Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Edge: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\BraveSoftware\Brave: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Vivaldi: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\YandexBrowser: Ограничение <==== ВНИМАНИЕ
C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndelhfhcfbdhndfpcinebijfcjpmpec
CHR HKU\S-1-5-21-2898858890-3343274005-1393113291-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gndelhfhcfbdhndfpcinebijfcjpmpec]
AV: Kaspersky Free (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
FirewallRules: [{70A01DAD-44B6-42C1-8A7F-407006CDF1EB}] => (Allow) LPort=9422
FirewallRules: [{2083A66B-0A77-4478-BCEF-0A1F6B728E09}] => (Allow) LPort=9245
FirewallRules: [{9033384B-13FA-43F1-9F06-B874ABCFFB3C}] => (Allow) LPort=9246
FirewallRules: [{37BB6DC0-8CFC-4E0C-8A8A-41E94CFCB480}] => (Allow) LPort=9247
FirewallRules: [{E9F10803-0759-4A93-8232-9082217EBE4E}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => Нет файла
FirewallRules: [{B2931A33-FCBD-43A5-9E11-C25CB654FD9E}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => Нет файла
FirewallRules: [{A1CEFE36-EDC1-4B0B-8533-29FACEF48FFD}] => (Allow) C:\Users\PC\AppData\Local\Temp\rh_package\SabyAdmin_1035490543.exe => Нет файла
FirewallRules: [{A4279671-0391-4A54-85AB-17779974CBBE}] => (Allow) C:\Users\PC\AppData\Local\Temp\rh_package\SabyAdmin_1035490543.exe => Нет файла
FirewallRules: [{33FBE799-4C36-4699-91C2-2502BDFDDDDE}] => (Allow) C:\Users\PC\AppData\Local\Temp\rh_package\SabyAdmin_1035490543.exe => Нет файла
startbatch:
DISM.exe /Online /Cleanup-image /Restorehealth
sfc /scannow
winmgmt /salvagerepository
winmgmt /verifyrepository
"%WINDIR%\SYSTEM32\lodctr.exe" /R
"%WINDIR%\SysWOW64\lodctr.exe" /R
"%WINDIR%\SYSTEM32\lodctr.exe" /R
"%WINDIR%\SysWOW64\lodctr.exe" /R
del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Code Cache\Js\*.*"
del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\Js\*.*"
endbatch:
EmptyTemp:
Reboot:
End::