﻿Лог утилиты random's system information tool 1.12(автор: random/random)
Run by МИХАИЛ 1 at 2016-04-14 20:16:25
Microsoft Windows 7 Ultimate  Service Pack 1
Системный раздел C: размер 3 GB (9%) Свободно 30 GB
Total RAM: 3010 MB (38% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:30, on 14.04.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe
C:\Windows\system32\srvany.exe
C:\Windows\kmsem\KMService.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
C:\Program Files\Mail.Ru\Update Service\mrupdsrv.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
D:\против вирусов\AutoLogger\AVZ\avz.exe
C:\Program Files\Classic Shell\ClassicStartMenu.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\USB Camera\VM331_STI.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ExpressDownloader\TorrentExpress.exe
C:\Program Files\Download Master\dmaster.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe
C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\MailRuUpdater.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\svchost.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\44.4.2403.3\amigo_cr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\amigo.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\servicing\TrustedInstaller.exe
D:\против вирусов\AutoLogger\RSIT\RSIT.exe
D:\против вирусов\AutoLogger\RSIT\МИХАИЛ 1_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fuxio.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.yandex.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.mail.ru/?ieverfix=1&fr=ieverfix_sg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fuxio.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.yandex.ru
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130948636742305387&GUID=00000000-0000-0000-0000-000000000000
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://unblock.ga/files/unblock.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: Спутник@Mail.Ru - {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (file missing)
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: SBCONVERT - {3017FB3E-9A77-4396-88C5-0EC9548FB42F} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
O2 - BHO: SearchPredictObj Class - {389943B0-C3A2-4E69-82CB-8596A84CB3DC} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Спутник@Mail.Ru - {8984B388-A5BB-4DF7-B274-77B879E179DB} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (file missing)
O2 - BHO: MRSearchPlugin - {8E8F97CD-60B5-456F-A201-73065652D099} - C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll
O2 - BHO: IE 4.x-6.x BHO for Download Master - {9961627E-4059-41B4-8E0E-A7D6B3854ADF} - C:\PROGRA~1\DOWNLO~1\dmiehlp.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Визуальные закладки - {C93F72A2-2162-4BBA-A07A-F13663C297A6} - C:\Program Files\Yandex\YandexBarIE\fastdial.dll (file missing)
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O3 - Toolbar: Яндекс.Бар - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\YandexBarIE\yndbar.dll (file missing)
O3 - Toolbar: Спутник@Mail.Ru - {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (file missing)
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [ClassicShell] C:\Program Files\Classic Shell\ClassicStartMenu.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKLM\..\Run: [331BigDog] C:\Program Files\USB Camera\VM331_STI.EXE
O4 - HKLM\..\Run: [2Gis Update Notifier] "C:\Program Files\2gis\3.0\2GISTrayNotifier.exe" -delayed_start
O4 - HKLM\..\Run: [DXDllRegExe] C:\WINDOWS\system32\dxdllreg.exe 
O4 - HKLM\..\Run: [Guard.Mail.ru.gui] "C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe" /gui
O4 - HKLM\..\Run: [SpaceSoundPro] "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe"
O4 - HKLM\..\Run: [ZaxarGameBrowser] "C:\Program Files\Zaxar\ZaxarGameBrowser.exe" -s
O4 - HKLM\..\Run: [ZaxarLoader] "C:\Program Files\Zaxar\ZaxarLoader.exe" /verysilent
O4 - HKLM\..\Run: [Timestasks] C:\ProgramData\TimeTasks\timetasks.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Praetorian] C:\Users\МИХАИЛ 1\AppData\Local\Yandex\Updater\praetorian.exe
O4 - HKCU\..\Run: [TorrentExpress] "C:\Program Files\ExpressDownloader\TorrentExpress.exe" 
O4 - HKCU\..\Run: [browserset] "C:\Users\МИХАИЛ 1\AppData\Roaming\BrowserSetup\browsersetup.exe"
O4 - HKCU\..\Run: [Download Master] C:\Program Files\Download Master\dmaster.exe -autorun
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [GameCenterMailRu] "C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe" -autostart
O4 - HKCU\..\Run: [eTranslator Update] "C:\Users\МИХАИЛ 1\AppData\Roaming\eTranslator\eTranslator.exe" -checkforupdates
O4 - HKCU\..\Run: [storegid] C:\Users\МИХАИЛ 1\AppData\Local\storegid\storegid.exe
O4 - HKCU\..\Run: [storegidUpdater] C:\Users\МИХАИЛ 1\AppData\Local\storegid\storegidup.exe
O4 - HKCU\..\Run: [SearchIndexer] "C:\Users\МИХАИЛ 1\AppData\Roaming\SearchIndexer\desktopsearchservice.exe" 
O4 - HKCU\..\Run: [MailRuUpdater] C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\MailRuUpdater.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [Client Server Runtime Subsystem] "C:\ProgramData\Windows\csrss.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: extsetup.lnk = ?
O4 - Startup: Вырезка экрана и программа запуска для OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: kbrowser-updater-utility.lnk = C:\ProgramData\Kbrowser utility\kbrowser-updater-utility.exe
O4 - Global Startup: Kinoroom Browser.lnk = C:\Program Files\Kinoroom Browser\kinoroom-browser.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
O4 - Global Startup: Быстрый запуск AutoCAD.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O8 - Extra context menu item: &Отправить в OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Закачать ВСЕ при помощи Download Master - C:\Program Files\Download Master\dmieall.htm
O8 - Extra context menu item: Закачать при помощи Download Master - C:\Program Files\Download Master\dmie.htm
O8 - Extra context menu item: Передать на удаленную закачку DM - C:\Program Files\Download Master\remdown.htm
O9 - Extra button: Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O9 - Extra button: &Связанные заметки OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Связанные заметки OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Download Master - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - C:\Program Files\Download Master\dmaster.exe
O9 - Extra 'Tools' menuitem: &Download Master - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - C:\Program Files\Download Master\dmaster.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {093500E9-F79F-4C52-A9B5-D8C7E4B3023E} (ParallelGraphics Installer Class) - file:///C:/Users/16CDA~1/AppData/Local/Temp/o3dEE5C.tmp.cab
O16 - DPF: {810B649C-CEAE-4AC9-BF26-81341B49E913} (ParallelGraphics PlanEditor Control) - file:///C:/Users/16CDA~1/AppData/Local/Temp/o3dB489.tmp.cab
O16 - DPF: {FC77AB1C-824C-416F-95BC-418029595B48} (ParallelGraphics Image Support Library) - file:///C:/Users/16CDA~1/AppData/Local/Temp/o3dF1DA.tmp.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 2GIS UpdateService (2GISUpdateService) - Unknown owner - C:\Program Files\2gis\3.0\2GISUpdateService.exe (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Guard.Mail.ru - Unknown owner - C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Mail.Ru Update Service (mrupdsrv) - Mail.Ru - C:\Program Files\Mail.Ru\Update Service\mrupdsrv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Comment Box Visit (rizyqibe) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Updater.Mail.Ru - Mail.Ru - C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
O23 - Service: Hit Enable (woqenuwo) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Presentation Software Satellite (zizusyju) - Unknown owner - C:\Program.exe (file missing)

--
End of file - 15750 bytes

======Папка назначеных зданий======

C:\Windows\tasks\WinZipDriverUpdater_UPDATES.job - C:\Program Files\WinZip Driver Updater\winzipdu.exe -updatecheck
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\MailRuUpdater - C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\MailRuUpdater.exe --check
C:\Windows\system32\tasks\MailRuUpdateTask - C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\MailRuUpdater.exe --scheduler
C:\Windows\system32\tasks\SmartWeb Upgrade Trigger Task - C:\Users\МИХАИЛ 1\AppData\Local\SmartWeb\SmartWebHelper.exe 
C:\Windows\system32\tasks\WinZipDriverUpdater_UPDATES - C:\Program Files\WinZip Driver Updater\winzipdu.exe -updatecheck
C:\Windows\system32\tasks\{06C4734A-DDB0-45A8-9D0F-585614FFDE75} - F:\Games\TimeShift\bin\TimeShift.exe 
C:\Windows\system32\tasks\{07A7C1BE-2546-4E8A-9F01-58BAD903F747} - F:\Games\bin\TimeShift.Exe 
C:\Windows\system32\tasks\{0E26E1C0-2F9E-4912-BB8D-35E08ABC57BA} - "c:\program files\mozilla firefox\firefox.exe" http://ui.skype.com/ui/0/5.5.0.124/ru/abandoninstall?page=tsPlugin&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
C:\Windows\system32\tasks\{16398A8C-BFCC-4853-BD47-177C5F03196A} - C:\Windows\system32\pcalua.exe -a "C:\Users\МИХАИЛ 1\AppData\Roaming\istartpageing\UninstallManager.exe" -c -ptid=cmi
C:\Windows\system32\tasks\{179B3638-723A-4CE7-A7DD-AA3D7C644750} - C:\Windows\system32\pcalua.exe -a "C:\Users\МИХАИЛ 1\Downloads\2GISShell-3.14.8.0-2GISData_Omsk-121.0.0.exe" -d "C:\Users\МИХАИЛ 1\Downloads"
C:\Windows\system32\tasks\{54DEACB8-8542-477F-84DF-41CCEC5965C0} - C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\
C:\Windows\system32\tasks\{6607C1CC-EC42-4E73-980D-1EFEED2DBCDE} - F:\Games\TimeShift\bin\TimeShift.exe 
C:\Windows\system32\tasks\{6E471CCD-3E51-4564-B59A-DF68AF1C3EBE} - C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\
C:\Windows\system32\tasks\{6F2BB746-DA3C-4538-B6C5-F0BC2E50FC05} - F:\Games\OmD\Build\release\OrcsMustDie.exe 
C:\Windows\system32\tasks\{82EDEFA4-64D6-4330-8579-A2813B9959FB} - C:\Windows\system32\pcalua.exe -a "C:\Users\МИХАИЛ 1\AppData\Local\Amigo\Application\44.4.2403.3\Installer\setup.exe" -c --uninstall
C:\Windows\system32\tasks\{8E67143C-3475-47C5-B144-47B66B00C398} - C:\Windows\system32\pcalua.exe -a "C:\Users\МИХАИЛ 1\Downloads\googlesketchupwru(1).exe" -d "C:\Users\МИХАИЛ 1\Downloads"
C:\Windows\system32\tasks\{9E511542-1631-43AE-936D-9C5A12D084A9} - F:\Games\Metro Last Light\MetroLL.exe 
C:\Windows\system32\tasks\{B20AC3F7-95AC-4058-9550-E9FA9BD60A7E} - C:\Windows\system32\pcalua.exe -a F:\Games\Scarface\DirectX9\DXSETUP.exe -d F:\Games\Scarface\DirectX9
C:\Windows\system32\tasks\{C2B62486-30D0-4AA5-AEA8-FAEBF86806B9} - F:\Games\Metro Last Light\MetroLL.exe 
C:\Windows\system32\tasks\{C8635629-C672-4122-B7F8-223C989D6CC7} - F:\игры\Scarface\Scarface.exe 
C:\Windows\system32\tasks\{C999146E-2A83-46DD-8C59-60FEAB1BB29A} - C:\Windows\system32\pcalua.exe -a "F:\кино\You Are Empty\YAE_setup.exe" -d "F:\кино\You Are Empty"
C:\Windows\system32\tasks\{D795DFDA-7E1E-43CC-8420-4A1A4C84E5F3} - C:\Windows\system32\pcalua.exe -a "F:\кино\Silent Hill - Homecoming\Руссификатор (Озвучка)\Silent Hill 5 - Homecoming-sound 1.3.1.exe" -d "F:\кино\Silent Hill - Homecoming\Руссификатор (Озвучка)"
C:\Windows\system32\tasks\{EA308191-BE61-4557-A514-1ED1BDF8DE66} - C:\Windows\system32\pcalua.exe -a E:\autorun.exe -d E:\
C:\Windows\system32\tasks\{FC999D47-94DE-417A-A117-9F14724FD962} - C:\Windows\system32\pcalua.exe -a "C:\Users\МИХАИЛ 1\Downloads\2GISShell-3.14.9.0-2GISData_Omsk-122.0.0.exe" -d "C:\Users\МИХАИЛ 1\Downloads"
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-3032902621-1377843980-1404468434-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - %systemroot%\system32\sc.exe start osppsvc
C:\Windows\system32\tasks\Microsoft\Windows Defender\MP Scheduled Scan - c:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" 
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs 
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe 
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate_scheduled - %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe 
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe 
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe 
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent 
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe 
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe 

=========Mozilla firefox=========

ProfilePath - C:\Users\МИХАИЛ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397

prefs.js - "keyword.URL" -  "http://go.mail.ru/search?fr=ntg&q="

"searchpredict@speedbit.com"=C:\Program Files\SearchPredict\PRFireFox
"{0329E7D6-6F54-462D-93F6-F5C3118BADF2}"=C:\Program Files\SpeedBit Video Downloader\SPFireFox


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.182 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_182.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@outline3d.com/MozillaWrapper]
"Description"=Outline3d Mozilla Wrapper Plugin
"Path"=C:\Program Files\Common Files\ParallelGraphics\Outline3d\npOutline3dWrapper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@parallelgraphics.com/Cortona]
"Description"=Cortona VRML Plugin
"Path"=C:\Program Files\Common Files\ParallelGraphics\Cortona\npcortona.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
np32dsw.dll
npOutline3dWrapper.dll
nppdf32.dll
ShockwavePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\МИХАИЛ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397\extensions\
{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}

C:\Users\МИХАИЛ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Firefox Hello Beta - extension - loop@mozilla.org

C:\Users\МИХАИЛ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397\extensions.json
SearchPredict - extension - searchpredict@speedbit.com - C:\Program Files\SearchPredict\PRFireFox
SpeedBit Video Downloader - extension - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\SPFireFox
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\ÐÐÐ¥ÐÐÐ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Firefox Hello Beta - extension - loop@mozilla.org - C:\Program Files\Mozilla Firefox\browser\features\loop@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Визуальные закладки @Mail.Ru - extension - {a38384b3-2d1d-4f36-bc22-0f7ae402bcd7} - C:\Users\ÐÐÐ¥ÐÐÐ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}

C:\Users\МИХАИЛ 1\AppData\Roaming\Mozilla\Firefox\Profiles\bh04g6lr.default-1452178200397\pluginreg.dat
Plugin - Adobe Acrobat - 10.1.11.8 - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll
Plugin - Adobe Acrobat - 10.1.11.8 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
Plugin - Cortona3D Viewer - 7.0.0.188 - C:\Program Files\Common Files\ParallelGraphics\Cortona\npcortona.dll
Plugin - Outline3d Mozilla Wrapper - 1.0.0.5 - C:\Program Files\Common Files\ParallelGraphics\Outline3d\npOutline3dWrapper.dll
Plugin - Microsoft Office 2010 - 14.0.4730.1010 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
Plugin - Microsoft Office 2010 - 14.0.4761.1000 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
Plugin - Shockwave Flash - 21.0.0.182 - C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_182.dll
Plugin - gamecenter3 component npdetector.dll - 3.0.1163.32464 - C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\GameCenter\npdetector.dll

======Снимок реестра======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3017FB3E-9A77-4396-88C5-0EC9548FB42F}]
SBCONVERT Class - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll [2014-01-08 2447360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{389943B0-C3A2-4E69-82CB-8596A84CB3DC}]
SearchPredictObj Class - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL [2010-12-22 469144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2011-03-27 501760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}]
Поиск@Mail.Ru - C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\Sputnik\IESearchPlugin.dll [2015-09-07 2275544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master - C:\PROGRA~1\DOWNLO~1\dmiehlp.dll [2015-04-02 168200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C93F72A2-2162-4BBA-A07A-F13663C297A6}]
Визуальные закладки - C:\Program Files\Yandex\YandexBarIE\fastdial.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF7C3CF0-4B15-11D1-ABED-709549C10000}]
GrabberObj Class - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber.dll [2014-01-08 182536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2011-03-27 501760]
{91397D20-1446-11D4-8AF4-0040CA1127B6} - Яндекс.Бар - C:\Program Files\Yandex\YandexBarIE\yndbar.dll []
{09900DE8-1DCA-443F-9243-26FF581438AF} - Спутник@Mail.Ru - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll []
{0329E7D6-6F54-462D-93F6-F5C3118BADF2} - SpeedBit Video Downloader - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll [2014-01-08 2447360]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ClassicShell"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2011-03-27 91648]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-14 2219184]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-03-02 143384]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-03-02 177176]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-03-02 178200]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-02-17 336384]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2011-03-02 307768]
"331BigDog"=C:\Program Files\USB Camera\VM331_STI.EXE [2011-03-02 536576]
"2Gis Update Notifier"=C:\Program Files\2gis\3.0\2GISTrayNotifier.exe -delayed_start []
"DXDllRegExe"=C:\WINDOWS\system32\dxdllreg.exe  []
"Guard.Mail.ru.gui"=C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe [2015-11-21 4721368]
"SpaceSoundPro"=C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe []
"gmsd_ru_005010171"= []
"rec_en_77"= []
"ZaxarGameBrowser"=C:\Program Files\Zaxar\ZaxarGameBrowser.exe -s []
"ZaxarLoader"=C:\Program Files\Zaxar\ZaxarLoader.exe /verysilent []
"Timestasks"=C:\ProgramData\TimeTasks\timetasks.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-07-29 17361032]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
"Praetorian"=C:\Users\МИХАИЛ 1\AppData\Local\Yandex\Updater\praetorian.exe [2012-06-04 1582976]
"TorrentExpress"=C:\Program Files\ExpressDownloader\TorrentExpress.exe [2013-05-30 630784]
"browserset"=C:\Users\МИХАИЛ 1\AppData\Roaming\BrowserSetup\browsersetup.exe []
"Download Master"=C:\Program Files\Download Master\dmaster.exe [2015-04-21 5889800]
"OfficeSyncProcess"=C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [2012-01-20 719672]
"GameCenterMailRu"=C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe [2016-04-07 5330816]
"eTranslator Update"=C:\Users\МИХАИЛ 1\AppData\Roaming\eTranslator\eTranslator.exe -checkforupdates []
"storegid"=C:\Users\МИХАИЛ 1\AppData\Local\storegid\storegid.exe []
"storegidUpdater"=C:\Users\МИХАИЛ 1\AppData\Local\storegid\storegidup.exe []
"SearchIndexer"=C:\Users\МИХАИЛ 1\AppData\Roaming\SearchIndexer\desktopsearchservice.exe  []
"MailRuUpdater"=C:\Users\МИХАИЛ 1\AppData\Local\Mail.Ru\MailRuUpdater.exe [2016-04-11 5873880]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-12-09 6602152]
"Client Server Runtime Subsystem"=C:\ProgramData\Windows\csrss.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
kbrowser-updater-utility.lnk - C:\ProgramData\Kbrowser utility\kbrowser-updater-utility.exe
Kinoroom Browser.lnk - C:\Program Files\Kinoroom Browser\kinoroom-browser.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
Быстрый запуск AutoCAD.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe

C:\Users\МИХАИЛ 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
extsetup.lnk - C:\Users\МИХАИЛ 1\AppData\Local\Microsoft\Extensions\extsetup.exe
Вырезка экрана и программа запуска для OneNote 2010.lnk - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-02 288256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 4171424]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\14905097.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\60661981.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\91861067.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\14905097.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\60661981.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\91861067.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=0
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.WMV3"=wmv9vcm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.VP31"=vp31vfw.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

======Ассоциации файлов======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - "C:\Windows\system32\NOTEPAD.EXE" "%1"
.scr - install - 
.scr - config - 

======Список файлов и папок, созданных за последние 3 месяца======

2016-04-14 20:06:45 ----A---- C:\Windows\system32\drivers\utezmjy3.sys
2016-04-14 19:22:20 ----AC---- C:\TDSSKiller.3.1.0.8_14.04.2016_19.22.20_log.txt
2016-04-14 19:07:55 ----AC---- C:\RannohDecryptor.1.8.0.2_14.04.2016_19.07.55_log.txt
2016-04-14 18:09:20 ----DC---- C:\FRST
2016-04-14 17:38:28 ----AC---- C:\RannohDecryptor.1.8.0.2_14.04.2016_17.38.28_log.txt
2016-04-14 17:31:20 ----AC---- C:\RannohDecryptor.1.8.0.2_14.04.2016_17.31.20_log.txt
2016-04-14 17:09:54 ----AC---- C:\RannohDecryptor.1.8.0.2_14.04.2016_17.09.54_log.txt
2016-04-14 17:05:56 ----AC---- C:\RannohDecryptor.1.8.0.2_14.04.2016_17.05.56_log.txt
2016-04-14 16:58:01 ----AC---- C:\RannohDecryptor.1.8.0.2_14.04.2016_16.58.01_log.txt
2016-04-14 16:28:14 ----DC---- C:\KVRT_Data
2016-04-14 16:23:28 ----AC---- C:\CleanAutoRun.1.2.1.0_14.04.2016_16.23.28_log.txt
2016-04-14 16:22:15 ----AC---- C:\CleanAutoRun.1.2.1.0_14.04.2016_16.22.15_log.txt
2016-04-14 15:41:22 ----AC---- C:\TDSSKiller.3.1.0.9_14.04.2016_15.41.22_log.txt
2016-04-14 15:38:01 ----AC---- C:\TDSSKiller.3.1.0.8_14.04.2016_15.38.01_log.txt
2016-04-14 15:27:43 ----AC---- C:\TDSSKiller.3.1.0.8_14.04.2016_15.27.43_log.txt
2016-04-14 14:25:20 ----AC---- C:\README9.txt
2016-04-14 14:25:20 ----AC---- C:\README8.txt
2016-04-14 14:25:20 ----AC---- C:\README7.txt
2016-04-14 14:25:20 ----AC---- C:\README6.txt
2016-04-14 14:25:20 ----AC---- C:\README5.txt
2016-04-14 14:25:20 ----AC---- C:\README4.txt
2016-04-14 14:25:20 ----AC---- C:\README3.txt
2016-04-14 14:25:20 ----AC---- C:\README2.txt
2016-04-14 14:25:20 ----AC---- C:\README10.txt
2016-04-14 14:25:20 ----AC---- C:\README1.txt
2016-04-14 14:24:35 ----SHD---- C:\ProgramData\Windows
2016-04-12 04:10:03 ----D---- C:\Program Files\Mozilla Firefox
2016-03-03 02:53:08 ----A---- C:\Windows\system32\BASSMOD.dll
2016-03-03 02:36:00 ----D---- C:\Program Files\ObjectRescue Pro
2016-03-03 01:45:16 ----D---- C:\Program Files\F-Recovery for MemoryStick
2016-03-03 00:30:18 ----D---- C:\Program Files\Sony
2016-03-01 04:14:29 ----AC---- C:\TDSSKiller.3.1.0.8_01.03.2016_04.14.29_log.txt

======Список файлов и папок, измененных за последние 3 месяца======

2016-04-14 20:16:21 ----D---- C:\Windows\Temp
2016-04-14 20:15:40 ----D---- C:\Windows\system32\config
2016-04-14 20:13:18 ----A---- C:\Windows\system32\log.txt
2016-04-14 20:06:45 ----D---- C:\Windows\system32\drivers
2016-04-14 18:09:33 ----D---- C:\Windows
2016-04-14 17:31:53 ----D---- C:\Windows\System32
2016-04-14 17:31:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-14 17:31:52 ----D---- C:\Windows\inf
2016-04-14 17:15:00 ----D---- C:\Program Files\ExpressDownloader
2016-04-14 16:36:11 ----D---- C:\Program Files\Internet Explorer
2016-04-14 15:34:14 ----DC---- C:\TDSSKiller_Quarantine
2016-04-14 15:19:47 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-14 15:17:27 ----D---- C:\Users\МИХАИЛ 1\AppData\Roaming\uTorrent
2016-04-14 14:24:35 ----HD---- C:\ProgramData
2016-04-13 01:11:56 ----D---- C:\Windows\Prefetch
2016-04-13 01:11:50 ----RD---- C:\Program Files
2016-04-11 08:15:19 ----D---- C:\Users\МИХАИЛ 1\AppData\Roaming\Skype
2016-04-04 22:18:47 ----D---- C:\Program Files\Common Files
2016-04-02 04:08:11 ----SHD---- C:\System Volume Information
2016-03-28 23:30:21 ----D---- C:\Program Files\Mail.Ru
2016-03-23 23:54:37 ----D---- C:\Windows\Minidump
2016-03-23 23:54:37 ----D---- C:\Windows\Logs
2016-03-23 20:12:10 ----D---- C:\Windows\system32\directx
2016-03-23 19:13:26 ----D---- C:\Windows\system32\Tasks
2016-03-23 18:02:47 ----SHD---- C:\Windows\Installer
2016-03-23 17:04:12 ----D---- C:\Users\МИХАИЛ 1\AppData\Roaming\DAEMON Tools Lite
2016-03-19 16:26:11 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-03-05 05:07:39 ----D---- C:\Windows\system32\catroot2
2016-03-03 00:30:16 ----HD---- C:\Program Files\InstallShield Installation Information
2016-02-07 00:53:15 ----D---- C:\Users\МИХАИЛ 1\AppData\Roaming\Media Player Classic
2016-01-15 22:53:19 ----D---- C:\Users\МИХАИЛ 1\AppData\Roaming\Bioshock2

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed
======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 173440]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-07-25 242240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 storegidfilter;storegidfilter; C:\Windows\storegidfilter.sys [2014-06-25 41632]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 95384]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-02 6790144]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-02 236544]
R3 b70bus;Virtual b70 Enumerator (public beta); C:\Windows\system32\DRIVERS\b70bus.sys [2009-10-16 423424]
R3 BCM43XX;Драйвер сетевого адаптера Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2010-10-28 4245568]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2011-03-02 1283200]
R3 GrdKey;Guardant LPT Dongle Service; C:\Windows\system32\DRIVERS\grdkey.sys [2007-11-08 1189888]
R3 GrdUsb;Guardant USB Dongle Service; C:\Windows\system32\DRIVERS\grdusb.sys [2007-11-08 1112832]
R3 IntcDAud;Аудио Intel(R) для дисплеев; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-03-02 269824]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd32.sys [2011-03-02 10543104]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x86.sys [2011-03-02 68208]
R3 MEI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2011-03-02 41088]
R3 utezmjy3;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\utezmjy3.sys [2016-04-14 7168]
R3 vm331avs;Digital Camera 1; C:\Windows\System32\Drivers\vm331avs.sys [2011-03-02 196352]
R3 vmuvcflt;Vimicro USB Camera Filter; C:\Windows\System32\Drivers\vmuvcflt.sys [2011-03-02 5888]
S1 swsedrvr_vt_1_10_0_25;swsedrvr_vt_1_10_0_25; C:\Windows\system32\drivers\swsedrvr_vt_1_10_0_25.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-21 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 27264]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2008-11-19 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2008-11-19 19968]
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2008-11-19 24832]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 175360]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 35968]
S3 XDva403;XDva403; \??\C:\Windows\system32\XDva403.sys []
S3 XDva404;XDva404; \??\C:\Windows\system32\XDva404.sys []
S3 XDva405;XDva405; \??\C:\Windows\system32\XDva405.sys []
S3 XDva407;XDva407; \??\C:\Windows\system32\XDva407.sys []
S3 XDva408;XDva408; \??\C:\Windows\system32\XDva408.sys []
S3 XDva409;XDva409; \??\C:\Windows\system32\XDva409.sys []
S3 XDva410;XDva410; \??\C:\Windows\system32\XDva410.sys []
S3 XDva411;XDva411; \??\C:\Windows\system32\XDva411.sys []
S3 XDva412;XDva412; \??\C:\Windows\system32\XDva412.sys []
S3 XDva413;XDva413; \??\C:\Windows\system32\XDva413.sys []
S3 XDva534;XDva534; \??\C:\Windows\system32\XDva534.sys []

======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-13 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-02 176128]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2013-03-02 79360]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\cscsvc.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-01-14 810144]
R2 Guard.Mail.ru;Guard.Mail.ru; C:\Program Files\Mail.Ru\Guard\GuardMailRu.exe [2015-11-21 4721368]
R2 KMService;KMService; C:\Windows\system32\srvany.exe [2011-11-24 8192]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-03-02 325656]
R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit; C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2008-03-10 65536]
R2 mrupdsrv;Mail.Ru Update Service; C:\Program Files\Mail.Ru\Update Service\mrupdsrv.exe [2016-03-28 2555096]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2013-02-02 75064]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-03-02 2656280]
R2 Updater.Mail.Ru;Updater.Mail.Ru; C:\Program Files\Mail.Ru\MailRuUpdater\MailRuUpdater.exe [2016-04-11 5873880]
S2 rizyqibe;Comment Box Visit; C:\Program Files\BD982A04-1449761186-E011-836D-B870F4300684\jnscCCB.tmp []
S2 woqenuwo;Hit Enable; C:\Program Files\BD982A04-1449761186-E011-836D-B870F4300684\knshF2FE.tmpfs []
S2 zizusyju;Presentation Software Satellite; C:\Program Files\BD982A04-1449761186-E011-836D-B870F4300684\hnsm26A3.tmp []
S3 2GISUpdateService;2GIS UpdateService; C:\Program Files\2gis\3.0\2GISUpdateService.exe []
S3 AppMgmt;@appmgmts.dll,-3250; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll"=%SystemRoot%\System32\appmgmts.dll
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-14 33584]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [2015-12-02 235696]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-12 146888]
S3 ose;Office  Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; %SystemRoot%\System32\svchost.exe -k PeerDist;"ServiceDll"=%SystemRoot%\system32\peerdistsvc.dll
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\umrdp.dll
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-08-11 1343400]

-----------------EOF-----------------
