﻿Лог утилиты random's system information tool 1.16(автор: random/random)
Run by Алексей at 2018-01-10 13:20:40
Microsoft Windows 7 Максимальная  Service Pack 1
Системный раздел C: размер 56 GB (56%) Свободно 100 GB
Total RAM: 8153 MB (62% free)
X64

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 13:20:41, on 10.01.2018
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe
C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe
C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avpui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe
C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Алексей\Desktop\AutoLogger.exe
C:\Users\Алексей\Desktop\AutoLogger\AVZ\avz.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Алексей\Desktop\AutoLogger\RSIT\Алексей_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yandex.ru/?win=315&clid=2256428-306
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {0E2877D3-2641-4970-B794-A553E295428D} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\IEExt\ie_plugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O3 - Toolbar: Kaspersky Protection Toolbar - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [Steam] "D:\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [McAfeeSafeConnect] C:\Program Files (x86)\McAfee Safe Connect\McAfee Safe Connect.exe
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe" Minimum
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Алексей\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service 18.0.0 (AVP18.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Служба Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: klvssbridge64_18.0.0 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\vssbridge64.exe
O23 - Service: Kaspersky Secure Connection Service 2.0.0 (KSDE2.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8807 bytes

====== Список процессов ======

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe" -r
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe" Minimum
"C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" 
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avpui.exe" -hidden
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe" -r
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe" -hidden
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
C:\Windows\system32\taskhost.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%dSPUser.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\SPUser" -r -l 3 -p 30000 -c
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe "1356069390353255118-1430359380-1544163935-946106196-785116027990552013-214559472
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --disable-gpu-compositing --no-sandbox --service-pipe-token=D21E008898751771AD261AC70AEFD59A --lang=en-US --lang=en-US --log-file="C:\Users\Алексей\AppData\Local\NVIDIA Corporation\NVIDIA Share\CefCache\debug.log" --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=D21E008898751771AD261AC70AEFD59A --renderer-client-id=2 --mojo-platform-channel-handle=1324 /prefetch:1
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -d "C:\Program Files\NVIDIA Corporation\NvStreamSrv\SsauPlugins" -f "C:\ProgramData\NVIDIA Corporation\nvstreamsvc\NvcSSAU.log" -l 4 -r  -c 
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Алексей\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Алексей\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Алексей\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=63.0.3239.132 --initial-client-data=0x80,0x84,0x88,0x7c,0x8c,0x7fef60d5720,0x7fef60d5760,0x7fef60d5738
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=4200 --on-initialized-event-handle=300 --parent-handle=304 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --gpu-vendor-id=0x10de --gpu-device-id=0x0fc6 --gpu-driver-vendor=NVIDIA --gpu-driver-version=23.21.13.9065 --gpu-driver-date=1-3-2018 --service-request-channel-token=7BBB2087314D07CC59CC51246A4E2F6E --mojo-platform-channel-handle=1268 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --service-pipe-token=7FB6809E8B85BEC39547B33D91647FE8 --lang=ru --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=7FB6809E8B85BEC39547B33D91647FE8 --renderer-client-id=4 --mojo-platform-channel-handle=1644 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --service-pipe-token=F5C8E2D6743CF7C7D7A29CB3369FB6C9 --lang=ru --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=F5C8E2D6743CF7C7D7A29CB3369FB6C9 --renderer-client-id=5 --mojo-platform-channel-handle=2272 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --service-pipe-token=F5D28064C11C5B5794AB7B2F02BC4A06 --lang=ru --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=F5D28064C11C5B5794AB7B2F02BC4A06 --renderer-client-id=6 --mojo-platform-channel-handle=2280 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --service-pipe-token=2C998907FCEACA25BF48F4E1DD29D513 --lang=ru --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=2C998907FCEACA25BF48F4E1DD29D513 --renderer-client-id=7 --mojo-platform-channel-handle=3220 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --service-pipe-token=8E2916765CD955DD632E8EB5AF8B9417 --lang=ru --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=8E2916765CD955DD632E8EB5AF8B9417 --renderer-client-id=12 --mojo-platform-channel-handle=2360 /prefetch:1
"C:\Users\Алексей\Desktop\AutoLogger.exe" 
"C:\Users\Алексей\Desktop\AutoLogger\AVZ\avz.exe" Script=AVZ\GeneralScript.txt HiddenMode=0
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://google.ru
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256,7656511811370988063,6189236543923434311,131072 --service-pipe-token=A1D11EEC488F74C50FD48B1ED094086F --lang=ru --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=A1D11EEC488F74C50FD48B1ED094086F --renderer-client-id=25 --mojo-platform-channel-handle=7328 /prefetch:1
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:980 CREDAT:79873
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532 
C:\Users\Алексей\Desktop\AutoLogger\RSIT\RSITx64.exe /silent /m3 /autolog /logfolder "C:\Users\Алексей\Desktop\AutoLogger\RSIT\Log" /hjtp "C:\Users\Алексей\Desktop\AutoLogger\RSIT\HiJackThis.exe"
C:\Windows\system32\wbem\wmiprvse.exe

====== Папка назначенных заданий ======

C:\Windows\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe -check pepperplugin
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\klcp_update - "%ProgramFiles(x86)%\K-Lite Codec Pack\Tools\CodecTweakTool.exe" /verysilent /update /freq=30
C:\Windows\system32\tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
C:\Windows\system32\tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\Microsoft\Windows Defender\MP Scheduled Scan - c:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan
C:\Windows\system32\tasks\Microsoft\Windows Defender\MpIdleTask - c:\program files\windows defender\MpCmdRun.exe -IdleTask -TaskName MpIdleTask
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Google Chrome=========

C:\Users\Алексей\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Презентации 0.10
Extension ablpcikjmhamjanpibkccdmpoekjigja 2 Поиск  Яндексa 2.0.4.15
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Интернет-магазин Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Документы 0.10
Extension apdfllckaahabafndbhieahigkjlhalf 1 Диск Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0  
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension cfhdojbkjhnklbpkdaibdccddilifddb 1 Adblock Plus 1.13.4
Extension dcnofaichneijfbkdkghmhjjbepjmble 1 Fair AdBlocker App 1.30
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Таблицы 1.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Документы офлайн 1.4
Extension hflefjhkfeiaignkclmphmokmmbhbhik 1 Блокировщик рекламы для Youtube ™ 1.5.20
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mchjnmdbdlkdbfliogedbnpnanfjnolk 1 Kaspersky Protection 5.1.93.0
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf   
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension nchoeafalnaacdkpoodkjnbogigpjabk 1 The Space  1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.5
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Платежная система Интернет-магазина Chrome 1.0.0.3
Extension ohfhlfmeecfipekmbehjpjiambhpgjej 0  
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 6317.1002.0.5
Homepage: http://www.yandex.ru/?win=70&clid=1872363
default_search_provider.search_url: 
C:\Users\Алексей\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage: 
default_search_provider.search_url: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ablpcikjmhamjanpibkccdmpoekjigja]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mchjnmdbdlkdbfliogedbnpnanfjnolk]
"Path"=https://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk


======Снимок реестра ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E2877D3-2641-4970-B794-A553E295428D}]
Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\IEExt\ie_plugin.dll [2018-01-08 1429352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E2877D3-2641-4970-B794-A553E295428D}]
Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\IEExt\ie_plugin.dll [2018-01-08 1150312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4853DF44-7D6B-48E9-9258-D800EEE54AF6} - Kaspersky Protection Toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\IEExt\ie_plugin.dll [2018-01-08 1429352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{4853DF44-7D6B-48E9-9258-D800EEE54AF6} - Kaspersky Protection Toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\IEExt\ie_plugin.dll [2018-01-08 1150312]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2017-12-13 18388416]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=D:\Steam\steam.exe [2017-12-15 3111712]
"McAfeeSafeConnect"=C:\Program Files (x86)\McAfee Safe Connect\McAfee Safe Connect.exe []
"Bloody2"=C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe [2017-09-01 17627648]
"uTorrent"=C:\Users\Алексей\AppData\Roaming\uTorrent\uTorrent.exe [2018-01-10 1985464]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-09-17 292088]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

====== Ассоциации файлов ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== Список файлов и папок, созданных за последние 3 месяца ======

2018-01-10 12:14:34 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2018-01-10 10:03:18 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2018-01-10 10:03:10 ----D---- C:\Program Files (x86)\VulkanRT
2018-01-10 10:03:10 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2018-01-10 10:03:10 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2018-01-10 10:03:10 ----A---- C:\Windows\system32\vulkaninfo.exe
2018-01-10 10:03:10 ----A---- C:\Windows\system32\vulkan-1.dll
2018-01-10 10:02:17 ----D---- C:\Windows\system32\drivers\NVIDIA Corporation
2018-01-10 10:02:17 ----D---- C:\Windows\LastGood
2018-01-10 10:01:15 ----A---- C:\Windows\system32\drivers\nvvhci.sys
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2018-01-10 10:01:13 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvopencl.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvoglv64.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvoglshim64.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvinitx.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\NvIFR64.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvhdap64.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\NvFBC64.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvdispgenco6439065.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvdispco6439065.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvcuvid.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvcuda.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\nvcompiler.dll
2018-01-10 10:01:13 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2018-01-10 10:01:13 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2018-01-10 09:49:37 ----D---- C:\Program Files\AVAST Software
2018-01-10 09:48:18 ----D---- C:\Users\Алексей\AppData\Roaming\uTorrent
2018-01-09 18:08:55 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2018-01-09 14:30:55 ----D---- C:\Windows\SYSWOW64\directx
2018-01-09 13:38:55 ----D---- C:\Program Files (x86)\Intel
2018-01-09 13:38:55 ----A---- C:\Windows\system32\drivers\USB3Ver.dll
2018-01-09 13:38:51 ----D---- C:\Intel
2018-01-09 13:38:26 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2018-01-09 13:38:26 ----A---- C:\Windows\system32\drivers\iusb3xhc.sys
2018-01-09 13:38:26 ----A---- C:\Windows\system32\drivers\iusb3hub.sys
2018-01-09 13:38:26 ----A---- C:\Windows\system32\drivers\iusb3hcs.sys
2018-01-09 11:09:06 ----D---- C:\Program Files (x86)\FinalWire
2018-01-08 22:00:22 ----A---- C:\Windows\NvTelemetryContainerRecovery.bat
2018-01-08 21:46:49 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2018-01-08 21:46:49 ----A---- C:\Windows\system32\x3daudio1_1.dll
2018-01-08 21:44:53 ----D---- C:\Windows\system32\appmgmt
2018-01-08 21:43:45 ----D---- C:\Users\Алексей\AppData\Roaming\McAfee Safe Connect
2018-01-08 21:34:20 ----D---- C:\Program Files (x86)\McAfee Safe Connect
2018-01-08 21:27:37 ----D---- C:\ProgramData\McAfee
2018-01-08 21:25:11 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2018-01-08 21:24:56 ----D---- C:\Windows\system32\Macromed
2018-01-08 21:24:48 ----D---- C:\Windows\SYSWOW64\Macromed
2018-01-08 20:54:45 ----D---- C:\Users\Алексей\AppData\Roaming\Wargaming.net
2018-01-08 20:33:57 ----D---- C:\Users\Алексей\AppData\Roaming\Google
2018-01-08 20:26:28 ----D---- C:\Program Files\Common Files\AV
2018-01-08 20:25:55 ----D---- C:\Users\Алексей\AppData\Roaming\DRPNPS
2018-01-08 20:25:30 ----A---- C:\Windows\system32\klfphc.dll
2018-01-08 20:25:12 ----D---- C:\ProgramData\Kaspersky Lab
2018-01-08 20:25:12 ----D---- C:\Program Files (x86)\Kaspersky Lab
2018-01-08 20:25:01 ----A---- C:\Windows\system32\klhkum.dll
2018-01-08 20:25:01 ----A---- C:\Windows\system32\drivers\klif.sys
2018-01-08 20:25:01 ----A---- C:\Windows\system32\drivers\klhk.sys
2018-01-08 20:25:01 ----A---- C:\Windows\system32\drivers\klflt.sys
2018-01-08 20:18:39 ----D---- C:\Users\Алексей\AppData\Roaming\NVIDIA
2018-01-08 20:13:04 ----D---- C:\Program Files (x86)\Microsoft Works
2018-01-08 20:12:54 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2018-01-08 20:12:47 ----D---- C:\Windows\PCHEALTH
2018-01-08 20:11:26 ----D---- C:\Program Files\Microsoft Office
2018-01-08 20:11:22 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2018-01-08 20:10:59 ----D---- C:\ProgramData\Microsoft Help
2018-01-08 20:10:59 ----D---- C:\Program Files (x86)\Microsoft Office
2018-01-08 20:10:23 ----RHD---- C:\MSOCache
2018-01-08 20:01:31 ----SD---- C:\Windows\SYSWOW64\Microsoft
2018-01-08 20:00:30 ----D---- C:\Program Files (x86)\Bloody6
2018-01-08 19:58:08 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2018-01-08 19:31:47 ----RA---- C:\Windows\infpub.dat
2018-01-08 19:31:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-08 19:31:01 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-08 19:31:01 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2018-01-08 19:31:01 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2018-01-08 19:31:01 ----A---- C:\Windows\system32\lsass.exe
2018-01-08 19:31:01 ----A---- C:\Windows\system32\cryptbase.dll
2018-01-08 19:31:01 ----A---- C:\Windows\system32\apisetschema.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-08 19:31:00 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-08 19:31:00 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2018-01-08 19:31:00 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2018-01-08 19:31:00 ----A---- C:\Windows\system32\wow64cpu.dll
2018-01-08 19:31:00 ----A---- C:\Windows\system32\wow64.dll
2018-01-08 19:31:00 ----A---- C:\Windows\system32\smss.exe
2018-01-08 19:31:00 ----A---- C:\Windows\system32\ntvdm64.dll
2018-01-08 19:31:00 ----A---- C:\Windows\system32\INETRES.dll
2018-01-08 19:31:00 ----A---- C:\Windows\system32\drivers\srvnet.sys
2018-01-08 19:31:00 ----A---- C:\Windows\system32\drivers\srv2.sys
2018-01-08 19:31:00 ----A---- C:\Windows\system32\drivers\srv.sys
2018-01-08 19:31:00 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2018-01-08 19:31:00 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2018-01-08 19:31:00 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2018-01-08 19:31:00 ----A---- C:\Windows\system32\csrsrv.dll
2018-01-08 19:31:00 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2018-01-08 19:30:59 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2018-01-08 19:30:59 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2018-01-08 19:30:59 ----A---- C:\Windows\SYSWOW64\mscms.dll
2018-01-08 19:30:59 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2018-01-08 19:30:59 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\wow64win.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\sspisrv.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\rstrui.exe
2018-01-08 19:30:59 ----A---- C:\Windows\system32\msxml3r.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\msobjs.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\mscms.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\msaudite.dll
2018-01-08 19:30:59 ----A---- C:\Windows\system32\bcrypt.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-08 19:30:58 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\wow32.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\user.exe
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\srclient.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\setup16.exe
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\secur32.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\instnm.exe
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\icm32.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\credssp.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\certcli.dll
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2018-01-08 19:30:58 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\WcsPlugInService.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\sspicli.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\srcore.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\srclient.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\setbcdlocale.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\secur32.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\rpchttp.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\KernelBase.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\icm32.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2018-01-08 19:30:58 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2018-01-08 19:30:58 ----A---- C:\Windows\system32\drivers\appid.sys
2018-01-08 19:30:58 ----A---- C:\Windows\system32\credssp.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\certcli.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\auditpol.exe
2018-01-08 19:30:58 ----A---- C:\Windows\system32\appidsvc.dll
2018-01-08 19:30:58 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2018-01-08 19:30:58 ----A---- C:\Windows\system32\appidapi.dll
2018-01-08 19:30:58 ----A---- C:\Windows\HelpPane.exe
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\schannel.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2018-01-08 19:30:57 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\winsrv.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\winresume.exe
2018-01-08 19:30:57 ----A---- C:\Windows\system32\wdigest.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\TSpkg.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\schannel.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\quartz.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\ncrypt.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\msv1_0.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\kerberos.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\inetcomm.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\gdi32.dll
2018-01-08 19:30:57 ----A---- C:\Windows\system32\conhost.exe
2018-01-08 19:30:57 ----A---- C:\Windows\system32\ci.dll
2018-01-08 19:30:56 ----A---- C:\Windows\SYSWOW64\quartz.dll
2018-01-08 19:30:56 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2018-01-08 19:30:56 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2018-01-08 19:30:56 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2018-01-08 19:30:56 ----A---- C:\Windows\system32\winload.exe
2018-01-08 19:30:56 ----A---- C:\Windows\system32\drivers\cng.sys
2018-01-08 19:30:56 ----A---- C:\Windows\system32\bcryptprimitives.dll
2018-01-08 19:30:56 ----A---- C:\Windows\system32\advapi32.dll
2018-01-08 19:30:56 ----A---- C:\Windows\system32\adtschema.dll
2018-01-08 19:30:55 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2018-01-08 19:30:55 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2018-01-08 19:30:55 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2018-01-08 19:30:55 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2018-01-08 19:30:55 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2018-01-08 19:30:55 ----A---- C:\Windows\system32\ntoskrnl.exe
2018-01-08 19:30:55 ----A---- C:\Windows\system32\ntdll.dll
2018-01-08 19:30:55 ----A---- C:\Windows\system32\msxml3.dll
2018-01-08 19:30:55 ----A---- C:\Windows\system32\lsasrv.dll
2018-01-08 19:30:55 ----A---- C:\Windows\system32\kernel32.dll
2018-01-08 19:30:54 ----A---- C:\Windows\system32\win32k.sys
2018-01-08 19:30:54 ----A---- C:\Windows\system32\rpcrt4.dll
2018-01-08 19:30:53 ----A---- C:\Windows\SYSWOW64\usp10.dll
2018-01-08 19:30:53 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2018-01-08 19:30:53 ----A---- C:\Windows\system32\usp10.dll
2018-01-08 19:30:53 ----A---- C:\Windows\system32\FntCache.dll
2018-01-08 19:30:53 ----A---- C:\Windows\system32\DWrite.dll
2018-01-08 19:26:26 ----A---- C:\AiOLog.txt
2018-01-08 19:25:06 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2018-01-08 19:24:24 ----D---- C:\Windows\Migration
2018-01-08 19:24:24 ----D---- C:\Program Files (x86)\Microsoft.NET
2018-01-08 19:18:26 ----D---- C:\Program Files\Common Files\Avast Software
2018-01-08 19:16:33 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2018-01-08 19:16:33 ----A---- C:\Windows\system32\ucrtbase.dll
2018-01-08 19:14:41 ----D---- C:\ProgramData\AVAST Software
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\Vb40032.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msvcrt10.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msvcr71.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msvcp71.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MSVCP70.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msvci70.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msvbvm50.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MSSTKPRP.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\msstdfmt.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71u.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71KOR.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71JPN.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71ITA.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71FRA.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71ESP.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71ENU.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71DEU.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71CHT.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71CHS.DLL
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\MFC71.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70u.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70kor.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70jpn.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70ita.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70fra.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70esp.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70enu.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70deu.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70cht.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70chs.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\mfc70.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\atl71.dll
2018-01-08 19:14:31 ----A---- C:\Windows\SYSWOW64\atl70.dll
2018-01-08 19:14:20 ----D---- C:\Windows\SYSWOW64\RTCOM
2018-01-08 19:14:20 ----D---- C:\Program Files\Realtek
2018-01-08 19:13:01 ----D---- C:\Users\Алексей\AppData\Roaming\Mozilla
2018-01-08 19:11:43 ----D---- C:\Users\Алексей\AppData\Roaming\Opera Software
2018-01-08 19:11:37 ----D---- C:\Program Files\Opera
2018-01-08 19:07:44 ----A---- C:\Windows\system32\wups2.dll
2018-01-08 19:07:44 ----A---- C:\Windows\system32\wucltux.dll
2018-01-08 19:07:44 ----A---- C:\Windows\system32\wuaueng.dll
2018-01-08 19:07:44 ----A---- C:\Windows\system32\wuauclt.exe
2018-01-08 19:07:39 ----A---- C:\Windows\SYSWOW64\wups.dll
2018-01-08 19:07:39 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2018-01-08 19:07:39 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2018-01-08 19:07:39 ----A---- C:\Windows\system32\wups.dll
2018-01-08 19:07:39 ----A---- C:\Windows\system32\wudriver.dll
2018-01-08 19:07:39 ----A---- C:\Windows\system32\wuapi.dll
2018-01-08 19:07:34 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2018-01-08 19:07:34 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2018-01-08 19:07:34 ----A---- C:\Windows\system32\wuwebv.dll
2018-01-08 19:07:34 ----A---- C:\Windows\system32\wuapp.exe
2018-01-08 19:06:29 ----A---- C:\Windows\system32\drivers\L1C63x64.sys
2018-01-08 18:30:55 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2018-01-08 18:30:55 ----D---- C:\Program Files (x86)\Realtek
2018-01-08 18:27:34 ----D---- C:\ProgramData\Qualcomm Atheros Mobile
2018-01-08 18:12:13 ----D---- C:\Program Files\ProgDVB
2018-01-08 17:50:53 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2018-01-08 17:50:53 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2018-01-08 17:50:53 ----A---- C:\Windows\system32\nvspcap64.dll
2018-01-08 17:50:53 ----A---- C:\Windows\system32\nvspbridge64.dll
2018-01-08 17:50:53 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2018-01-08 17:49:59 ----A---- C:\Windows\system32\nv3dappshextr.dll
2018-01-08 17:49:59 ----A---- C:\Windows\system32\nv3dappshext.dll
2018-01-08 17:49:42 ----A---- C:\Windows\NvContainerRecovery.bat
2018-01-08 17:48:53 ----D---- C:\ProgramData\Package Cache
2018-01-08 17:48:16 ----A---- C:\Windows\SYSWOW64\SET5A74.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\SYSWOW64\SET55CE.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2018-01-08 17:48:16 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2018-01-08 17:48:16 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\SET547F.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\system32\SET5316.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\system32\SET4E0E.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\system32\SET490A.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\system32\SET2483.tmp
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvwgf2umx.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvumdshimx.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvdispgenco6437570.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvdispco6437570.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvd3dumx.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvaudcap64v.dll
2018-01-08 17:48:16 ----A---- C:\Windows\system32\nvapi64.dll
2018-01-08 17:19:10 ----D---- C:\Users\Алексей\AppData\Roaming\DRPSu
2018-01-08 17:04:25 ----D---- C:\ProgramData\NVIDIA
2018-01-08 17:04:06 ----A---- C:\Windows\system32\nvsvcr.dll
2018-01-08 17:04:06 ----A---- C:\Windows\system32\nvsvc64.dll
2018-01-08 17:04:06 ----A---- C:\Windows\system32\nvshext.dll
2018-01-08 17:04:06 ----A---- C:\Windows\system32\nvmctray.dll
2018-01-08 17:04:06 ----A---- C:\Windows\system32\nvcpl.dll
2018-01-08 17:04:00 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2018-01-08 17:04:00 ----A---- C:\Windows\system32\OpenCL.dll
2018-01-08 17:03:59 ----D---- C:\ProgramData\NVIDIA Corporation
2018-01-08 17:03:57 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2018-01-08 17:03:28 ----A---- C:\Windows\system32\nvhdagenco64.dll
2018-01-08 17:03:28 ----A---- C:\Windows\system32\nvdispgenco6434709.dll
2018-01-08 17:03:28 ----A---- C:\Windows\system32\nvdispco6434709.dll
2018-01-08 17:02:35 ----D---- C:\Program Files\NVIDIA Corporation
2018-01-08 17:02:20 ----D---- C:\NVIDIA
2018-01-08 16:59:32 ----SD---- C:\Users\Алексей\AppData\Roaming\Microsoft
2018-01-08 16:59:32 ----D---- C:\Users\Алексей\AppData\Roaming\Yandex
2018-01-08 16:59:32 ----D---- C:\Users\Алексей\AppData\Roaming\WinRAR
2018-01-08 16:59:32 ----D---- C:\Users\Алексей\AppData\Roaming\Identities
2018-01-08 16:59:26 ----SHD---- C:\Recovery
2018-01-08 16:59:25 ----SHD---- C:\ProgramData\Шаблоны
2018-01-08 16:59:25 ----SHD---- C:\ProgramData\Рабочий стол
2018-01-08 16:59:25 ----SHD---- C:\ProgramData\Избранное
2018-01-08 16:59:25 ----SHD---- C:\ProgramData\Документы
2018-01-08 16:59:25 ----SHD---- C:\ProgramData\Главное меню
2018-01-08 16:57:01 ----D---- C:\Windows\SoftwareDistribution
2018-01-08 16:54:44 ----D---- C:\Windows\CSC
2018-01-08 16:54:18 ----SHD---- C:\System Volume Information
2018-01-08 16:54:18 ----ASH---- C:\pagefile.sys
2018-01-08 16:54:18 ----ASH---- C:\hiberfil.sys
2017-12-25 07:07:08 ----A---- C:\Windows\system32\drivers\kneps.sys
2017-12-25 07:07:08 ----A---- C:\Windows\system32\drivers\klwtp.sys
2017-12-25 07:07:08 ----A---- C:\Windows\system32\drivers\kltdi.sys
2017-12-25 07:07:08 ----A---- C:\Windows\system32\drivers\klpd.sys
2017-12-25 07:07:08 ----A---- C:\Windows\system32\drivers\klbackupflt.sys
2017-12-25 07:07:08 ----A---- C:\Windows\system32\drivers\klbackupdisk.sys
2017-12-22 11:05:42 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2017-12-22 11:05:34 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2017-12-22 11:04:31 ----A---- C:\Windows\system32\SRSWOW64.dll
2017-12-22 11:04:31 ----A---- C:\Windows\system32\SRSTSX64.dll
2017-12-22 11:04:31 ----A---- C:\Windows\system32\SRSTSH64.dll
2017-12-22 11:04:31 ----A---- C:\Windows\system32\SRSHP64.dll
2017-12-22 11:04:30 ----A---- C:\Windows\system32\RtPgEx64.dll
2017-12-22 11:04:30 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2017-12-22 11:04:29 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2017-12-22 11:04:29 ----A---- C:\Windows\system32\RtkCfg64.dll
2017-12-22 11:04:28 ----A---- C:\Windows\system32\RtkApi64.dll
2017-12-22 11:04:28 ----A---- C:\Windows\system32\RTEEP64A.dll
2017-12-22 11:04:28 ----A---- C:\Windows\system32\RTEEL64A.dll
2017-12-22 11:04:28 ----A---- C:\Windows\system32\RTEEG64A.dll
2017-12-22 11:04:28 ----A---- C:\Windows\system32\RTEED64A.dll
2017-12-22 11:04:28 ----A---- C:\Windows\system32\RtDataProc64.dll
2017-12-22 11:04:27 ----A---- C:\Windows\system32\RTCOM64.dll
2017-12-22 11:04:27 ----A---- C:\Windows\system32\RP3DHT64.dll
2017-12-22 11:04:27 ----A---- C:\Windows\system32\RP3DAA64.dll
2017-12-22 11:04:27 ----A---- C:\Windows\system32\RltkAPO64.dll
2017-12-22 11:04:26 ----A---- C:\Windows\system32\RCoInstII64.dll
2017-12-22 11:04:11 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2017-12-22 11:04:08 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2017-12-22 11:04:05 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2017-11-02 23:15:40 ----A---- C:\Windows\SYSWOW64\vulkan-1-1-0-65-0.dll
2017-11-02 23:15:26 ----A---- C:\Windows\SYSWOW64\vulkaninfo-1-1-0-65-0.exe
2017-11-02 23:15:04 ----A---- C:\Windows\system32\vulkan-1-1-0-65-0.dll
2017-11-02 23:14:46 ----A---- C:\Windows\system32\vulkaninfo-1-1-0-65-0.exe

====== Список файлов и папок, измененных за последние 3 месяца ======

2018-01-10 13:20:40 ----D---- C:\Windows\Temp
2018-01-10 12:16:49 ----D---- C:\Windows\system32\DriverStore
2018-01-10 12:16:49 ----D---- C:\Windows\system32\catroot
2018-01-10 12:16:48 ----D---- C:\Windows\inf
2018-01-10 12:15:46 ----D---- C:\Windows\System32
2018-01-10 12:15:46 ----AD---- C:\Windows\SysWOW64
2018-01-10 12:15:44 ----D---- C:\Windows\system32\Tasks
2018-01-10 12:14:46 ----D---- C:\Windows\system32\drivers
2018-01-10 10:05:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2018-01-10 10:03:10 ----RD---- C:\Program Files (x86)
2018-01-10 10:02:17 ----D---- C:\Windows
2018-01-10 10:02:11 ----D---- C:\Windows\system32\catroot2
2018-01-10 09:49:37 ----RD---- C:\Program Files
2018-01-09 14:35:30 ----RSD---- C:\Windows\assembly
2018-01-09 14:23:05 ----D---- C:\Windows\system32\config
2018-01-09 14:21:30 ----D---- C:\Windows\Logs
2018-01-09 13:10:09 ----D---- C:\Windows\system32\wdi
2018-01-09 12:12:57 ----D---- C:\Windows\Microsoft.NET
2018-01-08 21:44:53 ----SHD---- C:\Windows\Installer
2018-01-08 21:34:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2018-01-08 21:27:37 ----HD---- C:\ProgramData
2018-01-08 21:27:37 ----D---- C:\Windows\winsxs
2018-01-08 20:26:28 ----D---- C:\Program Files\Common Files
2018-01-08 20:25:48 ----D---- C:\Windows\SYSWOW64\config
2018-01-08 20:21:41 ----D---- C:\Windows\SYSWOW64\ru-RU
2018-01-08 20:21:41 ----D---- C:\Windows\system32\ru-RU
2018-01-08 20:21:40 ----D---- C:\Windows\SYSWOW64\migration
2018-01-08 20:21:40 ----D---- C:\Windows\SYSWOW64\en-US
2018-01-08 20:21:40 ----D---- C:\Windows\system32\migration
2018-01-08 20:21:40 ----D---- C:\Windows\system32\en-US
2018-01-08 20:21:40 ----D---- C:\Program Files\DVD Maker
2018-01-08 20:21:39 ----D---- C:\Windows\system32\CodeIntegrity
2018-01-08 20:21:39 ----D---- C:\Windows\system32\Boot
2018-01-08 20:21:39 ----D---- C:\Windows\AppPatch
2018-01-08 20:16:26 ----D---- C:\Program Files (x86)\Common Files
2018-01-08 20:12:58 ----D---- C:\Program Files (x86)\MSBuild
2018-01-08 20:12:53 ----D---- C:\Windows\ShellNew
2018-01-08 20:12:49 ----RSD---- C:\Windows\Fonts
2018-01-08 20:12:47 ----SD---- C:\ProgramData\Microsoft
2018-01-08 20:11:09 ----A---- C:\Windows\win.ini
2018-01-08 19:34:47 ----D---- C:\Windows\Tasks
2018-01-08 19:14:31 ----AD---- C:\Windows\system
2018-01-08 18:19:07 ----D---- C:\Windows\system32\NDF
2018-01-08 17:51:15 ----D---- C:\Windows\Prefetch
2018-01-08 17:18:57 ----D---- C:\Windows\system32\drivers\UMDF
2018-01-08 17:08:29 ----D---- C:\driversinstall
2018-01-08 17:05:43 ----D---- C:\Windows\system32\restore
2018-01-08 17:04:06 ----D---- C:\Windows\Help
2018-01-08 16:59:53 ----SHD---- C:\$Recycle.Bin
2018-01-08 16:59:31 ----RD---- C:\Users
2018-01-08 16:59:28 ----D---- C:\Windows\Panther
2018-01-08 16:59:26 ----D---- C:\Program Files\Windows NT
2018-01-08 16:59:08 ----D---- C:\Windows\rescache
2018-01-08 16:59:03 ----D---- C:\Windows\debug

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

====== Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено) ======

R0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit); C:\Windows\system32\DRIVERS\cm_km.sys [2016-12-26 247008]
R0 iusb3hcs;Драйвер хост-контроллера и коммутатора Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-09-17 20464]
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2016-10-01 554408]
R0 klbackupdisk;Kaspersky Lab klbackupdisk; C:\Windows\system32\DRIVERS\klbackupdisk.sys [2017-12-25 70880]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\Windows\system32\DRIVERS\klbackupflt.sys [2017-12-25 117984]
R1 KLHK;Kaspersky Lab service driver; C:\Windows\system32\DRIVERS\klhk.sys [2018-01-08 350944]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2018-01-08 1071808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2016-10-11 57936]
R1 klpd;Kaspersky Lab format recognizer driver; C:\Windows\system32\DRIVERS\klpd.sys [2017-12-25 50672]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2017-12-25 81904]
R1 Klwtp;KLwtp - WFP callout traffic inspector; C:\Windows\system32\DRIVERS\klwtp.sys [2017-12-25 140000]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2017-12-25 199392]
R2 kldisk;kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [2016-05-31 78216]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2017-12-13 6083008]
R3 iusb3hub;Драйвер концентратора Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2013-09-17 358896]
R3 iusb3xhc;Драйвер расширяемого хост-контроллера Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2013-09-17 795632]
R3 klflt;Kaspersky Lab Kernel DLL; C:\Windows\system32\DRIVERS\klflt.sys [2018-01-08 206040]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2016-12-23 57568]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2016-12-07 58592]
R3 kltap;Kaspersky Security Data Escort Adapter; C:\Windows\system32\DRIVERS\kltap.sys [2016-06-07 52152]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C63x64.sys [2016-01-29 125048]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2018-01-04 226760]
R3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2018-01-06 31032]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2017-12-15 59240]
R3 nvvhci;NVVHCI Enumerator Service; C:\Windows\system32\DRIVERS\nvvhci.sys [2018-01-04 57792]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 E1G60;Драйвер адаптера Intel(R) PRO/1000 NDIS 6; C:\Windows\system32\DRIVERS\E1G6032E.sys [2009-06-10 145792]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver; C:\Windows\system32\drivers\Synth3dVsc.sys [2010-11-21 88960]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2017-10-10 27136]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;Remote Deskotop USB Hub; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

====== Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено) ======

R2 AVP18.0.0;Kaspersky Anti-Virus Service 18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\avp.exe [2017-01-24 354672]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\cscsvc.dll
R2 KSDE2.0.0;Kaspersky Secure Connection Service 2.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe [2017-01-24 354672]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-01-06 519992]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2018-01-04 464744]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2018-01-06 461616]
R3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-01-06 519992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-10-04 107624]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-10-03 128608]
S2 gupdate;Служба Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-07 153752]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-09 272384]
S3 AppMgmt;@appmgmts.dll,-3250; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll" = %SystemRoot%\System32\appmgmts.dll
S3 gupdatem;Служба Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-07 153752]
S3 klvssbridge64_18.0.0;klvssbridge64_18.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 18.0.0\x64\vssbridge64.exe [2018-01-08 426416]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; %SystemRoot%\System32\svchost.exe -k PeerDist;"ServiceDll" = %SystemRoot%\system32\peerdistsvc.dll
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-12-15 1644832]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\umrdp.dll
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-10-03 52832]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-10-04 136288]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-10-04 136288]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-10-04 136288]

-----------------EOF-----------------
