Добрый день, прошу помощи. В Хроме переодически выскакивает реклама разных сайтов вроде Вулкана su-news.ru/ и рунеток. Касперский, malwer, Доктор веб, adwcleaner что-то находили, удаляли, но реклама все равно осталась. В планеровщике все чисто. Прилагаю файл hijack и FRST64
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 13:57:50, on 26.12.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
FIREFOX: 50.1.0 (x86 ru)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\avpui.exe
C:\Users\1\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Adguard\Adguard.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Users\1\Downloads\HijackThis.exe
R1 — HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo15.msn.com/?pc=LCTE
R1 — HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yandex.ru/?win=260&clid=2139453-1
R1 — HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 — HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 — HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 — HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 — HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 — HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 — HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 — HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 — REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 — BHO: ScriptInjectionPluginBrowserHelperObject — {2E38825B-8815-42CF-9126-C58BC28D4591} — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll
O2 — BHO: McAfee WebAdvisor BHO — {B164E929-A1B6-4A06-B104-2CD0E90A88FF} — c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 — Toolbar: Kaspersky Protection Toolbar — {093F479D-712E-46CD-9E06-62E734A05F68} — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll
O4 — HKLM\..\Run: [Adobe Creative Cloud] «C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe» —showwindow=false —onOSstartup=true
O4 — HKLM\..\Run: [AvastUI.exe] «C:\Program Files\AVAST Software\Avast\AvastUI.exe» /nogui
O4 — HKCU\..\Run: [OneDrive] «C:\Users\1\AppData\Local\Microsoft\OneDrive\OneDrive.exe» /background
O4 — HKCU\..\Run: [Adguard] C:\Program Files (x86)\Adguard\Adguard.exe /nosplash
O4 — HKCU\..\Run: [Browser Manager] C:\Users\1\AppData\Local\Yandex\BrowserManager\MBLauncher.exe
O4 — HKCU\..\Run: [CCleaner Monitoring] «C:\Program Files\CCleaner\CCleaner64.exe» /MONITOR
O8 — Extra context menu item: E&xport to Microsoft Excel — res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 — Extra context menu item: Se&nd to OneNote — res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 — Extra button: Send to OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 — Extra ‘Tools’ menuitem: Se&nd to OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 — Extra button: McAfee WebAdvisor — {48A61126-9A19-4C50-A214-FF08CB94995C} — c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O9 — Extra ‘Tools’ menuitem: McAfee WebAdvisor — {48A61126-9A19-4C50-A214-FF08CB94995C} — c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O9 — Extra button: OneNote Lin&ked Notes — {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} — C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 — Extra ‘Tools’ menuitem: OneNote Lin&ked Notes — {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} — C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 — Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 — Protocol: mso-minsb-roaming.16 — {83C25742-A9F7-49FB-9138-434302C88D07} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 — Protocol: mso-minsb.16 — {42089D2D-912D-4018-9087-2B87803E93FB} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 — Protocol: osf-roaming.16 — {42089D2D-912D-4018-9087-2B87803E93FB} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 — Protocol: osf.16 — {5504BE45-A83B-4808-900A-3A5C36E7F77A} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 — Protocol: sacore — {5513F07E-936B-4E52-9B00-067394E91CC5} — c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 — Protocol: tbauth — {14654CA6-5711-491D-B89A-58E571679951} — C:\Windows\SysWOW64\tbauth.dll
O18 — Protocol: windows.tbauth — {14654CA6-5711-491D-B89A-58E571679951} — C:\Windows\SysWOW64\tbauth.dll
O18 — Filter: application/x-mfe-ipt — {3EF5086B-5478-4598-A054-786C45D75692} — c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O23 — Service: AdaptiveSleepService — Unknown owner — C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 — Service: Adguard Service — Performix LLC — C:\Program Files (x86)\Adguard\AdguardSvc.exe
O23 — Service: Adobe Acrobat Update Service (AdobeARMservice) — Adobe Systems Incorporated — C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 — Service: AdobeUpdateService — Adobe Systems Incorporated — C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 — Service: Adobe Genuine Software Integrity Service (AGSService) — Adobe Systems, Incorporated — C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 — Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) — Unknown owner — C:\WINDOWS\System32\alg.exe (file missing)
O23 — Service: AMD External Events Utility — Unknown owner — C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 — Service: AtherosSvc — Windows (R) Win 7 DDK provider — C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 — Service: Avast Antivirus (avast! Antivirus) — AVAST Software — C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 — Service: Kaspersky Anti-Virus Service 17.0.0 (AVP17.0.0) — AO Kaspersky Lab — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe
O23 — Service: Служба Bonjour (Bonjour Service) — Apple Inc. — C:\Program Files\Bonjour\mDNSResponder.exe
O23 — Service: CCSDK — Lenovo — C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
O23 — Service: Intel(R) Content Protection HECI Service (cphs) — Intel Corporation — C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 — Service: Intel(R) Content Protection HDCP Service (cplspcon) — Unknown owner — C:\WINDOWS\system32\IntelCpHDCPSvc.exe (file missing)
O23 — Service: Conexant Audio Message Service (CxAudMsg) — Unknown owner — C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 — Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) — Unknown owner — C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 — Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) — Unknown owner — C:\WINDOWS\System32\lsass.exe (file missing)
O23 — Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) — Unknown owner — C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 — Service: GDCAgent — Lenovo — C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
O23 — Service: Globus Privacy (Globus) — Woogable Ltd. — C:\Program Files (x86)\Globus\GlobusService.exe
O23 — Service: Служба Google Update (gupdate) (gupdate) — Google Inc. — C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 — Service: Служба Google Update (gupdatem) (gupdatem) — Google Inc. — C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 — Service: McAfee Home Network (HomeNetSvc) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 — Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) — Intel Corporation — C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 — Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) — Unknown owner — C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 — Service: System Interface Foundation Service (ImControllerService) — Lenovo Group Limited — C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 — Service: @keyiso.dll,-100 (KeyIso) — Unknown owner — C:\WINDOWS\system32\lsass.exe (file missing)
O23 — Service: klvssbrigde64 — AO Kaspersky Lab — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\x64\vssbridge64.exe
O23 — Service: Kaspersky Secure Connection Service 1.0.0 (KSDE1.0.0) — AO Kaspersky Lab — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
O23 — Service: LSCWinService — Lenovo — C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 — Service: Malwarebytes Service (MBAMService) — Malwarebytes — C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 — Service: McAfee SiteAdvisor Service — McAfee, Inc. — C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 — Service: McAfee AP Service (McAPExe) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\VSCore_15_5\McAPExe.exe
O23 — Service: McAfee Boot Delay Start Service (McBootDelayStartSvc) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 — Service: McAfee Security Scan Component Host Service (McComponentHostService) — McAfee, Inc. — C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 — Service: McAfee CSP Service (mccspsvc) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\CSP\2.2.351.0\\McCSPServiceHost.exe
O23 — Service: McAfee Personal Firewall Service (McMPFSvc) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 — Service: McAfee VirusScan Announcer (McNaiAnn) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 — Service: McAfee Scanner (McODS) — McAfee, Inc. — C:\Program Files\mcafee\VirusScan\mcods.exe
O23 — Service: McAfee Platform Services (mcpltsvc) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 — Service: McAfee Proxy Service (McProxy) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 — Service: McAfee Firewall Core Service (mfefire) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 — Service: McAfee Service Controller (mfemms) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe
O23 — Service: McAfee Validation Trust Protection Service (mfevtp) — Unknown owner — C:\Windows\system32\mfevtps.exe (file missing)
O23 — Service: McAfee Module Core Service (ModuleCoreService) — McAfee, Inc. — C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
O23 — Service: Mozilla Maintenance Service (MozillaMaintenance) — Mozilla Foundation — C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 — Service: @comres.dll,-2797 (MSDTC) — Unknown owner — C:\WINDOWS\System32\msdtc.exe (file missing)
O23 — Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) — Unknown owner — C:\WINDOWS\system32\lsass.exe (file missing)
O23 — Service: Intel Security PEF Service (PEFService) — Intel Security, Inc. — C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
O23 — Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) — Unknown owner — C:\WINDOWS\system32\locator.exe (file missing)
O23 — Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) — Unknown owner — C:\WINDOWS\system32\lsass.exe (file missing)
O23 — Service: Conexant SmartAudio service (SAService) — Conexant Systems, Inc. — C:\Windows\system32\SAsrv.exe
O23 — Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) — Unknown owner — C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 — Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) — Unknown owner — C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 — Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) — Unknown owner — C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 — Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) — Unknown owner — C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 — Service: SynTPEnh Caller Service (SynTPEnhService) — Synaptics Incorporated — C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 — Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) — Unknown owner — C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 — Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) — Unknown owner — C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 — Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) — Unknown owner — C:\WINDOWS\system32\lsass.exe (file missing)
O23 — Service: @%SystemRoot%\system32\vds.exe,-100 (vds) — Unknown owner — C:\WINDOWS\System32\vds.exe (file missing)
O23 — Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) — Unknown owner — C:\WINDOWS\system32\vssvc.exe (file missing)
O23 — Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) — Unknown owner — C:\WINDOWS\system32\wbengine.exe (file missing)
O23 — Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) — Unknown owner — C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 — Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) — Unknown owner — C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 — Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) — Unknown owner — C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 — Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) — Unknown owner — C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 — Service: Yandex.Browser Update Service (YandexBrowserService) — YANDEX LLC — C:\Program Files (x86)\Yandex\YandexBrowser\16.11.1.673\service_update.exe
—
End of file — 15356 bytes
FRST64
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-12-2016
Ran by 1 (administrator) on LAPTOP-OQ81C0AF (26-12-2016 14:09:34)
Running from C:\Users\1\Downloads
Loaded Profiles: 1 (Available Profiles: 1)
Platform: Windows 10 Home Single Language Version 1607 (X64) Language: Русский (Россия)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Woogable Ltd.) C:\Program Files (x86)\Globus\GlobusService.exe
(YANDEX LLC) C:\Program Files (x86)\Yandex\YandexBrowser\16.11.1.673\service_update.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_5\mcapexe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\avpui.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.2.351.0\McCSPServiceHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
() C:\Program Files\Lenovo\LenovoUtility\utility.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Performix LLC) C:\Program Files (x86)\Adguard\Adguard.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Yandex LLC) C:\Users\1\AppData\Local\Yandex\BrowserManager\BrowserManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Lenovo) C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Lenovo) C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Lenovo) C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11610.1001.23.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Performix LLC) C:\Program Files (x86)\Adguard\AdguardSvc.exe
(Intel Security) C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\BackgroundTransferHost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6613896 2016-06-28] (Advanced Micro Devices, Inc.)
HKLM\…\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791848 2016-06-16] ()
HKLM\…\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\…\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [916184 2014-07-02] (Conexant Systems, Inc.)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323056 2015-11-04] (Intel Corporation)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3936936 2015-07-09] (Synaptics Incorporated)
HKLM\…\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM-x32\…\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2384984 2016-12-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-25] (AVAST Software)
HKU\S-1-5-21-2699415127-3231795442-1188641079-1001\…\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [5622032 2016-12-02] (Performix LLC)
HKU\S-1-5-21-2699415127-3231795442-1188641079-1001\…\Run: [Browser Manager] => C:\Users\1\AppData\Local\Yandex\BrowserManager\MBLauncher.exe [121704 2016-12-02] (Yandex LLC)
HKU\S-1-5-21-2699415127-3231795442-1188641079-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-12-25] (AVAST Software)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 169.254.0.5
Tcpip\..\Interfaces\{cf2ae066-83e4-45ce-95d8-2d26a2c4be8d}: [DhcpNameServer] 150.203.1.3
Tcpip\..\Interfaces\{dbbf1243-f56e-4f3f-b297-669ea401611d}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{e59efb04-39c3-4f80-b723-fda6f4ec7594}: [DhcpNameServer] 169.254.0.5
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2699415127-3231795442-1188641079-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yandex.ru/?win=260&clid=2139453-1
HKU\S-1-5-21-2699415127-3231795442-1188641079-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo15.msn.com/?pc=LCTE
SearchScopes: HKU\S-1-5-21-2699415127-3231795442-1188641079-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2699415127-3231795442-1188641079-1001 -> {759D9127-F557-427D-BFE2-E595ACBB3507} URL =
SearchScopes: HKU\S-1-5-21-2699415127-3231795442-1188641079-1001 -> {8C3078A0-9AAB-4371-85D1-656CA8E46EE8} URL = hxxps://yandex.ru/search/?text={searchTerms}&clid=2233627
BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\x64\IEExt\ie_plugin.dll [2016-12-25] (AO Kaspersky Lab)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-25] (Microsoft Corporation)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2016-10-24] (McAfee, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-25] (Microsoft Corporation)
BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll [2016-12-25] (AO Kaspersky Lab)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2016-10-24] (McAfee, Inc.)
Toolbar: HKLM — Kaspersky Protection Toolbar — {093F479D-712E-46CD-9E06-62E734A05F68} — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\x64\IEExt\ie_plugin.dll [2016-12-25] (AO Kaspersky Lab)
Toolbar: HKLM-x32 — Kaspersky Protection Toolbar — {093F479D-712E-46CD-9E06-62E734A05F68} — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\IEExt\ie_plugin.dll [2016-12-25] (AO Kaspersky Lab)
Handler-x32: mso-minsb-roaming.16 — {83C25742-A9F7-49FB-9138-434302C88D07} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-25] (Microsoft Corporation)
Handler-x32: mso-minsb.16 — {42089D2D-912D-4018-9087-2B87803E93FB} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-25] (Microsoft Corporation)
Handler-x32: osf-roaming.16 — {42089D2D-912D-4018-9087-2B87803E93FB} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-25] (Microsoft Corporation)
Handler-x32: osf.16 — {5504BE45-A83B-4808-900A-3A5C36E7F77A} — C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-25] (Microsoft Corporation)
Handler: sacore — {5513F07E-936B-4E52-9B00-067394E91CC5} — c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2016-10-24] (McAfee, Inc.)
Handler-x32: sacore — {5513F07E-936B-4E52-9B00-067394E91CC5} — c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2016-10-24] (McAfee, Inc.)
Filter: application/x-mfe-ipt — {3EF5086B-5478-4598-A054-786C45D75692} — c:\Program Files\mcafee\MSC\McSnIePl64.dll [2016-11-18] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt — {3EF5086B-5478-4598-A054-786C45D75692} — c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2016-11-18] (McAfee, Inc.)
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2699415127-3231795442-1188641079-1001 -> hxxps://www.yandex.ru/?win=260&clid=2139453-1
FireFox:
========
FF DefaultProfile: pfufwjhk.default
FF ProfilePath: C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\pfufwjhk.default [2016-12-26]FF DefaultSearchEngine: Mozilla\Firefox\Profiles\pfufwjhk.default -> Яндекс
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\pfufwjhk.default -> Яндекс
FF Extension: (No Name) — C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\pfufwjhk.default\extensions\yasearch@yandex.ru.xpi [not found]FF Extension: (McAfee WebAdvisor) — C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2016-12-25]FF SearchPlugin: C:\Users\1\AppData\Roaming\Mozilla\Firefox\Profiles\pfufwjhk.default\searchplugins\yandex.ru-130657.xml [2016-12-25]FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] — C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM\…\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2016-12-25]FF HKLM-x32\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] — C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\…\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] — C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-11-18] ()
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-12-09] (Adobe Systems)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-11-18] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-25] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-25] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-25] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2699415127-3231795442-1188641079-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\1\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> yandex.ru/?__PARAM__from=chromehp
CHR DefaultSearchURL: Profile 1 -> hxxps://yandex.ru/search/?__PARAM__from=chromesearch&text={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> yandex.ru
CHR DefaultSuggestURL: Profile 1 -> hxxps://suggest.yandex.net/suggest-ff.cgi?uil=ru&part={searchTerms}
CHR Profile: C:\Users\1\AppData\Local\Google\Chrome\User Data\Default [2016-12-25]CHR Profile: C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-12-26]CHR Extension: (Google Презентации) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-25]CHR Extension: (Документы Google) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-25]CHR Extension: (Диск Google) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-25]CHR Extension: (YouTube) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-25]CHR Extension: (Стартовая — Яндекс) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cpegcopcfajiiibidlaelhjjblpefbjk [2016-12-25]CHR Extension: (Google Таблицы) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-25]CHR Extension: (McAfee® WebAdvisor) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2016-12-25]CHR Extension: (Kaspersky Protection) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2016-12-25]CHR Extension: (Google Документы офлайн) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-25]CHR Extension: (Новая вкладка – Яндекс) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hdpgllbnilfcbckbdchjcfgopijgllcm [2016-12-25]CHR Extension: (Платежная система Интернет-магазина Chrome) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-25]CHR Extension: (Gmail) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-25]CHR Extension: (Chrome Media Router) — C:\Users\1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-25]CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] — hxxp://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] — hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\…\Chrome\Extension: [bejnpnkhfgfkcpgikiinojlmdcjimobi] — hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cpegcopcfajiiibidlaelhjjblpefbjk] — hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] — hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] — hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\…\Chrome\Extension: [hdpgllbnilfcbckbdchjcfgopijgllcm] — hxxp://clients2.google.com/service/update2/crx
Opera:
=======
OPR StartupUrls: «hxxps://www.yandex.ru/?win=260&clid=2139453-1»
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2016-06-28] () [File not signed]R2 Adguard Service; C:\Program Files (x86)\Adguard\AdguardSvc.exe [151312 2016-12-02] (Performix LLC)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [753240 2016-12-09] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [315472 2015-07-20] (Windows (R) Win 7 DDK provider)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-25] (AVAST Software)
R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [650680 2015-07-29] (Lenovo)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3019968 2016-12-04] (Microsoft Corporation)
S3 cplspcon; C:\WINDOWS\system32\IntelCpHDCPSvc.exe [457192 2016-12-14] (Intel Corporation)
R2 GDCAgent; C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe [1155512 2015-07-29] (Lenovo)
R2 Globus; C:\Program Files (x86)\Globus\GlobusService.exe [1228384 2016-04-14] (Woogable Ltd.) [File not signed]R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [382440 2016-12-14] (Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [62792 2016-12-01] (Lenovo Group Limited)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
R2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271328 2016-01-25] (Lenovo)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [187840 2016-10-24] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_5\McAPExe.exe [963176 2016-10-07] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [289256 2015-12-02] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.2.351.0\\McCSPServiceHost.exe [1934968 2016-10-17] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [1307752 2016-10-20] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [603752 2016-10-14] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [242704 2016-09-08] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [384016 2016-09-08] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [331280 2016-09-08] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1473128 2016-10-07] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1041512 2016-09-08] (Intel Security, Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2015-07-09] (Synaptics Incorporated)
R2 wbiosrvp; C:\WINDOWS\SysWOW64\wbiosrvp.dll [345088 2016-09-07] () [File not signed]S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 YandexBrowserService; C:\Program Files (x86)\Yandex\YandexBrowser\16.11.1.673\service_update.exe [620536 2016-12-19] (YANDEX LLC)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 adgnetworktdidrv; C:\WINDOWS\System32\drivers\adgnetworktdidrv.sys [64112 2016-07-21] ()
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [73976 2015-06-04] (Advanced Micro Devices, Inc.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [37656 2016-12-25] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [108816 2016-12-25] (AVAST Software)
S3 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [103064 2016-12-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-12-25] (AVAST Software)
S3 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [969184 2016-12-25] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [513632 2016-12-25] (AVAST Software)
S3 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [163416 2016-12-25] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-12-25] (AVAST Software)
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [88120 2016-09-09] (McAfee, Inc.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2016-12-14] ()
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [216704 2016-08-02] (McAfee, Inc.)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [191312 2016-06-26] (AO Kaspersky Lab)
S1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1019616 2016-12-25] (AO Kaspersky Lab)
S1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [57424 2016-12-25] (AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [218920 2016-12-25] (AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [85984 2016-12-25] ()
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [245512 2016-12-25] (AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [104720 2016-12-25] (AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [164888 2016-12-25] (AO Kaspersky Lab)
S4 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [134880 2016-12-25] (AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [194480 2016-06-14] (AO Kaspersky Lab)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176064 2016-12-26] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [102856 2016-12-26] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2016-12-26] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [250816 2016-12-26] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2016-12-26] (Malwarebytes)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [477752 2016-09-09] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [364088 2016-09-09] (McAfee, Inc.)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85656 2016-09-09] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [512056 2016-09-09] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [884792 2016-09-09] (McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [527496 2016-09-09] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [109336 2016-09-09] (McAfee, Inc.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [110136 2016-09-09] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [252984 2016-09-09] (McAfee, Inc.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3343872 2015-10-30] (Intel Corporation)
R3 Qcamain10x64; C:\WINDOWS\system32\DRIVERS\Qcamain10x64.sys [2403168 2016-09-20] (Qualcomm Atheros, Inc.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3059416 2015-06-11] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-07-09] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [102376 2012-06-13] («CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-26 14:06 — 2016-12-26 14:09 — 00043325 _____ C:\Users\1\Downloads\Addition.txt
2016-12-26 14:03 — 2016-12-26 14:09 — 00032036 _____ C:\Users\1\Downloads\FRST.txt
2016-12-26 14:03 — 2016-12-26 14:09 — 00000000 ____D C:\FRST
2016-12-26 13:56 — 2016-12-26 13:56 — 00002136 _____ C:\Users\Public\Desktop\Lenovo Photo Master.lnk
2016-12-26 13:56 — 2016-12-26 13:56 — 00000000 ____D C:\Program Files (x86)\CyberLink
2016-12-26 13:45 — 2016-12-26 13:45 — 00000000 ____D C:\Users\1\Downloads\backups
2016-12-26 13:40 — 2016-12-26 13:41 — 00388608 _____ (Trend Micro Inc.) C:\Users\1\Downloads\HijackThis.exe
2016-12-26 13:10 — 2016-12-26 13:30 — 00000000 ____D C:\Users\1\Doctor Web
2016-12-26 12:52 — 2016-12-26 13:09 — 146876368 _____ C:\Users\1\Downloads\jjoijc3l.exe
2016-12-26 12:51 — 2016-12-26 12:52 — 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2016-12-26 12:51 — 2016-12-26 12:51 — 00250816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-12-26 12:51 — 2016-12-26 12:51 — 00176064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2016-12-26 12:51 — 2016-12-26 12:51 — 00102856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2016-12-26 12:51 — 2016-12-26 12:51 — 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-12-26 12:50 — 2016-12-26 12:50 — 00001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2016-12-26 12:50 — 2016-12-26 12:50 — 00000000 ____D C:\Users\Все пользователи\Malwarebytes
2016-12-26 12:50 — 2016-12-26 12:50 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2016-12-26 12:50 — 2016-12-26 12:50 — 00000000 ____D C:\ProgramData\Malwarebytes
2016-12-26 12:50 — 2016-12-26 12:50 — 00000000 ____D C:\Program Files\Malwarebytes
2016-12-26 12:50 — 2016-12-14 12:55 — 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2016-12-26 12:46 — 2016-12-26 12:50 — 54199488 _____ (Malwarebytes ) C:\Users\1\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2016-12-26 12:28 — 2016-12-26 12:28 — 02420736 _____ (Farbar) C:\Users\1\Downloads\FRST64.exe
2016-12-26 10:12 — 2016-12-26 10:12 — 00000000 ____D C:\Users\Все пользователи\Microsoft OneDrive
2016-12-26 10:12 — 2016-12-26 10:12 — 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-12-26 10:07 — 2016-12-26 12:06 — 00000000 ____D C:\Users\1\AppData\Local\ConnectedDevicesPlatform
2016-12-26 10:07 — 2016-12-26 10:07 — 00000020 ___SH C:\Users\1\ntuser.ini
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\Шаблоны
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\Мои документы
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\главное меню
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\Documents\Моя музыка
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\Documents\мои рисунки
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\Documents\Мои видеозаписи
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Программы
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default User\Documents\Моя музыка
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default User\Documents\мои рисунки
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default User\Documents\Мои видеозаписи
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Программы
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 ____D C:\Users\Все пользователи\USOShared
2016-12-26 04:52 — 2016-12-26 04:52 — 00000000 ____D C:\ProgramData\USOShared
2016-12-26 04:50 — 2016-12-26 04:51 — 00007623 _____ C:\WINDOWS\diagwrn.xml
2016-12-26 04:50 — 2016-12-26 04:51 — 00007623 _____ C:\WINDOWS\diagerr.xml
2016-12-26 04:48 — 2016-12-26 13:56 — 00000000 ____D C:\WINDOWS\System32\Tasks\CyberLink
2016-12-26 04:48 — 2016-12-26 12:34 — 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-12-26 04:48 — 2016-12-26 04:57 — 00004020 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
2016-12-26 04:48 — 2016-12-26 04:53 — 00003680 _____ C:\WINDOWS\System32\Tasks\Системное обновление Браузера Яндекс
2016-12-26 04:48 — 2016-12-26 04:49 — 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-12-26 04:48 — 2016-12-26 04:49 — 00003414 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-26 04:48 — 2016-12-26 04:49 — 00003348 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1482655685
2016-12-26 04:48 — 2016-12-26 04:49 — 00003324 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7355C281-939F-488B-8D7F-8E11F9D71263}
2016-12-26 04:48 — 2016-12-26 04:49 — 00003190 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-26 04:48 — 2016-12-26 04:49 — 00003006 _____ C:\WINDOWS\System32\Tasks\Обновление Браузера Яндекс
2016-12-26 04:48 — 2016-12-26 04:49 — 00002952 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-12-26 04:48 — 2016-12-26 04:49 — 00002814 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-free.bmx.rider@gmail.com
2016-12-26 04:48 — 2016-12-26 04:49 — 00002772 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2016-12-26 04:48 — 2016-12-26 04:49 — 00002766 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-LAPTOP-OQ81C0AF-1
2016-12-26 04:48 — 2016-12-26 04:49 — 00002470 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2016-12-26 04:48 — 2016-12-26 04:49 — 00002220 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-12-26 04:48 — 2016-12-26 04:49 — 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2016-12-26 04:48 — 2016-12-26 04:48 — 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-12-26 04:48 — 2016-12-26 04:48 — 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2016-12-26 04:42 — 2016-12-26 04:42 — 00023752 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-12-26 04:32 — 2016-12-26 04:32 — 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-12-26 04:28 — 2016-12-26 04:34 — 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-12-26 04:26 — 2016-12-26 13:10 — 00000000 ____D C:\Users\1
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\Шаблоны
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\Мои документы
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\главное меню
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\Documents\Моя музыка
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\Documents\мои рисунки
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\Documents\Мои видеозаписи
2016-12-26 04:26 — 2016-12-26 04:26 — 00000000 _SHDL C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Программы
2016-12-26 04:22 — 2016-12-26 04:22 — 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-12-26 04:22 — 2016-12-26 04:22 — 00000000 ____D C:\WINDOWS\SysWOW64\sda
2016-12-26 04:21 — 2016-12-26 12:36 — 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-12-26 04:21 — 2016-12-26 04:28 — 00000000 ____D C:\Users\Все пользователи\Conexant
2016-12-26 04:21 — 2016-12-26 04:28 — 00000000 ____D C:\ProgramData\Conexant
2016-12-26 04:21 — 2016-12-26 04:28 — 00000000 ____D C:\Program Files\Intel
2016-12-26 04:21 — 2016-12-26 04:28 — 00000000 ____D C:\Program Files\CONEXANT
2016-12-26 04:21 — 2016-12-26 04:21 — 00000568 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2016-12-26 04:21 — 2016-12-26 04:21 — 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-12-26 04:21 — 2016-12-26 04:21 — 00000000 ____H C:\Users\Все пользователи\DP45977C.lfl
2016-12-26 04:21 — 2016-12-26 04:21 — 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-12-26 04:21 — 2016-12-26 04:21 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2016-12-26 04:21 — 2016-12-26 04:21 — 00000000 ____D C:\Program Files\ATI Technologies
2016-12-26 04:21 — 2016-12-26 04:21 — 00000000 ____D C:\Program Files (x86)\AMD
2016-12-26 04:21 — 2016-12-26 04:21 — 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2016-12-26 04:20 — 2016-12-26 04:29 — 00000000 ____D C:\Users\Все пользователи\Package Cache
2016-12-26 04:20 — 2016-12-26 04:29 — 00000000 ____D C:\ProgramData\Package Cache
2016-12-26 04:20 — 2016-12-26 04:20 — 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2016-12-26 04:20 — 2016-12-26 04:20 — 00000000 ____D C:\Program Files\Synaptics
2016-12-26 04:20 — 2016-07-16 14:41 — 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-12-26 04:19 — 2016-12-26 04:28 — 00000000 ____D C:\Program Files\AMD
2016-12-26 04:17 — 2016-12-26 12:03 — 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-12-26 04:17 — 2016-12-26 11:08 — 00338736 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-12-26 04:17 — 2016-12-26 04:17 — 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-12-26 04:16 — 2016-12-26 04:53 — 00000000 ___DC C:\WINDOWS\Panther
2016-12-26 04:13 — 2016-12-26 04:13 — 00000000 ____D C:\Windows.old
2016-12-26 04:12 — 2016-12-26 04:12 — 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-12-26 04:10 — 2016-12-26 04:10 — 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-12-26 04:10 — 2016-12-26 04:10 — 00000000 ____D C:\Program Files\Reference Assemblies
2016-12-26 04:10 — 2016-12-26 04:10 — 00000000 ____D C:\Program Files\MSBuild
2016-12-26 04:10 — 2016-12-26 04:10 — 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-12-26 04:10 — 2016-12-26 04:10 — 00000000 ____D C:\Program Files (x86)\MSBuild
2016-12-26 04:09 — 2016-05-25 14:31 — 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-12-26 04:09 — 2016-05-25 14:31 — 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-12-26 04:09 — 2016-05-25 14:31 — 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-12-26 04:09 — 2016-05-25 11:03 — 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-12-26 04:09 — 2016-05-25 11:03 — 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-12-26 04:09 — 2016-05-25 11:03 — 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-12-26 00:11 — 2016-12-26 13:37 — 00000000 ____D C:\AdwCleaner
2016-12-26 00:11 — 2016-12-26 00:11 — 03977168 _____ C:\Users\1\Downloads\adwcleaner_6.041.exe
2016-12-25 23:49 — 2016-12-26 00:15 — 128944061 _____ C:\Users\1\Downloads\Не подтвержден 726446.crdownload
2016-12-25 15:00 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-12-25 15:00 — 2016-12-25 15:00 — 00000870 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-12-25 14:59 — 2016-12-25 15:00 — 00000000 ____D C:\Program Files\CCleaner
2016-12-25 14:38 — 2016-12-25 14:38 — 00002339 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-25 14:34 — 2016-12-25 14:34 — 00245512 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2016-12-25 14:33 — 2016-12-25 14:33 — 00002142 _____ C:\Users\Public\Desktop\OneKey Recovery.lnk
2016-12-25 14:33 — 2012-06-13 17:10 — 00102376 _____ («CyberLink) C:\WINDOWS\system32\Drivers\wsvd.sys
2016-12-25 14:12 — 2016-12-26 04:27 — 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Яндекс
2016-12-25 14:12 — 2016-12-25 14:12 — 00000000 ____D C:\Users\1\AppData\Local\Package Cache
2016-12-25 14:10 — 2016-12-26 13:31 — 00000259 _____ C:\WINDOWS\SysWOW64\Drivers\vwifikerneldrv.sys
2016-12-25 14:10 — 2016-12-26 13:31 — 00000259 _____ C:\WINDOWS\SysWOW64\d3dx9_11.dll.tmp
2016-12-25 14:10 — 2016-12-26 13:31 — 00000259 _____ C:\Users\Все пользователи\fontcacheev1.dat
2016-12-25 14:10 — 2016-12-26 13:31 — 00000259 _____ C:\ProgramData\fontcacheev1.dat
2016-12-25 14:10 — 2016-07-21 16:54 — 00064112 _____ () C:\WINDOWS\system32\Drivers\adgnetworktdidrv.sys
2016-12-25 14:09 — 2016-12-26 14:10 — 00000000 ____D C:\Users\Все пользователи\Adguard
2016-12-25 14:09 — 2016-12-26 14:10 — 00000000 ____D C:\ProgramData\Adguard
2016-12-25 14:09 — 2016-12-26 13:31 — 00000000 ____D C:\Program Files (x86)\Adguard
2016-12-25 14:09 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adguard
2016-12-25 14:09 — 2016-12-25 14:09 — 00001009 _____ C:\Users\Public\Desktop\Adguard.lnk
2016-12-25 14:09 — 2016-12-25 14:09 — 00000000 ____D C:\Users\1\AppData\Roaming\Performix LLC
2016-12-25 14:09 — 2016-12-25 14:09 — 00000000 ____D C:\Users\1\AppData\Local\Performix_LLC
2016-12-25 14:01 — 2016-12-25 14:01 — 00218920 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2016-12-25 14:01 — 2016-12-25 14:01 — 00164888 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2016-12-25 14:01 — 2016-12-25 14:01 — 00104720 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2016-12-25 14:01 — 2016-12-25 14:01 — 00085984 _____ C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2016-12-25 13:59 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2016-12-25 13:59 — 2016-12-25 14:52 — 00001486 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
2016-12-25 13:58 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Free
2016-12-25 13:58 — 2016-12-25 13:58 — 00002133 _____ C:\Users\Public\Desktop\Kaspersky Free.lnk
2016-12-25 13:57 — 2013-05-06 08:13 — 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2016-12-25 13:56 — 2016-12-26 12:43 — 00000000 ____D C:\Users\Все пользователи\Kaspersky Lab
2016-12-25 13:56 — 2016-12-26 12:43 — 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-12-25 13:56 — 2016-12-25 13:59 — 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2016-12-25 13:55 — 2016-12-25 14:43 — 01019616 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2016-12-25 13:55 — 2016-06-26 15:14 — 00191312 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2016-12-25 13:36 — 2016-12-25 14:00 — 00000000 ____D C:\Users\1\.gimp-2.8
2016-12-25 13:36 — 2016-12-25 13:36 — 00000000 ____D C:\Users\1\AppData\Local\gegl-0.2
2016-12-25 13:36 — 2016-12-25 13:36 — 00000000 ____D C:\Users\1\AppData\Local\fontconfig
2016-12-25 13:33 — 2016-12-25 13:33 — 00000000 ____D C:\Users\1\AppData\Roaming\AVAST Software
2016-12-25 13:32 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GimpShop
2016-12-25 13:32 — 2016-12-25 13:32 — 00002523 _____ C:\Users\Public\Desktop\GimpShop.lnk
2016-12-25 13:32 — 2016-12-25 13:32 — 00001986 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-12-25 13:32 — 2016-12-25 13:32 — 00001974 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-12-25 13:31 — 2016-12-25 13:32 — 00000000 ____D C:\Program Files (x86)\GimpShop
2016-12-25 13:29 — 2016-12-25 13:31 — 00969184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-12-25 13:29 — 2016-12-25 13:31 — 00513632 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2016-12-25 13:29 — 2016-12-25 13:31 — 00293352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys
2016-12-25 13:29 — 2016-12-25 13:29 — 00391496 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-12-25 13:29 — 2016-12-25 13:29 — 00163416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2016-12-25 13:29 — 2016-12-25 13:29 — 00108816 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-12-25 13:29 — 2016-12-25 13:29 — 00103064 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2016-12-25 13:29 — 2016-12-25 13:29 — 00074544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-12-25 13:29 — 2016-12-25 13:29 — 00037656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-12-25 13:28 — 2016-12-25 13:28 — 00053208 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-12-25 13:06 — 2016-12-25 13:06 — 00000000 ____D C:\Users\1\AppData\Local\Chromium
2016-12-25 13:04 — 2016-12-25 13:04 — 00000000 ____D C:\Program Files\AVAST Software
2016-12-25 13:02 — 2016-12-25 13:02 — 00000000 ____D C:\Users\Все пользователи\AVAST Software
2016-12-25 13:02 — 2016-12-25 13:02 — 00000000 ____D C:\ProgramData\AVAST Software
2016-12-25 13:00 — 2016-12-25 13:00 — 00000000 ____D C:\Users\1\AppData\Roaming\Sparta
2016-12-25 12:43 — 2016-12-26 04:34 — 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-12-25 12:43 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-12-25 12:43 — 2016-12-25 12:43 — 00000000 ____D C:\Program Files\WinRAR
2016-12-25 12:31 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Globus Privacy
2016-12-25 12:31 — 2016-12-25 12:31 — 00002339 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Globus.lnk
2016-12-25 12:31 — 2016-12-25 12:31 — 00002327 _____ C:\Users\Public\Desktop\Globus.lnk
2016-12-25 12:31 — 2016-12-25 12:31 — 00000000 ____D C:\Users\1\AppData\Local\Globus
2016-12-25 12:30 — 2016-12-26 12:35 — 00000000 ____D C:\Users\Все пользователи\Globus Privacy
2016-12-25 12:30 — 2016-12-26 12:35 — 00000000 ____D C:\ProgramData\Globus Privacy
2016-12-25 12:30 — 2016-12-25 12:31 — 00000000 ____D C:\Program Files (x86)\Globus
2016-12-25 12:09 — 2016-12-25 12:09 — 00000733 _____ C:\Users\1\Desktop\Tor Browser.lnk
2016-12-25 12:08 — 2016-12-25 12:09 — 00000000 ____D C:\Users\1\Desktop\Tor Browser
2016-12-25 11:58 — 2016-12-25 11:58 — 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
2016-12-25 11:58 — 2016-12-25 11:58 — 00002507 _____ C:\Users\Public\Desktop\Safari.lnk
2016-12-25 11:58 — 2016-12-25 11:58 — 00000000 ____D C:\Users\1\AppData\Roaming\Apple Computer
2016-12-25 11:58 — 2016-12-25 11:58 — 00000000 ____D C:\Users\1\AppData\Local\Apple Computer
2016-12-25 11:57 — 2016-12-25 11:58 — 00000000 ____D C:\Program Files (x86)\Safari
2016-12-25 11:57 — 2016-12-25 11:57 — 00000000 ____D C:\Users\Все пользователи\Apple Computer
2016-12-25 11:57 — 2016-12-25 11:57 — 00000000 ____D C:\ProgramData\Apple Computer
2016-12-25 11:55 — 2016-12-26 13:11 — 00000000 ____D C:\Program Files\Bonjour
2016-12-25 11:55 — 2016-12-25 11:55 — 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-12-25 11:55 — 2016-12-25 11:55 — 00000000 ____D C:\Users\Все пользователи\Apple
2016-12-25 11:55 — 2016-12-25 11:55 — 00000000 ____D C:\Users\1\AppData\Local\Apple
2016-12-25 11:55 — 2016-12-25 11:55 — 00000000 ____D C:\ProgramData\Apple
2016-12-25 11:55 — 2016-12-25 11:55 — 00000000 ____D C:\Program Files (x86)\Bonjour
2016-12-25 11:55 — 2016-12-25 11:55 — 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-12-25 11:52 — 2016-12-25 11:53 — 00000000 ____D C:\Users\1\AppData\LocalLow\Mozilla
2016-12-25 11:49 — 2016-12-25 11:50 — 00000000 ____D C:\Users\1\AppData\Roaming\Mozilla
2016-12-25 11:49 — 2016-12-25 11:49 — 00001239 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-12-25 11:49 — 2016-12-25 11:49 — 00001227 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-12-25 11:49 — 2016-12-25 11:49 — 00000000 ____D C:\Users\1\AppData\Local\Mozilla
2016-12-25 11:49 — 2016-12-25 11:49 — 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-25 11:49 — 2016-12-25 11:49 — 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-25 11:48 — 2016-12-25 11:59 — 00001127 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-12-25 11:48 — 2016-12-25 11:48 — 00001215 _____ C:\Users\Public\Desktop\Opera.lnk
2016-12-25 11:48 — 2016-12-25 11:48 — 00000000 ____D C:\Users\1\AppData\Roaming\Opera Software
2016-12-25 11:48 — 2016-12-25 11:48 — 00000000 ____D C:\Users\1\AppData\Local\Opera Software
2016-12-25 11:47 — 2016-12-25 11:59 — 00000000 ____D C:\Program Files (x86)\Opera
2016-12-25 10:10 — 2016-12-25 10:10 — 00000000 ____D C:\Users\1\AppData\LocalLow\Yandex
2016-12-25 10:07 — 2016-12-26 13:07 — 00012125 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2016-12-25 10:03 — 2016-12-25 10:04 — 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Приложения Амиго
2016-12-25 00:48 — 2016-12-25 00:48 — 00000000 ____D C:\Users\1\AppData\Local\Tempzxpsign0df5d2c1edfdbfd1
2016-12-25 00:42 — 2016-09-07 08:39 — 00345088 _____ C:\WINDOWS\SysWOW64\wbiosrvp.dll
2016-12-25 00:42 — 2016-09-07 08:39 — 00126976 _____ C:\WINDOWS\SysWOW64\biosysrt.dll
2016-12-25 00:41 — 2016-12-25 00:41 — 00000000 ____D C:\Users\1\AppData\Roaming\PDAppFlex
2016-12-25 00:41 — 2016-12-25 00:41 — 00000000 ____D C:\Users\1\AppData\Local\Tempzxpsign352d95a621291629
2016-12-25 00:41 — 2016-12-25 00:41 — 00000000 ____D C:\Users\1\AppData\Local\Tempzxpsign0ac18caf1937b4aa
2016-12-21 10:56 — 2016-12-26 04:29 — 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2016-12-21 10:56 — 2016-12-26 04:29 — 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-12-21 09:08 — 2016-12-21 09:08 — 00000000 ____D C:\Users\1\AppData\Local\Tempzxpsign12712b90a64ced81
2016-12-20 22:28 — 2016-12-20 22:28 — 00000000 ____D C:\Users\1\AppData\Local\Tempzxpsign56e4d0073abb97e2
2016-12-20 22:28 — 2016-12-20 22:28 — 00000000 ____D C:\Users\1\AppData\Local\Tempzxpsign0a98229c54f49350
2016-12-20 22:27 — 2016-12-20 22:27 — 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2016-12-20 22:27 — 2016-12-20 22:27 — 00000000 ____D C:\Users\1\Documents\Adobe
2016-12-20 22:06 — 2016-12-20 22:27 — 00000000 ____D C:\Program Files\Common Files\Adobe
2016-12-20 21:52 — 2016-12-20 21:52 — 00000000 ____D C:\Program Files\Adobe
2016-12-20 21:49 — 2016-12-20 21:49 — 00000000 ___RD C:\Users\1\Creative Cloud Files
2016-12-20 21:49 — 2016-12-20 21:49 — 00000000 ____D C:\Users\Все пользователи\boost_interprocess
2016-12-20 21:49 — 2016-12-20 21:49 — 00000000 ____D C:\ProgramData\boost_interprocess
2016-12-20 21:16 — 2016-12-26 04:27 — 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2016-12-20 21:16 — 2016-12-21 03:00 — 00000000 ____D C:\Users\1\AppData\Roaming\WhatsApp
2016-12-20 21:16 — 2016-12-20 21:16 — 00002229 _____ C:\Users\1\Desktop\WhatsApp.lnk
2016-12-20 21:15 — 2016-12-20 21:16 — 00000000 ____D C:\Users\1\AppData\Local\WhatsApp
2016-12-20 21:13 — 2016-12-20 21:13 — 00001309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2016-12-20 21:13 — 2016-12-20 21:13 — 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2016-12-20 21:11 — 2016-12-26 04:34 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-12-20 21:11 — 2016-12-20 21:11 — 00000000 ____D C:\Program Files\McAfee Security Scan
2016-12-20 21:00 — 2016-12-20 21:00 — 00000000 ____D C:\Users\Все пользователи\AMD
2016-12-20 21:00 — 2016-12-20 21:00 — 00000000 ____D C:\ProgramData\AMD
2016-12-20 20:56 — 2016-12-20 21:16 — 00000000 ____D C:\Users\1\AppData\Local\SquirrelTemp
2016-12-20 20:51 — 2016-12-20 20:55 — 00000000 ____D C:\WINDOWS\system32\MRT
2016-12-20 20:51 — 2016-12-20 20:51 — 135632432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-12-20 20:41 — 2016-12-21 10:49 — 00000000 ____D C:\Program Files\TrueKey
2016-12-20 20:41 — 2016-12-20 21:11 — 00002016 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-12-20 20:41 — 2016-12-20 20:41 — 00000000 ____D C:\Users\Все пользователи\McAfee Security Scan
2016-12-20 20:41 — 2016-12-20 20:41 — 00000000 ____D C:\Users\1\AppData\LocalLow\Adobe
2016-12-20 20:41 — 2016-12-20 20:41 — 00000000 ____D C:\ProgramData\McAfee Security Scan
2016-12-20 20:40 — 2016-12-20 20:44 — 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-12-20 20:40 — 2016-12-20 20:40 — 00002131 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-12-20 20:38 — 2016-12-20 20:58 — 00000000 ____D C:\Program Files (x86)\Adobe
2016-12-20 20:37 — 2016-12-20 22:10 — 00000000 ____D C:\Users\Все пользователи\Adobe
2016-12-20 20:37 — 2016-12-20 22:10 — 00000000 ____D C:\ProgramData\Adobe
2016-12-20 20:36 — 2016-12-26 02:00 — 00000000 ____D C:\Users\1\AppData\Local\Adobe
2016-12-20 20:35 — 2016-12-25 09:58 — 00000000 ____D C:\Program Files (x86)\Ghostery Storage Server
2016-12-20 20:34 — 2016-12-20 20:34 — 00000000 ____D C:\Users\1\AppData\LocalLow\Unity
2016-12-20 20:34 — 2016-12-20 20:34 — 00000000 ____D C:\Users\1\AppData\Local\Unity
2016-12-20 20:27 — 2016-07-01 06:40 — 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2016-12-20 20:24 — 2016-12-26 04:29 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2016-12-20 20:24 — 2016-12-20 20:24 — 00002146 _____ C:\Users\Public\Desktop\McAfee LiveSafe.lnk
2016-12-20 20:22 — 2016-08-02 01:03 — 00216704 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys
2016-12-20 20:22 — 2016-07-01 06:57 — 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpreference.exe
2016-12-20 20:21 — 2016-12-20 20:21 — 00000000 ____D C:\Users\Все пользователи\Intel Security
2016-12-20 20:21 — 2016-12-20 20:21 — 00000000 ____D C:\ProgramData\Intel Security
2016-12-20 20:17 — 2016-12-20 20:17 — 00000000 ____D C:\Program Files\McAfee.com
2016-12-20 20:16 — 2016-12-25 14:01 — 00000000 ____D C:\Program Files\Common Files\AV
2016-12-20 20:16 — 2016-12-20 20:55 — 00000000 ____D C:\Program Files (x86)\McAfee
2016-12-20 20:16 — 2016-12-20 20:16 — 00000000 ____D C:\Program Files\Common Files\Intel Security
2016-12-20 20:07 — 2016-12-20 20:22 — 00000000 ____D C:\Program Files\Common Files\McAfee
2016-12-20 20:07 — 2016-09-08 15:15 — 00331280 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
2016-12-20 19:47 — 2016-12-20 19:47 — 00000000 ____D C:\Users\1\AppData\Roaming\Skype
2016-12-20 19:43 — 2016-12-26 12:35 — 00000506 _____ C:\WINDOWS\Tasks\Системное обновление Браузера Яндекс.job
2016-12-20 19:43 — 2016-12-26 04:27 — 00000000 ____D C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex
2016-12-20 19:43 — 2016-12-25 14:27 — 00000000 ____D C:\Users\1\AppData\Local\Yandex
2016-12-20 19:43 — 2016-12-25 14:10 — 00000000 ____D C:\Users\1\AppData\Roaming\Yandex
2016-12-20 19:43 — 2016-12-20 19:43 — 00002520 _____ C:\Users\1\Desktop\Yandex.lnk
2016-12-20 19:43 — 2016-12-20 19:43 — 00000000 ____D C:\Users\Все пользователи\Yandex
2016-12-20 19:43 — 2016-12-20 19:43 — 00000000 ____D C:\ProgramData\Yandex
2016-12-20 19:43 — 2016-12-20 19:43 — 00000000 ____D C:\Program Files (x86)\Yandex
2016-12-20 19:40 — 2016-12-26 04:40 — 00002275 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-20 19:39 — 2016-12-25 14:37 — 00000000 ____D C:\Program Files (x86)\Google
2016-12-20 19:39 — 2016-12-25 13:45 — 00000000 ____D C:\Users\1\AppData\Local\Google
2016-12-20 19:34 — 2016-12-20 19:34 — 00000000 ____D C:\Users\1\AppData\Local\CEF
2016-12-20 19:34 — 2016-10-28 04:22 — 00485032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-12-20 19:25 — 2016-12-20 19:25 — 00000000 ____D C:\Users\1\AppData\Roaming\Macromedia
2016-12-20 19:17 — 2016-12-20 19:46 — 02365304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WudfUpdate_01011.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 40213448 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 39244592 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumdim32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 35129072 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd11dxva32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 33773040 _____ (Intel Corporation) C:\WINDOWS\system32\igd11dxva64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 15629672 _____ (Intel Corporation) C:\WINDOWS\system32\igc64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 14748712 _____ (Intel Corporation) C:\WINDOWS\system32\igd10iumd64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 13607160 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igc32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 12032160 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10iumd32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 06761456 _____ (Intel Corporation) C:\WINDOWS\system32\igdusc64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 05191840 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdusc32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 04291792 _____ (Intel Corporation) C:\WINDOWS\system32\igd12umd64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 04258992 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd12umd32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 01921552 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 01841080 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 01838400 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 01491312 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00323736 _____ (Intel Corporation) C:\WINDOWS\system32\igd10idpp64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00308496 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10idpp32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00253016 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00233928 _____ (Intel Corporation) C:\WINDOWS\system32\igdde64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00215856 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00194336 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00193320 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00192160 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdde32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00170376 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00170376 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2016-12-14 02:15 — 2016-12-14 02:15 — 00064560 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 29110288 _____ (Intel Corporation) C:\WINDOWS\system32\common_clang64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 19870216 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\common_clang32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 13627920 _____ (Intel Corporation) C:\WINDOWS\system32\ig9icd64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 10325000 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig9icd32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 07954400 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2016-12-14 02:09 — 2016-12-14 02:09 — 05697552 _____ (Intel Corporation) C:\WINDOWS\system32\igdmcl64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 05242384 _____ (Intel Corporation) C:\WINDOWS\system32\GfxResources.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 04945424 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 04374528 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 03980304 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmcl32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 02071568 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 01599504 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 01187336 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00975328 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00971752 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00765968 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00652768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxSDK.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00641544 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00545248 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00475624 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00457192 _____ (Intel Corporation) C:\WINDOWS\system32\IntelCpHDCPSvc.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00448016 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00424976 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00410600 _____ C:\WINDOWS\system32\igfxTray.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00405520 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00398864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00397320 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00382440 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00363496 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00358888 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCComp64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00327176 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00310248 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00282128 _____ C:\WINDOWS\system32\igfxCPL.cpl
2016-12-14 02:09 — 2016-12-14 02:09 — 00277472 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00274960 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00263696 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00245736 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00241128 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00240616 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00234000 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00218128 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4474.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00201744 _____ (Intel Corporation) C:\WINDOWS\system32\igdail64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00183776 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-12-14 02:09 — 2016-12-14 02:09 — 00182280 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdail32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00120336 _____ ( ) C:\WINDOWS\system32\igfxSDKLibv2_0.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00112648 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00112144 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00109584 _____ ( ) C:\WINDOWS\system32\igfxSDKLib.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00108560 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00103952 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00093200 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00061456 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00037904 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00037904 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00036368 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00036368 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00031248 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
2016-12-14 02:09 — 2016-12-14 02:09 — 00031248 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
2016-12-01 12:46 — 2016-12-01 12:46 — 00257864 _____ (Lenovo Group Limited) C:\WINDOWS\system32\iMDriverHelper.dll
2016-12-01 10:15 — 2016-12-01 10:15 — 00003248 _____ C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo App Explorer.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-26 14:09 — 2016-07-16 14:45 — 00000000 ____D C:\WINDOWS\INF
2016-12-26 13:56 — 2016-06-16 10:42 — 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-12-26 13:56 — 2016-06-16 10:42 — 00000000 ____D C:\Users\Все пользователи\SUPPORTDIR
2016-12-26 13:56 — 2016-06-16 10:42 — 00000000 ____D C:\ProgramData\SUPPORTDIR
2016-12-26 13:56 — 2016-06-16 10:30 — 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-12-26 13:54 — 2016-06-16 10:30 — 00000000 ____D C:\Program Files (x86)\Lenovo
2016-12-26 13:53 — 2016-06-16 10:44 — 00000000 ____D C:\Users\Все пользователи\CyberLink
2016-12-26 13:53 — 2016-06-16 10:44 — 00000000 ____D C:\ProgramData\CyberLink
2016-12-26 13:49 — 2016-06-16 10:42 — 00000000 ____D C:\Users\Все пользователи\Temp
2016-12-26 13:49 — 2016-06-16 10:42 — 00000000 ____D C:\ProgramData\Temp
2016-12-26 13:41 — 2016-10-10 18:30 — 00000000 ____D C:\Users\1\AppData\Local\VirtualStore
2016-12-26 13:08 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\AppReadiness
2016-12-26 12:41 — 2016-07-17 02:08 — 00450340 _____ C:\WINDOWS\system32\perfh019.dat
2016-12-26 12:41 — 2016-07-17 02:08 — 00074918 _____ C:\WINDOWS\system32\perfc019.dat
2016-12-26 12:41 — 2015-11-03 22:28 — 01412116 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-12-26 12:36 — 2016-10-10 18:30 — 00000000 __SHD C:\Users\1\IntelGraphicsProfiles
2016-12-26 12:33 — 2016-07-16 09:04 — 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-12-26 12:26 — 2016-07-16 14:47 — 00000000 ___HD C:\Program Files\WindowsApps
2016-12-26 11:06 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\Registration
2016-12-26 10:27 — 2016-10-10 18:30 — 00000000 ____D C:\Users\1\AppData\Local\Packages
2016-12-26 10:15 — 2016-10-10 18:32 — 00002410 _____ C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-12-26 10:15 — 2016-10-10 18:32 — 00000000 ___RD C:\Users\1\OneDrive
2016-12-26 10:07 — 2015-11-03 22:24 — 00000000 __RHD C:\Users\Public\AccountPictures
2016-12-26 04:57 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\rescache
2016-12-26 04:52 — 2016-07-16 14:47 — 00000000 ____D C:\Users\Все пользователи\USOPrivate
2016-12-26 04:52 — 2016-07-16 14:47 — 00000000 ____D C:\ProgramData\USOPrivate
2016-12-26 04:52 — 2016-07-16 14:47 — 00000000 ____D C:\Program Files\Windows NT
2016-12-26 04:52 — 2016-07-16 09:04 — 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-12-26 04:49 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-12-26 04:49 — 2015-10-30 10:24 — 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-12-26 04:41 — 2016-07-16 14:47 — 00000000 __RHD C:\Users\Public\Libraries
2016-12-26 04:41 — 2016-06-16 12:31 — 01350994 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-12-26 04:34 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-12-26 04:34 — 2016-07-16 14:47 — 00000000 ____D C:\Users\Все пользователи\regid.1991-06.com.microsoft
2016-12-26 04:34 — 2016-07-16 14:47 — 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-12-26 04:34 — 2016-06-16 12:31 — 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-12-26 04:34 — 2016-06-16 12:19 — 00000000 ____D C:\WINDOWS\system32\ihvmanager
2016-12-26 04:34 — 2016-06-16 12:13 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2016-12-26 04:34 — 2016-06-16 10:33 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Средства Microsoft Office 2016
2016-12-26 04:32 — 2015-10-30 09:28 — 00000000 ____D C:\Users\Default.migrated
2016-12-26 04:29 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-12-26 04:29 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\system32\spool
2016-12-26 04:29 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\system32\oobe
2016-12-26 04:28 — 2016-07-16 14:47 — 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-12-26 04:28 — 2016-06-16 12:14 — 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2016-12-26 04:28 — 2015-10-30 10:24 — 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-12-26 04:25 — 2016-07-16 09:04 — 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-12-26 04:22 — 2016-07-16 14:47 — 00000000 ___RD C:\WINDOWS\PrintDialog
2016-12-26 04:22 — 2016-07-16 14:47 — 00000000 ___RD C:\WINDOWS\MiracastView
2016-12-26 04:22 — 2016-07-16 14:47 — 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-12-26 04:19 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-12-26 04:16 — 2016-07-16 14:47 — 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-12-26 04:10 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-12-26 04:10 — 2016-07-16 14:47 — 00000000 ____D C:\WINDOWS\system32\MUI
2016-12-26 04:10 — 2016-07-16 14:36 — 00000000 ____D C:\WINDOWS\CbsTemp
2016-12-26 03:53 — 2016-07-17 03:19 — 00000000 ___HD C:\$WINDOWS.~BT
2016-12-25 14:46 — 2016-06-20 23:41 — 00057424 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2016-12-25 14:43 — 2016-06-02 22:39 — 00134880 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2016-12-25 14:33 — 2016-06-16 10:42 — 00000000 ____D C:\Program Files\Lenovo
2016-12-25 12:27 — 2016-06-16 10:47 — 00000000 ____D C:\Users\Все пользователи\McAfee
2016-12-25 12:27 — 2016-06-16 10:47 — 00000000 ____D C:\ProgramData\McAfee
2016-12-25 10:09 — 2016-11-20 00:15 — 00000000 ____D C:\Users\1\AppData\Local\Lenovo
2016-12-25 02:17 — 2016-06-16 10:31 — 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-12-20 22:28 — 2016-10-10 18:32 — 00000000 ____D C:\Users\1\AppData\Local\AMD
2016-12-20 22:28 — 2016-10-10 18:30 — 00000000 ____D C:\Users\1\AppData\Roaming\Adobe
2016-12-20 21:00 — 2016-06-16 12:07 — 00000000 ___HD C:\Intel
2016-12-20 20:27 — 2016-06-16 10:47 — 00000000 ____D C:\Program Files\mcafee
2016-12-20 19:58 — 2015-10-30 10:19 — 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2016-12-20 19:58 — 2015-10-30 10:19 — 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2016-12-20 19:38 — 2016-10-20 03:15 — 00000000 ____D C:\Users\1\AppData\Local\MicrosoftEdge
==================== Files in the root of some directories =======
2016-12-26 04:21 — 2016-12-26 04:21 — 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-12-25 14:10 — 2016-12-26 13:31 — 0000259 _____ () C:\ProgramData\fontcacheev1.dat
Files to move or delete:
====================
C:\ProgramData\fontcacheev1.dat
C:\Users\Все пользователи\fontcacheev1.dat
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed