Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKU\S-1-5-21-80103531-2647236927-3508730776-1004\...\Run: [160195ED-38CE8FA4hta] => C:\Users\aFUI1!\AppData\Local\Temp\how_to_decrypt.hta [1794 2022-07-31] () [Файл не подписан] <==== ВНИМАНИЕ
Startup: C:\Users\aFUI1!\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\how_to_decrypt.hta [2022-07-31] () [Файл не подписан]
HKLM\SOFTWARE\Policies\Google: Ограничение <==== ВНИМАНИЕ
CHR StartupUrls: Default -> "hxxps://mail.ru/cnt/11956636","hxxps://www.google.com.ua/","hxxp://www.delta-homes.com/?type=hp&ts=1432124667&z=10554c9877a41043782d11dg4z5ccobg9o7z2q0wfc&from=wpm05203&uid=WDCXWD2500BEVT-24A23T0_WD-WXF1A30P6015P6015","hxxp://www.delta-homes.com/?type=hp&ts=1442916120&z=1a9f99f7cfdb810c27111e9g3zfz9obtdg0q7g8o4e&from=ient07031&uid=WDCXWD2500BEVT-24A23T0_WD-WXF1A30P6015P6015","hxxp://www.google.com/"
2022-07-31 14:04 - 2022-07-31 14:04 - 000001794 _____ C:\Users\Public\how_to_decrypt.hta
2022-07-31 14:04 - 2022-07-31 14:04 - 000001794 _____ C:\Users\Public\Downloads\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\Downloads\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\Documents\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\Desktop\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\AppData\Roaming\Microsoft\Windows\Start Menu\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\AppData\Roaming\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\AppData\LocalLow\how_to_decrypt.hta
2022-07-31 14:01 - 2022-07-31 14:01 - 000001794 _____ C:\Users\aFUI1!\AppData\how_to_decrypt.hta
2022-07-31 14:00 - 2022-07-31 14:00 - 000001794 _____ C:\Users\aFUI1!\AppData\Local\how_to_decrypt.hta
2022-07-31 13:33 - 2022-07-31 13:33 - 000001794 _____ C:\Users\Public\Documents\how_to_decrypt.hta
2022-07-31 13:33 - 2022-07-31 13:33 - 000001794 _____ C:\ProgramData\how_to_decrypt.hta
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::