Имя пользователя:
Пароль:  
Помощь | Регистрация | Забыли пароль?  

Показать сообщение отдельно

Аватара для shestale

Старожил


Сообщения: 387
Благодарности: 96

Профиль | Отправить PM | Цитировать


Выполните скрипт в Farbar Recovery Scan Tool. Лог, который создается после удаления, прикрепите к сообщению.
Код: Выделить весь код
start
CreateRestorePoint:
AlternateDataStreams: C:\KIS9!_2017-09-06_4E6A58AC.key:$CmdZnID [26]
AlternateDataStreams: C:\map.jpg:$CmdZnID [26]
AlternateDataStreams: C:\новый год мои планы.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Windows\PAExec.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\amdgfxinfo64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\amdlvr64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\amdmantle64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\amdmmcl6.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\amdocl12cl64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\amdpcom64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiadlxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiapfxx.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aticalcl64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aticaldd64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aticalrt64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\aticfx64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atidemgy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atidxx64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atieah64.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atieclxx.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiesrxx.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atig6pxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atig6txx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiglpxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atimpc64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atimuixx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atio6axx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ATIODCLI.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\ATIODE.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atitmm64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiu9p64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiumd64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\atiumd6a.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\atiuxp64.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\clinfo.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\coinst_15.30.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\dgtrayicon.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\GameManager64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\hsa-thunk64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mantle64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\mantleaxl64.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\OpenCL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdgfxinfo32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdlvr32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdmantle32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdmmcl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdocl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdocl12cl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\amdpcom32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atiadlxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atiadlxy.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aticalcl.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aticaldd.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aticalrt.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\aticfx32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atidxx32.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\atieah32.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atigktxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atiglpxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atimpc32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atioglxx.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atiu9pag.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atiumdag.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\atiumdva.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\atiuxpag.dll:$CmdTcID [130]
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\GameManager32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\hsa-thunk.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\ISDone.dll:$CmdZnID [26]
AlternateDataStreams: C:\Windows\SysWOW64\mantle32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\mantleaxl32.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\OpenCL.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\SysWOW64\unarc.dll:$CmdZnID [26]
AlternateDataStreams: C:\Windows\system32\Drivers\amdacpksd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\ati2erec.dll:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\atikmdag.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\atikmpag.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\cm_km.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\kl1.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\klbackupdisk.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\klbackupflt.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\kldisk.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\klflt.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\klhk.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\klim6.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\klkbdflt.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\klmouflt.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\klpd.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\kltdi.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\kneps.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mbam.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\mbamchameleon.sys:$CmdTcID [130]
AlternateDataStreams: C:\Windows\system32\Drivers\mwac.sys:$CmdTcID [64]
AlternateDataStreams: C:\Windows\system32\Drivers\tap0901.sys:$CmdTcID [64]
AlternateDataStreams: C:\Users\HDAEROHD\Desktop\карта.jpg:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\adwcleaner_6.041.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\adwcleaner_6.041.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\AutoLogger.zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\Deus Ex Human Revolution. Часть 8. О'Мэлли.mp4:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\DriverPack Solution 16.12 + Драйвер-Паки 16.12.4.torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\SecurityCheck.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\SecurityCheck.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\T_GIRL_IT_TRAIN_WEB_DL_1080p-BLUEBIRD.mkv.torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\[rutor.is]AOMEI_Partition_Assistant_6.0.torrent:$CmdZnID [26]
AlternateDataStreams: C:\Users\HDAEROHD\Downloads\[rutor.is]Mower.Minions.2016.HDRip.AVC.ExKinoRay.mkv.torrent:$CmdZnID [26]
GroupPolicyScripts: Restriction <======= ATTENTION
FF Homepage: Mozilla\Firefox\Profiles\nahd6ha2.default -> hxxp://mail.ru/cnt/10445?gp=820323
CHR HKLM-x32\...\Chrome\Extension: [pnooffjhclkocplopffdbcdghmiffhji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi
CHR HKLM\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi
EmptyTemp:
Reboot:
end

-------
© Рекомендации необходимо выполнять строго в том порядке, в котором они вам даны.


Отправлено: 11:03, 29-12-2016 | #6