Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
HKLM-x32\...\Run: [DesktopPortal] => [X]
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Genshin Impact_launcher_mihoyo_1_0] => D:\Genshin Impact\launcher.exe (Нет файла)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ограничение <==== ВНИМАНИЕ
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [1] eav_trial_rus.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [2] avast_free_antivirus_setup_online.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [3] eis_trial_rus.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [4] essf_trial_rus.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [5] hitmanpro_x64.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [6] ESETOnlineScanner_UKR.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [7] ESETOnlineScanner_RUS.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [8] HitmanPro.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [9] 360TS_Setup_Mini.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [10] Cezurity_Scanner_Pro_Free.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [11] Cube.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [12] AVbr.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [13] AV_br.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [14] KVRT.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [15] cureit.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [16] FRST64.exe => успешно удалены
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [17] eset_internet_security_live_installer.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [18] esetonlinescanner.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [19] eset_nod32_antivirus_live_installer.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [20] MBSetup.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [21] PANDAFREEAV.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [22] bitdefender_avfree.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [23] drweb-12.0-ss-win.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [24] Cureit.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [25] TDSSKiller.exe
HKU\S-1-5-21-892807838-2759882341-2100481072-1001\...\Policies\Explorer\DisallowRun: [26] eset_smart_security_premium_live_installer.exe
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
Task: {714DE7C6-EDAE-491E-9B85-51F3515684AD} - System32\Tasks\Восстановление сервиса обновлений Яндекс.Браузера => C:\Program Files (x86)\Yandex\YandexBrowser\22.9.1.1095\service_update.exe --repair (Нет файла)
Tcpip\..\Interfaces\{86190d29-1acf-477d-8051-1fecc9ad4ffe}: [DhcpNameServer] 40.42.1.11
CHR HKU\S-1-5-21-892807838-2759882341-2100481072-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
2024-12-28 01:32 - 2025-03-15 19:12 - 000000000 ___HD C:\Program Files\RDP Wrapper
2024-12-28 01:32 - 2024-12-28 01:32 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Users\arkek\Downloads\AV_block_remover
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Users\arkek\Downloads\AutoLogger
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Users\arkek\Desktop\AV_block_remover
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Users\arkek\Desktop\AutoLogger
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Users\arkek\AppData\Roaming\Sysfiles
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\WavePad
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\RobotDemo
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\PuzzleMedia
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\princeton-produce
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Norton
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\McAfee
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\MB3Install
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Malwarebytes
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Kaspersky Lab Setup Files
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Kaspersky Lab
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\grizzly
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\FingerPrint
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Evernote
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\ESET
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Doctor Web
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\BookManager
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\AVAST Software
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\360safe
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Transmission
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\SUPERAntiSpyware
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\SpyHunter
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\RogueKiller
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\ReasonLabs
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Ravantivirus
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Rainmeter
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\QuickCPU
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Process Lasso
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Process Hacker 2
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\NZXT CAM
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\NETGATE
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Malwarebytes
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Loaris Trojan Remover
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Kaspersky Lab
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\HitmanPro
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\ESET
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\EnigmaSoft
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Enigma Software Group
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\DrWeb
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Corsair
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\COMODO
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Common Files\McAfee
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Common Files\Doctor Web
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Common Files\AV
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Cezurity
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\ByteFence
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\Bitdefender Agent
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\AVG
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files\AVAST Software
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Wise
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Transmission
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\SpyHunter
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\SpeedFan
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Panda Security
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Moo0
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Microsoft JDX
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Kaspersky Lab
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\IObit
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\GRIZZLY Antivirus
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\GPU Temp
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\Cezurity
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\AVG
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\AVAST Software
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\Program Files (x86)\360
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\KVRT2020_Data
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 __SHD C:\AdwCleaner
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 ____D C:\Users\arkek\AppData\Roaming\RMS_settings
2024-12-28 01:32 - 2024-12-28 01:32 - 000000000 ____D C:\ProgramData\Avira
2024-12-28 01:31 - 2025-03-15 19:08 - 000000000 __SHD C:\ProgramData\WindowsTask
2024-12-28 01:31 - 2025-03-15 19:08 - 000000000 __SHD C:\ProgramData\Windows Tasks Service
2024-12-28 01:31 - 2025-03-15 19:08 - 000000000 __SHD C:\ProgramData\ReaItekHD
2024-12-28 01:31 - 2024-12-28 01:32 - 000000000 __SHD C:\ProgramData\Install
2024-12-28 01:31 - 2024-12-28 01:31 - 000000000 __SHD C:\ProgramData\RunDLL
2024-12-28 01:31 - 2024-12-28 01:31 - 000000000 __SHD C:\KVRT_Data
2024-12-28 01:31 - 2024-12-28 01:31 - 000000000 ____D C:\ProgramData\System32
2024-12-28 01:30 - 2025-01-18 12:07 - 000000000 __SHD C:\ProgramData\Setup
2024-12-28 01:32 C:\Program Files\AVAST Software
2024-12-28 01:32 C:\Program Files\AVG
2024-12-28 01:32 C:\Program Files\Bitdefender Agent
2024-12-28 01:32 C:\Program Files\ByteFence
2024-12-28 01:32 C:\Program Files\Cezurity
2024-12-28 01:32 C:\Program Files\COMODO
2024-12-28 01:32 C:\Program Files\Corsair
2024-12-28 01:32 C:\Program Files\DrWeb
2024-12-28 01:32 C:\Program Files\Enigma Software Group
2024-12-28 01:32 C:\Program Files\EnigmaSoft
2024-12-28 01:32 C:\Program Files\ESET
2024-12-28 01:32 C:\Program Files\HitmanPro
2024-12-28 01:32 C:\Program Files\Kaspersky Lab
2024-12-28 01:32 C:\Program Files\Loaris Trojan Remover
2024-12-28 01:32 C:\Program Files\Malwarebytes
2024-12-28 01:32 C:\Program Files\NETGATE
2024-12-28 01:32 C:\Program Files\NZXT CAM
2024-12-28 01:32 C:\Program Files\Process Hacker 2
2024-12-28 01:32 C:\Program Files\Process Lasso
2024-12-28 01:32 C:\Program Files\QuickCPU
2024-12-28 01:32 C:\Program Files\Rainmeter
2024-12-28 01:32 C:\Program Files\Ravantivirus
2024-12-28 01:32 C:\Program Files\ReasonLabs
2024-12-28 01:32 C:\Program Files\RogueKiller
2024-12-28 01:32 C:\Program Files\SpyHunter
2024-12-28 01:32 C:\Program Files\SUPERAntiSpyware
2024-12-28 01:32 C:\Program Files\Transmission
2024-12-28 01:32 C:\Program Files (x86)\360
2024-12-28 01:32 C:\Program Files (x86)\AVAST Software
2024-12-28 01:32 C:\Program Files (x86)\AVG
2024-12-28 01:32 C:\Program Files (x86)\Cezurity
2024-12-28 01:32 C:\Program Files (x86)\GPU Temp
2024-12-28 01:32 C:\Program Files (x86)\GRIZZLY Antivirus
2024-12-28 01:32 C:\Program Files (x86)\Kaspersky Lab
2024-12-28 01:32 C:\Program Files (x86)\Microsoft JDX
2024-12-28 01:32 C:\Program Files (x86)\Moo0
2024-12-28 01:32 C:\Program Files (x86)\Panda Security
2024-12-28 01:32 C:\Program Files (x86)\SpeedFan
2024-12-28 01:32 C:\Program Files (x86)\SpyHunter
2024-12-28 01:32 C:\Program Files (x86)\Transmission
2024-12-28 01:32 C:\Program Files (x86)\Wise
2024-12-28 01:32 C:\Program Files\Common Files\AV
2024-12-28 01:32 C:\Program Files\Common Files\Doctor Web
2024-12-28 01:32 C:\Program Files\Common Files\McAfee
2024-12-28 01:32 C:\ProgramData\360safe
2024-12-28 01:32 C:\ProgramData\AVAST Software
2024-12-28 01:32 C:\ProgramData\Avira
2024-12-28 01:32 C:\ProgramData\BookManager
2024-12-28 01:32 C:\ProgramData\Doctor Web
2024-12-28 01:32 C:\ProgramData\ESET
2024-12-28 01:32 C:\ProgramData\Evernote
2024-12-28 01:32 C:\ProgramData\FingerPrint
2024-12-28 01:32 C:\ProgramData\grizzly
2024-12-28 01:32 C:\ProgramData\Kaspersky Lab
2024-12-28 01:32 C:\ProgramData\Kaspersky Lab Setup Files
2024-12-28 01:32 C:\ProgramData\McAfee
2024-12-28 01:32 C:\ProgramData\Norton
2024-12-28 01:32 C:\ProgramData\princeton-produce
2024-12-28 01:32 C:\ProgramData\PuzzleMedia
2024-12-28 01:32 C:\ProgramData\RobotDemo
2024-12-28 01:32 C:\ProgramData\WavePad
2024-12-28 01:32 C:\Users\arkek\Desktop\AutoLogger
2024-12-28 01:32 C:\Users\arkek\Desktop\AV_block_remover
2024-12-28 01:32 C:\Users\arkek\Downloads\AutoLogger
2024-12-28 01:32 C:\Users\arkek\Downloads\AV_block_remover
2024-12-28 01:32 C:\Users\arkek\AppData\Roaming\Sysfiles
CustomCLSID: HKU\S-1-5-21-892807838-2759882341-2100481072-1001_Classes\CLSID\{d936918b-9c4b-555e-074a-c79314be04e1}\localserver32 -> "C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.exe" -ToastActivated => Нет файла
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="@%SystemRoot%\\System32\\swprv.dll,-102"
"DisplayName"="@%SystemRoot%\\System32\\swprv.dll,-103"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,73,00,77,00,70,00,72,00,76,00,00,00
"ObjectName"="LocalSystem"
"RequiredPrivileges"=hex(7):53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,\
68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,\
00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,\
65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,\
61,00,74,00,65,00,50,00,65,00,72,00,6d,00,61,00,6e,00,65,00,6e,00,74,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,42,00,61,00,\
73,00,65,00,50,00,72,00,69,00,6f,00,72,00,69,00,74,00,79,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,54,00,63,00,62,00,\
50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"ServiceSidType"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000010
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,77,00,70,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceDllUnloadOnStop"=dword:00000001
EndRegedit:
StartPowershell:
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\AppModule.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData\ReaItekHD\taskhost.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\audiodg.exe"
Remove-MpPreference -ExclusionPath "C:\Program Files\RDP Wrapper"
Remove-MpPreference -ExclusionPath "C:\Windows\SysWow64\unsecapp.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\AMD.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\AppHost.exe"
Set-MpPreference -DisableAutoExclusions $true -Force
Set-MpPreference -Mapsreporting basic -Force
Set-MpPreference -DisableRealtimeMonitoring $false -Force
Set-MpPreference -DisablePrivacyMode $true -Force
Set-MpPreference -DisableIOAVProtection $false -Force
Set-MpPreference -UILockdown 0
Set-MpPreference -ScanPurgeItemsAfterDelay 1
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true -Force
Set-MpPreference -PUAProtection enabled -Force
Update-MpSignature
Get-MpComputerStatus
Get-MpPreference
EndPowerShell:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::