. 1 ... 3 4 5 6 7 8 9 10 11 12 13 ... 1649 .
, WannaCash
@Deonis Andersen,
, [B] thyrex[/B]
https://twitter.com/thyrex2002/status/1023134444536913920
,
Danya Zozulya :
, ? eset
x64: https://download.eset.com/com/eset/apps/home/eis/windows/latest/eis_nt64.exe
x86: https://download.eset.com/com/eset/apps/home/eis/windows/latest/eis_nt32.exe

,
, .
,
. ESET, AVG (AVG AntiVirus FREE, AVG Secure Browser) Avast.
,
.ms13; .carcn; .btix; .gate; .love; .LDPR; .FREDD; .txt; .video; .wal; .MERS; .bat; .qbix; .aa1; .qbtex; .yG; .drweb; .plut; .jack; .DDOS; .cry; .4k; .TOR13; .good; .qbx; .beets; .zoh; .harma; .BSC; .kjh; .html; .HACK; .0day, Filecoder.Crysis / Encoder.3953 /Ransom.Win32.Crusis; r/n: info.hta
CrySis/Dharma,  :

[QUOTE].cesar; .arena; .cobra; .java; .write; .arrow; .bip; .cmb/.combo; .brrr; .gamma; .monro; .bkp; .btc; .bgtx; .boost; .waifu; .FUNNY; .betta; .vanss; .like; .gdb; .xxxxx; .adobe; .tron; .AUDIT; .cccmn; .back; .Bear; .fire; .myjob; .war; .risk; .bkpx; .santa; .bizer; .gif; .auf; .USA; .xwx; .best; .heets; .qwex; .ETH; .air; .888; .amber; .frend; .KARLS; .aqva; .AYE; .korea; .plomb; .NWA; .com; .azero; .bk666; .stun; .ms13; .carcn; .btix; .gate; .love; .LDPR; .FREDD; .txt; .video; .wal; .MERS; .bat; .qbix; .aa1; .qbtex; .yG; .drweb; .plut; .jack; .DDOS; .cry; .4k; .TOR13; .good; .qbx; .beets; .zoh; .harma; .BSC; .kjh; .html; .HACK; 0day[/QUOTE]
TrojanDownloader
[QUOTE]20:50:01.0296 0x0720 TDSS rootkit removing tool 3.1.0.26 Jan 16 2019 18:20:35
20:50:08.0765 0x0720  ============================================================­
20:50:08.0765 0x0720  Current date / time: 2019/04/11 20:50:08.0765

20:51:04.0903 0x1344  ============================================================­
20:51:04.0903 0x1344  Scan finished
20:51:04.0903 0x1344  ============================================================­
20:51:04.0923 0x04d0  Detected object count: 0
20:51:04.0923 0x04d0  Actual detected object count: 0
20:51:16.0003 0x1354  Deinitialize success
[/QUOTE]
. 3.1.0.28
+
winpe&uVS
TrojanDownloader
[QUOTE] :
?? . )))))[/QUOTE]
tdsskiller.
.   , ,
, .

:
[QUOTE]2019-04-10 11:43 - 2019-04-10 11:44 - 000186304 _____ C:\TDSSKiller.3.1.0.26_10.04.2019_11.43.24_log.txt
2019-04-10 02:25 - 2019-04-10 02:32 - 000186306 _____ C:\TDSSKiller.3.1.0.26_10.04.2019_02.25.24_log.txt
2019-04-10 02:22 - 2019-04-10 02:24 - 000186304 _____ C:\TDSSKiller.3.1.0.26_10.04.2019_02.22.53_log.txt
[/QUOTE]

+
winpe&uVS
iso
https://chklst.ru/discussion/61/winpe-uvs

winpe&uVS
https://forum.esetnod32.ru/forum27/topic2102/
TrojanDownloader
+
tdsskiller
http://media.kaspersky.com/utilities/VirusUtilities/RU/tdsskiller.exe
(...)
[ ] Eset http://addr.cx/, ?
uVS:
- ;
- uVS(start.exe), : , - - ;
- ;
- _ ""
[code]

;uVS v4.1.4 [http://dsrt.dyndns.org]
;Target OS: NTv10.0
v400c
OFFSGNSAVE
;------------------------autoscript---------------------------

delref {D5FEC983-01DB-414A-9456-AF95AC9ED7B5}\[CLSID]
delref HTTP://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DCNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH%26INSTALLSOURCE%3D­ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DEBKGAJJADGOJJKGACFGJPNPGAGPECPJP%26INSTALLSOURCE%3D­ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DFPPJHFCGNALGFIIMDFLMIKPIFODNDLJF%26INSTALLSOURCE%3D­ONDEMAND%26UC
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 10\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 10\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_1\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 2\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 2\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 3\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 3\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 4\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 4\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 5\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 5\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 6\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 6\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 6\EXTENSIONS\HMJKMJKEPDIJHOOJDOJKDFOHBDGMMHKI\3.1.19142.814_0\GOOGLE KEEP
delref HTTP://WWW.MYSTARTSEARCH.COM/?TYPE=HP&TS=1426593210&FROM=WPC&UID=WDCXWD10EZEX-00RKKA0_WD-WMC1S330805608056
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 7\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 7\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 8\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 8\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_0\GOOGLE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 9\EXTENSIONS\CNCGOHEPIHCEKKLOKHBHIBLHFCMIPBDH\1.2.9.0_0\  A
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\GOOGLE\CHROME\USE­R DATA\PROFILE 9\EXTENSIONS\GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI\1.7_1\GOOGLE
delref HTTP://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DDHDGFFKKEBHMKFJOJEJMPBLDMPOBFKFO%26INSTALLSOURCE%3D­ONDEMAND%26UC
delref HTTPS://CLIENTS2.GOOGLE.COM/SERVICE/UPDATE2/CRX?RESPONSE=REDIRECT&PRODVERSION=38.0&X=ID%3DLMJEGMLICAMNIMMFHCMPKCLMIGMMCBEH%26INSTALLSOURCE%3D­ONDEMAND%26UC
apply

; OpenAL
exec  C:\Program Files (x86)\OpenAL\OpenAL.exe" /U

deltmp
delref %SystemDrive%\PROGRAM FILES (X86)\MICROSOFT VISUAL STUDIO\2017\COMMUNITY\COMMON7\IDE\VSIXAUTOUPDATE.EXE
delref {9F2B0085-9218-42A1-88B0-9F0E65851666}\[CLSID]
delref {E984D939-0E00-4DD9-AC3A-7ACA04745521}\[CLSID]
delref {FE285C8C-5360-41C1-A700-045501C740DE}\[CLSID]
delref {9CDA66BE-3271-4723-8D35-DD834C58AD92}\[CLSID]
delref %SystemRoot%\SYSWOW64\MAPSTOASTTASK.DLL
delref %SystemRoot%\SYSWOW64\MAPSUPDATETASK.DLL
delref {DEF03232-9688-11E2-BE7F-B4B52FD966FF}\[CLSID]
delref %SystemDrive%\PROGRAM FILES (X86)\MSI AFTERBURNER\MSIAFTERBURNER.EXE
delref %SystemDrive%\USERS\BITPORT1\APPDATA\LOCAL\MICROSOFT\ONEDRIV­E\ONEDRIVESTANDALONEUPDATER.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\ZENNOLAB\RU\ZENNOPOSTER STANDARD\5.11.6.0\PROGS\ZENNOPOSTER.EXE
delref %SystemRoot%\SYSWOW64\PEERDISTSVC.DLL
delref %SystemRoot%\SYSWOW64\APPVETWCLIENTRES.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\MRXSMB.SYS
delref %SystemRoot%\SYSWOW64\W32TIME.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\NDIS.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\USBXHCI.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\SRV2.SYS
delref %SystemRoot%\SYSWOW64\RDPCORETS.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\HTTP.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\WINNAT.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\TCPIP.SYS
delref %SystemRoot%\SYSWOW64\UMPOEXT.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\VMBUSR.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\DMVSC.SYS
delref %SystemRoot%\SYSWOW64\IPHLPSVC.DLL
delref %SystemRoot%\SYSWOW64\CSCSVC.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\VMBKMCL.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\REFS.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\SPACEPORT.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\FVEVOL.SYS
delref %SystemRoot%\SYSWOW64\DRIVERS\AFD.SYS
delref %SystemRoot%\SYSWOW64\PNRPSVC.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\PACER.SYS
delref %SystemRoot%\SYSWOW64\HVHOSTSVC.DLL
delref %SystemRoot%\SYSWOW64\LSM.DLL
delref %SystemRoot%\SYSWOW64\DRIVERS\SYNTH3DVSC.SYS
delref {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\[CLSID]
delref {166B1BCA-3F9C-11CF-8075-444553540000}\[CLSID]
delref {19916E01-B44E-4E31-94A4-4696DF46157B}\[CLSID]
delref {233C1507-6A77-46A4-9443-F871F945D258}\[CLSID]
delref {4063BE15-3B08-470D-A0D5-B37161CFFD69}\[CLSID]
delref {CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}\[CLSID]
delref %SystemRoot%\SYSWOW64\IE4UINIT.EXE
delref H:\PROGRAMM\HTTPANALYZERFULLV7\FIREFOX\COMPONENTS
delref %SystemDrive%\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS\NPMEETINGJOINPLUGINOC.DLL
delref {1FBA04EE-3024-11D2-8F1F-0000F87ABD16}\[CLSID]
delref %SystemRoot%\SYSWOW64\BLANK.HTM
delref {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}\[CLSID]
delref {E6FB5E20-DE35-11CF-9C87-00AA005127ED}\[CLSID]
delref {32020A01-506E-484D-A2A8-BE3CF17601C3}\[CLSID]
delref {A470F8CF-A1E8-4F65-8335-227475AA5C46}\[CLSID]
delref {6351E20C-35FA-4BE3-98FB-4CABF1363E12}\[CLSID]
delref {4A7C4306-57E0-4C0C-83A9-78C1528F618C}\[CLSID]
delref %Sys32%\DRIVERS\VMBUSR.SYS
delref %Sys32%\DRIVERS\SCMDISK0101.SYS
delref %Sys32%\DRIVERS\UMDF\USBCCIDDRIVER.DLL
delref %SystemRoot%\INF\UNREGMP2.EXE
delref %Sys32%\BLANK.HTM
delref HELPSVC\[SERVICE]
delref MBAMSERVICE\[SERVICE]
delref SACSVR\[SERVICE]
delref TBS\[SERVICE]
delref VMMS\[SERVICE]
delref MESSENGER\[SERVICE]
delref RDSESSMGR\[SERVICE]
delref %Sys32%\DRIVERS\LGANDNETDIAG64.SYS
delref %Sys32%\DRIVERS\LGANDNETMODEM64.SYS
delref %Sys32%\DRIVERS\ATHUW8X.SYS
delref %Sys32%\DRIVERS\PCCSMCFDX64.SYS
delref %Sys32%\DRIVERS\VBAUDIO_CABLE64_WIN7.SYS
delref H:\PROGRAMM\NAVITEL NAVIGATOR UPDATE CENTER\NAVITELUPDATERSERVICE.EXE
delref %SystemDrive%\PROGRAM FILES\BLUESTACKS\BSTKSVC.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\MICROVIRT\MEMUHYPERV\MEMUPROXYSTUB.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.23\PSMACHINE_64.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\VIA\VIAUDIOI\VDECK\VDECK.EXE
delref %SystemDrive%\PROGRAM FILES\BLUESTACKS\BSTKC.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\MICROVIRT\MEMUHYPERV\MEMUC.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.32.7\PSMACHINE_64.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.5\PSMACHINE_64.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.17\PSMACHINE_64.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.7\PSMACHINE_64.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\BIGNOX\BIGNOXVM\RT\VBOXPROXYSTUB.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\BIGNOX\BIGNOXVM\RT\NOXVMC.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\BIGNOX\BIGNOXVM\RT\NOXVMSVC.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.3\PSMACHINE_64.DLL
delref %Sys32%\TETHERINGSETTINGHANDLER.DLL
delref %Sys32%\WBEM\WEMSAL_WMIPROVIDER (1).DLL
delref %SystemDrive%\PROGRAM FILES (X86)\MICROVIRT\MEMUHYPERV\MEMUSVC.EXE
delref %Sys32%\QUICKACTIONSPS.DLL
delref %SystemDrive%\PROGRAM FILES\BLUESTACKS\BSTKPROXYSTUB.DLL
delref %Sys32%\CHTADVANCEDDS.DLL
delref %SystemDrive%\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\DAO\DAO360.DLL
delref %SystemRoot%\SYSWOW64\SPEECH_ONECORE\COMMON\SPEECHRUNTIME.EXE
delref %SystemRoot%\SYSWOW64\TAPILUA.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.23\PSMACHINE.DLL
delref %SystemRoot%\SYSWOW64\LOCATIONFRAMEWORK.DLL
delref %SystemRoot%\SYSWOW64\MAPSBTSVCPROXY.DLL
delref %SystemRoot%\SYSWOW64\EAPPCFGUI.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.32.7\PSMACHINE.DLL
delref %SystemRoot%\SYSWOW64\LISTSVC.DLL
delref %SystemRoot%\SYSWOW64\AUTHHOSTPROXY.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.5\PSMACHINE.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.17\PSMACHINE.DLL
delref %SystemRoot%\SYSWOW64\WBEM\NLMCIM.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.7\PSMACHINE.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\BIGNOX\BIGNOXVM\RT\X86\NOXVMC-X86.DLL
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.3\PSMACHINE.DLL
delref %SystemRoot%\SYSWOW64\SPEECH_ONECORE\COMMON\SAPI_EXTENSIONS.DLL
delref %SystemRoot%\SYSWOW64\SMARTSCREEN.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.33.23\GOOGLEUPDATEBROKER.EXE
delref %SystemRoot%\SYSWOW64\GPSVC.DLL
delref %SystemRoot%\SYSWOW64\IDLISTEN.DLL
delref %SystemRoot%\SYSWOW64\WIFICONFIGSP.DLL
delref %SystemDrive%\PROGRAM FILES\COMMON FILES\SYSTEM\OLE DB\MSDAORA.DLL
delref J:\HTC_SYNC_MANAGER_PC.EXE
delref G:\LENOVO_SUITE.EXE
delref F:\AUTORUN.EXE
delref D:\MOTIV4G.EXE
delref F:\MOTIV4G.EXE
delref F:\SETUP.EXE
delref F:\4G_MOTIV.EXE
delref G:\AUTORUN.EXE
delref F:\HISUITEDOWNLOADER.EXE
delref K:\SETUP.EXE
delref I:\LENOVO_SUITE.EXE
delref I:\DRIVERPACK.EXE
delref L:\DRIVERPACK.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
delref {9B43B7B1-BF56-4708-81D2-332D708B0DD9}\[CLSID]
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ INSTALLSOFT EDITION.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\RF_INSTALLSOFT.RU.EXE
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\INSTALLSOFT\ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\INSTALLSOFT\ Ψ @MAIL.RU.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\INSTALLSOFT\ FACEBOOK.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ INSTALLSOFT EDITION.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ . . .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ . .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ ˨.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \-  . . .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ - ͨ.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \Ҩ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \.URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ - . . .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ . . .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ INSTALLSOFT EDITION 3.7\ \ .URL
delref %SystemDrive%\PROGRAM FILES (X86)\ZENNOLAB\RU\ZENNOPOSTER STANDARD\5.28.0.0\PROGS\ZENNOPOSTER.EXE
;-------------------------------------------------------------

restart
[/code]
, .
------------
,

http://forum.esetnod32.ru/forum9/topic10688/
, . .
ESETUninstaller,
. 1 ... 3 4 5 6 7 8 9 10 11 12 13 ... 1649 .