Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('C:\Programdata\ReaItekHD\taskhost.exe', '');
QuarantineFile('C:\ProgramData\ReaItekHD\taskhostw.exe', '');
QuarantineFile('C:\ProgramData\windowstask\audiodg.exe', '');
QuarantineFile('C:\ProgramData\windowstask\microsofthost.exe', '');
DeleteFile('C:\Programdata\ReaItekHD\taskhost.exe', '64');
DeleteFile('C:\Programdata\ReaItekHD\taskhostw.exe', '64');
DeleteFile('C:\ProgramData\windowstask\audiodg.exe', '32');
DeleteFile('C:\ProgramData\windowstask\microsofthost.exe', '32');
DeleteSchedulerTask('Microsoft\Windows\CheckGlobalR\RecoveryTask');
DeleteSchedulerTask('Microsoft\Windows\CheckGlobalR\xfQnWHZcVWT8fBXb');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'Software\Microsoft\Windows\CurrentVersion\Run', 'Realtek HD Audio', 'x64');
BC_ImportALL;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_Activate;
RebootWindows(true);
end.
begin
DeleteFile(GetAVZDirectory+'quarantine.7z');
ExecuteFile(GetAVZDirectory+'7za.exe', 'a -mx9 -pmalware quarantine .\Quarantine\*', 1, 300000, false);
end.
O4 - Autorun.inf: E:\autorun.inf - open - sources\SetupError.exe x64 (file missing)
O4 - Autorun.inf: K:\autorun.inf - open - sources\SetupError.exe x64 (file missing)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E897C3E-A9B3-4463-A1A5-ADB6EA9AA359} - \Microsoft\Windows\Wininet\winsers (no xml)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A200CD22-BFB6-44BF-ACE3-4F1716DF28B3} - \Microsoft\Windows\CheckGlobalR\RecoveryHosts (no xml)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB65E571-1C25-4F9B-83AD-CCD9B31B46AF} - \Microsoft\Windows\Wininet\winser (no xml)
O22 - Tasks: (damaged) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (user missing) (sign: 'Microsoft')
O22 - Tasks: (damaged) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (user missing) (sign: 'Microsoft')
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
CHR StartupUrls: Default -> "hxxp://www.yandex.ru/?win=55&clid=1787308","hxxp://mail.ru/cnt/7993/","hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={8A7EBD82-4B99-11E2-951A-54E6FC83B445}","hxxps://www.google.com/"
2023-08-30 01:13 - 2023-08-30 01:13 - 000000000 __SHD C:\ProgramData\princeton-produce
2023-08-30 01:13 - 2023-08-30 01:13 - 000000000 __SHD C:\Program Files\NETGATE
2023-08-30 01:13 - 2023-08-30 01:13 - 000000000 ____D C:\Program Files\CPUID
2023-08-30 01:13 - 2023-08-30 01:13 - 000000000 ____D C:\Program Files\7-Zip
2023-08-30 01:13 - 2023-08-30 01:13 - 000000000 ____D C:\Program Files (x86)\MSI
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::
проблема ушла после первого скрипта в AVZ и фиксов HijackThis. лишних папок в ProgramData, Program Files и Program Files (x86) нет.Что с проблемой?