Start::
CreateRestorePoint:
CloseProcesses:
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Users\petr_\OneDrive\Рабочий стол\AV_block_remover
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Users\petr_\OneDrive\Рабочий стол\AutoLogger
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Users\petr_\Downloads\AV_block_remover
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Users\petr_\Downloads\AutoLogger
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Users\petr_\AppData\Roaming\Sysfiles
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\WavePad
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\RobotDemo
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\PuzzleMedia
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\princeton-produce
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\Norton
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\McAfee
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\Kaspersky Lab Setup Files
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\Kaspersky Lab
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\grizzly
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\FingerPrint
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\Evernote
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\ESET
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\Doctor Web
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\BookManager
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\ProgramData\AVAST Software
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Transmission
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\SUPERAntiSpyware
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\RogueKiller
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\ReasonLabs
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Ravantivirus
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Rainmeter
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\QuickCPU
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Process Lasso
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Process Hacker 2
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\NETGATE
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Loaris Trojan Remover
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Kaspersky Lab
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\HitmanPro
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\ESET
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\EnigmaSoft
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\DrWeb
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Common Files\McAfee
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Common Files\Doctor Web
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Common Files\AV
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Cezurity
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\Bitdefender Agent
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\AVG
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files\AVAST Software
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\Wise
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\Transmission
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\SpeedFan
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\Panda Security
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\Moo0
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\Kaspersky Lab
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\IObit
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\GRIZZLY Antivirus
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\GPU Temp
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\Cezurity
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\AVG
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 __SHD C:\Program Files (x86)\AVAST Software
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 ____D C:\ProgramData\Avira
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 ____D C:\Program Files\CPUID
2024-12-14 17:59 - 2024-12-14 17:59 - 000000000 ____D C:\Program Files (x86)\MSI
2024-12-14 17:58 - 2024-12-20 18:04 - 000000000 ____D C:\FRST
2024-12-14 17:58 - 2024-12-20 17:19 - 000000000 __SHD C:\ProgramData\WindowsTask
2024-12-14 17:58 - 2024-12-15 21:46 - 000000000 ___HD C:\Program Files\RDP Wrapper
2024-12-14 17:58 - 2024-12-15 21:43 - 000000000 __SHD C:\ProgramData\Install
2024-12-14 17:58 - 2024-12-15 21:41 - 000000000 __SHD C:\ProgramData\Windows Tasks Service
2024-12-14 17:58 - 2024-12-15 17:57 - 000000000 __SHD C:\ProgramData\ReaItekHD
2024-12-14 17:58 - 2024-12-14 17:58 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\ProgramData\RunDLL
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\ProgramData\MB3Install
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\ProgramData\Malwarebytes
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\ProgramData\360safe
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files\SpyHunter
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files\Malwarebytes
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files\Enigma Software Group
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files\COMODO
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files\ByteFence
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files (x86)\SpyHunter
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files (x86)\Microsoft JDX
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\Program Files (x86)\360
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\KVRT2020_Data
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\KVRT_Data
2024-12-14 17:58 - 2024-12-14 17:58 - 000000000 __SHD C:\AdwCleaner
2024-12-14 17:57 - 2024-12-20 17:19 - 000000000 __SHD C:\ProgramData\Setup
2024-12-14 17:59 C:\Program Files\AVAST Software
2024-12-14 17:59 C:\Program Files\AVG
2024-12-14 17:59 C:\Program Files\Bitdefender Agent
2024-12-14 17:58 C:\Program Files\ByteFence
2024-12-14 17:59 C:\Program Files\Cezurity
2024-12-14 17:58 C:\Program Files\COMODO
2024-12-14 17:59 C:\Program Files\DrWeb
2024-12-14 17:58 C:\Program Files\Enigma Software Group
2024-12-14 17:59 C:\Program Files\EnigmaSoft
2024-12-14 17:59 C:\Program Files\ESET
2024-12-14 17:59 C:\Program Files\HitmanPro
2024-12-14 17:59 C:\Program Files\Kaspersky Lab
2024-12-14 17:59 C:\Program Files\Loaris Trojan Remover
2024-12-14 17:58 C:\Program Files\Malwarebytes
2024-12-14 17:59 C:\Program Files\NETGATE
2024-12-14 17:59 C:\Program Files\Process Hacker 2
2024-12-14 17:59 C:\Program Files\Process Lasso
2024-12-14 17:59 C:\Program Files\QuickCPU
2024-12-14 17:59 C:\Program Files\Rainmeter
2024-12-14 17:59 C:\Program Files\Ravantivirus
2024-12-14 17:59 C:\Program Files\ReasonLabs
2024-12-14 17:59 C:\Program Files\RogueKiller
2024-12-14 17:58 C:\Program Files\SpyHunter
2024-12-14 17:59 C:\Program Files\SUPERAntiSpyware
2024-12-14 17:59 C:\Program Files\Transmission
2024-12-14 17:58 C:\Program Files (x86)\360
2024-12-14 17:59 C:\Program Files (x86)\AVAST Software
2024-12-14 17:59 C:\Program Files (x86)\AVG
2024-12-14 17:59 C:\Program Files (x86)\Cezurity
2024-12-14 17:59 C:\Program Files (x86)\GPU Temp
2024-12-14 17:59 C:\Program Files (x86)\GRIZZLY Antivirus
2024-12-14 17:59 C:\Program Files (x86)\Kaspersky Lab
2024-12-14 17:58 C:\Program Files (x86)\Microsoft JDX
2024-12-14 17:59 C:\Program Files (x86)\Moo0
2024-12-14 17:59 C:\Program Files (x86)\Panda Security
2024-12-14 17:59 C:\Program Files (x86)\SpeedFan
2024-12-14 17:58 C:\Program Files (x86)\SpyHunter
2024-12-14 17:59 C:\Program Files (x86)\Transmission
2024-12-14 17:59 C:\Program Files (x86)\Wise
2024-12-14 17:59 C:\Program Files\Common Files\AV
2024-12-14 17:59 C:\Program Files\Common Files\Doctor Web
2024-12-14 17:59 C:\Program Files\Common Files\McAfee
2024-12-14 17:58 C:\ProgramData\360safe
2024-12-14 17:59 C:\ProgramData\AVAST Software
2024-12-14 17:59 C:\ProgramData\Avira
2024-12-14 17:59 C:\ProgramData\BookManager
2024-12-14 17:59 C:\ProgramData\Doctor Web
2024-12-14 17:59 C:\ProgramData\ESET
2024-12-14 17:59 C:\ProgramData\Evernote
2024-12-14 17:59 C:\ProgramData\FingerPrint
2024-12-14 17:59 C:\ProgramData\grizzly
2024-12-14 17:59 C:\ProgramData\Kaspersky Lab
2024-12-14 17:59 C:\ProgramData\Kaspersky Lab Setup Files
2024-12-14 17:59 C:\ProgramData\McAfee
2024-12-14 17:59 C:\ProgramData\Norton
2024-12-14 17:59 C:\ProgramData\princeton-produce
2024-12-14 17:59 C:\ProgramData\PuzzleMedia
2024-12-14 17:59 C:\ProgramData\RobotDemo
2024-12-14 17:59 C:\ProgramData\WavePad
2024-12-14 17:59 C:\Users\petr_\OneDrive\Рабочий стол\AutoLogger
2024-12-14 17:59 C:\Users\petr_\OneDrive\Рабочий стол\AV_block_remover
2024-12-14 17:59 C:\Users\petr_\Downloads\AutoLogger
2024-12-14 17:59 C:\Users\petr_\Downloads\AV_block_remover
2024-12-14 17:59 C:\Users\petr_\AppData\Roaming\Sysfiles
Tcpip\..\Interfaces\{38336dd9-b404-4cad-9f0e-ee5b89293926}\7455543545: [DhcpDomain] spbstu.ru
(C:\ProgramData\ReaItekHD\taskhost.exe ->) (Microsoft Corporation) [Файл не подписан] C:\ProgramData\WindowsTask\AppHost.exe
(C:\ProgramData\ReaItekHD\taskhost.exe ->) (Microsoft Corporation) [Файл не подписан] C:\ProgramData\WindowsTask\audiodg.exe
(C:\ProgramData\ReaItekHD\taskhostw.exe ->) (Microsoft Corporation) [Файл не подписан] C:\ProgramData\ReaItekHD\taskhost.exe
Task: {04DC6A11-7A8B-46A6-8C3E-E83FB49124FB} - \Microsoft\Windows\WindowsBackup\CheckUP -> Нет файла <==== ВНИМАНИЕ
Task: {2801B91F-D78D-4FC2-84DC-62C417905C68} - \Microsoft\Windows\WindowsBackup\SupportSystem -> Нет файла <==== ВНИМАНИЕ
Task: {616B4C49-0195-4DB2-A34B-5EB5423FBADC} - \Microsoft\Windows\WindowsBackup\OnlogonCheck -> Нет файла <==== ВНИМАНИЕ
Task: {C7CBDD91-F28E-4C84-8452-625B2AEEBD09} - \Microsoft\Windows\WindowsBackup\WinlogonCheck -> Нет файла <==== ВНИМАНИЕ
Shortcut: C:\Users\petr_\AppData\Roaming\Microsoft\Word\ТТП_2024_Дериглазов%20(4)%20(2)311500433190470051\ТТП_2024_Дериглазов%20(4)%20(2).docx.lnk -> C:\Users\petr_\Downloads\ТТП_2024_Дериглазов (4) (2).docx (Нет файла) <==== Cyrillic
Shortcut: C:\Users\petr_\AppData\Roaming\Microsoft\Word\Дериглазов_Задание_6311500430439105015\Дериглазов_Задание_6.docx.lnk -> C:\Users\petr_\Downloads\Дериглазов_Задание_6.docx (Нет файла) <==== Cyrillic
Shortcut: C:\Users\petr_\AppData\Roaming\Microsoft\Word\Дериглазов_Задание_5311500400533501759\Дериглазов_Задание_5.docx.lnk -> C:\Users\petr_\Downloads\Дериглазов_Задание_5.docx (Нет файла) <==== Cyrillic
Shortcut: C:\Users\petr_\AppData\Roaming\Microsoft\Word\Дериглазов_Задание_5%20(1)311500451540327346\Дериглазов_Задание_5%20(1).docx.lnk -> C:\Users\petr_\Downloads\Дериглазов_Задание_5 (1).docx (Нет файла) <==== Cyrillic
Shortcut: C:\Users\petr_\AppData\Roaming\Microsoft\Word\Дериглазов_Задание_1%20(3)%20(1)311500441423574709\Дериглазов_Задание_1%20(3)%20(1).docx.lnk -> C:\Users\petr_\Downloads\Дериглазов_Задание_1 (3) (1).docx (Нет файла) <==== Cyrillic
Task: {1FF51A81-57F4-4A50-A09B-1BF6CADFB1F0} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => %ProgramFiles%\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe (Нет файла)
Task: {67702E1E-2EB3-41BB-8479-786463B2D920} - System32\Tasks\Microsoft\Windows\GlobalDataF\RecoveryHosts => C:\ProgramData\Microsoft\DRM\UodGBY5R0yv7UIoO\GlobalDataF.bat (Нет файла) <==== ВНИМАНИЕ
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Нет файла)
FirewallRules: [{3C892035-C79F-4AA9-908C-4A87B18D1FFE}] => (Allow) C:\ProgramData\Windows Tasks Service\winserv.exe => Нет файла
FirewallRules: [{7B952DBB-4600-4E0D-99A9-CFF1D0B5AA26}] => (Allow) LPort=3389
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
StartBatch:
del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*" >nul
del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Code Cache\Js\*.*" >nul
del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Default\Cache\Cache_Data\*.*" >nul
del /s /q "%userprofile%\AppData\Local\Yandex\YandexBrowser\User Data\Default\Cache\*.*" >nul
del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\*.*" >nul
del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\Js\*.*" >nul
del /s /q C:\Windows\Minidump\*.dmp >nul
del /s /q C:\Windows\Temp\*.* >nul
del /s /q "%userprofile%\AppData\Local\temp\*.*" >nul
net user John /delete /y
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: bitsadmin /reset /allusers
cmd: ipconfig /flushdns
cmd: sfc /scannow
C:\Windows\SysWow64\unsecapp.exe
C:\ProgramData\WindowsTask\audiodg.exe
C:\ProgramData\WindowsTask\AppModule.exe
C:\Program Files\RDP Wrapper
C:\ProgramData\WindowsTask\AMD.exe
C:\ProgramData\ReaItekHD\taskhost.exe
Virusscan: C:\ProgramData\WindowsTask\MicrosoftHost.exe
cmd: DISM /Online /Cleanup-Image /CheckHealth
endbatch:
Hosts:
Reboot:
End::