fol3r, Выполнить скрипт AVZ (как выполнять скрипт - в шапке) beginSearchRootkit(true, true);SetAVZGuardStatus(True); QuarantineFile('C:\Program Files\sense\sense-codedownloader.exe',''); QuarantineFile('C:\Program Files\sense\sense-bho.dll',''); QuarantineFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-3.exe',''); QuarantineFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-2.exe',''); QuarantineFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-11.exe',''); QuarantineFile('C:\Program Files\Sense\Sense-codedownloader.exe',''); QuarantineFile('C:\ProgramData\ShopperPro\ShopperPro.dll',''); QuarantineFile('C:\Program Files\snipsmart\snipsmartbho.dll',''); DelBHO('{11111111-1111-1111-1111-110611191111}'); DelBHO('{11111111-1111-1111-1111-110611191115}'); DelBHO('{11111111-1111-1111-1111-110611341129}'); QuarantineFile('C:\Program Files\SavePass 1.1\SavePass 1.1-bho.dll',''); QuarantineFile('C:\Program Files\Sense\Sense-bho.dll',''); QuarantineFile('C:\Program Files\Ge-Force\Ge-Force-bho.dll',''); QuarantineFile('C:\Program Files\ShopperPro\JSDriver\1.37.0.1323\jsdrv.exe',''); QuarantineFile('C:\Windows\system32\drivers\{6ccfd995-07be-49cf-8ad6-1422dc08761a}Gw.sys',''); QuarantineFile('C:\Program Files\SavePass 1.1\WebSocket4Net.dll',''); QuarantineFile('C:\Program Files\SavePass 1.1\SuperSocket.ClientEngine.Protocol.dll',''); QuarantineFile('C:\Program Files\SavePass 1.1\SuperSocket.ClientEngine.Core.dll',''); QuarantineFile('C:\Program Files\SavePass 1.1\SuperSocket.ClientEngine.Common.dll',''); QuarantineFile('C:\Program Files\SavePass 1.1\Newtonsoft.Json.dll',''); QuarantineFile('C:\Program Files\SavePass 1.1\Interop.IWshRuntimeLibrary.dll',''); QuarantineFile('C:\Program Files\SavePass 1.1\087e6853-c3e9-4b4b-8b32-907946c3d517.dll',''); QuarantineFile('C:\Program Files\Ge-Force\3d750e74-bcc5-4071-9802-bd76b8e81e01.dll',''); QuarantineFile('c:\program files\ytdownloader\ytdownloader.exe',''); QuarantineFile('C:\Program Files\snipsmart\updatesnipsmart.exe',''); QuarantineFile('c:\program files\snipsmart\updatesnipsmart.exe',''); QuarantineFile('c:\program files\snipsmart\bin\snipsmart.browseradapter.exe',''); QuarantineFile('c:\program files\snipsmart\bin\snipsmart.boasprt.exe',''); QuarantineFile('c:\program files\snipsmart\bin\snipsmart.boashelper.exe',''); QuarantineFile('c:\program files\snipsmart\bin\snipsmart.boas.exe',''); QuarantineFile('c:\program files\shopperpro\jsdriver\1.37.0.1323\jsdrv.exe',''); QuarantineFile('c:\program files\ge-force\f244430e-5081-4c65-91f8-9a1f9210f500-6.exe',''); QuarantineFile('c:\program files\savepass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-6.exe',''); QuarantineFile('c:\program files\savepass 1.1\72239fef-1c9f-4091-b12c-2aeeecd2a277.exe',''); QuarantineFile('c:\program files\savepass 1.1\463a550c-b133-4e17-b1fd-ee7051c121cf.exe',''); QuarantineFile('c:\program files\sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-6.exe',''); DeleteFile('c:\program files\sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-6.exe','32'); DeleteFile('c:\program files\savepass 1.1\463a550c-b133-4e17-b1fd-ee7051c121cf.exe','32'); DeleteFile('c:\program files\savepass 1.1\72239fef-1c9f-4091-b12c-2aeeecd2a277.exe','32'); DeleteFile('c:\program files\savepass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-6.exe','32'); DeleteFile('c:\program files\ge-force\f244430e-5081-4c65-91f8-9a1f9210f500-6.exe','32'); DeleteFile('C:\Program Files\Ge-Force\3d750e74-bcc5-4071-9802-bd76b8e81e01.dll','32'); DeleteFile('C:\Program Files\SavePass 1.1\087e6853-c3e9-4b4b-8b32-907946c3d517.dll','32'); DeleteFile('C:\Program Files\Ge-Force\Ge-Force-bho.dll','32'); DeleteFile('C:\Program Files\Sense\Sense-bho.dll','32'); DeleteFile('C:\Program Files\SavePass 1.1\SavePass 1.1-bho.dll','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-1.job','32'); DeleteFile('C:\Program Files\Sense\Sense-codedownloader.exe','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-11.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-11.job','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-2.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-2.job','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-3.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-3.job','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-4.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-4.job','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-5.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-5.job','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-5_user.job','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-6.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-6.job','32'); DeleteFile('C:\Program Files\Sense\25cf42b9-9705-450e-bf6f-1c797d05a5d5-7.exe','32'); DeleteFile('C:\Windows\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-7.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\463a550c-b133-4e17-b1fd-ee7051c121cf.exe','32'); DeleteFile('C:\Windows\Tasks\463a550c-b133-4e17-b1fd-ee7051c121cf.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\72239fef-1c9f-4091-b12c-2aeeecd2a277.exe','32'); DeleteFile('C:\Windows\Tasks\72239fef-1c9f-4091-b12c-2aeeecd2a277.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\SavePass','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-1.job','32'); DeleteFile('1.1-codedownloader.exe','32'); DeleteFile('C:\Program Files\SavePass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-11.exe','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-11.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-2.exe','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-2.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-4.exe','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-4.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-5.exe','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-5.job','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-5_user.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-6.exe','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-6.job','32'); DeleteFile('C:\Program Files\SavePass 1.1\89a0faa6-1188-4c03-9f78-398161b269b2-7.exe','32'); DeleteFile('C:\Windows\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-7.job','32'); DeleteFile('C:\Program Files\Ge-Force\Ge-Force-codedownloader.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-1.job','32'); DeleteFile('C:\Program Files\Ge-Force\f244430e-5081-4c65-91f8-9a1f9210f500-11.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-11.job','32'); DeleteFile('C:\Program Files\Ge-Force\f244430e-5081-4c65-91f8-9a1f9210f500-2.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-2.job','32'); DeleteFile('C:\Program Files\Ge-Force\f244430e-5081-4c65-91f8-9a1f9210f500-4.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-4.job','32'); DeleteFile('C:\Program Files\Ge-Force\f244430e-5081-4c65-91f8-9a1f9210f500-5.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-5.job','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-5_user.job','32'); DeleteFile('C:\Program Files\Ge-Force\f244430e-5081-4c65-91f8-9a1f9210f500-6.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-6.job','32'); DeleteFile('C:\Program Files\Ge-Force\f244430e-5081-4c65-91f8-9a1f9210f500-7.exe','32'); DeleteFile('C:\Windows\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-7.job','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-1','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-11','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-2','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-3','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-4','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-5','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-5_user','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-6','32'); DeleteFile('C:\Windows\system32\Tasks\25cf42b9-9705-450e-bf6f-1c797d05a5d5-7','32'); DeleteFile('C:\Windows\system32\Tasks\463a550c-b133-4e17-b1fd-ee7051c121cf','32'); DeleteFile('C:\Windows\system32\Tasks\72239fef-1c9f-4091-b12c-2aeeecd2a277','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-1','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-11','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-2','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-4','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-5','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-5_user','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-6','32'); DeleteFile('C:\Windows\system32\Tasks\89a0faa6-1188-4c03-9f78-398161b269b2-7','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-1','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-11','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-2','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-4','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-5','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-5_user','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-6','32'); DeleteFile('C:\Windows\system32\Tasks\f244430e-5081-4c65-91f8-9a1f9210f500-7','32'); DeleteFile('C:\Windows\system32\Tasks\Funmoods','32'); DeleteFile('C:\Windows\system32\Tasks\kbrowser-updater-utility','32'); DeleteFile('C:\Windows\system32\Tasks\Kinoroom Browser','32'); DeleteFile('C:\Program Files\sense\sense-bho.dll','32'); DeleteFile('C:\Program Files\sense\sense-codedownloader.exe','32');BC_ImportAll;ExecuteSysClean;ExecuteWizard('TSW',2,3,true);BC_Activate;RebootWindows(true);end. После перзагрузки еще один скрипт AVZ: beginCreateQurantineArchive(GetAVZDirectory+'quarantine.zip');end.Архив quarantine.zip залить на файлообменник, ссылку сюда. Cделай новые логи AVZ (2-й стандартный скрипт AVZ) Сделай лог Malwarebytes Antimalware (как сделать лог см. - в шапке)