182_1.txt AdwCleaner使用した結果のログです。
182_2.txt 前回がC00。今回がS00です
182_4.txt 早速の返信ありがとうございます。Addition添付します。
182_5.txt こちらFRST添付します。症状が出始めた時にフルスキャンを実行しましたが、何も出ませんでした。もう一度フルスキャン実行してみますのでその結果を報告致します。
StartCloseprocesses:Emptytemp:File: C:\Windows\system32\OpenWith.exeFile: C:\Windows\yfPoQAtesYVDc.exeFile: C:\Program Files (x86)\Common Files\OnYIz.exeTask: {371EF82D-3329-4832-9E72-D2A79CE07205} - System32\Tasks\{C0BB02A0-3D6E-4A2F-AC09-57B8735D56B2} => C:\Windows\yfPoQAtesYVDc.exe [2014-10-29] (Microsoft Corporation)Task: {87A67540-6FEE-450E-B0CF-92AB8C6323D2} - System32\Tasks\hlatomernetkolc => C:\Windows\system32\OpenWith.exe [2014-10-29] (Microsoft Corporation)Task: {BF4C9198-E3D6-43CD-AC4D-182E3C6F8C92} - System32\Tasks\{34F238E2-8810-4497-AE58-3E0947B4121E} => C:\Program Files (x86)\Common Files\OnYIz.exe [2014-10-29] (Microsoft Corporation)FirewallRules: [{7DE4C73E-7E20-42B6-A045-008466E0712F}] => (Allow) C:\Windows\SysWOW64\msiexec.exeFirewallRules: [{453A7C74-D7FE-404E-ADB4-972151976BF9}] => (Allow) C:\Windows\yfPoQAtesYVDc.exeFirewallRules: [{2D077797-E43D-4184-A707-1F761A7085B6}] => (Allow) C:\Program Files (x86)\Common Files\OnYIz.exeC:\Windows\yfPoQAtesYVDc.exeC:\Program Files (x86)\Common Files\OnYIz.exeC:\Users\功士\AppData\Local\Temp\{E54B318F-2FD2-4912-A68A-1CDF4E8A95A0}GroupPolicy: Restriction <==== ATTENTIONGroupPolicy\User: Restriction <==== ATTENTIONSearchScopes: HKU\S-1-5-21-2226320585-714387487-3855243488-1001 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B1570C6DA-9537-4BFE-8EA5-B31CECC69221%7D&gp=811142CHR HomePage: Default -> inline.go.mail.ruCHR Extension: (Домашняя страница Mail.Ru) - C:\Users\功士\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnif [2018-04-20]C:\Users\功士\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnifC:\Users\功士\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnifCHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [ngdlmklkpclkhjopnhihdedhjgjmhlaa] - hxxps://clients2.google.com/service/update2/crx2014-10-29 10:40 - 2014-10-29 10:40 - 000197120 ____N (Microsoft Corporation) C:\Users\功士\UuFifOGHimLy.exe2014-10-29 10:40 - 2014-10-29 10:40 - 000059904 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\OnYIz.exe2018-04-20 22:42 - 2016-04-26 10:48 - 001173904 _____ (Baidu) C:\Users\功士\AppData\Local\Temp\1524231777.exe2018-01-29 23:48 - 2018-01-29 23:49 - 002575544 _____ () C:\Users\功士\AppData\Local\Temp\1wclsfy09z.exeCMD: bitsadmin /reset /allusersCMD: ipconfig /flushdnsCMD: ping www.google-analytics.comCMD: ping googleads.g.doubleclick.netCMD: ping connect.facebook.netCMD: ping doubleclick.netCMD: ping overture.comEND
182_8.txt FLXlog添付します。
182_9.txt MBAM添付します。
C:\ProgramData\AVAST Software\Avast\report