Junior Member
Вес репутации
53
Вирус закодировал файлы
Добрый день,
Вирус закодировал файлы и теперь они имеют такой вид
[email protected] -CL 0.0.1.0.id-TZFLRXDIOUAGLRXCIOUZFMRXDIOUAFLRWDJO-21.05.2015 12@[email protected]
Возможно ли найти решение как их раскодировать бесплатным методом или нужно подписываться обязательно на услугу "помогите+"?
еще хотел добавить, что у меня нигде на компьютере нет файла lockdir.exe
Последний раз редактировалось Trampoline; 27.05.2015 в 08:54 .
Будь в курсе!
Будь в курсе!
Надоело быть жертвой? Стань профи по информационной безопасности, получай самую свежую информацию об угрозах и средствах защиты от ведущего российского аналитического центра Anti-Malware.ru:
Уважаемый(ая) Trampoline , спасибо за обращение на наш форум!
Помощь в лечении комьютера на VirusInfo.Info оказывается абсолютно бесплатно. Хелперы в самое ближайшее время ответят на Ваш запрос. Для оказания помощи необходимо предоставить логи сканирования утилитами АВЗ и HiJackThis, подробнее можно прочитать в правилах оформления запроса о помощи .
Если наш сайт окажется полезен Вам и у Вас будет такая возможность - пожалуйста поддержите проект .
Выполните скрипт в AVZ
Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
if not IsWOW64
then
begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
end;
DelBHO('{50F4150A-48B2-417A-BE4C-C83F580FB904}');
QuarantineFile('H:\iexplore.bat','');
QuarantineFile('H:\firefox.bat','');
DeleteService('TS888');
DeleteService('sysdrv32');
DeleteService('QMUdisk');
DeleteService('innfd_1_10_0_14');
DeleteService('abp470n5');
DeleteFile('H:\WINDOWS\system32\drivers\kmnrok.sys','32');
DeleteFile('H:\WINDOWS\system32\drivers\innfd_1_10_0_14.sys','32');
DeleteFile('H:\Program Files\Tencent\QQPCMgr\10.9.16349.225\QMUdisk.sys','32');
DeleteFile('H:\WINDOWS\system32\drivers\sysdrv32.sys','32');
DeleteFile('H:\Program Files\Tencent\QQPCMgr\10.9.16349.225\TS888.sys','32');
DeleteFile('H:\firefox.bat','32');
DeleteFile('H:\iexplore.bat','32');
DeleteFile('H:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll','32');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(false);
end.
Компьютер перезагрузится.
Пришлите карантин согласно Приложения 2 правил по красной ссылке Прислать запрошенный карантин над первым сообщением в Вашей теме.
Сделайте новые логи по правилам
Microsoft MVP 2012-2016 Consumer Security
Microsoft MVP 2016 Reconnect
Junior Member
Вес репутации
53
Скачайте Farbar Recovery Scan Tool и сохраните на Рабочем столе.
Примечание : необходимо выбрать версию, совместимую с Вашей операционной системой. Если Вы не уверены, какая версия подойдет для Вашей системы, скачайте обе и попробуйте запустить. Только одна из них запустится на Вашей системе.
Запустите программу двойным щелчком. Когда программа запустится, нажмите Yes для соглашения с предупреждением. Убедитесь, что в окне Optional Scan отмечены "List BCD" и "Driver MD5" .
Нажмите кнопку Scan . После окончания сканирования будет создан отчет (FRST.txt ) в той же папке, откуда была запущена программа. Пожалуйста, прикрепите отчет в следующем сообщении. Если программа была запущена в первый раз, будет создан отчет (Addition.txt ). Пожалуйста, прикрепите его в следующем сообщении.
Microsoft MVP 2012-2016 Consumer Security
Microsoft MVP 2016 Reconnect
Junior Member
Вес репутации
53
есть
https://yadi.sk/d/TLPsw7E6h2Qmm
https://yadi.sk/d/_-K7F-EVh2Qms
у меня переполнилось хранилище для вложений, как удалить старые файлы в нём?
Сообщение от
Trampoline
у меня переполнилось хранилище для вложений, как удалить старые файлы в нём?
Мой кабинет - Вложения и удаляете старые
Microsoft MVP 2012-2016 Consumer Security
Microsoft MVP 2016 Reconnect
Junior Member
Вес репутации
53
последние вложения нужно верно перезалить или так сойдет?
Скопируйте приведенный ниже текст в Блокнот и сохраните файл как fixlist.txt в ту же папку, откуда была запущена утилита Farbar Recovery Scan Tool:
Код:
CreateRestorePoint:
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {6b998feb-39a7-11e0-a221-001cb32ae03e} - C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {83eaf480-dae4-11e1-a39a-001cb32ae03e} - C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {89a93fce-43a9-11df-a0eb-001cb32ae03e} - C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {8b22281e-d1db-11df-a197-001cb32ae03e} - J:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {8b222828-d1db-11df-a197-001cb32ae03e} - C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {be682ebe-c26f-11db-9c57-00e04d0a73dd} - H:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {d22f59dc-81de-11e0-a26e-001cb32ae03e} - RECYCLER\S-51-9-25-5467446591-1634435234-612382968-1224\txzrm.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {19794173-a9cc-11df-a163-001cb32ae03e} - C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {de24e386-1744-11e1-a2ea-001cb32ae03e} - C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {f9e7e16d-8951-11dd-9ea5-00e04d0a73dd} - H:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {fb1656f8-20d7-11dc-9d0f-00e04d0a73dd} - H:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe
HKU\S-1-5-21-1606980848-220523388-725345543-500\...\MountPoints2: {fd27a700-e862-11dd-9f09-00e04d0a73dd} - C:\jakwms.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:13828
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=98016256_hao_pg
HKU\S-1-5-21-1606980848-220523388-725345543-500\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=d45f4f6c16b17c3ca5ec10e3ad05b37e&text={searchTerms}
HKU\S-1-5-21-1606980848-220523388-725345543-500\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=d45f4f6c16b17c3ca5ec10e3ad05b37e&text={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.luckysearches.com/web/?type=ds&ts=1429708100&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=d45f4f6c16b17c3ca5ec10e3ad05b37e&text={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=d45f4f6c16b17c3ca5ec10e3ad05b37e&text=
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {19F9D834-8761-40B9-BF52-2717655562CE} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {225C1074-E77D-4F83-A77F-2A642A1C3992} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {950E160C-4356-4E36-A135-62DFBCB7E860} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://www.luckysearches.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=MaxtorX6V160E0_V30HDR3G&ts=1429708178&type=default&q={searchTerms}
Toolbar: HKU\S-1-5-21-1606980848-220523388-725345543-500 -> No Name - {468CD8A9-7C25-45FA-969E-3D925C689DC4} - No File
DefaultPrefix: => http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=d45f4f6c16b17c3ca5ec10e3ad05b37e&text= <==== ATTENTION
StartMenuInternet: IEXPLORE.EXE - H:\Program Files\Internet Explorer\iexplore.exe http://www.luckysearches.com/?type=sc&ts=1429708100&from=cmi&uid=MaxtorX6V160E0_V30HDR3G
FF DefaultSearchEngine: luckysearches
FF SelectedSearchEngine: luckysearches
FF Plugin: @qq.com/npAndroidAssistant -> H:\Program Files\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll No File
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> H:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-04-22] (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> H:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-04-22] (globalUpdate)
FF SearchPlugin: H:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ib437qdf.default\searchplugins\luckysearches.xml [2015-04-23]
FF Extension: QuickSearch - H:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ib437qdf.default\Extensions\[email protected] [2015-05-21]
2015-05-27 00:12 - 2015-04-22 16:09 - 00000000 ____D () H:\Program Files\XTab
2015-05-21 13:04 - 2015-05-21 13:04 - 0156286 _____ () H:\Program Files\desk.jpg
2015-05-21 13:04 - 2015-05-21 13:04 - 0156286 _____ () H:\Program Files\desk1.bmp
2015-05-21 12:15 - 2015-05-21 13:04 - 0000081 _____ () H:\Program Files\NKQRFNSJHD.AIJ
2015-04-14 19:28 - 2015-04-14 19:28 - 0004387 _____ () H:\Documents and Settings\Admin\Application Data\nPIMR80MPfo53m2rNdMwURVA
2015-04-20 16:45 - 2015-04-20 16:45 - 1246720 _____ () H:\Documents and Settings\Admin\Application Data\nPIMR80MPfo53m2rNdMwURVA.exe
2008-04-08 09:41 - 2012-10-03 09:29 - 0007888 _____ () H:\Documents and Settings\Admin\Application Data\SmarThruOptions.xml
2015-04-14 19:28 - 2015-04-14 19:28 - 0004387 _____ () H:\Documents and Settings\Admin\Application Data\ugN8wZXGvEkULzr862Ta0MX
2015-04-20 16:45 - 2015-04-20 16:45 - 1246720 _____ () H:\Documents and Settings\Admin\Application Data\ugN8wZXGvEkULzr862Ta0MX.exe
DomainProfile\AuthorizedApplications: [H:\Program Files\Tencent\QQPCMgr\10.9.16349.225\QMAccountProtection.exe] => Enabled:????-???
DomainProfile\AuthorizedApplications: [H:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
DomainProfile\AuthorizedApplications: [H:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
StandardProfile\AuthorizedApplications: [C:\hqac.pif] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\sadh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ygmlar.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wensg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qomksa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxudbjg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwbna.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winsoql.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winaddv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxgwgew.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winsethcy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\prge.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qhbxe.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gdeycn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qnir.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wjpb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ucjxwr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winsebo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\enfltj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\owek.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ignmlf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\vuus.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\eahpu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winmowb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxuif.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxxraxs.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winusgcv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\jfnpg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\mwbidd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\soid.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winfvwm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\mxpll.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\oenqmg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\cbvbw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\eqey.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\jykl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\fpulwb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\joojq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winvxhnm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winslxqqn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\xpha.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\lhxng.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxkhkl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\tuslx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\nnwj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winebkd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winosbpid.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwvmxlf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingyhgfg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwcuyb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winlcpd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingnung.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winyxueh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxoohqq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\obsh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winivui.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pachqh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\iwcqa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\windntrf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\hxxsfv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\upyi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\rexhsl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\iolfn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winyecicw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ldsn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\vqlfix.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winkbym.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winumiq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\cptbb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\oiftk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winganqof.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wintehy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\jemlbo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\mxhd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\chmyl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winoamvfy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ipmh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winlpqkeu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winqrraa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winotmr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\bsum.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\hsaxh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wineltilg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\enod.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winkunb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winmlwx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pjvy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winehvbg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winjgkwaw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winseumh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\nydv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winefcirk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winghty.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingcqo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwdmo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winrrqqp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winsejoq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winqlabqn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winfadovb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\sbaegw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qialhx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\mrjbm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winpvjtq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winptfa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winiljo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wgtd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\crnv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pqov.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winnrntp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\tllu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gomvmg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\dnqwc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winpqvutr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gbifld.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingmyeiw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winbsdwo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ruxf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pwyh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\jdnt.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winmfivq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\jsubg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\teebcg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\kacn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winylfhrd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winrtuykr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winbixj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wintoyrce.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winctgtnx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxmnon.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winfaibx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\windvjsy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winufqhgn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\nmkgn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winllbgxp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winalimkn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gijd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pjejca.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winjksifk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\tqjjwn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winolym.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\dpqcct.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwdyf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\liqsd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\chfod.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\yrer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winjduv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\tpkb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\vnhtl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winyovb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winimlm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winoxhwtr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winhalmnc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\yshdmw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winrkpc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winriul.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwgpsr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winairn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winknum.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winavqcw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winmsshrm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\uncgx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pxgnsw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\vtet.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qjmhb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winghqmk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\chhl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winnowqhq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winthmiu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxophxe.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winhfhjaf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\oewemd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winboyxl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winlsfltb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winpoetqx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winoqnbbn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winkqjhqb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winmdfmg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingujf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winduwi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winnxiytu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\bgshmf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\yctid.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingqxecu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingcvbd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wincjktp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winsmddi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winqnhx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wimmm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winuoni.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\exfkmg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\windxva.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\xefwc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\yowt.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winyscrwy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingnatxv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingwpaan.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\awxsfp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\yqafkg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\cswe.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winlpbdb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winrsted.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winimona.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\iaytm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winhvqy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winnwbw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winhnqs.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winvcoth.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qrddkc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wincatgi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winjgwu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winghttv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\xhkd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\hfok.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winpwvc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingxsidu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winmvqiu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winccnxae.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winwfqgkc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\xryb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxwof.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winravgvs.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wincgxrn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winqawfpm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winbqqqnp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\cdyw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\vhev.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winvmhngy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wingfrd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winkuqw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\mcemgc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\fmdfml.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\pbtuq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winsywdyi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winuyhsh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gufih.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winypybo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winlaitq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ritm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\fdaih.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\ycgmk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\vmmbtv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winorihl.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winpxkcqu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\bwmw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winufma.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\system32\myuninst.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\qmmamj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gvgu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\uqcmcu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winfekn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wgrdgh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\lksgeo.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\wineecokh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winafojit.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\xxtjdv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [M:\dpqx.pif] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\atcns.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winjmnuk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\koad.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\oxalhi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winyebbf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\gqlid.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winggkah.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\rvqay.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winpmhdk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winxnaa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\kfhxhk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\TEMP\winevre.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [H:\WINDOWS\system\wmisync.exe] => Microsoft Enabled
StandardProfile\AuthorizedApplications: [C:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe] => Microsoft Enabled
StandardProfile\AuthorizedApplications: [J:\RECYCLER\S-1-6-21-9432276501-9644491937-600003330-2300\openfiles.exe] => Microsoft Enabled
StandardProfile\AuthorizedApplications: [H:\Program Files\Tencent\QQPCMgr\10.9.16349.225\QMAccountProtection.exe] => Enabled:????-???
StandardProfile\AuthorizedApplications: [H:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
StandardProfile\AuthorizedApplications: [H:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
Reboot:
Запустите FRST, нажмите один раз на кнопку Fix и подождите. Программа создаст лог-файл (Fixlog.txt ). Пожалуйста, прикрепите его в следующем сообщении! Обратите внимание, что компьютер будет перезагружен .
Microsoft MVP 2012-2016 Consumer Security
Microsoft MVP 2016 Reconnect
Junior Member
Вес репутации
53
у вас там в предпоследних строчках какие-то иероглифы
сделал
Вложения
Логи в порядке. С расшифровкой не поможем.
Junior Member
Вес репутации
53
Сообщение от
mike 1
Логи в порядке. С расшифровкой не поможем.
даже на платной основе?
Junior Member
Вес репутации
53
Сообщение от
mike 1
Даже на платной основе.
ситуация может как-то измениться в будущем? или про файлы эти можно забыть и никто мне не поможет?
Сообщение от
Trampoline
ситуация может как-то измениться в будущем? или про файлы эти можно забыть и никто мне не поможет?
Расшифровки я думаю не будет. Такие файлы смогут расшифровать только злодеи.
Итог лечения
Статистика проведенного лечения:
Получено карантинов: 2 Обработано файлов: 37 В ходе лечения вредоносные программы в карантинах не обнаружены