Tak jak napisalem wczesniej, infekcja.
Odinstaluj CCleaner
Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
CloseProcesses:
(FirewallModule) [Brak podpisu cyfrowego] C:\Users\parvati\AppData\Roaming\Microsoft\FirewallModule\FirewallModule.exe
HKU\S-1-5-21-2437666945-214153291-1641091809-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2437666945-214153291-1641091809-1001\...\Policies\Explorer: [NoSecurityTab] 1
HKU\S-1-5-21-2437666945-214153291-1641091809-1001\...\Winlogon: [Shell] %comspec% <==== UWAGA
HKU\S-1-5-21-2437666945-214153291-1641091809-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq FirewallModule.exe" 2>NUL | find /I /N "FirewallModule.exe">NUL && exit & if exist "C:\Users\parvati\AppData\Roaming\Microsoft\FirewallModule\FirewallModule.exe" ( start /MIN "" "C:\Users\parvati\AppData\Roaming\Microsoft\FirewallModule\FirewallModule.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== UWAGA
CHR HKLM-x32\...\Chrome\Extension: [makcojoppodhcgmmchohadhpkicoafka]
S3 mracsvc; C:\Windows\System32\mracsvc.exe [20782752 2020-09-10] (Mail.Ru LLC -> LLC Mail.Ru)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv1.sys [20019440 2020-09-10] (Mail.Ru LLC -> LLC Mail.Ru)
C:\Users\parvati\AppData\Roaming\Microsoft\FirewallModule\
W FRST wybierz Napraw.
Na przyszlosc nie sciagaj pirackich zainfekowancyh gier.