Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
begin
QuarantineFile('C:\Users\user\AppData\Local\Programs\e3ce37514998\6ca9925c7e.msi', '');
DeleteFile('C:\Users\user\AppData\Local\Programs\e3ce37514998\6ca9925c7e.msi', '64');
DeleteFile('C:\ProgramData\quality-tidings\bin.exe', '64');
DeleteFile('C:\ProgramData\powerful-warrior\bin.exe', '64');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\CsaMspSvc_23b0a3\Parameters', 'ServiceDll', 'x64');
DeleteSchedulerTask('EdgeUpdate');
DeleteSchedulerTask('EdgeUpdateTaskUser');
DeleteSchedulerTask('MaintenanceSystemApps\MaintenanceUninstalledSystemApps');
DeleteSchedulerTask('MaintenanceUninstalledSystemApps');
DeleteSchedulerTask('notes-keep-S-1-5-21-705177890-1147294348-2339927788-1001');
DeleteSchedulerTask('perceive-throne');
DeleteSchedulerTask('survive-thunder');
ClearHostsFile;
ExecuteSysClean;
ExecuteWizard('TSW', 2, 3, true);
RebootWindows(true);
end.
begin
DeleteFile(GetAVZDirectory+'quarantine.7z');
ExecuteFile(GetAVZDirectory+'7za.exe', 'a -mx9 -pmalware quarantine .\Quarantine\*', 1, 300000, false);
end.
O1 - Hosts: Reset contents to default
O2 - HKLM\..\BHO: GBHO.BHO - {45d30484-7ded-43d9-957a-d2fd1f046511} - C:\WINDOWS\system32\mscoree.dll (sign: 'Microsoft')
O3 - HKLM\..\Toolbar: Smart Backup - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\WINDOWS\system32\mscoree.dll (sign: 'Microsoft')
O4 - ActiveSetup: HKLM\..\{3961E42E-3903-431D-8DB3-B786F8AED2F7}: [StubPath] = "C:\Users\user\AppData\Local\360extremebrowser\Chrome\Application\22.3.5068.64\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level (file missing)
O4 - HKCU\..\StartupApproved\Run: [InputMapper] = C:\Program Files (x86)\DSDCS\InputMapper 1.7\InputMapper.exe (file missing) (2025/03/17)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations2] = *2\??\C:\Users\user\AppData\Local\Temp\98F0E2C0-1D4E01FC-FD715CB4-D993077C\ZjhahLtqiq -> DELETE (file missing)
O4 - MountPoints2: HKCU\..\{77ac6aa1-9f36-11ef-b865-feb0de73cc23}\shell\AutoRun\command: (default) = H:\setup.exe (file missing)
O7 - Policy: HKLM\Software\Microsoft\Windows Defender\Features: [TamperProtection] = 4
O7 - Policy: HKLM\Software\Microsoft\Windows Defender\Real-Time Protection: [DisableRealtimeMonitoring] = 1
O22 - Tasks: \MaintenanceSystemApps\MaintenanceUninstalledSystemApps - C:\WINDOWS\System32\cmd.exe /d /q /e:on /v:on /c "chcp 65001>nul&set err=0&set key=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore&(for /f "tokens=1* delims=" %I in ('^(reg.exe query !key!\InboxApplications^®.exe query !key!\UpdatedApplications^)^|findstr /ir "\\Microsoft\.MicrosoftEdgeDevToolsClient_ \\Microsoft\.Windows\.ContentDeliveryManager_"')do reg.exe delete "%I" /f >nul 2>&1||set err=1)&(exit !err!)" (sign: 'Microsoft')
O22 - Tasks: EdgeUpdate - C:\WINDOWS\system32\cmd.exe /c auditpol /set /category:"Система" /success:enable && auditpol /set /category:"Подробное отслеживание" /subcategory:"Создание процесса" /success:enable (sign: 'Microsoft')
O22 - Tasks: EdgeUpdateTaskUser - C:\Windows\System32\wscript.exe /b "C:\ProgramData\Microsoft\wext.vbs" (sign: 'Microsoft')
O22 - Tasks: MaintenanceUninstalledSystemApps - C:\WINDOWS\System32\cmd.exe /d /q /e:on /v:on /c "chcp 65001>nul&set err=0&set key=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore&(for /f "tokens=1* delims=" %I in ('^(reg.exe query !key!\InboxApplications^®.exe query !key!\UpdatedApplications^)^|findstr /ir "\\Microsoft\.Windows\.ContentDeliveryManager_"')do reg.exe delete "%I" /f >nul 2>&1||set err=1)&(exit !err!)" (sign: 'Microsoft')
O22 - Tasks: perceive-throne - C:\ProgramData\quality-tidings\bin.exe /H (file missing)
O22 - Tasks: survive-thunder - C:\ProgramData\powerful-warrior\bin.exe /H (file missing)
O22 - Tasks_Migrated: \MaintenanceSystemApps\MaintenanceUninstalledSystemApps - C:\WINDOWS\System32\cmd.exe /d /q /e:on /v:on /c "chcp 65001>nul&set err=0&set key=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore&(for /f "tokens=1* delims=" %I in ('^(reg.exe query !key!\InboxApplications^®.exe query !key!\UpdatedApplications^)^|findstr /ir "\\Microsoft\.MicrosoftEdgeDevToolsClient_ \\Microsoft\.Windows\.ContentDeliveryManager_"')do reg.exe delete "%I" /f >nul 2>&1||set err=1)&(exit !err!)" (sign: 'Microsoft')
O22 - Tasks_Migrated: EdgeUpdate - C:\WINDOWS\system32\cmd.exe /c auditpol /set /category:"Система" /success:enable && auditpol /set /category:"Подробное отслеживание" /subcategory:"Создание процесса" /success:enable (sign: 'Microsoft')
O22 - Tasks_Migrated: EdgeUpdateTaskUser - C:\Windows\System32\wscript.exe /b "C:\ProgramData\Microsoft\wext.vbs" (sign: 'Microsoft')
O22 - Tasks_Migrated: MaintenanceUninstalledSystemApps - C:\WINDOWS\System32\cmd.exe /d /q /e:on /v:on /c "chcp 65001>nul&set err=0&set key=HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\AppxAllUserStore&(for /f "tokens=1* delims=" %I in ('^(reg.exe query !key!\InboxApplications^®.exe query !key!\UpdatedApplications^)^|findstr /ir "\\Microsoft\.Windows\.ContentDeliveryManager_"')do reg.exe delete "%I" /f >nul 2>&1||set err=1)&(exit !err!)" (sign: 'Microsoft')
O22 - Tasks_Migrated: RunGame - C:\Program Files\Client Helper\Client Helper.exe /schtask
O23 - Service S2: CsaMspAgnt_e7f35f - (CsaMspSvc_23b0a3) - C:\WINDOWS\SysWOW64\svchost.exe -k DcomLaunch; "ServiceDll" = C:\WINDOWS\SysWOW64\csamsp.dll (file missing)
Malwarebytes периодически находит не желательные файлы
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
HKLM\ DisallowedCertificates: 47D92D49E6F7F296260DA1AF355F941EB25360C4 (U)
HKLM\ DisallowedCertificates: EE45853E5C81DB8FDBB7F92C18B20972C744911C (U)
HKU\S-1-5-21-705177890-1147294348-2339927788-1001\...\MountPoints2: {77ac6aa1-9f36-11ef-b865-feb0de73cc23} - "H:\setup.exe"
GroupPolicy: Ограничение - Windows Defender <==== ВНИМАНИЕ
Policies: C:\ProgramData\NTUSER.pol: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Edge: Ограничение <==== ВНИМАНИЕ
CHR HKU\S-1-5-21-705177890-1147294348-2339927788-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ldgpjdiadomhinpimgchmeembbgojnjk]
CHR HKU\S-1-5-21-705177890-1147294348-2339927788-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ndidogegapfaolpcebadjknkdlladffa]
YAN DefaultSearchURL: Default -> hxxps://find-it.pro/search?utm_source=extension&q={searchTerms}
YAN DefaultSearchKeyword: Default -> find-it.pro
YAN DefaultSuggestURL: Default -> hxxps://find-it.pro/search/suggest.php?q={searchTerms}
C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\npiclhkkbgabhapklngkpahnaafkgpne
C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\odbmjgikedenicicookngdckhkjbebpd
U4 npcap_wifi; отсутствует ImagePath
2025-03-20 21:24 - 2025-03-20 21:24 - 000000000 ____D C:\ProgramData\XdbbnlBJHVLDfPX
2025-03-16 12:30 - 2025-04-06 15:01 - 000000000 ____D C:\Program Files\Client Helper
2025-03-16 12:41 - 2024-09-21 22:18 - 000014803 _____ C:\Users\user\ex-list2.json
2025-03-31 17:01 C:\Program Files\RDP Wrapper
2025-03-31 17:01 C:\ProgramData\RDP Wrapper
2025-03-31 17:01 C:\ProgramData\Setup
2025-03-31 17:01 C:\ProgramData\Windows Tasks Service
2025-03-31 17:01 C:\ProgramData\WindowsTask
Chunk Victim Lock 4.5.6.847 (HKLM-x32\...\{dfd2a276-4b0a-46f8-aa0e-35c3549b2544}) (Version: 4.5.6.847 - Barrientos y Redondo e Hija e Hija) Hidden
Link Reflector 4.9.67.184 (HKLM-x32\...\{9f36d5c1-6a6f-476f-958c-5b4a6212f182}) (Version: 4.9.67.184 - Terry-Gibson Ltd) Hidden
Notes Keep Sticky Thoughts in Google Drive 1.0.0.0 (HKU\S-1-5-21-705177890-1147294348-2339927788-1001\...\{e21fc34f-5740-4f68-9173-da8050a36214}) (Version: 1.0.0.0 - Notes Keep Sticky Thoughts in Google Drive) Hidden
ShellServiceObjects: Нет имени -> {C2796011-81BA-4148-8FCA-C6643245113F} =>
CustomCLSID: HKU\S-1-5-21-705177890-1147294348-2339927788-1001_Classes\CLSID\{0002DF01-0000-0000-C000-000000000046}\localserver32 -> "C:\Users\user\AppData\Local\360extremebrowser\Chrome\Application\360extremebrowser.exe" => Нет файла
ContextMenuHandlers1: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-81F6612BB909} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17 (2)\x64\shellex.dll -> Нет файла
ContextMenuHandlers1: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-AE912144D3DA} => -> Нет файла
ContextMenuHandlers2: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-81F6612BB909} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17 (2)\x64\shellex.dll -> Нет файла
ContextMenuHandlers2: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-AE912144D3DA} => -> Нет файла
ContextMenuHandlers4: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-81F6612BB909} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17 (2)\x64\shellex.dll -> Нет файла
ContextMenuHandlers4: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-AE912144D3DA} => -> Нет файла
ContextMenuHandlers6: [Kaspersky Free 21.17] -> {0F574355-9FBE-40DB-ACB8-81F6612BB909} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17 (2)\x64\shellex.dll -> Нет файла
ContextMenuHandlers6: [Kaspersky Standard 21.18] -> {2962565E-CA75-4BF1-B282-AE912144D3DA} => -> Нет файла
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Zip: C:\FRST\Quarantine
EmptyTemp:
Reboot:
End::
Chunk Victim Lock 4.5.6.847
Client Helper 6.2.1
IObit Driver Booster 12.2.0.542
Link Reflector 4.9.67.184
Notes Keep Sticky Thoughts in Google Drive 1.0.0.0