Все так же как и в этой теме https://safezone.cc/threads/kak-udalit-virus-mem-trojan-multi-cform-b.32981/ После загрузки выскакивает сообщение Касперского о вирусе. Вроде лечит его с проверкой. Но через время опять вылезает.
Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
opensource
SafeFinder
Spybot - Search & Destroy
Weatherbar
Первая скрыта. Пробуйте удалить обе через Geek Uninstalleropensource - такого названия в программах и компонентах нет.
SafeFinder - не удаляется. При нажатии "удалить", ничего не происходит.
WINSNARE
Start::
CreateRestorePoint:
HKLM\...\Providers\2uvkgjnf: C:\Program Files (x86)_\local64spl.dll [142336 2016-09-06] () [File not signed] <==== ATTENTION
HKLM\...\Providers\kzify2uw: C:\Program Files (x86)\\local64spl.dll <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{65122CB0-EA0F-47DF-A953-017170ED12F9}] -> "C:\Program Files (x86)\UCBrowser\Application\5.6.14087.902\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Toolbar: HKU\S-1-5-21-1548130441-1206604947-3116178147-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1548130441-1206604947-3116178147-1001 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
FF ProfilePath: C:\Users\Олег\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\nahd6ha2.default\Profiles\nahd6ha2.default [not found] <==== ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [jdkihdhlegcdggknokfekoemkjjnjhgi] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jggbjbmnfmipgcanidamjfpechdeekoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pchfckkccldkbclgdepkaonamkignanh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pldbienodkpgkccocelidinmciedjdok] - hxxps://clients2.google.com/service/update2/crx
S2 AppleAppSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 AppleAppSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 CWASRE; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 CWASRE; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 NPASRE; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 NPASRE; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 snare; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 snare; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 SNAREA; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 SNAREA; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 SNARER; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 SNARER; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 terana; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 terana; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 WINSNARE; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 WINSNARE; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 WPDTSrv; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 WPDTSrv; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
2019-04-02 18:03 - 2016-08-29 10:26 - 000000000 ____D C:\Users\Олег\AppData\Roaming\IObit
opensource (HKLM-x32\...\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}) (Version: 1.0.14960.3876 - Your Company Name) Hidden
Task: {45208D4C-DE8C-4E6C-99BA-5AA987D3B9A0} - \Milimili -> No File <==== ATTENTION
Task: {46ADD188-4730-4D39-AFEF-A2EEAA7685A1} - \{797F0547-0904-0E08-0A11-7E0E0C7D1108} -> No File <==== ATTENTION
Task: {55ACD0CA-348E-4D13-9CAC-916570626F65} - \Windows-PG -> No File <==== ATTENTION
Task: C:\Windows\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION
AlternateDataStreams: C:\Users\Олег\Local Settings:wa [146]
AlternateDataStreams: C:\Users\Олег\AppData\Local:wa [146]
AlternateDataStreams: C:\Users\Олег\AppData\Local\Application Data:wa [146]
HKU\S-1-5-21-1548130441-1206604947-3116178147-1001\Software\Classes\.scr: scrfile => <==== ATTENTION
EmptyTemp:
Reboot:
End::