Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01 Ran by Leda-11 (administrator) on LEDA-4 (01-04-2016 14:10:47) Running from C:\Documents and Settings\Leda-11\Рабочий стол Loaded Profiles: Leda-11 (Available Profiles: Leda-11 & Admin) Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: Русский Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Корпорация Майкрософт) C:\WINDOWS\system32\smss.exe (Корпорация Майкрософт) C:\WINDOWS\system32\winlogon.exe (Корпорация Майкрософт) C:\WINDOWS\system32\services.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Wireless Service) C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe () C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (Ext2Fsd Group (www.ext2fsd.com)) C:\Program Files\Ext2Fsd\Ext2Mgr.exe (FSPro Labs) C:\WINDOWS\system32\fsproflt.exe (LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (Aladdin Knowledge Systems Ltd.) C:\WINDOWS\system32\hasplms.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\27_ssconn\conn\ss_conn_service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe (Корпорация Майкрософт) C:\WINDOWS\explorer.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Winlogon: [Userinit] C:\WINDOWS\SYSTEM32\Userinit.exe, [26624 2008-04-15] (Корпорация Майкрософт) HKLM\...\Winlogon: [Shell] Explorer.exe [1034240 2008-04-15] (Корпорация Майкрософт) HKLM\...\Winlogon: [UIHost] C:\WINDOWS\system32\logonui.exe [515072 2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll [2008-02-26] (ATI Technologies Inc.) Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт) Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт) HKU\S-1-5-19\...\RunOnce: [ZZ_CustomSetting] => %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,CustomInstall,0 HKU\S-1-5-19\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-20\...\RunOnce: [ZZ_CustomSetting] => %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,CustomInstall,0 HKU\S-1-5-20\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\Run: [KiesPDLR.exe] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Run HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {35a034f2-6ea3-11e0-a36b-0022153c4329} - F:\AutoInstall.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {66a170c0-6581-11e4-9455-0022153c4329} - F:\Autoinstaller.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {70387445-b499-11de-a05c-001e584bd494} - F:\AutoInstall.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {71e63925-2b1d-11de-9f7c-0022153c4329} - F:\LaunchU3.exe -a HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {7a80a7cc-8f1e-11e4-a178-0022153c4329} - H:\autorun.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {8867673f-367c-11e0-a315-0022153c4329} - F:\Toshiba\Launcher\start.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {8c7043c1-8f3a-11e4-8bbb-0022153c4329} - I:\autorun.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {af4165bf-538e-11e0-a33e-0022153c4329} - F:\LaunchU3.exe -a HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {d7ad53c4-e2cc-11e0-a428-0022153c4329} - F:\setup.exe HKU\S-1-5-21-1343024091-1708537768-682003330-1006\...\MountPoints2: {f08ddec0-be92-11e5-9496-0022153c4329} - H:\AutoInstall.exe HKU\S-1-5-18\...\RunOnce: [ZZ_CustomSetting] => %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,CustomInstall,0 HKU\S-1-5-18\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\logon.scr [220672 2008-04-15] (Корпорация Майкрософт) AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll => C:\Documents and Settings\All Users\Application Data\VKSaver\vksaver3.dll [60928 2013-02-03] (AudioVkontakte.ru) Lsa: [Authentication Packages] msv1_0 relog_ap SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Корпорация Майкрософт) SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Корпорация Майкрософт) SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Корпорация Майкрософт) ShellExecuteHooks: Обработчик URL - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8478208 2008-04-15] (Корпорация Майкрософт) ShellIconOverlayIdentifiers: [Offline Files] -> {750fdf0e-2a26-11d1-a3ea-080036587f03} => C:\WINDOWS\System32\cscui.dll [2008-04-15] (Корпорация Майкрософт) ShellIconOverlayIdentifiers: [Обработчик значков цифровых подписей AutoCAD] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2008-02-10] (Autodesk, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 01 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog5 03 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 01 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 02 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 03 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 04 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 05 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 06 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 07 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 08 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 09 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 10 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 11 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 12 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 13 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 14 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 15 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 16 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 17 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 18 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 19 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 20 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 21 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 22 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 23 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 24 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 25 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 26 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 27 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 28 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 29 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 30 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 31 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 32 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 33 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 34 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 35 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 36 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Winsock: Catalog9 37 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) Tcpip\..\Interfaces\{4CF5CAAC-9785-43C2-A642-C2789F9C0686}: [NameServer] 192.168.255.1,192.168.0.1 Tcpip\..\Interfaces\{7F81F041-AA42-4B91-A8C6-60F4FDF64ABD}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{949D0252-7367-41C0-861D-95B055298F89}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{AFF8D20E-E08A-40A5-ABBF-D45861D508A2}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{CC19551E-D097-406C-9B03-26B1F04A2294}: [DhcpNameServer] 0.0.0.0 Internet Explorer: ================== HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1343024091-1708537768-682003330-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yandex.ru/?win=186&clid=1985535-207 HKU\S-1-5-21-1343024091-1708537768-682003330-1006\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1343024091-1708537768-682003330-1006\Software\Microsoft\Internet Explorer\Main,Яндекс = hxxp://yandex.ru/yandsearch?clid=40489&text={searchTerms} HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "C:\Documents and Settings\All Users\Application Data\ICQ\ICQNewTab\newTab.html" <======= ATTENTION SearchScopes: HKLM -> Yandex URL = hxxp://yandex.ru/yandsearch?clid=135294&text={searchTerms} SearchScopes: HKLM -> {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = SearchScopes: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/yandsearch?win=186&clid=1985536-207&text={searchTerms} SearchScopes: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> Moikrug URL = hxxp://moikrug.ru/persons/?clid=931354&charset=utf-8&keywords={searchTerms}&submitted=1 SearchScopes: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/yandsearch?win=186&clid=1985536-207&text={searchTerms} SearchScopes: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> {08015CD1-5EB1-4141-9A72-FC74E486A141} URL = hxxp://search.pivim.com/index.php?src=box&ver=1&topic=common&query={searchTerms} SearchScopes: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> {75B34134-097D-456b-BAB4-74DACD6FC2B1} URL = hxxp://search.pivim.com/index.php?src=box&ver=1&topic=yandex&query={searchTerms} SearchScopes: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> {B2A025AA-2242-4E2F-8FC6-6DC64A736A80} URL = hxxp://search.pivim.com/index.php?src=box&ver=1&topic=google&query={searchTerms} BHO: No Name -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File Toolbar: HKLM - Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\Elements\bartabhost.dll No File Toolbar: HKU\.DEFAULT -> Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\Elements\bartabhost.dll No File Toolbar: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> &Адрес - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2008-04-15] (Корпорация Майкрософт) Toolbar: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> &Ссылки - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll [2008-04-15] (Корпорация Майкрософт) Toolbar: HKU\S-1-5-21-1343024091-1708537768-682003330-1006 -> Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\Elements\bartabhost.dll No File DPF: {093500E9-F79F-4C52-A9B5-D8C7E4B3023E} file:///C:/WINDOWS/TEMP/o3d14BB.tmp.cab DPF: {113E52A8-A790-4B13-B5F8-B17BD5617707} hxxps://biz.smpbank.ru/CODE/3.17.9.1000/cr_call.cab DPF: {34E60EF0-8825-4AD8-ABED-ADC2F358F2C9} hxxps://biz.smpbank.ru/CODE/3.17.9.1000/bsssl.cab DPF: {3FD2F333-7E4B-43AC-BB2A-CC0410654160} hxxps://bk.smpbank.ru:1743/CODE/3.17.7.930/cr_msp2.cab DPF: {810B649C-CEAE-4AC9-BF26-81341B49E913} file:///C:/WINDOWS/TEMP/o3d14B2.tmp.cab Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll [2008-04-15] (Корпорация Майкрософт) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation) Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll [2008-04-15] (Корпорация Майкрософт) Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\SHELL32.dll [2008-04-15] (Корпорация Майкрософт) FireFox: ======== FF ProfilePath: C:\Documents and Settings\Leda-11\Application Data\Mozilla\Firefox\Profiles\8nm5h4nh.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] () FF Plugin: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-04-14] (RealNetworks, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-04-14] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-04-14] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-04-14] (RealNetworks, Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1343024091-1708537768-682003330-1006: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin HKU\S-1-5-21-1343024091-1708537768-682003330-1006: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npOutline3dWrapper.dll [2012-04-13] ( ) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.) FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-03-30] [not signed] Chrome: ======= CHR HomePage: Default -> hxxp://mail.ru/cnt/10445?gp=profitraf7 CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=profitraf7" CHR DefaultSearchURL: Default -> hxxp://yandex.ru/yandsearch?clid=187998&text={searchTerms} CHR DefaultSearchKeyword: Default -> yandex.ru_ CHR DefaultSuggestURL: Default -> hxxp://suggest.yandex.net/suggest-ff.cgi?part={searchTerms} CHR Session Restore: Default -> is enabled. CHR Profile: C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default CHR Extension: (Google Презентации) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-04] CHR Extension: (Документы Google) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04] CHR Extension: (Диск Google) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-10] CHR Extension: (Отправить SMS и MMS) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cgeioekfllobphkgcgebndcbliicnckg [2015-11-03] CHR Extension: (Google Search) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-03-10] CHR Extension: (Google Таблицы) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-04] CHR Extension: (Google Документы офлайн) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16] CHR Extension: (Mail.ru Checker) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\meffiamonaniekghongncpepaaecfoki [2015-11-03] CHR Extension: (Платежная система Интернет-магазина Chrome) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24] CHR Extension: (Экономия трафика) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pfmgfdlgomnbgkofeojodiodmgpgmkac [2016-02-03] CHR Extension: (Gmail) - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] StartMenuInternet: chrome.exe - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\Application\chrome.exe StartMenuInternet: Google Chrome - C:\Documents and Settings\Leda-11\Local Settings\Application Data\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [230944 2006-10-16] (Acronis) S3 AppMgmt; C:\WINDOWS\System32\appmgmts.dll [171008 2008-04-15] (Корпорация Майкрософт) S3 BITS; C:\WINDOWS\system32\qmgr.dll [409088 2008-04-15] (Корпорация Майкрософт) R2 Dhcp; C:\WINDOWS\System32\dhcpcsvc.dll [126464 2008-04-15] (Корпорация Майкрософт) S3 dmadmin; C:\WINDOWS\System32\dmadmin.exe [224768 2008-04-15] (Корпорация Microsoft и VERITAS Software) R2 dmserver; C:\WINDOWS\System32\dmserver.dll [24064 2008-04-15] (Корпорация Майкрософт) R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [45568 2008-04-15] (Корпорация Майкрософт) R2 D_Link_DWA-125; C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe [126976 2012-07-17] (Wireless Service) [File not signed] R2 D_Link_DWA-125_WPS; C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe [53248 2010-07-12] () [File not signed] S3 EhttpSrv; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [33584 2011-01-14] (ESET) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [810144 2011-01-14] (ESET) R2 Eventlog; C:\WINDOWS\system32\services.exe [109056 2008-04-15] (Корпорация Майкрософт) R2 Ext2Mgr; C:\Program Files\Ext2Fsd\Ext2Mgr.exe [1211536 2011-02-05] (Ext2Fsd Group (www.ext2fsd.com)) [File not signed] R3 FastUserSwitchingCompatibility; C:\WINDOWS\System32\shsvcs.dll [135680 2008-04-15] (Корпорация Майкрософт) R2 fsproflt; C:\WINDOWS\system32\fsproflt.exe [73392 2009-05-03] (FSPro Labs) R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1435984 2013-05-15] (LogMeIn Inc.) R2 hasplms; C:\WINDOWS\system32\hasplms.exe [2869760 2009-04-21] (Aladdin Knowledge Systems Ltd.) S3 idsvc; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [741376 2006-10-30] (Microsoft Corporation) [File not signed] S3 ImapiService; C:\WINDOWS\system32\imapi.exe [150528 2008-04-15] (Корпорация Майкрософт) S3 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2008-04-15] (Корпорация Майкрософт) S4 NetDDE; C:\WINDOWS\system32\netdde.exe [113664 2008-04-15] (Корпорация Майкрософт) S4 NetDDEdsdm; C:\WINDOWS\system32\netdde.exe [113664 2008-04-15] (Корпорация Майкрософт) R3 Netman; C:\WINDOWS\System32\netman.dll [198144 2008-04-15] (Корпорация Майкрософт) R3 Nla; C:\WINDOWS\System32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт) S3 NtmsSvc; C:\WINDOWS\system32\ntmssvc.dll [436736 2008-04-15] (Корпорация Майкрософт) R2 PlugPlay; C:\WINDOWS\system32\services.exe [109056 2008-04-15] (Корпорация Майкрософт) S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [141824 2008-04-15] (Корпорация Майкрософт) S3 Samsung UPD Service2; C:\WINDOWS\system32\SUPDSvc2.exe [129536 2012-04-06] (Samsung Electronics) S3 SCardSvr; C:\WINDOWS\System32\SCardSvr.exe [96768 2008-04-15] (Корпорация Майкрософт) R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [193024 2008-04-15] (Корпорация Майкрософт) S3 seclogon; C:\WINDOWS\System32\seclogon.dll [18944 2008-04-15] (Корпорация Майкрософт) R2 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [330752 2008-04-15] (Корпорация Майкрософт) R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [135680 2008-04-15] (Корпорация Майкрософт) R2 srservice; C:\WINDOWS\system32\srsvc.dll [171008 2008-04-15] (Корпорация Майкрософт) R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.) R2 stisvc; C:\WINDOWS\system32\wiaservc.dll [333824 2008-04-15] (Корпорация Майкрософт) S3 SysmonLog; C:\WINDOWS\system32\smlogsvc.exe [91648 2008-04-15] (Корпорация Майкрософт) R3 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [249856 2008-04-15] (Корпорация Майкрософт) R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH) R3 TermService; C:\WINDOWS\System32\termsrv.dll [295936 2008-04-15] (Корпорация Майкрософт) [File not signed] R2 Themes; C:\WINDOWS\System32\shsvcs.dll [135680 2008-04-15] (Корпорация Майкрософт) S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [73216 2008-04-15] (Корпорация Майкрософт) S3 upnphost; C:\WINDOWS\System32\upnphost.dll [186368 2008-04-15] (Корпорация Майкрософт) S3 VSS; C:\WINDOWS\System32\vssvc.exe [290304 2008-04-15] (Корпорация Майкрософт) R2 W32Time; C:\WINDOWS\system32\w32time.dll [175616 2008-04-15] (Корпорация Майкрософт) R2 winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [145408 2008-04-15] (Корпорация Майкрософт) S3 Wmi; C:\WINDOWS\System32\advapi32.dll [687616 2008-04-15] (Корпорация Майкрософт) S3 WmiApSrv; C:\WINDOWS\system32\wbem\wmiapsrv.exe [126464 2008-04-15] (Корпорация Майкрософт) R2 WZCSVC; C:\WINDOWS\System32\wzcsvc.dll [483328 2008-04-15] (Корпорация Майкрософт) S2 RTLDHCPService; C:\Program Files\REALTEK\USB Wireless LAN Utility\RTLDHCP.exe [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 ACPI; C:\WINDOWS\System32\DRIVERS\ACPI.sys [188288 2008-04-15] (Корпорация Майкрософт) S4 ACPIEC; C:\WINDOWS\system32\Drivers\ACPIEC.sys [11776 2008-04-15] (Корпорация Майкрософт) R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2016-01-25] (Cisco Systems, Inc.) [File not signed] R2 aksfridge; C:\WINDOWS\system32\drivers\aksfridge.sys [352256 2009-01-16] (Aladdin Knowledge Systems Ltd.) S3 akshasp; C:\WINDOWS\System32\DRIVERS\akshasp.sys [327168 2006-11-22] (Aladdin Knowledge Systems Ltd.) S3 aksusb; C:\WINDOWS\System32\DRIVERS\aksusb.sys [100096 2006-11-22] (Aladdin Knowledge Systems Ltd.) R0 amdide; C:\WINDOWS\System32\DRIVERS\amdide.sys [9096 2007-10-12] (Advanced Micro Devices) R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2006-06-19] (Advanced Micro Devices) [File not signed] R2 ANPD; C:\WINDOWS\system32\ANPD.sys [29411 2014-06-04] () [File not signed] S3 bcm; C:\WINDOWS\System32\DRIVERS\drxvi314.sys [331264 2010-10-20] (Beceem communications pvt ltd.) [File not signed] S3 bcmbusctr; C:\WINDOWS\System32\DRIVERS\BcmBusCtr.sys [48512 2010-10-20] (Beceem communications pvt ltd.) [File not signed] S3 BT_8x8; C:\WINDOWS\system32\BT_8x8.SYS [3264 2010-07-01] () [File not signed] R2 Consult; C:\WINDOWS\system32\Drivers\Consult.sys [3008 1997-02-04] (ConsultantPlus) S4 dmboot; C:\WINDOWS\System32\drivers\dmboot.sys [799872 2008-04-15] (Корпорация Microsoft и VERITAS Software) R0 dmio; C:\WINDOWS\System32\drivers\dmio.sys [153600 2008-04-15] (Корпорация Microsoft и VERITAS Software) R3 dtultrascsibus; C:\WINDOWS\System32\DRIVERS\dtultrascsibus.sys [25104 2014-12-29] (Disc Soft Ltd) R2 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [141264 2010-12-21] (ESET) R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [115008 2010-12-21] (ESET) R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [94872 2010-12-21] (ESET) R1 Ext2Fsd; C:\WINDOWS\system32\Drivers\Ext2Fsd.sys [686360 2011-07-09] (www.ext2fsd.com) R1 Fips; C:\WINDOWS\system32\Drivers\Fips.sys [44544 2008-04-15] (Корпорация Майкрософт) R0 FSProFilter; C:\WINDOWS\System32\Drivers\FSPFltd.sys [43792 2008-06-05] (FSPro Labs) R0 Ftdisk; C:\WINDOWS\System32\DRIVERS\ftdisk.sys [125440 2008-04-15] (Корпорация Майкрософт) R3 hamachi; C:\WINDOWS\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [587776 2009-07-09] (Aladdin Knowledge Systems Ltd.) S2 haspflt; C:\WINDOWS\System32\Drivers\haspflt.sys [29024 2003-10-10] () [File not signed] R2 Haspnt; C:\WINDOWS\system32\drivers\Haspnt.sys [47616 2009-01-30] (Aladdin Knowledge Systems) [File not signed] R2 hl_mull; C:\WINDOWS\System32\drivers\hl_mull.SYS [67712 2011-09-19] () [File not signed] R1 i8042prt; C:\WINDOWS\System32\DRIVERS\i8042prt.sys [53120 2008-04-15] (Корпорация Майкрософт) R0 isapnp; C:\WINDOWS\System32\DRIVERS\isapnp.sys [37504 2008-04-15] (Корпорация Майкрософт) R1 Kbdclass; C:\WINDOWS\System32\DRIVERS\kbdclass.sys [24832 2008-04-15] (Корпорация Майкрософт) S1 kbdhid; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [14720 2008-04-14] (Корпорация Майкрософт) S3 Modem; C:\WINDOWS\system32\Drivers\Modem.sys [30208 2008-04-15] (Корпорация Майкрософт) S3 ModemLTE; C:\WINDOWS\System32\DRIVERS\usb8023.sys [12800 2008-04-15] (Microsoft Corporation) R1 Mouclass; C:\WINDOWS\System32\DRIVERS\mouclass.sys [23296 2008-04-15] (Корпорация Майкрософт) R3 mouhid; C:\WINDOWS\System32\DRIVERS\mouhid.sys [12160 2001-10-19] (Корпорация Майкрософт) R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2006-02-26] () S3 Parport; C:\WINDOWS\System32\DRIVERS\parport.sys [80128 2008-04-15] (Корпорация Майкрософт) S2 ParVdm; C:\WINDOWS\system32\Drivers\ParVdm.sys [6912 2008-04-15] (Корпорация Майкрософт) R0 PCI; C:\WINDOWS\System32\DRIVERS\pci.sys [68480 2008-04-15] (Корпорация Майкрософт) R0 PCIIde; C:\WINDOWS\System32\DRIVERS\pciide.sys [3328 2008-04-15] (Корпорация Майкрософт) S4 Pcmcia; C:\WINDOWS\system32\Drivers\Pcmcia.sys [120192 2008-04-15] (Корпорация Майкрософт) R1 redbook; C:\WINDOWS\System32\DRIVERS\redbook.sys [58368 2008-04-15] (Корпорация Майкрософт) S3 rt2870; C:\WINDOWS\System32\DRIVERS\rt2870.sys [2811536 2014-07-04] (MediaTek Inc.) S3 RT73; C:\WINDOWS\System32\DRIVERS\Dr71WU.sys [459520 2008-01-15] (Ralink Technology, Corp.) S3 rtl8185; C:\WINDOWS\System32\DRIVERS\rtl8185.sys [308864 2008-06-06] (Realtek Semiconductor Corporation ) [File not signed] R1 Serial; C:\WINDOWS\System32\DRIVERS\serial.sys [65024 2008-04-15] (Корпорация Майкрософт) R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [473656 2012-04-07] (Duplex Secure Ltd.) R0 sr; C:\WINDOWS\System32\DRIVERS\sr.sys [73472 2008-04-15] (Корпорация Майкрософт) S3 StillCam; C:\WINDOWS\System32\DRIVERS\serscan.sys [6912 2001-10-19] (Корпорация Майкрософт) R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361344 2008-04-15] (Microsoft Corporation) [File not signed] R2 tifsfilter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [39264 2008-10-15] (Acronis) R1 VD_FileDisk; C:\WINDOWS\system32\Drivers\VD_FileDisk.sys [15872 2006-01-13] (Flint Incorporation) R0 VolSnap; C:\WINDOWS\system32\Drivers\VolSnap.sys [51968 2008-04-15] (Корпорация Майкрософт) R3 vusbbus; C:\WINDOWS\System32\DRIVERS\vusbbus.sys [11520 2005-09-22] (Chingachguk & Denger2k) [File not signed] S3 C7xxUSB; system32\DRIVERS\C7xUSBX3.sys [X] S2 EAPPkt; system32\DRIVERS\EAPPkt.sys [X] S4 IntelIde; no ImagePath S3 lmimirr; system32\DRIVERS\lmimirr.sys [X] U1 WS2IFSL; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Three Months Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-04-01 14:08 - 2016-04-01 14:10 - 00034887 _____ C:\Documents and Settings\Leda-11\Рабочий стол\FRST.txt 2016-04-01 14:07 - 2016-04-01 14:10 - 00000000 ____D C:\FRST 2016-04-01 14:00 - 2016-04-01 14:00 - 01725440 _____ (Farbar) C:\Documents and Settings\Leda-11\Рабочий стол\FRST.exe 2016-04-01 13:28 - 2016-04-01 13:27 - 00008374 _____ C:\Documents and Settings\Leda-11\Рабочий стол\AdwCleaner[S1].txt 2016-04-01 13:25 - 2016-04-01 13:49 - 00000000 ____D C:\AdwCleaner 2016-04-01 13:24 - 2016-04-01 13:24 - 03102720 _____ C:\Documents and Settings\Leda-11\Рабочий стол\adwcleaner_5.108.exe 2016-04-01 13:06 - 2016-04-01 13:06 - 00169876 _____ C:\Documents and Settings\Leda-11\Рабочий стол\BETTER_CALL_SAUL как расшифровать данные.htm 2016-04-01 13:06 - 2016-04-01 13:06 - 00000000 ____D C:\Documents and Settings\Leda-11\Рабочий стол\BETTER_CALL_SAUL как расшифровать данные_files 2016-04-01 13:01 - 2016-04-01 13:03 - 00000000 ____D C:\Documents and Settings\Leda-11\Рабочий стол\Новая папка (2) 2016-03-31 16:43 - 2016-03-31 16:39 - 186710376 _____ C:\Documents and Settings\Leda-11\Рабочий стол\ppk70aoq.exe 2016-03-31 16:24 - 2016-03-31 16:25 - 02356344 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-03-31 16:18 - 2016-04-01 09:52 - 00000000 ____D C:\Documents and Settings\Leda-11\Рабочий стол\Новая папка 2016-03-31 16:18 - 2016-03-31 16:18 - 00032902 _____ C:\Documents and Settings\Leda-11\Рабочий стол\cc_20160331_161822.reg 2016-03-31 16:01 - 2016-03-31 16:01 - 00000020 ___SH C:\Documents and Settings\NetworkService\ntuser.ini 2016-03-31 16:01 - 2016-03-31 16:01 - 00000020 ___SH C:\Documents and Settings\LocalService\ntuser.ini 2016-03-31 16:00 - 2016-04-01 13:47 - 00000178 ___SH C:\Documents and Settings\Leda-11\ntuser.ini 2016-03-31 15:40 - 2016-03-31 15:40 - 03932214 _____ C:\Documents and Settings\Leda-11\Application Data\296C4C64296C4C64.bmp 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README9.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README8.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README7.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README6.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README5.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README4.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README3.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README2.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README10.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\Leda-11\Рабочий стол\README1.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README9.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README8.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README7.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README6.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README5.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README4.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README3.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README2.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README10.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 00002714 _____ C:\Documents and Settings\All Users\Рабочий стол\README1.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README9.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README8.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README7.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README6.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README5.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README4.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README3.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README2.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README10.txt 2016-03-31 14:29 - 2016-03-31 14:29 - 00002714 _____ C:\README1.txt 2016-03-31 14:28 - 2016-04-01 13:08 - 00000000 __SHD C:\Documents and Settings\All Users\Application Data\Windows 2016-03-31 14:03 - 2016-03-31 15:27 - 00039296 _____ C:\Documents and Settings\Leda-11\Рабочий стол\1+j9r4kP8vmga7w6l0MpByXBIx5F3lqachRFZ4Z4IrDAqEC1BbKJZq3izGXoWr02yB4M7afmYT+SIh8--WRpvg==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 13:48 - 2016-03-31 15:27 - 00039296 _____ C:\Documents and Settings\Leda-11\Рабочий стол\B1haDghmi1hsvqjP71z3OfxOGd2UJl2WMTPvcG7Hu33Ut+Sdgivipy8rsiDDdsjaOqckDBf8SpLONaB0n-3c9Q==.1C739006E0FC262D12B4.better_call_saul 2016-03-26 13:19 - 2016-03-31 15:27 - 00057792 _____ C:\Documents and Settings\Leda-11\Рабочий стол\ARLAgk8YN83hhHyzbCHKnSFKzhuwxjQvvh0Y2QTpK3s=.1C739006E0FC262D12B4.better_call_saul 2016-03-24 12:25 - 2016-03-24 12:25 - 05306560 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe 2016-02-02 13:33 - 2016-01-08 11:51 - 00191200 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudmdm.sys 2016-02-02 13:33 - 2016-01-08 11:51 - 00099296 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudbus.sys 2016-01-25 13:34 - 2014-07-04 18:34 - 02811536 _____ (MediaTek Inc.) C:\WINDOWS\system32\Drivers\rt2870.sys 2016-01-25 13:34 - 2014-06-24 18:30 - 00091412 _____ C:\WINDOWS\system32\Drivers\FW_7662.bin 2016-01-25 13:34 - 2014-03-15 06:06 - 00020626 _____ C:\WINDOWS\system32\Drivers\Patch_7662.bin 2016-01-25 13:06 - 2016-01-25 13:06 - 00021361 _____ (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\AegisP.sys ==================== Three Months Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-04-01 14:10 - 2009-05-08 13:46 - 00000000 ____D C:\Documents and Settings\Leda-11\Рабочий стол 2016-04-01 14:07 - 2009-07-24 11:43 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Загрузки 2016-04-01 14:05 - 2013-02-13 09:49 - 00001056 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-1708537768-682003330-1006UA.job 2016-04-01 13:48 - 2008-08-30 21:33 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-04-01 13:47 - 2008-08-30 21:33 - 00032610 _____ C:\WINDOWS\SchedLgU.Txt 2016-04-01 13:46 - 2009-03-08 12:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ICQ 2016-04-01 13:46 - 2008-08-31 00:21 - 00000000 ___RD C:\Documents and Settings\All Users\Главное меню\Программы 2016-04-01 13:25 - 2013-06-05 15:16 - 00000896 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-04-01 13:04 - 2016-02-29 15:30 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-04-01 10:13 - 2009-09-23 13:40 - 00000000 ____D C:\Program Files\Opus 2016-04-01 10:11 - 2015-10-20 15:11 - 00000476 _____ C:\WINDOWS\Tasks\Обновление Браузера Яндекс.job 2016-04-01 09:52 - 2011-01-12 15:18 - 00000000 __SHD C:\Documents and Settings\Leda-11\PrivacIE 2016-04-01 09:50 - 2009-05-08 14:14 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\WinRAR 2016-04-01 08:44 - 2015-11-24 14:44 - 00000476 _____ C:\WINDOWS\Tasks\Обновление Браузера Яндекс .job 2016-03-31 16:43 - 2012-12-22 10:01 - 00000000 ____D C:\Documents and Settings\Leda-11\Doctor Web 2016-03-31 16:34 - 2008-08-31 00:22 - 01251006 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-03-31 16:34 - 2008-04-15 18:00 - 00543896 _____ C:\WINDOWS\system32\perfh019.dat 2016-03-31 16:34 - 2008-04-15 18:00 - 00102590 _____ C:\WINDOWS\system32\perfc019.dat 2016-03-31 16:24 - 2008-08-30 21:51 - 00524288 _____ C:\WINDOWS\system32\config\ACEEvent.evt 2016-03-31 16:23 - 2008-08-31 00:12 - 00000218 __RSH C:\boot.ini 2016-03-31 16:23 - 2008-04-15 18:00 - 00000629 _____ C:\WINDOWS\win.ini 2016-03-31 16:23 - 2008-04-15 18:00 - 00000227 _____ C:\WINDOWS\system.ini 2016-03-31 16:04 - 2011-01-12 10:32 - 00000000 ____D C:\Documents and Settings\LogMeInRemoteUser 2016-03-31 16:04 - 2008-08-30 21:33 - 00000000 ____D C:\Documents and Settings\Admin 2016-03-31 16:01 - 2008-08-30 21:33 - 00000000 __SHD C:\Documents and Settings\NetworkService 2016-03-31 16:01 - 2008-08-30 21:33 - 00000000 __SHD C:\Documents and Settings\LocalService 2016-03-31 16:00 - 2009-05-08 13:46 - 00000000 ____D C:\Documents and Settings\Leda-11 2016-03-31 15:41 - 2012-12-25 10:03 - 00000000 __SHD C:\Documents and Settings\Leda-11\IECompatCache 2016-03-31 15:40 - 2015-02-05 09:40 - 00045360 _____ C:\l4Ho78FmGzoCKUuqKkQMAYw0AFkl2P1lmzXv2GNYxJ0=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:40 - 2010-09-06 09:12 - 00000960 _____ C:\4n2xiCzuA86Ik0gdSnqCA8dkQON49OhABPpGCc1G2T0=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:40 - 2009-08-18 21:34 - 00000400 _____ C:\7rf4pVJ53JrK60VkY3skQNCsdegVR+k7JauWf4DZrwg=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:40 - 2009-06-18 12:40 - 00019536 _____ C:\kLnqfJJ8vzPh7o-R5Ni3sJ74VXQwLeFU6WgyWiKx58Y=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:40 - 2009-05-11 10:17 - 00000000 ____D C:\1Cv77 2016-03-31 15:40 - 2008-08-31 00:21 - 00000000 ____D C:\Documents and Settings\All Users\Рабочий стол 2016-03-31 15:40 - 2008-04-15 18:00 - 00005344 ___SH C:\OtFoO8EyCGbWbhS6iO-HDP3pybIdNhT91R5BINR-xik=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:40 - 2007-08-12 08:59 - 00375440 _____ C:\eug9Ai5G3L5LH9EfOZOd556e9B5Uxh93NgbFroV7jcs=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-05-11 13:13 - 00071040 _____ C:\Documents and Settings\Admin\Рабочий стол\qm5XvpYrpMTBlW+0gFwnn-23PqRLa4oEve4zrb+liO0-YV+tPY64F1fgycpTJMZMKQVYjl4KJakuIYBmpfItfES8QqqTCWpYBH6qFHR2x1UW-vTfoDIvdFOsi6IvFUhH41O3i8L0WATOw+K1wyevow==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-05-08 13:24 - 00000928 _____ C:\Documents and Settings\Admin\Рабочий стол\VyF69S1e-QmT9kVfwBov0rW2+WBQUyNNE3PGWkdMCMto5dMFYUyi4zFN62ayHXSZ.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-05-08 10:57 - 00016256 _____ C:\Documents and Settings\Admin\Рабочий стол\myR2SWpVvswBUHyaNR40KMQpqPhp2fAY-fEYwvXKi9+SE8+DRpcdx+GnlPLIhyGy.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-05-08 10:51 - 00016288 _____ C:\Documents and Settings\Admin\Рабочий стол\Vs1wC+U6aExjI9icTmnu2RRy+4G1oWEyWL42GWpJk+uOFmreNEdF+hp6OgPZI89z.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-04-07 14:31 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Crack Kompas V8 & SW2006 2016-03-31 15:39 - 2009-03-23 18:58 - 00094080 _____ C:\Documents and Settings\Admin\Рабочий стол\z9FeXAKrDvrfcFDT6QUvZvt4ANTKFyqsr7xqlT+y4jdGqsnwSa-taMcfytiWULpX.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-03-22 15:11 - 00020352 _____ C:\Documents and Settings\Admin\Рабочий стол\3LwaKbRPLBjIba5zm9wkKXmjvV79iHg7Vqu1J63kiFPL-J-R0CF6XDvi3ZIZq2kw.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-03-19 11:24 - 00025472 _____ C:\Documents and Settings\Admin\Рабочий стол\RAxQ2LXzKdRRt1etgsBt6PPGYgXIlFd9NItSaDL6x584hj4miRvLsQYjGROHXqu6.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-03-18 14:15 - 00030592 _____ C:\Documents and Settings\Admin\Рабочий стол\POxtQ+V630pms-W3t+V22ad2uoqISK+RUQo8T-bugsCrBZbvuvO3OBtau8erj+n+EKw45w6CWFcKWfHdyZOveg==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-03-08 12:23 - 00000000 ____D C:\Documents and Settings\Admin\Application Data\ICQ 2016-03-31 15:39 - 2009-03-06 14:33 - 00016240 _____ C:\Documents and Settings\Admin\Рабочий стол\4KfkHFB5HbK8x8uq5qE5hAdSFlK2acrVTJnocTZJIxdu0Z450McQ7ZoycQW-fH6NPGMcrnzrhKxFgN7NhPGYqg==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-03-05 17:18 - 00000000 ____D C:\Documents and Settings\Admin\Application Data\QIP.Online 2016-03-31 15:39 - 2009-02-07 18:17 - 00025168 _____ C:\Documents and Settings\Admin\Рабочий стол\bcIo6Mhr7dZdYPIPSp-RO-vDqQSyfdIKsjxqLc7-4zqgIo9R3rLblFmRlsfXIwQc.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2009-01-29 13:17 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Потолки для сайта 2016-03-31 15:39 - 2009-01-20 19:47 - 00000544 _____ C:\Documents and Settings\Admin\Рабочий стол\gky9uZ4R61+d4q53b9TK97vbP-Cuxou6r1zY+p7EHZU=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-30 11:22 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\ПОСТАВЩИКИ 2016-03-31 15:39 - 2008-12-24 20:05 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Диллеры 2016-03-31 15:39 - 2008-12-24 12:51 - 00026496 _____ C:\Documents and Settings\Admin\Рабочий стол\-Fi-fROnEwOydoR-6CnEGrl2F-jvZLQDEm9cjzOmG+823BD0The4NZCB4e-6aKSB.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-24 12:45 - 00016240 _____ C:\Documents and Settings\Admin\Рабочий стол\c5W2iPtpilcvgbt6TfC9ICeYuohX5L9Fq5gp3q+4tno1+LMlJKMbbxgkWPxIdco0.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-19 19:09 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\КОНТРОЛЬ ПРОИЗВОДСТВА 2016-03-31 15:39 - 2008-12-14 15:01 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\AutoCad2008 2016-03-31 15:39 - 2008-12-10 17:37 - 00959328 _____ C:\Documents and Settings\Admin\Рабочий стол\UN9NjU4BTCxilJz3-7G7xAscuRnitB-D3nYt9Q0Mwtk=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-06 15:01 - 00000560 ____H C:\Documents and Settings\Admin\Рабочий стол\ADEp62p4SWbPKCDUcmuio9O14TSqiRV3u18DC4gxIhz4C-2eiOj1HXKPZJTY8sC6.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-06 11:17 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\прогрSpB 2016-03-31 15:39 - 2008-12-05 19:16 - 00220384 _____ C:\Documents and Settings\Admin\Рабочий стол\9Pzy7yBRPoy8ncv20pgmrR3gaj0bswBIuJbTEZRWnwZgX00Qw-XrmKFhvh5+I7mj.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-04 18:33 - 00026496 _____ C:\Documents and Settings\Admin\Рабочий стол\STiH-qmsmzUT9B5B6nDO9HzQorYNvM2fe1BGKTpxSuQC4q1+9awX8xYQmCq69swO.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-02 10:17 - 00042368 _____ C:\Documents and Settings\Admin\Рабочий стол\n6+UpqnbMEvJkCplbBcIJkvt95A8Os9mlhO8L+75VDbTZBXQOaqoCpB+ZZtZ46ZfA5C0UymsonuKaIeRZVvFpA==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-12-01 20:27 - 00388336 _____ C:\Documents and Settings\Admin\Рабочий стол\rmov+Wdr3sY6WTkZ-yijWE3G1qARmLAGkA4G18UACEGfkIjtUNoGTFmottAbpJdU.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-11-18 10:32 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Звездное небо 2016-03-31 15:39 - 2008-11-17 13:18 - 00094080 _____ C:\Documents and Settings\Admin\Рабочий стол\-VOTGAc0oRTkr1bk0ARvYng3KGkI9wZnt3wV6gMDjKZLe3nqbGCMSYHxxl4WFUrD.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-11-12 20:36 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Никита 2016-03-31 15:39 - 2008-11-05 13:19 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\re1 2016-03-31 15:39 - 2008-11-05 12:17 - 32140384 _____ C:\Documents and Settings\Admin\Рабочий стол\pPyxfReKZbZTtiRKmErHKG4ehQK37nmoIpp7NrhAkdYJdyayFsmtZcErqOvLbmdK.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-11-05 12:09 - 08486864 _____ C:\Documents and Settings\Admin\Рабочий стол\Ob+kQhnhKpRr2+sNWucl9w==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-10-21 09:34 - 00792448 _____ C:\Documents and Settings\Admin\Рабочий стол\nsZRVZYYtCkON6LaW7qjzg==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-10-14 14:40 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Лена Заковоротная 2016-03-31 15:39 - 2008-10-14 13:08 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Доверенности 2016-03-31 15:39 - 2008-10-07 11:21 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\документы сканера 2016-03-31 15:39 - 2008-09-12 16:51 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Консультант + 2016-03-31 15:39 - 2008-09-12 16:00 - 00000000 ____D C:\ConsUserData 2016-03-31 15:39 - 2008-09-10 12:16 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Бухгалтерия 2016-03-31 15:39 - 2008-09-10 11:00 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Партнеры 2016-03-31 15:39 - 2008-08-30 22:03 - 00000560 _____ C:\Documents and Settings\Admin\cADx2b--cRr+a0byGa1b3-5BgvjOttHoKmZYtZllcIl8qujSqDeFEsgm-Zl+JWDX.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-08-30 21:44 - 00000000 ___HD C:\ASUS.BAK 2016-03-31 15:39 - 2008-08-30 21:33 - 04456832 ____H C:\Documents and Settings\Admin\rzfroEnhqodTR-Z4koKBPrfoqQS2PDO49qR09yQfVM8=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-08-30 21:33 - 00001408 ____H C:\Documents and Settings\Admin\QxIbOUu4dvmEX6Sy4mwSRwfzq+5gXEddtWEnR2YHLkY=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-08-30 21:33 - 00000576 ___SH C:\Documents and Settings\Admin\GR+3oXA9UNjUClmkU0cVbVr4lBaqCVFaG+MJFgCbzLk=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:39 - 2008-08-30 21:33 - 00000000 ___RD C:\Documents and Settings\Admin\Избранное 2016-03-31 15:39 - 2008-08-30 21:33 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол 2016-03-31 15:38 - 2009-01-12 18:01 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\НАТАША 2016-03-31 15:38 - 2008-12-06 16:14 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\КОМПАС-3D V8 2016-03-31 15:38 - 2008-10-08 15:47 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Клиент 2016-03-31 15:37 - 2015-04-13 08:36 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir 2016-03-31 15:37 - 2015-02-04 13:47 - 00000000 ____D C:\Documents and Settings\Leda-11\.android 2016-03-31 15:37 - 2014-06-04 18:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\CyberTank 2016-03-31 15:37 - 2013-05-11 10:54 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\nloader 2016-03-31 15:37 - 2012-12-11 15:27 - 00000000 __SHD C:\Documents and Settings\All Users\Svbwswqizvg 2016-03-31 15:37 - 2012-04-07 15:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite 2016-03-31 15:37 - 2011-04-24 22:07 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\VKSaver 2016-03-31 15:37 - 2011-01-12 10:28 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\LogMeIn 2016-03-31 15:37 - 2009-11-05 16:24 - 00000000 ____D C:\Documents and Settings\All Users\Anyplace Control 4 2016-03-31 15:37 - 2009-05-08 13:46 - 00000576 ___SH C:\Documents and Settings\Leda-11\YYdNDtDl3eEywe-6dgCi9TEw3xHnHYws2W8TwwTMIcE=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:37 - 2009-05-08 13:22 - 00000000 ___RD C:\Documents and Settings\Admin\Рабочий стол\Leda-2 на 192.168.255.2 2016-03-31 15:37 - 2009-05-02 10:27 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Потолки 2016-03-31 15:37 - 2009-04-23 09:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir 2016-03-31 15:37 - 2008-09-10 11:04 - 00000000 ____D C:\Documents and Settings\Admin\Рабочий стол\Счета 2016-03-31 15:37 - 2008-08-31 00:30 - 00287104 ____H C:\Documents and Settings\Default User\uEk90Vb19ZhOEg0PKylkNHJ9pQa53NdWos2xRhEwmbM=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:37 - 2008-08-31 00:29 - 00000000 __SHD C:\Documents and Settings\All Users\DRM 2016-03-31 15:37 - 2008-08-31 00:21 - 00000000 ___HD C:\Documents and Settings\Default User\Шаблоны 2016-03-31 15:37 - 2008-08-31 00:12 - 00000000 ___HD C:\Documents and Settings\Default User 2016-03-31 15:37 - 2008-08-30 22:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\FLEXnet 2016-03-31 15:37 - 2008-08-30 21:33 - 00000000 ___HD C:\Documents and Settings\Admin\Шаблоны 2016-03-31 15:36 - 2012-04-07 15:59 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\DAEMON Tools Lite 2016-03-31 15:35 - 2015-07-23 09:20 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\.oit 2016-03-31 15:35 - 2015-01-29 11:18 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\Samsung 2016-03-31 15:35 - 2012-12-07 19:55 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\TeamViewer 2016-03-31 15:35 - 2012-09-21 13:51 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\nloader 2016-03-31 15:35 - 2012-09-13 10:58 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\Skype 2016-03-31 15:35 - 2010-07-01 12:36 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\MxBoost 2016-03-31 15:35 - 2010-03-21 12:15 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\Yandex 2016-03-31 15:35 - 2009-06-06 12:59 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\WebMoney 2016-03-31 15:35 - 2009-05-08 14:14 - 00000000 ____D C:\Documents and Settings\Leda-11\Application Data\QIP.Online 2016-03-31 15:33 - 2012-09-10 14:21 - 00033664 _____ C:\Documents and Settings\Leda-11\Мои документы\plaDlsWvk-18iMIG73bsYCLddVN31asOlMDPImwyyPnSnt-3-g2CazKfCwr6zv7y.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2011-05-16 13:08 - 00059264 _____ C:\Documents and Settings\Leda-11\Мои документы\tJAa6zc+xESZgYXec506zs4BFArTSTEha6FsdJuj-P2UkbKmljuhwBQSswdUIWu0.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2011-05-13 13:23 - 00007456 _____ C:\Documents and Settings\Leda-11\Мои документы\nu5YuVepV3taUgMLNDgl9p0A0wPIyIr9IsHsuSctl-sBs0Tth8abufPgyGmUx2r2.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2011-03-20 14:09 - 00018960 _____ C:\Documents and Settings\Leda-11\Мои документы\l+UanilcMVH806NNpZ6F9hSfsCMdLjfI-tA6-jwRGns=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2010-04-03 16:57 - 00029360 _____ C:\Documents and Settings\Leda-11\Мои документы\0iBWJVon4CFCSlrvaViCZwp2X1OO9TnZglZzDq5RUnU=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2010-02-28 15:41 - 00019184 _____ C:\Documents and Settings\Leda-11\Мои документы\9Ecp6C5Wn9KNeLWYRh9McxZWXuoKwB939xCEFkOfIpJSum0S2MUlCyp64xIpzXSa.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2010-01-21 16:29 - 00029024 _____ C:\Documents and Settings\Leda-11\Мои документы\UICXCiiyhxto26L5eOwnaRDauDDetTSdKo8oPxFBlfCber4kfxmjAap61negC0he.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-11-30 12:50 - 00025984 _____ C:\Documents and Settings\Leda-11\Мои документы\+LaWHVYsUEdfr5kJEfvXdKwN3xHsAEasQ18I6L5RTls=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-10-12 13:18 - 01805472 _____ C:\Documents and Settings\Leda-11\Мои документы\y7ximpMS8Qje4qLAJprtPyzIzgeDp8ZEhcWnjXJmcTg=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-09-28 18:06 - 00004400 _____ C:\Documents and Settings\Leda-11\Мои документы\UUwS1AMGH1f8OK2VIDAaVQ==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-09-24 19:29 - 00018304 _____ C:\Documents and Settings\Leda-11\Мои документы\xbDc7tcP3HcWuFQyHhnN+YAENzKTwbx7-nV4iuFcDlI=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-08-05 13:50 - 00023984 _____ C:\Documents and Settings\Leda-11\Мои документы\hhCCLbjW9wB2BLD5GYxpqzQ0HJRB9EiJB3LCLJpjJpuZ6aoNhmpruitNSwIbTNDC.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-08-05 13:44 - 00682752 _____ C:\Documents and Settings\Leda-11\Мои документы\3sr86VXhsnhT+B9JisssFYtQ3iw8ucMlt6oNLtfFdY74mNBm8Myy3cxB1VvSngCL.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-08-05 12:06 - 10046624 _____ C:\Documents and Settings\Leda-11\Мои документы\AMYZbQ0U71J5hZVhtsU+-TFfzklwnWx41G6GhN9f87uUZGe8dszfHFJoWLpcG6OIbIf4eJ5Uf3tDf517ftkHNA==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-07-21 19:39 - 00089472 _____ C:\Documents and Settings\Leda-11\Мои документы\c1dOp6PRG63+7F7WsfrKzo7PHOR6NvZIGKk9uZJZcAotWp20ZKUaIOPXXL8hahXF.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-07-21 19:39 - 00028544 _____ C:\Documents and Settings\Leda-11\Мои документы\lzU+oGQg0Ejng5XP2OGUGnqEGhUSY2EEb41Q+xNf+Ys=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-07-17 15:14 - 00157344 _____ C:\Documents and Settings\Leda-11\Мои документы\wTzH5DM-G4rpVa-sq60ob9ssJKIxdDWmwIZNH18Q3mia8yxKO700CJ9JAZ-wmIqg.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-07-09 13:34 - 00238976 _____ C:\Documents and Settings\Leda-11\Мои документы\NHPCj57FgrkCiBy04-J0EhfTAiUaVHMBrelDSvjdh3yX8LyEt+D0kXlqvMYqqbKF.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-18 18:01 - 00290176 _____ C:\Documents and Settings\Leda-11\Мои документы\3dXEnLMEsFBXJrosFkfvtXJL-Hqo7KW5nob8289MLww=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-18 14:37 - 00000688 _____ C:\Documents and Settings\Leda-11\Мои документы\zupC8HxXRkgIn7l09PIRbQ==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-18 12:22 - 00981920 _____ C:\Documents and Settings\Leda-11\Мои документы\iKHGT+kiMEwkwHoecb7bw1glx25ySQuafR5RcjUoUg4=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-17 16:11 - 00234000 _____ C:\Documents and Settings\Leda-11\Мои документы\b2bU8oDmQ+L+86uBTZVKPUsLrMKT7UPVjM1jT6eqqWQJk0HjAr-lXG9eowgHsGPL.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-17 09:39 - 00024448 _____ C:\Documents and Settings\Leda-11\Мои документы\lnXom3VEl517ih65nGo0Tjutu6RLPrPpN0pZtEe9EI5iO+ZvPiXEajG-67ORs2vx.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-16 16:48 - 00031744 _____ C:\Documents and Settings\Leda-11\Мои документы\AQGCmMC2-M-ihZtq8hxN6gVmSc3tMuRCUDKWfFSujGs=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-16 13:01 - 00024960 _____ C:\Documents and Settings\Leda-11\Мои документы\-gBMiABTPqWgl0sM-NmDRwGWjkrLST2cPI7E-VTv5RtVyCavniq6Bdl510M9EJMaumuJ5HjRcxOMXRtsv8FjZQ==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-16 11:26 - 00024960 _____ C:\Documents and Settings\Leda-11\Мои документы\9FrAnW+ju+9aWKkjTx+tDSblCvSMUBSqMElMiIeoC3Y8ynGVS8UBj1MXIR+qHDBq.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-13 11:18 - 15667104 _____ C:\Documents and Settings\Leda-11\Мои документы\I-ea8aOVocOnWRT0eoRf1VhKizY5+mov6QcLXl5ek45qvSrJfHV7WLppw9prgbZw.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-10 16:24 - 00050048 _____ C:\Documents and Settings\Leda-11\Мои документы\VKtt2UvDTCqtdmZN94G44PLiDsalxLUDVVAcLMNo+w+y0bfH2yZN9DvRCfxB3Un3D7CHEDGs0+fdYCxRJIIKGQ==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-06-09 10:02 - 00105072 _____ C:\Documents and Settings\Leda-11\Мои документы\rQaKZ0k0FHI2b2KaYX4yaA==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 01220480 _____ C:\Documents and Settings\Leda-11\Мои документы\VPVeA49yUKw6T8dlsxs4+4DTpF7BnIerUSdoWCcaxn8=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00374256 _____ C:\Documents and Settings\Leda-11\Мои документы\LgbmaboDmwUVHli439xnUpxAZVttdSwobXRY4zxAXJNdKBZ1DN6kg9fRwc5utjrP.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00045952 _____ C:\Documents and Settings\Leda-11\Мои документы\O-4m5+bbQMJBM7dDTfJ16-fC9TCfpc2n+M-mS8MCCm6aZcqNxhJyl6ehBhtARFsd.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00027520 _____ C:\Documents and Settings\Leda-11\Мои документы\BR0VwTwqH9OFebov-IkMHMR9hlo0sKZ6bNV2z5-sW+H4WHW0XQtAivOpsHqAqESw45J3agZRt3Ifh1gBfLO1uw==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00022912 _____ C:\Documents and Settings\Leda-11\Мои документы\lZLL-YoahmLjDCPYl09JGMiHqEYRCwtlSTnwGwpIYMA031o+xukO8DjO1rT5n4kt.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00022400 _____ C:\Documents and Settings\Leda-11\Мои документы\lBuqmuLk8lDKgS4fSX3peXlbaW2QZAYesaHwdEUlZBPNuvXsNJqfqSjK-7mMeZDD.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00021888 _____ C:\Documents and Settings\Leda-11\Мои документы\yCsXBrSHrWifAGWBK787BPFJV1zsLsgHCGH1QUWNPhIIyEBgGxQWZjtoMHBmGC1rCJCesNyd5GFAiAppDtqlYw==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00021888 _____ C:\Documents and Settings\Leda-11\Мои документы\GeCg5Es7oCTKFiSHpl69UF4nLU20hXgwXDuuv8v4YMjPSQpfxQP5n8j4haZ1TSCK.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-14 15:08 - 00018816 _____ C:\Documents and Settings\Leda-11\Мои документы\4p+P92n7PVWi0-Uz4qLvoNBIIxTmrukG73vcxfqtEAqhld5gmTQfJZOIV6voLGf8tF97W2nxMJhimN5+uaVIVQ==.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:33 - 2009-05-08 13:46 - 00000000 ___RD C:\Documents and Settings\Leda-11\Мои документы 2016-03-31 15:33 - 2009-05-08 13:46 - 00000000 ___RD C:\Documents and Settings\Leda-11\Избранное 2016-03-31 15:32 - 2012-04-06 18:05 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\EasyCeiling 2016-03-31 15:32 - 2011-09-14 10:45 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Maxthon Ru-Board 2010 Edition 2016-03-31 15:27 - 2015-04-17 08:52 - 00000400 _____ C:\Documents and Settings\Leda-11\Рабочий стол\TO4UE4mczO19iPv6u9FmHWj0skmJUoYVi2jGOx969vpuF4rDKzN2i-3SKMnOv1ec.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2014-11-30 12:31 - 00044416 _____ C:\Documents and Settings\Leda-11\Рабочий стол\sI+4zSY70UBnfd7lXPA7OMKL5wju++IuXUg2aCuzqRg=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2011-01-12 10:32 - 00287104 ____H C:\Documents and Settings\LogMeInRemoteUser\eh2wjoCuGit6kBQ1SLK+E3WNVioAWJHHOhFyK0qH+UE=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2011-01-12 10:32 - 00001408 ____H C:\Documents and Settings\LogMeInRemoteUser\dPWn7NwKZxk0YdMdFZLmQywfZUJm8XIf2CB+UW+pLX4=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2011-01-12 10:32 - 00000576 ___SH C:\Documents and Settings\LogMeInRemoteUser\IAzR9j+2GrO7zKAZ2qBJioU+A5leg4cQum1gCyR+BiQ=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2011-01-12 10:32 - 00000000 ___HD C:\Documents and Settings\LogMeInRemoteUser\Шаблоны 2016-03-31 15:27 - 2010-07-01 12:09 - 00000000 __SHD C:\Documents and Settings\LocalService\IETldCache 2016-03-31 15:27 - 2010-06-10 11:53 - 00145792 ___SH C:\Documents and Settings\Leda-11\Рабочий стол\HDZ3izMfFBbLH7RSIZJW-cQ5+1aepyCGRbw76fQR63c=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2009-08-24 16:14 - 00000000 ____D C:\Documents and Settings\Гость\Application Data\ICQ 2016-03-31 15:27 - 2009-08-24 16:13 - 00001408 ____H C:\Documents and Settings\Гость\rFkc7XtNObowpWw8qnwDv473-Z-ydQ7I4gnkRRlBADg=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2009-08-24 16:13 - 00000560 _____ C:\Documents and Settings\Гость\D9QvqPVMiDTVUWzi5kUyF-7KashwUYmzzbhpBhuv47u6t3ymOZ3o1pAY7B12hj0z.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2009-08-24 16:13 - 00000000 ____D C:\Documents and Settings\Гость\Application Data\QIP.Online 2016-03-31 15:27 - 2009-08-24 16:13 - 00000000 ____D C:\Documents and Settings\Гость 2016-03-31 15:27 - 2009-06-05 15:24 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\ЛАРИСА 2016-03-31 15:27 - 2009-06-03 15:26 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Минифото потолков 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ___RD C:\Documents and Settings\Leda-11\Мои документы\Мои видеозаписи 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Производство 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Потолки 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Макеты 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Кулинская 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Друзья 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Двухуровн констр 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Гуля 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Будапешт 2016-03-31 15:27 - 2009-05-14 15:08 - 00000000 ____D C:\Documents and Settings\Leda-11\Мои документы\Бали 2016-03-31 15:27 - 2009-05-08 13:47 - 00000000 ___RD C:\Documents and Settings\Leda-11\Мои документы\Моя музыка 2016-03-31 15:27 - 2009-05-08 13:47 - 00000000 ___RD C:\Documents and Settings\Leda-11\Мои документы\Мои рисунки 2016-03-31 15:27 - 2009-05-08 13:46 - 00000000 ___HD C:\Documents and Settings\Leda-11\Шаблоны 2016-03-31 15:27 - 2008-08-30 21:33 - 00000416 ___SH C:\Documents and Settings\NetworkService\AzXK1C+x4sSgwcie3oviLVJTEFvC+23ueDKNK3YGIKs=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:27 - 2008-08-30 21:33 - 00000416 ___SH C:\Documents and Settings\LocalService\+Fyzga7zBRo80mDByZGqIpDyFpC+xU0-oo6biHD+pvM=.1C739006E0FC262D12B4.better_call_saul 2016-03-31 15:26 - 2015-02-04 13:45 - 00000000 ____D C:\Unified_Android_ToolKit 2016-03-31 15:26 - 2010-04-30 21:19 - 00000000 ____D C:\sane 2016-03-31 15:26 - 2009-02-07 17:47 - 00000000 ____D C:\Np2008w 2016-03-31 09:07 - 2010-07-01 12:43 - 00002302 _____ C:\Documents and Settings\Leda-11\Главное меню\Программы\Google Chrome.lnk 2016-03-30 17:15 - 2015-03-14 14:46 - 00002368 _____ C:\Documents and Settings\Leda-11\Рабочий стол\Yandex.lnk 2016-03-30 10:24 - 2014-06-04 15:06 - 00000000 ____D C:\Program Files\TeamViewer 2016-03-29 08:58 - 2008-04-15 18:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2016-03-24 12:25 - 2012-04-14 10:04 - 00797376 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe 2016-03-24 12:25 - 2011-08-20 18:37 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2016-03-19 11:50 - 2008-11-07 17:07 - 00000000 ____D C:\Program Files\NCSoft 2016-03-19 11:16 - 2014-12-26 12:38 - 00000000 ____D C:\Program Files\SAMSUNG 2016-03-19 11:16 - 2008-08-30 21:44 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2016-03-19 11:14 - 2011-09-14 10:53 - 00000000 ____D C:\Program Files\Yandex 2016-03-19 11:14 - 2011-09-14 10:53 - 00000000 ____D C:\Documents and Settings\All Users\Главное меню\Программы\Яндекс 2016-03-19 11:14 - 2011-09-14 10:53 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Yandex 2016-03-19 11:14 - 2009-05-08 13:46 - 00000000 ___RD C:\Documents and Settings\Leda-11\Главное меню\Программы 2016-03-17 11:45 - 2008-08-31 00:06 - 00000000 ____D C:\WINDOWS\Network Diagnostic 2016-03-12 08:48 - 2012-08-01 09:46 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service ==================== Files in the root of some directories ======= 2012-04-06 18:05 - 2012-04-06 18:05 - 0813992 _____ () C:\Program Files\bak.rar 2009-12-24 18:14 - 2009-12-24 18:14 - 0464015 _____ () C:\Program Files\No-IP.rar 2009-02-03 12:21 - 2009-02-03 12:21 - 0044194 _____ () C:\Program Files\Пасюков №6 от 03.02.09.TIF 2010-06-15 12:05 - 2010-06-15 12:05 - 0000000 _____ () C:\Program Files\Common Files\keylog.txt 2016-03-31 15:40 - 2016-03-31 15:40 - 3932214 _____ () C:\Documents and Settings\Leda-11\Application Data\296C4C64296C4C64.bmp 2010-04-10 17:32 - 2012-03-20 13:59 - 0000600 _____ () C:\Documents and Settings\Leda-11\Application Data\winscp.rnd 2009-05-10 13:55 - 2016-03-31 15:35 - 1045712 ____H () C:\Documents and Settings\Leda-11\Local Settings\Application Data\2w27OHpwbwQcBMMR-6ZdHxzDZzBZd7HIFmyV8na1ywY=.1C739006E0FC262D12B4.better_call_saul 2009-05-27 11:15 - 2016-03-31 15:35 - 0115072 _____ () C:\Documents and Settings\Leda-11\Local Settings\Application Data\6u+yKOT1RP3yLG5O04HmQu8YI6H+GvLQpBdtEHh71+cMja-45euGoV5LkzGGxjhlbMXSDsqOQgnwzqkkM9kURZbG7voUk6VdwuyPFF7sQvY=.1C739006E0FC262D12B4.better_call_saul 2016-01-28 16:40 - 2016-03-31 15:35 - 0085840 _____ () C:\Documents and Settings\Leda-11\Local Settings\Application Data\eVc7y+l20d36V7BGXQIwRcLzt0iaPvTG-v4glw1gm51JQ2ic9d18ACKE4QK71X3w.1C739006E0FC262D12B4.better_call_saul 2010-04-10 17:15 - 2010-06-15 11:50 - 0000600 _____ () C:\Documents and Settings\Leda-11\Local Settings\Application Data\PUTTY.RND ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End of FRST.txt ============================