Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
QuarantineFile('C:\Windows\System32\comparevers.exe','');
DeleteFile('C:\Users\артем\Desktop\SpyHunter 4.21.10.4585 Portable by wood\esgiguard.sys','32');
DeleteFile('C:\Windows\System32\comparevers.exe','32');
DeleteFile('C:\Windows\system32\Tasks\cvc','64');
DeleteService('esgiguard');
ExecuteFile('schtasks.exe', '/delete /TN "cvc" /F', 0, 15000, true);
DelBHO('{0633EE93-D776-472f-A0FF-E1416B8B2E3D}');
DelBHO('{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}');
DelBHO('{2670000A-7350-4f3c-8081-5663EE0C6C49}');
BC_ImportAll;
ExecuteRepair(21);
ExecuteWizard('SCU', 2, 3, true);
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
begin
CreateQurantineArchive('c:\quarantine.zip');
end.
start
CreateRestorePoint:
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
CHR HKU\S-1-5-21-702486136-2279187319-2471415920-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [imhlianhlhdicjchlbmbfaefhhjencbe] - hxxps://clients2.google.com/service/update2/crx
CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{2D6BD2F0-5F84-4a06-924F-AEE0598B6272}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{64A9418A-B6B1-4112-B75C-E61633C9A31F}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File
CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{6775BBF1-8D9D-4D14-A999-4E78DF8DCEC6}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File
CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{6A2E142B-EA63-433A-AC05-5223CBD26E65}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File
CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{6AFCC535-2F12-4F50-9F0A-1CF856CFC95D}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File
CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{97836AB9-12C5-4C30-A128-B75196DD1787}\InprocServer32 -> no filepath
AlternateDataStreams: C:\ProgramData\TEMP:41ADDB8A [282]
AlternateDataStreams: C:\ProgramData\TEMP:83893510 [154]
AlternateDataStreams: C:\ProgramData\TEMP:A064CECC [138]
AlternateDataStreams: C:\Users\Все пользователи\TEMP:41ADDB8A [282]
AlternateDataStreams: C:\Users\Все пользователи\TEMP:83893510 [154]
AlternateDataStreams: C:\Users\Все пользователи\TEMP:A064CECC [138]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"
EmptyTemp:
Reboot:
end
Создайте текстовый файл fixlist.txt в папке с Farbar Recovery Scan Tool.
Cкопируйте в него текст из окна ниже и сохраните.
Отключите до перезагрузки антивирус, запустите FRST, нажмите Fix и подождите. Программа создаст лог-файл (Fixlog.txt). Прикрепите его к своему следующему сообщению.Код:start CreateRestorePoint: GroupPolicy: Restriction <======= ATTENTION GroupPolicy\User: Restriction <======= ATTENTION GroupPolicyScripts: Restriction <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION CHR HKU\S-1-5-21-702486136-2279187319-2471415920-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [imhlianhlhdicjchlbmbfaefhhjencbe] - hxxps://clients2.google.com/service/update2/crx CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{2D6BD2F0-5F84-4a06-924F-AEE0598B6272}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{64A9418A-B6B1-4112-B75C-E61633C9A31F}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{6775BBF1-8D9D-4D14-A999-4E78DF8DCEC6}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{6A2E142B-EA63-433A-AC05-5223CBD26E65}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{6AFCC535-2F12-4F50-9F0A-1CF856CFC95D}\InprocServer32 -> C:\Users\3C26~1\AppData\Local\Temp\mcse64_00.dll => No File CustomCLSID: HKU\S-1-5-21-702486136-2279187319-2471415920-1000_Classes\CLSID\{97836AB9-12C5-4C30-A128-B75196DD1787}\InprocServer32 -> no filepath AlternateDataStreams: C:\ProgramData\TEMP:41ADDB8A [282] AlternateDataStreams: C:\ProgramData\TEMP:83893510 [154] AlternateDataStreams: C:\ProgramData\TEMP:A064CECC [138] AlternateDataStreams: C:\Users\Все пользователи\TEMP:41ADDB8A [282] AlternateDataStreams: C:\Users\Все пользователи\TEMP:83893510 [154] AlternateDataStreams: C:\Users\Все пользователи\TEMP:A064CECC [138] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service" EmptyTemp: Reboot: end
Компьютер будет перезагружен автоматически.
SecurityCheck by glax24 & Severnyj v.1.4.0.46 [22.09.16]Подготовьте лог SecurityCheck by glax24: https://safezone.cc/resources/security-check-by-glax24.25/
Ещё раз спасибо огромное, чтоб без вас делалиОбновляйте программы по ссылкам и читайте: https://safezone.cc/threads/rekomendacii-posle-udalenija-vredonosnogo-po.16715/