Velton Выполни скрипт AVZ (как выполнить скрипт - в шапке): ClearQuarantine; SearchRootkit(true, true); SetAVZGuardStatus(True); QuarantineFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll',''); QuarantineFile('C:\WINDOWS\system32\Audiodev.dll',''); QuarantineFile('C:\WINDOWS\System32\wzcsvc.dll',''); QuarantineFile('C:\Program Files\ExtensionPack\TransBar\TransBar.exe',''); QuarantineFile('C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL',''); QuarantineFile('C:\Documents and Settings\Коля\Application Data\jzkv.exe',''); QuarantineFile('C:\Program Files\VKMus\vkmus.dll',''); QuarantineFile('C:\WINDOWS\system32\ntshrui.dll',''); QuarantineFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll',''); DeleteFile('C:\Documents and Settings\Коля\Application Data\jzkv.exe'); BC_DeleteFile('C:\Documents and Settings\Коля\Application Data\jzkv.exe'); ClearHostsFile; BC_ImportAll; ExecuteSysClean; ExecuteWizard('TSW',2,3,true); ExecuteRepair(13); BC_Activate; RebootWindows(true); end.begin После перзагрузки еще один скрипт AVZ: begin CreateQurantineArchive(GetAVZDirectory+'quarantine.zip'); end. Архив quarantine.zip залить на файлообменник, ссылку сюда. После чего сделать новые логи AVZ (2й стандартный скрипт AVZ) Добавлено спустя 3 минуты 35 секунд: ViktorOBM в логах чисто Добавлено спустя 21 минуту 26 секунд: vit007 Выполни скрипт AVZ (как выполнить скрипт - в шапке): begin SearchRootkit(true, true); SetAVZGuardStatus(True); QuarantineFile('C:\Documents and Settings\Администратор\Application Data\14C.tmp',''); QuarantineFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FWLSEUM9\e[1].exe',''); QuarantineFile('C:\Documents and Settings\Администратор\dwvcwj.exe',''); QuarantineFile('c:\documents and settings\all users\application data\vksaver\vksaver.exe',''); QuarantineFile('C:\WINDOWS\system32\occache.dll',''); QuarantineFile('C:\WINDOWS\System32\logon.scr',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-9850\kswor50y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-9813\kswor98y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-6883\dfe.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1858\kswor18y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1413\syitm.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1214\t7vd.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0953\klmqm122y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0318\k344m093y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0172\kmixm122y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0122\k344m122y.exe',''); QuarantineFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0113\kswor122y.exe',''); QuarantineFile('C:\Program Files\facemoods.com\facemoods\1.4.17.6\facemoodssrv.exe',''); QuarantineFile('C:\Documents and Settings\Администратор\Application Data\Ekhghk.exe',''); QuarantineFile('C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll',''); QuarantineFile('C:\WINDOWS\system32\drivers\aspi32.sys',''); DeleteFile('C:\Documents and Settings\Администратор\Application Data\Ekhghk.exe'); BC_DeleteFile('C:\Documents and Settings\Администратор\Application Data\Ekhghk.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0113\kswor122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0122\k344m122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0172\kmixm122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0318\k344m093y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0953\klmqm122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1214\t7vd.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1413\syitm.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1858\kswor18y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-6883\dfe.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-9813\kswor98y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-9850\kswor50y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','12CFG214-K641-12SF-N85P'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kswor50y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kswor98y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Fnfx'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kswor18y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','zaber0'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Tnaww'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','t7vd'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','klmq122y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','k344m093y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Ekhghk'); RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','facemoods'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kswor122y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','k344m122y'); RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kmix122y'); DeleteFile('C:\Documents and Settings\Администратор\dwvcwj.exe'); DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FWLSEUM9\e[1].exe'); DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\FWLSEUM9\y[1].exe'); DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\G7N6XPXI\y[2].exe'); DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YKC9LA53\v[1].exe'); DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YKC9LA53\w[1].exe'); DeleteFile('C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YKC9LA53\y[1].exe'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\149.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\14C.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\178.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\199.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\1A7.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\25.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\284.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\2C.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\2DE.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\2E.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\305.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\32.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\33.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\40.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\4E0.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\57.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\64.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\83.tmp'); DeleteFile('C:\Documents and Settings\Администратор\Application Data\8B.tmp'); DeleteFile('C:\Documents and Settings\Администратор\caddwqj.exe'); DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\12FPE1PE\ddng[1].exe'); DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\12FPE1PE\shrine[1].exe'); DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\UFXDV0V9\ddng[1].exe'); DeleteFile('C:\Documents and Settings\Администратор\Local Settings\Temporary Internet Files\Content.IE5\XHHOHS0D\shrine[1].exe'); DeleteFile('C:\WINDOWS\system32\53.exe'); DeleteFile('C:\WINDOWS\system32\80.exe'); DeleteFile('C:\WINDOWS\system32\86.exe'); DeleteFile('C:\WINDOWS\system32\88.exe'); DeleteFile('C:\WINDOWS\system32\01.exe'); DeleteFile('C:\WINDOWS\system32\04.exe'); DeleteFile('C:\WINDOWS\system32\05.exe'); DeleteFile('C:\WINDOWS\system32\06.exe'); DeleteFile('C:\WINDOWS\system32\07.exe'); DeleteFile('C:\WINDOWS\system32\08.exe'); DeleteFile('C:\WINDOWS\system32\10.exe'); DeleteFile('C:\WINDOWS\system32\11.exe'); DeleteFile('C:\WINDOWS\system32\14.exe'); DeleteFile('C:\WINDOWS\system32\16.exe'); DeleteFile('C:\WINDOWS\system32\17.exe'); DeleteFile('C:\WINDOWS\system32\18.exe'); DeleteFile('C:\WINDOWS\system32\24.exe'); DeleteFile('C:\WINDOWS\system32\25.exe'); DeleteFile('C:\WINDOWS\system32\30.exe'); DeleteFile('C:\WINDOWS\system32\31.exe'); DeleteFile('C:\WINDOWS\system32\32.exe'); DeleteFile('C:\WINDOWS\system32\33.exe'); DeleteFile('C:\WINDOWS\system32\34.exe'); DeleteFile('C:\WINDOWS\system32\38.exe'); DeleteFile('C:\WINDOWS\system32\40.exe'); DeleteFile('C:\WINDOWS\system32\42.exe'); DeleteFile('C:\WINDOWS\system32\43.exe'); DeleteFile('C:\WINDOWS\system32\46.exe'); DeleteFile('C:\WINDOWS\system32\47.exe'); DeleteFile('C:\WINDOWS\system32\57.exe'); DeleteFile('C:\WINDOWS\system32\58.exe'); DeleteFile('C:\WINDOWS\system32\60.exe'); DeleteFile('C:\WINDOWS\system32\61.exe'); DeleteFile('C:\WINDOWS\system32\62.exe'); DeleteFile('C:\WINDOWS\system32\66.exe'); DeleteFile('C:\WINDOWS\system32\68.exe'); DeleteFile('C:\WINDOWS\system32\70.exe'); DeleteFile('C:\WINDOWS\system32\71.exe'); DeleteFile('C:\WINDOWS\system32\72.exe'); DeleteFile('C:\WINDOWS\system32\74.exe'); DeleteFile('C:\WINDOWS\system32\75.exe'); DeleteFile('C:\WINDOWS\system32\77.exe'); DeleteFile('C:\WINDOWS\system32\81.exe'); BC_DeleteFile('C:\Documents and Settings\Администратор\dwvcwj.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0172\kmixm122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0953\klmqm122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0113\kswor122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0122\k344m122y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0318\k344m093y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1858\kswor18y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-9850\kswor50y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-9813\kswor98y.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1214\t7vd.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-6883\dfe.exe'); DeleteFile('C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1413\syitm.exe'); BC_ImportAll; ExecuteSysClean; ClearHostsFile; ExecuteWizard('TSW',2,3,true); BC_Activate; RebootWindows(true); end. После перзагрузки еще один скрипт AVZ: begin CreateQurantineArchive(GetAVZDirectory+'quarantine.zip'); end. Архив quarantine.zip залить на файлообменник, ссылку сюда. После чего сделать новые логи AVZ (2й стандартный скрипт AVZ)