Актвного заражения нет, остатки троянов и мусор.
Выполните скрипт в AVZ:
Код:
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
TerminateProcessByName('c:\program files (x86)\gamexpservice\gamexpsvc.exe');
StopService('gamexpsvc');
DeleteFile('c:\program files (x86)\gamexpservice\gamexpsvc.exe', '');
DeleteFile('C:\Program Files (x86)\GameXPService\gamexpsvc.exe', '64');
DeleteService('gamexpsvc');
DeleteFileMask('c:\program files (x86)\gamexpservice', '*', true);
DeleteFileMask('c:\users\victor\appdata\roaming\curl', '*', true);
DeleteDirectory('c:\program files (x86)\gamexpservice');
DeleteDirectory('c:\users\victor\appdata\roaming\curl');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NeoRouter Network Explorer.lnk', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Watch.lnk', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Victor^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Twitch.lnk', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Lite Automount', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dropbox', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GameXP AccessPoint', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Kerio VPN Client', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MailRuUpdater', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VKSaver', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\wA-jgWn8M4.exe', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\World of Warships', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\Kerio Control VPN Client Service', 'x64');
RegKeyDel('HKEY_LOCAL_MACHINE', 'SYSTEM\CurrentControlSet\Services\Eventlog\Application\LogMeIn Guardian', 'x64');
DeleteSchedulerTask('{05DB1D95-EA61-41F0-A51B-725DABF67453}');
DeleteSchedulerTask('{73BBD4F3-8C5D-4AE6-A9BE-F13FD9E96F8C}');
DeleteSchedulerTask('{F5AB4A2F-A105-4534-97FA-02B1B9B19067}');
DeleteSchedulerTask('curl');
DeleteSchedulerTask('curls');
DeleteSchedulerTask('GameNet');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(false);
end.
Компьютер перезагрузится.
Скачайте, распакуйте и запустите утилиту ClearLNK. Скопируйте текст ниже в окно утилиты и нажмите "Лечить".
Код:
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk" -> ["C:\Program Files (x86)\Mozilla Firefox\firefox.exe"]
>>> "C:\Users\Victor\Desktop\Progs\Mozilla Firefox.lnk" -> ["C:\Program Files (x86)\Mozilla Firefox\firefox.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC Browser\Uninstall UC Browser.lnk" -> ["C:\Program Files (x86)\UCBrowser\Application\Uninstall.exe" =>> --uninstall --system-level]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET\ESET NOD32 Antivirus\ESET NOD32 Antivirus.lnk" -> ["C:\Program Files\ESET\ESET Security\egui.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk" -> ["C:\WINDOWS\system32\StikyNot.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk" -> ["C:\Program Files\Windows Journal\Journal.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk" -> ["C:\WINDOWS\ehome\ehshell.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk" -> ["C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Documentation\OpenVPN Manual Page.lnk" -> ["C:\OpenVPN\doc\openvpn.8.html"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Documentation\OpenVPN Windows Notes.lnk" -> ["C:\OpenVPN\doc\INSTALL-win32.txt"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Utilities\Generate a static OpenVPN key.lnk" -> ["C:\OpenVPN\bin\openvpn.exe" =>> --pause-exit --verb 3 --genkey --secret "C:\OpenVPN\config\key.txt"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Shortcuts\OpenVPN Sample Configuration Files.lnk" -> ["C:\OpenVPN\sample-config"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Shortcuts\OpenVPN log file directory.lnk" -> ["C:\OpenVPN\log"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Shortcuts\OpenVPN configuration file directory.lnk" -> ["C:\OpenVPN\config"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\OpenVPN GUI.lnk" -> ["C:\OpenVPN\bin\openvpn-gui.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN\Uninstall OpenVPN.lnk" -> ["C:\OpenVPN\Uninstall.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall\RaidCall.lnk" -> ["C:\Program Files (x86)\RaidCall.RU\raidcall.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall\Uninstall RaidCall.lnk" -> ["C:\Program Files (x86)\RaidCall.RU\uninst.exe"]
>>> "C:\Users\Victor\Дия\от старшекурсников\Антона Соловьева\ИИ\Сделаные лабы\Кузнечик.lnk" -> ["D:\Учеба\4 курс\ИИ\Сделаные лабы\Hop\bin\Debug\Hop.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aladdin\HASP License Manager\HASP License Manager Help.lnk" -> ["C:\Program Files (x86)\Aladdin\HASP LM\nhsrvw32.hlp"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\TeamSpeak 3 Client.lnk" -> ["C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\Uninstall.lnk" -> ["C:\Program Files (x86)\TeamSpeak 3 Client\Uninstall.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PES 2015 Patch Tuga Vicio v1.0\Pes 2015 Selector.lnk" -> ["C:\Program Files (x86)\Pro Evolution Soccer 2015\Pes 2015 Selector.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast\SopCast.lnk" -> ["C:\Program Files (x86)\SopCast\SopCast.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast\SopCast web site.lnk" -> ["C:\Program Files (x86)\SopCast\SopCast web site.url"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast\Uninstall.lnk" -> ["C:\Program Files (x86)\SopCast\uninst.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDRViewer\CDR Viewer.lnk" -> ["C:\Program Files (x86)\CDRViewer\CDRViewer.exe"]
>>> "C:\Users\Victor\Desktop\всё для 1с\!Консоль8.2\!Консоль8.2\Скрипт горячих клавиш UCR.lnk" -> ["C:\Program Files\Универсальная консоль отчетов (UCR)\AutoIt.Exe" =>> C:\Program Files\Универсальная консоль отчетов (UCR)\hotkey.au3]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin.lnk" -> ["C:\Program Files (x86)\Origin\Origin.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Средство отправки отчетов об ошибках Origin.lnk" -> ["C:\Program Files (x86)\Origin\OriginER.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Удаление Origin.lnk" -> ["C:\Program Files (x86)\Origin\OriginUninstall.exe"]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk" -> ["C:\Users\Victor\AppData\Roaming\Curse Client\Bin\Twitch.exe"]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\956dcf162a936b0d\Heroes and generals.lnk" -> ["I:\steam\Steam.exe" =>> steam://run/227940]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\JP2View.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\JP2View.exe"]
>>> "C:\Users\Victor\Desktop\всё для 1с\!Консоль8.2\!Консоль8.2\Универсальная консоль отчетов 8.1\Скрипт горячих клавиш UCR.lnk" -> ["C:\Program Files\Универсальная консоль отчетов (UCR)\AutoIt.Exe" =>> C:\Program Files\Универсальная консоль отчетов (UCR)\hotkey.au3]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\BearPaw Panel.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\Panel.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Help\Software.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Driver\Software.chm"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Help\Hardware.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Driver\Hardware.chm"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Scanner Settings.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\Settings.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Bonus Features\Smart Photo Refresh .lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\Plug-in\SPF\SPFresh.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Bonus Features\Smart Image Merge.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\Plug-in\SIM\MergeImage.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Bonus Features\e-Photo Snap.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\Plug-in\EPS\e-PhotoSnap.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BearPaw 2448CU Pro\Bonus Features\e-Photo Snap Settings.lnk" -> ["C:\Program Files (x86)\BearPaw 2448CU Pro\Panel\Plug-in\EPS\ePSnapSetting.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Service Center.lnk" -> ["C:\Program Files\Native Instruments\Service Center\ServiceCenter.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\Readme.txt.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation\Readme.txt"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\Service Center Manual German.pdf.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation\Service Center Manual German.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\Service Center Manual English.pdf.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation\Service Center Manual English.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\Service Center Manual French.pdf.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation\Service Center Manual French.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\Service Center Manual Spanish.pdf.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation\Service Center Manual Spanish.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\Service Center Manual Japanese.pdf.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation\Service Center Manual Japanese.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Documentation\More Documentation.lnk" -> ["C:\Program Files\Native Instruments\Service Center\Documentation"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Rig Kontrol 3\Rig Kontrol 3 Control Panel.lnk" -> ["C:\Program Files\Native Instruments\Rig Kontrol 3 Driver\rig3cpl.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Rig Kontrol 3\Documentation\Rig Kontrol 3 Manual English.pdf.lnk" -> ["C:\Program Files\Native Instruments\Rig Kontrol 3 Driver\Documentation\Rig Kontrol 3 Manual English.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Rig Kontrol 3\Documentation\Rig Kontrol 3 Manual French.pdf.lnk" -> ["C:\Program Files\Native Instruments\Rig Kontrol 3 Driver\Documentation\Rig Kontrol 3 Manual French.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Rig Kontrol 3\Documentation\Rig Kontrol 3 Manual German.pdf.lnk" -> ["C:\Program Files\Native Instruments\Rig Kontrol 3 Driver\Documentation\Rig Kontrol 3 Manual German.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Rig Kontrol 3\Documentation\Rig Kontrol 3 Manual Japanese.pdf.lnk" -> ["C:\Program Files\Native Instruments\Rig Kontrol 3 Driver\Documentation\Rig Kontrol 3 Manual Japanese.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Rig Kontrol 3\Documentation\Rig Kontrol 3 Manual Spanish.pdf.lnk" -> ["C:\Program Files\Native Instruments\Rig Kontrol 3 Driver\Documentation\Rig Kontrol 3 Manual Spanish.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Guitar Rig Session IO Control Panel.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Session IO Driver\sesscpl.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Documentation\Guitar Rig Session IO Manual English.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Session IO Driver\Documentation\Guitar Rig Session IO Manual English.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Documentation\Guitar Rig Session IO Manual French.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Session IO Driver\Documentation\Guitar Rig Session IO Manual French.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Documentation\Guitar Rig Session IO Manual German.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Session IO Driver\Documentation\Guitar Rig Session IO Manual German.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Documentation\Guitar Rig Session IO Manual Japanese.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Session IO Driver\Documentation\Guitar Rig Session IO Manual Japanese.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Documentation\Guitar Rig Session IO Manual Spanish.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Session IO Driver\Documentation\Guitar Rig Session IO Manual Spanish.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Controller Editor\Controller Editor.lnk" -> ["C:\Program Files\Native Instruments\Controller Editor\Controller Editor.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Mobile IO\Guitar Rig Mobile IO Control Panel.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Mobile IO Driver\grmobilecpl.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Mobile IO\Documentation\Guitar Rig Mobile IO Manual English.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Mobile IO Driver\Documentation\Guitar Rig Mobile IO Manual English.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Mobile IO\Documentation\Guitar Rig Mobile IO Manual French.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Mobile IO Driver\Documentation\Guitar Rig Mobile IO Manual French.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Mobile IO\Documentation\Guitar Rig Mobile IO Manual German.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Mobile IO Driver\Documentation\Guitar Rig Mobile IO Manual German.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Mobile IO\Documentation\Guitar Rig Mobile IO Manual Japanese.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Mobile IO Driver\Documentation\Guitar Rig Mobile IO Manual Japanese.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Mobile IO\Documentation\Guitar Rig Mobile IO Manual Spanish.pdf.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig Mobile IO Driver\Documentation\Guitar Rig Mobile IO Manual Spanish.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UVI Workstation x64\UVI Workstation x64.lnk" -> ["C:\Program Files\UVI Workstation x64\UVIWorkstationx64.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UVI Workstation x64\Manual.lnk" -> ["C:\Program Files\UVI Workstation x64\UVIWorkstation User Guide JP.pdf"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UVI Workstation x64\www.uvi.net.lnk" -> ["C:\Program Files\UVI Workstation x64\UVI.url"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UVI Workstation x64\Uninstall UVI Workstation.lnk" -> ["C:\Program Files\UVI Workstation x64\unins000.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig 5\Guitar Rig 5.lnk" -> ["C:\Program Files\Native Instruments\Guitar Rig 5\Guitar Rig 5.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLok License Manager.lnk" -> ["C:\Program Files (x86)\iLok License Manager\iLok License Manager.exe"]
>>> "C:\Users\Victor\AppData\Roaming\Autodesk\AutoCAD 2016\R20.1\rus\Plotters\Мастер установки плоттеров.lnk" -> ["E:\a\AutoCAD 2016\addplwiz.exe" =>> /LANGUAGE ru-RU]
>>> "C:\Users\Victor\AppData\Roaming\Autodesk\AutoCAD 2016\R20.1\rus\Plotters\Plot Styles\Мастер стилей печати.lnk" -> ["E:\a\AutoCAD 2016\styshwiz.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameNet.lnk" -> ["C:\Program Files (x86)\QGNA\qGNA.exe"]
>>> "C:\Users\Victor\Desktop\Progs\Acrobat Reader DC.lnk" -> ["C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe"]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent Web.lnk" -> ["C:\Users\Victor\AppData\Roaming\BitTorrent Web\btweb.exe"]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor Plus 2020\Сайт Movavi Video Editor Plus 2020.lnk" -> ["I:\Movavy Video Editor Plus 2020\Movavi Video Editor Plus 2020\Movavi Video Editor Plus 2020.url"]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor Plus 2020\Movavi Video Editor Plus 2020.lnk" -> ["I:\Movavy Video Editor Plus 2020\Movavi Video Editor Plus 2020\VideoEditorPlus.exe"]
>>> "C:\Users\Victor\Desktop\Movavi Video Editor Plus 2020.lnk" -> ["I:\Movavy Video Editor Plus 2020\Movavi Video Editor Plus 2020\VideoEditorPlus.exe"]
>>> "C:\Users\Victor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor Plus 2020\Удалить Movavi Video Editor Plus 2020.lnk" -> ["I:\Movavy Video Editor Plus 2020\Movavi Video Editor Plus 2020\uninst.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stronghold Crusader HD\Stronghold Crusader HD.lnk" -> ["C:\Program Files (x86)\Stronghold Crusader Extreme HD\Stronghold Crusader.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stronghold Crusader HD\Stronghold Crusader Extreme HD.lnk" -> ["C:\Program Files (x86)\Stronghold Crusader Extreme HD\Stronghold_Crusader_Extreme.exe"]
>>> "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stronghold Crusader HD\Деинсталлировать Stronghold Crusader HD.lnk" -> ["C:\Program Files (x86)\Stronghold Crusader Extreme HD\unins000.exe"]
Отчёт о работе прикрепите.
Сделайте лог Malwarebytes AdwCleaner.