puertorikanez
Постоянный участник
- Сообщения
- 189
- Реакции
- 18
Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
StopService('{00aec75d-051f-41a9-9837-e94ac4f56303}Gw64');
StopService('{10e3e2da-8f7b-42cc-9f00-90007ce494b8}Gw64');
StopService('{1de2a23f-1c23-4ea1-8ef4-79bc5c5cea78}Gw64');
StopService('{255a824a-3cde-4dee-9785-284605606456}Gw64');
StopService('{32c6b9d7-6b2c-4b03-9178-01abbf9c7194}Gw64');
StopService('{336e37ae-3235-4f16-98ec-8cdf679be7d2}Gw64');
StopService('{3b808196-ff63-49ee-b33b-efdf51723eca}Gw64');
StopService('{3cac76e7-8310-45ea-8277-96d048a78c60}Gw64');
StopService('{3fa44d1f-c300-4673-a8c1-5ba05468b4bd}Gw64');
StopService('{4096aedf-3f28-4c8e-aebe-00255138fa8a}Gw64');
StopService('{4530e639-76ab-4435-889d-a5e81ae090a4}Gw64');
StopService('{46a147d8-5171-42d8-b8a8-6a187525781d}Gw64');
StopService('{51b9c91c-8e38-40ae-80de-58a590512b6b}Gw64');
StopService('{67f29abb-07b3-41f5-94cd-f819d7c1fc76}Gw64');
StopService('{6b89253f-7097-40c7-9ead-2d5b1ceb02e2}w64');
StopService('{733fb217-c049-41ba-9504-3f2045e61977}Gw64');
StopService('{8ac13c32-b1f4-495e-8b0b-4bd4fd38c6b5}Gw64');
StopService('{949aba83-1d7f-4d0b-b0ba-203450825231}Gw64');
StopService('{94d62e35-4b43-494c-bf52-ba5935df36ef}Gw64');
StopService('{94d62e35-4b43-494c-bf52-ba5935df36ef}w64');
StopService('{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw64');
StopService('{b44cc396-b011-428e-9498-207b6b7bc335}Gw64');
StopService('{b59efc84-8479-4faa-b02a-e5c7e85c7926}Gw64');
StopService('{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}Gw64');
StopService('{d428f5a9-a362-4938-a8b7-f0abd920078b}Gw64');
StopService('{d997fcb4-42b4-4f84-a147-2e498567c954}Gw64');
StopService('{db1293a0-85fd-418d-b0d6-c79faa7c8ace}Gw64');
StopService('{dbec4a38-79aa-4d48-ac2b-d4467b1ded12}Gw64');
StopService('{dc592624-f532-4311-9fc7-6920126fc404}Gw64');
StopService('{e9629596-2cbd-4eea-9329-7470e8b0fdae}Gw64');
StopService('{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw64');
StopService('{f63e4e62-e47d-4415-9bb4-c9b1dfe161b9}Gw64');
StopService('{f9595960-dc6f-49f8-83db-4f3a4c9b714d}Gw64');
StopService('{fce396ae-d8d1-4789-946e-2106fbe4292b}Gw64');
QuarantineFile('C:\Windows\system32\drivers\{00aec75d-051f-41a9-9837-e94ac4f56303}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{10e3e2da-8f7b-42cc-9f00-90007ce494b8}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{1de2a23f-1c23-4ea1-8ef4-79bc5c5cea78}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{255a824a-3cde-4dee-9785-284605606456}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{32c6b9d7-6b2c-4b03-9178-01abbf9c7194}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{336e37ae-3235-4f16-98ec-8cdf679be7d2}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{3b808196-ff63-49ee-b33b-efdf51723eca}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{3cac76e7-8310-45ea-8277-96d048a78c60}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{3fa44d1f-c300-4673-a8c1-5ba05468b4bd}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{4096aedf-3f28-4c8e-aebe-00255138fa8a}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{4530e639-76ab-4435-889d-a5e81ae090a4}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{46a147d8-5171-42d8-b8a8-6a187525781d}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{51b9c91c-8e38-40ae-80de-58a590512b6b}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{67f29abb-07b3-41f5-94cd-f819d7c1fc76}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{6b89253f-7097-40c7-9ead-2d5b1ceb02e2}w64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{733fb217-c049-41ba-9504-3f2045e61977}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{8ac13c32-b1f4-495e-8b0b-4bd4fd38c6b5}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{949aba83-1d7f-4d0b-b0ba-203450825231}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{94d62e35-4b43-494c-bf52-ba5935df36ef}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{94d62e35-4b43-494c-bf52-ba5935df36ef}w64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{b44cc396-b011-428e-9498-207b6b7bc335}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{b59efc84-8479-4faa-b02a-e5c7e85c7926}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{d428f5a9-a362-4938-a8b7-f0abd920078b}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{d997fcb4-42b4-4f84-a147-2e498567c954}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{db1293a0-85fd-418d-b0d6-c79faa7c8ace}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{dbec4a38-79aa-4d48-ac2b-d4467b1ded12}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{dc592624-f532-4311-9fc7-6920126fc404}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{e9629596-2cbd-4eea-9329-7470e8b0fdae}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{f63e4e62-e47d-4415-9bb4-c9b1dfe161b9}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{f9595960-dc6f-49f8-83db-4f3a4c9b714d}Gw64.sys', '');
QuarantineFile('C:\Windows\system32\drivers\{fce396ae-d8d1-4789-946e-2106fbe4292b}Gw64.sys', '');
QuarantineFile('C:\Program Files (x86)\Google\chrome.bat', '');
QuarantineFile('C:\iexplore.bat', '');
QuarantineFile('C:\Users\xxx\AppData\Local\Yandex\browser.bat', '');
DeleteFile('C:\Windows\system32\drivers\{00aec75d-051f-41a9-9837-e94ac4f56303}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{10e3e2da-8f7b-42cc-9f00-90007ce494b8}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{1de2a23f-1c23-4ea1-8ef4-79bc5c5cea78}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{255a824a-3cde-4dee-9785-284605606456}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{32c6b9d7-6b2c-4b03-9178-01abbf9c7194}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{336e37ae-3235-4f16-98ec-8cdf679be7d2}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{3b808196-ff63-49ee-b33b-efdf51723eca}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{3cac76e7-8310-45ea-8277-96d048a78c60}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{3fa44d1f-c300-4673-a8c1-5ba05468b4bd}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{4096aedf-3f28-4c8e-aebe-00255138fa8a}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{4530e639-76ab-4435-889d-a5e81ae090a4}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{46a147d8-5171-42d8-b8a8-6a187525781d}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{51b9c91c-8e38-40ae-80de-58a590512b6b}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{67f29abb-07b3-41f5-94cd-f819d7c1fc76}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{6b89253f-7097-40c7-9ead-2d5b1ceb02e2}w64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{733fb217-c049-41ba-9504-3f2045e61977}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{8ac13c32-b1f4-495e-8b0b-4bd4fd38c6b5}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{949aba83-1d7f-4d0b-b0ba-203450825231}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{94d62e35-4b43-494c-bf52-ba5935df36ef}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{94d62e35-4b43-494c-bf52-ba5935df36ef}w64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{b44cc396-b011-428e-9498-207b6b7bc335}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{b59efc84-8479-4faa-b02a-e5c7e85c7926}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{d428f5a9-a362-4938-a8b7-f0abd920078b}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{d997fcb4-42b4-4f84-a147-2e498567c954}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{db1293a0-85fd-418d-b0d6-c79faa7c8ace}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{dbec4a38-79aa-4d48-ac2b-d4467b1ded12}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{dc592624-f532-4311-9fc7-6920126fc404}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{e9629596-2cbd-4eea-9329-7470e8b0fdae}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{f63e4e62-e47d-4415-9bb4-c9b1dfe161b9}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{f9595960-dc6f-49f8-83db-4f3a4c9b714d}Gw64.sys', '32');
DeleteFile('C:\Windows\system32\drivers\{fce396ae-d8d1-4789-946e-2106fbe4292b}Gw64.sys', '32');
DeleteFile('C:\Program Files (x86)\Google\chrome.bat', '32');
DeleteFile('C:\iexplore.bat', '32');
DeleteFile('C:\Users\xxx\AppData\Local\Yandex\browser.bat', '32');
DeleteService('{00aec75d-051f-41a9-9837-e94ac4f56303}Gw64');
DeleteService('{10e3e2da-8f7b-42cc-9f00-90007ce494b8}Gw64');
DeleteService('{1de2a23f-1c23-4ea1-8ef4-79bc5c5cea78}Gw64');
DeleteService('{255a824a-3cde-4dee-9785-284605606456}Gw64');
DeleteService('{32c6b9d7-6b2c-4b03-9178-01abbf9c7194}Gw64');
DeleteService('{336e37ae-3235-4f16-98ec-8cdf679be7d2}Gw64');
DeleteService('{3b808196-ff63-49ee-b33b-efdf51723eca}Gw64');
DeleteService('{3cac76e7-8310-45ea-8277-96d048a78c60}Gw64');
DeleteService('{3fa44d1f-c300-4673-a8c1-5ba05468b4bd}Gw64');
DeleteService('{4096aedf-3f28-4c8e-aebe-00255138fa8a}Gw64');
DeleteService('{4530e639-76ab-4435-889d-a5e81ae090a4}Gw64');
DeleteService('{46a147d8-5171-42d8-b8a8-6a187525781d}Gw64');
DeleteService('{51b9c91c-8e38-40ae-80de-58a590512b6b}Gw64');
DeleteService('{67f29abb-07b3-41f5-94cd-f819d7c1fc76}Gw64');
DeleteService('{6b89253f-7097-40c7-9ead-2d5b1ceb02e2}w64');
DeleteService('{733fb217-c049-41ba-9504-3f2045e61977}Gw64');
DeleteService('{8ac13c32-b1f4-495e-8b0b-4bd4fd38c6b5}Gw64');
DeleteService('{949aba83-1d7f-4d0b-b0ba-203450825231}Gw64');
DeleteService('{94d62e35-4b43-494c-bf52-ba5935df36ef}Gw64');
DeleteService('{94d62e35-4b43-494c-bf52-ba5935df36ef}w64');
DeleteService('{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw64');
DeleteService('{b44cc396-b011-428e-9498-207b6b7bc335}Gw64');
DeleteService('{b59efc84-8479-4faa-b02a-e5c7e85c7926}Gw64');
DeleteService('{bb7b7a60-f574-47c2-8a0b-4c56f2da9802}Gw64');
DeleteService('{d428f5a9-a362-4938-a8b7-f0abd920078b}Gw64');
DeleteService('{d997fcb4-42b4-4f84-a147-2e498567c954}Gw64');
DeleteService('{db1293a0-85fd-418d-b0d6-c79faa7c8ace}Gw64');
DeleteService('{dbec4a38-79aa-4d48-ac2b-d4467b1ded12}Gw64');
DeleteService('{dc592624-f532-4311-9fc7-6920126fc404}Gw64');
DeleteService('{e9629596-2cbd-4eea-9329-7470e8b0fdae}Gw64');
DeleteService('{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw64');
DeleteService('{f63e4e62-e47d-4415-9bb4-c9b1dfe161b9}Gw64');
DeleteService('{f9595960-dc6f-49f8-83db-4f3a4c9b714d}Gw64');
DeleteService('{fce396ae-d8d1-4789-946e-2106fbe4292b}Gw64');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
Если есть, прикрепите.отладку клинера не надо прикрепить?
Да, слишком малый размер.опять все закончилось перезагрузкой
;uVS v4.0.6 [http://dsrt.dyndns.org]
;Target OS: NTv6.1
v400c
OFFSGNSAVE
BREG
; %SystemDrive%\FIREFOX.BAT
bl 7544B2999EED394A58F0A10DBD904036 134
zoo %SystemDrive%\FIREFOX.BAT
del %SystemDrive%\FIREFOX.BAT
zoo %SystemDrive%\IEXPLORE.BAT
del %SystemDrive%\IEXPLORE.BAT
; %SystemDrive%\OPERA.BAT
bl AD7E05570147DD94F5114BD9A2A33DBD 112
zoo %SystemDrive%\OPERA.BAT
del %SystemDrive%\OPERA.BAT
; %SystemDrive%\USERS\XXX\APPDATA\LOCAL\BROWSERMANAGER.BAT
bl DFA79CCDFBE870C9574A7981BF32F21A 149
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\BROWSERMANAGER.BAT
del %SystemDrive%\USERS\XXX\APPDATA\LOCAL\BROWSERMANAGER.BAT
; C:\USERS\XXX\APPDATA\LOCAL\CSRSS.EXE
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\CSRSS.EXE
bl 483FCF432217D71544246AA760D98CDC 42687
addsgn 1B457B67AA661C700BD4AEB164C8120525F708F489F64F7A85C3C5BC50D6714C2317C3573E559D492B80849F461649FA7DDFE87255DAB02C2D77A42FC7062273 12 Trojan.Win32.Genome.amzxw [Kaspersky] 7
; C:\USERS\XXX\APPDATA\LOCAL\WINLOGON.EXE
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\WINLOGON.EXE
; C:\USERS\XXX\APPDATA\LOCAL\SERVICES.EXE
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\SERVICES.EXE
; C:\USERS\XXX\APPDATA\LOCAL\LSASS.EXE
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\LSASS.EXE
; C:\USERS\XXX\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\EMPTY.PIF
zoo %SystemDrive%\USERS\XXX\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\EMPTY.PIF
; C:\USERS\XXX\APPDATA\LOCAL\SMSS.EXE
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\SMSS.EXE
; C:\USERS\XXX\APPDATA\LOCAL\INETINFO.EXE
zoo %SystemDrive%\USERS\XXX\APPDATA\LOCAL\INETINFO.EXE
delref %SystemDrive%\ТРИ БОГАТЫРЯ И ШАМАХАНСКАЯ ЦАРИЦА\TRYBOG.EXE
chklst
delvir
deltmp
Действительно не страшно. Запустите UVS - файл - Архивировать ZOOне создался архив ZOO
Наоборот, сейчас все элемент от Mail.ru сгруппированы отдельно.не видно где от майла или там ничего не было
var PathAutoLogger, CMDLine : string;
begin
clearlog;
PathAutoLogger := Copy(GetAVZDirectory, 0, (Length(GetAVZDirectory)-4));
AddToLog('start time ' + FormatDateTime('yyyy.mm.dd-hh:mm:ss', now)+#13#10+ PathAutoLogger);
SaveLog(PathAutoLogger+'report3.log');
if FolderIsEmpty(PathAutoLogger+'CrashDumps')
then CMDLine := 'a "' + PathAutoLogger + 'Report.7z" "' + PathAutoLogger + '\report*.log"'
else CMDLine := 'a "' + PathAutoLogger + 'Report.7z" "' + PathAutoLogger + '\report*.log" "' + PathAutoLogger + 'CrashDumps\"';
if FileExists('7za.exe') then ExecuteFile('7za.exe', CMDLine, 0, 180000, false)
else ExecuteFile('7za.pif', CMDLine, 0, 180000, false);
AddLineToTxtFile(PathAutoLogger+'report3.log', '7z ReturnCode ' + IntToStr(GetLastExitCode)+#13#10+'end time ' + FormatDateTime('yyyy.mm.dd-hh:mm:ss', now));
end.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
StopService('{fd600559-a688-4110-b9b9-0f1a9beae8ae}Gw64');
QuarantineFile('C:\Windows\system32\drivers\{fd600559-a688-4110-b9b9-0f1a9beae8ae}Gw64.sys', '');
QuarantineFile('C:\Users\xxx\AppData\Local\smss.exe', '');
DeleteFile('C:\Windows\system32\drivers\{fd600559-a688-4110-b9b9-0f1a9beae8ae}Gw64.sys', '32');
DeleteFile('C:\Users\xxx\AppData\Local\smss.exe', '32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Tok-Cirrhatus','command');
DeleteService('{fd600559-a688-4110-b9b9-0f1a9beae8ae}Gw64');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
O4 - MSConfig\startupfolder: C:^Users^xxx^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Empty.pif - C:\Windows\pss\Empty.pif.Startup (2017/07/18)