1) CHROME.DLL Win32/Patched.NFS ( ESET )
2) А скрипт я бы такой написал.
;uVS v3.85.22 [http://dsrt.dyndns.org]
;Target OS: NTv6.1
v385c
deldirex %SystemDrive%\USERS\ГОСТЬ\APPDATA\ROAMING\MICROSOFT\INTERNET
deldirex %SystemDrive%\USERS\ГОСТЬ\APPDATA\ROAMING\MICROSOFT\WINDOWS\
deldirex %SystemDrive%\USERS\ГОСТЬ\DESKTOP
;------------------------autoscript---------------------------
chklst
delvir
deldirex %SystemDrive%\PROGRAMDATA\VKSAVER
deldirex %SystemDrive%\PROGRAM FILES\SURPRISINGDISCOUNTS
deldirex %SystemDrive%\PROGRAMDATA\CLUICKFORSALE
deldirex %SystemDrive%\PROGRAMDATA\GREATSAVING
deldirex %SystemDrive%\PROGRAMDATA\CLICKFORSALOE
deldirex %SystemDrive%\PROGRAMDATA\PPRICEDOWNLOADERO
deldirex %SystemDrive%\PROGRAMDATA\FLEASHCOUPONU
deldirex %SystemDrive%\PROGRAMDATA\SAVINSHOOP
deldirex %SystemDrive%\PROGRAMDATA\SHHOPPERMASTER
deldirex %SystemDrive%\PROGRAM FILES\TPERFECTCOUPON
delref HTTP://SEARCH.GBOXAPP.COM/?AFF=P
bl 5103F2D8EDC9A8A89BBFD8D538230D32 1737024
delref \\?\C:\USERS\ADMIN\APPDATA\LOCAL\YANDEX\UPDATER\PRAETORIAN.EXE
del \\?\C:\USERS\ADMIN\APPDATA\LOCAL\YANDEX\UPDATER\PRAETORIAN.EXE
deldirex %SystemDrive%\USERS\ADMIN\APPDATA\LOCAL\AMIGO\APPLICATION\32
bl 7701918E29359D58E39BF0F0AEBFEDDE 688424
delref \\?\C:\USERS\ADMIN\APPDATA\LOCAL\YANDEX\UPDATER2\BROWSERMANAGERSHO
del \\?\C:\USERS\ADMIN\APPDATA\LOCAL\YANDEX\UPDATER2\BROWSERMANAGERSHO
deldirex %SystemDrive%\USERS\ADMIN\APPDATA\LOCAL\AMIGO\APPLICATION
deldirex %SystemDrive%\PROGRAM FILES\OPTIMIZER PRO
bl 3B81BDDED18AAF51E02F0CB6CC69F27A 78352
delref \\?\C:\PROGRAM FILES\ASSETS MANAGER\SMDMF\TBICON.EXE
del \\?\C:\PROGRAM FILES\ASSETS MANAGER\SMDMF\TBICON.EXE
deldirex %SystemDrive%\PROGRAM FILES\ZAXAR
bl 10C1D8E3173284659C3757537E134D60 6977768
delref \\?\C:\USERS\ADMIN\APPDATA\LOCAL\MAIL.RU\MAILRUUPDATER.EXE
del \\?\C:\USERS\ADMIN\APPDATA\LOCAL\MAIL.RU\MAILRUUPDATER.EXE
bl 1B98C0F857374169E84168B7210EC0E4 7241960
delref \\?\C:\USERS\ADMIN\APPDATA\LOCAL\MAILRU\MAILRUUPDATER.EXE
del \\?\C:\USERS\ADMIN\APPDATA\LOCAL\MAILRU\MAILRUUPDATER.EXE
bl 5F65D6C209792A411A774CCCA5683C9F 261416
delref \\?\C:\USERS\ADMIN\APPDATA\LOCAL\YANDEX\UPDATER2\FIXHOSTS.EXE
del \\?\C:\USERS\ADMIN\APPDATA\LOCAL\YANDEX\UPDATER2\FIXHOSTS.EXE
bl 7586B12BA0407E7A38D0419D27BB411A 488464
delref \\?\C:\PROGRAM FILES\SETTINGS MANAGER\SMDMF\DEL_DM_LL_NSK40B6.DLL
del \\?\C:\PROGRAM FILES\SETTINGS MANAGER\SMDMF\DEL_DM_LL_NSK40B6.DLL
del %SystemDrive%\USERS\PUBLIC\RECORDED TV\TRZE44F.TMP
del %SystemDrive%\USERS\PUBLIC\RECORDED TV\TRZD982.TMP
bl B25FD4DDB7CB059904C2108C24C8B00B 209384
delref \\?\C:\PROGRAM FILES\WINDOWSPLAYER\UPDATER.EXE
del \\?\C:\PROGRAM FILES\WINDOWSPLAYER\UPDATER.EXE
bl E8344257056C7F903BA488DD93E0A371 7736368
delref \\?\C:\PROGRAM FILES\WINDOWSPLAYER\WINPLAYER.EXE
del \\?\C:\PROGRAM FILES\WINDOWSPLAYER\WINPLAYER.EXE
deldirex %SystemDrive%\PROGRAM FILES\LOVIVKONTAKTE
;-------------------------------------------------------------
bl 101859FE092973933EADBACF3AC99D2D 565760
delall %SystemDrive%\PROGRAMDATA\DUEAL4ME\ESNNPXOEOKGFS5.DLL
bl 8B4796E82170E61D2FB8F1B9230D80BF 54
delall %SystemDrive%\PROGRAM FILES\OPTIMIZER PRO\HOMEPAGE.URL
bl DD01BBD8AB4B5A67DC0A402D160400FD 395264
delall %SystemDrive%\USERS\ADMIN\APPDATA\ROAMING\VG01_2\S_INST.EXE
bl DF851B3F995F729A8E1D37EC19C2401C 31893832
delall %SystemDrive%\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\38.0.2125.111\CHROME.DLL
deltmp
delnfr
restart