Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 50000, false);
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\0.7796119840654661.exe','');
QuarantineFile('C:\WINDOWS\system32\22A.tmp','');
DeleteFile('C:\DOCUME~1\Admin\LOCALS~1\Temp\0.7796119840654661.exe');
DeleteFile('C:\WINDOWS\system32\22A.tmp');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','system');
RegKeyStrParamWrite('HKLM', 'Software\Microsoft\Windows NT\CurrentVersion\Windows', 'AppInit_DLLs', '');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
Зараженные файлы:
c:\WINDOWS\notepad.exe (Trojan.Agent) -> No action taken.
c:\WINDOWS\AppPatch\yiamdig.exe (Trojan.Apppatch) -> No action taken.
c:\WINDOWS\Temp\11A4.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\B83.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\CA0.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\3A.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\3A5.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\3D1.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\648.tmp (Trojan.Apppatch) -> No action taken.
c:\WINDOWS\Temp\68.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\872.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\28D.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\2AC.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\2C7.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\460.tmp (Trojan.Apppatch) -> No action taken.
c:\WINDOWS\Temp\47.tmp (Trojan.Apppatch) -> No action taken.
c:\WINDOWS\Temp\6FA.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\73F.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\936.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\345.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\34A.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\366.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\567.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\5B.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\5D.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\146.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\151.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\154.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\3E4.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\3F.tmp (Trojan.Apppatch.Gen) -> No action taken.
c:\WINDOWS\Temp\413.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\AA1.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\5E.tmp (Trojan.Apppatch.Gen) -> No action taken.
c:\WINDOWS\Temp\5F.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\61.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\61E.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\63.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\4C7.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\4D.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\4E8.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\4F.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\7ED.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\2F.tmp (Trojan.Apppatch.Gen) -> No action taken.
c:\WINDOWS\Temp\317.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\18B.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\19F.tmp (Trojan.Apppatch.Gen) -> No action taken.
c:\WINDOWS\Temp\1A7.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\6D7.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\52.tmp (Trojan.Apppatch.Gen) -> No action taken.
c:\WINDOWS\Temp\54.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\56.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\FB.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\1D2.tmp (Trojan.Apppatch.Gen) -> No action taken.
c:\WINDOWS\Temp\1E0.tmp (Spyware.Passwords.XGen) -> No action taken.
c:\WINDOWS\Temp\208.tmp (Spyware.Passwords.XGen) -> No action taken.
текст скопируйте и запостите сюда.c:\documents and settings\admin\local settings\temp\_uninst_43962913.bat
нажмите "Fix checked"O4 - Startup: _uninst_43962913.lnk = C:\Documents and Settings\Admin\Local Settings\Temp\_uninst_43962913.bat
??4. сделайте новый лог malwarebytes
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"d40819d1"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\43187385.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\43187385.sys]
RegLock::
[HKEY_USERS\S-1-5-21-436374069-651377827-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
Reboot::