;uVS v3.83 [http://dsrt.dyndns.org]
;Target OS: NTv6.1
OFFSGNSAVE
bl 39DC2B7A667276603629849BE89DADEE 6204136
addsgn 1AB2B79A5583C58CF42B254E3143FE86C99A5DC6C5A71F4B404A8040DB83691F10CC95000586E356A0C590148C5F71E209D7A8499EAF46AFE4882FEDECC76A48 8 mail_upd
bl EDAA8A0C07B2F379950FE1F0432C10B7 259592
addsgn 7300F79B556A1F275DE775E6ED94361DE2CED8E6E96B5F78B63503F874C251B33627B3173E3D9CC92B807B8AF66609FA2E20FD0E279AB04625D49C408306CA82 8 Win32/BrowseFox.C [ESET]
addsgn 1A92A49A5583338CF42B627DA804DEC9E946303A4536D32FD348B198405D3D68379CBF7332DE5CC2FA8342A4B86041C185D06A1A56DAB0239752A8F581062300 8 Win32/ELEX.AV [ESET]
bl 146BF1C1D613AC15F1AC900D3BBE02E7 702344
addsgn 1A8B8D9A5583338CF42BFB3A88434711AEC7F4A00C286A75000AB0B1699B7D39022403BC10D0543D320BC193C3D63DE8F80D9D76DDCB5BC5A602B4AA317335B5 8 Win32/ELEX.AM [ESET]
bl BA4DA4299310F4A54CBBA25221072D70 535936
addsgn 79132211B982F18DF42BF3580698EDFAE946883789FA1F7885C3C5BC50D6CD88231703F73E5529892B80849F461649FA7DDFFAB755DAB08C2D7748EFC7062273 64 Trojan.BPlug.123 [DrWeb]
zoo %Sys32%\DRIVERS\{57F143AE-1ECD-493D-9DDB-32C45A3CECD5}GW.SYS
bl 1F20D46FAD74AB7EF090DC1D579A4174 52920
zoo %Sys32%\DRIVERS\{6FCD6092-9615-4F7F-8898-8DF53980E5D2}GW.SYS
bl A57D04466B0EE2796F22556B12694FF2 52920
zoo %Sys32%\DRIVERS\{6FCD6092-9615-4F7F-8898-8DF53980E5D2}W.SYS
bl 33A0A71D609493ACA05050F309F7F7B0 52920
zoo %Sys32%\DRIVERS\{C5E48979-BD7F-4CF7-9B73-2482A67A4F37}W.SYS
bl 26FDF13D16D8388D9DCC5E9637E81E25 52368
chklst
delvir
bl 6F20ED8290135F1FA9CF2A5C2AE28DD6 323312
delall %SystemDrive%\PROGRAM FILES\CLEARTHINK\UPDATECLEARTHINK.EXE
delall %SystemDrive%\PROGRAM FILES\CLEARTHINK\BIN\UTILCLEARTHINK.EXE
deldir %SystemDrive%\PROGRAM FILES\CLEARTHINK
delref CDN.SHAREDADDOMAIN2.COM
delref HTTP://APIUSECLEARTHINK-A.AKAMAIHD.NET/GSRS?IS=ISGIWHRU&BP=PB&G=00000000-0000-0000-0000-000000000000
delref HTTP://GO.MAIL.RU/SEARCH?FR=NTG&Q=
delref HTTP://MAIL.RU/CNT/10445?GP=OPENPR2
delref HTTP://UFIRSTPAGE.COM/
delref HTTP://WWW.SWEET-PAGE.COM/WEB/?TYPE=DS&TS=1406580873&FROM=COR&UID=HITACHIXHDS5C3020ALA632_ML2220F30VRHSE0VRHSEX&Q={SEARCHTERMS}
delref HTTP://WWW.YANDEX.RU/?WIN=130&CLID=1985535
deltmp
delnfr
czoo
restart