This log shows you ran the previous fix again. I need you to run the latest one.
Code:
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
RemoveProxy:
C:\Windows\system32\drivers\etc\hosts.ics
C:\Windows\system32\drivers\etc\hosts
Hosts:
HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\Run: [RuntimeBroker_tMaIE] => wscript.exe "C:\Users\Isaac\AppData\Roaming\tMaIE.vbs" (No File) <==== ATTENTION
C:\Users\Isaac\AppData\Roaming\tMaIE.vbs
HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\Run: [MicrosoftEdgeAutoLaunch_E61B34E8EC343F2555F1806FED7939D1] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4088272 2023-07-21] (Microsoft Corporation -> Microsoft Corporation)
CHR Extension: (Google Drive) - C:\Users\Isaac\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hlkmeeakkncieeijddcglidlhknobaff [2023-04-08] [UpdateUrl:hxxps://web-extensions.net/updates?x=_\u003Cextension_data>_] <==== ATTENTION
CHR Extension: (Google Drive) - C:\Users\Isaac\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hlkmeeakkncieeijddcglidlhknobaff [2023-04-08] [UpdateUrl:hxxps://web-extensions.net/updates?x=_\u003Cextension_data>_] <==== ATTENTION
CHR HomePage: Profile 3 -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311256¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC2KfnG8vMCKm3vGZa%2FXNlWN0tXIMKbngDuAjl4mz0LjLQt%2B1clYw9AXDdKfbY0VltFgRBsV5W1gBD40yD%2Fa%2Bf6hwgm%2FhRnHfjTwklzVl%2B3J4K9qfYAbY8Lx6p15Ot4o2VMpncuztKIV8DD7WOSkR2oO0agq4ALQOJpkIvZ2T05lYxdID%2BhyxQuFtzkYdlagNLI%3D
C:\Users\Isaac\AppData\Roaming\1000219050
C:\Users\Isaac\AppData\Roaming\1000071060
ShortcutWithArgument: C:\Users\Isaac\AppData\Roaming\Microsoft\Windows\Start Menu\Яндекс.Игры.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> url="hxxps://gogone.ru/gl/?cid=31444&oid=75XMXY&v=6&utm_campaign=20.8 " <==== Cyrillic
HKU\S-1-5-21-1347779806-3341832456-1933409962-1001\...\StartupApproved\StartupFolder: => "jweupdater.exe"
cmd: net stop bits
cmd: net stop cryptSvc
cmd: net stop wuauserv
cmd: net stop msiserver
cmd: del /s /q C:\Windows\SoftwareDistribution\download\*.*
cmd: net start cryptSvc
cmd: net start bits
cmd: net start wuauserv
cmd: net start msiserver
cmd: netsh winsock reset catalog
cmd: netsh int ip reset C:\resettcpip.txt
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: Bitsadmin /Reset /Allusers
cmd: DISM.exe /Online /Cleanup-image /Restorehealth
cmd: winmgmt /salvagerepository
cmd: winmgmt /verifyrepository
cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R
cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R
cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R
cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*"
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
CMD: ipconfig /flushdns
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
emptytemp:
Reboot:
End::
Attachments
-
6.3 KB Views: 3