: , , NETFrameWork 3.5
Aleksey1993
27.03.2025, 14:18
. ,, . ( ,, ) . . 100 % , . . NetFrameWork 3.5 ( , ) .
Info_bot
27.03.2025, 14:19
() Aleksey1993, !
- VirusInfo.Info. . Autologger, (https://virusinfo.info/pravila.html).
, + (https://virusinfo.info/content.php?r=613-sub_pomogite).
- , (https://virusinfo.info/content.php?r=113-virusinfo.info-donate).
!
. .. .
(https://virusinfo.info/showthread.php?t=130828).
AVZ (https://virusinfo.info/showthread.php?t=7239):
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFile('C:\ProgramData\Google\Chrome\updat er.exe', '');
QuarantineFile('C:\ProgramData\xxubhctopuuh\uqpllc tchben.exe', '');
DeleteFile('C:\ProgramData\Google\Chrome\updater.e xe', '64');
DeleteFile('C:\ProgramData\xxubhctopuuh\uqpllctchb en.exe', '64');
DeleteService('GoogleUpdateTaskMachineQC');
DeleteService('XPMMCKSP');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '2201', 3);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
.
:
Farbar Recovery Scan Tool (https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) .
: , . , , . .
, .
(Scan).
FRST.txt Addition.txt , . .
Aleksey1993
27.03.2025, 15:27
Утилита Farbar установилась,запускается и тут же закрывается.Сам ноутбук очень медленно заходит на данный сайт.Что интересно,с персонального компьютера в гуглхроме,войдя в свою учётную запись,я тоже не смог зайти на данный сайт.Только через Иридиум браузер.
- - - - - - - - - -
Farbar . . . .
?
FRST64.exe -> FRSTEnglish.exe .
Aleksey1993
27.03.2025, 16:34
. txt
- () , , , , , .
.
:
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
S2 BITS_bkp; C:\Windows\System32\qmgr.dll [1481216 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 dosvc_bkp; C:\Windows\system32\dosvc.dll [1519616 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 GoogleUpdateTaskMachineQC; C:\ProgramData\Google\Chrome\updater.exe [2727704 2025-03-27] (Google LLC -> Google Inc.) [File not signed] <==== ATTENTION
S2 UsoSvc_bkp; C:\Windows\system32\usosvc.dll [570368 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S3 WaaSMedicSvc_bkp; C:\Windows\System32\WaaSMedicSvc.dll [427520 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S3 wuauserv_bkp; C:\Windows\system32\wuaueng.dll [3447296 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
C:\ProgramData\Google\Chrome\updater.exe
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::
( - ).
FRST (FRST64) .
(Fix) (!) . - (Fixlog.txt). .
.
(https://disk.yandex.ru/d/ioc5fijaNhA4GA), reg- , .
.
:
Farbar Service Scanner ('https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/')
.
, :
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender
"Scan"
(FSS.txt) , .
.
FRST.txt Addition.txt
Aleksey1993
27.03.2025, 18:40
. FRST, FIX . . . FixLog
- - - - - - - - - -
.
(FSS.txt) , .
.
FRST.txt Addition.txt
, .
Aleksey1993
28.03.2025, 10:39
.,.
.
.
:
Start::
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
U3 wuauserv_bkp; C:\Windows\system32\wuaueng.dll [3447296 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 XPMMCKSP; C:\ProgramData\xxubhctopuuh\uqpllctchben.exe [786432000 2025-03-27] (Microsoft Corporation) [File not signed] <==== ATTENTION <==== ATTENTION
C:\ProgramData\xxubhctopuuh\uqpllctchben.exe
Folder: C:\ProgramData\xxubhctopuuh\
2025-03-27 01:33 - 2025-03-27 01:33 - 000000000 ____D C:\ProgramData\Avast Software
Reboot:
End::
( - ).
FRST (FRST64) ( ).
(Fix) (!) . - (Fixlog.txt). .
.
:
:
Farbar Service Scanner (https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/)
.
, :
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender
"Scan"
(FSS.txt) , .
.
vBulletin® v4.2.5, Copyright ©2000-2025, Jelsoft Enterprises Ltd. : zCarot