Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
begin
ClearQuarantine;
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk','');
QuarantineFile('C:\Users\Public\Desktop\Google Chrome.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\790a9b09c70e855d\Google Chrome.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex\Yandex.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru Агент.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Windows\SendTo\МойМир@Mail.ru.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru Агент.lnk','');
QuarantineFile('C:\Users\Максим\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Удалить Google Chrome.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Знакомства.lnk','');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nival\Prime World\Prime World.lnk','');
QuarantineFile('C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plarium\Game - Total Domination.lnk','');
QuarantineFile('C:\iexplore.bat','');
QuarantineFile('C:\Users\Mother\AppData\Local\Yandex\YandexBrowser\Application\browser.exe.bat','');
QuarantineFile('C:\Games\Prime World\PWLauncher.exe.bat','');
QuarantineFile('C:\Program Files\Google\Chrome\Application\chrome.exe.bat','');
QuarantineFile('C:\Users\Mother\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Mobogenie.url','');
DeleteFile('C:\Users\Mother\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Mobogenie.url','');
DeleteFile('C:\iexplore.bat','');
DeleteFile('C:\Users\Mother\AppData\Local\Yandex\YandexBrowser\Application\browser.exe.bat','');
DeleteFile('C:\Games\Prime World\PWLauncher.exe.bat','');
DeleteFile('C:\Program Files\Google\Chrome\Application\chrome.exe.bat','');
ExecuteRepair(3);
ExecuteRepair(4);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
end.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
C:\Users\Public\Desktop\Google Chrome.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\790a9b09c70e855d\Google Chrome.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex\Yandex.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru Агент.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\SendTo\МойМир@Mail.ru.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Mail.Ru Агент.lnk
C:\Users\Максим\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Удалить Google Chrome.lnk
C:\Users\Mother\AppData\Roaming\Знакомства.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nival\Prime World\Prime World.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plarium\Game - Total Domination.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\baidu\baidu.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up\PC Speed Up.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up\Деинсталлировать PC Speed Up.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Kinoroom Browser.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader\YTDownloader.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\storegid\storegid.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\storegid\Uninstall.lnk
C:\Users\Mother\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\Configure.lnk
C:\Users\Максим\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Kinoroom Browser.lnk
Пополните, пожалуйста, базу безопасных файлов антивирусной утилиты AVZ:
не поняла...... можно подробнее???-
Повторите логи по правилам. Для повторной диагностики запустите снова Autologger. В первом диалоговом окне нажмите ОК, удерживая нажатой клавишу Shift
что значит нету? Вы же в предыдущем посте мне его лог прикладывали.C:\AdwCleaner - нет вообще, через поиск пробовала, нет нашлось(((
вы это уже делали когда логи делали для создания темы (см. правила раздела). Просто теперь в первом окно нажмите Shift и так нажимайте Ок, там будет об этом подсказка.не поняла...... можно подробнее???
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFileF('C:\Program Files\Common Files\{21F0E466-68C8-4EFF-A28B-C52CFFDCACEA}\0.8', '');
QuarantineFile('C:\Windows\Fonts\Fap.dll', '');
QuarantineFile('C:\Windows\Fonts\FapCF.dll', '');
QuarantineFile('C:\Windows\Fonts\FapCF2.dll', '');
QuarantineFile('C:\Windows\Fonts\MiniObject.dll', '');
QuarantineFile('C:\Windows\Fonts\SynBozLib.dll', '');
QuarantineFileF('C:\Program Files\Common Files\{21F0E466-68C8-4EFF-A28B-C52CFFDCACEA}\0.8', '*', true, '', 0, 0);
QuarantineFile('C:\Windows\Fonts\FAPCFPACK.EXE', '');
QuarantineFile('C:\Windows\Fonts\iie9T2F6sl3bHjdKcBdlL6uA9N463W.EXE', '');
QuarantineFile('C:\Program Files\YTDownloader\updater.exe', '');
QuarantineFile('C:\Users\Mother\AppData\Roaming\HRFNKVG.exe', '');
QuarantineFile('C:\Users\Mother\AppData\Roaming\TSDI.exe', '');
QuarantineFile('C:\Users\Mother\AppData\Local\Microsoft\Windowssystem.vbs', '');
DeleteFileMask(' C:\Program Files\Common Files\{21F0E466-68C8-4EFF-A28B-C52CFFDCACEA}\0.8 ', '*', true);
DeleteFile('C:\Windows\Tasks\Registry Optimizer_DEFAULT.job', '32');
DeleteFile('C:\Users\Mother\AppData\Roaming\TSDI.exe', '32');
DeleteFile('C:\Windows\Tasks\TSDI.job', '32');
DeleteFile('C:\Users\Mother\AppData\Roaming\HRFNKVG.exe', '32');
DeleteFile('C:\Windows\system32\Tasks\HRFNKVG', '32');
DeleteFile('C:\Windows\system32\Tasks\kbrowser-updater-utility', '32');
DeleteFile('C:\Windows\system32\Tasks\TSDI', '32');
DeleteFile('C:\Windows\system32\Tasks\YTDownloaderUpd', '32');
DeleteFile('C:\Program Files\YTDownloader\updater.exe', '32');
DeleteFile('C:\Users\Mother\AppData\Roaming\Знакомства.lnk');
DeleteFile('C:\Windows\Fonts\FAPCFPACK.EXE', '32');
DeleteFile('C:\Windows\Fonts\iie9T2F6sl3bHjdKcBdlL6uA9N463W.EXE', '32');
DeleteFile('C:\Windows\Fonts\Fap.dll', '32');
DeleteFile('C:\Windows\Fonts\FapCF.dll', '32');
DeleteFile('C:\Windows\Fonts\FapCF2.dll', '32');
DeleteFile('C:\Windows\Fonts\MiniObject.dll', '32');
DeleteFile('C:\Windows\Fonts\SynBozLib.dll', '32');
BC_ImportALL;
ExecuteSysClean;
ExecuteRepair(2);
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
;uVS v3.84.3 [http://dsrt.dyndns.org]
;Target OS: NTv6.1
v384c
BREG
zoo %SystemDrive%\PROGRAM FILES\PDAPP\CSTART.BAT
dirzooex %SystemDrive%\PROGRAM FILES\PDAPP
bl 4E45B74DBACB69D2F0A61C165F674623 90
delall %SystemDrive%\PROGRAM FILES\PDAPP\CSTART.BAT
delref %SystemDrive%\USERS\MOTHER\APPDATA\LOCAL\SCREENTK\UNINSTALL.EXE
delref %SystemDrive%\USERS\MOTHER\APPDATA\ROAMING\MYSTARTSEARCH\UNINSTALLMANAGER.EXE
delref %SystemDrive%\USERS\MOTHER\APPDATA\LOCAL\SCREENTK\SCREENTOOL.EXE
zoo %SystemDrive%\USERS\MOTHER\APPDATA\LOCAL\MICROSOFT\EXTENSIONS\SAFEBROWSER.EXE
delref %SystemDrive%\USERS\MOTHER\APPDATA\ROAMING\MAIL.RU\AGENT\MAGENT.EXE
dirzoo %SystemDrive%\USERS\MOTHER\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DFLTUSER\EXTENSIONS\BDIGKPJBMBDEPGPKJEABFGHLCHDMPHKE\3.2_0
delref %SystemDrive%\USERS\MOTHER\APPDATA\ROAMING\HRFNKVG.EXE
delall %SystemDrive%\PROGRAM FILES\COMMON FILES\BAIDU\BAIDUPROTECT1.3\1.3.0.542\BAIDUPROTECT.EXE
zoo %SystemDrive%\USERS\МАКСИМ\DESKTOP\89514551820\CS1.6REALEDITION2011.EXE
bl 52CE66834117591A8C5DD48B5956C4A9 429376573
delall %SystemDrive%\USERS\МАКСИМ\DESKTOP\89514551820\CS1.6REALEDITION2011.EXE
uidel C:\Users\Mother\AppData\Roaming\mystartsearch\UninstallManager.exe -ptid=amt
uidel MsiExec.exe /I{D492942E-9368-48D9-BB8B-68E8E4CE2D43}
uidel MsiExec.exe /I{71D05F96-6AF4-4961-9E9C-AE4B8C9793E9}
; Java(TM) 6 Update 38
exec MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216038FF} /quiet
czoo
restart
O4 - HKCU\..\Run: [SystemScript] "C:\Users\Mother\AppData\Local\Microsoft\Windowssystem.vbs"
C:\Program Files\Common Files\{21F0E466-68C8-4EFF-A28B-C52CFFDCACEA}
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
StopService('BDMNetMon');
StopService('bd0002');
StopService('BDSafeBrowser');
StopService('bd0004');
StopService('bd0003');
StopService('bd0001');
DeleteFile('C:\Windows\system32\DRIVERS\bd0001.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0003.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0004.sys', '32');
DeleteFile('C:\Windows\system32\drivers\BDSafeBrowser.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\BDArKit.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\bd0002.sys', '32');
DeleteFile('C:\Windows\system32\DRIVERS\BDMNetMon.sys', '32');
DeleteFile('C:\ProgramData\Kbrowser utility\kbrowser-updater-utility.exe', '32');
DeleteFile('C:\Windows\Tasks\HRFNKVG.job', '32');
DeleteFile('C:\Windows\Tasks\Registry Optimizer_UPDATES.job', '32');
DeleteFile('C:\Windows\system32\Tasks\Registry Optimizer_UPDATES', '32');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\kbrowser-updater-utility.lnk');
DeleteFile('C:\Users\Mother\AppData\Roaming\HRFNKVG.exe', '32');
DeleteService('BDMNetMon');
DeleteService('bd0002');
DeleteService('BDSafeBrowser');
DeleteService('bd0004');
DeleteService('bd0003');
DeleteService('bd0001');
DeleteFileMask('C:\Program Files\Common Files\{21F0E466-68C8-4EFF-A28B-C52CFFDCACEA}', '*', true);
DeleteDirectory('C:\Program Files\Common Files\{21F0E466-68C8-4EFF-A28B-C52CFFDCACEA}');
DelBHO('{8DAE90AD-4583-4977-9DD4-4360F7A45C74}');
DelBHO('{91397D20-1446-11D4-8AF4-0040CA1127B6}');
DelBHO('{DBC80044-A445-435b-BC74-9C25C1C588A9}');
DelBHO('{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}');
DelBHO('{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
C:\Users\Public\Desktop\Google Chrome.lnk