Clean Master
McAfee Security Scan Plus
setupsk
YoutubeAdBlock
begin
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
ClearQuarantineEx(true);
TerminateProcessByName('c:\program files (x86)\gbemzxqzbie\heudmvgiqc.exe');
QuarantineFile('C:\Program Files (x86)\aohGTEheqdnWC\eQKwlCE.dll', '');
QuarantineFile('C:\Program Files (x86)\Common Files\IAoIOAugoyuIo.bat', '');
QuarantineFile('C:\Program Files (x86)\fJwAOztOW.bat', '');
QuarantineFile('c:\program files (x86)\gbemzxqzbie\heudmvgiqc.exe', '');
QuarantineFile('C:\Program Files (x86)\GBeMZXQZBIE\klK3GEwU7.dll', '');
QuarantineFile('C:\Program Files (x86)\RrHYXuUpocPTIXdsppR\vCjPKOS.dll', '');
QuarantineFile('C:\Program Files (x86)\TwPufLOWyrxU2\CZEfsdHCcRkpN.dll', '');
QuarantineFile('C:\Program Files (x86)\umkISPBbU\ZfdCRp.dll', '');
QuarantineFile('C:\Users\Элеонора\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe', '');
QuarantineFile('C:\Users\Элеонора\AppData\Local\Kometa\StartButton\kometastartvx64.exe', '');
ExecuteFile('schtasks.exe', '/delete /TN "App Explorer" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "BcyoMZkjXMgFaPP" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "BcyoMZkjXMgFaPP2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "LnvajhyOu" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "plaAVjRQXWCDePSecyr" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "plaAVjRQXWCDePSecyr2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "pnIxobGIUDXdNt" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "saKXaLnxQURzlMgex" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "saKXaLnxQURzlMgex2" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "setupsk_upd" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "suEiACyYhyYOv" /F', 0, 15000, true);
ExecuteFile('schtasks.exe', '/delete /TN "uXUOeJ" /F', 0, 15000, true);
DeleteFile('C:\Program Files (x86)\aohGTEheqdnWC\eQKwlCE.dll', '32');
DeleteFile('C:\Program Files (x86)\Common Files\IAoIOAugoyuIo.bat', '32');
DeleteFile('C:\Program Files (x86)\fJwAOztOW.bat', '32');
DeleteFile('c:\program files (x86)\gbemzxqzbie\heudmvgiqc.exe', '32');
DeleteFile('C:\Program Files (x86)\GBeMZXQZBIE\klK3GEwU7.dll', '32');
DeleteFile('C:\Program Files (x86)\RrHYXuUpocPTIXdsppR\vCjPKOS.dll', '32');
DeleteFile('C:\Program Files (x86)\TwPufLOWyrxU2\CZEfsdHCcRkpN.dll', '32');
DeleteFile('C:\Program Files (x86)\umkISPBbU\ZfdCRp.dll', '32');
DeleteFile('C:\Users\Элеонора\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe', '32');
DeleteFile('C:\Users\Элеонора\AppData\Local\Kometa\StartButton\kometastartvx64.exe', '32');
DelBHO('{C0D38E5A-7CF8-4105-8FE8-31B81443A114}');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'jbzcjwqkoq');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'setupsk');
RegKeyParamDel('HKEY_CURRENT_USER', 'Software\Microsoft\Windows\CurrentVersion\Run', 'setupsk_upd');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
ExecuteSysClean;
ExecuteWizard('SCU', 2, 3, true);
RebootWindows(true);
end.
# AdwCleaner 7.0.6.0 - Logfile created on Wed Jan 10 12:39:46 2018
# AdwCleaner v6.047 - Отчёт создан 10/01/2018 в 16:05:46
Start::
CreateRestorePoint:
GroupPolicy: Restriction - Chrome <==== ATTENTION
2017-12-25 15:52 - 2017-09-29 16:42 - 000001237 _____ C:\Users\Элеонора\aKGMovGooWxO
2017-12-25 15:52 - 2017-09-29 16:42 - 000000060 _____ C:\Program Files (x86)\fJwAOztOW
2017-12-25 15:49 - 2018-01-10 15:01 - 000002644 _____ C:\WINDOWS\System32\Tasks\bltopncomhohoj
2017-09-29 16:42 - 2017-09-29 16:42 - 000001237 _____ () C:\Users\Элеонора\aKGMovGooWxO.bat
Task: {43740F2B-0F5F-48AF-9F33-4696097E5651} - System32\Tasks\bltopncomhohoj => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" bltopn.com/hohoj <==== ATTENTION
EmptyTemp:
Reboot:
End::
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?