<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0">
	<channel>
		<title>Форум esetnod32.ru [тема: Вирус майнер audiodg.exe]</title>
		<link>http://forum.esetnod32.ru</link>
		<description>Новое в теме Вирус майнер audiodg.exe форума  на сайте Форум esetnod32.ru [forum.esetnod32.ru]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Wed, 15 Apr 2026 23:54:59 +0300</pubDate>
		<item>
			<title>Вирус майнер audiodg.exe</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum6/topic17859/message116931/">Вирус майнер audiodg.exe</a></b> в форуме <a href="http://forum.esetnod32.ru/forum6/">Обнаружение вредоносного кода и ложные срабатывания</a>. <br />
			выполняем скрипт в uVS:<br />- стартуем uVS(start.exe от имени Администратора), выбираем: текущий пользователь, <br />- скопировать из браузера содержимое кода в буфер обмена;<br />- закрываем все браузеры перед выполнением скрипта;<br />- меню - скрипты - выполнить скрипт из буфера обмена;<br />
====code====
<pre>

;uVS v4.15.1 &#91;http://dsrt.dyndns.org:8888&#93;
;Target OS: NTv10.0
v400c
OFFSGNSAVE
zoo %SystemDrive%&#92;PROGRAMDATA&#92;MICROSOFT&#92;DRM&#92;0ZUCTIYAZCW&#92;MASTERDATAB.BAT
;------------------------autoscript---------------------------

delall %SystemDrive%&#92;PROGRAM FILES (X86)&#92;ADWCLEANER&#92;ADWCLEANER.EXE
delall %SystemDrive%&#92;PROGRAMDATA&#92;MICROSOFT&#92;WINDOWS&#92;START MENU&#92;PROGRAMS&#92;STARTUP&#92;ADWCLEANER.LNK
delall %SystemDrive%&#92;PROGRAMDATA&#92;MICROSOFT&#92;DRM&#92;0ZUCTIYAZCW&#92;MASTERDATAB.BAT
delall %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;UMMY&#92;UMMY.EXE
delref %SystemDrive%&#92;PROGRAMDATA&#92;MICROSOFT&#92;DRM&#92;0ZUCTIYAZCW&#92;&#92;GAME.EXE
delref SERVICE&#92;WINSERV.EXE
zoo %SystemRoot%&#92;SYSWOW64&#92;UNSECAPP.EXE
addsgn 1A6E769A552B1E3B8236EFE32D4360156C0186D675489FF2838B3A7AD8D139B3E4ACC1573E559D9B5E870E890EE98FEAAFAC0C7287AFB7A63B3F5BE9D7D4512D 8&nbsp;&nbsp;Win64/Packed.Themida.L 7

zoo %SystemDrive%&#92;PROGRAMDATA&#92;WINDOWSTASK&#92;MICROSOFTHOST.EXE
addsgn BA6F9BB2BD5149720B9C2D754C2160FBDA75303A4536D3B4490F09709C1ABD80EFDBA531314A19492B80849F0E95A5EA3156FC561953EC08253A97F48B8B7657 21 Win64/CoinMiner.QG 7

zoo %SystemDrive%&#92;PROGRAMDATA&#92;REAITEKHD&#92;TASKHOSTW.EXE
zoo %SystemDrive%&#92;PROGRAMDATA&#92;WINDOWSTASK&#92;AUDIODG.EXE
zoo %SystemDrive%&#92;PROGRAMDATA&#92;WINDOWS TASKS SERVICE&#92;WINSERV.EXE
addsgn A7679B19919AF4BAC461AE594CAF9BFACD99D70B7612C9950D3C4E7C50D6714C2317C3573E559D492B80849F461649FA7DDFE87255DAB02C2D77A42FC7062273 9 Win32/RemoteAdmin.RemoteUtilities.V 7

zoo %SystemDrive%&#92;PROGRAMDATA&#92;REAITEKHD&#92;TASKHOST.EXE
zoo %SystemDrive%&#92;PROGRAMDATA&#92;MICROSOFT&#92;DRM&#92;0ZUCTIYAZCW&#92;GAME.EXE
addsgn 1A76739A5583C28CF42B95BC0C1E5105D7FFFE044A08F67783C3C57FD3B7754CA8D6403636555A082FE8B4DC46D1487E3F9CE8B100515C7AD202ACA436EE2E47 13 Generik.MKWSFH &#91;ESET-NOD32&#93; 7

addsgn 1A76739A5583C28CF42B95BC0C1E5105D7FFFE044A08F67783C3C57FD3B7754CA8D6403636555A082FE8B4DC46D1487E3F9CE8B100515C7AD202ACA436EE2E47 8 BAT/RA-based.FY &#91;ESET-NOD32&#93; 7

chklst
delvir

delref G:&#92;HISUITEDOWNLOADER.EXE
delref H:&#92;HISUITEDOWNLOADER.EXE
apply

REGT 2
REGT18

deltmp
delref %SystemDrive%&#92;PROGRAM FILES&#92;BLUESTACKS_NXT&#92;BLUESTACKSHELPER.EXE
delref %SystemRoot%&#92;SYSWOW64&#92;GPSVC.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;TCPIP.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;MRXSMB.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;USBXHCI.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;SRV2.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;HTTP.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;UMPOEXT.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;DMVSC.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;SPACEPORT.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;FVEVOL.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERS&#92;AFD.SYS
delref %SystemRoot%&#92;SYSWOW64&#92;LSM.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;BLANK.HTM
delref {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}&#92;&#91;CLSID&#93;
delref {1FBA04EE-3024-11D2-8F1F-0000F87ABD16}&#92;&#91;CLSID&#93;
delref %Sys32%&#92;BLANK.HTM
delref %Sys32%&#92;EUGDIDRV.SYS
delref %SystemDrive%&#92;PROGRAM FILES&#92;ROCKSTAR GAMES&#92;LAUNCHER&#92;ROCKSTARSERVICE.EXE
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.169.31&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.342&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.175.29&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES&#92;BLUESTACKS_NXT&#92;BSTKPROXYSTUB.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.49&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.242&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.55&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.152&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES&#92;BLUESTACKS_NXT&#92;HD-PLAYER.EXE
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.272&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.202&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.212&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.175.27&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.332&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.33.7&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.312&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.292&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;EASEUS&#92;EASEUS PARTITION MASTER&#92;DC&#92;BIN&#92;X64&#92;VSSEASEUSPROVIDER.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.177.11&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES&#92;BLUESTACKS_NXT&#92;BSTKC.DLL
delref %SystemDrive%&#92;PROGRAM FILES&#92;BLUESTACKS_NXT&#92;BSTKSVC.EXE
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.51&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.45&#92;PSMACHINE_64.DLL
delref %SystemDrive%&#92;PROGRAM FILES&#92;COMMON FILES&#92;MICROSOFT SHARED&#92;DAO&#92;DAO360.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;TAPILUA.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.169.31&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.342&#92;PSMACHINE.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERSTORE&#92;FILEREPOSITORY&#92;U0379487.INF_AMD64_69570110508A8108&#92;B379425&#92;AMDHWDECODER_32.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.175.29&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.49&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.242&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.55&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.152&#92;PSMACHINE.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;LISTSVC.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.272&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.202&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.212&#92;PSMACHINE.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERSTORE&#92;FILEREPOSITORY&#92;U0379487.INF_AMD64_69570110508A8108&#92;B379425&#92;AMDH265ENC32.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERSTORE&#92;FILEREPOSITORY&#92;U0379487.INF_AMD64_69570110508A8108&#92;B379425&#92;AMF-MFT-MJPEG-DECODER32.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.175.27&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.332&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.33.7&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.312&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.36.292&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.177.11&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;GOOGLE&#92;UPDATE&#92;1.3.33.7&#92;GOOGLEUPDATEBROKER.EXE
delref %SystemRoot%&#92;SYSWOW64&#92;DRIVERSTORE&#92;FILEREPOSITORY&#92;U0379487.INF_AMD64_69570110508A8108&#92;B379425&#92;AMDH264ENC32.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.51&#92;PSMACHINE.DLL
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;MICROSOFT&#92;EDGEUPDATE&#92;1.3.173.45&#92;PSMACHINE.DLL
delref %SystemRoot%&#92;SYSWOW64&#92;IDLISTEN.DLL
delref %SystemDrive%&#92;PROGRAM FILES&#92;COMMON FILES&#92;SYSTEM&#92;OLE DB&#92;MSDAORA.DLL
delref %SystemDrive%&#92;USERS&#92;USER&#92;APPDATA&#92;LOCAL&#92;PROGRAMS&#92;BLUESTACKS-SERVICES&#92;BLUESTACKSSERVICES.EXE
delref %SystemDrive%&#92;PROGRAM FILES (X86)&#92;EASEUS&#92;EASEUS PARTITION MASTER&#92;BIN&#92;EPMUI.EXE
;-------------------------------------------------------------

restart
czoo
</pre>
=============
<br />перезагрузка, пишем о старых и новых проблемах.<br />------------<br />далее,<br />сделайте логи FRST<br /><noindex><a href="https://forum.esetnod32.ru/forum9/topic2798/" target="_blank" rel="nofollow">https://forum.esetnod32.ru/forum9/topic2798/</a></noindex> <br />
			<i>16.01.2024 00:51:48, santy.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum6/topic17859/message116931/</link>
			<guid>http://forum.esetnod32.ru/messages/forum6/topic17859/message116931/</guid>
			<pubDate>Tue, 16 Jan 2024 00:51:48 +0300</pubDate>
			<category>Обнаружение вредоносного кода и ложные срабатывания</category>
		</item>
		<item>
			<title>Вирус майнер audiodg.exe</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum6/topic17859/message116930/">Вирус майнер audiodg.exe</a></b> в форуме <a href="http://forum.esetnod32.ru/forum6/">Обнаружение вредоносного кода и ложные срабатывания</a>. <br />
			AVbr не запускается<br />закрываются вкладки в браузере поиск файла hosts не работает и закрываются некоторые программы<br />файл образа автозапуска из uVS <br />
			<a href="https://forum.esetnod32.ru/bitrix/components/bitrix/forum.interface/show_file.php?fid=128838">WIN-TVC5KGDBNAA_2024-01-16_00-27-59_v4.15.7z</a><br /><i>16.01.2024 00:31:52, Агент Санчез.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum6/topic17859/message116930/</link>
			<guid>http://forum.esetnod32.ru/messages/forum6/topic17859/message116930/</guid>
			<pubDate>Tue, 16 Jan 2024 00:31:52 +0300</pubDate>
			<category>Обнаружение вредоносного кода и ложные срабатывания</category>
		</item>
	</channel>
</rss>
