Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-08-2020 Ran by Степа (administrator) on STEPA (31-08-2020 16:37:43) Running from C:\Users\Степа\Desktop Loaded Profiles: Степа Platform: Windows 7 Professional Service Pack 1 (X64) Language: Русский (Россия) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Acronis International GmbH -> ) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis International GmbH -> Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Brio) [File not signed] C:\Program Files\FolderSize\FolderSizeSvc.exe (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <2> (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avpui.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\wmi64.exe (LLC Mail.Ru -> Mail.Ru) C:\Users\Степа\AppData\Local\Mail.Ru\MailRuUpdater.exe (Logitech, Inc. -> Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe (LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe (Microsoft Corporation) [File not signed] C:\ProgramData\RealtekHD\taskhost.exe (Microsoft Corporation) [File not signed] C:\ProgramData\RunDLL\rundll.exe (Microsoft Corporation) [File not signed] C:\ProgramData\RunDLL\system.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\alg.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe <2> (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectMonitor.exe (Paramount Software UK Ltd -> Paramount Software UK Ltd) C:\Program Files\Macrium\Common\ReflectUI.exe (Realtek Semiconductor) [File not signed] C:\ProgramData\RealtekHD\taskhostw.exe (SafeNet Canada, Inc. -> SafeNet, Inc.) C:\Windows\System32\hasplms.exe (SafeNet Canada, Inc. -> SafeNet, Inc.) C:\Windows\System32\hasplmv.exe <2> (Tencent Technology(Shenzhen) Company Limited -> Tencent) C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [FlightSupport] => C:\Program Files\Logitech\FlightSupport\FlightSupport.exe [368776 2018-09-04] (Logitech Inc -> Logitech) HKLM\...\Run: [X52] => C:\Program Files\Logitech\X52\X52_Profiler.exe [17920 2018-09-04] (Logitech) [File not signed] HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [353776 2020-07-31] (Riot Games, Inc. -> Riot Games, Inc.) HKLM\...\Run: [Reflect UI] => C:\Program Files\Macrium\Common\ReflectUI.exe [7509728 2020-08-05] (Paramount Software UK Ltd -> Paramount Software UK Ltd) HKLM\...\Run: [Realtek HD Audio] => C:\ProgramData\RealtekHD\taskhostw.exe [3027968 2020-05-05] (Realtek Semiconductor) [File not signed] <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9532120 2017-04-11] (Piriform Ltd -> Piriform Ltd) HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [Folder Size] => C:\Program Files\FolderSize\FolderSize.exe [169472 2013-02-13] (Brio) [File not signed] HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [Discord] => C:\Users\Степа\AppData\Local\Discord\app-0.0.307\Discord.exe [91023672 2020-08-04] (Discord Inc. -> Discord Inc.) HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [MailRuUpdater] => C:\Users\Степа\AppData\Local\Mail.Ru\MailRuUpdater.exe [3255480 2019-08-07] (LLC Mail.Ru -> Mail.Ru) <==== ATTENTION HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [com.blitz.app] => C:\Users\Степа\AppData\Local\Programs\Blitz\Blitz.exe [108260048 2020-08-28] (Swift Media Entertainment, Inc. -> Blitz, Inc.) HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3377440 2020-07-31] (Valve -> Valve Corporation) HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [1] eav_trial_rus.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [2] avast_free_antivirus_setup_online.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [3] eis_trial_rus.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [4] essf_trial_rus.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [5] hitmanpro_x64.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [6] ESETOnlineScanner_UKR.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [7] ESETOnlineScanner_RUS.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [8] HitmanPro.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [9] 360TS_Setup_Mini.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [10] Cezurity_Scanner_Pro_Free.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\Policies\Explorer\DisallowRun: [11] Cube.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: J - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {0be89d98-137b-11e7-890f-8c89a5c892db} - J:\Setup.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {77fdf047-5121-11e9-b5b0-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {866b30a1-c3a1-11e7-8c03-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {90a1244e-b2bf-11e6-8972-c7c3005845a5} - K:\LGAutoRun.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {be0b0aab-a7e3-11e9-89f4-8c89a5c892db} - L:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {d38c54b1-e8c3-11e8-b0e2-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKU\S-1-5-21-3129829678-2388851804-851762452-1000\...\MountPoints2: {fb251bd2-9af8-11e8-8d59-8c89a5c892db} - J:\HiSuiteDownLoader.exe HKLM\...\Print\Monitors\HP a211 Status Monitor: C:\Windows\system32\hpinkstsa211LM.dll [354152 2011-06-09] (Hewlett Packard -> Hewlett-Packard Co.) HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP Deskjet 3070 B611 series): C:\Windows\system32\HPDiscoPMa211.dll [778088 2011-06-08] (Hewlett Packard -> Hewlett-Packard Co.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.83\Installer\chrmstp.exe [2020-08-29] (Google LLC -> Google LLC) HKLM\Software\...\Winlogon\GPExtensions: [{C631DF4C-088F-4156-B058-4375F0853CD8}] -> C:\Windows\System32\cscobj.dll [2010-11-21] (Microsoft Windows -> Корпорация Майкрософт) GroupPolicy: Restriction ? <==== ATTENTION GroupPolicy\User: Restriction ? <==== ATTENTION FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1E72F7FC-E997-4B77-923A-86678B59890C} - System32\Tasks\Microsoft\Windows\Wininet\Taskhost => C:\Programdata\RealtekHD\taskhostw.exe [3027968 2020-05-05] (Realtek Semiconductor) [File not signed] <==== ATTENTION Task: {51067BA9-EB58-45E7-A104-E6548E76C80A} - System32\Tasks\Microsoft\Windows\Wininet\Taskhostw => C:\Programdata\RealtekHD\taskhostw.exe [3027968 2020-05-05] (Realtek Semiconductor) [File not signed] <==== ATTENTION Task: {718663C5-2A92-477F-8AF6-D426E2D9BDB2} - System32\Tasks\Microsoft\Windows\Wininet\Cleaner => C:\Programdata\WindowsTask\winlogon.exe [390144 2019-04-19] () [File not signed] <==== ATTENTION Task: {9ED7D791-5E25-4A01-BDDE-BF62E3AC47F4} - System32\Tasks\Microsoft\Windows\Wininet\RealtekHDStartUP => C:\Programdata\RealtekHD\taskhost.exe [1767424 2020-05-05] (Microsoft Corporation) [File not signed] <==== ATTENTION Task: {CB3B5721-A5BB-47EB-BD5D-3D963B9ABD9B} - System32\Tasks\Microsoft\Windows\Wininet\RealtekHDControl => C:\Programdata\RealtekHD\taskhost.exe [1767424 2020-05-05] (Microsoft Corporation) [File not signed] <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{00DC326C-E3A9-49F4-A3FC-61E6EC7FBCFE}: [DhcpNameServer] 192.168.1.2 Tcpip\..\Interfaces\{866F17FB-A432-4163-8DD2-240F2428B3CE}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{9F444B6F-15EB-4A7D-A690-78E7B894E19A}: [DhcpNameServer] 192.168.1.2 Tcpip\..\Interfaces\{EE887A6A-4DF7-4D45-85B1-FF0F50AAF25A}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKU\S-1-5-21-3129829678-2388851804-851762452-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/ru-ru/?ocid=iehp SearchScopes: HKU\S-1-5-21-3129829678-2388851804-851762452-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={SearchTerms}&fr=iextn&gp=821273 SearchScopes: HKU\S-1-5-21-3129829678-2388851804-851762452-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?q={SearchTerms}&fr=iextn&gp=821273 BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-08-17] (Oracle America, Inc. -> Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-08-17] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll [2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) Toolbar: HKU\S-1-5-21-3129829678-2388851804-851762452-1000 -> Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) Handler: soloresinternetrusengnum - {1B7043A7-84E1-443a-804F-20A75728892C} - D:\SOLO9R~1\SoloRes.dll No File FireFox: ======== FF DefaultProfile: mxir2ml3.default FF ProfilePath: C:\Users\Степа\AppData\Roaming\Mozilla\Firefox\Profiles\mxir2ml3.default-release [2020-08-19] FF DownloadDir: L:\Загрузки FF Extension: (AdGuard Антибаннер) - C:\Users\Степа\AppData\Roaming\Mozilla\Firefox\Profiles\mxir2ml3.default-release\Extensions\adguardadblocker@adguard.com.xpi [2020-08-10] FF ProfilePath: C:\Users\Степа\AppData\Roaming\Mozilla\Firefox\Profiles\mxir2ml3.default [2020-08-19] FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-10-19] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_414.dll [2020-08-12] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-08-17] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-08-17] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_414.dll [2020-08-12] (Adobe Inc. -> ) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin HKU\S-1-5-21-3129829678-2388851804-851762452-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Степа\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies SF -> Unity Technologies ApS) Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default [2020-08-19] CHR Extension: (Презентации) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-08-19] CHR Extension: (Документы) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-08-19] CHR Extension: (Диск Google) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-08-19] CHR Extension: (YouTube) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-08-19] CHR Extension: (Tampermonkey) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2020-08-19] CHR Extension: (Avast SafePrice | Сравнения, предложения, купоны) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-08-19] CHR Extension: (Таблицы) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-08-19] CHR Extension: (Kaspersky Protection) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2020-08-19] CHR Extension: (Google Документы офлайн) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-08-19] CHR Extension: (Avast Online Security) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-08-19] CHR Extension: (MeddleMonkey) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\moihledlmchhofenpacbhphnbnpakgmo [2020-08-19] CHR Extension: (Платежная система Интернет-магазина Chrome) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-08-19] CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\odijcgafkhpobjlnfdgiacpdenpmbgme [2020-08-19] CHR Extension: (Поиск Mail.Ru) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\phkdcinmmljblpnkohlipaiodlonpinf [2020-08-19] CHR Extension: (Gmail) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-08-19] CHR Extension: (Chrome Media Router) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-08-19] CHR Extension: (Визуальные закладки) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmpoaahleccaibbhfjfimigepmfmmbbk [2020-08-19] CHR Profile: C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-08-31] CHR Notifications: Profile 1 -> hxxps://www.youtube.com CHR HomePage: Profile 1 -> hxxp://vk.com/ CHR StartupUrls: Profile 1 -> "hxxp://www.yandex.ru/","hxxp://youtube.com/" CHR DefaultSearchURL: Profile 1 -> hxxps://yandex.ru/{yandex:searchPath}?text={searchTerms}&{yandex:referralID} CHR DefaultSearchKeyword: Profile 1 -> yandex.ru CHR DefaultNewTabURL: Profile 1 -> hxxps://www.yandex.ru/chrome/newtab CHR DefaultSuggestURL: Profile 1 -> hxxps://suggest.yandex.ru/suggest-ff.cgi?part={searchTerms} CHR Extension: (Презентации) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-08-19] CHR Extension: (Яндекс) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akkhkcocfnopiccplnimkefmaejepdlj [2020-08-19] CHR Extension: (Документы) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-08-19] CHR Extension: (Диск Google) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-08-19] CHR Extension: (AdGuard Антибаннер) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2020-08-19] CHR Extension: (YouTube) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-08-19] CHR Extension: (Таблицы) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-08-19] CHR Extension: (Google Документы офлайн) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-08-19] CHR Extension: (Space) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hepnfgiockihbakjbhonkinpagbkaobo [2020-08-19] CHR Extension: (Платежная система Интернет-магазина Chrome) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-08-19] CHR Extension: (Gmail) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-08-19] CHR Extension: (Chrome Media Router) - C:\Users\Степа\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-08-29] CHR Profile: C:\Users\Степа\AppData\Local\Google\Chrome\User Data\System Profile [2020-08-19] CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib CHR HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] CHR HKU\S-1-5-21-3129829678-2388851804-851762452-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [moihledlmchhofenpacbhphnbnpakgmo] CHR HKLM-x32\...\Chrome\Extension: [ajflepegnononcfmoikdnephfleldnbh] CHR HKLM-x32\...\Chrome\Extension: [bobeehhgpnppdghmfffdjadmbjbaeeod] CHR HKLM-x32\...\Chrome\Extension: [ccfifbojenkenpkmnbnndeadpfdiffof] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] CHR HKLM-x32\...\Chrome\Extension: [indjgiebmakhmnaplnlnanodkfiejfjd] CHR HKLM-x32\...\Chrome\Extension: [odijcgafkhpobjlnfdgiacpdenpmbgme] CHR HKLM-x32\...\Chrome\Extension: [oelpkepjlgmehajehfeicfbjdiobdkfj] CHR HKLM-x32\...\Chrome\Extension: [ojlcebdkbpjdpiligkdbbkdkfjmchbfd] CHR HKLM-x32\...\Chrome\Extension: [phkdcinmmljblpnkohlipaiodlonpinf] CHR HKLM-x32\...\Chrome\Extension: [pmpoaahleccaibbhfjfimigepmfmmbbk] Opera: ======= OPR Extension: (Советник Яндекс.Маркета) - C:\Users\Степа\AppData\Roaming\Opera Software\Opera Stable\Extensions\dmdhajlcfmlocjeihknhbbekjaageelh [2017-07-15] OPR Extension: (SaveFrom.net helper) - C:\Users\Степа\AppData\Roaming\Opera Software\Opera Stable\Extensions\npdpplbicnmpoigidfdjadamgfkilaak [2017-10-01] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-12] (Adobe Inc. -> Adobe) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.) [File not signed] R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7356680 2018-11-19] (BattlEye Innovations e.K. -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803952 2019-08-02] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) R2 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [163840 2013-02-13] (Brio) [File not signed] R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.) R2 hasplms; C:\Windows\system32\hasplms.exe [4502024 2018-03-29] (SafeNet Canada, Inc. -> SafeNet, Inc.) S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab) S3 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.) R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [7409472 2020-08-05] (Paramount Software UK Ltd -> Paramount Software UK Ltd) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.599\McCHSvc.exe [404376 2017-09-05] (McAfee, Inc. -> McAfee, Inc.) S3 mracsvc; C:\Windows\System32\mracsvc.exe [20321952 2020-06-06] (Mail.Ru LLC -> LLC Mail.Ru) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2019-06-18] (Even Balance, Inc. -> ) R2 QMEmulatorService; C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe [343288 2019-03-13] (Tencent Technology(Shenzhen) Company Limited -> Tencent) S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [9754048 2020-07-31] (Riot Games, Inc. -> Riot Games, Inc.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation) S2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [X] ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices, Inc. -> Advanced Micro Devices) S3 atikmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [5020672 2009-07-14] () [File not signed] R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (Kaspersky Lab -> AO Kaspersky Lab) S3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [94208 2013-08-05] (Etron Technology Inc) [File not signed] R3 EuMusDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\vrtaucbl.sys [110368 2017-06-22] (Muzychenko Evgenii Viktorovich -> Eugene V. Muzychenko) R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [1304816 2018-03-29] (SafeNet, Inc. -> SafeNet, Inc.) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (Kaspersky Lab -> AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (Kaspersky Lab -> AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-14] (Kaspersky Lab -> AO Kaspersky Lab) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [78216 2016-05-31] (Kaspersky Lab -> AO Kaspersky Lab) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [195288 2017-10-19] (Kaspersky Lab -> AO Kaspersky Lab) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [348376 2017-10-19] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1038552 2017-10-19] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [57936 2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [52144 2016-05-18] (Kaspersky Lab -> AO Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab -> Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-05-31] (Kaspersky Lab -> AO Kaspersky Lab) R3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [75696 2016-05-17] (Kaspersky Lab -> AO Kaspersky Lab) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [135904 2017-04-29] (Kaspersky Lab -> AO Kaspersky Lab) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [199640 2017-10-19] (Kaspersky Lab -> AO Kaspersky Lab) R3 LSaiMini; C:\Windows\System32\DRIVERS\LSaiMini.sys [20720 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech) R3 LSaiNtBus; C:\Windows\System32\drivers\LSaiBus.sys [60336 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech) R0 mountmgr; C:\Windows\System32\drivers\mountmgr.sys [94440 2019-06-12] (Microsoft Windows -> Корпорация Майкрософт) S3 mracdrv; C:\Windows\System32\drivers\mracdrv1.sys [19551936 2020-06-06] (Mail.Ru LLC -> LLC Mail.Ru) S3 PortTalk; C:\Windows\SysWOW64\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic hxxp://www.beyondlogic.org) [File not signed] R3 SaiK075C; C:\Windows\System32\DRIVERS\SaiK075C.sys [217408 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech) R3 SaiU075C; C:\Windows\System32\DRIVERS\SaiU075C.sys [24816 2018-09-04] (WDKTestCert SYSTEM,131245371151827277 -> Logitech) R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-30] (SOKNO S.R.L. -> Almico Software) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> ) S1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [5395880 2020-07-31] (Riot Games, Inc. -> Riot Games, Inc.) R0 volmgrx; C:\Windows\System32\drivers\volmgrx.sys [363752 2017-07-07] (Microsoft Windows -> Корпорация Майкрософт) S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X] S3 taphss6; system32\DRIVERS\taphss6.sys [X] S3 VBAudioVACMME; system32\DRIVERS\vbaudio_cable64_win7.sys [X] S3 X6va064; \??\C:\Windows\SysWOW64\Drivers\X6va064 [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-08-31 16:37 - 2020-08-31 16:38 - 000031234 _____ C:\Users\Степа\Desktop\FRST.txt 2020-08-31 16:37 - 2020-08-31 16:38 - 000000000 ____D C:\FRST 2020-08-31 16:36 - 2020-08-31 16:36 - 002298880 _____ (Farbar) C:\Users\Степа\Desktop\FRST64.exe 2020-08-30 22:47 - 2020-08-30 22:47 - 000477836 _____ C:\Users\Степа\Desktop\imgonline-com-ua-BigPicture-dP8bU8NP14mRxV.psd 2020-08-30 19:52 - 2020-08-30 19:52 - 000000000 ____D C:\Users\Степа\Desktop\AutoLogger 2020-08-30 19:52 - 2020-08-30 19:21 - 015225543 _____ (Company © regist & Drongo) C:\Users\Степа\Desktop\AutoLogger.pif 2020-08-29 23:45 - 2020-08-30 00:04 - 000000000 ____D C:\AutoLogger 2020-08-29 23:44 - 2020-08-29 07:10 - 015045293 _____ (Company © regist & Drongo) C:\Users\Степа\Desktop\AutoLogger.exe 2020-08-29 23:25 - 2020-08-29 23:25 - 000000000 ____D C:\Users\Степа\AppData\Roaming\KillProcess 2020-08-29 23:22 - 2020-08-29 23:22 - 000000000 ____D C:\Users\Степа\Documents\KillProcess Kill Lists 2020-08-29 23:22 - 2020-08-29 23:22 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KillProcess 2020-08-29 23:22 - 2020-08-29 23:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KillProcess 2020-08-29 23:22 - 2020-08-29 23:22 - 000000000 ____D C:\Program Files (x86)\KillProcess 2020-08-29 22:52 - 2020-08-29 22:52 - 000233960 _____ C:\Windows\ntbtlog.txt 2020-08-29 19:06 - 2020-08-29 19:06 - 000000000 ____D C:\Users\Все пользователи\Tencent 2020-08-29 19:06 - 2020-08-29 19:06 - 000000000 ____D C:\ProgramData\Tencent 2020-08-29 13:47 - 2020-08-29 13:47 - 000001051 _____ C:\Users\Все пользователи\Desktop\Guitar Rig 5.lnk 2020-08-29 13:47 - 2020-08-29 13:47 - 000001051 _____ C:\Users\Public\Desktop\Guitar Rig 5.lnk 2020-08-29 13:47 - 2020-08-29 13:47 - 000001051 _____ C:\ProgramData\Desktop\Guitar Rig 5.lnk 2020-08-29 13:47 - 2020-08-29 13:47 - 000000000 __HDC C:\Users\Все пользователи\{DA31E3B5-AD7E-4759-A162-75CF964B70AC} 2020-08-29 13:47 - 2020-08-29 13:47 - 000000000 __HDC C:\ProgramData\{DA31E3B5-AD7E-4759-A162-75CF964B70AC} 2020-08-29 13:46 - 2020-08-29 13:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments 2020-08-29 13:46 - 2020-08-29 13:46 - 000000000 ____D C:\Program Files\Common Files\Native Instruments 2020-08-29 13:44 - 2020-08-29 13:44 - 000000000 ____D C:\Program Files\Native Instruments 2020-08-28 14:28 - 2020-08-28 14:28 - 000032768 _____ C:\Users\Все пользователи\Documents\crash_dump.bin 2020-08-28 14:28 - 2020-08-28 14:28 - 000032768 _____ C:\Users\Public\Documents\crash_dump.bin 2020-08-28 14:28 - 2020-08-28 14:28 - 000032768 _____ C:\ProgramData\Documents\crash_dump.bin 2020-08-26 23:46 - 2020-08-26 23:47 - 000000000 ____D C:\Users\Stepa-2\AppData\Roaming\Sony 2020-08-26 23:46 - 2020-08-26 23:46 - 000000000 ____D C:\Users\Stepa-2\AppData\Local\CEF 2020-08-26 23:45 - 2020-08-26 23:46 - 000000000 ____D C:\Users\Stepa-2\AppData\Local\NVIDIA Corporation 2020-08-26 23:45 - 2020-08-26 23:45 - 000070568 _____ C:\Users\Stepa-2\AppData\Local\GDIPFONTCACHEV1.DAT 2020-08-26 23:45 - 2020-08-26 23:45 - 000002258 _____ C:\Users\Stepa-2\Desktop\Google Chrome.lnk 2020-08-26 23:45 - 2020-08-26 23:45 - 000001412 _____ C:\Users\Stepa-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2020-08-26 23:45 - 2020-08-26 23:45 - 000000020 ___SH C:\Users\Stepa-2\ntuser.ini 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\Шаблоны 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\Мои документы 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\Главное меню 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\Documents\Моя музыка 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\Documents\Мои рисунки 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\Documents\Мои видеозаписи 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 _SHDL C:\Users\Stepa-2\AppData\Roaming\Microsoft\Windows\Start Menu\Программы 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 ____D C:\Users\Stepa-2\AppData\Roaming\Adobe 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 ____D C:\Users\Stepa-2\AppData\Local\Google 2020-08-26 23:45 - 2020-08-26 23:45 - 000000000 ____D C:\Users\Stepa-2 2020-08-26 23:45 - 2020-08-14 12:52 - 000000000 ____D C:\Users\Stepa-2\AppData\Local\NVIDIA 2020-08-26 23:45 - 2017-12-07 13:18 - 000000000 ____D C:\Users\Stepa-2\AppData\Local\Microsoft Help 2020-08-26 23:45 - 2017-03-04 10:20 - 000000000 ____D C:\Users\Stepa-2\AppData\Local\CrashRpt 2020-08-26 23:45 - 2011-04-12 18:37 - 000000000 ____D C:\Users\Stepa-2\AppData\Roaming\Media Center Programs 2020-08-26 23:34 - 2020-08-26 23:34 - 000000000 ____D C:\TMP 2020-08-26 23:29 - 2020-08-26 23:29 - 000000000 ____D C:\Sony_Vegas_13_x64 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\Norton 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\grizzly 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\ESET 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\360safe 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\Norton 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\grizzly 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\ESET 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\360safe 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\SpyHunter 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Malwarebytes 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Kaspersky Lab 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\ESET 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Enigma Software Group 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\COMODO 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Common Files\McAfee 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\Cezurity 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\AVG 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files\AVAST Software 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\SpyHunter 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\Panda Security 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\GRIZZLY Antivirus 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\Cezurity 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\AVG 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\AVAST Software 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 __SHD C:\Program Files (x86)\360 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 ____D C:\Users\Все пользователи\Avira 2020-08-26 23:28 - 2020-08-26 23:28 - 000000000 ____D C:\ProgramData\Avira 2020-08-26 23:27 - 2020-08-31 16:36 - 000000000 __SHD C:\Users\Все пользователи\WindowsTask 2020-08-26 23:27 - 2020-08-31 16:36 - 000000000 __SHD C:\Users\Все пользователи\RunDLL 2020-08-26 23:27 - 2020-08-31 16:36 - 000000000 __SHD C:\ProgramData\WindowsTask 2020-08-26 23:27 - 2020-08-31 16:36 - 000000000 __SHD C:\ProgramData\RunDLL 2020-08-26 23:27 - 2020-08-29 19:04 - 000000000 __SHD C:\AdwCleaner 2020-08-26 23:27 - 2020-08-26 23:47 - 000000000 __SHD C:\Users\Все пользователи\Setup 2020-08-26 23:27 - 2020-08-26 23:47 - 000000000 __SHD C:\ProgramData\Setup 2020-08-26 23:27 - 2020-08-26 23:28 - 000000000 __SHD C:\Users\Все пользователи\RealtekHD 2020-08-26 23:27 - 2020-08-26 23:28 - 000000000 __SHD C:\ProgramData\RealtekHD 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 __SHD C:\Program Files\ByteFence 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 __SHD C:\Program Files (x86)\Microsoft JDX 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 __SHD C:\KVRT_Data 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Windows\speechstracing 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Users\Все пользователи\System32 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Users\Все пользователи\MB3Install 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Users\Все пользователи\Malwarebytes 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Users\Все пользователи\install 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\Users\Все пользователи\Indus 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\System32 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\MB3Install 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\Malwarebytes 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\install 2020-08-26 23:27 - 2020-08-26 23:27 - 000000000 ____D C:\ProgramData\Indus 2020-08-26 23:18 - 2020-08-26 23:18 - 000000000 ____D C:\Users\Степа\AppData\Local\MAGIX 2020-08-26 23:17 - 2020-08-26 23:17 - 000000000 ____D C:\Users\Степа\AppData\Roaming\VEGAS Pro 2020-08-26 23:12 - 2020-08-26 23:17 - 000000000 ____D C:\Users\Все пользователи\Magix 2020-08-26 23:12 - 2020-08-26 23:17 - 000000000 ____D C:\ProgramData\Magix 2020-08-26 23:12 - 2020-08-26 23:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS 2020-08-26 23:12 - 2020-08-26 23:12 - 000000000 ____D C:\Program Files\VEGAS 2020-08-26 22:46 - 2020-08-26 23:17 - 000000000 ____D C:\Users\Степа\AppData\Local\VEGAS Pro 2020-08-26 22:46 - 2020-08-26 23:12 - 000000000 ____D C:\Users\Все пользователи\VEGAS 2020-08-26 22:46 - 2020-08-26 23:12 - 000000000 ____D C:\ProgramData\VEGAS 2020-08-26 22:46 - 2020-08-26 22:46 - 000000000 ____D C:\Users\Степа\AppData\Roaming\MAGIX Computer Products Intl. Co 2020-08-26 22:46 - 2020-08-26 22:46 - 000000000 ____D C:\Users\Степа\AppData\Roaming\MAGIX 2020-08-26 22:46 - 2020-08-26 22:46 - 000000000 ____D C:\Users\Степа\AppData\Local\VEGAS 2020-08-25 17:50 - 2020-08-25 17:53 - 000000000 ____D C:\Program Files (x86)\Photoshop CS6 2020-08-25 14:53 - 2020-08-28 20:44 - 000000151 _____ C:\Users\Степа\AppData\Local\dc4f79923a5baeb14164.bin 2020-08-25 14:53 - 2020-08-28 20:44 - 000000121 _____ C:\Users\Все пользователи\fb948b48afea7b43ea1e3256.bin 2020-08-25 14:53 - 2020-08-28 20:44 - 000000121 _____ C:\ProgramData\fb948b48afea7b43ea1e3256.bin 2020-08-25 14:40 - 2020-08-25 14:40 - 000000561 _____ C:\Users\Степа\Desktop\Malinovka.lnk 2020-08-25 14:40 - 2020-08-25 14:40 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malinovka 2020-08-21 15:38 - 2020-08-21 15:38 - 000000000 ____D C:\Users\Степа\AppData\Local\Roblox 2020-08-21 15:37 - 2020-08-21 15:37 - 000000000 ____D C:\Users\Все пользователи\Roblox 2020-08-21 15:37 - 2020-08-21 15:37 - 000000000 ____D C:\ProgramData\Roblox 2020-08-21 15:37 - 2020-08-21 15:37 - 000000000 ____D C:\Program Files (x86)\Roblox 2020-08-21 14:18 - 2020-08-21 14:18 - 000000000 ____D C:\Users\Степа\AppData\Local\SwGame 2020-08-21 13:40 - 2020-08-21 13:40 - 000000000 ____D C:\Users\Все пользователи\Origin 2020-08-21 13:40 - 2020-08-21 13:40 - 000000000 ____D C:\ProgramData\Origin 2020-08-20 22:26 - 2020-08-20 22:26 - 000001258 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk 2020-08-20 22:26 - 2020-08-20 22:26 - 000001246 _____ C:\Users\Все пользователи\Desktop\Epic Games Launcher.lnk 2020-08-20 22:26 - 2020-08-20 22:26 - 000001246 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk 2020-08-20 22:26 - 2020-08-20 22:26 - 000001246 _____ C:\ProgramData\Desktop\Epic Games Launcher.lnk 2020-08-20 20:57 - 2020-08-28 21:12 - 000000000 ____D C:\Users\Степа\AppData\Roaming\blitz-core 2020-08-20 20:51 - 2020-08-20 20:48 - 067110624 _____ (Blitz, Inc.) C:\Blitz-1.11.12.exe 2020-08-20 17:27 - 2020-08-20 17:27 - 000000000 ____D C:\Users\Степа\Desktop\F-16A Моделист 2020-08-20 14:41 - 2020-08-20 15:02 - 000000000 ____D C:\Users\Степа\Desktop\Су-57 Звезда 2020-08-19 12:37 - 2020-08-29 18:57 - 000002227 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-08-19 12:37 - 2020-08-25 17:53 - 000000000 ____D C:\Users\Степа\AppData\Local\Google 2020-08-17 21:41 - 2020-08-17 21:41 - 000000000 ____D C:\Users\Степа\AppData\Local\Origin 2020-08-17 14:43 - 2020-08-17 14:43 - 000000000 ____D C:\Users\GLCache\e121e7f940050434e3607f793b00d59f 2020-08-15 22:45 - 2020-08-16 00:22 - 000000000 ____D C:\Users\Степа\Documents\Reflect 2020-08-15 22:42 - 2020-08-15 22:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium 2020-08-15 22:42 - 2020-08-15 22:42 - 000000000 ____D C:\Program Files\Macrium 2020-08-15 22:39 - 2020-08-15 22:43 - 000000000 ____D C:\Users\Все пользователи\Macrium 2020-08-15 22:39 - 2020-08-15 22:43 - 000000000 ____D C:\ProgramData\Macrium 2020-08-15 20:22 - 2020-08-16 11:55 - 000000048 _____ C:\Windows\SysWOW64\EUTB.TODJ 2020-08-15 20:22 - 2020-08-15 20:22 - 000000000 ____D C:\Users\Степа\AppData\Local\AdvertisingPopup 2020-08-15 20:22 - 2020-08-15 20:22 - 000000000 ____D C:\Users\Степа\.AdvertisingPopup 2020-08-15 20:22 - 2020-08-15 20:22 - 000000000 ____D C:\Users\GLCache\61e45a91da16af61b39c1317c74555dc 2020-08-15 20:21 - 2020-08-15 20:21 - 000000000 ____D C:\Users\Все пользователи\SystemAcCrux 2020-08-15 20:21 - 2020-08-15 20:21 - 000000000 ____D C:\Users\Все пользователи\EaseUS 2020-08-15 20:21 - 2020-08-15 20:21 - 000000000 ____D C:\ProgramData\SystemAcCrux 2020-08-15 20:21 - 2020-08-15 20:21 - 000000000 ____D C:\ProgramData\EaseUS 2020-08-15 20:21 - 2020-07-09 21:52 - 000344200 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\EuFdDisk.sys 2020-08-15 20:21 - 2020-07-09 21:52 - 000073864 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\eubakup.sys 2020-08-15 20:21 - 2020-07-09 21:52 - 000053896 _____ C:\Windows\system32\Drivers\EUBKMON.sys 2020-08-15 20:21 - 2020-07-09 21:52 - 000023176 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\eudskacs.sys 2020-08-15 20:19 - 2020-08-16 12:43 - 000000000 ____D C:\Program Files (x86)\EaseUS 2020-08-14 13:35 - 2020-08-14 13:35 - 000000000 ____D C:\Users\Степа\Desktop\Краски 2020-08-14 12:52 - 2020-08-14 12:52 - 000000000 ____D C:\Users\Default\AppData\Local\NVIDIA Corporation 2020-08-14 12:52 - 2020-08-14 12:52 - 000000000 ____D C:\Users\Default\AppData\Local\NVIDIA 2020-08-14 12:52 - 2020-08-14 12:52 - 000000000 ____D C:\Users\Default User\AppData\Local\NVIDIA Corporation 2020-08-14 12:52 - 2020-08-14 12:52 - 000000000 ____D C:\Users\Default User\AppData\Local\NVIDIA 2020-08-12 21:41 - 2020-08-12 21:41 - 000000000 ____D C:\Users\Степа\AppData\Roaming\InstallPack 2020-08-11 21:04 - 2020-08-11 21:04 - 000001836 _____ C:\Users\Степа\Desktop\Запустить Kerbal Space Program Multiplayer.lnk 2020-08-11 20:54 - 2020-08-11 20:54 - 000001228 _____ C:\Users\Все пользователи\Desktop\Kerbal Space Program.lnk 2020-08-11 20:54 - 2020-08-11 20:54 - 000001228 _____ C:\Users\Public\Desktop\Kerbal Space Program.lnk 2020-08-11 20:54 - 2020-08-11 20:54 - 000001228 _____ C:\ProgramData\Desktop\Kerbal Space Program.lnk 2020-08-11 20:52 - 2020-08-12 22:15 - 000000000 ____D C:\Program Files (x86)\Kerbal Space Program 2020-08-11 18:41 - 2020-08-31 16:36 - 000000000 ____D C:\Program Files (x86)\Steam 2020-08-11 18:41 - 2020-08-11 18:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2020-08-10 21:51 - 2020-08-10 21:51 - 000001212 _____ C:\Users\Все пользователи\Desktop\LEGO® Star Wars™ - The Complete Saga.lnk 2020-08-10 21:51 - 2020-08-10 21:51 - 000001212 _____ C:\Users\Public\Desktop\LEGO® Star Wars™ - The Complete Saga.lnk 2020-08-10 21:51 - 2020-08-10 21:51 - 000001212 _____ C:\ProgramData\Desktop\LEGO® Star Wars™ - The Complete Saga.lnk 2020-08-10 21:51 - 2020-08-10 21:51 - 000000000 ____D C:\Windows\SysWOW64\GOG.com 2020-08-10 21:48 - 2020-08-10 21:51 - 000000000 ____D C:\Program Files (x86)\LEGO Star Wars 2020-08-10 21:32 - 2020-08-10 21:32 - 000000000 ____D C:\Users\Степа\AppData\Local\LucasArts 2020-08-10 16:39 - 2020-08-10 16:39 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bink and Smacker 2020-08-10 16:39 - 2020-08-10 16:39 - 000000000 ____D C:\Program Files (x86)\RADVideo 2020-08-09 16:51 - 2020-08-20 20:51 - 000002273 _____ C:\Users\Степа\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blitz.lnk 2020-08-09 16:44 - 2020-08-09 16:50 - 000000000 ____D C:\Users\Степа\AppData\Local\blitz-updater 2020-08-09 15:09 - 2020-08-26 23:28 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla 2020-08-09 15:09 - 2020-08-09 15:09 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Mozilla 2020-08-09 15:09 - 2020-08-09 15:09 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-08-09 15:09 - 2020-08-09 15:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-08-08 19:41 - 2002-01-12 17:30 - 000003567 _____ (Beyond Logic hxxp://www.beyondlogic.org) C:\Windows\SysWOW64\Drivers\PortTalk.sys 2020-08-01 00:01 - 2020-08-01 00:01 - 000001315 _____ C:\Users\Степа\Desktop\Soundpad.exe.lnk ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-08-31 16:36 - 2020-07-13 16:43 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Blitz 2020-08-31 16:36 - 2020-06-16 11:23 - 000000000 ____D C:\Users\Степа\AppData\Roaming\discord 2020-08-31 16:36 - 2016-11-26 11:56 - 000000000 ____D C:\Users\Все пользователи\Kaspersky Lab 2020-08-31 16:36 - 2016-11-26 11:56 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2020-08-31 16:35 - 2020-06-15 13:27 - 000000400 __RSH C:\Users\Все пользователи\ntuser.pol 2020-08-31 16:35 - 2020-06-15 13:27 - 000000400 __RSH C:\ProgramData\ntuser.pol 2020-08-31 16:35 - 2017-10-29 11:03 - 000000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2020-08-31 16:35 - 2016-11-25 20:23 - 000000000 ____D C:\Windows\system32\Tasks\OfficeSoftwareProtectionPlatform 2020-08-31 16:35 - 2016-11-25 18:35 - 000000000 ____D C:\Users\Все пользователи\NVIDIA 2020-08-31 16:35 - 2016-11-25 18:35 - 000000000 ____D C:\ProgramData\NVIDIA 2020-08-31 16:35 - 2009-07-14 10:09 - 000000000 ____D C:\Windows\system32\Tasks\WPD 2020-08-31 16:33 - 2019-02-13 22:52 - 000000000 _____ C:\Windows\system32\Drivers\lvuvc.hs 2020-08-31 16:33 - 2017-01-17 15:13 - 000065536 _____ C:\Windows\system32\Ikeext.etl 2020-08-31 16:33 - 2009-07-14 10:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-08-30 20:04 - 2016-11-25 18:56 - 000000000 ____D C:\Users\Степа\Desktop\всё с экрана 2020-08-30 11:58 - 2009-07-14 09:45 - 000050576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2020-08-30 11:58 - 2009-07-14 09:45 - 000050576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2020-08-29 22:45 - 2020-06-17 23:10 - 000000000 ____D C:\Users\Степа\AppData\Local\LogMeIn Hamachi 2020-08-29 22:43 - 2016-11-25 19:17 - 000000000 ____D C:\Users\Степа\AppData\Local\CrashDumps 2020-08-29 18:03 - 2009-07-14 08:20 - 000000000 ____D C:\Windows\inf 2020-08-29 17:11 - 2017-01-29 19:50 - 000000000 ____D C:\Users\Степа\AppData\Roaming\uTorrent 2020-08-29 16:40 - 2009-07-14 08:20 - 000000000 ____D C:\Windows\tracing 2020-08-29 13:46 - 2016-11-25 18:35 - 000000000 ____D C:\Users\Все пользователи\Package Cache 2020-08-29 13:46 - 2016-11-25 18:35 - 000000000 ____D C:\ProgramData\Package Cache 2020-08-29 13:40 - 2019-04-16 18:19 - 000000000 ____D C:\Users\Степа\AppData\Local\BitTorrentHelper 2020-08-28 14:38 - 2018-08-12 21:02 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2020-08-26 23:45 - 2009-07-14 09:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2020-08-26 23:27 - 2009-07-14 08:20 - 000000000 ____D C:\Program Files\Common Files\System 2020-08-26 23:21 - 2017-08-20 11:42 - 000012578 _____ C:\Windows\system32\--traceoff 2020-08-23 11:51 - 2012-03-07 00:32 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2020-08-22 22:57 - 2011-04-12 18:26 - 001205192 _____ C:\Windows\system32\perfh019.dat 2020-08-22 22:57 - 2011-04-12 18:26 - 000316154 _____ C:\Windows\system32\perfc019.dat 2020-08-22 22:57 - 2009-07-14 10:13 - 000006494 _____ C:\Windows\system32\PerfStringBackup.INI 2020-08-21 23:03 - 2020-07-13 16:47 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Blitz-helpers 2020-08-21 15:38 - 2018-06-18 21:07 - 000000252 _____ C:\Users\Степа\AppData\LocalLow\rbxcsettings.rbx 2020-08-21 15:38 - 2018-06-18 21:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox 2020-08-20 23:00 - 2020-07-12 19:12 - 000000000 ____D C:\Program Files (x86)\TheEscapists2 2020-08-20 22:26 - 2020-05-14 20:14 - 000000000 ____D C:\Program Files (x86)\Epic Games 2020-08-20 15:50 - 2020-06-15 13:26 - 000000000 ____D C:\Users\Степа\Desktop\Новая папка 2020-08-20 13:09 - 2020-06-17 22:43 - 000000000 ____D C:\Users\Степа\AppData\Roaming\.tlauncher 2020-08-20 13:09 - 2020-06-17 22:43 - 000000000 ____D C:\Users\Степа\AppData\Roaming\.minecraft 2020-08-19 12:44 - 2016-12-18 19:16 - 000000000 ____D C:\Users\Степа\AppData\LocalLow\Mozilla 2020-08-19 12:36 - 2016-11-24 20:42 - 000000000 ____D C:\Program Files (x86)\Google 2020-08-19 12:32 - 2016-11-23 21:18 - 000000000 ____D C:\Users\Степа 2020-08-18 13:49 - 2017-03-20 14:44 - 000000000 ____D C:\Users\Степа\AppData\Local\ElevatedDiagnostics 2020-08-17 22:32 - 2016-11-25 19:24 - 000000000 ____D C:\Windows\SysWOW64\directx 2020-08-17 16:54 - 2019-04-16 18:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\by.xatab 2020-08-17 14:43 - 2017-11-04 15:33 - 000000000 ____D C:\Users\GLCache 2020-08-16 21:11 - 2020-07-28 13:35 - 000000223 _____ C:\Users\Степа\Desktop\STAR WARS™ The Old Republic™.url 2020-08-15 20:01 - 2020-07-14 17:16 - 000003957 _____ C:\Windows\GA_OF.dat 2020-08-15 20:01 - 2018-03-04 17:17 - 000001024 ____H C:\AMTAG.BIN 2020-08-13 12:52 - 2009-07-14 08:20 - 000000000 ____D C:\Windows\system32\NDF 2020-08-13 01:10 - 2016-11-25 20:22 - 000000000 ____D C:\Users\Все пользователи\Microsoft Help 2020-08-12 19:26 - 2020-07-18 23:26 - 004510264 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2020-08-12 19:26 - 2017-06-04 19:41 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe 2020-08-12 19:26 - 2017-06-04 19:41 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2020-08-12 19:26 - 2016-11-25 16:21 - 000000000 ____D C:\Windows\system32\Macromed 2020-08-11 20:54 - 2009-07-14 10:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2020-08-11 19:14 - 2018-06-13 20:42 - 000000000 ____D C:\Program Files (x86)\SteamLibrary 2020-08-11 19:05 - 2020-07-27 22:23 - 000000222 _____ C:\Users\Степа\Desktop\SCP Secret Laboratory.url 2020-08-10 21:51 - 2018-03-26 19:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2020-08-10 21:40 - 2012-03-07 00:13 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2020-08-10 17:50 - 2016-12-03 16:54 - 000000000 ____D C:\Windows\Minidump 2020-08-09 15:09 - 2016-12-18 19:16 - 000000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2020-08-08 19:41 - 2015-06-24 15:15 - 000000000 ____D C:\Users\Степа\Desktop\Victoria-HDD-4.47-Rus 2020-08-07 12:33 - 2020-07-12 22:27 - 000000000 ____D C:\Program Files\Riot Vanguard 2020-08-06 22:53 - 2020-07-31 23:39 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Leppsoft 2020-08-06 22:35 - 2020-06-16 11:23 - 000000000 ____D C:\Users\Степа\AppData\Local\Discord 2020-08-06 22:35 - 2017-12-06 16:29 - 000000000 ____D C:\Users\Степа\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 2020-08-01 00:01 - 2020-07-31 23:38 - 000000000 ____D C:\Program Files\Soundpad ==================== Files in the root of some directories ======== 2019-09-12 22:08 - 2019-09-17 23:08 - 000000016 _____ () C:\Users\Степа\AppData\Roaming\msregsvv.dll 2018-05-25 22:11 - 2018-05-25 22:18 - 000000132 _____ () C:\Users\Степа\AppData\Roaming\Установки формата GIF Adobe CS6 2017-04-16 12:14 - 2019-10-15 21:35 - 000000132 _____ () C:\Users\Степа\AppData\Roaming\Установки формата PNG Adobe CS6 2018-05-25 22:19 - 2018-05-25 22:32 - 000001456 _____ () C:\Users\Степа\AppData\Local\Adobe Сохранить для Web 13.0 Prefs 2020-08-25 14:53 - 2020-08-28 20:44 - 000000151 _____ () C:\Users\Степа\AppData\Local\dc4f79923a5baeb14164.bin 2019-06-19 13:49 - 2019-06-19 13:49 - 000000093 _____ () C:\Users\Степа\AppData\Local\fusioncache.dat 2017-10-15 13:20 - 2020-06-16 23:30 - 000007611 _____ () C:\Users\Степа\AppData\Local\Resmon.ResmonCfg ==================== FCheck ================================ (If an entry is included in the fixlist, the file/folder will be moved.) FCheck: C:\Windows\system32\MRT.exe [2020-05-13] <==== ATTENTION (zero byte File/Folder) ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2020-08-28 13:31 ==================== End of FRST.txt ========================