bdb86', '*', true);
DeleteFileMask('c:\users\strel\appdata\local\879f87~1', '*', true);
DeleteDirectory('c:\progra~3\620bdb86');
DeleteDirectory('c:\users\strel\appdata\local\879f87~1');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(21);
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Выполните в AVZ скрипт:
Код:
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
В папке с AVZ появится архив карантина quarantine.zip, отправьте этот файл по ссылке "Прислать запрошенный карантин" над над первым сообщением в теме.
Сделайте новый лог Autologger, Ok после запуска нажимайте с зажатой клавишей Shift.
Сделайте лог Malwarebytes AdwCleaner.