[QUOTE]
Геннадий Дежников написал:
Здравствуйте, коллеге по почте прилетел шифрователь, образ:[/QUOTE]
сорри, пропустил вчера образ,
выполняем скрипт в uVS:
- скопировать содержимое кода в буфер обмена;
- стартуем uVS(start.exe), далее выбираем: текущий пользователь, меню - скрипты - выполнить скрипт из буфера обмена;
- закрываем все браузеры перед выполнением скрипта;
при деинсталляции программ - соглашаемся на деинсталляцию_удаление подтверждаем "да"
[code]
;uVS v3.87.9 [http://dsrt.dyndns.org]
;Target OS: NTv6.1
OFFSGNSAVE
zoo %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\MEDIAGET2\MEDIAGET
-UNINSTALLER.EXE
addsgn 9252771A116AC1CC0B44554E33231995AF8CBA7E8EBD1EA3F0C44EA2D338
8D5DF8652EEF3F559D492A5BF198CD08CA1481CE336395DB6B5F26028CA4
D985CC8F 14 Win32:FakeSys-BF [PUP]
addsgn A7679BF0AA028C9F2BD4C6FBA7E81261848AFCF689AA7BF1A0C3C5BC5055
9D24704194DE5BBDAE92A2DD78F544E95C42A8FFE82BD6D7A0390C775BAC
CA123752 8 Win32/Filecoder.ED [ESET-NOD32]
zoo %SystemDrive%\PROGRAMDATA\WINDOWS\CSRSS.EXE
addsgn 1AEF719A5583CC8CF42B5194FCF95505AEC7089200F71F7885C39CE30F88
2AC7C64A92A5FDDED0B9184D767756E3B6058F36328DAA253B61C14469DD
2FF9D68C 8 Adware.HPDefender
zoo %SystemDrive%\USERS\AIVANOV\APPDATA\ROAMING\GAMELAUNCHER\SEV
ILER\SEVILER.EXE
;------------------------autoscript---------------------------
chklst
delvir
delref HTTP://TOPSNOTE.RU/ALONSM
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DCCFIFBOJENKENPKMNBNNDEADPFDIFFOF%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DEIODDFAEPDOEIFBHJPHFEFGIPCJCDIEO%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DICANJJKADCEEBMHANPEKKOFDHCLNOIJL%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DIFLPPBJNPNEIIGCBDFJPNKEBIDMKJMOI%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DODIJCGAFKHPOBJLNFDGIACPDENPMBGME%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DOELPKEPJLGMEHAJEHFEICFBJDIOBDKFJ%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DOJLCEBDKBPJDPILIGKDBBKDKFJMCHBFD%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DPHKDCINMMLJBLPNKOHLIPAIODLONPINF%26INSTALLSOURCE%3D
ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DPPOILMFKBPCKODOIFDLKMKEPCAJFJMHL%26INSTALLSOURCE%3D
ONDEMAND%26UC
deldirex %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\MEDIAGET2
delref %SystemDrive%\USERS\AIVANOV\APPDATA\ROAMING\MYDESKTOP\QWEEEC
L.EXE
delref HTTP:\\HELLO.LIMBBO.RU\OFFERS\RU.CSV
delref HTTP://NATSIMA.RU/?UTM_SOURCE=UOUA03&UTM_CONTENT=4E8C9050D51EBFF187B4E21DDD852E
D8&UTM_TERM=ED90F0FC6FAA9CA0031DFE0631CACC9A&UTM_D=20160816
delref %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\HOST SERVICE\LAUNCHALL.JS
deldirex %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\MEDIA GET LLC\MEDIAGET2\USER_SEARCH\TSERVERINFO
deldirex %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\MEDIA GET LLC\MEDIAGET2\USER_SEARCH\ISERVERINFO
deldirex %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\MEDIA GET LLC\MEDIAGET2\USER_SEARCH\SSERVERINFO
deldirex %SystemDrive%\USERS\AIVANOV\APPDATA\LOCAL\MEDIA GET LLC\MEDIAGET2
deltmp
delnfr
;-------------------------------------------------------------
restart
[/code]
перезагрузка, пишем о старых и новых проблемах.
------------