Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
RemoveProxy:
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Ограничение <==== ВНИМАНИЕ
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
HKU\S-1-5-21-2218555335-3482933222-348965604-1001\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
IFEO\SecurityHealthService.exe: [Debugger] C:\Windows\system32\systray.exe
Startup: C:\Users\Yopt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zfe_Bg.lnk [2025-04-11] <==== ВНИМАНИЕ
ShortcutTarget: zfe_Bg.lnk -> C:\Users\Yopt\AppData\Local\Temp\Temp_b640a3ef\aqsFVFkX.exe (Нет файла) <==== ВНИМАНИЕ
GroupPolicy: Ограничение ? <==== ВНИМАНИЕ
GroupPolicyScripts: Ограничение <==== ВНИМАНИЕ
GroupPolicyScripts\User: Ограничение <==== ВНИМАНИЕ
Policies: C:\ProgramData\NTUSER.pol: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ограничение <==== ВНИМАНИЕ
Task: {2E7B6473-31B8-4CEB-AA98-C53BEE673A19} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXvGPUDisableTask => %windir%\System32\RemoteFXvGPUDisablement.exe Disable (Нет файла)
Task: {6FD47A1C-DF3C-4D71-9296-7C96251EB7AB} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXWarningTask => %windir%\System32\RemoteFXvGPUDisablement.exe Warning (Нет файла)
Edge Extension: (Нет имени) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [не найдено]
Edge Extension: (Нет имени) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [не найдено]
Edge Extension: (Нет имени) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [не найдено]
Edge Extension: (Нет имени) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [не найдено]
S3 KSDE5.21; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.21\ksde.exe <==== ВНИМАНИЕ (Доступ не разрешён)
2022-09-29 23:03 C:\AdwCleaner
2025-09-22 15:34 C:\DrWeb Quarantine
2022-09-29 23:03 C:\KVRT2020_Data
2022-09-29 23:03 C:\KVRT_Data
2025-09-20 12:41 C:\_MinerSearchLogs
2022-09-29 23:03 C:\Program Files\AVAST Software
2022-09-29 23:03 C:\Program Files\AVG
2022-09-29 23:03 C:\Program Files\Bitdefender Agent
2022-09-29 23:03 C:\Program Files\ByteFence
2022-09-29 23:03 C:\Program Files\Cezurity
2022-09-29 23:03 C:\Program Files\COMODO
2022-09-29 23:03 C:\Program Files\Enigma Software Group
2025-09-20 12:41 C:\Program Files\EnigmaSoft
2025-09-20 12:41 C:\Program Files\ESET
2025-09-20 12:41 C:\Program Files\HitmanPro
2022-09-29 23:03 C:\Program Files\Kaspersky Lab
2022-09-29 23:03 C:\Program Files\Loaris Trojan Remover
2022-09-29 23:03 C:\Program Files\Malwarebytes
2025-09-20 12:41 C:\Program Files\NETGATE
2025-09-20 12:41 C:\Program Files\Process Hacker 2
2022-09-29 23:03 C:\Program Files\Process Lasso
2025-09-20 12:41 C:\Program Files\QuickCPU
2022-09-29 23:03 C:\Program Files\Rainmeter
2022-09-29 23:03 C:\Program Files\Ravantivirus
2025-09-20 12:41 C:\Program Files\ReasonLabs
2025-09-20 12:41 C:\Program Files\RogueKiller
2022-09-29 23:03 C:\Program Files\SpyHunter
2025-09-20 12:41 C:\Program Files\SUPERAntiSpyware
2025-09-20 12:41 C:\Program Files\Transmission
2022-09-29 23:03 C:\Program Files (x86)\360
2022-09-29 23:03 C:\Program Files (x86)\AVAST Software
2022-09-29 23:03 C:\Program Files (x86)\AVG
2022-09-29 23:03 C:\Program Files (x86)\Cezurity
2025-09-20 12:41 C:\Program Files (x86)\GPU Temp
2022-09-29 23:03 C:\Program Files (x86)\GRIZZLY Antivirus
2025-06-16 12:48 C:\Program Files (x86)\Kaspersky Lab
2022-09-29 23:03 C:\Program Files (x86)\Microsoft JDX
2025-09-20 12:41 C:\Program Files (x86)\Moo0
2022-09-29 23:03 C:\Program Files (x86)\Panda Security
2025-09-20 12:41 C:\Program Files (x86)\SpeedFan
2022-09-29 23:03 C:\Program Files (x86)\SpyHunter
2022-09-29 23:03 C:\Program Files (x86)\Transmission
2025-09-20 12:41 C:\Program Files (x86)\Wise
2022-09-29 23:03 C:\WINDOWS\speechstracing
2022-09-29 23:03 C:\Program Files\Common Files\AV
2022-09-29 23:03 C:\Program Files\Common Files\McAfee
2022-09-29 23:03 C:\ProgramData\360safe
2022-09-29 23:03 C:\ProgramData\AVAST Software
2022-09-29 23:03 C:\ProgramData\Avira
2022-09-29 23:03 C:\ProgramData\BookManager
2025-09-20 12:41 C:\ProgramData\ESET
2022-09-29 23:03 C:\ProgramData\Evernote
2022-09-29 23:03 C:\ProgramData\FingerPrint
2022-09-29 23:03 C:\ProgramData\grizzly
2025-09-20 12:41 C:\ProgramData\Kaspersky Lab Setup Files
2022-09-29 23:03 C:\ProgramData\Malwarebytes
2022-09-29 23:03 C:\ProgramData\MB3Install
2022-09-29 23:03 C:\ProgramData\McAfee
2022-09-29 23:03 C:\ProgramData\Norton
2025-09-20 12:41 C:\ProgramData\princeton-produce
2022-09-29 23:03 C:\ProgramData\PuzzleMedia
2022-09-29 23:03 C:\ProgramData\RobotDemo
2022-09-29 23:03 C:\ProgramData\WavePad
2025-09-20 12:41 C:\Users\Yopt\Desktop\AutoLogger
2025-09-20 12:41 C:\Users\Yopt\Desktop\AV_block_remover
2025-09-20 12:41 C:\Users\Yopt\Downloads\AutoLogger
2025-09-20 12:41 C:\Users\Yopt\Downloads\AV_block_remover
2025-09-20 12:41 C:\Users\Yopt\AppData\Roaming\Sysfiles
2025-09-25 17:57 - 2022-09-29 23:02 - 000000000 __SHD C:\ProgramData\WindowsTask
2025-09-21 19:15 - 2022-09-29 23:03 - 000000000 ___HD C:\Program Files\RDP Wrapper
2025-09-21 19:12 - 2022-09-29 23:02 - 000000000 __SHD C:\ProgramData\Install
2025-09-21 19:06 - 2022-09-29 23:03 - 000000000 __SHD C:\ProgramData\Windows Tasks Service
2025-09-21 00:35 - 2022-09-29 23:02 - 000000000 __SHD C:\ProgramData\Setup
2025-09-20 12:40 - 2025-09-21 19:06 - 000000000 __SHD C:\ProgramData\ReaItekHD
2025-09-20 12:41 - 2025-09-20 12:41 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2025-09-21 00:35 - 2025-09-21 00:35 - 000000000 ___SH C:\ProgramData\tg.txt
2025-09-21 00:35 - 2025-09-21 00:35 - 000000000 ___SH C:\ProgramData\temp.txt
CustomCLSID: HKU\S-1-5-21-2218555335-3482933222-348965604-1001_Classes\CLSID\{9914FC2A-D49E-4e44-A607-5D697693120B}\InprocServer32 -> C:\WINDOWS\System32\mscomct2.ocx => Нет файла
CustomCLSID: HKU\S-1-5-21-2218555335-3482933222-348965604-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\Yopt\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => Нет файла
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Нет файла
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Нет файла
ContextMenuHandlers1: [TranslationStudioShlExt2011] -> -{F6C08E19-DCE1-45B5-A225-E94FADB585DD} => -> Нет файла
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Нет файла
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Нет файла
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Нет файла
AlternateDataStreams: C:\ProgramData\TEMP:F8AF2BB9 [360]
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\swprv]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="@%SystemRoot%\\System32\\swprv.dll,-102"
"DisplayName"="@%SystemRoot%\\System32\\swprv.dll,-103"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,73,00,77,00,70,00,72,00,76,00,00,00
"ObjectName"="LocalSystem"
"RequiredPrivileges"=hex(7):53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,\
68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,\
00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,\
65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,72,00,65,00,\
61,00,74,00,65,00,50,00,65,00,72,00,6d,00,61,00,6e,00,65,00,6e,00,74,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,42,00,61,00,\
73,00,65,00,50,00,72,00,69,00,6f,00,72,00,69,00,74,00,79,00,50,00,72,00,69,\
00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4d,00,61,00,6e,00,\
61,00,67,00,65,00,56,00,6f,00,6c,00,75,00,6d,00,65,00,50,00,72,00,69,00,76,\
00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,74,00,\
6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,\
00,53,00,65,00,54,00,63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
67,00,65,00,00,00,00,00
"ServiceSidType"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000010
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\swprv\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,77,00,70,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceDllUnloadOnStop"=dword:00000001
EndRegedit:
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="@%SystemRoot%\\System32\\termsrv.dll,-267"
"DisplayName"="@%SystemRoot%\\System32\\termsrv.dll,-268"
"ErrorControl"=dword:00000001
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,60,ea,00,00
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,53,00,65,00,72,00,76,\
00,69,00,63,00,65,00,00,00
"ObjectName"="NT Authority\\NetworkService"
"RequiredPrivileges"=hex(7):53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,\
00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,\
72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,75,\
00,64,00,69,00,74,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,00,6f,00,74,00,69,\
00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,00,6c,00,6f,00,62,00,61,\
00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,\
65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,00,61,00,74,00,65,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,\
6e,00,63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,\
00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"ServiceSidType"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000020
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
74,00,65,00,72,00,6d,00,73,00,72,00,76,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceDllUnloadOnStop"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService\Performance]
"Close"="CloseTSObject"
"Collect"="CollectTSObjectData"
"Collect Supports Metadata"=dword:00000001
"Collect Timeout"=dword:000003e8
"Library"="C:\\Windows\\System32\\perfts.dll"
"Open"="OpenTSObject"
"Open Timeout"=dword:000003e8
"InstallType"=dword:00000001
"PerfIniFile"="tslabels.ini"
"First Counter"=dword:000026d2
"Last Counter"=dword:000026d2
"First Help"=dword:000026d3
"Last Help"=dword:000026d3
"Object List"="9938"
EndRegedit:
StartRegedit:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS]
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"Description"="@%systemroot%\\system32\\vssvc.exe,-101"
"DisplayName"="@%systemroot%\\system32\\vssvc.exe,-102"
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,76,\
00,73,00,73,00,76,00,63,00,2e,00,65,00,78,00,65,00,00,00
"ObjectName"="LocalSystem"
"ServiceSidType"=dword:00000001
"Start"=dword:00000003
"Type"=dword:00000010
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\SPP]
"SppGetSnapshots (Enter)"=hex:48,00,00,00,00,00,00,00,a9,86,74,25,bc,1f,d8,01,\
c0,06,00,00,f8,21,00,00,d2,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
"SppGetSnapshots (Leave)"=hex:48,00,00,00,00,00,00,00,a9,86,74,25,bc,1f,d8,01,\
c0,06,00,00,f8,21,00,00,d2,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
"SppEnumGroups (Enter)"=hex:48,00,00,00,00,00,00,00,a9,86,74,25,bc,1f,d8,01,c0,\
06,00,00,f8,21,00,00,d1,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00
"SppEnumGroups (Leave)"=hex:48,00,00,00,00,00,00,00,3c,eb,76,25,bc,1f,d8,01,c0,\
06,00,00,f8,21,00,00,d1,07,00,00,01,00,00,00,00,00,00,00,01,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00
"SppCreate (Enter)"=hex:48,00,00,00,00,00,00,00,ef,55,6a,bd,b9,1f,d8,01,38,25,\
00,00,04,0c,00,00,d0,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
"SppGatherWriterMetadata (Enter)"=hex:48,00,00,00,00,00,00,00,57,b6,6c,bd,b9,\
1f,d8,01,38,25,00,00,04,0c,00,00,d3,07,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00
"SppGatherWriterMetadata (Leave)"=hex:48,00,00,00,00,00,00,00,9d,e3,1d,c0,b9,\
1f,d8,01,38,25,00,00,04,0c,00,00,d3,07,00,00,01,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00
"SppAddInterestingComponents (Enter)"=hex:48,00,00,00,00,00,00,00,9d,e3,1d,c0,\
b9,1f,d8,01,38,25,00,00,04,0c,00,00,d4,07,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00
"SppAddInterestingComponents (Leave)"=hex:48,00,00,00,00,00,00,00,6d,af,35,c0,\
b9,1f,d8,01,38,25,00,00,04,0c,00,00,d4,07,00,00,01,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00
"SppCreate (Leave)"=hex:48,00,00,00,00,00,00,00,76,fa,80,c1,b9,1f,d8,01,38,25,\
00,00,04,0c,00,00,d0,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\SystemRestore]
"SrCreateRp (Enter)"=hex:48,00,00,00,00,00,00,00,a9,86,74,25,bc,1f,d8,01,c0,06,\
00,00,f8,21,00,00,d5,07,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
"SrCreateRp (Leave)"=hex:48,00,00,00,00,00,00,00,3c,eb,76,25,bc,1f,d8,01,c0,06,\
00,00,f8,21,00,00,d5,07,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\ASR Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\BITS Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\MSSearch Service Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\System Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\VolSnap]
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}DiscoverSnapshots (Enter)"=hex:48,\
00,00,00,00,00,00,00,46,e7,ad,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,20,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}Activate (Enter)"=hex:48,00,00,00,\
00,00,00,00,46,e7,ad,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,08,00,00,00,01,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}ActivateLoop (Enter)"=hex:48,00,\
00,00,00,00,00,00,46,e7,ad,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,1a,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}ActivateLoop (Leave)"=hex:48,00,\
00,00,00,00,00,00,d4,a4,b2,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,1b,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}ComputeIgnorableProduct (Enter)"=hex:48,\
00,00,00,00,00,00,00,d4,a4,b2,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,0c,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}ComputeIgnorableProduct (Leave)"=hex:48,\
00,00,00,00,00,00,00,d4,a4,b2,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,0d,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}Activate (Leave)"=hex:48,00,00,00,\
00,00,00,00,d4,a4,b2,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,09,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}DiscoverSnapshots (Leave)"=hex:48,\
00,00,00,00,00,00,00,d4,a4,b2,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,21,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}DeleteProcess (Enter)"=hex:48,00,\
00,00,00,00,00,00,d4,a4,b2,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,12,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}SetIgnorable (Enter)"=hex:48,00,\
00,00,00,00,00,00,98,f2,b4,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,0a,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}SetIgnorable (Leave)"=hex:48,00,\
00,00,00,00,00,00,d1,bc,b9,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,0b,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}AdjustBitmap (Enter)"=hex:48,00,\
00,00,00,00,00,00,d1,bc,b9,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,04,00,00,\
00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}ValidateDiffAreaFiles (Enter)"=hex:48,\
00,00,00,00,00,00,00,d1,bc,b9,a7,d7,1f,d8,01,00,00,00,00,00,00,00,00,1c,00,\
00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"VolumesSafeForWrite (Enter)"=hex:48,00,00,00,00,00,00,00,d1,bc,b9,a7,d7,1f,d8,\
01,00,00,00,00,00,00,00,00,1e,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
"VolumesSafeForWrite (Leave)"=hex:48,00,00,00,00,00,00,00,2e,84,60,a8,d7,1f,d8,\
01,00,00,00,00,00,00,00,00,1f,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}ValidateDiffAreaFiles (Leave)"=hex:48,\
00,00,00,00,00,00,00,2e,84,60,a8,d7,1f,d8,01,00,00,00,00,00,00,00,00,1d,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}AdjustBitmap (Leave)"=hex:48,00,\
00,00,00,00,00,00,2e,84,60,a8,d7,1f,d8,01,00,00,00,00,00,00,00,00,05,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
"Volume{0612cf60-075a-429b-b4c4-6f62c6d4cc9b}DeleteProcess (Leave)"=hex:48,00,\
00,00,00,00,00,00,2e,84,60,a8,d7,1f,d8,01,00,00,00,00,00,00,00,00,13,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}]
@="Microsoft Software Shadow Copy provider 1.0"
"Type"=dword:00000001
"Version"="1.0.0.7"
"VersionId"="{00000001-0000-0000-0007-000000000001}"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Providers\{b5946137-7b9f-4925-af80-51abd60b20d5}\CLSID]
@="{65EE1DBA-8FF4-4a58-AC1C-3470EE2F376A}"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings\WritersBlockingRevert]
"TornComponentsBlockRevert"=dword:00000001
"{2707761B-2324-473D-88EB-EB007A359533}"="DFS-R Writer"
"{B2014C9E-8711-4C5C-A5A9-3CF384484757}"="AD Writer"
"{D76F5A28-3092-4589-BA48-2958FB88CE29}"="FRS Writer"
"{DD846AAA-A1B6-42a8-AAF8-03DCB6114BFD}"="ADAM Writer"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl]
"NT Authority\\NetworkService"=dword:00000001
EndRegedit:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: netsh int ip reset
EmptyTemp:
Reboot:
End::