Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4146699174-386112156-479380857-1001\...\MountPoints2: {07e44446-85c7-11ed-9ea2-7085c29b8e81} - "H:\autoplay.exe"
HKU\S-1-5-21-4146699174-386112156-479380857-1001\...\MountPoints2: {d6202aa7-38be-11ed-9e1c-7085c29b8e81} - "H:\AutoRun.exe"
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
CHR StartupUrls: Default -> "hxxp://mypoisk.su/","hxxp://googla.com.ua/q","hxxps://www.google.com/"
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [mfhcmdonhekjhfbjmeacdjbhlfgpjabp]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [2594]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blend for Visual Studio 2019.lnk:6569B2479D [2594]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OVGorskiy.ru.URL:FC91667982 [2594]
FirewallRules: [{48A084DC-89E6-4D2F-8E88-CC6E20489645}] => (Allow) LPort=1688
FirewallRules: [{1BC06689-9622-4F9E-8C58-2D4CAEB26DAE}] => (Allow) LPort=53
FirewallRules: [{F7823479-2544-4020-8D96-7218705EF7E4}] => (Allow) LPort=3001
FirewallRules: [{842FB2D9-2E3E-4070-A9EE-41FE53CE389B}] => (Allow) LPort=3000
FirewallRules: [{EC8BCE25-D224-4B8B-A113-B40775C7B373}] => (Allow) LPort=1542
FirewallRules: [{C245C890-898D-43E5-87FA-5AB39C36B265}] => (Allow) LPort=1542
FirewallRules: [{C3148E68-B91B-40A1-AD56-2E94CAE567FA}] => (Allow) LPort=53
FirewallRules: [{1C6D3C8F-6AC2-4B6C-8566-D2FB772A317B}] => (Allow) C:\Users\Kusachki\Downloads\360TS_Setup_Mini.exe => No File
FirewallRules: [{6FFC3DD7-0DDE-4012-9A7D-EA5E5D114F11}] => (Allow) C:\Users\Kusachki\Downloads\360TS_Setup_Mini.exe => No File
ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
EmptyTemp:
Reboot:
End::