. ,, . ( ,, ) . . 100 % , . . NetFrameWork 3.5 ( , ) .
Printable View
. ,, . ( ,, ) . . 100 % , . . NetFrameWork 3.5 ( , ) .
() [B]Aleksey1993[/B], !
- VirusInfo.Info. . Autologger, [URL="https://virusinfo.info/pravila.html"] [/URL].
[INFORMATION] , [URL="https://virusinfo.info/content.php?r=613-sub_pomogite"]+[/URL].[/INFORMATION]
- , [URL="https://virusinfo.info/content.php?r=113-virusinfo.info-donate"] [/URL].
!
[quote="Aleksey1993;1533317"] [/quote]
. .. .
[URL="https://virusinfo.info/showthread.php?t=130828"][b][/b] [/URL].
[URL="https://virusinfo.info/showthread.php?t=7239"] AVZ[/URL]:
[CODE]begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
QuarantineFile('C:\ProgramData\Google\Chrome\updater.exe', '');
QuarantineFile('C:\ProgramData\xxubhctopuuh\uqpllctchben.exe', '');
DeleteFile('C:\ProgramData\Google\Chrome\updater.exe', '64');
DeleteFile('C:\ProgramData\xxubhctopuuh\uqpllctchben.exe', '64');
DeleteService('GoogleUpdateTaskMachineQC');
DeleteService('XPMMCKSP');
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1001', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1004', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1201', 3);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '1804', 1);
RegKeyIntParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\', '2201', 3);
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
[/CODE]
[U][/U].
:
[URL="https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/"]Farbar Recovery Scan Tool[/URL] .
: , . , , . .
, [B][/B] .
[B][/B] ([B]Scan[/B]).
[B]FRST.txt[/B] [B]Addition.txt[/B] , . .
Утилита Farbar установилась,запускается и тут же закрывается.Сам ноутбук очень медленно заходит на данный сайт.Что интересно,с персонального компьютера в гуглхроме,войдя в свою учётную запись,я тоже не смог зайти на данный сайт.Только через Иридиум браузер.
[COLOR="silver"]- - - - - - - - - -[/COLOR]
Farbar . . . .
?
FRST64.exe -> FRSTEnglish.exe .
. txt
[B] [/B] - () , , , , , .
[List][*] .[*] :
[code]
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
S2 BITS_bkp; C:\Windows\System32\qmgr.dll [1481216 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 dosvc_bkp; C:\Windows\system32\dosvc.dll [1519616 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 GoogleUpdateTaskMachineQC; C:\ProgramData\Google\Chrome\updater.exe [2727704 2025-03-27] (Google LLC -> Google Inc.) [File not signed] <==== ATTENTION
S2 UsoSvc_bkp; C:\Windows\system32\usosvc.dll [570368 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S3 WaaSMedicSvc_bkp; C:\Windows\System32\WaaSMedicSvc.dll [427520 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S3 wuauserv_bkp; C:\Windows\system32\wuaueng.dll [3447296 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
C:\ProgramData\Google\Chrome\updater.exe
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::
[/code]
[*] ( - ).[*] FRST (FRST64) .[*] [B][/B] ([B]Fix[/B]) (!) . - (Fixlog.txt). .[/List]
.
[url=https://disk.yandex.ru/d/ioc5fijaNhA4GA] [/url], reg- , .
.
:
[URL='https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/'][B]Farbar Service Scanner[/B][/URL]
.
, :
[LIST][*][B]Internet Services[/B][*][B]Windows Firewall[/B][*][B]System Restore[/B][*][B]Security Center/Action Center[/B][*][B]Windows Update[/B][*][B]Windows Defender[/B][/LIST]
"[B]Scan[/B]"
([B]FSS.txt[/B]) , .
.
FRST.txt Addition.txt
. FRST, FIX . . . FixLog
[COLOR="silver"]- - - - - - - - - -[/COLOR]
.
[quote="Sandor;1533327"] ([B]FSS.txt[/B]) , .
.
[B]FRST.txt[/B] [B]Addition.txt[/B][/quote]
, .
.,.
[B] [/B].
[List][*] .[*] :
[code]
Start::
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Restriction <==== ATTENTION
U3 wuauserv_bkp; C:\Windows\system32\wuaueng.dll [3447296 2023-06-09] (Microsoft Windows -> Microsoft Corporation)
S2 XPMMCKSP; C:\ProgramData\xxubhctopuuh\uqpllctchben.exe [786432000 2025-03-27] (Microsoft Corporation) [File not signed] <==== ATTENTION <==== ATTENTION
C:\ProgramData\xxubhctopuuh\uqpllctchben.exe
Folder: C:\ProgramData\xxubhctopuuh\
2025-03-27 01:33 - 2025-03-27 01:33 - 000000000 ____D C:\ProgramData\Avast Software
Reboot:
End::
[/code]
[*] ( - ).[*] FRST (FRST64) ( ).[*] [B][/B] ([B]Fix[/B]) (!) . - (Fixlog.txt). .[/List]
.
:
[quote="Sandor;1533327"] :
[url=https://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/]Farbar Service Scanner[/url]
.
, :
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender
"Scan"
([B]FSS.txt[/B]) , .
.[/quote]