Start::
CreateRestorePoint:
CloseProcesses:
Virusscan: C:\Program Files (x86)\Common Files\Autodesk Shared\Network License Manager\adskflex.exe
Virusscan: C:\ProgramData\Tenorshare\Service\TenorshareUpdateAssistant.exe
Virusscan: C:\Windows\system32\pdfcmon.dll
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\Run: [YandexBrowserAutoLaunch_B64B7D5D07784CD66F00CA43360BB68B] => "C:\Users\User\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --shutdown-if-not-closed-by-system-restart (Нет файла)
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\Policies\Explorer: []
Task: {1F987E41-50D2-4513-A886-C53458F420FE} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (Нет файла)
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge HKLM-x32\...\Edge\Extension: [iifchhfnnmpdbibifmljnfjhpififfog]
CHR HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gndelhfhcfbdhndfpcinebijfcjpmpec]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [iifchhfnnmpdbibifmljnfjhpififfog
S3 cpuz154; \??\C:\Windows\temp\cpuz154\cpuz154_x64.sys [X] <==== ВНИМАНИЕ
R3 cpuz157; C:\Windows\temp\cpuz157\cpuz157_x64.sys [43568 2024-11-21] (Microsoft Windows Hardware Compatibility Publisher -> CPUID) <==== ВНИМАНИЕ
CustomCLSID: HKU\S-1-5-21-3376671446-1666229863-4157894722-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Нет файла
CustomCLSID: HKU\S-1-5-21-3376671446-1666229863-4157894722-1001_Classes\CLSID\{345D3165-3889-4694-AB75-A91A27B217E8}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2024\acad.exe => Нет файла
CustomCLSID: HKU\S-1-5-21-3376671446-1666229863-4157894722-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => Нет файла
CustomCLSID: HKU\S-1-5-21-3376671446-1666229863-4157894722-1001_Classes\CLSID\{8B4929F8-076F-4AEC-AFEE-8928747B7AE3}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2024\acad.exe /Automation => Нет файла
CustomCLSID: HKU\S-1-5-21-3376671446-1666229863-4157894722-1001_Classes\CLSID\{AA46BA8A-9825-40FD-8493-0BA3C4D5CEB5}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2024\acad.exe /Automation => Нет файла
CustomCLSID: HKU\S-1-5-21-3376671446-1666229863-4157894722-1001_Classes\CLSID\{AF18D91C-A699-4578-ADC6-972F3BA007F0}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2024\acad.exe /Automation => Нет файла
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Калькулятор\Деинсталляция Калькулятор.lnk -> C:\Program Files\Base\Foundation\Uninstal.exe (Нет файла) <==== Cyrillic
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Калькулятор\Калькулятор.lnk -> C:\Program Files\Base\Foundation\CalcK.exe (Нет файла) <==== Cyrillic
HKLM\...\StartupApproved\StartupFolder: => "Wondershare PEToolbox.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Wondershare PEScreenshot.lnk"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "pac"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "YandexDisk2"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "MediaGet2"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "Opera Stable"
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\...\StartupApproved\Run: => "YandexBrowserAutoLaunch_B64B7D5D07784CD66F00CA43360BB68B"
FirewallRules: [{7A8EC1CD-1532-4CDD-B93D-C91A0D6E47B9}] => (Allow) LPort=9422
FirewallRules: [{88D331BC-1BDF-4BDE-9B9D-8C7C6589214E}] => (Allow) LPort=9245
FirewallRules: [{F4E1060E-B935-43FB-B2EB-267C66C1A8D1}] => (Allow) LPort=9246
FirewallRules: [{2B2B30C1-B3E0-4F4B-91FA-FCCE0C3530F9}] => (Allow) LPort=9247
FirewallRules: [{E6BE28D5-BA76-4E72-8548-8E5A222C28F0}] => (Allow) C:\Users\User\MediaGet2\mediaget.exe => Нет файла
FirewallRules: [{049AA255-B07F-470B-AFDA-1C0757484254}] => (Allow) C:\Users\User\MediaGet2\mediaget.exe => Нет файла
FirewallRules: [{83BC4B66-2CE0-4973-AE02-6298E0B07057}] => (Allow) C:\Users\User\MediaGet2\QtWebEngineProcess.exe => Нет файла
FirewallRules: [{954FE14B-3DFC-446C-AEFF-A88F38522F30}] => (Allow) C:\Users\User\MediaGet2\QtWebEngineProcess.exe => Нет файла
FirewallRules: [TCP Query User{DADABA64-B8E7-4B55-8449-2B86DA7B7393}C:\program files\transmission\transmission-qt.exe] => (Block) C:\program files\transmission\transmission-qt.exe => Нет файла
FirewallRules: [UDP Query User{C1078566-454C-4EC3-99DD-06726A1874C2}C:\program files\transmission\transmission-qt.exe] => (Block) C:\program files\transmission\transmission-qt.exe => Нет файла
FirewallRules: [{D7F4517F-5D40-4A45-8729-0BB4B98CF487}] => (Allow) C:\Program Files (x86)\Tenorshare\Tenorshare 4DDiG\Monitor\Monitor.exe => Нет файла
FirewallRules: [{05E9A6C9-BCA9-45FF-BFA0-B56C4DC5CCAC}] => (Allow) C:\Program Files (x86)\Tenorshare\Tenorshare 4DDiG\Monitor\Monitor.exe => Нет файла
FirewallRules: [{0B2C765A-0874-4AE7-A8BA-E8A6689DDBC9}] => (Allow) C:\Program Files (x86)\Tenorshare\Tenorshare 4DDiG\NASConnecter.exe => Нет файла
FirewallRules: [{C0ED18BC-2F73-49F7-9426-686C9E312E83}] => (Allow) C:\Program Files (x86)\Tenorshare\Tenorshare 4DDiG\NASConnecter.exe => Нет файла
FirewallRules: [{407D3044-A839-484A-8ECF-FAB45E9679B7}] => (Allow) C:\Program Files\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe => Нет файла
HKU\S-1-5-21-3376671446-1666229863-4157894722-1001\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Reboot:
End::