Выполните скрипт в uVS:
Код:
;uVS v4.0.10 [http://dsrt.dyndns.org]
;Target OS: NTv10.0
v400c
;------------------------autoscript---------------------------
sreg
delref %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\CURL\CURL.EXE
delref %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\CURL\CURL_7_54.EXE
delref %SystemDrive%\USERS\МАКСИМ\APPDATA\ROAMING\MICROSOFT\MSI.EXE
delref %SystemDrive%\USERS\МАКСИМ\APPDATA\LOCAL\SYSLOG\SYSLOG.EXE
zoo %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\SETUPSK\PYTHON\PYTHONW.EXE
delall %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\SETUPSK\PYTHON\PYTHONW.EXE
zoo %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\SETUPS~1\PYTHON\PYTHONW.EXE
delall %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\SETUPS~1\PYTHON\PYTHONW.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCLAUNCHER.EXE
del %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCLAUNCHER.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY:UCDRV-X64.SYS
del %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY:UCDRV-X64.SYS
delref %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCDRV-X64.SYS
del %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCDRV-X64.SYS
delref %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCLAUNCHER-X86.EXE
del %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCLAUNCHER-X86.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCLAUNCHER-X64.EXE
del %SystemDrive%\PROGRAM FILES (X86)\UCBROWSER\SECURITY\UCLAUNCHER-X64.EXE
zoo %SystemDrive%\USERS\МАКСИМ\DESKTOP\CONSOLEAPPLICATION1.EXE
delall %SystemDrive%\USERS\МАКСИМ\DESKTOP\CONSOLEAPPLICATION1.EXE
delref HTTP://GO.MAIL.RU/DISTIB/EP/?PRODUCT_ID=%7B40B3BF36-53AD-4A1F-A157-7E18731C770C%7D&GP=831106
delref HTTP://MAIL.RU/CNT/10445?GP=831105
delref %SystemDrive%\PROGRAM FILES (X86)\THZXUJVJU\3NWXG8V.DLL
delref DESKTOP\CRUTCHESUPDATER_5F8-64A___.EXE
delref HTTP://AMTOMIL.RU/F.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\GXZIGYYLSHYU2\IWR5ZE3.DLL
delref %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\SETUPS~1\ML.PY
delref %SystemDrive%\USERS\2BA0~1\APPDATA\ROAMING\SETUPSK\ML.PY
delref %SystemDrive%\PROGRAM FILES (X86)\PC PROTECTOR PLUS\PCPROTECTORPLUS.EXE
delref %SystemDrive%\PROGRAM FILES\XWINBRAYME\XWINBRAYME.DLL
del %Sys32%\DRIVERS:UCDRV-X64.SYS
delref %Sys32%\DRIVERS:UCDRV-X64.SYS
czoo
deltmp
apply
areg
Сделайте
лог Farbar Recovery Scan Tool.