adviser.vlad
Новый пользователь
- Сообщения
- 7
- Реакции
- 0
Follow along with the video below to see how to install our site as a web app on your home screen.
Примечание: This feature currently requires accessing the site using the built-in Safari browser.
Внимание. Восстановление баз 1С7, 1C8 и Mssql после атаки шифровальщика, подробности и отзывы читайте в профильной теме.
Внимание. Восстановление архивов RAR и ZIP, образов Acronis и виртуальных машин, баз почтовых программ после атаки шифровальщика, подробности и отзывы читайте в профильной теме.
Где вы его увидели?в памяти болтается троян
Start::
CreateRestorePoint:
VirusTotal::\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe;
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
GroupPolicy: Restriction - Chrome <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {8E015791-D453-4DE4-999D-B369FAF71DFB} - \KMSAuto -> No File <==== ATTENTION
S4 Updater.Mail.Ru; C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe --s [X] <==== ATTENTION
S4 mrupdsrv; "C:\Program Files (x86)\Mail.Ru\Update Service\mrupdsrv.exe" --s [X] <==== ATTENTION
2019-06-23 18:48 - 2019-06-23 18:48 - 000000061 _____ C:\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\AppData\Roaming\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\AppData\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\Downloads\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\Documents\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\Desktop\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\Бухгалтер\AppData\Roaming\Microsoft\Windows\Start Menu\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\���������\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\���������\AppData\README.txt
2019-06-23 18:44 - 2019-06-23 18:44 - 000000061 _____ C:\Users\���������\AppData\Local\README.txt
2019-06-23 18:43 - 2019-06-23 18:43 - 000000061 _____ C:\Users\Бухгалтер\AppData\Roaming\README.txt
2019-06-23 18:43 - 2019-06-23 18:43 - 000000061 _____ C:\Users\Бухгалтер\AppData\README.txt
2019-06-23 18:40 - 2019-06-23 18:40 - 000000061 _____ C:\Users\Бухгалтер\AppData\LocalLow\README.txt
2019-06-23 18:22 - 2019-06-23 18:22 - 000000061 _____ C:\Users\Бухгалтер\AppData\Local\README.txt
2019-06-23 18:21 - 2019-06-23 18:44 - 000001259 _____ C:\Users\Все пользователи\README.txt
2019-06-23 18:21 - 2019-06-23 18:44 - 000001259 _____ C:\ProgramData\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Public\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Public\Downloads\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\Downloads\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\Documents\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\Desktop\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\AppData\Roaming\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\AppData\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default\AppData\Local\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\Downloads\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\Documents\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\Desktop\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\AppData\Roaming\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\AppData\README.txt
2019-06-23 18:21 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Default User\AppData\Local\README.txt
2019-06-23 18:20 - 2019-06-23 18:21 - 000001259 _____ C:\Users\Все пользователи\email-3nity@tuta.io.ver-CL 1.5.1.0.id-.fname-README.txt.doubleoffset
2019-06-23 18:20 - 2019-06-23 18:21 - 000001259 _____ C:\Users\Public\Documents\email-3nity@tuta.io.ver-CL 1.5.1.0.id-.fname-README.txt.doubleoffset
2019-06-23 18:20 - 2019-06-23 18:21 - 000001259 _____ C:\Users\Public\Desktop\email-3nity@tuta.io.ver-CL 1.5.1.0.id-.fname-README.txt.doubleoffset
2019-06-23 18:20 - 2019-06-23 18:21 - 000001259 _____ C:\ProgramData\email-3nity@tuta.io.ver-CL 1.5.1.0.id-.fname-README.txt.doubleoffset
2019-06-23 18:20 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Public\Documents\README.txt
2019-06-23 18:20 - 2019-06-23 18:21 - 000000061 _____ C:\Users\Public\Desktop\README.txt
2019-06-23 18:20 - 2019-06-23 18:20 - 000000061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\README.txt
2019-06-23 18:20 - 2019-06-23 18:20 - 000000061 _____ C:\Program Files (x86)\README.txt
2019-06-23 18:14 - 2019-06-23 18:14 - 000000061 _____ C:\Program Files\README.txt
2019-06-23 18:14 - 2019-06-23 18:14 - 000000061 _____ C:\Program Files\Common Files\README.txt
2019-06-23 18:13 - 2019-06-23 18:21 - 000001259 _____ C:\Users\email-3nity@tuta.io.ver-CL 1.5.1.0.id-.fname-README.txt.doubleoffset
2019-06-23 18:10 - 2019-06-23 18:44 - 000000000 ____D C:\Users\Бухгалтер\Downloads\taskmgr
2019-06-23 18:10 - 2019-06-23 18:41 - 000000000 ____D C:\Users\Бухгалтер\AppData\Roaming\Process Hacker 2
2019-06-23 18:09 - 2019-06-23 18:09 - 000000000 ____H C:\Users\Бухгалтер\Documents\Default.rdp
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll -> No File
FirewallRules: [{1A0EC57E-F084-4940-A769-975012FAD23A}] => (Block) C:\program files (x86)\1cv8\8.3.6.2041\bin\1cv8c.exe No File
FirewallRules: [{F8560201-DEFD-44CF-8DF8-3B266CF182A0}] => (Block) C:\program files (x86)\1cv8\8.3.6.2041\bin\1cv8c.exe No File
FirewallRules: [TCP Query User{5A61CAC5-7E33-4F00-884B-51CCB4AAE6D7}C:\tt\jre\bin\javaw.exe] => (Block) C:\tt\jre\bin\javaw.exe No File
FirewallRules: [UDP Query User{4FFFC2E2-1D14-4E71-8F9A-E4CD5FBF354D}C:\tt\jre\bin\javaw.exe] => (Block) C:\tt\jre\bin\javaw.exe No File
FirewallRules: [TCP Query User{68EC1061-F514-42E2-8EAD-9B13B4CFBAA8}C:\tt\jre\bin\javaw.exe] => (Block) C:\tt\jre\bin\javaw.exe No File
FirewallRules: [UDP Query User{4777A9AB-1D6F-4ED4-8116-93E780247D82}C:\tt\jre\bin\javaw.exe] => (Block) C:\tt\jre\bin\javaw.exe No File
FirewallRules: [{863C558C-291F-4D0A-88E6-15A9EEDCCB92}] => (Allow) C:\Users\Бухгалтер\AppData\Roaming\Mail.Ru\Agent\magent.exe No File
FirewallRules: [{8C92169F-D610-4A2E-A073-7DD6BB67FC87}] => (Allow) C:\Users\Бухгалтер\AppData\Roaming\Mail.Ru\Agent\magent.exe No File
FirewallRules: [{80FE8D1A-0F56-4D27-904C-666BC0CFBB56}] => (Allow) C:\Users\Бухгалтер\AppData\Local\Amigo\Application\amigo.exe No File
FirewallRules: [{51D0FC12-9619-4AA0-A5FE-D81E1691C33A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe No File
FirewallRules: [TCP Query User{5BDE23A5-7628-4B7C-8F81-337C792D194C}C:\utm\jre\bin\javaw.exe] => (Allow) C:\utm\jre\bin\javaw.exe No File
FirewallRules: [UDP Query User{AA43DBBC-9D2C-4696-8780-2903936AF436}C:\utm\jre\bin\javaw.exe] => (Allow) C:\utm\jre\bin\javaw.exe No File
FirewallRules: [{491A0F33-4C7F-444C-8A9B-8C9035AC423D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe No File
FirewallRules: [{A3780C6F-598A-40EE-B6D4-926C6CAD0710}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe No File
FirewallRules: [{BB5E1F4C-53C9-4F5D-8B86-C5951C905AE6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe No File
FirewallRules: [{C008091D-47DF-4BB3-90AC-ED60697A4E02}] => (Allow) C:\Program Files (x86)\IVView\bin\ServerCMS.exe No File
FirewallRules: [{57BC13E2-1A34-4D7D-BFF2-0E749320B31B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File
FirewallRules: [{4F4E407A-BADF-4543-84D4-4C72000D7206}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe No File
EmptyTemp:
Reboot:
End::
???Постарайтесь найти пару - зашифрованный и его не зашифрованный оригинал размером не менее 256 байт (ищите такой в бэкапах, в почте, на других ПК и т.д.). Упакуйте в архив и прикрепите к следующему сообщению.
Тип файла предпочтительно офисный документ или картинка.