Start::
SystemRestore: On
CreateRestorePoint:
VirusTotal: C:\Users\nikdan\exe.reg
Policies: C:\ProgramData\NTUSER.pol: Ограничение <==== ВНИМАНИЕ
Edge HKLM-x32\...\Edge\Extension: [odbmjgikedenicicookngdckhkjbebpd]
Edge DefaultSearchURL: Default -> hxxp://search-cdn.net/fip/?q={searchTerms}
Edge DefaultSearchKeyword: Default -> search-cdn.net
Edge StartupUrls: Default -> "hxxps://find-it.pro/?utm_source=distr_m"
CHR HKU\S-1-5-21-2907845927-29716864-2120206527-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [djgdgdcfmdkficbifbnaacknblbkhhoc]
2022-02-16 20:15 - 2022-02-16 20:15 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign3385decce5fdb9df
2022-02-16 20:14 - 2022-02-16 20:14 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign3fbc1e03e0a93926
2022-02-15 19:48 - 2022-02-15 19:48 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigna346561ca2c44ac8
2022-02-15 19:48 - 2022-02-15 19:48 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign8395cbb9b6c90dfc
2022-02-13 23:22 - 2022-02-13 23:22 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign911604850d0a7e37
2022-02-13 23:21 - 2022-02-13 23:21 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign23328540f2fab7a7
2022-02-13 17:39 - 2022-02-13 17:39 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigndf65399b328e11c5
2022-02-13 17:39 - 2022-02-13 17:39 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign7f7f1bf3afcc5c4a
2022-02-13 17:39 - 2022-02-13 17:39 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign173f51d9b64bdc60
2022-02-13 17:38 - 2022-02-13 17:38 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign4c156c66a56f7e31
2022-02-13 16:31 - 2022-02-13 16:31 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigne222212df8339fed
2022-02-13 14:31 - 2022-02-13 14:31 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign01cc2608f928e3c2
2022-02-13 14:13 - 2022-02-13 14:13 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignc2707c07dbcf1743
2022-02-13 14:07 - 2022-02-13 14:07 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign6d342fb044f83bc9
2022-02-13 12:49 - 2022-02-13 12:49 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign7fd40de00dbf5c48
2022-02-13 12:49 - 2022-02-13 12:49 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign52a1fdef7077774a
2022-02-08 22:07 - 2022-02-08 22:07 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign7fe346797c44f010
2022-02-08 22:07 - 2022-02-08 22:07 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign09c16e79e4f68154
2022-02-08 19:45 - 2022-02-08 19:45 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign1707ed5f1f69f31e
2022-02-08 19:45 - 2022-02-08 19:45 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign0a6c540a65a6dc1a
2022-02-07 18:58 - 2022-02-07 18:58 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign910620cb6666c42d
2022-02-07 18:58 - 2022-02-07 18:58 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign2b27cd6d8f80b54d
2022-02-06 11:45 - 2022-02-06 11:45 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign9f21911ed4fdacc4
2022-02-06 11:44 - 2022-02-06 11:44 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign6ef71fecfa6ee79d
2022-02-06 11:41 - 2022-02-06 11:41 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignad9479792070ba2d
2022-02-06 11:40 - 2022-02-06 11:40 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign93f3d910bb4a9671
2022-02-05 20:00 - 2022-02-05 20:00 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignce6c1d59e40cb31a
2022-02-05 19:16 - 2022-02-05 19:16 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignf7d15a4b49c5fc12
2022-02-05 19:15 - 2022-02-05 19:15 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign79359302249410fa
2022-02-04 16:12 - 2022-02-04 16:12 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignca7f5aaca013f01f
2022-02-04 16:12 - 2022-02-04 16:12 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign11b458ce5871cd71
2022-02-04 16:08 - 2022-02-04 16:08 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignbfea3345ba196855
2022-02-04 16:08 - 2022-02-04 16:08 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign8016c16ac77e89d7
2022-02-04 15:19 - 2022-02-04 15:19 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign47f03cd6c2aa081a
2022-02-04 15:19 - 2022-02-04 15:19 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign4265b7defe9c962c
2022-01-29 23:09 - 2022-01-29 23:09 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign3fddd6c1bcea49d1
2022-01-29 23:08 - 2022-01-29 23:08 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign961673254dfcbdc9
2022-01-29 22:54 - 2022-01-29 22:54 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign3553af68b3da2394
2022-01-29 22:53 - 2022-01-29 22:53 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigne3a099514db2ba70
2022-01-29 11:28 - 2022-01-29 11:28 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign91bfa9b2c4ad2cdb
2022-01-29 11:26 - 2022-01-29 11:26 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign7c5e248144ece216
2022-01-29 11:26 - 2022-01-29 11:26 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign205bbeb5e4c0fd2f
2022-01-29 11:25 - 2022-01-29 11:25 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignb769c94b8593e41b
2022-01-29 10:36 - 2022-01-29 10:36 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignec6bc7fedd26be7b
2022-01-29 10:36 - 2022-01-29 10:36 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign252a75417535a399
2022-01-29 10:20 - 2022-01-29 10:20 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignb1b6c003e63ef0ce
2022-01-29 10:20 - 2022-01-29 10:20 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign1130faac07ad6a4f
2022-01-29 09:16 - 2022-01-29 09:16 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign5841587cceb5ffeb
2022-01-29 09:16 - 2022-01-29 09:16 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign3578f6875fb21bb3
2022-01-29 09:12 - 2022-01-29 09:12 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign4197651855001e44
2022-01-29 09:11 - 2022-01-29 09:11 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignb2c004d1875ada86
2022-01-28 23:41 - 2022-01-28 23:41 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigna1c023333d7a374f
2022-01-28 23:40 - 2022-01-28 23:40 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign699b6d5c46b9cf4b
2022-01-28 23:31 - 2022-01-28 23:31 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigne52bf80446d00dac
2022-01-28 23:31 - 2022-01-28 23:31 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignd658ad88729800df
2022-01-28 23:26 - 2022-01-28 23:26 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignba3b9ff1f04da095
2022-01-28 23:26 - 2022-01-28 23:26 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign443807ccf29dc380
2022-01-28 23:15 - 2022-01-28 23:15 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignda685d0dbd5bf7b6
2022-01-28 23:14 - 2022-01-28 23:14 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign6974d12856079db5
2022-01-28 22:40 - 2022-01-28 22:40 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign3a31a0c2198e4e35
2022-01-28 22:40 - 2022-01-28 22:40 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign1b0e9e6eff6edca9
2022-01-28 21:49 - 2022-01-28 21:49 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign9e8e9fd47a463dba
2022-01-28 21:49 - 2022-01-28 21:49 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign7c6b38daf8bccb7b
2022-01-28 18:12 - 2022-01-28 18:12 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignaaad15f19f4af453
2022-01-28 18:12 - 2022-01-28 18:12 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigna034cd45c27b12bc
2022-01-28 16:03 - 2022-01-28 16:03 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign5eb762e22daece72
2022-01-28 15:52 - 2022-01-28 15:52 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignb486f3030432981a
2022-01-28 15:52 - 2022-01-28 15:52 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign64357d8b6ed91bf1
2022-01-28 15:50 - 2022-01-28 15:50 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigne6481f6a4de0e077
2022-01-28 15:49 - 2022-01-28 15:49 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign04a011aa76778e46
2022-01-28 14:29 - 2022-01-28 14:29 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign318cb138da8f2333
2022-01-28 14:29 - 2022-01-28 14:29 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign0cca599305e1b280
2022-01-28 12:51 - 2022-01-28 12:51 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign6a684c54937038fb
2022-01-28 12:51 - 2022-01-28 12:51 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign2338c2c04b9bd43e
2022-01-28 11:53 - 2022-01-28 11:53 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign4bdfe5a4075324a9
2022-01-28 11:53 - 2022-01-28 11:53 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign39cb225b493273a9
2022-01-28 11:34 - 2022-01-28 11:34 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsigna599e538f587cf57
2022-01-28 11:34 - 2022-01-28 11:34 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign0332f14b9374157d
2022-01-27 18:09 - 2022-01-27 18:09 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign4cab4ab012ef273e
2022-01-27 18:09 - 2022-01-27 18:09 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign01ff5084753dbd6a
2022-01-27 17:25 - 2022-01-27 17:25 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsignb5f41c6575542d7d
2022-01-27 17:24 - 2022-01-27 17:24 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign134df716eb74f111
2022-01-27 14:16 - 2022-01-27 14:16 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign945e2bc3793c8c5c
2022-01-27 14:15 - 2022-01-27 14:15 - 000000000 ____D C:\Users\nikdan\AppData\Local\Tempzxpsign35432cdb93b822b9
URLSearchHook: HKU\S-1-5-21-2907845927-29716864-2120206527-1001 - (Нет имени) - {C9423817-5DA7-494E-87E4-111F1B49A1FD} - Нет файла
SearchScopes: HKU\S-1-5-21-2907845927-29716864-2120206527-1001 -> DefaultScope 90f3dc62-eeec-11eb-8011-d8c0a6b45aa4 URL = hxxp://search-cdn.net/fip/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2907845927-29716864-2120206527-1001 -> 90f3dc62-eeec-11eb-8011-d8c0a6b45aa4 URL = hxxp://search-cdn.net/fip/?q={searchTerms}
FirewallRules: [{00A90C57-F8DB-45E3-AC87-A88A5E481423}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe => Нет файла
FirewallRules: [{91167807-C910-4453-9D6F-472A4896EA12}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe => Нет файла
EmptyTemp:
Reboot:
End::