simply god
Постоянный участник
- Сообщения
- 136
- Реакции
- 8
VKSaver [2015/10/25 10:31:13]-->"C:\ProgramData\VKSaver\VKSaver.exe" -uninstall
Raptr [2016/04/28 06:52:04]-->"C:\Program Files (x86)\Raptr Inc\Raptr\uninstall.exe"
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFile('C:\Users\super\Favorites\Links\Интернет.url','');
QuarantineFile('C:\Users\super\AppData\LocalLow\SearchGo\searchgo.dll','');
QuarantineFileF('C:\Users\super\AppData\LocalLow\SearchGo', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.com', true, '', 0, 0);
QuarantineFileF('C:\Users\super\appdata\local\svshost', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.com', true, '', 0, 0);
QuarantineFileF('C:\Users\super\AppData\Local\fupdate', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.com', true, '', 0, 0);
QuarantineFileF('C:\Users\super\AppData\Local\SearchGo', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js, *.com', true, '', 0, 0);
DeleteFile('C:\WINDOWS\system32\Tasks\svshost','64');
DeleteFile('C:\Users\super\AppData\Local\svshost\svshost.exe','32');
DeleteFile('C:\Users\super\AppData\Local\SearchGo\searchgo.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\SearchGo Task','64');
DeleteFile('C:\Users\super\appdata\local\svshost\svshost.exe','32');
DeleteFile('C:\WINDOWS\system32\Tasks\fupdate','64');
DeleteFile('C:\Users\super\AppData\Local\fupdate\fupdate.exe','32');
DeleteFile('C:\Users\super\AppData\LocalLow\SearchGo\searchgo.dll','32');
DeleteFile('C:\Users\super\Favorites\Links\Интернет.url','32');
DelBHO('{2BC46CFA-4B00-4193-A7BD-6AD1D0BCB5BC}');
DelBHO('{598AEFC6-DD3C-4A63-9AC3-53FCF6155931}');
DeleteFileMask('C:\Users\super\AppData\Local\fupdate','*', true);
DeleteFileMask('C:\Users\super\AppData\Local\SearchGo','*', true);
DeleteFileMask('C:\Users\super\appdata\local\svshost','*', true);
DeleteFileMask('C:\Users\super\AppData\LocalLow\SearchGo','*', true);
DeleteDirectory('C:\Users\super\appdata\local\svshost');
DeleteDirectory('C:\Users\super\AppData\Local\SearchGo');
DeleteDirectory('C:\Users\super\AppData\Local\fupdate');
DeleteDirectory('C:\Users\super\AppData\LocalLow\SearchGo');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','uuawidevtt');
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
ExecuteSysClean;
ExecuteRepair(4);
ExecuteRepair(3);
RebootWindows(true);
end.
start
CreateRestorePoint:
Task: {D90AEAC0-FAC5-4C01-8617-E9893F80D85E} - \svshost -> No File <==== ATTENTION
FF Homepage: hxxp://chatozov.ru/?utm_content=706daf58c4c295e14015a61bf477685c&utm_source=startpm&utm_term=ECAC407760535258C1054FFC13DA4FE0&utm_d=20160519
2016-05-19 19:00 - 2016-05-19 19:00 - 00000000 ____D C:\Users\super\AppData\Local\Вoйти в Интeрнет
2016-05-19 18:54 - 2016-05-19 18:54 - 00000000 ____D C:\Users\super\AppData\Local\Поиcк в Интeрнете
EmptyTemp:
Reboot:
end
var
LogPath : string;
ScriptPath : string;
begin
LogPath := GetAVZDirectory + 'log\avz_log.txt';
if FileExists(LogPath) Then DeleteFile(LogPath);
ScriptPath := GetAVZDirectory +'ScanVuln.txt';
if DownloadFile('http://dataforce.ru/~kad/ScanVuln.txt', ScriptPath, 1) then ExecuteScript(ScriptPath) else begin
if DownloadFile('http://dataforce.ru/~kad/ScanVuln.txt', ScriptPath, 0) then ExecuteScript(ScriptPath) else begin
ShowMessage('Невозможно загрузить скрипт AVZ для обнаружения наиболее часто используемых уязвимостей!');
exit;
end;
end;
if FileExists(LogPath) Then ExecuteFile('notepad.exe', LogPath, 1, 0, false)
end.
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?