Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
RemoveProxy:
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
Task: {A90B00FE-669A-4A37-AD46-312D224ABAC4} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{58E42048-EEB6-473C-AD36-8720E10C0F7B} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
2025-06-08 17:57 - 2025-06-08 17:57 - 000000000 ___SH C:\ProgramData\tg.txt
2025-06-08 16:03 - 2025-06-08 16:03 - 000000000 ___SH C:\ProgramData\temp.txt
2025-06-07 16:35 - 2025-06-23 21:52 - 000000000 ___HD C:\Program Files\RDP Wrapper
2025-06-07 16:35 - 2025-06-07 16:35 - 000000000 ____D C:\Users\Yakov\AppData\Roaming\RMS_settings
2025-06-07 16:35 - 2025-06-07 16:35 - 000000000 ____D C:\ProgramData\Avira
2025-06-07 16:36 C:\_MinerSearchLogs
2025-06-07 16:35 C:\Program Files\AVAST Software
2025-06-07 16:35 C:\Program Files\AVG
2025-06-07 16:35 C:\Program Files\Bitdefender Agent
2025-06-07 16:35 C:\Program Files\ByteFence
2025-06-07 16:35 C:\Program Files\Cezurity
2025-06-07 16:35 C:\Program Files\COMODO
2025-06-07 16:35 C:\Program Files\DrWeb
2025-06-07 16:35 C:\Program Files\Enigma Software Group
2025-06-07 16:36 C:\Program Files\EnigmaSoft
2025-06-07 16:35 C:\Program Files\ESET
2025-06-07 16:35 C:\Program Files\HitmanPro
2025-06-07 16:35 C:\Program Files\Kaspersky Lab
2025-06-07 16:35 C:\Program Files\Loaris Trojan Remover
2025-06-07 16:35 C:\Program Files\Malwarebytes
2025-06-07 16:36 C:\Program Files\NETGATE
2025-06-07 16:35 C:\Program Files\Process Hacker 2
2025-06-07 16:35 C:\Program Files\Process Lasso
2025-06-07 16:36 C:\Program Files\QuickCPU
2025-06-07 16:35 C:\Program Files\Rainmeter
2025-06-07 16:35 C:\Program Files\Ravantivirus
2025-06-07 16:36 C:\Program Files\ReasonLabs
2025-06-07 16:36 C:\Program Files\RogueKiller
2025-06-07 16:35 C:\Program Files\SpyHunter
2025-06-07 16:36 C:\Program Files\SUPERAntiSpyware
2025-06-07 16:35 C:\Program Files\Transmission
2025-06-07 16:35 C:\Program Files (x86)\360
2025-06-07 16:35 C:\Program Files (x86)\AVAST Software
2025-06-07 16:35 C:\Program Files (x86)\AVG
2025-06-07 16:35 C:\Program Files (x86)\Cezurity
2025-06-07 16:36 C:\Program Files (x86)\GPU Temp
2025-06-07 16:35 C:\Program Files (x86)\GRIZZLY Antivirus
2025-06-07 16:35 C:\Program Files (x86)\Kaspersky Lab
2025-06-07 16:35 C:\Program Files (x86)\Microsoft JDX
2025-06-07 16:36 C:\Program Files (x86)\Moo0
2025-06-07 16:35 C:\Program Files (x86)\Panda Security
2025-06-07 16:36 C:\Program Files (x86)\SpeedFan
2025-06-07 16:35 C:\Program Files (x86)\SpyHunter
2025-06-07 16:35 C:\Program Files (x86)\Transmission
2025-06-07 16:36 C:\Program Files (x86)\Wise
2025-06-07 16:35 C:\Program Files\Common Files\AV
2025-06-07 16:35 C:\Program Files\Common Files\Doctor Web
2025-06-07 16:35 C:\Program Files\Common Files\McAfee
2025-06-07 16:35 C:\ProgramData\360safe
2025-06-07 16:35 C:\ProgramData\AVAST Software
2025-06-07 16:35 C:\ProgramData\Avira
2025-06-07 16:35 C:\ProgramData\BookManager
2025-06-07 16:35 C:\ProgramData\Doctor Web
2025-06-07 16:35 C:\ProgramData\ESET
2025-06-07 16:35 C:\ProgramData\Evernote
2025-06-07 16:35 C:\ProgramData\FingerPrint
2025-06-07 16:35 C:\ProgramData\grizzly
2025-06-07 16:35 C:\ProgramData\Kaspersky Lab
2025-06-07 16:35 C:\ProgramData\Kaspersky Lab Setup Files
2025-06-07 16:35 C:\ProgramData\McAfee
2025-06-07 16:35 C:\ProgramData\Norton
2025-06-07 16:35 C:\ProgramData\princeton-produce
2025-06-07 16:35 C:\ProgramData\PuzzleMedia
2025-06-07 16:35 C:\ProgramData\RobotDemo
2025-06-07 16:35 C:\ProgramData\WavePad
2025-06-07 16:35 C:\Users\Yakov\Desktop\AutoLogger
2025-06-07 16:35 C:\Users\Yakov\Desktop\AV_block_remover
2025-06-07 16:35 C:\Users\Yakov\Downloads\AutoLogger
2025-06-07 16:35 C:\Users\Yakov\Downloads\AV_block_remover
2025-06-07 16:36 C:\Users\Yakov\AppData\Roaming\Sysfiles
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="@%SystemRoot%\\System32\\swprv.dll,-102"
"DisplayName"="@%SystemRoot%\\System32\\swprv.dll,-103"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,73,00,77,00,70,00,72,00,76,00,00,00
"ObjectName"="LocalSystem"
"RequiredPrivileges"=hex(7):53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,\
68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,\
00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,\
65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,\
61,00,74,00,65,00,50,00,65,00,72,00,6d,00,61,00,6e,00,65,00,6e,00,74,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,42,00,61,00,\
73,00,65,00,50,00,72,00,69,00,6f,00,72,00,69,00,74,00,79,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,54,00,63,00,62,00,\
50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"ServiceSidType"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000010
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,77,00,70,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceDllUnloadOnStop"=dword:00000001
EndRegedit:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::