Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ограничение <==== ВНИМАНИЕ
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ВНИМАНИЕ
HKU\S-1-5-21-868203072-465459243-2922284378-1001\...\Run: [MediaGet2] => C:\Users\79114\MediaGet2\mediaget.exe --minimized (Нет файла)
HKU\S-1-5-21-868203072-465459243-2922284378-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize (Нет файла) <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ограничение <==== ВНИМАНИЕ
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
Task: {D0D69554-48A3-4E7D-95C9-B89E228C586B} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3818024 2025-04-10] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {F828D1BD-120F-4794-B040-77F15F897A4C} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3818024 2025-04-10] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {0A2D2D58-B4A4-4480-A302-50F4172A27C9} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
Task: {E331B2C6-C9C7-4839-B433-D37433F11657} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
Edge HomePage: Default -> hxxps://find-it.pro/?utm_source=distr_m
Edge DefaultSearchURL: Default -> hxxps://xfinder.pro/q?q={searchTerms}
Edge DefaultSearchKeyword: Default -> xfinder.pro
Edge DefaultSuggestURL: Default -> hxxps://xfinder.pro/q/suggest.php?q={searchTerms}
C:\Users\79114\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ggnchfknjkebijkdlbddehcpgfebapdc
C:\Users\79114\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oikgcnjambfooaigmdljblbaeelmekem
CHR HomePage: Default -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: Default -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchKeyword: Default -> cdn
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\khflaofpanjfdfkgglalicnelkgjnjef
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocpngelafhpaapgfbcobfpappmpifenm
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\oikgcnjambfooaigmdljblbaeelmekem
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Default\Extensions\onbkopaoemachfglhlpomhbpofepfpom
CHR HomePage: Guest Profile -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: Guest Profile -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchKeyword: Guest Profile -> cdn
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Guest Profile\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Guest Profile\Extensions\oikgcnjambfooaigmdljblbaeelmekem
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\khflaofpanjfdfkgglalicnelkgjnjef
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ocpngelafhpaapgfbcobfpappmpifenm
CHR HomePage: Profile 2 -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: Profile 2 -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchURL: Profile 2 -> hxxp://search-cdn.net/fip/?q={searchTerms}
CHR DefaultSearchKeyword: Profile 2 -> cdn
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\oikgcnjambfooaigmdljblbaeelmekem
CHR HomePage: Profile 4 -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: Profile 4 -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchKeyword: Profile 4 -> cdn
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\oikgcnjambfooaigmdljblbaeelmekem
CHR HomePage: Profile 5 -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: Profile 5 -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchURL: Profile 5 -> hxxp://search-cdn.net/fip/?q={searchTerms}
CHR DefaultSearchKeyword: Profile 5 -> cdn
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\oikgcnjambfooaigmdljblbaeelmekem
CHR HomePage: Profile 7 -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: Profile 7 -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchKeyword: Profile 7 -> cdn
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\oikgcnjambfooaigmdljblbaeelmekem
CHR HomePage: System Profile -> hxxps://find-it.pro/?utm_source=distr_m
CHR StartupUrls: System Profile -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR DefaultSearchURL: System Profile -> hxxps://xfinder.pro/q?q={searchTerms}
CHR DefaultSearchKeyword: System Profile -> xfinder.pro
CHR DefaultSuggestURL: System Profile -> hxxps://xfinder.pro/q/suggest.php?q={searchTerms}
C:\Users\79114\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\iddmabhekhhonkmomaklnflhhgbfnioe
C:\Users\79114\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\oikgcnjambfooaigmdljblbaeelmekem
CHR HKU\S-1-5-21-868203072-465459243-2922284378-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fgflndiedodffhcdiopjphegdlofpgoc]
CHR HKU\S-1-5-21-868203072-465459243-2922284378-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ldgpjdiadomhinpimgchmeembbgojnjk]
CHR HKLM-x32\...\Chrome\Extension: [fdjdjkkjoiomafnihnobkinnfjnnlhdg]
CHR HKLM-x32\...\Chrome\Extension: [mfhcmdonhekjhfbjmeacdjbhlfgpjabp]
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2022-12-13] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\134.0.29548.179\elevation_service.exe [2580000 2025-04-10] (Avast Software s.r.o. -> Gen Digital Inc.)
2025-04-30 00:52 - 2025-04-30 00:52 - 000000000 ____D C:\ProgramData\PDJxffHHBXNTxhp
2025-04-12 15:40 - 2025-04-30 02:36 - 000000000 ____D C:\ProgramData\XThUeAnPtjHvTaVB
Folder: C:\rdp
2021-05-14 20:44 C:\ProgramData\Indus
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1579.3 - AVAST Software) Hidden
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1065.0 - AVAST Software) Hidden
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
DeleteKey: HKEY_USERS\S-1-5-21-868203072-465459243-2922284378-1001\SOFTWARE\tektonit
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::