<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0">
	<channel>
		<title>Форум esetnod32.ru [тема: Много вирусов. Помогите.]</title>
		<link>http://forum.esetnod32.ru</link>
		<description>Новое в теме Много вирусов. Помогите. форума  на сайте Форум esetnod32.ru [forum.esetnod32.ru]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Thu, 30 Apr 2026 08:16:17 +0300</pubDate>
		<item>
			<title>Много вирусов. Помогите.</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum6/topic12215/message86640/">Много вирусов. Помогите.</a></b> в форуме <a href="http://forum.esetnod32.ru/forum6/">Обнаружение вредоносного кода и ложные срабатывания</a>. <br />
			Скопировать текст КОДА - в буфер обмена.<br />uVS: start.exe, текущий пользователь, меню, скрипты - выполнить скрипт из буфера обмена.<br />ПЕРЕД ВЫПОЛНЕНИЕМ СКРИПТА, ЗАКРЫТЬ БРАУЗЕРЫ!<br />ВНИМАНИЕ : По окончанию выполнения скрипта компьютер выполнит перезагрузку !<br />На вопросы программы отвечаем: Да ! <br />
====code====
<pre>&nbsp;&nbsp;&nbsp;&nbsp; 


;uVS v3.85.25 &#91;http://dsrt.dyndns.org&#93;
;Target OS: NTv6.1
v385c
;------------------------autoscript---------------------------

chklst
delvir

bl E9E2DC4B14F2A20046683E2B699BA79C 125112
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;PROTECTSERVICE.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;PROTECTSERVICE.EXE

bl 39A3CFAF9434930C61C51E546AA0C5CF 4705512
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MAIL.RU&#92;MAILRUUPDATER&#92;MAILRUUPDATER.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MAIL.RU&#92;MAILRUUPDATER&#92;MAILRUUPDATER.EXE

bl CC0A167686956CDACCAA04F495515B01 3988624
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;GMSD_RU_005010030&#92;GMSD_RU_005010030.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;GMSD_RU_005010030&#92;GMSD_RU_005010030.EXE

bl 0DE6521016CAE929552DD557979E196C 29368
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;CMDSHELL.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;CMDSHELL.EXE

deldirex %SystemDrive%&#92;PROGRAMDATA&#92;WINDOWSMANGERPROTECT

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;03000200-1436784293-0500-0006-000700080009&#92;HNSUC40B.TMP

bl EA53AECFA07C4CE409EBD0F62F84CFCD 544952
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;SUPTAB.DLL
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;SUPTAB.DLL

deldirex %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;KOMETA

deldirex %SystemDrive%&#92;PROGRAM FILES&#92;CROSSBROWSE&#92;CROSSBROWSE&#92;APPLICATION

bl 2D4A05784DDD53D0B310BB336517F0ED 3984016
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;GMSD_RU_005010033&#92;GMSD_RU_005010033.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;GMSD_RU_005010033&#92;GMSD_RU_005010033.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-10.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-10.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;03000200-1436784293-0500-0006-000700080009&#92;KNSE9C1D.TMP

bl A91C23B73C968975F14175453EB996B5 1425488
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-10.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-10.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;03000200-1436784293-0500-0006-000700080009&#92;JNSOAD0F.TMP

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-1-6.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-1-6.EXE

bl 9E233ACD8DACE09CFE8743B7D6EB3C49 3983504
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;GMSD_RU_005010032&#92;GMSD_RU_005010032.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;GMSD_RU_005010032&#92;GMSD_RU_005010032.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-10.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-10.EXE

deldirex %SystemDrive%&#92;PROGRAM FILES&#92;OBNOVI SOFT

delref &#92;&#92;?&#92;C:&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;MAIL.RU&#92;MAILRUUPDATER.EXE
del &#92;&#92;?&#92;C:&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;MAIL.RU&#92;MAILRUUPDATER.EXE

bl 84B5D5396472C76E2DC550F4401EA233 673976
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;HPNOTIFY.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;HPNOTIFY.EXE

bl B5B798AEDE56CE7A45FC38F982EAA856 20664
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;IEWATCHDOG.DLL
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;MIUITAB&#92;IEWATCHDOG.DLL

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;~NSU.TMP&#92;AU_.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;NSMAF72.TMP&#92;SYSTEM.DLL

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;NSMAF72.TMP&#92;NSDIALOGS.DLL

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;NSMAF72.TMP&#92;NSEXEC.DLL

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;NSMAF72.TMP&#92;UAC.DLL

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;NSMAF72.TMP&#92;NSISPLUGIN.DLL

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;NSMAF72.TMP&#92;NSCC88.TMP

bl 75D6ACC0AD32FA6CFBCF6E829677A982 1072720
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-1-7.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-1-7.EXE

bl 02B0B10632901D290C524FA4EE882B1A 1398352
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-11.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-11.EXE

bl 1266761EE1E97301F69DCDD58F066A9B 1125456
delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-5.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07&#92;3E328F2F-4D8E-4467-84CD-1B272D34ABAC-5.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-1-6.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-1-6.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-1-7.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-1-7.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-11.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-11.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-5.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;CIPLUS-4.5VV13.07&#92;6598A7A8-86F8-401A-BF09-4E79FBD5DA4A-5.EXE

deldirex %SystemDrive%&#92;PROGRAM FILES&#92;ANYPROTECTEX

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-1-7.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-1-7.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-11.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-11.EXE

delref &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-5.EXE
del &#92;&#92;?&#92;C:&#92;PROGRAM FILES&#92;PLUSHD_5.1V08.07&#92;B7672D65-0301-436A-804F-3AB3FC98C9AF-5.EXE

deldirex %SystemDrive%&#92;PROGRAM FILES&#92;GLOBALUPDATE&#92;UPD ATE

deldirex %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;SMARTWEB

deldirex %SystemDrive%&#92;PROGRAM FILES&#92;ZAXAR

delref HTTP://WWW.MYSTARTSEARCH.COM/?TYPE=HP&#38;TS=1437049664&#38;Z=EBD681DE4D234E829FE3F5DGEZ2C9MEEBZ0T7Q9Z0G&#38;FROM=CMI&#38;UID=395049983_397234_42FF6114
delref HTTP://WWW.MYSTARTSEARCH.COM/WEB/?TYPE=DS&#38;TS=1437049664&#38;Z=EBD681DE4D234E829FE3F5DGEZ2C9MEEBZ0T7Q9Z0G&#38;FROM=CMI&#38;UID=395049983_397234_42FF6114&#38;Q={SEARCHTERMS}
bl 6AC4D4E8F13E973F94AA0F13D5CB0C6D 541888
delref &#92;&#92;?&#92;C:&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;PROMOSKIKI&#92;STUB.EXE
del &#92;&#92;?&#92;C:&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;PROMOSKIKI&#92;STUB.EXE

delref HTTP://GO.MAIL.RU/?IEVERFIX=1&#38;FR=IEVERFIX_SG
delref HTTP://SPACESEARCH.RU/?RI=1&#38;RSID=C1614207995B4B133BCC1E619857165C&#38;Q={SEARCHTERMS}
del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;13490602&#92;OPERA_NL_STABLE.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;26132134&#92;10C90A78.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;14217812&#92;ZAXARSETUP.4.001.31.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;64209592&#92;PROMOSKIKI_SETUP_2.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;MAILRUUPDATER.EXE

del %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;TEMP&#92;IS-PV1PS.TMP&#92;SOLUN.EXE

bl 8A95321526CF20F7247AF00CE82AAB80 168
delref &#92;&#92;?&#92;C:&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;YANDEX&#92;BROWSER.BAT
del &#92;&#92;?&#92;C:&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;YANDEX&#92;BROWSER.BAT

delref HTTP://SEARCHYDA-S.RU
bl 9CA9509B6B7658F335AB387AA2E7DC9E 102
delref &#92;&#92;?&#92;C:&#92;IEXPLORE.BAT
del &#92;&#92;?&#92;C:&#92;IEXPLORE.BAT

delref &#92;&#92;?&#92;HTTP:&#92;&#92;SEARCHYDA-S.RU
deldirex %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;MICROSOFT&#92;WINDOWS&#92;START MENU&#92;PROGRAMS&#92;ZAXAR GAMES BROWSER

delref &#92;&#92;?&#92;HTTP:&#92;&#92;WWW.MYSTARTSEARCH.COM&#92;?TYPE=SC&#38;TS=1437049664&#38;Z=EBD681DE4D234E829FE3F5DGEZ2C9MEEBZ0T7Q9Z0G&#38;FROM=CMI&#38;UID=395049983_397234_42FF6114
regt 27
regt 28
regt 29
;-------------------------------------------------------------

bl 6535B695B3264C3869FBA989C4E5F3A6 844
delall %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;MICROSOFT&#92;WINDOWS&#92;START MENU&#92;PROGRAMS&#92;ZAXAR GAMES BROWSER&#92;ZAXAR GAMES BROWSER.LNK
bl 89557F4FBB6122DA07B60B809C99A67D 1030
delall %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;MICROSOFT&#92;WINDOWS&#92;START MENU&#92;PROGRAMS&#92;ZAXAR GAMES BROWSER&#92;ZAXAR UPD ATE.LNK
deldirex %SystemDrive%&#92;PROGRAM FILES&#92;CIPLUS-4.5VV16.07
deldir %SystemDrive%&#92;PROGRAM FILES&#92;ANYPROTECTEX
deldir %SystemDrive%&#92;PROGRAM FILES&#92;OBNOVI SOFT
delall %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;SMARTWEB&#92;SMARTWEBHELPER.EXE
delall %SystemDrive%&#92;PROGRAM FILES&#92;ZAXAR&#92;TIMETASKS.EXE
bl 1EC4A72C32DE01DE4608C95EEDB2C980 49104
delall %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;PROMOSKIKI&#92;UNINSTALL.EXE
deldir %SystemDrive%&#92;PROGRAM FILES&#92;ZAXAR
bl 71060D4753A584A4D5242D8D615C4981 1996896
delall %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;ROAMING&#92;UTORRENT&#92;UTORRENT.EXE
deldir %SystemDrive%&#92;PROGRAM FILES&#92;WORDSURFER_1.10.0.19&#92;UPD ATE
setdns Подключение по локальной сети 2&#92;4&#92;{D8CED18D-8100-45C3-B613-8F0E6AF287C5}&#92;208.67.222.222,208.67.220.220
setdns Подключение по локальной сети&#92;4&#92;{0EB0EC91-4060-426D-A123-76B2FFAA4E48}&#92;208.67.222.222,208.67.220.220
delall %SystemDrive%&#92;PROGRAM FILES&#92;REGISTRY HELPER&#92;REGISTRYHELPERSERVICE.EXE
exec C:&#92;Users&#92;User&#92;AppData&#92;Roaming&#92;mystartsearch&#92;UninstallManager.exe&nbsp;&nbsp;-ptid=cmi
exec "C:&#92;Program Files&#92;Crossbrowse&#92;Crossbrowse&#92;Application&#92;39.6.2171.95&#92;Installer&#92;setup.exe" --uninstall --system-level
exec "C:&#92;ProgramData&#92;Package Cache&#92;{1f974034-d972-42fa-9b6f-3833c0a8a0c8}&#92;setup.exe"&nbsp;&nbsp;/uninstall
deltmp
delnfr
restart


</pre>
=============
<br /><br />-------------<br />Пишем по результату.<br />+<br />Далее (даже если проблема решена) выполните лог программой Malwarebytes<br /><noindex><a href="http://forum.esetnod32.ru/forum9/topic10688/" target="_blank" rel="nofollow">http://forum.esetnod32.ru/forum9/topic10688/</a></noindex><br /><br />Выберите вариант сканирования: Быстрое или Полное сканирование.<br />Отчет предоставить для анализа ( в своей теме на форуме ).<br />Отчёт нужно предоставить в .txt ( блокнот ) <br />
			<i>17.07.2015 21:00:12, RP55 RP55.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum6/topic12215/message86640/</link>
			<guid>http://forum.esetnod32.ru/messages/forum6/topic12215/message86640/</guid>
			<pubDate>Fri, 17 Jul 2015 21:00:12 +0300</pubDate>
			<category>Обнаружение вредоносного кода и ложные срабатывания</category>
		</item>
		<item>
			<title>Много вирусов. Помогите.</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum6/topic12215/message86639/">Много вирусов. Помогите.</a></b> в форуме <a href="http://forum.esetnod32.ru/forum6/">Обнаружение вредоносного кода и ложные срабатывания</a>. <br />
			Много вирусов. Помогите. <br />
			<a href="https://forum.esetnod32.ru/bitrix/components/bitrix/forum.interface/show_file.php?fid=96736">WIN-P6UECU15U67_2015-07-17_20-10-44.rar</a><br /><i>17.07.2015 19:29:41, Владимир  Шариков.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum6/topic12215/message86639/</link>
			<guid>http://forum.esetnod32.ru/messages/forum6/topic12215/message86639/</guid>
			<pubDate>Fri, 17 Jul 2015 19:29:41 +0300</pubDate>
			<category>Обнаружение вредоносного кода и ложные срабатывания</category>
		</item>
	</channel>
</rss>
