Выполните скрипт в AVZ
Код:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\yqptot.pif','');
QuarantineFile('C:\wwdx.pif','');
QuarantineFile('C:\wqtwgb.pif','');
QuarantineFile('C:\vvxx.pif','');
QuarantineFile('C:\uauear.pif','');
QuarantineFile('C:\tuosej.pif','');
QuarantineFile('C:\tnoo.pif','');
QuarantineFile('C:\tkrw.pif','');
QuarantineFile('C:\spcwy.pif','');
QuarantineFile('C:\shqkqm.pif','');
QuarantineFile('C:\rmxctg.pif','');
QuarantineFile('C:\qbrs.pif','');
QuarantineFile('C:\pjftqx.pif','');
QuarantineFile('C:\owwuct.pif','');
QuarantineFile('C:\oqtcq.pif','');
QuarantineFile('C:\mtbt.pif','');
QuarantineFile('C:\mibdd.pif','');
QuarantineFile('C:\mhrvqr.pif','');
QuarantineFile('C:\luwuxb.pif','');
QuarantineFile('C:\lijf.pif','');
QuarantineFile('C:\kyux.pif','');
QuarantineFile('C:\ksek.pif','');
QuarantineFile('C:\jkmkk.pif','');
QuarantineFile('C:\iodyu.pif','');
QuarantineFile('C:\hwhu.pif','');
QuarantineFile('C:\hrktp.pif','');
QuarantineFile('C:\Documents and Settings\Дарья\DoctorWeb\Quarantine\91[1].exe','');
QuarantineFile('C:\cjraq.pif','');
QuarantineFile('C:\chyxh.pif','');
QuarantineFile('C:\caiux.pif','');
QuarantineFile('C:\Documents and Settings\Дарья\Рабочий стол\.\..\windrv.exe','');
QuarantineFile('C:\Documents and Settings\Дарья\Application Data\lbisov.exe','');
TerminateProcessByName('c:\docume~1\2377~1\locals~1\temp\winfqmv.exe');
QuarantineFile('c:\docume~1\2377~1\locals~1\temp\winfqmv.exe','');
DeleteFile('c:\docume~1\2377~1\locals~1\temp\winfqmv.exe');
DeleteFile('C:\Documents and Settings\Дарья\Application Data\lbisov.exe');
DeleteFile('C:\Documents and Settings\Дарья\Рабочий стол\.\..\windrv.exe');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','advap32');
DeleteFile('C:\caiux.pif');
DeleteFile('C:\chyxh.pif');
DeleteFile('C:\cjraq.pif');
DeleteFile('C:\Documents and Settings\Дарья\DoctorWeb\Quarantine\91[1].exe');
DeleteFile('C:\hrktp.pif');
DeleteFile('C:\hwhu.pif');
DeleteFile('C:\iodyu.pif');
DeleteFile('C:\jkmkk.pif');
DeleteFile('C:\ksek.pif');
DeleteFile('C:\kyux.pif');
DeleteFile('C:\lijf.pif');
DeleteFile('C:\luwuxb.pif');
DeleteFile('C:\mhrvqr.pif');
DeleteFile('C:\mibdd.pif');
DeleteFile('C:\mtbt.pif');
DeleteFile('C:\oqtcq.pif');
DeleteFile('C:\owwuct.pif');
DeleteFile('C:\pjftqx.pif');
DeleteFile('C:\qbrs.pif');
DeleteFile('C:\rmxctg.pif');
DeleteFile('C:\shqkqm.pif');
DeleteFile('C:\spcwy.pif');
DeleteFile('C:\tkrw.pif');
DeleteFile('C:\tnoo.pif');
DeleteFile('C:\tuosej.pif');
DeleteFile('C:\uauear.pif');
DeleteFile('C:\vvxx.pif');
DeleteFile('C:\wqtwgb.pif');
DeleteFile('C:\wwdx.pif');
DeleteFile('C:\yqptot.pif');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows NT\CurrentVersion\Winlogon','Taskman');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Пришлите карантин согласно Приложения 3 правил по красной ссылке Прислать запрошенный карантин вверху темы
Сделайте новые логи
Сделайте лог полного сканирования МВАМ