.
. virusinfo_syscheck.zip AVZ .
. . :(
:
150502_145429_virus_5544ace554940.zip
39969
MD5 7cee0b25d2cc74ec09e2ae10a5805f31
Printable View
.
. virusinfo_syscheck.zip AVZ .
. . :(
:
150502_145429_virus_5544ace554940.zip
39969
MD5 7cee0b25d2cc74ec09e2ae10a5805f31
() [B]Nail69[/B], !
VirusInfo.Info . . HiJackThis, [URL="http://virusinfo.info/pravila.html"] [/URL].
- [URL="http://virusinfo.info/content.php?r=113-virusinfo.info-donate"] [/URL].
[B][COLOR="#FF0000"]![/COLOR][/B] . , - .
- [url=http://virusinfo.info/forumdisplay.php?f=46] [/url] [url=http://virusinfo.info/content.php?r=136-pravila] [/url].
!
, [URL="http://virusinfo.info/showthread.php?t=130828"][B][/B] , [/URL].
[B][COLOR="#000080"]![/COLOR][/B] Windows Vista/7/8 AVZ . [URL="http://virusinfo.info/showthread.php?t=7239"] [/URL] ( - ):
[CODE]
begin
DeleteService('ccnfd_1_10_0_6');
StopService('WindowsMangerProtect');
DeleteService('WindowsMangerProtect');
TerminateProcessByName('c:\documents and settings\all users\application data\windowsmangerprotect\protectwindowsmanager.exe');
QuarantineFile('c:\documents and settings\all users\application data\windowsmangerprotect\protectwindowsmanager.exe','');
TerminateProcessByName('c:\documents and settings\nail\application data\acewebextension\updater\ace_web_extension.exe');
QuarantineFile('c:\documents and settings\nail\application data\acewebextension\updater\ace_web_extension.exe','');
DeleteFile('c:\documents and settings\nail\application data\acewebextension\updater\ace_web_extension.exe','32');
DeleteFile('c:\documents and settings\all users\application data\windowsmangerprotect\protectwindowsmanager.exe','32');
DeleteFile('C:\WINDOWS\system32\drivers\ccnfd_1_10_0_6.sys','32');
RegKeyParamDel('HKEY_CURRENT_USER','Software\Microsoft\Windows\CurrentVersion\Run','AceWebException');
ExecuteSysClean;
RebootWindows(true);
end.
[/CODE]
[B]![/B] . [URL="http://virusinfo.info/showthread.php?t=7239"] [/URL] :
[CODE]begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.[/CODE]
2 [B] [/B]
[url=http://virusinfo.info/pravila.html][/url] .2 3 .([color=Blue]virusinfo_syscheck.zip;hijackthis.log[/color])
[url=http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/][b]Farbar Recovery Scan Tool[/b][/url] [img]http://i.imgur.com/NAAC5Ba.png[/img] .
[b][/b]: , . , , . .
[list][*] . , [b]Yes[/b] .[*], [b]Optional Scan[/b] [i]"List BCD"[/i], [i]"Driver MD5"[/i] [i]"90 Days Files"[/i].[*] [b]Scan[/b].[*] ([b]FRST.txt[/b]) , . , .[*] , ([b]Addition.txt[/b]). , .[/list]
[img]http://i.imgur.com/3munStB.png[/img]
:(
AVZ. :(
[list][*] [b]fixlist.txt[/b] Farbar Recovery Scan Tool:
[code]
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1482476501-1958367476-682003330-1004\...\Run: [AdobeBridge] => [X]
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1422533236&from=cor&uid=WDCXWD3200BPVT-80JJ5T0_WD-WXM1EC1FMXFKFMXFK&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422533236&from=cor&uid=WDCXWD3200BPVT-80JJ5T0_WD-WXM1EC1FMXFKFMXFK&q={searchTerms}
FF Extension: Slick Savings - C:\Documents and Settings\Nail\Application Data\Mozilla\Firefox\Profiles\viz3r0c8.НАИЛЬ\Extensions\{54FBE89E-C878-46bb-A064-AB327EE26EBC} [2015-03-17]
FF Extension: Start Page - C:\Documents and Settings\Nail\Application Data\Mozilla\Firefox\Profiles\viz3r0c8.НАИЛЬ\Extensions\{62DD0A97-FDD4-421b-94A5-D1A9434450C7} [2015-03-17]
FF Extension: Ebay Shopping Assistant by Spigot - C:\Documents and Settings\Nail\Application Data\Mozilla\Firefox\Profiles\viz3r0c8.НАИЛЬ\Extensions\{CA8C84C6-3918-41b1-BE77-049B2BDD887C} [2015-03-17]
c:\documents and settings\all users\application data\windowsmangerprotect
EmptyTemp:
[/code][*] FRST [b]Fix[/b] . - ([b]Fixlog.txt[/b]). , ![*] , [b][/b].[/list]
.
.
:
[LIST][*] : [B]1[/B][*] : [B]1[/B][*] [/LIST]