Åù¸ è êîäèðîâêà ñáèëàñü ïðè ïîñòå (çàãîëîâîê íå ìîãó èñïðàâèòü)
Ïîéìàë òðîÿí.  áåçîïàñíîì ðåæèìå ñ ïîìîùüþ adwcleaner óäàëÿþ åãî, íî ïðè îáû÷íîé çàãðóçêå îí ñíîâà âîñêðåñàåò è ñúåäàåò âñå ðåñóðñû.
Printable View
Åù¸ è êîäèðîâêà ñáèëàñü ïðè ïîñòå (çàãîëîâîê íå ìîãó èñïðàâèòü)
Ïîéìàë òðîÿí.  áåçîïàñíîì ðåæèìå ñ ïîìîùüþ adwcleaner óäàëÿþ åãî, íî ïðè îáû÷íîé çàãðóçêå îí ñíîâà âîñêðåñàåò è ñúåäàåò âñå ðåñóðñû.
Óâàæàåìûé(àÿ) [B]Serjic[/B], ñïàñèáî çà îáðàùåíèå íà íàø ôîðóì!
Óäàëåíèå âèðóñîâ - àáñîëþòíî áåñïëàòíàÿ óñëóãà íà VirusInfo.Info. Õåëïåðû â ñàìîå áëèæàéøåå âðåìÿ îòâåòÿò íà Âàø çàïðîñ. Äëÿ îêàçàíèÿ ïîìîùè íåîáõîäèìî ïðåäîñòàâèòü ëîãè ñêàíèðîâàíèÿ óòèëèòîé Autologger, ïîäðîáíåå ìîæíî ïðî÷èòàòü â [URL="https://virusinfo.info/pravila.html"]ïðàâèëàõ îôîðìëåíèÿ çàïðîñà î ïîìîùè[/URL].
[INFORMATION]Åñëè âû õîòèòå ïîëó÷èòü ïåðñîíàëüíóþ ãàðàíòèðîâàííóþ ïîìîùü â ïðèîðèòåòíîì ðåæèìå, òî âîñïîëüçóéòåñü ïëàòíûì ñåðâèñîì [URL="https://virusinfo.info/content.php?r=613-sub_pomogite"]Ïîìîãèòå+[/URL].[/INFORMATION]
Åñëè íàø ñàéò îêàæåòñÿ ïîëåçåí Âàì è ó Âàñ áóäåò òàêàÿ âîçìîæíîñòü - ïîæàëóéñòà [URL="https://virusinfo.info/content.php?r=113-virusinfo.info-donate"]ïîääåðæèòå ïðîåêò[/URL].
Ëîãè íóæíû èç îáû÷íîãî, à íå áåçîïàñíîãî, ðåæèìà
Ïðîáóþ â îáû÷íîì ðåæèìå, ïèøåò ÷òî âêëþ÷åí AVZPM è îòïðàâëÿåò â ïåðåçàãðóçêó. Ïîñëå ïåðåçàãðóçêè ñíîâà ïèøåò ÷òî âêëþ÷åí AVZPM è ñíîâà â ïåðåçàãðóçêó. È òàê ïî êðóãó.
Ïîôèêñèòå â HiJack èç ïàïêè Autologger
[CODE]O3 - HKCU\..\Toolbar: (no name) - {1E796980-9CC5-11D1-A83F-00C04FC99D61} - (no file)
O3 - HKCU\..\Toolbar: (no name) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
O3 - HKLM\..\Toolbar: (no name) - {91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
O4 - HKLM\..\Run: [collect] = C:\Collect.exe -s:192.168.5.104:9997
O4 - MSConfig\startupreg: AdobeUpdater [command] = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (file missing) (HKCU) (2015/11/23)
O4 - MSConfig\startupreg: Firewall auto setup [command] = C:\Documents and Settings\user\Local Settings\Temp\winlogon.exe (file missing) (HKCU) (2015/11/23)
O4 - MSConfig\startupreg: MicrosoftUpdate [command] = C:\Documents and Settings\user\Local Settings\Temp\44.tmp.exe (file missing) (HKCU) (2015/11/23)
O4 - MSConfig\startupreg: YI9B2F0FYEXG0G0HB [command] = C:\systemhost\24FC2AE3EA8.exe (file missing) (HKCU) (2015/11/23)
O4 - MSConfig\startupreg: c: [command] = (no file) (2010/11/20)
[/CODE]Ïåðåçàãðóçèòå êîìïüþòåð è ïðîáóéòå ñäåëàòü ëîãè â îáû÷íîì ðåæèìå
[QUOTE=thyrex;1484988]... Ïåðåçàãðóçèòå êîìïüþòåð è ïðîáóéòå ñäåëàòü ëîãè â îáû÷íîì ðåæèìå[/QUOTE]
[COLOR=#333333]Ìåðòâî âèñåòü ïåðåñòàë,íî ïèøåò ÷òî âêëþ÷åí AVZPM è îòïðàâëÿåò â ïåðåçàãðóçêó. Ïîñëå ïåðåçàãðóçêè ñíîâà ïèøåò ÷òî âêëþ÷åí AVZPM è ñíîâà â ïåðåçàãðóçêó. È òàê ïî êðóãó.[/COLOR]
Âûïîëíèòå ñêðèïò â AVZ èç ïàïêè Autologger
[code] begin
SetAVZPMStatus(False);
ExecuteStdScr(6);
RebootWindows(true);
end. [/code]Êîìïüþòåð ïåðåçàãðóçèòñÿ.
Ïðîáóéòå òåïåðü ñîáðàòü ëîãè.
[QUOTE=thyrex;1485000]Âûïîëíèòå ñêðèïò ...[/QUOTE]
Âûïîëíèë. Êîìïüþòåð ïåðåãðóçèëñÿ è ñíîâà ïèøåò "Âêëþ÷åí AVZPM! Ñåé÷àñ îí áóäåò îòêëþ÷åí... " è ïðåäëàãàåò ïåðåçàãðóçêó. Åñëè îòêàçûâàþñü îò ïåðåçàãðóçêè, òî AVZ çàêðûâàåòñÿ.
Ñêà÷àéòå [url=https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/][b]Farbar Recovery Scan Tool[/b][/url] [img]https://i.imgur.com/NAAC5Ba.png[/img] è ñîõðàíèòå íà Ðàáî÷åì ñòîëå.
[list][*][b]Ïðèìå÷àíèå[/b]: íåîáõîäèìî âûáðàòü âåðñèþ, ñîâìåñòèìóþ ñ Âàøåé îïåðàöèîííîé ñèñòåìîé. Åñëè Âû íå óâåðåíû, êàêàÿ âåðñèÿ ïîäîéäåò äëÿ Âàøåé ñèñòåìû, ñêà÷àéòå îáå è ïîïðîáóéòå çàïóñòèòü. Òîëüêî îäíà èç íèõ çàïóñòèòñÿ íà Âàøåé ñèñòåìå.[/list]
1. Çàïóñòèòå ïðîãðàììó äâîéíûì ùåë÷êîì. Êîãäà ïðîãðàììà çàïóñòèòñÿ, íàæìèòå [b]Yes[/b] äëÿ ñîãëàøåíèÿ ñ ïðåäóïðåæäåíèåì.
2. Óáåäèòåñü, ÷òî â îêíå [b]Optional Scan[/b] îòìå÷åíû [i]List BCD[/i], [i]Driver MD5[/i] è [i]90 Days Files[/i].
[img]https://i.imgur.com/3munStB.png[/img]
3. Íàæìèòå êíîïêó [b]Scan[/b].
4. Ïîñëå îêîí÷àíèÿ ñêàíèðîâàíèÿ áóäåò ñîçäàí îò÷åò ([b]FRST.txt[/b]) â òîé æå ïàïêå, îòêóäà áûëà çàïóùåíà ïðîãðàììà.
5. Åñëè ïðîãðàììà áûëà çàïóùåíà â ïåðâûé ðàç, òàêæå áóäåò ñîçäàí îò÷åò ([b]Addition.txt[/b]).
6. Îò÷åòû, ïîëó÷åííûå â ïóíêòàõ 4 è 5, çààðõèâèðóéòå (â [b]îäèí àðõèâ[/b]) è ïðèêðåïèòå ê ñîîáùåíèþ.
Ñäåëàíî
1. Îòêðîéòå [b]Áëîêíîò[/b] è ñêîïèðóéòå â íåãî ïðèâåäåííûé íèæå òåêñò
[code]
CreateRestorePoint:
U5 vdmynzg0; C:\Windows\System32\Drivers\vdmynzg0.sys [13312 2010-10-29] () [File not signed]
S0 Winsx05; System32\Drivers\Winsx05.sys [X]
S1 yvbb02; \??\C:\WINDOWS\system32\yvbb02.sys [X]
S4 crvdll; C:\WINDOWS\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
HKLM\...\RunOnce: [AVZ] => cmd /c start " " "C:\Documents and Settings\terminal1\Ìîè äîêóìåíòû\Çàãðóçêè\AutoLogger\AutoLogger\AVZ\avz.exe" Script="C:\Documents and Settings\terminal1\Ìîè äîêóìåíòû\Çàãðóçêè\AutoLogger\AutoLogger (the data entry has 36 more characters).
2010-09-28 08:13 - 2010-10-07 16:32 - 000076296 _____ () C:\Program Files\Common Files\jqyrg4inedzz13m
2014-10-05 12:07 - 2014-10-05 12:07 - 000000000 ____D () C:\Documents and Settings\terminal1\Local Settings\Temp\avgnt.exe
2014-10-05 12:31 - 2014-10-05 12:31 - 000000000 ____D () C:\Documents and Settings\terminal10\Local Settings\Temp\avgnt.exe
2014-10-05 12:34 - 2014-10-05 12:34 - 000000000 ____D () C:\Documents and Settings\terminal11\Local Settings\Temp\avgnt.exe
2012-08-23 06:38 - 2012-08-23 06:38 - 000248008 _____ (Ask.com) C:\Documents and Settings\terminal12\Local Settings\Temp\AskSLib.dll
2014-10-05 12:39 - 2014-10-05 12:39 - 000000000 ____D () C:\Documents and Settings\terminal12\Local Settings\Temp\avgnt.exe
2013-01-29 01:20 - 2013-01-29 01:20 - 000248008 _____ (Ask.com) C:\Documents and Settings\terminal13\Local Settings\Temp\AskSLib.dll
2014-10-05 12:40 - 2014-10-05 12:40 - 000000000 ____D () C:\Documents and Settings\terminal13\Local Settings\Temp\avgnt.exe
2014-10-05 12:43 - 2014-10-05 12:43 - 000000000 ____D () C:\Documents and Settings\terminal14\Local Settings\Temp\avgnt.exe
2014-10-05 12:44 - 2014-10-05 12:44 - 000000000 ____D () C:\Documents and Settings\terminal15\Local Settings\Temp\avgnt.exe
2014-10-05 12:46 - 2014-10-05 12:46 - 000000000 ____D () C:\Documents and Settings\terminal16\Local Settings\Temp\avgnt.exe
2014-10-05 12:48 - 2014-10-05 12:48 - 000000000 ____D () C:\Documents and Settings\terminal17\Local Settings\Temp\avgnt.exe
2014-10-05 12:49 - 2014-10-05 12:49 - 000000000 ____D () C:\Documents and Settings\terminal18\Local Settings\Temp\avgnt.exe
2014-10-05 12:51 - 2014-10-05 12:51 - 000000000 ____D () C:\Documents and Settings\terminal19\Local Settings\Temp\avgnt.exe
2013-01-29 01:20 - 2013-01-29 01:20 - 000248008 _____ (Ask.com) C:\Documents and Settings\terminal2\Local Settings\Temp\AskSLib.dll
2014-05-13 13:25 - 2014-05-13 13:25 - 000000000 ____D () C:\Documents and Settings\terminal2\Local Settings\Temp\avgnt.exe
2014-10-05 12:52 - 2014-10-05 12:52 - 000000000 ____D () C:\Documents and Settings\terminal20\Local Settings\Temp\avgnt.exe
2014-10-05 12:54 - 2014-10-05 12:54 - 000000000 ____D () C:\Documents and Settings\terminal21\Local Settings\Temp\avgnt.exe
2014-10-05 12:57 - 2014-10-05 12:57 - 000000000 ____D () C:\Documents and Settings\terminal22\Local Settings\Temp\avgnt.exe
2014-10-05 12:55 - 2014-10-05 12:55 - 000000000 ____D () C:\Documents and Settings\terminal23\Local Settings\Temp\avgnt.exe
2013-01-29 01:20 - 2013-01-29 01:20 - 000248008 _____ (Ask.com) C:\Documents and Settings\terminal3\Local Settings\Temp\AskSLib.dll
2014-10-05 12:15 - 2014-10-05 12:15 - 000000000 ____D () C:\Documents and Settings\terminal3\Local Settings\Temp\avgnt.exe
2013-01-29 01:20 - 2013-01-29 01:20 - 000248008 _____ (Ask.com) C:\Documents and Settings\terminal4\Local Settings\Temp\AskSLib.dll
2014-10-05 12:17 - 2014-10-05 12:17 - 000000000 ____D () C:\Documents and Settings\terminal4\Local Settings\Temp\avgnt.exe
2014-10-05 12:20 - 2014-10-05 12:20 - 000000000 ____D () C:\Documents and Settings\terminal5\Local Settings\Temp\avgnt.exe
2014-10-05 12:23 - 2014-10-05 12:23 - 000000000 ____D () C:\Documents and Settings\terminal6\Local Settings\Temp\avgnt.exe
2014-10-05 12:25 - 2014-10-05 12:25 - 000000000 ____D () C:\Documents and Settings\terminal7\Local Settings\Temp\avgnt.exe
2014-10-05 12:27 - 2014-10-05 12:27 - 000000000 ____D () C:\Documents and Settings\terminal8\Local Settings\Temp\avgnt.exe
2014-10-05 12:30 - 2014-10-05 12:30 - 000000000 ____D () C:\Documents and Settings\terminal9\Local Settings\Temp\avgnt.exe
2014-04-16 12:00 - 2014-04-16 12:00 - 000000000 ____D () C:\Documents and Settings\Àäìèíèñòðàòîð\Local Settings\Temp\avgnt.exe
2014-05-24 15:05 - 2014-05-24 15:05 - 000000000 ____D () C:\Documents and Settings\Âñå îñòàëüíûå\Local Settings\Temp\avgnt.exe
Reboot:
[/code]
2. Íàæìèòå [b]Ôàéë[/b] – [b]Ñîõðàíèòü êàê[/b]
3. Âûáåðèòå ïàïêó, îòêóäà áûëà çàïóùåíà óòèëèòà [b]Farbar Recovery Scan Tool[/b]
4. Óêàæèòå [b]Òèï ôàéëà[/b] – [b]Âñå ôàéëû (*.*)[/b]
5. Ââåäèòå èìÿ ôàéëà [b]fixlist.txt[/b] è íàæìèòå êíîïêó [b]Ñîõðàíèòü[/b]
6. Çàïóñòèòå FRST, íàæìèòå îäèí ðàç íà êíîïêó [b]Fix[/b] è ïîäîæäèòå. Ïðîãðàììà ñîçäàñò ëîã-ôàéë ([b]Fixlog.txt[/b]). Ïîæàëóéñòà, ïðèêðåïèòå åãî â ñëåäóþùåì ñîîáùåíèè.
[list][*]Îáðàòèòå âíèìàíèå: áóäåò âûïîëíåíà [b]ïåðåçàãðóçêà êîìïüþòåðà[/b].[/list]
Ñäåëàíî
×òî ñ ïðîáëåìîé?
Îáå ïðîáëåìû îñòàëèñü.
AVZPM îòêëþ÷èòü òàê è íå ìîæåò
Âèðóñ òîæå ïîõîæå æèâîé. Ïðè ïåðåêëþ÷åíèè â îñíîâíóþ ó÷åòíóþ çàïèñü ìàøèíà ÷åðåç ïîë ìèíóòû íàãëóõî âèñíåò è êëàäåò ëîêàëüíóþ ñåòü.
Ñäåëàéòå ëîã [url="https://virusinfo.info/showthread.php?t=218706&p=1480220&viewfull=1#post1480220"]ÌÂÀÌ[/url]
Ñäåëàíî
Ïîìåñòèòå â êàðàíòèí âñå, ÊÐÎÌÅ
[CODE]PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-500\SOFTWARE\MICROSOFT\SECURITY CENTER|ANTIVIRUSDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293291],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-500\SOFTWARE\MICROSOFT\SECURITY CENTER|FIREWALLDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293292],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-500\SOFTWARE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293293],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-1004\SOFTWARE\MICROSOFT\SECURITY CENTER|ANTIVIRUSDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293291],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-1004\SOFTWARE\MICROSOFT\SECURITY CENTER|FIREWALLDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293292],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-1004\SOFTWARE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293293],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-1003\SOFTWARE\MICROSOFT\SECURITY CENTER|ANTIVIRUSDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293291],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-1003\SOFTWARE\MICROSOFT\SECURITY CENTER|FIREWALLDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293292],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKU\S-1-5-21-1801674531-1708537768-1957994488-1003\SOFTWARE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293293],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|ANTIVIRUSDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293294],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|FIREWALLDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293295],1.0.5935
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [12970], [293296],1.0.5935
HackTool.Agent, C:\WINDOWS\SYSTEM32\CRYPT.DLL, Ïðîèãíîðèðîâàíî ïîëüçîâàòåëåì, [3936], [146769],1.0.5935[/CODE]
Ñäåëàíî. Íî ìàøèíà ïî ïðåæíåìó æèâåò òîëüêî â áåçîïàñíîì ðåæèìå. Ïðè çàãðóçêå â îáû÷íûé ðåæèì, ãäå òî ÷åðåç ìèíóòó ìàøèíà âåøàåò ëîêàëêó è íà÷èíàåò áåçáîæíî òîðìîçèòü.
[quote="Serjic;1484973"] áåçîïàñíîì ðåæèìå ñ ïîìîùüþ adwcleaner óäàëÿþ åãî, íî ïðè îáû÷íîé çàãðóçêå îí ñíîâà âîñêðåñàåò è ñúåäàåò âñå ðåñóðñû.[/quote]Ëîã AdwCleaner ïðèêðåïèòå