-
Âëîæåíèé: 3
ßðëûêè íà ôëåøêå
Ïîéìàëè âèðóñ, ïðè ïîäêëþ÷åíèè ôëåøêè ñîçäàþòñÿ ÿðëûêè íà ôëåøêå ñ èìåíàìè ïàïîê, à ïàïêè ïðîïàäàþò. Ñíà÷àëà äóìàëè äåëàåò ñêðûòûìè ýòè ïàïêè, ïîñòàâèëè ãàëî÷êó ïîêàçûâàòü ñêðûòûå, íî ïàïêè íå ïîÿâèëèñü, ïðè ïîïûòêè çàïèñàòü ïàïêó íà ôëåøêó - ïèøåò ÷òî òàêàÿ ïàïêó ñóùåñòâóåò, çàìåíèòü ? è òàê ñ êàæäîé ôëåøêîé, ïîìîãèòå! âåáîì è àâç ñêàíèðîâàëè, íî ïðîáëåìà îñòàëàñü, ëîãè êðåïèì.
-
Óâàæàåìûé(àÿ) [B]Àëåêñåé Âåëèêîðîäîâ[/B], ñïàñèáî çà îáðàùåíèå íà íàø ôîðóì!
Ïîìîùü ïðè çàðàæåíèè êîìüþòåðà íà VirusInfo.Info îêàçûâàåòñÿ àáñîëþòíî áåñïëàòíî. Õåëïåðû, â ñàìîå áëèæàéøåå âðåìÿ, îòâåòÿò íà Âàø çàïðîñ. Äëÿ îêàçàíèÿ ïîìîùè íåîáõîäèìî ïðåäîñòàâèòü ëîãè ñêàíèðîâàíèÿ óòèëèòàìè ÀÂÇ è HiJackThis, ïîäðîáíåå ìîæíî ïðî÷èòàòü â [URL="http://virusinfo.info/pravila.html"]ïðàâèëàõ îôîðìëåíèÿ çàïðîñà î ïîìîùè[/URL].
[INFORMATION]Åñëè âû õîòèòå ïîëó÷èòü ïåðñîíàëüíóþ ãàðàíòèðîâàííóþ ïîìîùü â ïðèîðèòåòíîì ðåæèìå, òî âîñïîëüçóéòåñü ïëàòíûì ñåðâèñîì [URL="http://virusinfo.info/content.php?r=613-sub_pomogite"]Ïîìîãèòå+[/URL].[/INFORMATION]
Åñëè íàø ñàéò îêàæåòñÿ ïîëåçåí Âàì è ó Âàñ áóäåò òàêàÿ âîçìîæíîñòü - ïîæàëóéñòà [URL="http://virusinfo.info/content.php?r=113-virusinfo.info-donate"]ïîääåðæèòå ïðîåêò[/URL].
-
ïîñòàâèë ïîêàçûâàòü ñêðûòûå ñèñòåìíûå ïàïêè è ôàéëû íà ôëåøêå ïîÿâèëèñü ñ àòðèáóòîì ñêðûòûé è àòðèáóò íåàêòèâíûé, íåëüçÿ ñíÿòü ãàëî÷êó "ñêðûòûé", êàê áûòü?
-
[B]Îáíîâèòå áàçû AVZ[/B] ("Ôàéë" -> "Îáíîâëåíèå áàç").
[url="http://virusinfo.info/showthread.php?t=7239"]Âûïîëíèòå ñêðèïò â AVZ[/url]:[code]begin
ExecuteAVUpdate;
SearchRootkit(true, true);
SetAVZGuardStatus(True);
TerminateProcessByName('c:\documents and settings\user\local settings\application data\mail.ru\mailruupdater.exe');
TerminateProcessByName('c:\program files\mail.ru\mailruupdater\mailruupdater.exe');
TerminateProcessByName('c:\program files\mail.ru\update service\mrupdsrv.exe');
StopService('mrupdsrv');
StopService('Updater.Mail.Ru');
QuarantineFileF('c:\documents and settings\all users\application data\microsoft\adobe\flash player\d5b3886d-57e3-4939-814e-b0d2e6e8abd9', '*', true, '', 0 , 0);
QuarantineFileF('c:\documents and settings\user\local settings\application data\microsoft\extensions', '*', true, '', 0 , 0);
QuarantineFile('c:\documents and settings\user\local settings\application data\mail.ru\mailruupdater.exe', '');
QuarantineFile('c:\program files\mail.ru\mailruupdater\mailruupdater.exe', '');
QuarantineFile('c:\program files\mail.ru\update service\mrupdsrv.exe', '');
QuarantineFile('C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Extensions\extsetup.exe', '');
QuarantineFile('C:\Program Files\Common Files\6213CC31-7C44-4068-952A-ED4CF6050DD5\EFDCFC7B-9BF1-4615-9F8C-18F854591F57.exe', '');
QuarantineFile('C:\Documents and Settings\All Users\Application Data\Microsoft\Adobe\Flash Player\D5B3886D-57E3-4939-814E-B0D2E6E8ABD9\163A9920-BDAB-430E-A7B4-AB3C6C3753BC.exe', '');
DeleteFile('c:\documents and settings\user\local settings\application data\mail.ru\mailruupdater.exe', '32');
DeleteFile('c:\program files\mail.ru\mailruupdater\mailruupdater.exe', '32');
DeleteFile('c:\program files\mail.ru\update service\mrupdsrv.exe', '32');
DeleteFile('C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Extensions\extsetup.exe', '32');
DeleteFile('C:\Program Files\Common Files\6213CC31-7C44-4068-952A-ED4CF6050DD5\EFDCFC7B-9BF1-4615-9F8C-18F854591F57.exe', '32');
DeleteFile('C:\Documents and Settings\All Users\Application Data\Microsoft\Adobe\Flash Player\D5B3886D-57E3-4939-814E-B0D2E6E8ABD9\163A9920-BDAB-430E-A7B4-AB3C6C3753BC.exe', '32');
DeleteService('mrupdsrv');
DeleteService('Updater.Mail.Ru');
DeleteFileMask('c:\documents and settings\user\local settings\application data\mail.ru', '*', true);
DeleteFileMask('c:\program files\mail.ru', '*', true);
DeleteFileMask('c:\documents and settings\user\local settings\application data\microsoft\extensions', '*', true);
DeleteFileMask('c:\program files\common files\6213cc31-7c44-4068-952a-ed4cf6050dd5', '*', true);
DeleteFileMask('C:\Documents and Settings\All Users\Application Data\Microsoft\Adobe', '*', true);
DeleteDirectory('c:\documents and settings\user\local settings\application data\mail.ru');
DeleteDirectory('c:\program files\mail.ru');
DeleteDirectory('c:\program files\common files\6213cc31-7c44-4068-952a-ed4cf6050dd5');
DeleteDirectory('C:\Documents and Settings\All Users\Application Data\Microsoft\Adobe');
ExecuteFile('schtasks.exe', '/delete /TN "C:\WINDOWS\Tasks\MailRuUpdater.job" /F', 0, 15000, true);
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'MailRuUpdater');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'D5B3886D-57E3-4939-814E-B0D2E6E8ABD9');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'SafeBrowser');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run', 'AppDownloads');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
BC_Activate;
RebootWindows(true);
end.[/code]Êîìïüþòåð ïåðåçàãðóçèòñÿ.
Âûïîëíèòå â AVZ ñêðèïò:
[CODE]begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.[/CODE]
 ïàïêå ñ AVZ ïîÿâèòñÿ àðõèâ êàðàíòèíà quarantine.zip, îòïðàâüòå ýòîò ôàéë ïî ññûëêå "Ïðèñëàòü çàïðîøåííûé êàðàíòèí" íàä íàä ïåðâûì ñîîáùåíèåì â òåìå.
Âûïîëíèòå 2-é ñòàíäàðòíûé ñêðèïò â AVZ è ïðèêðåïèòå ê ñâîåìó ñëåäóþùåìó ñîîáùåíèþ ôàéë virusinfo_syscheck.zip.
Ñäåëàéòå ëîã [url=http://virusinfo.info/showthread.php?t=53070&p=1104657&viewfull=1#post1104657]ñêàíèðîâàíèÿ ÌÂÀÌ[/url] ñ ïîäêëþ÷¸ííîé ôëýøêîé.
-
Âëîæåíèé: 2
-
[url=http://virusinfo.info/showthread.php?t=53070&p=493584&viewfull=1#post493584]Óäàëèòå â MBAM[/url] âñ¸ íàéäåííîå.
Ñîîáùèòå, ÷òî ñ ïðîáëåìîé.
-
íà êîìïüþòåðå è ôëåøêå îñòàëèñü ïàïêè ñ ãàëî÷êîé "ñêðûòûé", ñíÿòü ãàëî÷êó íåëüçÿ, ò.ê àòðèáóò íå àêòèâíûé
-
Ñêîïèðóéòå ñëåäóþùèé òåêñò â Áëîêíîò è ñîõðàíèòå, êàê [B]run.bat[/B]:
[CODE]attrib "*" -s -h /S /D[/CODE]
ñêîïèðóéòå ôàéë run.bat â êîðåíü ôëåøêè è çàïóñòèòå
[B]Âíèìàíèå [U]íå çàïóñêàéòå ýòîò ôàéë[/U], êîãäà îí íàõîäèòñÿ íà æåñòêîì äèñêå.[/B]
-
Ïðè÷¸ì, çàïóñòèòå ÷åðåç ïðàâóþ êíîïêó ìûøè [B]Çàïóñê îò èìåíè àäìèíèñòðàòîðà[/B].
À êàêèå èìåííî ïàïêè ñ àòðèáóòîì "Ñêðûòûé"?
-
Èòîã ëå÷åíèÿ
Ñòàòèñòèêà ïðîâåäåííîãî ëå÷åíèÿ:
[LIST][*]Ïîëó÷åíî êàðàíòèíîâ: [B]1[/B][*]Îáðàáîòàíî ôàéëîâ: [B]19[/B][*] õîäå ëå÷åíèÿ âðåäîíîñíûå ïðîãðàììû â êàðàíòèíàõ íå îáíàðóæåíû[/LIST]
Page generated in 0.00903 seconds with 10 queries