Start::
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST
John (S-1-5-21-364097164-3679396712-3319335087-1002 - Administrator - Enabled)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Ограничение <==== ВНИМАНИЕ
HKU\S-1-5-21-364097164-3679396712-3319335087-1001\...\Policies\Explorer: [DisallowRun] 1
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\WavePad
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\RobotDemo
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\PuzzleMedia
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\McAfee
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\grizzly
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\FingerPrint
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\Evernote
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\BookManager
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files\Ravantivirus
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files\Rainmeter
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files\Process Lasso
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files\Loaris Trojan Remover
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files\Common Files\McAfee
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files\Cezurity
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files (x86)\Transmission
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files (x86)\Panda Security
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files (x86)\GRIZZLY Antivirus
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 __SHD C:\Program Files (x86)\Cezurity
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 ____D C:\ProgramData\Avira
2023-03-29 15:08 - 2023-03-29 15:08 - 000000000 ____D C:\Program Files (x86)\IObit
2023-03-29 15:07 - 2023-04-22 14:46 - 000000000 __SHD C:\ProgramData\Doctor Web
2023-03-29 15:07 - 2023-04-22 14:08 - 000000000 __SHD C:\Program Files\DrWeb
2023-03-29 15:07 - 2023-04-22 13:44 - 000000000 ___HD C:\Program Files\RDP Wrapper
2023-03-29 15:07 - 2023-04-22 13:39 - 000000000 __SHD C:\ProgramData\Windows Tasks Service
2023-03-29 15:07 - 2023-04-22 13:30 - 000000000 __SHD C:\Program Files\Common Files\Doctor Web
2023-03-29 15:07 - 2023-03-29 15:14 - 000000000 __SHD C:\ProgramData\WindowsTask
2023-03-29 15:07 - 2023-03-29 15:13 - 000000000 __SHD C:\ProgramData\ReaItekHD
2023-03-29 15:07 - 2023-03-29 15:10 - 000000000 __SHD C:\ProgramData\Setup
2023-03-29 15:07 - 2023-03-29 15:08 - 000000000 __SHD C:\ProgramData\Install
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\RunDLL
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\Norton
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\MB3Install
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\Malwarebytes
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\Kaspersky Lab Setup Files
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\Kaspersky Lab
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\AVAST Software
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\ProgramData\360safe
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\SpyHunter
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\Malwarebytes
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\Kaspersky Lab
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\Enigma Software Group
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\COMODO
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\Common Files\AV
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\ByteFence
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\Bitdefender Agent
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\AVG
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files\AVAST Software
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files (x86)\SpyHunter
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files (x86)\Microsoft JDX
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files (x86)\Kaspersky Lab
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files (x86)\AVG
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files (x86)\AVAST Software
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\Program Files (x86)\360
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\KVRT2020_Data
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\KVRT_Data
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 __SHD C:\AdwCleaner
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 ___HD C:\Users\John
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 ____D C:\Windows\speechstracing
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 ____D C:\Users\lenya\AppData\Roaming\RMS_settings
2023-03-29 15:07 - 2023-03-29 15:07 - 000000000 ____D C:\ProgramData\System32
C:\ProgramData\WindowsTask\AppModule.exe
C:\ProgramData\WindowsTask\AMD.exe
FirewallRules: [{3A8CD4A2-44FA-40CB-A94F-CB3D8BACBEA6}] => (Allow) C:\Users\lenya\AppData\Local\Temp\utorrent\utorrent.exe => Нет файла
FirewallRules: [{A339DABF-6F3E-4980-A65C-80AC33A44964}] => (Allow) C:\Users\lenya\AppData\Local\Temp\utorrent\utorrent.exe => Нет файла
FirewallRules: [{FEC0CF8A-0907-4F59-967F-8DC1984DAAAB}] => (Allow) C:\ProgramData\WindowsTask\AppModule.exe () [Файл не подписан]
FirewallRules: [{D9EC32A3-2F34-462C-AF3C-D18E6DFEC82C}] => (Allow) C:\ProgramData\WindowsTask\AMD.exe () [Файл не подписан]
FirewallRules: [{34BEB2C5-BF1E-42E9-AE9A-4C01E9C0BB49}] => (Block) LPort=445
FirewallRules: [{A2315400-9ADB-4815-88B3-9FBD71DE4B6B}] => (Block) LPort=445
FirewallRules: [{6F52B076-955D-4636-B982-7F48CDC4A29B}] => (Block) LPort=139
FirewallRules: [{47869C18-72EE-4939-A42D-5E77914896F0}] => (Block) LPort=139
FirewallRules: [{AED65D77-3606-4407-91ED-D2A724E87044}] => (Allow) C:\ProgramData\Windows Tasks Service\winserv.exe => Нет файла
FirewallRules: [{5DAD8753-5B23-4A54-A5E1-6E8626A695E2}] => (Allow) LPort=3389
EmptyTemp:
Reboot:
End::