...
Запустите FRST и нажмите один раз на кнопку Fix и подождите.
Код |
---|
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File FirewallRules: [{4EDD521D-2E06-4722-A2F5-4C763B60D57E}] => (Allow) LPort=50248 FirewallRules: [{2679733B-70FA-4B3F-B112-CFEE1B2BDD21}] => (Allow) C:\Users\eugen\AppData\Local\Programs\Opera\60.0.3255.151\opera.exe => No File FirewallRules: [{8C02CABD-3823-4569-9374-08B3FD6C5FC8}] => (Allow) LPort=50248 FirewallRules: [{CEE3CB19-875C-4E27-A49E-B88BBE810B9A}] => (Allow) C:\ProgramData\Windows\rutserv.exe => No File FirewallRules: [{5A9E5F4C-85F3-4E6F-8B0B-9356FFFE1885}] => (Block) LPort=445 FirewallRules: [{B6408552-4A43-44B0-9082-B0929ECB6B40}] => (Block) LPort=445 FirewallRules: [{411F1A99-C48A-4713-A9D7-AE148F25B12D}] => (Block) LPort=139 FirewallRules: [{23A33B83-5BF7-449F-B368-3AE437A6D8E3}] => (Block) LPort=139 FirewallRules: [{E489DBAC-8490-4766-98E1-1F0DE2EA6C96}] => (Allow) LPort=3389 FirewallRules: [{0E8AAEBA-9AB7-44B3-A508-577EC10F20AF}] => (Allow) LPort=3389 FirewallRules: [{7DE4F665-E9EA-442E-9F90-BA2565B5EEE8}] => (Allow) C:\Users\eugen\AppData\Local\Programs\Opera\70.0.3728.165\opera.exe => No File HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-1746922213-3879629762-2739902823-1001\...\Policies\Explorer: [] HKU\S-1-5-21-1746922213-3879629762-2739902823-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1746922213-3879629762-2739902823-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1746922213-3879629762-2739902823-1001\...\Policies\Explorer\DisallowRun: [10] Cezurity_Scanner_Pro_Free.exe HKU\S-1-5-21-1746922213-3879629762-2739902823-1001\...\Policies\Explorer\DisallowRun: [11] Cube.exe GroupPolicy: Restriction ? <==== ATTENTION GroupPolicy\User: Restriction ? <==== ATTENTION Task: {BE93E16B-6407-413F-A625-D4D2A9F5B1B3} - System32\Tasks\Microsoft\Windows\Wininet\Taskhostw => C:\Programdata\RealtekHD\taskhostw.exe <==== ATTENTION Task: {CA0A88E9-9FB3-4890-83F1-AD819061570E} - System32\Tasks\Microsoft\Windows\Wininet\RealtekHDStartUP Task: {DEED6A6E-6A1F-4671-B827-964901C6298C} - System32\Tasks\Microsoft\Windows\Wininet\RealtekHDControl => C:\Programdata\RealtekHD\taskhost.exe <==== ATTENTION Task: {EC53AA9E-EF5C-4241-A465-B5CFEAE7D7A8} - System32\Tasks\Microsoft\Windows\Wininet\Taskhost => C:\Programdata\RealtekHD\taskhostw.exe <==== ATTENTION CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] S3 esihdrv; \??\C:\Users\eugen\AppData\Local\Temp\esihdrv.sys [X] <==== ATTENTION 2020-10-23 16:20 - 2020-10-23 16:20 - 000000000 ____D C:\Users\Все пользователи\Malwarebytes 2020-10-23 16:20 - 2020-10-23 16:20 - 000000000 ____D C:\ProgramData\Malwarebytes 2020-10-30 14:57 - 2019-06-23 23:06 - 000000000 ____D C:\Users\eugen\Doctor Web 2020-10-16 14:49 C:\AdwCleaner 2020-10-16 14:49 C:\KVRT_Data 2020-10-16 14:49 C:\Program Files\AVAST Software 2020-10-16 14:49 C:\Program Files\AVG 2020-10-16 14:49 C:\Program Files\Cezurity 2020-10-16 14:49 C:\Program Files\COMODO 2020-10-16 14:49 C:\Program Files\Enigma Software Group 2020-10-16 14:49 C:\Program Files\ESET 2020-10-16 14:49 C:\Program Files\Kaspersky Lab 2020-10-16 14:49 C:\Program Files\Malwarebytes 2020-10-16 14:49 C:\Program Files\SpyHunter 2020-10-16 14:49 C:\Program Files (x86)\360 2020-10-16 14:49 C:\Program Files (x86)\AVAST Software 2020-10-16 14:49 C:\Program Files (x86)\AVG 2020-10-16 14:49 C:\Program Files (x86)\Cezurity 2020-10-16 14:49 C:\Program Files (x86)\GRIZZLY Antivirus 2020-10-16 14:49 C:\Program Files (x86)\Kaspersky Lab 2020-10-16 14:49 C:\Program Files (x86)\Microsoft JDX 2020-10-16 14:49 C:\Program Files (x86)\Panda Security 2020-10-16 14:49 C:\Program Files (x86)\SpyHunter 2020-10-16 14:49 C:\WINDOWS\speechstracing 2020-10-16 14:49 C:\Program Files\Common Files\McAfee 2020-10-16 14:49 C:\ProgramData\AVAST Software 2020-10-20 17:50 C:\ProgramData\Doctor Web 2020-10-16 14:49 C:\ProgramData\ESET 2020-10-16 14:49 C:\ProgramData\grizzly 2020-10-16 14:49 C:\ProgramData\Indus 2020-10-16 14:49 C:\ProgramData\Kaspersky Lab 2020-10-16 14:49 C:\ProgramData\Kaspersky Lab Setup Files 2020-10-16 14:49 C:\ProgramData\McAfee 2020-10-16 14:49 C:\ProgramData\Norton 2020-10-16 14:49 C:\Users\Все пользователи\AVAST Software 2020-10-20 17:50 C:\Users\Все пользователи\Doctor Web 2020-10-16 14:49 C:\Users\Все пользователи\ESET 2020-10-16 14:49 C:\Users\Все пользователи\grizzly 2020-10-16 14:49 C:\Users\Все пользователи\Indus 2020-10-16 14:49 C:\Users\Все пользователи\Kaspersky Lab 2020-10-16 14:49 C:\Users\Все пользователи\Kaspersky Lab Setup Files 2020-10-16 14:49 C:\Users\Все пользователи\McAfee 2020-10-16 14:49 C:\Users\Все пользователи\Norton EmptyTemp: Reboot: |
+
Выполните лог в AdwCleaner
после завершения сканирования:
Записи относящиеся к Mail.Ru и Yandex можете не удалять ( если пользуетесь программой )
На вкладке:
Папки (Folders) для Mail.Ru и Yandex снимите [V]
Удалите найденное в AdwCleaner по кнопке Очистить (Clean), подтвердите действие
с автоперезагрузкой
Проверяем, как работает система...
и
Пишем по _общему результату лечения.