Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
Подготовьте логи по правилам: https://safezone.cc/pravila/
begin
 QuarantineFile('C:\ProgramData\Microsoft\Search\setup.exe', '');
 DeleteFile('C:\ProgramData\Microsoft\Search\setup.exe', '64');
 DeleteService('HSUURMZV');
ExecuteSysClean;
 ExecuteWizard('TSW', 2, 3, true);
RebootWindows(true);
end.
	begin
 CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
end.
	O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\TEMP\cb21287db4b311f08f7c8c870b6009af.tmp -> DELETE
O18 - HKLM\Software\Classes\Protocols\Filter\application/octet-stream: [CLSID] = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - (no file)
O18 - HKLM\Software\Classes\Protocols\Filter\application/x-complus: [CLSID] = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - (no file)
O18 - HKLM\Software\Classes\Protocols\Filter\application/x-msdownload: [CLSID] = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - (no file)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{658B15EB-DC2D-482A-8FE4-AB09CD9B06BD} - (no key)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{658B15EB-DC2D-482A-8FE4-AB09CD9B06BD} - \dialersvc64 (no xml)
O26 - Office Addin: HKLM\..\AccessAddin.DC - (Microsoft Access Outlook Add-in for Data Collection and Publishing) -> (no file)
	Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
RemoveProxy:
S2 HitmanPro38CrusaderBoot; "C:\Users\DZ\AppData\Local\Temp\scoped_dir10024_398579015\HitmanPro_x64.exe" /crusader:boot [X] <==== ВНИМАНИЕ
AlternateDataStreams: C:\Windows\System32:sguard [36]
AlternateDataStreams: C:\Windows\tracing:? [16]
AlternateDataStreams: C:\Users\DZ\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\DZ\Downloads\adwcleaner.exe:MBAM.Zone.Identifier [293]
AlternateDataStreams: C:\Users\DZ\Downloads\MBSetup (3).exe:MBAM.Zone.Identifier [297]
AlternateDataStreams: C:\Users\DZ\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
StartPowershell:
Remove-MpPreference -ExclusionExtension ".exe"
Remove-MpPreference -ExclusionPath "C:\Windows\system32\config\systemprofile"
Remove-MpPreference -ExclusionPath "C:\ProgramData"
Set-MpPreference -DisableAutoExclusions $true -Force
Set-MpPreference -Mapsreporting basic -Force
Set-MpPreference -DisableRealtimeMonitoring $false -Force
Set-MpPreference -DisablePrivacyMode $true -Force
Set-MpPreference -DisableIOAVProtection $false -Force
Set-MpPreference -UILockdown 0
Set-MpPreference -ScanPurgeItemsAfterDelay 1
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true -Force
Set-MpPreference -PUAProtection enabled -Force
Update-MpSignature
Get-MpComputerStatus
Get-MpPreference
EndPowerShell:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::
	пока не восстанавливается, послежу пару дней отпишу)) спасибо за помощь!!!Если нажать карантин - восстанавливается?
