Çàãðóçèòå ñèñòåìó â áåçîïàñíîì ðåæèìå (Safe mode) è âûïîëíèòå ñêðèïò â AVZ (Ôàéë - Âûïîëíèòü ñêðèïò):
Êîä:
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kcalendar.exe', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxescore.exe', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\jsonv6.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kavmenu.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kcalendar.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kcctrl.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kdgui2.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kdump.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kdynmrey.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\keasyipcn.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kpopclt.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\krcmdsext.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\ksapi.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\ksdectrl.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kshmpg.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kshmpgext.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kswebshield.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\ktoolupd.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kupdatesp.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kwansvc.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kwssp.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kwsui.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxebase.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxebscsp.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxecore\kxecore.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxecore\kxelog.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\lblocker.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\operation\cas\kinfoc.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\scom.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksde\kislog.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksde\klengine.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksde\kmctrl.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksde\ksdecs.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksnetm\kmonstat.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaearcha.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaearchb.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecore.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecorea.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecoref.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaecorem.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaext2.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\kaextend.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kae\karchive.dat', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kaeunpack.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kanthack.dll', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kavquara.dll', '32');
DeleteFile('C:\Windows\system32\Drivers\KAVBootC.sys', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys', '32');
DeleteFile('C:\Windows\system32\drivers\kisknl.sys', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\security\ksnetm\kisnetm.sys', '32');
DeleteFile('C:\Windows\system32\drivers\ksapi.sys', '32');
DeleteFile('c:\program files\kingsoft\kingsoft antivirus\kxetray.exe', '32');
DeleteFile('C:\Windows\Tasks\Digital Sites.job', '32');
DeleteFile('C:\Windows\system32\Tasks\Digital Sites', '32');
DeleteFile('C:\Windows\system32\Tasks\kbrowser-updater-utility', '32');
DeleteFile('C:\Windows\system32\Tasks\Safebrowser', '32');
DeleteFile('C:\Windows\system32\Tasks\SystemScript', '32');
DeleteService('ccnfd_1_10_0_6');
DeleteService('ksapi');
DeleteService('kisnetm');
DeleteService('kisknl');
DeleteService('KDHacker');
DeleteService('KAVBootC');
DeleteFileMask('c:\program files\kingsoft\kingsoft antivirus', '*', true);
DeleteDirectory('c:\program files\kingsoft\kingsoft antivirus');
DelCLSID('{D21D88E8-4123-48BA-B0B1-3FDBE4AE5FA4}');
BC_ImportDeletedList;
ExecuteSysClean;
BC_DeleteSvc('KAVBootC');
BC_DeleteSvc('KDHacker');
BC_DeleteSvc('kisknl');
BC_DeleteSvc('kisnetm');
BC_DeleteSvc('ksapi');
BC_Activate;
RebootWindows(true);
end.
Êîìïüþòåð ïåðåçàãðóçèòñÿ.
Ïîâòîðèòå ëîãè ïî ïðàâèëàì. Äëÿ ïîâòîðíîé äèàãíîñòèêè çàïóñòèòå ñíîâà Autologger. Â ïåðâîì äèàëîãîâîì îêíå íàæìèòå ÎÊ, óäåðæèâàÿ íàæàòîé êëàâèøó Shift.
|