Плэз помогите почистить хром от рекламы! Захожу на сайт любой открывается эта хрень (hxxp://traffic-media.co/mghtml/framehtml/c/1/t/603159.html) или другие сайти ненужные!
данные с файла FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2017
Ran by Vasya (administrator) on LENOVOG500 (07-09-2017 01:23:32)
Running from C:\Users\Vasya\Desktop
Loaded Profiles: Vasya (Available Profiles: Vasya)
Platform: Windows 7 Ultimate (X64) Language: Русский (Россия)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\47.0.2631.80\opera.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [899680 2013-02-04] (Conexant Systems, Inc.)
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2013-03-05] (Conexant Systems, Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-02-04] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-08-31] (Dolby Laboratories Inc.)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291280 2012-12-21] (Intel Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1712080336-141016392-1547431035-1000\…\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [5077792 2017-05-16] (Nota Inc.)
HKU\S-1-5-21-1712080336-141016392-1547431035-1000\…\Run: [Gaijin.Net Agent] => C:\Users\Vasya\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2010056 2017-06-29] (Gaijin Entertainment)
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{42B32396-3201-44A4-887A-BA8FEC83D156}: [NameServer] 52.56.51.39,178.132.6.57,46.101.28.31,82.202.226.203,193.238.153.54
Tcpip\..\Interfaces\{8DFAD62A-B2AD-40F7-A443-49165112AD9A}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{FE5FC7B3-2FF7-442F-AB42-933084A503E8}: [NameServer] 52.56.51.39,178.132.6.57,46.101.28.31,82.202.226.203,193.238.153.54,192.168.1.1
Tcpip\..\Interfaces\{FE5FC7B3-2FF7-442F-AB42-933084A503E8}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131365156690630830&GUID=5140E61B-CC20-437C-80EA-D5A84258EC6A
HKU\S-1-5-21-1712080336-141016392-1547431035-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://viktor.ucoz.com/forum
SearchScopes: HKU\S-1-5-21-1712080336-141016392-1547431035-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-1712080336-141016392-1547431035-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-06-27] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-06-27] (Oracle Corporation)
Filter: deflate — {8f6b0360-b80d-11d0-a9b3-006097942311} — C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate — {8f6b0360-b80d-11d0-a9b3-006097942311} — C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip — {8f6b0360-b80d-11d0-a9b3-006097942311} — C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip — {8f6b0360-b80d-11d0-a9b3-006097942311} — C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 1z7uj0hj.default
FF ProfilePath: C:\Users\Vasya\AppData\Roaming\Mozilla\Firefox\Profiles\1z7uj0hj.default [2017-09-06]FF Homepage: Mozilla\Firefox\Profiles\1z7uj0hj.default -> user_pref(«browser.startup.homepage», «hxxps://www.malwarebytes.org/restorebrowser/
FF Extension: (VK Music Downloader) — C:\Users\Vasya\AppData\Roaming\Mozilla\Firefox\Profiles\1z7uj0hj.default\Extensions\@vkmad.xpi [2017-05-06]FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-06-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-06-27] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [No File]FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Vasya\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2014-11-28] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-1712080336-141016392-1547431035-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Vasya\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll [2009-08-23] (Foxit Software Company)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll [2009-07-31] (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\firefox-branding.js [2009-07-31]FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\firefox-l10n.js [2009-07-31]FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\firefox.js [2009-07-31]FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\reporter.js [2009-07-31]
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default [2017-09-07]CHR Extension: (Google Презентации) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-05]CHR Extension: (Документы Google) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-05]CHR Extension: (Диск Google) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-05]CHR Extension: (YouTube) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-05]CHR Extension: (Новости) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbcakcafkeacjljckffjnmliiikgoag [2017-09-06]CHR Extension: (Google Таблицы) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-05]CHR Extension: (Google Документы офлайн) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-05]CHR Extension: (Открытые вкладки — Chrome) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcankddlhambomjmegjefebfafkbddhl [2017-02-14]CHR Extension: (Платежная система Интернет-магазина Chrome) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]CHR Extension: (Gmail) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-05]CHR Extension: (Chrome Media Router) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-30]CHR Profile: C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-09-06]CHR Extension: (No Name) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Guest Profile\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe [2017-09-06]CHR Profile: C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-09-07]CHR Extension: (Google Презентации) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-04-15]CHR Extension: (Документы Google) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-15]CHR Extension: (Диск Google) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-15]CHR Extension: (YouTube) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-15]CHR Extension: (Блокировщик Рекламы Для Ютуба™) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cmhomipkklckpomafalojobppmmidlgl [2017-09-07]CHR Extension: (Google Таблицы) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-15]CHR Extension: (Google Документы офлайн) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-15]CHR Extension: (Unlimited Free VPN — Hola) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2017-07-13]CHR Extension: (Платежная система Интернет-магазина Chrome) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]CHR Extension: (AdBlocker Ultimate) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ohahllgiabjaoigichmmfljhkcfikeof [2017-09-06]CHR Extension: (Gmail) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-15]CHR Extension: (Chrome Media Router) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-10]CHR Profile: C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\System Profile [2017-09-06]CHR Extension: (No Name) — C:\Users\Vasya\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\ahggfmgiidlaceichjfemgbaggnbaloe [2017-09-06]
Opera:
=======
OPR StartupUrls: «hxxp://www.google.com/»
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-10-31] (BlackBerry Limited)
S3 defragsvc; C:\Windows\System32\defragsvc.dll [291328 2009-07-14] (Корпорация Майкрософт)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2009-08-23] (Microsoft Corporation) [File not signed]R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [12288 2009-07-14] (Корпорация Майкрософт)
S3 WPCSvc; C:\Windows\SysWOW64\wpcsvc.dll [10752 2009-07-14] (Корпорация Майкрософт)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Ak27x64; C:\Windows\System32\DRIVERS\Ak27x64.sys [4057808 2013-09-04] (Qualcomm Atheros, Inc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [36520 2012-09-14] (Advanced Micro Devices, Inc.)
R3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [601608 2017-01-19] (Qualcomm)
R3 ETDSMBus; C:\Windows\System32\DRIVERS\ETDSMBus.sys [32344 2016-06-08] (ELAN Microelectronic Corp.)
R0 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [94784 2009-07-14] (Корпорация Майкрософт)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2014-05-06] (BlackBerry Limited)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [418784 2016-09-01] (Realsil Semiconductor Corporation)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2016-03-28] (Apple, Inc.) [File not signed]R0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [363584 2009-07-14] (Корпорация Майкрософт)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-07 01:23 — 2017-09-07 01:24 — 000017035 _____ C:\Users\Vasya\Desktop\FRST.txt
2017-09-07 01:23 — 2017-09-07 01:23 — 000000000 ____D C:\FRST
2017-09-07 01:22 — 2017-09-07 01:23 — 002395648 _____ (Farbar) C:\Users\Vasya\Desktop\FRST64.exe
2017-09-07 01:17 — 2017-09-07 01:17 — 000006416 _____ C:\Users\Vasya\Documents\AdwCleaner[C0].txt
2017-09-07 01:11 — 2017-09-07 01:14 — 000000000 ____D C:\AdwCleaner
2017-09-07 01:11 — 2017-09-07 01:11 — 004110280 _____ C:\Users\Vasya\Downloads\adwcleaner 6.047 .exe
2017-09-07 01:05 — 2017-09-07 01:05 — 000000425 _____ C:\Users\Vasya\Desktop\adwcleaner_6_047_4b9-75b.torrent
2017-09-06 23:49 — 2017-09-06 23:49 — 000000258 __RSH C:\Users\Все пользователи\ntuser.pol
2017-09-06 23:49 — 2017-09-06 23:49 — 000000258 __RSH C:\ProgramData\ntuser.pol
2017-09-06 23:22 — 2017-09-06 23:22 — 000000000 ____D C:\Users\Все пользователи\Malwarebytes
2017-09-06 23:22 — 2017-09-06 23:22 — 000000000 ____D C:\ProgramData\Malwarebytes
2017-09-06 22:32 — 2017-09-06 22:32 — 000000000 ____D C:\Users\Vasya\AppData\Local\Notepad++
2017-09-06 22:32 — 2017-09-06 22:32 — 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2017-09-06 22:18 — 2017-09-06 22:18 — 000005070 _____ C:\Users\Vasya\Documents\startu1p.txt
2017-09-06 21:14 — 2017-09-06 21:14 — 001165931 _____ C:\Users\Vasya\Downloads\FixerBro.zip
2017-09-06 15:45 — 2017-09-06 15:48 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\Tortoise SVN
2017-09-06 15:40 — 2017-09-06 23:49 — 000000000 ____D C:\Program Files (x86)\thzXuJvjUitxjehyvqs
2017-09-06 15:36 — 2017-09-06 15:36 — 000790517 _____ C:\Users\Vasya\Downloads\skachat-proshivku-na-lg-l60-x135_79f-2b0.zip
2017-09-06 14:52 — 2017-09-06 14:14 — 471459669 _____ C:\Users\Vasya\Documents\LG L60 Off v10b with FlshTool.rar.zip
2017-09-06 14:31 — 2017-09-06 14:45 — 000000000 ____D C:\Users\Все пользователи\SP_FT_Logs
2017-09-06 14:31 — 2017-09-06 14:45 — 000000000 ____D C:\ProgramData\SP_FT_Logs
2017-09-06 14:02 — 2017-09-06 14:14 — 471459669 _____ C:\Users\Vasya\Downloads\LG L60 Off v10b with FlshTool.rar.zip
2017-09-05 12:37 — 2017-09-05 12:38 — 051005826 _____ C:\Users\Vasya\Downloads\1489530364_sp_flash_tool-rulsmart.zip
2017-09-03 12:55 — 2017-09-03 12:55 — 000313366 _____ C:\Users\Vasya\Downloads\WindowsUpdate.diagcab
2017-09-03 12:13 — 2017-09-03 13:10 — 000000000 ____D C:\51a302d76c598bf29d57
2017-09-03 12:13 — 2017-09-03 12:13 — 000000000 ____D C:\Windows\system32\EventProviders
2017-09-03 11:59 — 2017-01-19 12:32 — 000601608 _____ (Qualcomm) C:\Windows\system32\Drivers\btfilter.sys
2017-09-03 11:54 — 2017-09-03 11:54 — 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf
2017-09-03 11:54 — 2012-12-04 21:20 — 000041984 _____ (Intel Corporation) C:\Windows\system32\Drivers\USB3Ver.dll
2017-09-03 11:53 — 2012-12-04 21:21 — 000791608 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys
2017-09-03 11:53 — 2012-12-04 21:21 — 000358456 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys
2017-09-03 11:53 — 2012-12-04 21:21 — 000020024 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys
2017-09-03 11:53 — 2009-07-15 05:21 — 001721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2017-09-03 11:52 — 2017-09-03 11:52 — 005009128 _____ (Lenovo Group Limited ) C:\Users\Vasya\Downloads\usb110w7.exe
2017-09-03 11:37 — 2017-09-03 12:12 — 947070088 _____ (Microsoft Corporation) C:\Users\Vasya\Downloads\windows6.1-KB976932-X64.exe
2017-09-03 09:58 — 2017-09-03 09:58 — 003328910 _____ C:\Users\Vasya\Downloads\Windows6.1-KB3102810-x64.msu
2017-08-27 05:30 — 2017-08-27 05:30 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\Twitch
2017-08-27 05:29 — 2017-08-27 05:29 — 000000758 _____ C:\Users\Vasya\Desktop\Twitch.lnk
2017-08-27 05:29 — 2017-08-27 05:29 — 000000758 _____ C:\Users\Vasya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk
2017-08-27 05:22 — 2017-08-27 05:27 — 124418192 _____ C:\Users\Vasya\Downloads\TwitchSetup_[usher-85232220].exe
2017-08-24 03:49 — 2017-08-24 03:50 — 004956875 _____ C:\Users\Vasya\Downloads\3glVh86.zip
2017-08-20 21:10 — 2017-08-20 21:10 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2017-08-09 00:52 — 2017-08-09 00:52 — 000000000 ____D C:\Program Files\DIFX
2017-08-09 00:50 — 2017-08-09 00:50 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\DRPNano
2017-08-09 00:46 — 2015-06-04 22:21 — 005906536 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000513640 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000444008 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000401512 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000280680 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000256616 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000187496 _____ (Intel Corporation) C:\Windows\system32\difx64.exe
2017-08-09 00:46 — 2015-06-04 22:21 — 000173672 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe
2017-08-09 00:46 — 2015-06-04 22:20 — 000116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4229.dll
2017-08-09 00:46 — 2015-05-26 21:02 — 005375448 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
2017-08-09 00:46 — 2015-05-26 21:00 — 012937864 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 011245520 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 011117808 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 001049576 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000940360 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000530968 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000525800 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000220432 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000184352 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000031984 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
2017-08-09 00:46 — 2015-05-26 21:00 — 000017082 _____ C:\Windows\system32\iglhxs64.vp
2017-08-09 00:46 — 2015-05-26 20:53 — 000101376 _____ C:\Windows\system32\igdde64.dll
2017-08-09 00:46 — 2015-05-26 20:53 — 000081408 _____ C:\Windows\SysWOW64\igdde32.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 010811392 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000410112 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc
2017-08-09 00:46 — 2015-05-26 20:52 — 000223664 _____ C:\Windows\system32\Gfxres.th-TH.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000210106 _____ C:\Windows\system32\Gfxres.el-GR.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000194245 _____ C:\Windows\system32\Gfxres.ru-RU.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000166170 _____ C:\Windows\system32\Gfxres.ar-SA.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000163421 _____ C:\Windows\system32\Gfxres.ja-JP.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000159008 _____ C:\Windows\system32\Gfxres.he-IL.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000149682 _____ C:\Windows\system32\Gfxres.it-IT.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000148042 _____ C:\Windows\system32\Gfxres.ko-KR.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000147393 _____ C:\Windows\system32\Gfxres.de-DE.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000147288 _____ C:\Windows\system32\Gfxres.es-ES.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000146004 _____ C:\Windows\system32\Gfxres.ro-RO.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000145491 _____ C:\Windows\system32\Gfxres.fr-FR.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000144645 _____ C:\Windows\system32\Gfxres.tr-TR.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000144260 _____ C:\Windows\system32\Gfxres.pt-BR.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000144020 _____ C:\Windows\system32\Gfxres.nl-NL.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000143932 _____ C:\Windows\system32\Gfxres.hu-HU.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000142882 _____ C:\Windows\system32\Gfxres.sv-SE.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000142877 _____ C:\Windows\system32\Gfxres.pt-PT.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000142717 _____ C:\Windows\system32\Gfxres.pl-PL.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000142289 _____ C:\Windows\system32\Gfxres.cs-CZ.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000142008 _____ C:\Windows\system32\Gfxres.fi-FI.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000141838 _____ C:\Windows\system32\Gfxres.sk-SK.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000141049 _____ C:\Windows\system32\Gfxres.hr-HR.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000137889 _____ C:\Windows\system32\Gfxres.sl-SI.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000137784 _____ C:\Windows\system32\Gfxres.nb-NO.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000137141 _____ C:\Windows\system32\Gfxres.da-DK.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000132623 _____ C:\Windows\system32\Gfxres.en-US.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl
2017-08-09 00:46 — 2015-05-26 20:52 — 000126300 _____ C:\Windows\system32\Gfxres.zh-TW.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000124650 _____ C:\Windows\system32\Gfxres.zh-CN.resources
2017-08-09 00:46 — 2015-05-26 20:52 — 000025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll
2017-08-09 00:46 — 2015-05-26 20:52 — 000000268 _____ C:\Windows\system32\GfxUI.exe.config
2017-08-09 00:46 — 2015-05-26 20:51 — 013028864 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll
2017-08-09 00:46 — 2015-05-26 20:50 — 003511296 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
2017-08-09 00:46 — 2015-05-26 20:50 — 003121152 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
2017-08-09 00:46 — 2015-05-26 20:50 — 000963452 _____ C:\Windows\SysWOW64\igcodeckrng600.bin
2017-08-09 00:46 — 2015-05-26 20:50 — 000963452 _____ C:\Windows\system32\igcodeckrng600.bin
2017-08-09 00:46 — 2015-05-26 20:50 — 000575488 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
2017-08-09 00:46 — 2015-05-26 20:50 — 000542720 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
2017-08-09 00:46 — 2015-05-26 20:50 — 000272928 _____ C:\Windows\SysWOW64\igvpkrng600.bin
2017-08-09 00:46 — 2015-05-26 20:50 — 000272928 _____ C:\Windows\system32\igvpkrng600.bin
2017-08-09 00:43 — 2017-08-09 00:45 — 053230976 _____ (DriverPack) C:\Users\Vasya\Downloads\Intel-FORCED-78×64-HD3000_9.17.10.4229-drp_0.000665.1502228442.1471190573260.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-07 01:23 — 2009-07-14 07:45 — 000014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-07 01:23 — 2009-07-14 07:45 — 000014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-07 01:15 — 2009-07-14 08:08 — 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-07 01:12 — 2017-01-05 21:31 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\uTorrent
2017-09-07 01:03 — 2017-08-02 13:56 — 000007641 _____ C:\Users\Vasya\AppData\Local\Resmon.ResmonCfg
2017-09-07 00:52 — 2017-01-05 21:40 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\AIMP
2017-09-07 00:29 — 2017-01-06 14:44 — 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-09-07 00:29 — 2009-07-14 06:20 — 000000000 ____D C:\Windows\inf
2017-09-06 23:57 — 2009-07-14 18:18 — 000726670 _____ C:\Windows\system32\perfh019.dat
2017-09-06 23:57 — 2009-07-14 18:18 — 000152050 _____ C:\Windows\system32\perfc019.dat
2017-09-06 23:57 — 2009-07-14 08:13 — 001651650 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-06 23:41 — 2017-01-05 21:05 — 000000000 ____D C:\Users\Vasya
2017-09-06 23:30 — 2017-01-06 23:26 — 000000000 ____D C:\Users\Vasya\AppData\LocalLow\Nival Network
2017-09-06 22:32 — 2017-03-19 15:13 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\Notepad++
2017-09-06 22:27 — 2009-08-23 12:04 — 000000000 ____D C:\Program Files (x86)\Opera
2017-09-06 22:15 — 2017-01-10 00:01 — 000000000 ____D C:\Program Files (x86)\Steam
2017-09-05 12:18 — 2017-07-23 10:23 — 000000000 ____D C:\LGX135
2017-09-05 12:16 — 2017-07-23 10:17 — 000000831 _____ C:\Users\Vasya\Desktop\LGMobile Support Tool.lnk
2017-09-05 12:16 — 2017-07-23 10:16 — 000002760 _____ C:\Windows\SysWOW64\lgAxconfig.ini
2017-09-03 15:02 — 2017-02-12 00:19 — 000000000 ____D C:\Users\Vasya\AppData\Local\ElevatedDiagnostics
2017-09-03 13:51 — 2017-07-29 19:05 — 000000000 ____D C:\Users\Vasya\Desktop\тату
2017-09-03 11:54 — 2017-01-06 13:48 — 000000000 ____D C:\Program Files (x86)\Intel
2017-09-03 07:00 — 2009-07-14 08:08 — 000024174 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-08-31 08:06 — 2017-01-05 21:54 — 000002191 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-31 08:06 — 2017-01-05 21:54 — 000002179 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-27 05:29 — 2017-01-26 23:03 — 000000000 ____D C:\Users\Vasya\Desktop\123
2017-08-20 21:10 — 2017-01-06 17:24 — 000002162 _____ C:\Users\Vasya\Desktop\Discord.lnk
2017-08-20 21:10 — 2017-01-06 17:24 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\discord
2017-08-20 21:10 — 2017-01-06 17:23 — 000000000 ____D C:\Users\Vasya\AppData\Local\Discord
2017-08-19 12:18 — 2017-03-26 19:30 — 000000000 ____D C:\Users\Vasya\AppData\Roaming\Skype
2017-08-14 22:32 — 2009-07-14 06:20 — 000000000 ____D C:\Windows\system32\NDF
2017-08-09 03:45 — 2017-01-05 21:50 — 000000000 ____D C:\Program Files\Common Files\AV
2017-08-09 03:45 — 2017-01-05 21:28 — 000000000 ____D C:\Users\Все пользователи\AVAST Software
2017-08-09 03:45 — 2017-01-05 21:28 — 000000000 ____D C:\ProgramData\AVAST Software
2017-08-08 12:52 — 2017-03-21 20:46 — 000004390 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-08-08 12:52 — 2017-01-09 02:21 — 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-08-08 12:52 — 2017-01-09 02:21 — 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-08-08 12:52 — 2017-01-09 02:21 — 000004520 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-08-08 12:52 — 2017-01-09 02:21 — 000000000 ____D C:\Windows\system32\Macromed
2017-08-08 12:52 — 2009-08-23 12:02 — 000000000 ____D C:\Windows\SysWOW64\Macromed
==================== Files in the root of some directories =======
2017-01-29 13:34 — 2017-01-29 15:42 — 000000154 _____ () C:\Users\Vasya\AppData\Roaming\Rim.Desktop.Exception.log
2017-01-29 13:31 — 2017-06-18 19:47 — 000002021 _____ () C:\Users\Vasya\AppData\Roaming\Rim.Desktop.hxxpServerSetup.log
2017-01-29 13:34 — 2017-01-29 15:42 — 000000154 _____ () C:\Users\Vasya\AppData\Roaming\Rim.DesktopHelper.Exception.log
2017-04-03 01:26 — 2017-04-03 01:26 — 000000132 _____ () C:\Users\Vasya\AppData\Roaming\Установки формата Adobe PNG CC
2017-08-02 13:56 — 2017-09-07 01:03 — 000007641 _____ () C:\Users\Vasya\AppData\Local\Resmon.ResmonCfg
2017-01-06 15:15 — 2017-01-06 15:15 — 000000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-08-31 12:20
==================== End of FRST.txt ============================
Для того чтобы убрать рекламу, полностью выполните эту инструкцию http://www.spyware-ru.com/ubrat-reklamu/ . Если проблема останется, то сделайте следующее:
- в браузере в котором появляется реклама, откройте менеджер расширений
- отключите все расширения, абсолютно все
- если реклама пропадет, то включая по одному, найдите то, которое её открывает, после чего просто удалите это вредоносное расширение
- если п.п. 1-3 вам не могут, то обратитесь на наш форум.