Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
StopService('0302161496252842mcinstcleanup');
QuarantineFileF('c:\program files (x86)\kinoroom browser', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\programdata\krb updater utility', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('C:\Users\Roman\AppData\Roaming\win32taskhost\', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0, 0);
QuarantineFile('B:\Temp\030216~1.EXE', '');
QuarantineFile('C:\Windows\System32\ihctrl32.dll', '');
QuarantineFile('C:\Windows\System32\wsaudio.dll', '');
QuarantineFile('B:\Temp\DATA.cmd', '');
QuarantineFile('C:\Users\Public\0ld.C.Win7\0ld.D.DATA\Documents and Settings\Admin\Рабочий стол\Internet Explorer.lnk', '');
QuarantineFile('C:\Users\Public\0ld.C.Win7\0ld.D.DATA\Documents and Settings\Admin\Рабочий стол\Mozilla Firefox.lnk', '');
QuarantineFile('C:\Users\Public\0ld.C.Win7\0ld.D.DATA\Documents and Settings\Default User\Рабочий стол\Internet Explorer.lnk', '');
QuarantineFile('C:\Users\Public\0ld.C.Win7\0ld.D.DATA\Documents and Settings\Default User\Рабочий стол\Mozilla Firefox.lnk', '');
QuarantineFile('C:\Users\Public\0ld.C.Win7\0ld.D.DATA\Documents and Settings\User\Рабочий стол\Mozilla Firefox.lnk', '');
QuarantineFile('C:\Users\Dima\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk', '');
QuarantineFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '');
QuarantineFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '');
QuarantineFile('C:\Windows\system32\tasks\InternetAA', '');
QuarantineFile('C:\Windows\system32\tasks\InternetAE', '');
QuarantineFile('C:\Windows\system32\tasks\brandnewcoms', '');
QuarantineFile('C:\Windows\system32\tasks\httpbubskiv2rufreemanm', '');
ExecuteFile('schtasks.exe', '/delete /TN "brandnewcoms" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "httpbubskiv2rufreemanm" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "InternetAA" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "InternetAE" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Kinoroom Browser" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\KRBUUS\KRB Updater Utility Service" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\KRBUUS\KRBLNKRUN" /F', 0, 15000, true);
DeleteFile('B:\Temp\030216~1.EXE', '32');
DeleteFile('C:\Windows\System32\ihctrl32.dll', '32');
DeleteFile('C:\Windows\System32\wsaudio.dll', '32');
DeleteFile('B:\Temp\DATA.cmd', '32');
DeleteFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '32');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '32');
DeleteFileMask('c:\program files (x86)\kinoroom browser', '*', true);
DeleteFileMask('c:\programdata\krb updater utility', '*', true);
DeleteFileMask('C:\Users\Roman\AppData\Roaming\win32taskhost\', '*', true);
DeleteDirectory('C:\Users\Roman\AppData\Roaming\win32taskhost\');
DeleteDirectory('c:\program files (x86)\kinoroom browser');
DeleteDirectory('c:\programdata\krb updater utility');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','kjbwolrwrc');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\ihctrl32\Parameters','ServiceDll');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\wsaudio\Parameters','ServiceDll');
DeleteService('0302161496252842mcinstcleanup');
ExecuteSysClean;
ExecuteRepair(4);
ExecuteRepair(22);
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
перетащите на утилиту ClearLNK....\AutoLogger\CheckBrowserLnk
Отчет покажите:сделал очистку в AdwCleaner
отчет будет сохранен в следующем расположении: C:\AdwCleaner\AdwCleaner[Cx].txt
Start::
CreateRestorePoint:
() C:\Program Files (x86)\UCBrowser\Application\UCService.exe
AppInit_DLLs-x32: 婢Ȍ䵆汳 => No File
BHO: No Name -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File
BHO-x32: No Name -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File
Toolbar: HKU\S-1-5-21-1974309347-2533221104-2972174623-1001 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
CHR NewTab: Default -> Not-active:"chrome-extension://oelpkepjlgmehajehfeicfbjdiobdkfj/visual-bookmarks.html", Not-active:"chrome-extension://iflppbjnpneiigcbdfjpnkebidmkjmoi/visual-bookmarks.html", Not-active:"chrome-extension://bpgangmffjcofiknibcmfjionicohfgj/visual-bookmarks.html"
CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&product_id=%7B8B7EB09C-99AC-4CE7-92F5-1276A68A2D51%7D&gp=811041
CHR DefaultSearchKeyword: Default -> go.mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/ff3?q={searchTerms}
S2 ihctrl32; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (ServiceDLL not found)
S2 ihctrl32; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) <==== ATTENTION (ServiceDLL not found)
R2 UCBrowserSvc; C:\Program Files (x86)\UCBrowser\Application\UCService.exe [629648 2017-02-21] () <==== ATTENTION
C:\Users\TEMP\DATA.cmd
Task: {8E4FFC0B-2BCD-45CD-A4D1-22E621ECB3F7} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION
Task: C:\Windows\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION
FirewallRules: [{84A738BB-7170-4E78-951C-323A9408EA02}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
FirewallRules: [{C0480ABE-7E28-47E2-B9DF-B71792432D2E}] => (Allow) C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
EmptyTemp:
Reboot:
End::