Смотрите видео ниже, чтобы узнать, как установить наш сайт в качестве веб-приложения на домашнем экране.
Примечание: Эта возможность может быть недоступна в некоторых браузерах.
begin
TerminateProcessByName('C:\Windows\SysWOW64\SystemDiagnosticsHost.exe');
TerminateProcessByName('c:\windows\media\mppr.exe');
QuarantineFile('C:\Windows\INF\.NETFramework\CORPerfMonSymbols.exe', '');
QuarantineFile('C:\Windows\INF\usbhub\usbperfsym.exe', '');
QuarantineFile('C:\Windows\InputMethod\SHARED\RC_ConnectedAccount.exe', '');
QuarantineFile('C:\Windows\SysWOW64\SystemDiagnosticsHost.exe', '');
QuarantineFile('c:\windows\media\mppr.exe', '');
DeleteFile('c:\windows\media\mppr.exe', '32');
DeleteFile('c:\windows\syswow64\systemdiagnosticshost.exe', '32');
DeleteFile('C:\Windows\Media\mppr.exe', '64');
DeleteFile('C:\Windows\InputMethod\SHARED\RC_ConnectedAccount.exe', '64');
DeleteFile('C:\Windows\INF\usbhub\usbperfsym.exe', '64');
DeleteFile('C:\Windows\INF\.NETFramework\CORPerfMonSymbols.exe', '64');
DeleteSchedulerTask('Launch Adobe CCXProcess');
DeleteSchedulerTask('Microsoft\Microsoft Launcher');
DeleteSchedulerTask('Microsoft\Windows\Windows Update Listner');
DeleteSchedulerTask('XCCProcess');
ExecuteSysClean;
ExecuteWizard('TSW', 2, 3, true);
RebootWindows(true);
end.
begin
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
end.
F2 - HKLM\..\WinLogon: [UserInit] = C:\Windows\System32\userinit.exe,C:\Windows\INF\.NETFramework\CORPerfMonSymbols.exe
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
RemoveProxy:
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
Task: {98961C3D-CEAF-4933-A7C4-ABD53516574B} - System32\Tasks\Обновление Браузера Яндекс => C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --background-update --noerrdialogs (Нет файла)
CHR HKU\S-1-5-21-1720535831-2360648822-1352276810-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ibknafobnmndicojahlppolcaaibngjf]
CHR HKLM-x32\...\Chrome\Extension: [kadaohckdkghfaclhjmkmplebcdcnfnp] - <отсутствует Path/update_url>
S3 MicrosoftEdgeElevationService; "C:\Program Files (x86)\Microsoft\Edge\Application\143.0.3650.96\elevation_service.exe" [X]
S2 RvControlSvc; "C:\Program Files (x86)\Radmin VPN\RvControlSvc.exe" /service [X]
S3 SteelSeriesGGUpdateServiceProxy; "C:\Program Files\SteelSeries\GG\SteelSeriesGGUpdateServiceProxy.exe" [X]
S2 WifiAutoInstallSrv; C:\Program Files\Realtek\WifiAutoInstall\WifiAutoInstallSrv.exe [X]
S3 PDFWKRNL; \??\C:\WINDOWS\SystemTemp\USBCPDFW\pdfwkrnl.sys [X]
StartPowershell:
Remove-MpPreference -ExclusionPath "NXLZEYchv.exe"
Remove-MpPreference -ExclusionPath "C:\Windows"
Remove-MpPreference -ExclusionPath "C:\Windows\InputMethod"
Remove-MpPreference -ExclusionPath "C:\Windows\INF"
Remove-MpPreference -ExclusionPath "C:\Recovery\OEM"
Set-MpPreference -DisableAutoExclusions $true -Force
Set-MpPreference -Mapsreporting basic -Force
Set-MpPreference -DisableArchiveScanning $false -Force
Set-MpPreference -DisableBehaviorMonitoring $false -Force
Set-MpPreference -DisableRealtimeMonitoring $false -Force
Set-MpPreference -DisablePrivacyMode $true -Force
Set-MpPreference -DisableIOAVProtection $false -Force
Set-MpPreference -UILockdown 0
Set-MpPreference -ScanPurgeItemsAfterDelay 1
Set-MpPreference -CheckForSignaturesBeforeRunningScan $true -Force
Set-MpPreference -PUAProtection enabled -Force
Update-MpSignature
Get-MpComputerStatus
Get-MpPreference
Get-AppxPackage Microsoft.SecHealthUI -AllUsers | Reset-AppxPackage
Get-AppxPackage Microsoft.SecHealthUI -AllUsers|select Name, Status
EndPowerShell:
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Zip: C:\FRST\Quarantine
EmptyTemp:
Reboot:
End::
C:\Users\admin\Desktop\AL\AutoLogger\AV\Quarantine\2025-12-28\avz00003.dta
C:\Users\admin\Desktop\AL\AutoLogger\AV\Quarantine\2025-12-28\avz00005.dta