Перезапустил машину, обнаружил уведомление от центра безопасности, что антивирус не запущен. Навожу мышкой на значек антивируса, на нем "Dr.Web is starting....". Изредка похожее поведение вижу на других машинах, тут поймал на своей. Что-то я могу сделать для помощи в отлове такого злодейства, чтобы оно больше не повторялось? Дамп с процесса снять не выходит, т.к. не выходит отключить самозащиту. Антивирус при этом действительно не работает совсем, лог спайдергейта с момента выключения не обновлялся, как и лог гейта. Лог запуска dwservice с момента перезагрузки и до текущего момента:
Spoiler
2016-Sep-16 17:55:11.694673 [1172] [LOG] Starting service...
===============================================================================
Dr.Web Control Service for Windows v11.0.9.08101
Copyright © Doctor Web, Ltd., 1992-2016
Current arch: x64
Binary: x64
Operating System: win/nt/seven
Command line: C:\Program Files\DrWeb\dwservice.exe --logfile=C:\ProgramData\Doctor Web\Logs\dwservice.log
===============================================================================
2016-Sep-16 17:55:11.694673 [1896] [INF] [service_main] !Set SERVICE_RUNNING successfully...Start
2016-Sep-16 17:55:11.694673 [1896] [INF] [svc] Unable to open FW driver. Disabling service ...
2016-Sep-16 17:55:11.725873 [1896] [INF] [subsysmanager] Starting STANDALONE components...
2016-Sep-16 17:55:11.788273 [1896] [INF] [template-parser] xml for lang: cn was successfully loaded from file
2016-Sep-16 17:55:11.803873 [1896] [INF] [template-parser] xml for lang: cs was successfully loaded from file
2016-Sep-16 17:55:11.819473 [1896] [INF] [template-parser] xml for lang: de was successfully loaded from file
2016-Sep-16 17:55:11.866273 [1896] [INF] [template-parser] xml for lang: en was successfully loaded from file
2016-Sep-16 17:55:11.913073 [1896] [INF] [template-parser] xml for lang: es was successfully loaded from file
2016-Sep-16 17:55:11.991073 [1896] [INF] [template-parser] xml for lang: et was successfully loaded from file
2016-Sep-16 17:55:12.006673 [1896] [INF] [template-parser] xml for lang: fr was successfully loaded from file
2016-Sep-16 17:55:12.022273 [1896] [INF] [template-parser] xml for lang: it was successfully loaded from file
2016-Sep-16 17:55:12.037873 [1896] [INF] [template-parser] xml for lang: ja was successfully loaded from file
2016-Sep-16 17:55:12.053473 [1896] [INF] [template-parser] xml for lang: kk was successfully loaded from file
2016-Sep-16 17:55:12.084673 [1896] [INF] [template-parser] xml for lang: ko was successfully loaded from file
2016-Sep-16 17:55:12.115873 [1896] [INF] [template-parser] xml for lang: lv was successfully loaded from file
2016-Sep-16 17:55:12.147073 [1896] [INF] [template-parser] xml for lang: pl was successfully loaded from file
2016-Sep-16 17:55:12.162673 [1896] [INF] [template-parser] xml for lang: pt was successfully loaded from file
2016-Sep-16 17:55:12.209473 [1896] [INF] [template-parser] xml for lang: ru was successfully loaded from file
2016-Sep-16 17:55:12.225073 [1896] [INF] [template-parser] xml for lang: sk was successfully loaded from file
2016-Sep-16 17:55:12.240673 [1896] [INF] [template-parser] xml for lang: tr was successfully loaded from file
2016-Sep-16 17:55:12.287474 [1896] [INF] [template-parser] xml for lang: uk was successfully loaded from file
2016-Sep-16 17:55:12.334274 [1896] [INF] [template-parser] xml for lang: zh was successfully loaded from file
2016-Sep-16 17:55:12.334274 [1896] [INF] [config] Create
2016-Sep-16 17:55:12.334274 [1896] [INF] [win_upgrade] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [wsc] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [protection] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [ark-daemon] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [hips] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [licenses] Create
2016-Sep-16 17:55:12.334274 [1896] [INF] [secrets] Create
2016-Sep-16 17:55:12.334274 [1896] [INF] [qr] create
2016-Sep-16 17:55:12.443474 [1896] [INF] [event-manager] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [local-services] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [components] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [spider_scan] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [Updater] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [backup] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [Scheduler] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [multicast] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [fw_client] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [sysinfo] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [statistics] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [cluster] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [virtual-fs] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [dws9rpc] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [email] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [subsysmanager] esmode
2016-Sep-16 17:55:12.474674 [1896] [INF] [subsysmanager] Creating ES components...
2016-Sep-16 17:55:12.474674 [1896] [INF] [DbStorage] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [DbStorage] db path: C:\ProgramData\Doctor Web\Database
2016-Sep-16 17:55:12.474674 [1896] [INF] [DbStorage] Trying to open DB for the current thread
2016-Sep-16 17:55:12.786674 [1896] [INF] [DbStorage] DB opened successfully
2016-Sep-16 17:55:12.786674 [1896] [INF] [DbStorage] dbi created
2016-Sep-16 17:55:12.786674 [1896] [INF] [DbStorage] exec: "DELETE FROM admin_message"
2016-Sep-16 17:55:12.880275 [1896] [INF] [Reconnector] Create reconnector
2016-Sep-16 17:55:12.880275 [1896] [INF] [EsUpdLoader] Create
2016-Sep-16 17:55:12.880275 [1896] [INF] [event_processor] create
2016-Sep-16 17:55:12.880275 [1896] [INF] [QWatcher] Create
2016-Sep-16 17:55:12.880275 [1896] [INF] [escanner] Create
2016-Sep-16 17:55:12.880275 [1896] [INF] [plugins] create
2016-Sep-16 17:55:12.895875 [1896] [ERR] [template-parser] switching templates to language -d failed. xml document is not loaded. Switched to default language: en
2016-Sep-16 17:55:12.895875 [1896] [INF] [template-parser] stages: retcode_descrs {
retcode: UNKNOWN_ERROR
text: "see log file for details"
}
retcode_descrs {
retcode: SERVER_CONNECT_ERROR
text: "unable to connect to update servers"
}
stage_descrs {
numbers: CREATING_MIRROR
text: "creating mirror"
}
stage_descrs {
numbers: UPDATING_PRODUCTS
text: "downloading files"
}
stage_descrs {
numbers: POSTUPDATING
text: "checking integrity"
}
2016-Sep-16 17:55:12.895875 [1896] [INF] [template-parser] finished loading templates for lang: en
2016-Sep-16 17:55:12.895875 [1896] [INF] [hips] Set ShellGuard status: enable
2016-Sep-16 17:55:12.942675 [1896] [INF] [Updater] set Updater logs to INFO
2016-Sep-16 17:55:12.958275 [1896] [INF] [win_upgrade] start
2016-Sep-16 17:55:12.989475 [1896] [INF] [wsc] start
2016-Sep-16 17:55:13.114275 [1896] [ERR] [get_spiderg3_state] SpiderG3State: -1; RpcStatus: 1722
2016-Sep-16 17:55:13.114275 [1896] [ERR] [get_engine_state] Exception at [engine_client.info]. Code 1722 "The RPC server is unavailable. ".
2016-Sep-16 17:55:13.114275 [1896] [INF] [wsc] fill_comp_state: fw: 5 av: 4 as: 1
2016-Sep-16 17:55:13.114275 [1896] [INF] [protection] start
2016-Sep-16 17:55:13.114275 [2084] [INF] [wsc] COM Initialized code: 0
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] Remove 0 element from class list
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] Add 34 classes to list.
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] load bucket 0 success
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] load bucket 1 success
2016-Sep-16 17:55:13.145475 [1896] [INF] [ark-daemon] start
2016-Sep-16 17:55:13.270275 [1896] [ERR] [get_spiderg3_state] SpiderG3State: -1; RpcStatus: 1722
2016-Sep-16 17:55:13.270275 [1896] [ERR] [get_engine_state] Exception at [engine_client.info]. Code 1722 "The RPC server is unavailable. ".
2016-Sep-16 17:55:17.341882 [1896] [INF] [ark] load and init success version: 11.1.6.2016_08_17_0, API version = 806
2016-Sep-16 17:55:17.341882 [1896] [INF] [ark] system hash: AAA4C28443CE6097256EEAB88E3BE381
2016-Sep-16 17:55:17.341882 [1896] [INF] [ark-daemon] started...
2016-Sep-16 17:55:17.357482 [1896] [INF] [DPH] reinit objects...
2016-Sep-16 17:55:17.357482 [1896] [INF] [HIPSObject] Total 155 values for protect
2016-Sep-16 17:55:17.357482 [1896] [INF] [DPH] reinit objects success
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] <DefH> started.
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] <DelH> started.
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] <HrdH> started.
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] Manager started...3 workers.
2016-Sep-16 17:55:17.419883 [1896] [INF] [hips] set hips status: 1
2016-Sep-16 17:55:19.572686 [1896] [ERR] [licenses] failed to load bool from registry: The system cannot find the file specified.
2016-Sep-16 17:55:19.572686 [1896] [ERR] [licenses] failed to load int from registry: The system cannot find the file specified.
2016-Sep-16 17:55:19.619486 [1896] [INF] [qr] start
2016-Sep-16 17:55:19.619486 [1896] [INF] [event-manager] start
2016-Sep-16 17:55:19.759887 [1896] [INF] [event-manager] database version is 1
2016-Sep-16 17:55:20.118687 [1896] [INF] [local-service] restore states for files: 0 devguard_enabled: 0
2016-Sep-16 17:55:22.489891 [2084] [INF] [wsc] AV registered: 1 FW registered: 0 AS registered: 1
===============================================================================
Dr.Web Control Service for Windows v11.0.9.08101
Copyright © Doctor Web, Ltd., 1992-2016
Current arch: x64
Binary: x64
Operating System: win/nt/seven
Command line: C:\Program Files\DrWeb\dwservice.exe --logfile=C:\ProgramData\Doctor Web\Logs\dwservice.log
===============================================================================
2016-Sep-16 17:55:11.694673 [1896] [INF] [service_main] !Set SERVICE_RUNNING successfully...Start
2016-Sep-16 17:55:11.694673 [1896] [INF] [svc] Unable to open FW driver. Disabling service ...
2016-Sep-16 17:55:11.725873 [1896] [INF] [subsysmanager] Starting STANDALONE components...
2016-Sep-16 17:55:11.788273 [1896] [INF] [template-parser] xml for lang: cn was successfully loaded from file
2016-Sep-16 17:55:11.803873 [1896] [INF] [template-parser] xml for lang: cs was successfully loaded from file
2016-Sep-16 17:55:11.819473 [1896] [INF] [template-parser] xml for lang: de was successfully loaded from file
2016-Sep-16 17:55:11.866273 [1896] [INF] [template-parser] xml for lang: en was successfully loaded from file
2016-Sep-16 17:55:11.913073 [1896] [INF] [template-parser] xml for lang: es was successfully loaded from file
2016-Sep-16 17:55:11.991073 [1896] [INF] [template-parser] xml for lang: et was successfully loaded from file
2016-Sep-16 17:55:12.006673 [1896] [INF] [template-parser] xml for lang: fr was successfully loaded from file
2016-Sep-16 17:55:12.022273 [1896] [INF] [template-parser] xml for lang: it was successfully loaded from file
2016-Sep-16 17:55:12.037873 [1896] [INF] [template-parser] xml for lang: ja was successfully loaded from file
2016-Sep-16 17:55:12.053473 [1896] [INF] [template-parser] xml for lang: kk was successfully loaded from file
2016-Sep-16 17:55:12.084673 [1896] [INF] [template-parser] xml for lang: ko was successfully loaded from file
2016-Sep-16 17:55:12.115873 [1896] [INF] [template-parser] xml for lang: lv was successfully loaded from file
2016-Sep-16 17:55:12.147073 [1896] [INF] [template-parser] xml for lang: pl was successfully loaded from file
2016-Sep-16 17:55:12.162673 [1896] [INF] [template-parser] xml for lang: pt was successfully loaded from file
2016-Sep-16 17:55:12.209473 [1896] [INF] [template-parser] xml for lang: ru was successfully loaded from file
2016-Sep-16 17:55:12.225073 [1896] [INF] [template-parser] xml for lang: sk was successfully loaded from file
2016-Sep-16 17:55:12.240673 [1896] [INF] [template-parser] xml for lang: tr was successfully loaded from file
2016-Sep-16 17:55:12.287474 [1896] [INF] [template-parser] xml for lang: uk was successfully loaded from file
2016-Sep-16 17:55:12.334274 [1896] [INF] [template-parser] xml for lang: zh was successfully loaded from file
2016-Sep-16 17:55:12.334274 [1896] [INF] [config] Create
2016-Sep-16 17:55:12.334274 [1896] [INF] [win_upgrade] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [wsc] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [protection] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [ark-daemon] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [hips] create
2016-Sep-16 17:55:12.334274 [1896] [INF] [licenses] Create
2016-Sep-16 17:55:12.334274 [1896] [INF] [secrets] Create
2016-Sep-16 17:55:12.334274 [1896] [INF] [qr] create
2016-Sep-16 17:55:12.443474 [1896] [INF] [event-manager] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [local-services] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [components] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [spider_scan] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [Updater] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [backup] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [Scheduler] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [multicast] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [fw_client] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [sysinfo] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [statistics] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [cluster] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [virtual-fs] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [dws9rpc] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [email] create
2016-Sep-16 17:55:12.474674 [1896] [INF] [subsysmanager] esmode
2016-Sep-16 17:55:12.474674 [1896] [INF] [subsysmanager] Creating ES components...
2016-Sep-16 17:55:12.474674 [1896] [INF] [DbStorage] Create
2016-Sep-16 17:55:12.474674 [1896] [INF] [DbStorage] db path: C:\ProgramData\Doctor Web\Database
2016-Sep-16 17:55:12.474674 [1896] [INF] [DbStorage] Trying to open DB for the current thread
2016-Sep-16 17:55:12.786674 [1896] [INF] [DbStorage] DB opened successfully
2016-Sep-16 17:55:12.786674 [1896] [INF] [DbStorage] dbi created
2016-Sep-16 17:55:12.786674 [1896] [INF] [DbStorage] exec: "DELETE FROM admin_message"
2016-Sep-16 17:55:12.880275 [1896] [INF] [Reconnector] Create reconnector
2016-Sep-16 17:55:12.880275 [1896] [INF] [EsUpdLoader] Create
2016-Sep-16 17:55:12.880275 [1896] [INF] [event_processor] create
2016-Sep-16 17:55:12.880275 [1896] [INF] [QWatcher] Create
2016-Sep-16 17:55:12.880275 [1896] [INF] [escanner] Create
2016-Sep-16 17:55:12.880275 [1896] [INF] [plugins] create
2016-Sep-16 17:55:12.895875 [1896] [ERR] [template-parser] switching templates to language -d failed. xml document is not loaded. Switched to default language: en
2016-Sep-16 17:55:12.895875 [1896] [INF] [template-parser] stages: retcode_descrs {
retcode: UNKNOWN_ERROR
text: "see log file for details"
}
retcode_descrs {
retcode: SERVER_CONNECT_ERROR
text: "unable to connect to update servers"
}
stage_descrs {
numbers: CREATING_MIRROR
text: "creating mirror"
}
stage_descrs {
numbers: UPDATING_PRODUCTS
text: "downloading files"
}
stage_descrs {
numbers: POSTUPDATING
text: "checking integrity"
}
2016-Sep-16 17:55:12.895875 [1896] [INF] [template-parser] finished loading templates for lang: en
2016-Sep-16 17:55:12.895875 [1896] [INF] [hips] Set ShellGuard status: enable
2016-Sep-16 17:55:12.942675 [1896] [INF] [Updater] set Updater logs to INFO
2016-Sep-16 17:55:12.958275 [1896] [INF] [win_upgrade] start
2016-Sep-16 17:55:12.989475 [1896] [INF] [wsc] start
2016-Sep-16 17:55:13.114275 [1896] [ERR] [get_spiderg3_state] SpiderG3State: -1; RpcStatus: 1722
2016-Sep-16 17:55:13.114275 [1896] [ERR] [get_engine_state] Exception at [engine_client.info]. Code 1722 "The RPC server is unavailable. ".
2016-Sep-16 17:55:13.114275 [1896] [INF] [wsc] fill_comp_state: fw: 5 av: 4 as: 1
2016-Sep-16 17:55:13.114275 [1896] [INF] [protection] start
2016-Sep-16 17:55:13.114275 [2084] [INF] [wsc] COM Initialized code: 0
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] Remove 0 element from class list
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] Add 34 classes to list.
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] load bucket 0 success
2016-Sep-16 17:55:13.145475 [1896] [INF] [protection] load bucket 1 success
2016-Sep-16 17:55:13.145475 [1896] [INF] [ark-daemon] start
2016-Sep-16 17:55:13.270275 [1896] [ERR] [get_spiderg3_state] SpiderG3State: -1; RpcStatus: 1722
2016-Sep-16 17:55:13.270275 [1896] [ERR] [get_engine_state] Exception at [engine_client.info]. Code 1722 "The RPC server is unavailable. ".
2016-Sep-16 17:55:17.341882 [1896] [INF] [ark] load and init success version: 11.1.6.2016_08_17_0, API version = 806
2016-Sep-16 17:55:17.341882 [1896] [INF] [ark] system hash: AAA4C28443CE6097256EEAB88E3BE381
2016-Sep-16 17:55:17.341882 [1896] [INF] [ark-daemon] started...
2016-Sep-16 17:55:17.357482 [1896] [INF] [DPH] reinit objects...
2016-Sep-16 17:55:17.357482 [1896] [INF] [HIPSObject] Total 155 values for protect
2016-Sep-16 17:55:17.357482 [1896] [INF] [DPH] reinit objects success
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] <DefH> started.
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] <DelH> started.
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] <HrdH> started.
2016-Sep-16 17:55:17.373082 [1896] [INF] [DPH] Manager started...3 workers.
2016-Sep-16 17:55:17.419883 [1896] [INF] [hips] set hips status: 1
2016-Sep-16 17:55:19.572686 [1896] [ERR] [licenses] failed to load bool from registry: The system cannot find the file specified.
2016-Sep-16 17:55:19.572686 [1896] [ERR] [licenses] failed to load int from registry: The system cannot find the file specified.
2016-Sep-16 17:55:19.619486 [1896] [INF] [qr] start
2016-Sep-16 17:55:19.619486 [1896] [INF] [event-manager] start
2016-Sep-16 17:55:19.759887 [1896] [INF] [event-manager] database version is 1
2016-Sep-16 17:55:20.118687 [1896] [INF] [local-service] restore states for files: 0 devguard_enabled: 0
2016-Sep-16 17:55:22.489891 [2084] [INF] [wsc] AV registered: 1 FW registered: 0 AS registered: 1
Отчет с машины приложил, могу попробовать ещё снять полный дамп памяти вашей утилитой, т.к. на ручной дамп машина не настроена. Что-то я ещё могу сделать?
Прикрепленные файлы:
- WS-020_eg_190916_091514.zip 9,49Мб 6 Скачано раз