rukov Posted March 25, 2014 Report Posted March 25, 2014 Acum 2 zile am gasit balaria asta ca rula la mine in pc.Am incercat sa ii dau kill la proces si fericire blue screen folderu si fisierele erau ascunse.Folositi cu grija fisierele sunt infectateNew folder (2).zip — RGhost — file sharing Quote
Maximus Posted March 25, 2014 Report Posted March 25, 2014 "If ProcessExists("avastui.exe") Then Sleep(20000)"If $fake = "fake3" ThenIf $delay = "3168468" ThenIf $mutex = "mutex3" ThenIf $startup = "3526264" ThenIf $antis = "antis3" ThenIf $botkiller = "botkiller3" ThenIf $downloader = "downloader3" ThenIf $uac = "uac3" ThenIf $systemrestore = "systemrestore3" ThenIf $antitask = "antitask3" ThenIf UBound(ProcessList($scriptname)) > 2 Then ExitIf NOT ($read_antitask = "1") ThenIf NOT ($read_uac = "0") ThenIf $buac = 0 ThenIf NOT FileExists($unicode_userprofile & "\" & $path & "\17472.vbs") ThenIf FileExists($unicode_startup & "\start.lnk") ThenIf @ERROR Then Return.. si lista continuapare a fi AutoIT, cred ca adevaratul cod se compileaza la primul RUN in functie de ce gaseste in PC (tip antivirusi/etc) Quote