Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\WINDOWS\system32\MEMIO.SYS','');
QuarantineFile('C:\PROGRA~1\FOLDER~1\FGH32.dll','');
QuarantineFile('C:\WINDOWS\system32\drivers\xinstall.sys','');
DelBHO('{855F3B16-6D32-4fe6-8A56-BBB695989046}');
DelBHO('{18DF081C-E8AD-4283-A596-FA578C2EBDC3}');
BC_ImportQuarantineList;
BC_Activate;
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
1. Знакомо сам выставлял авто запускC:\WINDOWS\tasks\Быстрое решение проблем.job - знакомо?
Радмин сами устанавливали?
:Processes
explorer.exe
:Services
:Files
C:\WINDOWS\NV34763480.TMP
:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== FILES ==========
C:\WINDOWS\NV34763480.TMP moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02262009_184405
Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
QuarantineFile('C:\WINDOWS\system32\drivers\xinstall.sys','');
DeleteFile('C:\WINDOWS\system32\drivers\xinstall.sys');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
http://www.virustotal.com/ru/analisis/13533d10cc114e75c9ecd340052dd772
http://www.virustotal.com/ru/analisis/5b14cd1119a9169d261d140d94b6ac96
http://www.virustotal.com/ru/analisis/460a395bd63de854850f81a6ecc68a0c
http://www.virustotal.com/ru/analisis/20b5d252c864cb729af04fae0899025f
http://www.virustotal.com/ru/analisis/78de9c9c3fabe3ab915fe1293c2cd07b
http://www.virustotal.com/ru/analisis/acf86963f2586e970869f4dba5048b3c
http://www.virustotal.com/ru/analisis/32f042d4a1e5d2acc3a1780ed55a3ddf
O2 - BHO: (no name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
O3 - Toolbar: (no name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - (no file) O9 - Extra button: (no name) - {3CA1D406-30D8-4DBC-8EE6-0E2C05F78864} - (no file) (HKCU)
C:\Program Files\Outlook Express\msimn.cfg\volume.ini
C:\Program Files\Sony Setup\Vegas 7.0\mediamgr.dat\convert.ini
C:\Program Files\Microsoft SQL Server\80\tools.ico\user.ini
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\Program Files\Sony Setup\Vegas 7.0\mediamgr.dat\convert.ini\ChamClock.exe .','');
QuarantineFile('C:\Program Files\Sony\Vegas 7.0\video plug-ins.cfg\connect.ini\mirc.exe .','');
QuarantineFile('C:\Program Files\Radmin Viewer 3.0\addbacktrayicon.dat\channel.ini\StyleXP.exe .','');
QuarantineFile('C:\Program Files\QIP Infium\Smilies\qip infium smilies.log\read.ini\msmsgs.exe','');
QuarantineFile('C:\Program Files\Alcohol Soft\Alcohol 120\starwind.txt\info.ini\WinRAR.exe .','');
QuarantineFile('C:\Program Files\Alky for Applications\Libraries\manifest.dat\format.ini\wordpad.exe .','');
QuarantineFile('C:\Program Files\Common Files\GTK\GTK.dll\library.ini\Hcontrol.exe .','');
QuarantineFile('C:\Program Files\AIMP2\System\aimp_mmk.ini\perform.ini\Total.exe .','');
QuarantineFile('C:\Program Files\Microsoft SQL Server\80\tools.ico\user.ini\FineReader.exe .','');
QuarantineFile('C:\DOCUME~1\F085~1\LOCALS~1\Temp\aujasnkj.sys','');
QuarantineFile('C:\Program Files\Download Master\temp\dbans.txt.cfg\event.ini\WinRAR.exe','');
QuarantineFile('c:\program files\alcohol soft\alcohol 120\starwind.txt\info.ini\winrar.exe','');
QuarantineFile('c:\program files\download master\temp\dbans.txt.cfg\event.ini\winrar.exe','');
QuarantineFile('c:\program files\alky for applications\documentation\manual.txt\result.ini\regetdx.exe','');
QuarantineFile('c:\program files\windows nt\accessories\mswrd6.ico\event.ini\miranda.exe','');
QuarantineFile('c:\program files\outlook express\msimn.cfg\volume.ini\calc.exe','');
QuarantineFile('c:\program files\sony\shared plug-ins\utilities.txt\message.ini\avp.exe','');
DeleteFile('c:\program files\sony\shared plug-ins\utilities.txt\message.ini\avp.exe');
DeleteFile('c:\program files\outlook express\msimn.cfg\volume.ini\calc.exe');
DeleteFile('C:\DOCUME~1\F085~1\LOCALS~1\Temp\aujasnkj.sys');
DeleteFile('kdzw.sys');
BC_ImportALL;
BC_Activate;
ExecuteSysClean;
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.