Имя пользователя:
Пароль:
 

Показать сообщение отдельно

Аватара для Sandor

Ветеран


Консультант


Сообщения: 5350
Благодарности: 1341

Профиль | Отправить PM | Цитировать


Здравствуйте!

Через Панель управления - Удаление программ - удалите нежелательное ПО:
Цитата:
CurrencyConvertor
Unity Web Player
Video and Audio Plugin UBar
Zaxar Games Browser 4
Служба автоматического обновления программ
Закройте все программы, временно выгрузите антивирус, файрволл и прочее защитное ПО.

Выполните скрипт в АВЗ (Файл - Выполнить скрипт):

Код: Выделить весь код
begin
 ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
 TerminateProcessByName('c:\program files (x86)\zaxar\zaxargamebrowser.exe');
 TerminateProcessByName('c:\program files (x86)\zaxar\zaxarloader.exe');
 TerminateProcessByName('c:\windows\microsoft\svchost.exe');
 TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
 TerminateProcessByName('C:\Windows\System32\Ea3Host.exe');
 StopService('Ea3Host');
 StopService('SvcHost Service Host');
 QuarantineFile('C:\Program Files (x86)\Zaxar\bearer\qgenericbearer.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\bearer\qnativewifibearer.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\icudt58.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\icuin58.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\icuuc58.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qgif.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qicns.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qico.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qjpeg.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qsvg.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qtga.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qtiff.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qwbmp.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\imageformats\qwebp.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\libGLESv2.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\platforms\qwindows.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Core.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Gui.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Multimedia.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5MultimediaWidgets.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Network.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5OpenGL.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Positioning.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5PrintSupport.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Qml.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Quick.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Sensors.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Sql.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Svg.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5WebChannel.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5WebKit.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5WebKitWidgets.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Widgets.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\Qt5Xml.dll', '');
 QuarantineFile('C:\Program Files (x86)\Zaxar\sensors\qtsensors_generic.dll', '');
 QuarantineFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe', '');
 QuarantineFile('c:\program files (x86)\zaxar\zaxarloader.exe', '');
 QuarantineFile('C:\Users\Andrei\AppData\Local\DuckGo\duckgo.exe', '');
 QuarantineFile('C:\Users\Andrei\AppData\Local\wutphost\wutphost.exe', '');
 QuarantineFile('C:\Users\Andrei\AppData\Roaming\curl\curl.exe', '');
 QuarantineFile('C:\Users\Andrei\AppData\Roaming\curl\curl_7_54.exe', '');
 QuarantineFile('c:\windows\microsoft\svchost.exe', '');
 QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe', '');
 QuarantineFile('C:\Windows\System32\Ea3Host.exe', '');
 QuarantineFileF('c:\program files (x86)\zaxar', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
 QuarantineFileF('c:\program files (x86)\zaxar\bearer', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
 QuarantineFileF('c:\program files (x86)\zaxar\imageformats', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
 QuarantineFileF('c:\program files (x86)\zaxar\platforms', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
 QuarantineFileF('c:\program files (x86)\zaxar\sensors', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', true, '', 0 , 0);
 QuarantineFileF('c:\users\andrei\appdata\local\wutphost', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.ps1, *.js*, *.tmp*', false, '', 0 , 0);
 DeleteFile('C:\Program Files (x86)\Zaxar\bearer\qgenericbearer.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\bearer\qnativewifibearer.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\icudt58.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\icuin58.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\icuuc58.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qgif.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qicns.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qico.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qjpeg.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qsvg.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qtga.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qtiff.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qwbmp.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\imageformats\qwebp.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\libGLESv2.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\platforms\qwindows.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Core.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Gui.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Multimedia.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5MultimediaWidgets.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Network.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5OpenGL.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Positioning.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5PrintSupport.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Qml.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Quick.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Sensors.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Sql.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Svg.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5WebChannel.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5WebKit.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5WebKitWidgets.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Widgets.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\Qt5Xml.dll', '32');
 DeleteFile('C:\Program Files (x86)\Zaxar\sensors\qtsensors_generic.dll', '32');
 DeleteFile('c:\program files (x86)\zaxar\zaxargamebrowser.exe', '32');
 DeleteFile('c:\program files (x86)\zaxar\zaxarloader.exe', '32');
 DeleteFile('C:\Users\Andrei\AppData\Local\DuckGo\duckgo.exe', '32');
 DeleteFile('C:\Users\Andrei\AppData\Local\wutphost\wutphost.exe', '32');
 DeleteFile('C:\Users\Andrei\AppData\Roaming\curl\curl.exe', '32');
 DeleteFile('C:\Users\Andrei\AppData\Roaming\curl\curl_7_54.exe', '32');
 DeleteFile('C:\Users\Andrei\Desktop\Поиcк в Интeрнете.lnk');
 DeleteFile('c:\windows\microsoft\svchost.exe', '32');
 DeleteFile('C:\Windows\Microsoft\svchost.exe.exe', '32');
 DeleteFile('C:\Windows\System32\Ea3Host.exe', '32');
 ExecuteFile('schtasks.exe', '/delete /TN "curl" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "curls" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "CurrencyConvertor" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "CurrencyConvertor2" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "DuckGo Task" /F', 0, 15000, true);
 ExecuteFile('schtasks.exe', '/delete /TN "wutphost" /F', 0, 15000, true);
 DeleteService('Ea3Host');
 DeleteService('SvcHost Service Host');
 DeleteFileMask('c:\program files (x86)\zaxar', '*', true);
 DeleteFileMask('c:\program files (x86)\zaxar\bearer', '*', true);
 DeleteFileMask('c:\program files (x86)\zaxar\imageformats', '*', true);
 DeleteFileMask('c:\program files (x86)\zaxar\platforms', '*', true);
 DeleteFileMask('c:\program files (x86)\zaxar\sensors', '*', true);
 DeleteFileMask('c:\users\andrei\appdata\local\wutphost', '*', false);
 DeleteDirectory('c:\program files (x86)\zaxar');
 DeleteDirectory('c:\program files (x86)\zaxar\bearer');
 DeleteDirectory('c:\program files (x86)\zaxar\imageformats');
 DeleteDirectory('c:\program files (x86)\zaxar\platforms');
 DeleteDirectory('c:\program files (x86)\zaxar\sensors');
 DeleteDirectory('c:\users\andrei\appdata\local\wutphost');
 RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ctelruegfh');
 RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'CurrencyConvertor');
 RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'ycAutoLaunch_1A04FCC48409310FF3A616F80D6C75DE');
 CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
 ExecuteRepair(3);
 ExecuteRepair(4);
 ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
Компьютер перезагрузится.



Файл quarantine.zip из папки с распакованной утилитой AVZ отправьте с помощью этой формы или (если размер архива превышает 8 MB) на этот почтовый ящик: quarantine <at> safezone.cc (замените <at> на @) с указанием ссылки на тему в теме (заголовке) сообщения и с указанием пароля: virus в теле письма.

Файл CheckBrowserLnk.log
из папки
Цитата:
...\AutoLogger\CheckBrowserLnk
перетащите на утилиту ClearLNK.



Отчёт о работе в виде файла ClearLNK-<Дата>.log прикрепите к вашему следующему сообщению.


Повторите логи по правилам. Для повторной диагностики запустите снова Autologger.

-------


Отправлено: 14:40, 24-10-2017 | #2