Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
RemoveProxy:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Ограничение <==== ВНИМАНИЕ
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
HKU\S-1-5-21-665326728-240714533-2514036665-1001\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (Нет файла)
HKU\S-1-5-21-665326728-240714533-2514036665-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (Нет файла)
HKU\S-1-5-21-665326728-240714533-2514036665-1001\...\RunOnce: [Uninstall 25.075.0420.0002] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\25.075.0420.0002" [0 2025-05-26] () <==== ВНИМАНИЕ [нулевой байт Файл/Папка]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ограничение <==== ВНИМАНИЕ
CHR HKU\S-1-5-21-665326728-240714533-2514036665-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gndelhfhcfbdhndfpcinebijfcjpmpec]
CHR HKLM-x32\...\Chrome\Extension: [gjaojbkkfpedgefidkagjeibcbfnakke] - hxxps://fastproxy.app/service/update2/crx?partner=02
2025-05-25 21:29 C:\DrWeb Quarantine
2024-11-20 20:49 C:\Program Files\AVAST Software
2024-11-20 20:49 C:\Program Files\AVG
2024-11-20 20:49 C:\Program Files\Bitdefender Agent
2024-11-20 20:49 C:\Program Files\ByteFence
2024-11-20 20:49 C:\Program Files\Cezurity
2024-11-20 20:49 C:\Program Files\COMODO
2024-11-20 20:49 C:\Program Files\Enigma Software Group
2024-11-20 20:49 C:\Program Files\EnigmaSoft
2024-11-20 20:49 C:\Program Files\ESET
2024-11-20 20:49 C:\Program Files\HitmanPro
2024-11-20 20:49 C:\Program Files\Kaspersky Lab
2024-11-20 20:49 C:\Program Files\Loaris Trojan Remover
2024-11-20 20:49 C:\Program Files\Malwarebytes
2024-11-20 20:50 C:\Program Files\NETGATE
2024-11-20 20:49 C:\Program Files\Process Hacker 2
2024-11-20 20:49 C:\Program Files\Process Lasso
2024-11-20 20:50 C:\Program Files\QuickCPU
2024-11-20 20:49 C:\Program Files\Rainmeter
2024-11-20 20:49 C:\Program Files\Ravantivirus
2024-11-20 20:50 C:\Program Files\ReasonLabs
2024-11-20 20:49 C:\Program Files\RogueKiller
2024-11-20 20:49 C:\Program Files\SpyHunter
2024-11-20 20:49 C:\Program Files\SUPERAntiSpyware
2024-11-20 20:49 C:\Program Files\Transmission
2022-10-17 14:33 C:\Program Files (x86)\360
2024-11-20 20:49 C:\Program Files (x86)\AVAST Software
2024-11-20 20:49 C:\Program Files (x86)\AVG
2024-11-20 20:49 C:\Program Files (x86)\Cezurity
2024-11-20 20:50 C:\Program Files (x86)\GPU Temp
2024-11-20 20:49 C:\Program Files (x86)\GRIZZLY Antivirus
2024-11-20 20:49 C:\Program Files (x86)\Kaspersky Lab
2024-11-20 20:49 C:\Program Files (x86)\Microsoft JDX
2024-11-20 20:49 C:\Program Files (x86)\Moo0
2024-11-20 20:49 C:\Program Files (x86)\Panda Security
2024-11-20 20:49 C:\Program Files (x86)\SpeedFan
2024-11-20 20:49 C:\Program Files (x86)\SpyHunter
2024-11-20 20:49 C:\Program Files (x86)\Transmission
2024-11-20 20:50 C:\Program Files (x86)\Wise
2024-11-20 20:49 C:\Program Files\Common Files\AV
2024-11-20 20:49 C:\Program Files\Common Files\McAfee
2024-11-20 20:49 C:\Users\Admin\Desktop\AutoLogger
2024-11-20 20:49 C:\Users\Admin\Desktop\AV_block_remover
2024-11-20 20:49 C:\Users\Admin\Downloads\AutoLogger
2024-11-20 20:49 C:\Users\Admin\Downloads\AV_block_remover
2024-11-20 20:50 C:\Users\Admin\AppData\Roaming\Sysfiles
2024-11-20 20:49 C:\ProgramData\360safe
2024-11-20 20:49 C:\ProgramData\AVAST Software
2024-11-20 20:49 C:\ProgramData\Avira
2024-11-20 20:49 C:\ProgramData\BookManager
2024-11-20 20:49 C:\ProgramData\ESET
2024-11-20 20:49 C:\ProgramData\Evernote
2024-11-20 20:49 C:\ProgramData\FingerPrint
2024-11-20 20:49 C:\ProgramData\grizzly
2024-11-20 20:49 C:\ProgramData\Kaspersky Lab
2024-11-20 20:49 C:\ProgramData\Kaspersky Lab Setup Files
2024-11-20 20:49 C:\ProgramData\McAfee
2024-11-20 20:49 C:\ProgramData\Norton
2024-11-20 20:49 C:\ProgramData\princeton-produce
2024-11-20 20:49 C:\ProgramData\PuzzleMedia
2024-11-20 20:49 C:\ProgramData\RobotDemo
2024-11-20 20:49 C:\ProgramData\WavePad
AdShield 1.0.0.2 (HKLM-x32\...\{e8a76c44-522f-41a2-9177-39af7d5f2ed2}) (Version: 1.0.0.2 - Limbo Solutions) Hidden
AlternateDataStreams: C:\Windows\tracing:? [16]
AlternateDataStreams: C:\Users\Admin\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Admin\Application Data:bc6be3eabffaddc099151eee7bdd94ee [394]
AlternateDataStreams: C:\Users\Admin\Application Data:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
AlternateDataStreams: C:\Users\Admin\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Admin\AppData\Roaming:bc6be3eabffaddc099151eee7bdd94ee [394]
AlternateDataStreams: C:\Users\Admin\AppData\Roaming:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
AlternateDataStreams: C:\Users\Admin\AppData\Local\Temp:$DATA [16]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [4254]
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\swprv]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="@%SystemRoot%\\System32\\swprv.dll,-102"
"DisplayName"="@%SystemRoot%\\System32\\swprv.dll,-103"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,73,00,77,00,70,00,72,00,76,00,00,00
"ObjectName"="LocalSystem"
"RequiredPrivileges"=hex(7):53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,\
68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,\
00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,\
65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,\
61,00,74,00,65,00,50,00,65,00,72,00,6d,00,61,00,6e,00,65,00,6e,00,74,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,42,00,61,00,\
73,00,65,00,50,00,72,00,69,00,6f,00,72,00,69,00,74,00,79,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,54,00,63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
67,00,65,00,00,00,00,00
"ServiceSidType"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000010
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\swprv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,77,00,70,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceDllUnloadOnStop"=dword:00000001
EndRegedit:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::