Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\DOCUME~1\anton\LOCALS~1\Temp\mcjzmk.exe','');
QuarantineFile('C:\WINDOWS\system32\cda73942.exe','');
QuarantineFile('c:\recycler\s-1-5-21-5696832281-0176001093-571042467-2978\syscr.exe','');
DeleteFile('c:\recycler\s-1-5-21-5696832281-0176001093-571042467-2978\syscr.exe');
DeleteFile('C:\DOCUME~1\anton\LOCALS~1\Temp\mcjzmk.exe');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
gmer.exe -del service mtebj
gmer.exe -del file "C:\WINDOWS\system32\qmqyh.dll"
gmer.exe -del reg "HKLM\SYSTEM\CurrentControlSet\Services\mtebj"
gmer.exe -del reg "HKLM\SYSTEM\ControlSet002\Services\mtebj"
gmer.exe -reboot
....
И запустите сохранённый пакетный файл cleanup.bat.
....
Сделайте новый лог gmer
Получил результат анализа карантина:
syscr.exe - P2P-Worm.Win32.Palevo.aaso
gmer.exe -del service qzkgixpo
gmer.exe -del file "C:\WINDOWS\system32\qmqyh.dll"
gmer.exe -del reg "HKLM\SYSTEM\CurrentControlSet\Services\qzkgixpo"
gmer.exe -del reg "HKLM\SYSTEM\ControlSet002\Services\qzkgixpo"
gmer.exe -reboot
R3 - URLSearchHook: (no name) - {83821C2B-32A8-4DD7-B6D4-44309A78E668} - (no file)
R3 - URLSearchHook: (no name) - - (no file)