Start::
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\MRT: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Microsoft\Edge: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\BraveSoftware\Brave: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Vivaldi: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\YandexBrowser: Ограничение <==== ВНИМАНИЕ
CHR StartupUrls: Default -> "hxxps://213.33.146.50:8084/secure/Dashboard.jspa","hxxps://213.33.146.50:8084/secure/ConfigureReport.jspa?usergroup=Test+group&subtasktypes=10&subtasktypes=24&subtasktypes=15&subtasktypes=17&subtasktypes=34&subtasktypes=29&datestart=1%2F%D1%81%D0%B5%D0%BD%2F13&dateend=30%2F%D1%81%D0%B5%D0%BD%2F13&selectedProjectId=10351&reportKey=com.teleformis.jira.plugins.tfsuite%3AtechnologsTest&%D0%94%D0%B0%D0%BB%D0%B5%D0%B5=%D0%94%D0%B0%D0%BB%D0%B5%D0%B5","hxxp://192.168.5.44/SpiraTeam/15/TestCase/4726.aspx","hxxp://ccm.teleformis.ru:8080/share/page/site/chemodanov/dashboard","hxxp://get-tune.net/?a=music&q=offspring","hxxp://www.sweet-page.com/?type=hp&ts=1399576799&from=cor&uid=ST3250318AS_9VY9KZEPXXXX9VY9KZEP","hxxp://www.google.com","hxxp://www.istartsurf.com/?type=hp&ts=1446554395&z=0d57965d72c257f578633e7gaz7z6qbw9wfz5g5oez&from=face&uid=TOSHIBAXMK3265GSX_908BP5VYTXX908BP5VYT","hxxp://www.google.com/"
C:\Users\timof\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgpjdiadomhinpimgchmeembbgojnjk
CHR HKU\S-1-5-21-1293453156-688989951-3096954729-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ldgpjdiadomhinpimgchmeembbgojnjk]
S4 BITS_bkp; C:\WINDOWS\System32\qmgr.dll [1474560 2025-12-10] (Microsoft Windows -> Microsoft Corporation)
U2 dosvc_bkp; C:\WINDOWS\system32\dosvc.dll [98304 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
S2 UsoSvc_bkp; C:\WINDOWS\system32\usosvc.dll [106496 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
S3 WaaSMedicSvc_bkp; C:\WINDOWS\System32\WaaSMedicSvc.dll [94208 2025-12-10] (Microsoft Windows -> Microsoft Corporation)
S2 WCFVBXSG; C:\ProgramData\tfkxupgodbpx\cderspzpcngq.exe [2879488 2026-03-26] () [Файл не подписан] <==== ВНИМАНИЕ
S2 wuauserv_bkp; C:\WINDOWS\system32\wuaueng.dll [184736 2026-03-11] (Microsoft Windows -> Корпорация Майкрософт)
C:\ProgramData\tfkxupgodbpx\cderspzpcngq.exe
2026-03-26 11:21 - 2025-10-20 00:07 - 000000000 ____D C:\Program Files\RDP Wrapper
StartPowerShell:
Remove-MpPreference -ExclusionExtension ".exe"
Remove-MpPreference -ExclusionPath "C:\Windows\SysWow64\unsecapp.exe"
Remove-MpPreference -ExclusionPath "C:\Program Files\RDP Wrapper"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\AMD.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\audiodg.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\MicrosoftHost.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData\ReaItekHD\taskhost.exe"
Remove-MpPreference -ExclusionPath "C:\ProgramData\WindowsTask\AppModule.exe"
Remove-MpPreference -ExclusionPath "C:\Users\timof"
Remove-MpPreference -ExclusionPath "C:\WINDOWS\system32\config\systemprofile"
Remove-MpPreference -ExclusionPath "C:\Users\timof\AppData\Local\JetBrains\IdeaIC2025.2\tmp"
EndPowerShell:
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
FirewallRules: [{BEF6D425-0C50-46F8-B883-91D132578AFA}] => (Allow) C:\Users\timof\AppData\Local\Programs\Opera\opera.exe => Нет файла
FirewallRules: [{1015A71D-9DC5-4671-A9FA-C0B1D9CDAF26}] => (Allow) C:\Users\timof\AppData\Local\Programs\Opera GX\opera.exe => Нет файла
FirewallRules: [{6B7265D0-CFCA-4ABA-B9A2-3C4713074FEE}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => Нет файла
FirewallRules: [{79CF79F1-E54E-4B5D-8950-A56E2CBD385A}] => (Allow) C:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe => Нет файла
EmptyTemp:
Reboot:
End::