Êîìïüþòåðíûé ôîðóì OSzone.net  

Êîìïüþòåðíûé ôîðóì OSzone.net (http://forum.oszone.net/index.php)
-   Ëå÷åíèå ñèñòåì îò âðåäîíîñíûõ ïðîãðàìì (http://forum.oszone.net/forumdisplay.php?f=87)
-   -   Ïîéìàë âèðóñû ïîìîãèòå! (http://forum.oszone.net/showthread.php?t=321349)

Vovik_0_1 01-12-2016 22:19 2692139

Ïîéìàë âèðóñû ïîìîãèòå!
 
Âëîæåíèé: 1
Çäðàâñòâóéòå. Ïðîöåññîð çàãðóæàåòñÿ íà 100%, êîìïüþòåð ãëþ÷èò.. Âèäíî ÿâíîå ïðèñóòñòâèå âèðóñîâ ò.ê. çàáëîêèðîâàíà êîìàíäíàÿ ñòðîêà, ðåäàêòîð ðååñòðà, ïàðàìåòðû ïàïîê è ïîèñêà è ò.ä. Ïîìîãèòå!

shestale 02-12-2016 10:32 2692259

Çàêðîéòå âñå ïðîãðàììû, âðåìåííî âûãðóçèòå àíòèâèðóñ, ôàéðâîëë è ïðî÷åå çàùèòíîå ÏÎ.

Âûïîëíèòå ñêðèïò â ÀÂÇ (Ôàéë - Âûïîëíèòü ñêðèïò):

Êîä:

begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
 QuarantineFileF('c:\program files (x86)\zaxar', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
 QuarantineFileF('c:\program files (x86)\youtube adblock', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
 QuarantineFile('c:\users\phantomlvl\appdata\local\lsass.exe', '');
 QuarantineFile('c:\users\phantomlvl\appdata\local\services.exe', '');
 QuarantineFile('c:\users\phantomlvl\appdata\local\winlogon.exe', '');
 QuarantineFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe', '');
 QuarantineFile('c:\program files (x86)\zaxar\zaxarloader.exe', '');
 QuarantineFile('C:\Windows\ShellNew\bronstab.exe', '');
 QuarantineFile('C:\Users\Phantomlvl\AppData\Local\smss.exe', '');
 QuarantineFile('C:\Windows\eksplorasi.exe', '');
 QuarantineFile('C:\Windows\System32\config\systemprofile\AppData\Local\smss.exe', '');
 QuarantineFile('C:\Users\Phantomlvl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif', '');
 QuarantineFile('C:\Users\Phantomlvl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemAutorun.exe', '');
 QuarantineFile('C:\Users\Phantomlvl\AppData\Roaming\Microsoft\Windows\Templates\WowTumpeh.com', '');
 QuarantineFile('C:\Program Files (x86)\Youtube AdBlock\ecYg64P.exe', '');
 QuarantineFile('C:\Users\Phantomlvl\appdata\local\csrss.exe', '');
 QuarantineFile('C:\Users\Phantomlvl\documents\documents.exe', '');
 ExecuteFile('schtasks.exe', '/delete /TN "At1" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "At4" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "Update Service for Youtube AdBlock" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "{E1451253-9A52-4DE7-941C-A3189D5176BD}" /F', 0, 15000, true);
 DeleteFile('c:\users\phantomlvl\appdata\local\lsass.exe', '32');
 DeleteFile('c:\users\phantomlvl\appdata\local\services.exe', '32');
 DeleteFile('c:\users\phantomlvl\appdata\local\winlogon.exe', '32');
 DeleteFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe', '32');
 DeleteFile('c:\program files (x86)\zaxar\zaxarloader.exe', '32');
 DeleteFile('C:\Windows\ShellNew\bronstab.exe', '32');
 DeleteFile('C:\Users\Phantomlvl\AppData\Local\smss.exe', '32');
 DeleteFile('C:\Windows\eksplorasi.exe', '32');
 DeleteFile('C:\Windows\System32\config\systemprofile\AppData\Local\smss.exe', '32');
 DeleteFile('C:\Users\Phantomlvl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif', '32');
 DeleteFile('C:\Users\Phantomlvl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemAutorun.exe', '32');
 DeleteFile('C:\Users\Phantomlvl\AppData\Roaming\Microsoft\Windows\Templates\WowTumpeh.com', '32');
 DeleteFile('C:\Program Files (x86)\Youtube AdBlock\ecYg64P.exe', '32');
 DeleteFile('C:\Users\Phantomlvl\appdata\local\csrss.exe', '32');
 DeleteFile('C:\Users\Phantomlvl\documents\documents.exe', '32');
 DeleteFileMask('c:\program files (x86)\zaxar', '*', true);
 DeleteFileMask('c:\program files (x86)\youtube adblock', '*', true);
 DeleteDirectory('c:\program files (x86)\zaxar');
 DeleteDirectory('c:\program files (x86)\youtube adblock');
 RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Bron-Spizaetus');
 RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','Tok-Cirrhatus');
 RegKeyParamDel('HKEY_USERS','.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run','Tok-Cirrhatus');
 RegKeyParamDel('HKEY_USERS','S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run','Tok-Cirrhatus');
ExecuteSysClean;
 ExecuteRepair(8);
 ExecuteRepair(13);
 ExecuteRepair(16);
 ExecuteRepair(17);
 ExecuteWizard('SCU', 2, 3, true);
 CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.

Êîìïüþòåð ïåðåçàãðóçèòñÿ. Ïîñëå ïåðåçàãðóçêè, âûïîëíèòå òàêîé ñêðèïò:

Êîä:

begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.

Ôàéë quarantine.zip èç ïàïêè ñ ðàñïàêîâàííîé óòèëèòîé AVZ îòïðàâüòå ñ ïîìîùüþ ýòîé ôîðìû èëè (åñëè ðàçìåð àðõèâà ïðåâûøàåò 8 MB) íà ýòîò ïî÷òîâûé ÿùèê: quarantine <at> safezone.cc (çàìåíèòå <at> íà @) ñ óêàçàíèåì ññûëêè íà òåìó â òåìå (çàãîëîâêå) ñîîáùåíèÿ è ñ óêàçàíèåì ïàðîëÿ: virus â òåëå ïèñüìà.

Óäàëèòå ïàðàìåòðû çàïóñêà ÿðëûêîâ.

Ïîäãîòîâüòå íîâûé CollectionLog.

ï.ñ.
Âåðîÿòíåå âñåãî âû çàðàçèëèñü ÷åðåç ýë. ïî÷òó.


Âðåìÿ: 22:31.

Âðåìÿ: 22:31.
© OSzone.net 2001-