А у меня горе, в лабе дефендер замочил такие файлы.
File to act on SHA1:1942A0BC6B5D32DE95E2781F97E3AAE034549727
File owner:BUILTIN\Administrators
File cleaned/removed successfully
File Name:C:\inetpub\wwwroot\aspnet_client\V0vney.aspx
Action remove successful on file:\\?\C:\inetpub\wwwroot\aspnet_client\V0vney.aspx
Resource action complete:Removal
Schema:file
Path:\\?\C:\inetpub\wwwroot\aspnet_client\V0vney.aspx
Threat ID:2147776820
Resource refcount:1
Result:0