Пароли RDP = паролям пользователя. Effector saver - в настройках программы (закладка активные задачи).
Проверьте администраторов, нет ли лишних:
Buh3 (S-1-5-21-1449044906-2441549753-1413590287-1012 - Administrator - Enabled) => C:\Users\Buh3
systembackup (S-1-5-21-1449044906-2441549753-1413590287-1014 - Administrator - Enabled)
Администратор (S-1-5-21-1449044906-2441549753-1413590287-500 - Administrator - Enabled) => C:\Users\Администратор
Теневые копии проверяли?
Отключите до перезагрузки антивирус.
Выделите следующий код:
Код:
Start::
CreateRestorePoint:
() [File not signed] C:\Users\Buh3\Music\Desktop_Locker.exe
HKU\S-1-5-21-1449044906-2441549753-1413590287-1012\...\Run: [Desktop_Locker_456] => C:\Users\Buh3\Music\Desktop_Locker.exe [279303 2019-04-25] () [File not signed]
HKU\S-1-5-21-1449044906-2441549753-1413590287-1012\...\Run: [A5AD6CC7-945FA664hta] => C:\Users\Buh3\AppData\Local\Temp\how_to_decrypt.hta [6036 2020-10-22] () [File not signed] <==== ATTENTION
2020-10-22 03:38 - 2020-10-22 03:38 - 000006036 _____ C:\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\Downloads\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\Documents\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\Desktop\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ C:\Users\Администратор\AppData\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\Downloads\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\Documents\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\Desktop\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\zavhoz\AppData\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\systembackup\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Public\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Public\Downloads\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\Downloads\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\Documents\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\Desktop\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ C:\Users\Otb\AppData\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Otb\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Otb\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\Downloads\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\Documents\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\Desktop\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:35 - 2020-10-22 03:35 - 000006036 _____ C:\Users\Geg\AppData\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\Downloads\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\Documents\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\Desktop\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default\AppData\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\Downloads\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\Documents\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\Desktop\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Default User\AppData\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\Downloads\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\Documents\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\Desktop\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:34 - 2020-10-22 03:34 - 000006036 _____ C:\Users\Buh3\AppData\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\Downloads\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\Documents\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\Desktop\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh2\AppData\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\Downloads\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\Documents\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\Desktop\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:33 - 2020-10-22 03:33 - 000006036 _____ C:\Users\Buh1\AppData\how_to_decrypt.hta
2020-10-22 03:32 - 2020-10-22 03:32 - 000006036 _____ C:\Users\Buh1\AppData\LocalLow\how_to_decrypt.hta
2020-10-22 03:32 - 2020-10-22 03:32 - 000006036 _____ C:\Users\Buh1\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\Users\Все пользователи\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\Users\Все пользователи\Documents\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\Users\Все пользователи\Desktop\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\Users\Public\Documents\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\Users\Public\Desktop\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\Users\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\ProgramData\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\ProgramData\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\ProgramData\Documents\how_to_decrypt.hta
2020-10-22 03:29 - 2020-10-22 03:29 - 000006036 _____ C:\ProgramData\Desktop\how_to_decrypt.hta
2020-10-22 02:58 - 2020-10-22 02:58 - 000006036 _____ C:\Users\Buh3\AppData\Local\Temp\how_to_decrypt.hta
2020-10-22 03:37 - 2020-10-22 03:37 - 000006036 _____ () C:\Users\Администратор\AppData\Roaming\how_to_decrypt.hta
2020-10-22 03:36 - 2020-10-22 03:36 - 000006036 _____ () C:\Users\Администратор\AppData\Local\how_to_decrypt.hta
End::
Скопируйте выделенный текст (правой кнопкой - Копировать).
Запустите FRST (FRST64) от имени администратора.
Нажмите Fix и подождите. Программа создаст лог-файл (Fixlog.txt). Прикрепите его к своему следующему сообщению.
Компьютер перезагрузите вручную.
Подробнее читайте в
этом руководстве .