Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
ImageCropResize
Unity Web Player
ZetaGames
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('C:\Windows\System32\Ea3Host.exe');
TerminateProcessByName('c:\windows\microsoft\svchost.exe');
TerminateProcessByName('C:\Users\арсений\AppData\Roaming\svchost.exe');
TerminateProcessByName('C:\Windows\Microsoft\svchost.exe.exe');
QuarantineFile('C:\Users\арсений\AppData\Roaming\WindowsUpdater\Updater.exe','');
QuarantineFile('C:\Users\арсений\AppData\Roaming\WindowsUpdater','');
QuarantineFile('C:\Windows\System32\Ea3Host.exe','');
QuarantineFile('c:\windows\microsoft\svchost.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Roaming\svchost.exe', '');
QuarantineFile('C:\Windows\Microsoft\svchost.exe.exe', '');
QuarantineFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Roaming\Adobe\NativePlugin\OOBA\PPAPI\F60F0BB5-5177-40B9-9839-F6CD9F17D997\46B3EA92-AEC0-4CD9-9193-2B7381F7AC49.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Local\Microsoft\Extensions\extsetup.exe', '');
QuarantineFile('C:\Program Files (x86)\Common Files\11316257-9926-458C-A1D7-6118D36CC139\4383379E-2D29-4E21-83CC-E12097B00117.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Local\Microsoft\4B142EE006E51C3FBDFCEF2ABF5D542F\49974B8C822D2B5CF096DB2A02B0B5A6.exe', '');
QuarantineFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Roaming\Microsoft\msi.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Local\SystemDir\nethost.exe', '');
QuarantineFile('C:\Users\арсений\appdata\local\wupdate\wupdate.exe', '');
QuarantineFileF('c:\program files (x86)\kinoroom browser', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\арсений\appdata\roaming\adobe\nativeplugin\ooba\ppapi\f60f0bb5-5177-40b9-9839-f6cd9f17d997', '*', true, '', 0 ,0);
QuarantineFileF('c:\users\арсений\appdata\local\microsoft\extensions', '*', true, '', 0 ,0);
QuarantineFileF('c:\programdata\krb updater utility', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFileF('c:\users\арсений\appdata\local\systemdir', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
ExecuteFile('schtasks.exe', '/delete /TN "Kinoroom Browser" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\B0B5A620A2BD690FC5B2D228C849974B" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\extsetupSB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\KRBUUS\KRB Updater Utility Service" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\KRBUUS\KRBLNKRUN" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "A4383379E-2D29-4E21-83CC-E12097B00117" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\AF60F0BB5-5177-40B9-9839-F6CD9F17D997" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\B0B5A620A2BD690FC5B2D228C849974B" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "Microsoft\Windows\extsetupSB" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ATWURM" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "ATWURM_OL" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "WindowsUpdater" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "wupdate" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MSI" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "nethost task" /F', 0, 15000, true);
DeleteFile('C:\Windows\System32\Ea3Host.exe','32');
DeleteFile('C:\Users\арсений\AppData\Roaming\WindowsUpdater','32');
DeleteFile('C:\Users\арсений\AppData\Roaming\WindowsUpdater\Updater.exe','32');
DeleteFile('c:\windows\microsoft\svchost.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Roaming\svchost.exe', '32');
DeleteFile('C:\Windows\Microsoft\svchost.exe.exe', '32');
DeleteFile('C:\Program Files (x86)\Kinoroom Browser\krbrowser.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Roaming\Adobe\NativePlugin\OOBA\PPAPI\F60F0BB5-5177-40B9-9839-F6CD9F17D997\46B3EA92-AEC0-4CD9-9193-2B7381F7AC49.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Local\Microsoft\Extensions\extsetup.exe', '32');
DeleteFile('C:\Program Files (x86)\Common Files\11316257-9926-458C-A1D7-6118D36CC139\4383379E-2D29-4E21-83CC-E12097B00117.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Local\Microsoft\4B142EE006E51C3FBDFCEF2ABF5D542F\49974B8C822D2B5CF096DB2A02B0B5A6.exe', '32');
DeleteFile('C:\ProgramData\KRB Updater Utility\krbupdater.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Roaming\Microsoft\msi.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Local\SystemDir\nethost.exe', '32');
DeleteFile('C:\Users\арсений\appdata\local\wupdate\wupdate.exe');
DeleteService('SvcHost Service Host');
DeleteFileMask('c:\program files (x86)\kinoroom browser', '*', true);
DeleteFileMask('c:\users\арсений\appdata\local\microsoft\extensions', '*', true);
DeleteFileMask('c:\programdata\krb updater utility', '*', true);
DeleteFileMask('c:\users\арсений\appdata\local\systemdir', '*', true);
DeleteDirectory('c:\program files (x86)\kinoroom browser');
DeleteDirectory('c:\programdata\krb updater utility');
DeleteDirectory('c:\users\арсений\appdata\local\systemdir');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','Kinoroom Browser');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','F60F0BB5-5177-40B9-9839-F6CD9F17D997');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','extsetupSB');
RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run','AppDownloads');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
MediaGet
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantine;
QuarantineFileF('c:\users\арсений\appdata\local\systemdir', '*.exe, *.dll, *.sys, *.bat, *.vbs, *.js*, *.tmp*', true, '', 0 ,0);
QuarantineFile('C:\Users\арсений\AppData\Roaming\Microsoft\msi.exe', '');
QuarantineFile('C:\Users\арсений\AppData\Local\SystemDir\nethost.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "MSI" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "nethost task" /F', 0, 15000, true);
DeleteFile('C:\Users\арсений\AppData\Roaming\Microsoft\msi.exe', '32');
DeleteFile('C:\Users\арсений\AppData\Local\SystemDir\nethost.exe', '32');
DeleteFileMask('c:\users\арсений\appdata\local\systemdir', '*', true);
DeleteDirectory('c:\users\арсений\appdata\local\systemdir');
ExecuteSysClean;
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
Start::
CreateRestorePoint:
() C:\Users\арсений\AppData\Roaming\nssm.exe
HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-3922765855-2569331851-42374664-1001\...\MountPoints2: {2f8d5d90-1536-11e5-825b-806e6f6e6963} - "E:\Shell\CB.exe"
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
U2 clr_optimization_v1.02; C:\Users\арсений\AppData\Roaming\nssm.exe [294912 2014-08-31] () [File not signed]
2017-08-03 09:19 - 2017-08-03 09:19 - 000000000 ____D C:\Users\арсений\AppData\Local\ZaxarGameBrowser
2017-08-03 09:14 - 2017-08-03 09:06 - 000969024 _____ C:\Windows\system32\Ea3Host.exe
2017-08-03 09:14 - 2017-08-03 09:14 - 000003594 _____ C:\Windows\System32\Tasks\ifgker
2017-08-03 08:55 - 2017-08-03 08:55 - 000003374 __RSH C:\Windows\System32\Tasks\MSI
C:\Users\арсений\AppData\Roaming\nssm.exe
Task: {5807B774-BB83-4EB7-97C0-6AAC4935A79B} - System32\Tasks\ifgker => C:\Users\арсений\AppData\Local\ifgker\ifgker.exe <==== ATTENTION
Task: {58D2DE7C-714C-49C8-B6F9-4204819029C5} - System32\Tasks\AudioHD => C:\ProgramData\taskmnr\taskmnr.exe <==== ATTENTION
Task: {E4345BC1-054C-414F-8C14-B5809770A52C} - System32\Tasks\MSI => C:\Users\арсений\AppData\Roaming\Microsoft\msi.exe
Task: {ECE78C94-EEA1-40A2-AB90-2C4EF299647D} - System32\Tasks\nethost task => C:\Users\арсений\AppData\Local\SystemDir\nethost.exe <==== ATTENTION
Task: {FED9220A-C226-4174-BAC6-5F31CB22BEE8} - System32\Tasks\Microsoft\Windows\A4383379E-2D29-4E21-83CC-E12097B00117 => C:\Program Files (x86)\Common Files\11316257-9926-458C-A1D7-6118D36CC139\4383379E-2D29-4E21-83CC-E12097B00117.exe <==== ATTENTION
Task: {D63D6241-579D-4F7A-8892-9610497B21E5} - System32\Tasks\Microsoft\Windows\B0B5A620A2BD690FC5B2D228C849974BRunOnce => C:\Users\арсений\AppData\Local\Microsoft\4B142EE006E51C3FBDFCEF2ABF5D542F\49974B8C822D2B5CF096DB2A02B0B5A6.exe
EmptyTemp:
Reboot:
End::
Не вижу логов.После повторите логи FRST
McAfee Security Scan Plus [2017/07/11 11:48:57]-->"C:\Program Files\McAfee Security Scan\uninstall.exe"
Кнопка "Яндекс" на панели задач [2016/07/31 19:23:02]-->C:\Users\арсений\AppData\Local\Yandex\yapin\YandexWorking.exe --uninstall --nopinned
Менеджер браузеров [2016/12/17 19:20:18]-->"C:\Users\арсений\AppData\Local\Package Cache\{a7c1813c-6b3f-480b-96d6-eafe9f12caac}\BrowserManagerInstaller.exe" /uninstall
Менеджер браузеров [20161217]-->MsiExec.exe /X{36E317A1-1384-4FC5-92CD-D4731B651859}