rukov Posted March 25, 2014 Report Share Posted March 25, 2014 Acum 2 zile am gasit balaria asta ca rula la mine in pc.Am incercat sa ii dau kill la proces si fericire blue screen folderu si fisierele erau ascunse.Folositi cu grija fisierele sunt infectateNew folder (2).zip — RGhost — file sharing Quote Link to comment Share on other sites More sharing options...
Maximus Posted March 25, 2014 Report Share Posted March 25, 2014 "If ProcessExists("avastui.exe") Then Sleep(20000)"If $fake = "fake3" ThenIf $delay = "3168468" ThenIf $mutex = "mutex3" ThenIf $startup = "3526264" ThenIf $antis = "antis3" ThenIf $botkiller = "botkiller3" ThenIf $downloader = "downloader3" ThenIf $uac = "uac3" ThenIf $systemrestore = "systemrestore3" ThenIf $antitask = "antitask3" ThenIf UBound(ProcessList($scriptname)) > 2 Then ExitIf NOT ($read_antitask = "1") ThenIf NOT ($read_uac = "0") ThenIf $buac = 0 ThenIf NOT FileExists($unicode_userprofile & "\" & $path & "\17472.vbs") ThenIf FileExists($unicode_startup & "\start.lnk") ThenIf @ERROR Then Return.. si lista continuapare a fi AutoIT, cred ca adevaratul cod se compileaza la primul RUN in functie de ce gaseste in PC (tip antivirusi/etc) Quote Link to comment Share on other sites More sharing options...