PDA

: , , NETFrameWork 3.5



Aleksey1993
27.03.2025, 14:18
. ,, . ( ,, ) . . 100 % , . . NetFrameWork 3.5 ( , ) .

Info_bot
27.03.2025, 14:19
() Aleksey1993, !

- VirusInfo.Info. . Autologger, (https://virusinfo.info/pravila.html).

, + (https://virusinfo.info/content.php?r=613-sub_pomogite).

- , (https://virusinfo.info/content.php?r=113-virusinfo.info-donate).

Sandor
27.03.2025, 15:01
!




. .. .

(https://virusinfo.info/showthread.php?t=130828).
AVZ (https://virusinfo.info/showthread.php?t=7239):


begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFile('C:\ProgramData\Google\Chrome\updat er.exe', '');
QuarantineFile('C:\ProgramData\xxubhctopuuh\uqpllc tchben.exe', '');
DeleteFile('C:\ProgramData\Google\Chrome\updater.e xe', '64');
DeleteFile('C:\ProgramData\xxubhctopuuh\uqpllctchb en.exe', '64');
DeleteService('GoogleUpdateTaskMachineQC');
DeleteService('XPMMCKSP');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Interne t Settings\Zones\3\', '2201', 3);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.


.


:
Farbar Recovery Scan Tool (https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) .

: , . , , . .
, .

(Scan).
FRST.txt Addition.txt , . .

Aleksey1993
27.03.2025, 15:27
Утилита Farbar установилась,запускается и тут же закрывается.Сам ноутбук очень медленно заходит на данный сайт.Что интересно,с персонального компьютера в гуглхроме,войдя в свою учётную запись,я тоже не смог зайти на данный сайт.Только через Иридиум браузер.

- - - - - - - - - -

Farbar . . . .

Sandor
27.03.2025, 16:09
?
FRST64.exe -> FRSTEnglish.exe .

Aleksey1993
27.03.2025, 16:34
. txt

Sandor
27.03.2025, 17:18
- () , , , , , .

.
:


Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
S2 BITS_bkp; C:\Windows\System32\qmgr.dll [1481216 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 dosvc_bkp; C:\Windows\system32\dosvc.dll [1519616 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 GoogleUpdateTaskMachineQC; C:\ProgramData\Google\Chrome\updater.exe [2727704 2025-03-27] (Google LLC -> Google Inc.) [File not signed] <==== ATTENTION
S2 UsoSvc_bkp; C:\Windows\system32\usosvc.dll [570368 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S3 WaaSMedicSvc_bkp; C:\Windows\System32\WaaSMedicSvc.dll [427520 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S3 wuauserv_bkp; C:\Windows\system32\wuaueng.dll [3447296 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
C:\ProgramData\Google\Chrome\updater.exe
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::


( - ).
FRST (FRST64) .
(Fix) (!) . - (Fixlog.txt). .

.


(https://disk.yandex.ru/d/ioc5fijaNhA4GA), reg- , .
.

:
Farbar Service Scanner ('https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/')

.
, :

Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender

"Scan"

(FSS.txt) , .
.

FRST.txt Addition.txt

Aleksey1993
27.03.2025, 18:40
. FRST, FIX . . . FixLog

- - - - - - - - - -

.

Sandor
28.03.2025, 08:55
(FSS.txt) , .
.

FRST.txt Addition.txt
, .

Aleksey1993
28.03.2025, 10:39
.,.

Sandor
28.03.2025, 10:57
.

.
:


Start::
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
U3 wuauserv_bkp; C:\Windows\system32\wuaueng.dll [3447296 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 XPMMCKSP; C:\ProgramData\xxubhctopuuh\uqpllctchben.exe [786432000 2025-03-27] (Microsoft Corporation) [File not signed] <==== ATTENTION <==== ATTENTION
C:\ProgramData\xxubhctopuuh\uqpllctchben.exe
Folder: C:\ProgramData\xxubhctopuuh\
2025-03-27 01:33 - 2025-03-27 01:33 - 000000000 ____D C:\ProgramData\Avast Software
Reboot:
End::


( - ).
FRST (FRST64) ( ).
(Fix) (!) . - (Fixlog.txt). .

.

:


:
Farbar Service Scanner (https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/)

.
, :
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender

"Scan"

(FSS.txt) , .
.