Şimdi Ara

msiexec64.exe Miner virüs

Daha Fazla
Bu Konudaki Kullanıcılar: Daha Az
2 Misafir - 2 Masaüstü
5 sn
2
Cevap
0
Favori
554
Tıklama
Daha Fazla
İstatistik
  • Konu İstatistikleri Yükleniyor
0 oy
Öne Çıkar
Sayfa: 1
Giriş
Mesaj
  • msiexec64.exe Miner virüs
    Bu dosya olan sürekli her silişimde pc açılışında tekrardan bi şekilde kendini kuran bu miner virüsten nasıl kurtulabilirim bunun gibi aynı Localde 10 dosyası vardı hepsinin içeriği aynı buldum ve tek tek sildim Combofix ve hitmanpro ile tarattım buldum siliyorlar ama yine açılışta aynısı oluyor. Yaşayan varsa yardım etsin aşağıyada o logu atıcam incelersiniz buyrun;
    Bu Rkill;

    Rkill 2.9.1 by Lawrence Abrams (Grinler)http://www.bleepingcomputer.com/
    Copyright 2008-2018 BleepingComputer.com
    More Information about Rkill can be found at this link:
    http://www.bleepingcomputer.com/forums/topic308364.html

    Program started at: 05/10/2018 05:37:24 PM in x64 mode.
    Windows Version: Windows 7 Professional Service Pack 1

    Checking for Windows services to stop:

    * No malware services found to stop.

    Checking for processes to terminate:

    * C:\Users\1\AppData\Local\Unity\msiexec64.exe (PID: 1420) [UP-HEUR]

    1 proccess terminated!

    Checking Registry for malware related settings:

    * No issues found in the Registry.

    Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

    Performing miscellaneous checks:

    * No issues found.

    Searching for Missing Digital Signatures:

    * No issues found.

    Checking HOSTS File:

    * HOSTS file entries found:

    127.0.0.1 localhost

    Program finished at: 05/10/2018 05:39:05 PM
    Execution time: 0 hours(s), 1 minute(s), and 41 seconds(s)


    Buda minerin içindeki log;
    17:34:21:863 2b0 args: -zpool ssl://europe.equihash-hub.miningpoolhub.com:20570 -zwal mihail_mavrutenkov.r -zpsw x -ftime 1 -i 5 -tt 70
    17:34:21:864 2b0
    17:34:21:865 2b0 ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
    17:34:21:866 2b0 º Claymore's ZCash AMD GPU Miner v12.6 º
    17:34:21:867 2b0 ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
    17:34:21:868 2b0
    17:34:22:071 2b0 ZEC: 3 pools are specified
    17:34:22:072 2b0 Main ZCash pool is europe.equihash-hub.miningpoolhub.com:20570
    17:34:22:269 2b0 OpenCL platform: AMD Accelerated Parallel Processing
    17:34:22:273 2b0 OpenCL initializing...
    17:34:22:274 2b0 driver 10.0.2527.10
    17:34:22:275 2b0 AMD Cards available: 1
    17:34:22:281 2b0 GPU #0: Baffin, 2048 MB available, 14 compute units
    17:34:22:282 2b0 GPU #0 recognized as Radeon RX 460/560
    17:34:22:283 2b0 POOL version
    17:34:22:284 2b0 b571
    17:34:22:285 2b0 Platform: Windows
    17:34:22:406 2b0 start building OpenCL program for GPU 0...
    17:34:22:818 2b0 done
    17:34:23:036 2b0 GPU #0 is going to use too high intensity (5), not enough GPU memory, intensity value reduced (3)
    17:34:23:038 2b0 GPU #0 algorithm ASM, intensity 3
    17:34:23:039 2b0 Total cards: 1
    17:34:37:454 2b0 Watchdog enabled
    17:34:37:455 2b0 Remote management (READ-ONLY MODE) is enabled on port 3333
    17:34:37:456 2b0

    17:34:37:465 7cc ZEC: Stratum - connecting to 'europe.equihash-hub.miningpoolhub.com' <172.104.127.76> port 20570 (SSL/TLS)
    17:34:38:417 7cc cert subject: /O=mph
    17:34:38:418 7cc cert issuer: /O=mph
    17:34:38:419 7cc SSL/TLS encryption is enabled
    17:34:38:420 7cc send: {"id": 1, "method": "mining.subscribe", "params": ["equihashminer", null, "europe.equihash-hub.miningpoolhub.com", "20570"]}

    17:34:38:422 7cc send: {"id": 2, "method": "mining.authorize", "params": ["mihail_mavrutenkov.r","x"]}

    17:34:38:423 7cc send: {"id": 5, "method": "mining.extranonce.subscribe", "params": []}

    17:34:38:424 7cc ZEC: Stratum - Connected (europe.equihash-hub.miningpoolhub.com:20570) (SSL/TLS)
    17:34:38:745 7cc got 79 bytes
    17:34:38:746 7cc buf: {"id":1,"result":["deadbeefcafebabef7c70b0000000000","3d002a89"],"error":null}

    17:34:38:746 7cc parse packet: 78
    17:34:38:747 7cc new buf size: 0
    17:34:39:058 7cc got 119 bytes
    17:34:39:059 7cc buf: {"id":null,"method":"mining.set_target","params":["0001000000000000000000000000000000000000000000000000000000000000"]}

    17:34:39:059 7cc parse packet: 118
    17:34:39:061 7cc Pool sets new share target: 0x00010000 (diff: 65535H)
    17:34:39:061 7cc new buf size: 0
    17:34:39:062 7cc got 295 bytes
    17:34:39:063 7cc buf: {"id":null,"method":"mining.notify","params":["344e","04000000","81cdb669b57f4405305866d0073bfe2ae7c7f322159e7fda205ca30b00000000","a6da36450c0c6d36f5337a7394e897bfe445e1e8f5e0b103210a7e3b21c600d8","0000000000000000000000000000000000000000000000000000000000000000","6c58f45a","169a0f1c",false]}

    17:34:39:064 7cc parse packet: 294
    17:34:39:065 7cc new buf size: 0
    17:34:39:560 7cc got 36 bytes
    17:34:39:561 7cc buf: {"id":2,"result":true,"error":null}

    17:34:39:562 7cc parse packet: 35
    17:34:39:563 7cc ZEC: Authorized
    17:34:39:564 7cc new buf size: 0
    17:34:39:566 7cc got 119 bytes
    17:34:39:566 7cc buf: {"id":null,"method":"mining.set_target","params":["00087ff978da0165000000000000000000000000000000000000000000000000"]}

    17:34:39:567 7cc parse packet: 118
    17:34:39:568 7cc Pool sets new share target: 0x00087ff9 (diff: 7710H)
    17:34:39:569 7cc new buf size: 0
    17:34:40:458 2b0 OC v7, Reset control for GPU 0, close miner right now if you want to use default control from Catalyst
    17:34:43:460 2b0 OC v7, Reset control for GPU 0, close miner right now if you want to use default control from Catalyst
    17:34:46:463 2b0 GPU 0 temp = 41, old fan speed = 46, new fan speed = 77

    17:34:49:466 2b0 GPU 0 temp = 42, old fan speed = 84, new fan speed = 64

    17:34:52:468 2b0 GPU 0 temp = 43, old fan speed = 74, new fan speed = 51

    17:34:55:470 2b0 GPU 0 temp = 44, old fan speed = 64, new fan speed = 39

    17:34:58:472 2b0 GPU 0 temp = 44, old fan speed = 54, new fan speed = 27

    17:35:01:474 2b0 GPU 0 temp = 45, old fan speed = 41, new fan speed = 25

    17:35:01:552 904 warning: solutions buf overflow, 195 > 20
    17:35:04:476 2b0 GPU 0 temp = 46, old fan speed = 39, new fan speed = 25

    17:35:07:479 2b0 GPU 0 temp = 46, old fan speed = 39, new fan speed = 25

    17:35:07:481 2b0 GPU0 t=46C fan=39%
    17:35:07:482 2b0 em hbt: 0, fm hbt: 31,
    17:35:07:483 2b0 watchdog - thread 0, hb time 514
    17:35:07:484 2b0 watchdog - thread 1, hb time 343
    17:35:07:485 2b0 watchdog - thread 2, hb time 171
    17:35:07:486 2b0 watchdog - thread 3, hb time 686
    17:35:10:488 2b0 GPU 0 temp = 47, old fan speed = 39, new fan speed = 25

    17:35:13:490 2b0 GPU 0 temp = 48, old fan speed = 39, new fan speed = 25

    17:35:16:492 2b0 GPU 0 temp = 48, old fan speed = 39, new fan speed = 25

    17:35:19:562 2b0 GPU 0 temp = 49, old fan speed = 39, new fan speed = 25

    17:35:21:664 7cc got 295 bytes
    17:35:21:665 7cc buf: {"id":null,"method":"mining.notify","params":["344f","04000000","81cdb669b57f4405305866d0073bfe2ae7c7f322159e7fda205ca30b00000000","ecee67f8ede56f7c7ad9a995df79d288115a18f530f3d4bc7101266c5ab84299","0000000000000000000000000000000000000000000000000000000000000000","a358f45a","169a0f1c",false]}

    17:35:21:665 7cc parse packet: 294
    17:35:21:666 7cc new buf size: 0
    17:35:21:667 7cc ZEC: 05/10/18-17:35:21 - New job from europe.equihash-hub.miningpoolhub.com:20570
    17:35:21:668 7cc target: 0x00087ff9 (diff: 7710H)
    17:35:21:670 7cc ZEC - Total Speed: 129.981 H/s, Total Shares: 0, Rejected: 0, Time: 00:00
    17:35:21:671 7cc ZEC: GPU0 129.981 H/s
    17:35:22:162 aac warning: solutions buf overflow, 433 > 20
    17:35:22:607 2b0 GPU 0 temp = 49, old fan speed = 39, new fan speed = 25

    17:35:25:609 2b0 GPU 0 temp = 50, old fan speed = 39, new fan speed = 25

    17:35:27:580 904 warning: solutions buf overflow, 197 > 20
    17:35:28:611 2b0 GPU 0 temp = 51, old fan speed = 39, new fan speed = 25

    17:35:31:613 2b0 GPU 0 temp = 51, old fan speed = 39, new fan speed = 25

    17:35:34:615 2b0 GPU 0 temp = 51, old fan speed = 39, new fan speed = 25

    17:35:37:618 2b0 GPU 0 temp = 52, old fan speed = 39, new fan speed = 25

    17:35:37:621 2b0 GPU0 t=52C fan=39%
    17:35:37:622 2b0 em hbt: 0, fm hbt: 63,
    17:35:37:623 2b0 watchdog - thread 0, hb time 421
    17:35:37:624 2b0 watchdog - thread 1, hb time 250
    17:35:37:625 2b0 watchdog - thread 2, hb time 78
    17:35:37:625 2b0 watchdog - thread 3, hb time 609
    17:35:40:628 2b0 GPU 0 temp = 52, old fan speed = 39, new fan speed = 25

    17:35:43:630 2b0 GPU 0 temp = 53, old fan speed = 39, new fan speed = 25

    17:35:46:632 2b0 GPU 0 temp = 53, old fan speed = 39, new fan speed = 25

    17:35:49:634 2b0 GPU 0 temp = 54, old fan speed = 39, new fan speed = 25

    17:35:52:636 2b0 GPU 0 temp = 54, old fan speed = 39, new fan speed = 25

    17:35:52:740 904 ZEC: put share nonce d86
    17:35:52:741 904 ZEC round found 1 shares
    17:35:52:742 7cc ZEC: 05/10/18-17:35:52 - SHARE FOUND - (GPU 0)
    17:35:52:743 7cc send share: {"id": 4, "method": "mining.submit", "params": ["mihail_mavrutenkov.r","344f","a358f45a","860d0000000000000000000000000000000000000000000000000000","fd40050012fc5c9cc866e2ed8bc15e8d5ff18c9a37569c09377
    17:35:53:096 7cc got 36 bytes
    17:35:53:097 7cc buf: {"id":4,"result":true,"error":null}

    17:35:53:097 7cc parse packet: 35
    17:35:53:099 7cc ZEC: Share accepted (359 ms)!

    17:35:53:099 7cc new buf size: 0
    17:35:55:638 2b0 GPU 0 temp = 55, old fan speed = 39, new fan speed = 25

    17:35:58:641 2b0 GPU 0 temp = 55, old fan speed = 39, new fan speed = 25

    17:36:01:644 2b0 GPU 0 temp = 55, old fan speed = 39, new fan speed = 25

    17:36:04:646 2b0 GPU 0 temp = 56, old fan speed = 39, new fan speed = 25

    17:36:07:649 2b0 GPU 0 temp = 56, old fan speed = 39, new fan speed = 25

    17:36:07:652 2b0 GPU0 t=56C fan=39%
    17:36:07:653 2b0 em hbt: 0, fm hbt: 94,
    17:36:07:654 2b0 watchdog - thread 0, hb time 437
    17:36:07:654 2b0 watchdog - thread 1, hb time 265
    17:36:07:655 2b0 watchdog - thread 2, hb time 78
    17:36:07:656 2b0 watchdog - thread 3, hb time 608
    17:36:07:743 bb0 warning: solutions buf overflow, 120 > 20
    17:36:10:658 2b0 GPU 0 temp = 57, old fan speed = 39, new fan speed = 25

    17:36:13:660 2b0 GPU 0 temp = 57, old fan speed = 39, new fan speed = 25

    17:36:16:663 2b0 GPU 0 temp = 57, old fan speed = 39, new fan speed = 25

    17:36:16:730 7cc got 295 bytes
    17:36:16:731 7cc buf: {"id":null,"method":"mining.notify","params":["3450","04000000","81cdb669b57f4405305866d0073bfe2ae7c7f322159e7fda205ca30b00000000","9d41dba07a59f09236a7acabc9cdb25847c01466c772674b1445b7a59c2263ac","0000000000000000000000000000000000000000000000000000000000000000","db58f45a","169a0f1c",false]}

    17:36:16:731 7cc parse packet: 294
    17:36:16:732 7cc new buf size: 0
    17:36:16:733 7cc ZEC: 05/10/18-17:36:16 - New job from europe.equihash-hub.miningpoolhub.com:20570
    17:36:16:734 7cc target: 0x00087ff9 (diff: 7710H)
    17:36:16:735 7cc ZEC - Total Speed: 130.819 H/s, Total Shares: 1, Rejected: 0, Time: 00:01
    17:36:16:737 7cc ZEC: GPU0 130.819 H/s
    17:36:19:665 2b0 GPU 0 temp = 58, old fan speed = 39, new fan speed = 25

    17:36:22:377 bb0 warning: solutions buf overflow, 52 > 20
    17:36:22:667 2b0 GPU 0 temp = 58, old fan speed = 39, new fan speed = 25

    17:36:25:669 2b0 GPU 0 temp = 58, old fan speed = 39, new fan speed = 25

    17:36:28:671 2b0 GPU 0 temp = 59, old fan speed = 39, new fan speed = 25

    17:36:31:673 2b0 GPU 0 temp = 59, old fan speed = 39, new fan speed = 25

    17:36:34:676 2b0 GPU 0 temp = 59, old fan speed = 39, new fan speed = 25

    17:36:37:678 2b0 GPU 0 temp = 60, old fan speed = 39, new fan speed = 25

    17:36:37:680 2b0 GPU0 t=60C fan=39%
    17:36:37:681 2b0 em hbt: 0, fm hbt: 15,
    17:36:37:682 2b0 watchdog - thread 0, hb time 499
    17:36:37:683 2b0 watchdog - thread 1, hb time 327
    17:36:37:684 2b0 watchdog - thread 2, hb time 156
    17:36:37:685 2b0 watchdog - thread 3, hb time 671
    17:36:40:686 2b0 GPU 0 temp = 60, old fan speed = 39, new fan speed = 25

    17:36:43:688 2b0 GPU 0 temp = 60, old fan speed = 39, new fan speed = 25

    17:36:46:691 2b0 GPU 0 temp = 60, old fan speed = 39, new fan speed = 25

    17:36:49:693 2b0 GPU 0 temp = 61, old fan speed = 39, new fan speed = 25

    17:36:50:068 aac warning: solutions buf overflow, 151 > 20
    17:36:52:696 2b0 GPU 0 temp = 61, old fan speed = 39, new fan speed = 25

    17:36:54:248 aac ZEC: put share nonce 106d
    17:36:54:249 aac ZEC round found 1 shares
    17:36:54:250 7cc ZEC: 05/10/18-17:36:54 - SHARE FOUND - (GPU 0)
    17:36:54:251 7cc send share: {"id": 4, "method": "mining.submit", "params": ["mihail_mavrutenkov.r","3450","db58f45a","6d100000000000000000000000000000000000000000000000000000","fd4005004c85196d4058c4b55392200632c49193b3d22744008
    17:36:55:698 2b0 GPU 0 temp = 61, old fan speed = 39, new fan speed = 25

    17:36:58:701 2b0 GPU 0 temp = 61, old fan speed = 39, new fan speed = 25

    17:37:01:703 2b0 GPU 0 temp = 62, old fan speed = 39, new fan speed = 25

    17:37:04:705 2b0 GPU 0 temp = 62, old fan speed = 39, new fan speed = 25

    17:37:07:708 2b0 GPU 0 temp = 62, old fan speed = 39, new fan speed = 25

    17:37:07:710 2b0 GPU0 t=62C fan=39%
    17:37:07:712 2b0 em hbt: 0, fm hbt: 46,
    17:37:07:712 2b0 watchdog - thread 0, hb time 577
    17:37:07:713 2b0 watchdog - thread 1, hb time 390
    17:37:07:714 2b0 watchdog - thread 2, hb time 218
    17:37:07:715 2b0 watchdog - thread 3, hb time 46
    17:37:10:717 2b0 GPU 0 temp = 62, old fan speed = 39, new fan speed = 25

    17:37:13:719 2b0 GPU 0 temp = 62, old fan speed = 39, new fan speed = 25

    17:37:14:110 c34 warning: solutions buf overflow, 214 > 20
    17:37:16:721 2b0 GPU 0 temp = 62, old fan speed = 39, new fan speed = 25

    17:37:19:724 2b0 GPU 0 temp = 63, old fan speed = 39, new fan speed = 25

    17:37:22:726 2b0 GPU 0 temp = 63, old fan speed = 39, new fan speed = 25

    17:37:25:125 aac warning: solutions buf overflow, 202 > 20
    17:37:25:730 2b0 GPU 0 temp = 63, old fan speed = 39, new fan speed = 25

    Msiexec64.exe değilse ismi ne isterseniz diye combo dosyasınıda atabiliim.







  • önce windowsu güvenli modda başlat. regedite gir aşağıdaki tüm kayıtları elle tek tek sil

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

    daha sonra aşağıdaki klasörlerin içindekileri temizle.
    C:\Users\GB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Burda dosyalar gizli olabilir klasör seçeneklerinden gizli dosyaları göster yap.

    daha sonra çalıştıra msconfig yaz enterla açılan pencerede başlatma sekmesine git tüm tikleri kaldır kaydet.

    sonra tekrar tespit ettiğin exe dosyalarını sil ve windowsu normal başlat.

    yine geri gelirlerse format dostum antivirüsler bi halta yaramıyor.

    kolay gelsin




  • Yapay Zeka’dan İlgili Konular
    Wuauclt.exe nedir? virüsmüdür?
    14 yıl önce açıldı
    svchost.exe hatası
    17 yıl önce açıldı
    avg antivirüs
    2 yıl önce açıldı
    Daha Fazla Göster
    
Sayfa: 1
- x
Bildirim
mesajınız kopyalandı (ctrl+v) yapıştırmak istediğiniz yere yapıştırabilirsiniz.