Выполните скрипт в AVZ из папки Autologger\AV\av_z.exe:
Код:
begin
DeleteFile('C:\Program Files\Bonjour\mDNSResponder.exe', '64');
DeleteFile('C:\Program Files\Netmarble\Netmarble Launcher\Netmarble Launcher.exe', '32');
DeleteFile('C:\Users\alexp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent Web.lnk', '64');
DeleteService('NetShieldKitSvc');
DeleteService('WinSetupMon');
RegKeyParamDel('HKEY_USERS', '.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x64');
RegKeyParamDel('HKEY_USERS', 'S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x32');
RegKeyParamDel('HKEY_USERS', 'S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x64');
RegKeyParamDel('HKEY_USERS', 'S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x32');
RegKeyParamDel('HKEY_USERS', 'S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x64');
RegKeyParamDel('HKEY_USERS', 'S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x32');
RegKeyParamDel('HKEY_USERS', 'S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x64');
RegKeyParamDel('HKEY_USERS', 'S-1-5-21-3826645219-2081751773-1208502310-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x32');
RegKeyParamDel('HKEY_USERS', 'S-1-5-21-3826645219-2081751773-1208502310-1001_Classes\Software\Microsoft\Windows\CurrentVersion\Run', 'GoogleDriveFS', 'x64');
DeleteSchedulerTask('GoogleUpdateTaskMachineCore');
DeleteSchedulerTask('GoogleUpdateTaskMachineUA');
DeleteSchedulerTask('Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser');
DeleteSchedulerTask('NetShield Kit scheduled Autoupdate');
DeleteSchedulerTask('NetShield Kit Self Repair');
DeleteSchedulerTask('Telamon Cleaner');
ExecuteSysClean;
ExecuteRepair(3);
ExecuteRepair(4);
ExecuteWizard('SCU', 2, 2, true);
RebootWindows(false);
end.
Компьютер перезагрузится.
Запустите HijackThis, расположенный в папке Autologger и пофиксите только эти строки:
Код:
O15 - Trusted Zone: *.localhost
O15 - Trusted Zone: http://webcompanion.com
O17 - DHCP DNS 1: 185.192.111.210
O17 - DHCP DNS 2: 37.59.58.122
O17 - HKLM\System\CCS\Services\Tcpip\..\{39d15045-2a30-11ea-839b-806e6f6e6963}: [NameServer] = 185.192.111.210
O17 - HKLM\System\CCS\Services\Tcpip\..\{39d15045-2a30-11ea-839b-806e6f6e6963}: [NameServer] = 37.59.58.122
O17 - HKLM\System\CCS\Services\Tcpip\..\{40393a16-5f53-4c1a-9fba-129d3dbc1bf0}: [NameServer] = 185.192.111.210
O17 - HKLM\System\CCS\Services\Tcpip\..\{40393a16-5f53-4c1a-9fba-129d3dbc1bf0}: [NameServer] = 37.59.58.122
O17 - HKLM\System\CCS\Services\Tcpip\..\{4d1d9cb2-4263-431d-b47e-8bacd84a2faa}: [NameServer] = 185.192.111.210
O17 - HKLM\System\CCS\Services\Tcpip\..\{4d1d9cb2-4263-431d-b47e-8bacd84a2faa}: [NameServer] = 37.59.58.122
O17 - HKLM\System\CCS\Services\Tcpip\..\{9d78c7b9-ae9a-49aa-b9c3-5b1e865458f4}: [NameServer] = 185.192.111.210
O17 - HKLM\System\CCS\Services\Tcpip\..\{9d78c7b9-ae9a-49aa-b9c3-5b1e865458f4}: [NameServer] = 37.59.58.122
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: [SearchList] = localdomain
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive1: (no name) - {BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive2: (no name) - {5AB7172C-9C11-405C-8DD5-AF20F3606282} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive3: (no name) - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive4: (no name) - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive5: (no name) - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive6: (no name) - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive7: (no name) - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive1: (no name) - {BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive2: (no name) - {5AB7172C-9C11-405C-8DD5-AF20F3606282} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive3: (no name) - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive4: (no name) - {F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive5: (no name) - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive6: (no name) - {9AA2F32D-362A-42D9-9328-24A483E2CCC3} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive7: (no name) - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} - (no file)
Сделайте лог Malwarebytes AdwCleaner.