Показано с 1 по 5 из 5.

Самоустанавливаются программы GameDesctop /AnyProtect (заявка № 189006)

  1. #1
    Junior Member Репутация
    Регистрация
    25.08.2015
    Сообщений
    2
    Вес репутации
    32

    Самоустанавливаются программы GameDesctop /AnyProtect

    Добрый день! моя проблема в том что программы самоустанавливаются и в браузере меняется система поиска по умолчанию. и открываются сайты с рекламой.
    При выполннении скрипта №3 комп повисает и выдает ошибку ,остальное прилагаю во вложениях. Спасибо.
    Вложения Вложения

  2. Будь в курсе!
    Реклама на VirusInfo

    Надоело быть жертвой? Стань профи по информационной безопасности, получай самую свежую информацию об угрозах и средствах защиты от ведущего российского аналитического центра Anti-Malware.ru:

    Anti-Malware Telegram
     

  3. #2
    Cyber Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Info_bot
    Регистрация
    11.05.2011
    Сообщений
    2,287
    Вес репутации
    378
    Уважаемый(ая) NuraProg, спасибо за обращение на наш форум!

    Помощь при заражении комьютера на VirusInfo.Info оказывается абсолютно бесплатно. Хелперы, в самое ближайшее время, ответят на Ваш запрос. Для оказания помощи необходимо предоставить логи сканирования утилитами АВЗ и HiJackThis, подробнее можно прочитать в правилах оформления запроса о помощи.

    Если наш сайт окажется полезен Вам и у Вас будет такая возможность - пожалуйста поддержите проект.

  4. #3
    Moderator Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для mrak74
    Регистрация
    03.10.2009
    Адрес
    Москва
    Сообщений
    9,009
    Вес репутации
    489
    Здравствуйте !!!

    Выполните скрипт в AVZ:
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
      TerminateProcessByName('c:\users\user\appdata\local\служба.exe');
      TerminateProcessByName('c:\users\user\appdata\local\gmsd_ru_005010046\upgmsd_ru_005010046.exe');
      TerminateProcessByName('c:\program files\schk32\schk32.exe');
      TerminateProcessByName('c:\programdata\saophase\saophase.exe');
      TerminateProcessByName('c:\program files\rising\rsd\rsmgrsvc.exe');
      TerminateProcessByName('c:\programdata\5winmanpro5\protectwindowsmanager.exe');
      TerminateProcessByName('c:\program files\miuitab\protectservice.exe');
      TerminateProcessByName('c:\users\user\appdata\local\pricefountain\pricefountainw.exe');
      TerminateProcessByName('c:\users\user\appdata\local\pricefountain\pricefountain.exe');
      TerminateProcessByName('c:\program files\baidu\pps.exe');
      TerminateProcessByName('c:\program files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\nixhost.exe');
      TerminateProcessByName('c:\program files\media player z\wfp\media player zfilterusageexample.exe');
      TerminateProcessByName('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\knsu47a9.tmp');
      TerminateProcessByName('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\jnsu56f.tmp');
      TerminateProcessByName('c:\program files\miuitab\hpnotify.exe');
      TerminateProcessByName('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\hnsj1dfa.tmp');
      TerminateProcessByName('c:\program files\gmsd_ru_005010046\gmsd_ru_005010046.exe');
      StopService('QMIEProtect');
      StopService('{92bcf460-f3fc-4c73-8f63-31a272ed861d}Gw');
      StopService('wsafd_1_10_0_19');
      StopService('TSKSP');
      StopService('TSDefenseBt');
      StopService('TSCPM');
      StopService('TFsFlt');
      StopService('TAOKernelDriver');
      StopService('rsdsys');
      StopService('QQSysMon');
      StopService('ppfd_vw_1_10_0_21');
      StopService('netmon_wfp');
      StopService('UpdatingServiceMed');
      StopService('sogrMed');
      StopService('QQPCRTP');
      StopService('ExtTag');
      StopService('schk32');
      StopService('Saophase');
      StopService('RsMgrSvc');
      StopService('IHProtect Service');
      StopService('hyverumu');
      StopService('DMG30');
      StopService('comyninu');
      QuarantineFile('C:\Users\user\appdata\local\smartweb\__u.exe','');
      QuarantineFile('C:\Users\user\AppData\Local\диспетчер.exe','');
      QuarantineFile('C:\Users\user\AppData\Roaming\istartsurf\UninstallManager.exe','');
      QuarantineFile('C:\Users\user\AppData\Roaming\mystartsearch\UninstallManager.exe','');
      QuarantineFile('C:\Users\user\AppData\Local\SmartWeb\SmartWebHelper.exe','');
      QuarantineFile('C:\PROGRAM FILES\RISING\RAV\rsdelaylauncher.exe','');
     QuarantineFile('C:\Program Files\PC Speed Up\PCSUSD.exe','');
      QuarantineFile('C:\Program Files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\fchk.exe','');
      QuarantineFile('C:\Program Files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\temp\run.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-6.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-5.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-3.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-10.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-1-7.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-1-6.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-7.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-6.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-5.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-3.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-10.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-1-7.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-1-6.exe','');
      QuarantineFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe','');
      QuarantineFile('C:\Users\user\AppData\Local\14968\Updater.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-7.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-6.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-5.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-3.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-10.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-1-7.exe','');
      QuarantineFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-1-6.exe','');
     QuarantineFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-6.exe','');
     QuarantineFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-5.exe','');
     QuarantineFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-3.exe','');
     QuarantineFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-10.exe','');
     QuarantineFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-1-7.exe','');
     QuarantineFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-1-6.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-7.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-6.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-5.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-3.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-14.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-13.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-10.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-1-7.exe','');
     QuarantineFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-1-6.exe','');
      QuarantineFile('C:\ProgramData\EroBisis\onudci.exe','');
      QuarantineFile('C:\ProgramData\EroBisis\onu6ci.exe','');
      QuarantineFile('C:\ProgramData\EroBisis\onuaci.exe','');
      QuarantineFile('C:\ProgramData\EroBisis\onu3ci.exe','');
      QuarantineFile('C:\Users\user\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE','');
      QuarantineFile('C:\Users\user\AppData\Roaming\OJNaEuNt1AalTt.exe','');
      QuarantineFile('C:\Users\user\AppData\Roaming\n7UwlJpt85H5xdKzqLOT.exe','');
      QuarantineFile('C:\Users\user\AppData\Roaming\cWI0Jc2xQOelIW83lsG5cxn.exe','');
      QuarantineFile('C:\Program Files\AnyProtectEx\AnyProtect.exe','');
      QuarantineFile('C:\Users\user\AppData\Local\PriceFountain\PriceFountainIE.dll','');
      QuarantineFile('C:\Users\user\AppData\Roaming\ASPackage\ASPackage.exe','');
      QuarantineFile('C:\ProgramData\Saophase\RankLatlam.dll','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQPCTRAY.EXE','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMContextUninstall.dll','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMContextScan.dll','');
     QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer.lnk','');
     QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnеt Ехplоrеr Вrоwsеr.lnk','');
      QuarantineFile('C:\Program Files\Internet Explorer\iexplore.bat','');
     QuarantineFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk','');
      QuarantineFile('C:\Program Files\Google\Chrome\Application\chrome.bat','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMIEProtect.sys','');
      QuarantineFile('C:\WINDOWS\system32\drivers\{92bcf460-f3fc-4c73-8f63-31a272ed861d}Gw.sys','');
      QuarantineFile('C:\WINDOWS\system32\drivers\wsafd_1_10_0_19.sys','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\TSKsp.sys','');
      QuarantineFile('C:\WINDOWS\system32\DRIVERS\TSDefenseBt.sys','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\tscpm.sys','');
      QuarantineFile('C:\WINDOWS\system32\Drivers\TFsFlt.sys','');
      QuarantineFile('C:\WINDOWS\system32\drivers\TAOKernel.sys','');
      QuarantineFile('C:\WINDOWS\system32\drivers\protreg.sys','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQSysMon.sys','');
      QuarantineFile('C:\WINDOWS\system32\drivers\ppfd_vw_1_10_0_21.sys','');
      QuarantineFile('C:\WINDOWS\system32\drivers\netmon_wfp.sys','');
      QuarantineFile('C:\WINDOWS\Microsoft\UpdatingServiceMed\Media Player ZNewVersionDownloader.exe','');
      QuarantineFile('C:\WINDOWS\Microsoft\sogrMed\Media Player ZUpdater.exe','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQPCRTP.exe','');
      QuarantineFile('C:\ProgramData\ExtTag\ExtTag','');
      QuarantineFile('C:\Users\user\AppData\Local\PriceFountain\prfo.dll','');
      QuarantineFile('C:\ProgramData\Saophase\Keyis.dll','');
      QuarantineFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMGCShellExt.dll','');
      QuarantineFile('C:\Program Files\Rising\RSD\rsmginfo.dll','');
      QuarantineFile('C:\Program Files\MiuiTab\SupTab.dll','');
      QuarantineFile('C:\Program Files\MiuiTab\IeWatchDog.dll','');
      QuarantineFile('C:\Program Files\MiuiTab\BrowserAction.dll','');
      QuarantineFile('C:\Program Files\MiuiTab\BrowerWatchCH.dll','');
      QuarantineFile('C:\Program Files\Media Player Z\WFP\http_filter.dll','');
      QuarantineFile('c:\users\user\appdata\local\служба.exe','');
      QuarantineFile('c:\users\user\appdata\local\gmsd_ru_005010046\upgmsd_ru_005010046.exe','');
      QuarantineFile('c:\program files\schk32\schk32.exe','');
      QuarantineFile('c:\programdata\saophase\saophase.exe','');
      QuarantineFile('c:\program files\rising\rsd\rsmgrsvc.exe','');
      QuarantineFile('c:\programdata\5winmanpro5\protectwindowsmanager.exe','');
      QuarantineFile('c:\program files\miuitab\protectservice.exe','');
      QuarantineFile('c:\users\user\appdata\local\pricefountain\pricefountainw.exe','');
      QuarantineFile('c:\users\user\appdata\local\pricefountain\pricefountain.exe','');
      QuarantineFile('c:\program files\baidu\pps.exe','');
      QuarantineFile('c:\program files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\nixhost.exe','');
      QuarantineFile('c:\program files\media player z\wfp\media player zfilterusageexample.exe','');
      QuarantineFile('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\knsu47a9.tmp','');
      QuarantineFile('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\jnsu56f.tmp','');
      QuarantineFile('c:\program files\miuitab\hpnotify.exe','');
      QuarantineFile('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\hnsj1dfa.tmp','');
      QuarantineFile('c:\program files\gmsd_ru_005010046\gmsd_ru_005010046.exe','');
     DeleteFile('C:\Program Files\PC Speed Up\PCSUSD.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-7.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-6.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-5.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-3.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-10.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-1-7.exe');
     DeleteFile('C:\Program Files\Shop and Save Up\542b8970-7fa1-4a29-8c06-2b5ba711272f-1-6.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-7.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-6.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-5.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-3.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-14.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-13.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-10.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-1-7.exe');
     DeleteFile('C:\Program Files\SavePass 1.1\2baf08be-a43a-44ab-950f-a58cdf6142a1-1-6.exe');
     DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer.lnk');
     DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Intеrnеt Ехplоrеr Вrоwsеr.lnk');
     DeleteFile('C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооglе Сhrоmе.lnk');
      DeleteFile('c:\program files\miuitab\hpnotify.exe','32');
      DeleteFile('c:\program files\82a4d680-1437621130-11d5-8809-90e6bae04574\knsu47a9.tmp','32');
      DeleteFile('c:\program files\media player z\wfp\media player zfilterusageexample.exe','32');
      DeleteFile('c:\programdata\5winmanpro5\protectwindowsmanager.exe','32');
      DeleteFile('C:\ProgramData\Saophase\Saophase.exe','32');
      DeleteFile('C:\Program Files\Media Player Z\WFP\http_filter.dll','32');
      DeleteFile('C:\Program Files\MiuiTab\BrowerWatchCH.dll','32');
      DeleteFile('C:\Program Files\MiuiTab\BrowserAction.dll','32');
      DeleteFile('C:\Program Files\MiuiTab\IeWatchDog.dll','32');
      DeleteFile('C:\Program Files\MiuiTab\SupTab.dll','32');
      DeleteFile('C:\Program Files\Rising\RSD\rsmginfo.dll','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMGCShellExt.dll','32');
      DeleteFile('C:\ProgramData\Saophase\Keyis.dll','32');
      DeleteFile('C:\Users\user\AppData\Local\PriceFountain\prfo.dll','32');
      DeleteFile('C:\Program Files\82A4D680-1437621130-11D5-8809-90E6BAE04574\hnsj1DFA.tmp','32');
      DeleteFile('C:\Users\user\AppData\Local\служба.exe','32');
      DeleteFile('C:\Program Files\82A4D680-1437621130-11D5-8809-90E6BAE04574\jnsu56F.tmp','32');
      DeleteFile('C:\Program Files\MiuiTab\ProtectService.exe','32');
      DeleteFile('C:\Program Files\Rising\RSD\RsMgrSvc.exe','32');
      DeleteFile('C:\Program Files\schk32\schk32.exe','32');
      DeleteFile('C:\ProgramData\ExtTag\ExtTag','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQPCRTP.exe','32');
      DeleteFile('C:\WINDOWS\system32\drivers\ppfd_vw_1_10_0_21.sys','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQSysMon.sys','32');
      DeleteFile('C:\WINDOWS\system32\drivers\protreg.sys','32');
      DeleteFile('C:\WINDOWS\system32\drivers\TAOKernel.sys','32');
      DeleteFile('C:\WINDOWS\system32\Drivers\TFsFlt.sys','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\tscpm.sys','32');
      DeleteFile('C:\WINDOWS\system32\DRIVERS\TSDefenseBt.sys','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\TSKsp.sys','32');
      DeleteFile('C:\WINDOWS\system32\drivers\wsafd_1_10_0_19.sys','32');
      DeleteFile('C:\WINDOWS\system32\drivers\{92bcf460-f3fc-4c73-8f63-31a272ed861d}Gw.sys','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMIEProtect.sys','32');
      DeleteFile('C:\Program Files\Google\Chrome\Application\chrome.bat','32');
      DeleteFile('C:\Program Files\Internet Explorer\iexplore.bat','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMContextScan.dll','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QMContextUninstall.dll','32');
      DeleteFile('C:\Program Files\Tencent\QQPCMgr\10.7.16066.216\QQPCTRAY.EXE','32');
      DeleteFile('C:\Program Files\baidu\pps.exe','32');
      DeleteFile('C:\Program Files\gmsd_ru_005010046\gmsd_ru_005010046.exe','32');
      DeleteFile('C:\Users\user\AppData\Local\gmsd_ru_005010046\upgmsd_ru_005010046.exe','32');
      DeleteFile('C:\Users\user\AppData\Roaming\ASPackage\ASPackage.exe','32');
      DeleteFile('C:\Users\user\AppData\Local\PriceFountain\PriceFountainIE.dll','32');
      DeleteFile('C:\Program Files\AnyProtectEx\AnyProtect.exe','32');
      DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP1.job','32');
      DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP2.job','32');
      DeleteFile('C:\WINDOWS\Tasks\APSnotifierPP3.job','32');
      DeleteFile('C:\Users\user\AppData\Roaming\cWI0Jc2xQOelIW83lsG5cxn.exe','32');
      DeleteFile('C:\WINDOWS\Tasks\cWI0Jc2xQOelIW83lsG5cxn.job','32');
      DeleteFile('C:\Users\user\AppData\Roaming\n7UwlJpt85H5xdKzqLOT.exe','32');
      DeleteFile('C:\WINDOWS\Tasks\n7UwlJpt85H5xdKzqLOT.job','32');
      DeleteFile('C:\Users\user\AppData\Roaming\OJNaEuNt1AalTt.exe','32');
      DeleteFile('C:\WINDOWS\Tasks\OJNaEuNt1AalTt.job','32');
      DeleteFile('C:\Users\user\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE','32');
      DeleteFile('C:\WINDOWS\Tasks\Price Fountain.job','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-1-7','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-13','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-14','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-3','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-5','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-5_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\2baf08be-a43a-44ab-950f-a58cdf6142a1-7','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-1-7','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-3','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-5','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-5_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\542b8970-7fa1-4a29-8c06-2b5ba711272f-7','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-1-6.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-1-6','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-1-7.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-1-7','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-10.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-10_user','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-3.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-3','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-5.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-5','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-5_user','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-6.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-6','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV30.07\ae60b39b-ed0e-4287-9f18-d483c42d2363-7.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\ae60b39b-ed0e-4287-9f18-d483c42d2363-7','32');
      DeleteFile('C:\Users\user\AppData\Local\14968\Updater.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\AmiUpdXp','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\APSnotifierPP1','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\APSnotifierPP2','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\APSnotifierPP3','32');
      DeleteFile('C:\Program Files\Crossbrowse\Crossbrowse\Application\utility.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\Crossbrowse','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\cWI0Jc2xQOelIW83lsG5cxn','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-1-6.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-1-6','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-1-7.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-1-7','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-10.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-10_user','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-3.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-3','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-5.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-5','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-5_user','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-6.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-6','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV23.08\d43324e1-721a-4b0a-a538-14c83ee019d4-7.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\d43324e1-721a-4b0a-a538-14c83ee019d4-7','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-1-6.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-1-6','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-1-7.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-1-7','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-10.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-10_user','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-3.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-3','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-5.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-5','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-5_user','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-6.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-6','32');
      DeleteFile('C:\Program Files\CiPlus-4.5vV22.07\e35ad005-b129-4e68-9b0f-b87c301fd106-7.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\e35ad005-b129-4e68-9b0f-b87c301fd106-7','32');
      DeleteFile('C:\Program Files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\temp\run.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\Install','32');
      DeleteFile('C:\Program Files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\NixHost.exe','32');
      DeleteFile('C:\Program Files\schk32\packages\a2572d87-1bbd-44d0-88df-72ebc0c59bd2\fchk.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\Install Java','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\n7UwlJpt85H5xdKzqLOT','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\OJNaEuNt1AalTt','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\PC SpeedUp Service Deactivator','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\Price Fountain','32');
      DeleteFile('C:\PROGRAM FILES\RISING\RAV\rsdelaylauncher.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\RsDelayLauncher_{8A34248E-7D35-4832-8378-7659E0B0A380}','32');
      DeleteFile('C:\Users\user\AppData\Local\SmartWeb\SmartWebHelper.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\SmartWeb Upgrade Trigger Task','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-14','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_542b8970-7fa1-4a29-8c06-2b5ba711272f-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_542b8970-7fa1-4a29-8c06-2b5ba711272f-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_542b8970-7fa1-4a29-8c06-2b5ba711272f-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_ae60b39b-ed0e-4287-9f18-d483c42d2363-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_ae60b39b-ed0e-4287-9f18-d483c42d2363-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_ae60b39b-ed0e-4287-9f18-d483c42d2363-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_d43324e1-721a-4b0a-a538-14c83ee019d4-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_d43324e1-721a-4b0a-a538-14c83ee019d4-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_d43324e1-721a-4b0a-a538-14c83ee019d4-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_e35ad005-b129-4e68-9b0f-b87c301fd106-1-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_e35ad005-b129-4e68-9b0f-b87c301fd106-10_user','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\temp_e35ad005-b129-4e68-9b0f-b87c301fd106-6','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\{04582253-550E-44FC-ACA5-12942A8DEDED}','32');
      DeleteFile('C:\Users\user\AppData\Roaming\istartsurf\UninstallManager.exe','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\{1EFEDD41-AE08-4C15-B6F3-A63A0D60CA2B}','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\{AAC1C7D6-97AD-41C1-A276-977F0E032959}','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\{C85F25C5-3275-438F-B636-12088A895030}','32');
      DeleteFile('C:\WINDOWS\system32\Tasks\Диспетчер подключений Windows 1.0.3','32');
      DeleteFile('C:\Users\user\AppData\Local\диспетчер.exe','32');
      DeleteFile('C:\WINDOWS\microsoft\sogrmed\media player zupdater.exe','32');
      DeleteFile('C:\WINDOWS\microsoft\updatingservicemed\media player znewversiondownloader.exe','32');
      DeleteFile('C:\WINDOWS\system32\Drivers\netmon_wfp.sys','32');
      DeleteFile('C:\Users\user\appdata\local\pricefountain\pricefountain.exe','32');
      DeleteFile('C:\Users\user\appdata\local\pricefountain\pricefountainw.exe','32');
      DeleteFile('C:\Users\user\appdata\local\smartweb\__u.exe','32');
      DeleteFile('C:\Users\user\appdata\roaming\mystartsearch\uninstallmanager.exe','32');
      DelBHO('{b608cc98-54de-4775-96c9-097de398500c}');
      DelBHO('{1F91A9A1-01BA-4c81-863D-3BA0751E1419}');
      DelCLSID('{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
      DelCLSID('{63332668-8CE1-445D-A5EE-25929176714E}');
      RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{63332668-8CE1-445D-A5EE-25929176714E}');
      RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved','{CBDECEF7-7A29-4cbf-A009-2673D82C7BF9}');
      RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','QQPCTray');
      RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','apphide');
      RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','gmsd_ru_005010046');
      RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','pricefountainw.exe');
      RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','upgmsd_ru_005010046.exe');
      RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\RunOnce','Update');
     RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
     RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
     RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
     RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
     RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
      DeleteService('QMIEProtect');
      DeleteService('{92bcf460-f3fc-4c73-8f63-31a272ed861d}Gw');
      DeleteService('wsafd_1_10_0_19');
      DeleteService('TSKSP');
      DeleteService('TSDefenseBt');
      DeleteService('TSCPM');
      DeleteService('TFsFlt');
      DeleteService('TAOKernelDriver');
      DeleteService('rsdsys');
      DeleteService('QQSysMon');
      DeleteService('ppfd_vw_1_10_0_21');
      DeleteService('netmon_wfp');
      DeleteService('UpdatingServiceMed');
      DeleteService('sogrMed');
      DeleteService('QQPCRTP');
      DeleteService('ExtTag');
      DeleteService('schk32');
      DeleteService('Saophase');
      DeleteService('RsMgrSvc');
      DeleteService('IHProtect Service');
      DeleteService('hyverumu');
      DeleteService('DMG30');
      DeleteService('comyninu');
    BC_ImportAll;
    ExecuteSysClean;
    BC_Activate;
     ExecuteRepair(3);
     ExecuteRepair(4);
     ExecuteWizard('SCU',2,2,true);
    RebootWindows(true);
    end.
    После перезагрузки выполните скрипт:
    Код:
    begin 
    CreateQurantineArchive(GetAVZDirectory+'quarantine.zip'); 
    end.
    Загрузите quarantine.zip из папки AVZ по красной ссылке вверху темы Прислать запрошенный карантин
    - Сделайте повторные логи по правилам п.2 и 3 раздела Диагностика.(virusinfo_syscheck.zip;hijackthis.log )
    Virusinfo - за чистый Интернет.
    Делай добро и бросай его в воду.

  5. #4
    Junior Member Репутация
    Регистрация
    25.08.2015
    Сообщений
    2
    Вес репутации
    32
    Не могу выполнить даже первый скрипт. Программа вылетает при запуске скрипта.

  6. #5
    Moderator Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для mrak74
    Регистрация
    03.10.2009
    Адрес
    Москва
    Сообщений
    9,009
    Вес репутации
    489
    Выполните скрипт в Безопасном режиме, загрузившись через F8.

    +
    • Скачайте AdwCleaner (by Xplode) и сохраните его на Рабочем столе.
    • Запустите его (в ОС Windows Vista/Seven необходимо запускать через правую кн. мыши от имени администратора), нажмите кнопку "Scan" и дождитесь окончания сканирования.
    • Когда сканирование будет завершено, отчет будет сохранен в следующем расположении: C:\AdwCleaner\AdwCleaner[R0].txt.
    • Прикрепите отчет к своему следующему сообщению.


    Сделайте дополнительный лог AdwCleaner[R0].txt.
    Virusinfo - за чистый Интернет.
    Делай добро и бросай его в воду.

Похожие темы

  1. Самоустанавливаются программы Opera Smart web
    От Lenarayan в разделе Помогите!
    Ответов: 4
    Последнее сообщение: 19.08.2015, 01:38
  2. Ответов: 3
    Последнее сообщение: 08.07.2015, 00:00
  3. Ответов: 10
    Последнее сообщение: 22.06.2015, 18:33
  4. Ответов: 11
    Последнее сообщение: 05.06.2015, 19:19

Свернуть/Развернуть Ваши права в разделе

  • Вы не можете создавать новые темы
  • Вы не можете отвечать в темах
  • Вы не можете прикреплять вложения
  • Вы не можете редактировать свои сообщения
  •  
Page generated in 0.00143 seconds with 20 queries