Здравствуйте!
Через Панель управления - Удаление программ - удалите нежелательное ПО:
CurrencyConvertor
Unity Web Player
Video and Audio Plugin UBar
Zaxar Games Browser 4
Служба автоматического обновления программ
Закройте все программы, временно выгрузите антивирус, файрволл и прочее защитное ПО (http://safezone.cc/forum/showthread.php?t=18577).
Выполните скрипт в АВЗ (http://forum.oszone.net/post-1430637-4.html) (Файл - Выполнить скрипт):
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\program files (x86)\zaxar\zaxargamebrowser.exe');
TerminateProcessByName('c:\program files (x86)\zaxar\zaxarloader.exe');
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
TerminateProcessByName('C:\Windows\System32\Ea3Host.exe');
StopService('Ea3Host');
StopService('SvcHost Service Host');
QuarantineFile('C:\Program Files (x86)\Zaxar\bearer\qgenericbearer.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\bearer\qnativewifibearer.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\icudt58.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\icuin58.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\icuuc58.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qgif.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qicns.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qico.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qjpeg.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qsvg.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qtga.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qtiff.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qwbmp.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qwebp.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\libGLESv2.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\platforms\qwindows.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Core.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Gui.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Multimedia.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5MultimediaWidgets.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Network.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5OpenGL.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Positioning.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5PrintSupport.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Qml.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Quick.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Sensors.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Sql.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Svg.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5WebChannel.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5WebKit.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5WebKitWidgets.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Widgets.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Xml.dll', '');
QuarantineFile('C:\Program Files (x86)\Zaxar\sensors\qtsensors_generic.dll', '');
QuarantineFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe', '');
QuarantineFile('c:\program files (x86)\zaxar\zaxarloader.exe', '');
QuarantineFile('C:\Users\Andrei\AppData\Local\DuckGo\duckgo.exe', '');
QuarantineFile('C:\Users\Andrei\AppData\Local\wutphost\wutphost.exe', '');
QuarantineFile('C:\Users\Andrei\AppData\Roaming\curl\curl.exe', '');
QuarantineFile('C:\Users\Andrei\AppData\Roaming\curl\curl_7_54.exe', '');
QuarantineFile('c:\windows\microsoft\svchost.exe', '');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe', '');
QuarantineFile('C:\Windows\System32\Ea3Host.exe', '');
QuarantineFileF('c:\program files (x86)\zaxar', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\zaxar\bearer', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\zaxar\imageformats', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\zaxar\platforms', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\program files (x86)\zaxar\sensors', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
QuarantineFileF('c:\users\andrei\appdata\local\wutphost', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', false, '', 0 , 0);
DeleteFile('C:\Program Files (x86)\Zaxar\bearer\qgenericbearer.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\bearer\qnativewifibearer.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\icudt58.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\icuin58.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\icuuc58.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qgif.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qicns.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qico.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qjpeg.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qsvg.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qtga.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qtiff.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qwbmp.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qwebp.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\libGLESv2.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\platforms\qwindows.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Core.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Gui.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Multimedia.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5MultimediaWidgets.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Network.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5OpenGL.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Positioning.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5PrintSupport.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Qml.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Quick.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Sensors.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Sql.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Svg.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5WebChannel.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5WebKit.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5WebKitWidgets.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Widgets.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Xml.dll', '32');
DeleteFile('C:\Program Files (x86)\Zaxar\sensors\qtsensors_generic.dll', '32');
DeleteFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe', '32');
DeleteFile('c:\program files (x86)\zaxar\zaxarloader.exe', '32');
DeleteFile('C:\Users\Andrei\AppData\Local\DuckGo\duckgo.exe', '32');
DeleteFile('C:\Users\Andrei\AppData\Local\wutphost\wutphost.exe', '32');
DeleteFile('C:\Users\Andrei\AppData\Roaming\curl\curl.exe', '32');
DeleteFile('C:\Users\Andrei\AppData\Roaming\curl\curl_7_54.exe', '32');
DeleteFile('C:\Users\Andrei\Desktop\Поиcк в Интeрнете.lnk');
DeleteFile('c:\windows\microsoft\svchost.exe', '32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe', '32');
DeleteFile('C:\Windows\System32\Ea3Host.exe', '32');
ExecuteFile('schtasks.exe', '/delete /TN "curl" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "curls" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "CurrencyConvertor" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "CurrencyConvertor2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "DuckGo Task" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wutphost" /F', 0, 15000, true);
DeleteService('Ea3Host');
DeleteService('SvcHost Service Host');
DeleteFileMask('c:\program files (x86)\zaxar', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar\bearer', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar\imageformats', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar\platforms', '*', true);
DeleteFileMask('c:\program files (x86)\zaxar\sensors', '*', true);
DeleteFileMask('c:\users\andrei\appdata\local\wutphost', '*', false);
DeleteDirectory('c:\program files (x86)\zaxar');
DeleteDirectory('c:\program files (x86)\zaxar\bearer');
DeleteDirectory('c:\program files (x86)\zaxar\imageformats');
DeleteDirectory('c:\program files (x86)\zaxar\platforms');
DeleteDirectory('c:\program files (x86)\zaxar\sensors');
DeleteDirectory('c:\users\andrei\appdata\local\wutphost');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ctelruegfh');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'CurrencyConvertor');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ycAutoLaunch_1A04FCC48409310FF3A616F80D6C75DE');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.
Файл quarantine.zip из папки с распакованной утилитой AVZ отправьте с помощью этой формы (http://www.oszone.net/virusnet/) или (если размер архива превышает 8 MB) на этот почтовый ящик: quarantine <at> safezone.cc (замените <at> на @) с указанием ссылки на тему в теме (заголовке) сообщения и с указанием пароля: virus в теле письма.
Файл CheckBrowserLnk.log
из папки
...\AutoLogger\CheckBrowserLnk перетащите на утилиту ClearLNK (http://dragokas.com/tools/ClearLNK.zip).
http://dragokas.com/tools/move.gif
Отчёт о работе в виде файла ClearLNK-<Дата>.log прикрепите к вашему следующему сообщению.
Повторите логи по правилам (http://forum.oszone.net/thread-98169.html). Для повторной диагностики запустите снова Autologger.
vBulletin v3.6.4, Copyright ©2000-2025, Jelsoft Enterprises Ltd.