@Алексей Сергеевич,
по очистке системы выполните:
выполняем скрипт в uVS:
- скопировать содержимое кода в буфер обмена;
- стартуем uVS(start.exe), далее выбираем: текущий пользователь, меню - скрипты - выполнить скрипт из буфера обмена;
- закрываем все браузеры перед выполнением скрипта;
при деинсталляции программ - соглашаемся на деинсталляцию_удаление подтверждаем "да"
Код |
---|
;uVS v4.0b12 [http://dsrt.dyndns.org]
;Target OS: NTv6.1
v400c
OFFSGNSAVE
;------------------------autoscript---------------------------
zoo %SystemDrive%\USERS\USER\APPDATA\LOCAL\TEMP\AEE9C62F.EXE
addsgn 9252774A0A6AC1CC0B944E4EA34FFE85168A8D1AD65748F1604E5998D0178EB312D7936EE220660F6DD3ECE23A2049ADFE1CEC213DD1773A2D2127ECC35572B4 8 a variant of Win32/Filecoder.ED 7
zoo %SystemDrive%\USERS\USER\APPDATA\LOCAL\TEMP\A86B5C6747183B1C9BBB4181C53F302D.DLL
addsgn 729053925465C99500D4AED1DAC88216350742F60916E02F0C2648207456B0B3DC2603070789E8B26DC6D7F736D16BFA2A5C2B7606B2FD732277F2AC04027123 64 a variant of Win32/Filecoder.ED 7
zoo %SystemDrive%\PROGRAMDATA\WINDOWS\CSRSS.EXE
addsgn A7679B19B9761B1AC1C0AEB1C5DCD15725DA03E37D7D4D780003B1BE9DCFFA9EA842CBDCECDC8855E8D284166BEA8BA87D19AD81551DF5C035B7F62F0043CA0F 8 Win32/Kryptik 7
zoo %SystemDrive%\USERS\USER\APPDATA\LOCAL\TEMP\CE14E8BD.EXE
addsgn 9252777A066AC1CC0BE4424EA34FFAB8058A60F4690848F1604E5998D0278DB312D7936EE220660F6DD3ECBA7B3749ADFE1CEC213DFDC4212D2127ECC35572B4 8 Win32/Filecoder.ED [ESET-NOD32] 7
zoo %SystemDrive%\USERS\USER\APPDATA\LOCAL\TEMP\030049F0.EXE
addsgn 925277EA0C6AC1CC0B74484EA34FFEFF008AE174F74048F1604E5998D0278DB312D7936EE220660F6DD3ECBCB13E49ADFE1CEC213DC81B232D2127ECC35572B4 8 Win32/Filecoder.ED 7
zoo %SystemDrive%\PROGRAMDATA\CSRSS\CSRSS.EXE
zoo %SystemDrive%\PROGRAMDATA\DRIVERS\CSRSS.EXE
zoo %SystemDrive%\PROGRAMDATA\SERVICES\CSRSS.EXE
zoo %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\APPLICATION DATA\ASPACKAGE\ASPACKAGE.EXE
addsgn 7300A398556A1F275D83C49157254C8C49AEE431CDDE0FA02483C5353CF265B3362753173E3D9CC92B807B8AFE8609FA2820FDB2C79AB04625D45C09B806CA45 59 AdWare.ConvertAd 7
chklst
delvir
deldirex %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\UNITY\WEBPLAYER\LOADER
deldirex %SystemDrive%\PROGRAM FILES\DEALPLY
deldirex %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\ГЛАВНОЕ МЕНЮ\ПРОГРАММЫ\DEALPLY
deldirex %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\APPLICATION DATA\VOPACKAGE
deldirex %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\ГЛАВНОЕ МЕНЮ\ПРОГРАММЫ\VOPACKAGE
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ADMIN\LOCAL SETTINGS\APPLICATION DATA\YANDEX\UPDATER\PRAETORIAN.EXE
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\APPLICATION DATA\MYDESKTOP\QWEEECL.EXE
delref HTTP:\\HELLO.LIMBBO.RU\OFFERS\RU.CSV
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\COUPONRISER\COUPONRISER_STB.EXE
delref HTTP://DCUBEGE.RU/?UTM_SOURCE=UOUA03N&UTM_CONTENT=65D7070BB524C9CE20A0E94F70433559&UTM_TERM=0752C824510FFFD073CDC97F558A4D1F
delref %SystemDrive%\PROGRAM FILES\FITBIT CONNECT\FITBIT CONNECT.EXE
delref %SystemDrive%\PROGRAM FILES\OBNOVI SOFT\OBNOVISOFT.EXE
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DEFAIDNBMNNNIBPCAJPCGLCLEFINDMKAJ%26INSTALLSOURCE%3DONDEMAND%26UC
delref %SystemDrive%\USERS\USER\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\AOJOECKCMJGHLCHNNENFKBFLNDBEPJPK\8.22.5_0\ПОИСК И СТАРТОВАЯ — ЯНДЕКС
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\AHNPHCMHMHCJJCJHMNNJJLBMAELJECGA\12.0.8_0\ПОИСК MAIL.RU
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\AOJOECKCMJGHLCHNNENFKBFLNDBEPJPK\8.19.0_0\ПОИСК И СТАРТОВАЯ — ЯНДЕКС
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\BGCIFLJFAPBHGIEHKJLCKFJMGEOJIJCB\7.0.25_0\ПОИСК MAIL.RU
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\EIODDFAEPDOEIFBHJPHFEFGIPCJCDIEO\5.0.1_1\ПОИСК MAIL.RU
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\GEHNGEIFMELPHPLLNCOBKMIMPHFKCKNE\1.2.9.0_0\СТАРТОВАЯ — ЯНДЕКС
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\NBIFDKMDOJGMPMOPDEBNJCOBEKGDONCN\4.0.5_0\ПОИСК MAIL.RU
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\PROFILE 4\EXTENSIONS\OJLCEBDKBPJDPILIGKDBBKDKFJMCHBFD\12.0.11_0\ПОИСК MAIL.RU
apply
; McAfee Security Scan Plus
exec C:\Program Files\McAfee Security Scan\uninstall.exe
deltmp
delref {23E5D772-327A-42F5-BDEE-C65C6796BB2A}\[CLSID]
delref {177AFECE-9599-46CF-90D7-68EC9EEB27B4}\[CLSID]
delref {CEF51277-5358-477B-858C-4E14F0C80BF7}\[CLSID]
delref {59116E30-02BD-4B84-BA1E-5D77E809B1A2}\[CLSID]
delref {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}\[CLSID]
delref %Sys32%\BLANK.HTM
delref {18DF081C-E8AD-4283-A596-FA578C2EBDC3}\[CLSID]
delref {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\[CLSID]
delref {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\[CLSID]
delref {8E5E2654-AD2D-48BF-AC2D-D17F00898D06}\[CLSID]
delref {91397D20-1446-11D4-8AF4-0040CA1127B6}\[CLSID]
delref {D27CDB6E-AE6D-11CF-96B8-444553540000}\[CLSID]
delref {D5FEC983-01DB-414A-9456-AF95AC9ED7B5}\[CLSID]
delref {E2E2DD38-D088-4134-82B7-F2BA38496583}\[CLSID]
delref {1B1F6171-E8D6-4F5F-9778-3009CC2748E2}\[CLSID]
delref {FF20459C-DA6E-41A7-80BC-8F4FEFD9C575}\[CLSID]
delref {452ADB5B-00BE-469D-A65F-3046146B2ED5}\[CLSID]
delref {8984B388-A5BB-4DF7-B274-77B879E179DB}\[CLSID]
delref E:\AUTORUN.EXE
delref E:\AUTOINSTALL.EXE
delref G:\LAUNCHER.EXE
delref G:\AUTOINSTALL.EXE
delref {BDEADF00-C265-11D0-BCED-00A0C90AB50F}\[CLSID]
delref {041CA328-918A-4EB9-BBC0-525BB3E5B535}\[CLSID]
delref {09900DE8-1DCA-443F-9243-26FF581438AF}\[CLSID]
delref {0E8A89AD-95D7-40EB-8D9D-083EF7066A01}\[CLSID]
delref {10921475-03CE-4E04-90CE-E2E7EF20C814}\[CLSID]
delref {17B4E3DD-1CD4-4BCE-AC11-8DCD50771F5E}\[CLSID]
delref {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\[CLSID]
delref {29B6CFD5-0064-411A-8C42-9890C83F9921}\[CLSID]
delref {2A5D2C17-4836-4BBE-897F-64167A9101EB}\[CLSID]
delref {3431BE7D-729A-421C-B05F-DA10D63C4F38}\[CLSID]
delref {444785F1-DE89-4295-863A-D46C3A781394}\[CLSID]
delref {5FAB84B8-F777-45C0-A23A-A7074432A2B9}\[CLSID]
delref {61628E2A-4FF9-4454-992D-D92A8CD27399}\[CLSID]
delref {6220FB26-353D-4F22-9E8B-2CAA1B1A5211}\[CLSID]
delref {6325E28F-D844-41BC-A0DA-098771915D9B}\[CLSID]
delref {6414512B-B978-451D-A0D8-FCFDF33E833C}\[CLSID]
delref {748E146C-5842-4AD4-8A01-ACA7E61C6FCE}\[CLSID]
delref {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\[CLSID]
delref {77E06B43-DAE7-44C8-A17E-142F018E412C}\[CLSID]
delref {77E65655-CE52-4AA0-B431-1ABED0D9A59C}\[CLSID]
delref {8151E923-BAE1-4C40-9A7D-1E8BBFB438F7}\[CLSID]
delref {8A06DE21-1DB8-426F-8E46-3B96134B9FA8}\[CLSID]
delref {8E39EBE3-185C-40DC-88D7-D3285CFF07B2}\[CLSID]
delref {8E8F97CD-60B5-456F-A201-73065652D099}\[CLSID]
delref {9B162141-8C4B-47B8-B0A4-678026ADB884}\[CLSID]
delref {AAF93162-F338-41CB-BB5F-4115BDA972FB}\[CLSID]
delref {B5B27B9D-BDFC-4645-9AA5-33A8008E3860}\[CLSID]
delref {B738032D-77A3-443B-B7FB-BAD755CBB314}\[CLSID]
delref {BC7D8114-76A4-47B5-A009-15ABB5E6AB57}\[CLSID]
delref {C8804369-9983-48B4-ACED-DB6C44418EA4}\[CLSID]
delref {DBC80044-A445-435B-BC74-9C25C1C588A9}\[CLSID]
delref {DFEAF541-F3E1-4C24-ACAC-99C30715084A}\[CLSID]
delref {EF7BD87A-8024-11E2-F316-F3E56188709B}\[CLSID]
delref {FE341F2F-1296-4C20-82C0-E6EC54F4D8B7}\[CLSID]
delref {C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\[CLSID]
delref {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\[CLSID]
delref {166B1BCA-3F9C-11CF-8075-444553540000}\[CLSID]
delref {233C1507-6A77-46A4-9443-F871F945D258}\[CLSID]
delref {4063BE15-3B08-470D-A0D5-B37161CFFD69}\[CLSID]
delref {88D969C0-F192-11D4-A65F-0040963251E5}\[CLSID]
delref {88D969C1-F192-11D4-A65F-0040963251E5}\[CLSID]
delref {88D969C2-F192-11D4-A65F-0040963251E5}\[CLSID]
delref {88D969C3-F192-11D4-A65F-0040963251E5}\[CLSID]
delref {88D969C4-F192-11D4-A65F-0040963251E5}\[CLSID]
delref {88D969C5-F192-11D4-A65F-0040963251E5}\[CLSID]
delref {8AD9C840-044E-11D1-B3E9-00805F499D93}\[CLSID]
delref {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}\[CLSID]
delref {1FBA04EE-3024-11D2-8F1F-0000F87ABD16}\[CLSID]
delref {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}\[CLSID]
delref {E6FB5E20-DE35-11CF-9C87-00AA005127ED}\[CLSID]
delref HELPSVC\[SERVICE]
delref SACSVR\[SERVICE]
delref VMMS\[SERVICE]
delref MESSENGER\[SERVICE]
delref RDSESSMGR\[SERVICE]
delref %SystemDrive%\PROGRAM FILES\TRUEKEY\MCAFEE.TRUEKEY.INSTALLERSERVICE.EXE
delref %Sys32%\PSXSS.EXE
delref %SystemDrive%\PROGRAM FILES\GOOGLE\UPDATE\1.3.32.7\PSMACHINE.DLL
delref %SystemDrive%\PROGRAM FILES\ADOBE\ACROBAT READER DC\ACRORD32INFO.EXE
delref %Sys32%\SHAREMEDIACPL.CPL
delref %SystemDrive%\PROGRAM FILES\GOOGLE\UPDATE\1.3.31.5\PSMACHINE.DLL
delref D:\SETUP.EXE
delref D:\ASRSETUP.EXE
delref %SystemDrive%\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
delref %Sys32%\RCIMLBY.EXE
delref %SystemDrive%\PROGRAM FILES\OUTLOOK EXPRESS\WAB.EXE
delref %SystemDrive%\PROGRAM FILES\ANYSEND\ANYSENDUI.EXE
delref %SystemDrive%\PROGRAM FILES\ANYSEND\UNINSTALL.EXE
delref %SystemDrive%\PROGRAM FILES\HAMSTER SOFT\HAMSTER PDF READER\HAMSTERPDFREADER.EXE
delref %SystemDrive%\PROGRAM FILES\PHOTOCONVERTER STANDARD\PHOTOCONVERTER.EXE
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\LOCAL SETTINGS\APPLICATION DATA\COUPONRISER\UNINSTALL.EXE
delref %SystemDrive%\PROGRAM FILES\DEALPLY\UNINST.EXE
delref %SystemDrive%\PROGRAM FILES\MIPONY\MIPONY.EXE
delref %SystemDrive%\PROGRAM FILES\TOTAL COMMANDER\PLUGINS\EXE\TWEAKTC.EXE
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ОПЕРАТОР\APPLICATION DATA\VOPACKAGE\VOPACKAGE.EXE
delref %SystemDrive%\PROGRAM FILES\OBNOVI SOFT\UNINSTALL.EXE
delref %SystemDrive%\PROGRAM FILES\OPERA\LAUNCHER.EXE
;-------------------------------------------------------------
restart
|
перезагрузка, пишем о старых и новых проблемах.
по расшифровке файлов восстанавливаем файлы из архивных копий
если таковых нет,
сохраните важные каталоги с зашифрованными файлами на отдельный носитель до лучших времен, когда вирусописатели начнут раздавать всем бесплатно приватные ключи.