﻿Лог утилиты random's system information tool 1.14(автор: random/random)
Run by Николай at 2017-02-22 18:24:53
Microsoft Windows 7 Максимальная  Service Pack 1
Системный раздел C: размер 60 GB (28%) Свободно 216 GB
Total RAM: 2047 MB (44% free)
X86

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 18:25:03, on 22.02.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!

FIREFOX: 51.0.1 (x86 ru)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Yandex\YandexBrowser\17.1.1.1004\service_update.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Николай\Downloads\AutoLogger\AutoLogger\AVZ\avz.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\avpui.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Николай\Downloads\AutoLogger\AutoLogger\RSIT\RSIT.exe
C:\Users\Николай\Downloads\AutoLogger\AutoLogger\RSIT\Николай_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rigneda.ru/?utm_source=startpage03&utm_content=17932093119668bc1771ad2792b5a42b&utm_term=D640C1541D5AC83BA58E2ADAB5813FD3&utm_d=20170106
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {2E38825B-8815-42CF-9126-C58BC28D4591} - C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll
O3 - Toolbar: Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Mail.Ru Агент - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Users\Николай\AppData\Roaming\Mail.Ru\Agent\magent.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Mail.Ru Агент - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Users\Николай\AppData\Roaming\Mail.Ru\Agent\magent.exe (file missing) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Kaspersky Anti-Virus Service 17.0.0 (AVP17.0.0) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe
O23 - Service: Служба Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Kaspersky Secure Connection Service 1.0.0 (KSDE1.0.0) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
O23 - Service: Wise Boot Assistant (WiseBootAssistant) - WiseCleaner.com - E:\софт\Wise Care 365\BootTime.exe
O23 - Service: Yandex.Browser Update Service (YandexBrowserService) - YANDEX LLC - C:\Program Files\Yandex\YandexBrowser\17.1.1.1004\service_update.exe

--
End of file - 5408 bytes

======Папка назначенных заданий======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\Windows\tasks\Обновление Браузера Яндекс.job - C:\Users\Николай\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  --background-update
C:\Windows\tasks\Системное обновление Браузера Яндекс.job - C:\Program Files\Yandex\YandexBrowser\17.1.1.1004\service_update.exe  --run-as-launcher
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Обновление Браузера Яндекс - C:\Users\Николай\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --background-update
C:\Windows\system32\tasks\Системное обновление Браузера Яндекс - C:\Program Files\Yandex\YandexBrowser\17.1.1.1004\service_update.exe --run-as-launcher
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-4125973568-1523799668-3568329379-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows Defender\MP Scheduled Scan - c:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate_scheduled - %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Николай\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default

prefs.js - "browser.search.useDBForOrder" -  false
prefs.js - "browser.startup.homepage" -  "about:home"
prefs.js - "keyword.URL" -  "http://go.mail.ru/distib/ep/?product_id=%7BA27DCFB1-0941-4134-890E-BC9657951077%7D&gp=811014"

"light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\FFExt\light_plugin_firefox\addon.xpi


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.5.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.5.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll


C:\Users\Николай\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Доступ к Рутрекеру - extension - public.proartex@gmail.com

C:\Users\Николай\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\ÐÐ¸ÐºÐ¾Ð»Ð°Ð¹\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Global Stat - extension - {98538934-3027-1265-953f-95936ac8736f} - C:\Users\ÐÐ¸ÐºÐ¾Ð»Ð°Ð¹\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\{98538934-3027-1265-953f-95936ac8736f}.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Youtube AdBlock - extension - {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} - C:\Program Files\Mozilla Firefox\browser\features\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Доступ к Рутрекеру - extension - public.proartex@gmail.com - C:\Users\ÐÐ¸ÐºÐ¾Ð»Ð°Ð¹\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\public.proartex@gmail.com.xpi
Kaspersky Protection - extension - light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com - C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\FFExt\light_plugin_firefox\addon.xpi
Diagnostics - extension - diagnostics@mozilla.org - C:\Users\ÐÐ¸ÐºÐ¾Ð»Ð°Ð¹\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\features\{539cac27-a73d-436f-a05b-c92f4f6360c7}\diagnostics@mozilla.org.xpi
Send HSTS Priming Requests - extension - hsts-priming@mozilla.org - C:\Users\ÐÐ¸ÐºÐ¾Ð»Ð°Ð¹\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\features\{539cac27-a73d-436f-a05b-c92f4f6360c7}\hsts-priming@mozilla.org.xpi
SHA-1 deprecation staged rollout - extension - disableSHA1rollout@mozilla.org - C:\Users\ÐÐ¸ÐºÐ¾Ð»Ð°Ð¹\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\features\{539cac27-a73d-436f-a05b-c92f4f6360c7}\disableSHA1rollout@mozilla.org.xpi

C:\Users\Николай\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\pluginreg.dat
Plugin - Google Update - 1.3.32.7 - C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll
Plugin - Silverlight Plug-In - 5.1.41212.0 - C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
Plugin - Java(TM) Platform SE 8 U5 - 11.5.2.13 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll
Plugin - Java Deployment Toolkit 8.0.50.13 - 11.5.2.13 - C:\Program Files\Java\jre8\bin\dtplugin\npdeployJava1.dll
Plugin - Unity Player - 5.3.5.3775 - C:\Users\Николай\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
Plugin - Shockwave Flash - 13.0.0.214 - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll

=========Google Chrome=========

C:\Users\Николай\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Google Презентации 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Интернет-магазин Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Документы Google 3.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Диск Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0  
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Google Search 0.0.0.60
Extension dhdgffkkebhmkfjojejmpbldmpobfkfo 0 Tampermonkey 4.2.7
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension fampnmnfdebhlnecpiojjbejnnnjifch 1 Блокировщик рекламы в социальных сетях 362.0.0.105
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Google Таблицы 1.1
Extension fhoibnponjcgjgcnfacekaijdbbplhib 2 Kaspersky Protection 5.0.141.4
Extension gcbommkclmclpchllfjekcdonpmejbdp 0 HTTPS Everywhere 2016.12.19
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Документы офлайн 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension lpeeaghdjmhlakojjcgfdhgcejdaefmi 2 Kaspersky Protection 4.6.1.170
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Платежная система Интернет-магазина Chrome 1.0.0.1
Extension obciceimmggglbmelaidpjlmodcebijb 0 Продвинутая история 3.9.15
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5516.1005.0.3
Homepage: 
default_search_provider.search_url: 
C:\Users\Николай\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage: 
default_search_provider.search_url: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib]
"Path"=https://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib


======Снимок реестра======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2E38825B-8815-42CF-9126-C58BC28D4591}]
Kaspersky Protection - C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll [2017-01-31 1028968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre8\bin\ssv.dll [2015-10-31 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre8\bin\jp2ssv.dll [2015-10-31 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{093F479D-712E-46CD-9E06-62E734A05F68} - Kaspersky Protection Toolbar - C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll [2017-01-31 1028968]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoSimpleNetIDList"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======Ассоциации файлов======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======Список файлов и папок, созданных за последние 3 месяца======

2017-02-22 18:17:03 ----A---- C:\Windows\system32\drivers\utmxndmy.sys
2017-02-22 17:52:21 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2017-02-22 17:52:20 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-02-22 17:52:20 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-02-22 17:40:08 ----A---- C:\Windows\system32\drivers\mbae.sys
2017-02-22 17:39:55 ----D---- C:\ProgramData\Malwarebytes
2017-02-15 22:52:48 ----D---- C:\ProgramData\Yandex
2017-02-07 22:15:34 ----A---- C:\Windows\ntbtlog.txt
2017-02-07 20:59:45 ----D---- C:\Program Files\CCleaner
2017-02-03 21:13:10 ----A---- C:\Windows\system32\FNTCACHE.DAT
2017-01-31 22:56:38 ----D---- C:\Windows\ELAMBKUP
2017-01-31 22:55:56 ----A---- C:\Windows\system32\drivers\klif.sys
2017-01-31 22:55:56 ----A---- C:\Windows\system32\drivers\klflt.sys
2017-01-31 22:16:36 ----D---- C:\Program Files\Wise
2017-01-31 22:07:48 ----A---- C:\Windows\WiseHDInfo32.dll
2017-01-31 22:04:51 ----D---- C:\Users\Николай\AppData\Roaming\Wise Care 365
2017-01-31 22:04:50 ----A---- C:\Windows\WiseRegNotify.sys
2017-01-29 19:26:34 ----D---- C:\KVRT_Data
2017-01-29 18:06:12 ----AH---- C:\Windows\system32\mlfcache.dat
2017-01-29 17:47:15 ----D---- C:\Users\Николай\AppData\Roaming\Apple Computer
2017-01-29 17:42:52 ----D---- C:\ProgramData\Apple
2017-01-29 17:42:52 ----D---- C:\Program Files\Apple Software Update
2017-01-22 17:36:32 ----D---- C:\sounds
2017-01-22 17:36:29 ----D---- C:\skin_cache
2017-01-22 17:36:27 ----D---- C:\skin
2017-01-22 17:36:26 ----D---- C:\translation
2017-01-22 17:36:25 ----D---- C:\smiles
2017-01-22 15:39:12 ----D---- C:\Users\Николай\AppData\Roaming\Mra
2017-01-15 20:53:25 ----D---- C:\Windows\rescache
2017-01-11 12:59:04 ----A---- C:\Windows\system32\wdigest.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\TSpkg.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\sspisrv.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\sspicli.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\secur32.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\schannel.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\rpcrt4.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\rpchttp.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\ncrypt.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\msv1_0.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\lsass.exe
2017-01-11 12:59:04 ----A---- C:\Windows\system32\lsasrv.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\kerberos.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-01-11 12:59:04 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-01-11 12:59:04 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-01-11 12:59:04 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-01-11 12:59:04 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-01-11 12:59:04 ----A---- C:\Windows\system32\cryptbase.dll
2017-01-11 12:59:04 ----A---- C:\Windows\system32\bcrypt.dll
2017-01-11 12:59:03 ----A---- C:\Windows\system32\msobjs.dll
2017-01-11 12:59:03 ----A---- C:\Windows\system32\msaudite.dll
2017-01-11 12:59:03 ----A---- C:\Windows\system32\credssp.dll
2017-01-11 12:59:03 ----A---- C:\Windows\system32\auditpol.exe
2017-01-11 12:59:03 ----A---- C:\Windows\system32\adtschema.dll
2017-01-10 12:50:00 ----D---- C:\Program Files\Mozilla Firefox
2017-01-09 21:31:35 ----D---- C:\ProgramData\Чистилка
2017-01-09 20:42:52 ----D---- C:\AdwCleaner
2017-01-08 18:22:38 ----D---- C:\Program Files\Windows Journal
2017-01-06 19:00:55 ----D---- C:\Users\Николай\AppData\Roaming\MediaPlayerApplication
2016-12-15 12:47:17 ----A---- C:\Windows\system32\vbscript.dll
2016-12-15 12:47:17 ----A---- C:\Windows\system32\jsproxy.dll
2016-12-15 12:47:17 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-12-15 12:47:17 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-12-15 12:47:17 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-12-15 12:47:16 ----A---- C:\Windows\system32\wininet.dll
2016-12-15 12:47:16 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-12-15 12:47:16 ----A---- C:\Windows\system32\jscript9diag.dll
2016-12-15 12:47:16 ----A---- C:\Windows\system32\jscript.dll
2016-12-15 12:47:16 ----A---- C:\Windows\system32\ieUnatt.exe
2016-12-15 12:47:16 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-12-15 12:47:16 ----A---- C:\Windows\system32\dxtmsft.dll
2016-12-15 12:47:15 ----A---- C:\Windows\system32\ieui.dll
2016-12-15 12:47:15 ----A---- C:\Windows\system32\dxtrans.dll
2016-12-15 12:47:14 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-12-15 12:47:14 ----A---- C:\Windows\system32\mshtmled.dll
2016-12-15 12:47:13 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-12-15 12:47:13 ----A---- C:\Windows\system32\iertutil.dll
2016-12-15 12:47:12 ----A---- C:\Windows\system32\mshtml.dll
2016-12-15 12:47:12 ----A---- C:\Windows\system32\jscript9.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\urlmon.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\occache.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\inseng.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\iernonce.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\iedkcs32.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\ieapfltr.dll
2016-12-15 12:47:11 ----A---- C:\Windows\system32\ie4uinit.exe
2016-12-15 12:47:10 ----A---- C:\Windows\system32\webcheck.dll
2016-12-15 12:47:10 ----A---- C:\Windows\system32\msfeeds.dll
2016-12-15 12:47:09 ----A---- C:\Windows\system32\msrating.dll
2016-12-15 12:47:09 ----A---- C:\Windows\system32\iesetup.dll
2016-12-15 12:47:09 ----A---- C:\Windows\system32\ieframe.dll
2016-12-15 12:47:08 ----A---- C:\Windows\system32\win32k.sys
2016-12-15 12:47:08 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-12-15 12:47:08 ----A---- C:\Windows\system32\ntkrnlpa.exe
2016-12-15 12:47:07 ----A---- C:\Windows\system32\winload.exe
2016-12-15 12:47:07 ----A---- C:\Windows\system32\win32spl.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\UIAnimation.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\oleaut32.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\ntdll.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\msctf.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\input.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\inetcomm.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\IMJP10K.DLL
2016-12-15 12:47:07 ----A---- C:\Windows\system32\crypt32.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\atmfd.dll
2016-12-15 12:47:07 ----A---- C:\Windows\system32\advapi32.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\UtcResources.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\srcore.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\smss.exe
2016-12-15 12:47:06 ----A---- C:\Windows\system32\rstrui.exe
2016-12-15 12:47:06 ----A---- C:\Windows\system32\olepro32.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\msi.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\drivers\cng.sys
2016-12-15 12:47:06 ----A---- C:\Windows\system32\drivers\bowser.sys
2016-12-15 12:47:06 ----A---- C:\Windows\system32\drivers\appid.sys
2016-12-15 12:47:06 ----A---- C:\Windows\system32\csrsrv.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\clfs.sys
2016-12-15 12:47:06 ----A---- C:\Windows\system32\bcdedit.exe
2016-12-15 12:47:06 ----A---- C:\Windows\system32\appidsvc.dll
2016-12-15 12:47:06 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-12-15 12:47:06 ----A---- C:\Windows\system32\appidapi.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\wintrust.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\usp10.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\user32.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\srclient.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\nlsbres.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\lpk.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\INETRES.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\hlink.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\gdi32.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\fontsub.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\dciman32.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\consent.exe
2016-12-15 12:47:05 ----A---- C:\Windows\system32\atmlib.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\asycfilt.dll
2016-12-15 12:47:05 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-12-15 12:47:05 ----A---- C:\Windows\system32\apisetschema.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\tzres.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\msimsg.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\msihnd.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\msiexec.exe
2016-12-15 12:47:04 ----A---- C:\Windows\system32\cryptsvc.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\cryptnet.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\authui.dll
2016-12-15 12:47:04 ----A---- C:\Windows\system32\appinfo.dll
2016-12-15 12:47:02 ----A---- C:\Windows\system32\diagtrack.dll
2016-12-01 22:05:16 ----A---- C:\Windows\system32\АААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААААА.doc.lnk

======Список файлов и папок, измененных за последние 3 месяца======

2017-02-22 18:24:59 ----D---- C:\Windows\Temp
2017-02-22 18:24:07 ----D---- C:\Windows\system32\config
2017-02-22 18:23:11 ----D---- C:\ProgramData\Kaspersky Lab
2017-02-22 18:21:01 ----SHD---- C:\System Volume Information
2017-02-22 18:17:03 ----D---- C:\Windows\system32\drivers
2017-02-22 17:39:55 ----HD---- C:\ProgramData
2017-02-22 16:41:58 ----SHD---- C:\Windows\Installer
2017-02-22 16:41:54 ----D---- C:\Windows\Microsoft.NET
2017-02-22 16:40:41 ----D---- C:\Windows\System32
2017-02-22 16:40:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-02-22 16:40:36 ----D---- C:\Windows\inf
2017-02-22 12:49:08 ----RSD---- C:\Windows\Fonts
2017-02-22 08:57:18 ----D---- C:\Windows\system32\Macromed
2017-02-20 23:10:36 ----D---- C:\Users\Николай\AppData\Roaming\uTorrent
2017-02-20 22:52:19 ----A---- C:\Windows\winamp.ini
2017-02-14 17:09:03 ----SD---- C:\ProgramData\Microsoft
2017-02-14 15:12:36 ----SHD---- C:\$Recycle.Bin
2017-02-08 09:48:46 ----A---- C:\Windows\WORDPAD.INI
2017-02-07 22:15:34 ----D---- C:\Windows
2017-02-07 20:59:49 ----D---- C:\Windows\system32\Tasks
2017-02-07 20:59:45 ----RD---- C:\Program Files
2017-02-03 21:13:15 ----D---- C:\Windows\debug
2017-02-03 21:07:23 ----D---- C:\Windows\system32\catroot2
2017-02-03 20:56:35 ----D---- C:\Windows\SoftwareDistribution
2017-02-03 20:55:51 ----D---- C:\Windows\Panther
2017-02-03 20:55:51 ----D---- C:\Windows\Downloaded Program Files
2017-02-03 17:46:01 ----A---- C:\Windows\EurekaLog.ini
2017-02-03 14:02:39 ----D---- C:\Windows\Prefetch
2017-02-01 21:37:16 ----D---- C:\Windows\Tasks
2017-02-01 08:34:28 ----D---- C:\Windows\system32\catroot
2017-01-31 23:03:07 ----D---- C:\Windows\system32\DriverStore
2017-01-31 22:59:42 ----D---- C:\Program Files\Common Files\AV
2017-01-31 22:57:58 ----D---- C:\Program Files\Kaspersky Lab
2017-01-29 08:38:01 ----D---- C:\Program Files\Mozilla Maintenance Service
2017-01-27 00:13:13 ----D---- C:\Windows\system32\drivers\UMDF
2017-01-13 14:44:13 ----D---- C:\Windows\winsxs
2017-01-13 14:42:18 ----D---- C:\Windows\system32\ru-RU
2017-01-13 14:42:18 ----D---- C:\Windows\system32\en-US
2017-01-13 14:20:01 ----D---- C:\Windows\system32\MRT
2017-01-13 14:17:43 ----AC---- C:\Windows\system32\MRT.exe
2017-01-08 18:24:41 ----HD---- C:\W7P_Backups
2017-01-08 18:24:35 ----D---- C:\Windows\system32\Wat
2017-01-08 18:24:04 ----D---- C:\Windows\system32\oobe
2017-01-08 18:24:02 ----D---- C:\Windows\system32\migwiz
2017-01-08 18:23:16 ----D---- C:\Windows\ru-RU
2017-01-08 18:22:39 ----D---- C:\Program Files\Windows Sidebar
2017-01-08 18:21:31 ----SD---- C:\Users\Николай\AppData\Roaming\Microsoft
2017-01-08 18:21:27 ----D---- C:\Users\Николай\AppData\Roaming\Yandex
2017-01-07 20:43:57 ----D---- C:\Program Files\Google
2017-01-06 22:16:36 ----D---- C:\Program Files\Internet Explorer
2017-01-06 19:03:45 ----HD---- C:\Windows\system32\GroupPolicy
2016-12-15 13:28:23 ----RSD---- C:\Windows\assembly
2016-12-15 13:19:34 ----D---- C:\Windows\system32\migration
2016-12-15 13:19:33 ----D---- C:\Windows\system32\Boot

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)======

R0 cm_km;AO Kaspersky Lab Cryptographic Module x86 (56 bit); C:\Windows\system32\DRIVERS\cm_km.sys [2016-06-10 170840]
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2016-06-02 165296]
R0 klbackupdisk;Kaspersky Lab klbackupdisk; C:\Windows\system32\DRIVERS\klbackupdisk.sys [2016-06-07 57264]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 173440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 388096]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\Windows\system32\DRIVERS\klbackupflt.sys [2016-06-15 71504]
R1 klhk;Kaspersky Lab service driver; C:\Windows\system32\DRIVERS\klhk.sys [2017-01-31 120664]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2017-01-31 804128]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2017-01-31 49744]
R1 klpd;Kaspersky Lab format recognizer driver; C:\Windows\system32\DRIVERS\klpd.sys [2016-05-31 41392]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2016-05-17 71088]
R1 Klwtp;KLwtp - WFP callout traffic inspector; C:\Windows\system32\DRIVERS\klwtp.sys [2017-01-31 115936]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2016-06-14 161712]
R2 kldisk;kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [2016-05-31 69000]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 klflt;Kaspersky Lab Kernel DLL; C:\Windows\system32\DRIVERS\klflt.sys [2016-06-26 149840]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2016-05-19 46000]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2015-06-07 38072]
R3 kltap;Kaspersky Security Data Escort Adapter; C:\Windows\system32\DRIVERS\kltap.sys [2016-06-07 48056]
R3 ltmodem5;Agere Modem Driver; C:\Windows\system32\DRIVERS\ltmdmnt.sys [2009-07-14 503296]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 RTL8167;Драйвер Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 utmxndmy;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\utmxndmy.sys [2017-02-22 7168]
S1 qutmipc;qutmipc; \??\C:\Windows\system32\drivers\qutmipc.sys [2016-04-18 53960]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files\Bluestacks\HD-Hypervisor-x86.sys [2016-10-21 139360]
S3 BstkDrv;BlueStacks Plus Hypervisor; \??\C:\Program Files\Bluestacks\BstkDrv.sys [2016-10-07 220216]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-06-11 14848]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2014-06-11 24064]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2014-06-11 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-06-11 26880]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 35968]
S3 WiseHDInfo;WiseHDInfo; \??\C:\Windows\WiseHDInfo32.dll [2017-01-31 13264]
S3 WiseRegNotify;WiseRegNotify; \??\C:\Windows\WiseRegNotify.sys [2017-01-31 23984]

======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)======

R2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe [2016-06-28 241544]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [2016-06-28 241544]
R2 YandexBrowserService;Yandex.Browser Update Service; C:\Program Files\Yandex\YandexBrowser\17.1.1.1004\service_update.exe [2017-02-04 625656]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-31 257712]
S3 AppMgmt;@appmgmts.dll,-3250; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll"=%SystemRoot%\System32\appmgmts.dll
S3 gupdate;Служба Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-01-07 153752]
S3 gupdatem;Служба Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2017-01-07 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-11-12 102912]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; %SystemRoot%\System32\svchost.exe -k PeerDist;"ServiceDll"=%SystemRoot%\system32\peerdistsvc.dll
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\umrdp.dll
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-06-11 1343400]
S3 WiseBootAssistant;Wise Boot Assistant; E:\софт\Wise Care 365\BootTime.exe [2016-10-13 646904]
S4 aspnet_state;Служба состояний ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-11-05 45744]
S4 BstHdAndroidSvc;BlueStacks Android Service ; C:\Program Files\Bluestacks\HD-Service.exe [2016-10-21 445976]
S4 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files\Bluestacks\HD-LogRotatorService.exe [2016-10-21 425496]
S4 BstHdPlusAndroidSvc;BlueStacks Plus Android Service ; C:\Program Files\Bluestacks\HD-Plus-Service.exe [2016-10-21 466456]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\cscsvc.dll
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-01-29 172488]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]

-----------------EOF-----------------
