Start::
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Ограничение <==== ВНИМАНИЕ
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
Task: {2AC8D78E-0EEA-4EB3-BF76-98A6B23BB066} - System32\Tasks\Microsoft\Windows\CheckGlobalO\RecoveryHosts => C:\ProgramData\Microsoft\Network\yNBKhBExp\CheckGlobalO.bat (Нет файла) <==== ВНИМАНИЕ
Task: {AE7A392D-7180-428B-BF1E-1EF355DEF756} - System32\Tasks\Microsoft\Windows\Wininet\winser => "C:\ProgramData\Windows Tasks Service\winserv.exe" -> Task Service\winserv.exe <==== ВНИМАНИЕ
Task: {5E84A43B-472C-4173-A287-910E89BB3EDB} - System32\Tasks\Microsoft\Windows\Wininet\winsers => "C:\ProgramData\Windows Tasks Service\winserv.exe" -> Task Service\winserv.exe <==== ВНИМАНИЕ
C:\ProgramData\Windows Tasks Service\winserv.exe
CHR HKU\S-1-5-21-4165786792-2377350130-1350153214-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ldgpjdiadomhinpimgchmeembbgojnjk]
John (S-1-5-21-4165786792-2377350130-1350153214-1002 - Administrators - Enabled) <==== ВНИМАНИЕ
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> Нет файла
FirewallRules: [{174C8800-012F-483D-95C2-780273E53B02}] => (Block) LPort=445
FirewallRules: [{0B25E344-D521-4C04-85B6-65DEA298285E}] => (Block) LPort=445
FirewallRules: [{B2214829-DEB7-4F72-87AF-FA4829E09660}] => (Block) LPort=139
FirewallRules: [{E41D95D8-73E2-4914-B373-94B23099AFDC}] => (Block) LPort=139
FirewallRules: [{7FFCB571-74DD-4DDC-A510-FBE8DBBD774B}] => (Allow) LPort=3389
FirewallRules: [{5A38AF1A-D1AF-4F3B-B86E-49B5A9A762B1}] => (Allow) LPort=2869
FirewallRules: [{E9A5A36C-E58F-4BDC-9190-F46EBC0B509D}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{FE8E948F-D66C-40E0-959B-E5E2DFB4FF5D}C:\program files\nekoray\nekoray.exe] => (Allow) C:\program files\nekoray\nekoray.exe => Нет файла
FirewallRules: [UDP Query User{1F077E68-B6CA-492B-8612-E1C4A5E6B7CA}C:\program files\nekoray\nekoray.exe] => (Allow) C:\program files\nekoray\nekoray.exe => Нет файла
EmptyTemp:
Reboot:
End::