Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
O4 - HKCU\..\Run: [ProtonVPN] = C:\Program Files\Proton\VPN\ProtonVPN.Launcher.exe (file missing)
O22 - Tasks: hurry-shop-S-1-5-21-1227249708-149983825-2673253129-1001 - C:\WINDOWS\System32\msiexec.exe /i "C:\Users\ugle_\AppData\Local\Programs\2e4f9b78f5\c95b51189e.msi" /quiet FWVP=1 (sign: 'Microsoft')
O22 - Tasks: melt-sake - C:\ProgramData\relieve-joke\TGMacro.exe /trayMode (file missing)
O22 - Tasks: NinjaBrowserUpdate - C:\Program Files (x86)\NinjaBrowser\1912180306\updater.exe /VERYSILENT /SUPPRESSMSGBOXES (file missing)
O22 - Tasks: NinjaBrowserUpdateLog - C:\Program Files (x86)\NinjaBrowser\1912180306\updater.exe /VERYSILENT /SUPPRESSMSGBOXES (file missing)
O23 - Driver S3: atvi-randgrid - C:\ProgramData\Battle.net_components\randgridauks\randgrid.sys (file missing)
не ставили самостоятельно, деинсталлируйте.detector distract 5.1.40.383
melt-sake
oeksound soothe2
begin
QuarantineFile('C:\Users\ugle_\AppData\Local\Programs\2e4f9b78f5\c95b51189e.msi', '');
QuarantineFile('C:\WINDOWS\SysWOW64\adsiedit.dll', '');
QuarantineFile('c:\windows\System32\adsiedit.dll', '');
DeleteFile('C:\WINDOWS\SysWOW64\adsiedit.dll', '64');
DeleteFile('C:\Users\ugle_\AppData\Local\Programs\2e4f9b78f5\c95b51189e.msi', '64');
DeleteFile('C:\ProgramData\relieve-joke\TGMacro.exe', '64');
DeleteFile('C:\Program Files (x86)\NinjaBrowser\1912180306\updater.exe', '64');
DeleteFile('C:\WINDOWS\syswow64\adsiedit.dll', '32');
DeleteFile('C:\WINDOWS\system32\adsiedit.dll', '32');
DelCLSID('{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}');
RegKeyParamDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\ADSISvc_b7da3e\Parameters', 'ServiceDll', 'x64');
DeleteSchedulerTask('hurry-shop-S-1-5-21-1227249708-149983825-2673253129-1001');
DeleteSchedulerTask('melt-sake');
DeleteSchedulerTask('NinjaBrowserUpdateLog');
DeleteSchedulerTask('NinjaBrowserUpdate');
ExecuteSysClean;
ExecuteWizard('TSW', 2, 3, true);
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
end.
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
RemoveProxy:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ограничение <==== ВНИМАНИЕ
HKU\S-1-5-21-1227249708-149983825-2673253129-1001\...\Run: [Opera Stable] => C:\Users\ugle_\AppData\Local\Programs\Opera\opera.exe (Нет файла)
HKU\S-1-5-21-1227249708-149983825-2673253129-1001\...\Run: [EADM] => "C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe" -silent (Нет файла)
HKU\S-1-5-21-1227249708-149983825-2673253129-1001\...\Run: [Opera Browser Assistant] => C:\Users\ugle_\AppData\Local\Programs\Opera\assistant\browser_assistant.exe (Нет файла)
HKU\S-1-5-21-1227249708-149983825-2673253129-1001\...\Run: [YandexBrowserAutoLaunch_83556BD3FCDCA350477D5794385B7F1E] => "C:\Users\ugle_\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --shutdown-if-not-closed-by-system-restart (Нет файла)
GroupPolicy: Ограничение - Windows Defender <==== ВНИМАНИЕ
Policies: C:\ProgramData\NTUSER.pol: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
C:\Users\ugle_\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hjfhbdephncmhdmomijibpmfiodgjkmm
CHR HKU\S-1-5-21-1227249708-149983825-2673253129-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gndelhfhcfbdhndfpcinebijfcjpmpec]
CHR HKU\S-1-5-21-1227249708-149983825-2673253129-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ilddbkfacgbalaeoadiddiooeenkomlb]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [imamimdkhkjdmcnpifkjndkbgmjgjmdo]
CHR HKLM-x32\...\Chrome\Extension: [kadaohckdkghfaclhjmkmplebcdcnfnp]
S3 ChromiumElevationService; "C:\Program Files (x86)\NinjaBrowser\NinjaBrowser\Application\139.0.7258.155\elevation_service.exe" [X]
S3 EABackgroundService; "C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe" [X]
S3 Rockstar Service; "C:\Program Files\Rockstar Games\Launcher\RockstarService.exe" [X]
2025-12-29 12:43 - 2025-12-29 12:43 - 000000000 __SHD C:\ProgramData\ArtisanDesigner-f5aca758-de75-4bff-83fc-7bf03a24cf15
2025-12-28 18:06 - 2025-12-28 18:06 - 001235139 _____ C:\WINDOWS\SysWOW64\data846.dat
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\ProgramData\WindowsTask
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\ProgramData\Windows Tasks Service
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\ProgramData\Setup
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\ProgramData\ReaItekHD
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\ProgramData\RDP Wrapper
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\Program Files\RDP Wrapper
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 _RSHD C:\Program Files (x86)\360
2025-12-27 18:08 - 2025-12-27 18:08 - 000000000 ____D C:\Program Files (x86)\Avocado past
2025-12-19 18:03 - 2025-12-19 18:03 - 000000000 ____D C:\Users\ugle_\AppData\Local\NinjaBrowser
2025-12-19 18:02 - 2025-12-19 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\thee-shawn
2025-12-27 18:08 C:\Program Files\RDP Wrapper
2025-12-27 18:08 C:\Program Files (x86)\360
2025-12-27 18:08 C:\ProgramData\RDP Wrapper
2025-12-27 18:08 C:\ProgramData\ReaItekHD
2025-12-27 18:08 C:\ProgramData\Setup
2025-12-27 18:08 C:\ProgramData\Windows Tasks Service
2025-12-27 18:08 C:\ProgramData\WindowsTask
Avocado past 3.10.43.968 (HKLM-x32\...\{fdcb3880-a69e-4cd7-af03-2592fbb7b15d}) (Version: 3.10.43.968 - Caruso-Amato Group s.r.l.) Hidden
detector distract 5.1.40.383 (HKLM-x32\...\{010212f2-a6d3-41db-a906-434c2464d859}) (Version: 5.1.40.383 - Swaniawski, Beatty and Toy Ltd) Hidden
StartPowershell:
Set-MpPreference -DisableAutoExclusions $true -Force
Set-MpPreference -Mapsreporting basic -Force
Set-MpPreference -DisableArchiveScanning $false -Force
Set-MpPreference -DisableBehaviorMonitoring $false -Force
Set-MpPreference -DisableRealtimeMonitoring $false -Force
Set-MpPreference -DisablePrivacyMode $true -Force
Set-MpPreference -DisableIOAVProtection $false -Force
Set-MpPreference -UILockdown 0
Set-MpPreference -ScanPurgeItemsAfterDelay 1
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true -Force
Set-MpPreference -PUAProtection enabled -Force
Update-MpSignature
Get-MpComputerStatus
Get-MpPreference
Get-AppxPackage Microsoft.SecHealthUI -AllUsers | Reset-AppxPackage
Get-AppxPackage Microsoft.SecHealthUI -AllUsers|select Name, Status
EndPowershell:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::
Avocado past 3.10.43.968
detector distract 5.1.40.383
melt-sake
Ninja Browser
Start::
Hurry Shop Nearby and Save 1.0.0.0 (HKU\S-1-5-21-1227249708-149983825-2673253129-1001\...\{feb2b8d8-e726-48c8-9270-285fbf87d697}) (Version: 1.0.0.0 - Hurry Shop Nearby and Save) Hidden
End::
Hurry Shop Nearby and Save 1.0.0.0