Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
Unlock: C:\FRST\
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
HKU\S-1-5-21-3992856254-958219828-1378424414-1001\...\Run: [gt-launcher] => C:\Users\Usuario\AppData\Local\Programs\com.gametop.launcher\gt-launcher.exe [146382336 2024-08-21] (GitHub, Inc.) [Файл не подписан]
C:\Users\Usuario\AppData\Local\Programs\com.gametop.launcher\
Task: {31B5181E-5073-4EF9-B7AA-4EA85F29E5A1} - \Microsoft\Windows\CreedMobeX\K4BjFXmpQD -> Нет файла <==== ВНИМАНИЕ
Task: {F79F97E0-F13E-4BFD-B5CD-B9C58C26407D} - \Microsoft\Windows\CreedMobeX\RecoveryHosts -> Нет файла <==== ВНИМАНИЕ
Task: {343F1148-00B9-4870-99B2-CD3CC0DB02C7} - System32\Tasks\EdgeUpdateTaskUser => C:\Windows\System32\wscript.exe [200704 2025-02-18] (Microsoft Windows -> Microsoft Corporation) -> /b "C:\ProgramData\Microsoft\wext.vbs" <==== ВНИМАНИЕ
C:\ProgramData\Microsoft\wext.vbs
Task: {5E1C577B-975B-4C04-BF0E-2794DEE9F7A0} - System32\Tasks\OneDriveUpdater => C:\Windows\System32\wscript.exe [200704 2025-02-18] (Microsoft Windows -> Microsoft Corporation) -> /b "C:\ProgramData\Microsoft\wsIC.vbs" <==== ВНИМАНИЕ
C:\ProgramData\Microsoft\wsIC.vbs
C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmabgcinfefhdgfmjeiobhoianebmlkh
C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\leifkeoalnhcknnnejjddjppnolfieoi
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKU\S-1-5-21-3992856254-958219828-1378424414-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fhkbfkkohcdgpckffakhbllifkakihmh]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
C:\Firewall.reg
CMD: netsh advfirewall reset
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Zip: C:\FRST\Quarantine
EmptyTemp:
Reboot:
End::