Результат сканирования Farbar Recovery Scan Tool (FRST) (x64) Версия: 18-03-2023 Запущено с помощью vexte (Администратор) на DESKTOP-OTAV2SK (18-03-2023 22:48:59) Запущено из C:\Users\vexte\OneDrive\Рабочий стол Загруженные профили: vexte Платформа: Майкрософт Windows 10 Pro Версия 22H2 19045.2728 (X64) Язык: Русский (Россия) Браузер по умолчанию: Yandex Browser Режим загрузки: Normal ==================== Процессы (В белом списке) ================= (Если запись включена в fixlist, процесс будет закрыт. Файл не будет перемещён.) (ASUSTeK COMPUTER INC. -> ) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\ArmourySwAgent.exe (ASUSTeK COMPUTER INC. -> ASUS) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Users\vexte\AppData\Local\Temp\ACFL\ACSetup\ACSetup.exe (C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\avp.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\avpui.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe (C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe (C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.UserSessionHelper.exe (C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe (C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\nvrla.exe (C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe <2> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3> (C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (explorer.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK COMPUTER INC.) H:\Downloads Browser\SW_ASUS_AISuite3_PPSU_EZ_SZ_TSD_W11_64_V30110_20220110R\AsusSetup.exe (explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\72.0.2.0\crashpad_handler.exe <4> (explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\72.0.2.0\GoogleDriveFS.exe <7> (explorer.exe ->) (YANDEX LLC -> YANDEX LLC) C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\Application\browser.exe <21> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe (H:\Downloads Browser\SW_ASUS_AISuite3_PPSU_EZ_SZ_TSD_W11_64_V30110_20220110R\AsusSetup.exe ->) (ASUSTeK Computer Inc. -> ) H:\Downloads Browser\SW_ASUS_AISuite3_PPSU_EZ_SZ_TSD_W11_64_V30110_20220110R\Setup.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe (services.exe ->) (Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (services.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe (services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) C:\Program Files (x86)\LightingService\LightingService.exe (services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe (services.exe ->) (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.) C:\Users\vexte\AppData\Local\Temp\AsusCertService.exe.old (services.exe ->) (Firebird Project) [Файл не подписан] C:\Program Files (x86)\BazisSoft\BazisFirebird 2.5\bin\fbguard.exe (services.exe ->) (Firebird Project) [Файл не подписан] C:\Program Files (x86)\BazisSoft\BazisFirebird 2.5\bin\fbserver.exe (services.exe ->) (Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\avp.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2> (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservices.exe (services.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingServices_10.75.13001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe (services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (NVIDIA Corporation -> NVIDIA) C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe (services.exe ->) (QUALCOMM, Inc.) [Файл не подписан] C:\Program Files (x86)\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe (services.exe ->) (YANDEX LLC -> YANDEX LLC) C:\Program Files (x86)\Yandex\YandexBrowser\23.1.5.708\service_update.exe <2> (svchost.exe ->) (Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe (svchost.exe ->) (ASUSTeK COMPUTER INC.) C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_5.4.10.0_x64__qmba6cd70vzyy\ArmouryCrate.exe (svchost.exe ->) (Corel Corporation -> Corel Corporation) C:\Program Files (x86)\Corel\CUH\v2\CUH.EXE (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23012.167.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (YANDEX LLC -> Yandex LLC) C:\Users\vexte\AppData\Local\Yandex\SearchBand\Application\5.5.0.1923\searchbandapp64.exe ==================== Реестр Windows (В белом списке) =================== (Если запись включена в fixlist, элемент реестра будет сброшен на значение по умолчанию или удалён. Файл не будет перемещён.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech) HKLM\...\Run: [Virtual Pet] => C:\Program Files\ASUS\Virtual Pet\Virtual Pet.exe [38396528 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [5296864 2021-06-27] (Adobe Inc. -> Adobe Systems Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-01-25] (Adobe Inc. -> ) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [711288 2023-01-09] (Oracle America, Inc. -> Oracle Corporation) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Ограничение <==== ВНИМАНИЕ HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Ограничение <==== ВНИМАНИЕ HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\72.0.2.0\GoogleDriveFS.exe [52902168 2023-03-16] (Google LLC -> Google, Inc.) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\72.0.2.0\GoogleDriveFS.exe [52902168 2023-03-16] (Google LLC -> Google, Inc.) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4268456 2022-01-16] (Valve Corp. -> Valve Corporation) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [33650656 2022-02-16] (Epic Games Inc. -> Epic Games, Inc.) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [YandexSearchBand] => C:\Users\vexte\AppData\Local\Yandex\SearchBand\Application\5.5.0.1923\searchbandapp64.exe [6489592 2022-03-29] (YANDEX LLC -> Yandex LLC) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [YandexDisk2] => C:\Users\vexte\AppData\Roaming\Yandex\YandexDisk2\3.2.24.4790\YandexDisk2.exe [45769880 2023-01-31] (YANDEX LLC -> Яндекс) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [YandexBrowserAutoLaunch_24F08C4E39FC879E1081566676045DBE] => "C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --shutdown-if-not-closed-by-system-restart (Нет файла) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\72.0.2.0\GoogleDriveFS.exe [52902168 2023-03-16] (Google LLC -> Google, Inc.) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\Run: [MicrosoftEdgeAutoLaunch_9E79BCE2BA29B9A668F04F1661C7B04E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4056000 2023-03-12] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\MountPoints2: {47b7acfb-2e1a-11ed-9850-24418cf931d3} - "F:\OnePlus_setup.exe" /s HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\MountPoints2: {47b7ad9e-2e1a-11ed-9850-24418cf931d3} - "F:\OnePlus_setup.exe" /s HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\MountPoints2: {54e5b02c-9d1d-11ec-9714-24418cf931d3} - "F:\OnePlus_setup.exe" /s HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\...\MountPoints2: {d89860a7-dc5b-11ec-97ab-24418cf931d3} - "F:\OnePlus_setup.exe" /s HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\72.0.2.0\GoogleDriveFS.exe [52902168 2023-03-16] (Google LLC -> Google, Inc.) HKLM\...\Windows x64\Print Processors\Canon MG2500 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBX.DLL [30208 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [65160 2021-06-27] (Adobe Inc. -> Adobe Systems Inc) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG2500 series: C:\Windows\system32\CNMLMBX.DLL [391168 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG2500 series XPS: C:\Windows\system32\CNMXLMBX.DLL [393728 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\111.0.5563.65\Installer\chrmstp.exe [2023-03-13] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{C57B257B-3D92-4AC0-8FE8-7D6FF81AEF73}] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f GroupPolicy: Ограничение ? <==== ВНИМАНИЕ Policies: C:\ProgramData\NTUSER.pol: Ограничение <==== ВНИМАНИЕ ==================== Запланированные задачи (В белом списке) ============ (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) Task: {0557DE13-9714-435E-B2A4-1F7E3C5A2D64} - System32\Tasks\Yandex.Stroka.User.S-1-5-21-2127754763-3569965573-3384584848-1002 => C:\Users\vexte\AppData\Local\Yandex\SearchBand\Application\5.5.0.1923\searchbandapp64.exe [6489592 2022-03-29] (YANDEX LLC -> Yandex LLC) Task: {082414AC-1AD5-4CF8-80E9-35EAF578F28E} - System32\Tasks\ASUS\ASUSUpdateTaskMachineCore => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) Task: {08425E28-BEC2-4624-A072-25EF5E8BD9F4} - System32\Tasks\CorelUpdateHelperTask-7609E3187205CBEAB403D54E66CC7FBE => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe [3799264 2021-08-26] (Corel Corporation -> Corel Corporation) Task: {0C18D5F5-9483-4E76-8A0D-5A4D3AB7FD6B} - System32\Tasks\Системное обновление Браузера Яндекс => C:\Program Files (x86)\Yandex\YandexBrowser\23.1.5.708\service_update.exe [3223192 2023-03-15] (YANDEX LLC -> YANDEX LLC) Task: {1D40A1F3-7B21-4FAD-9A98-350517D1753F} - System32\Tasks\Восстановление сервиса обновлений Яндекс.Браузера => C:\Program Files (x86)\Yandex\YandexBrowser\22.9.1.1095\service_update.exe --repair (Нет файла) Task: {1FEA0150-54C7-44C3-ABE8-3F5C86BA7099} - System32\Tasks\CorelUpdateHelperTaskCore => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe [3799264 2021-08-26] (Corel Corporation -> Corel Corporation) Task: {2924583D-8F7D-4E86-B7C3-5B2D6129B511} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (Нет файла) Task: {3336B3C9-B008-4B60-B5CE-0B58DF3C2168} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2021-09-09] (Google LLC -> Google LLC) Task: {35708CCD-42ED-4AD1-BB67-05EBE5084EE5} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [804312 2022-11-17] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {3F162422-A957-4D34-941B-EF5B6DF14C9D} - System32\Tasks\ASUS\Ez Update => C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EzUpdt.exe [1610808 2021-04-14] (ASUSTeK Computer Inc. -> ) Task: {5027D6F5-6381-4044-BF5E-DE5032824368} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {52F99C34-A1BD-4F38-81CF-2AE83D110B50} - System32\Tasks\ASUS\Framework Service => C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe [46597976 2022-12-15] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) Task: {54323B2F-F944-4D1F-A28B-1C90744B5308} - System32\Tasks\Kontur.Updater-v1.1.2.154-S-1-5-21-2127754763-3569965573-3384584848-1002 => C:\Users\vexte\AppData\Local\SkbKontur\Updater\1.1.2.154\kontur.updater.exe [1280456 2021-06-24] (AO Proizvodstvennaya Firma SKB Kontur -> PF SKB Kontur AO) Task: {60B17FC7-349C-4A2E-B293-44E6D8D01EBF} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [1471104 2021-10-22] (ASUSTeK Computer Inc. -> ) Task: {66420790-F274-4511-B89D-8FB687EDE6C4} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [168840 2023-03-04] (Microsoft Corporation -> Microsoft Corporation) Task: {6D49636B-E84D-49F9-B722-D1BB8C7B28D4} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26296808 2023-03-18] (Microsoft Corporation -> Microsoft Corporation) Task: {81597793-9A04-48BC-A736-BE7C7D8B2327} - System32\Tasks\ASUS\AcPowerNotification => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\AcPowerNotification\AcPowerNotification.exe [308584 2023-02-01] (ASUSTeK COMPUTER INC. -> ASUS) Task: {87850C9F-EF38-4FB1-B0E9-9266A31F2E6B} - System32\Tasks\ASUS\ArmourySocketServer => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe [1860968 2023-02-01] (ASUSTeK COMPUTER INC. -> ASUS) Task: {8B048418-0D91-4B32-B889-22B3160F7EC4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2021-09-09] (Google LLC -> Google LLC) Task: {92AB2F9A-B95C-4D2D-B8D8-F41916CDD2EA} - System32\Tasks\ASUS\ASUSUpdateTaskMachineUA => C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) Task: {956D7289-6EF5-4413-B77B-399763FAE9B3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {9C481660-08C9-447B-A157-F0D2BB58A4AF} - System32\Tasks\Kontur.Plugin.Assistant-v3.17.1.682-S-1-5-21-2127754763-3569965573-3384584848-1002 => C:\Users\vexte\AppData\Local\SkbKontur\Plugin\3.17.1.682\kontur.plugin.assistant.exe [1279904 2023-02-17] (AO Proizvodstvennaya Firma SKB Kontur -> PF SKB Kontur AO) Task: {A1665C43-C468-43A0-8D42-439B85DB9A9E} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {B45F3D80-5B04-4B6E-A909-D456ACB22AAB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144232 2023-03-18] (Microsoft Corporation -> Microsoft Corporation) Task: {B6202F81-F696-489D-9B7C-8D98B4E0CFC4} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {BA78DD34-66E5-4606-A566-3491E309B31A} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {BAEB9626-1860-46F2-94CE-D6773500B826} - System32\Tasks\AMDAutoUpdate => C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe [672064 2022-12-02] (Advanced Micro Devices Inc. -> ) Task: {BFD00829-9039-4F11-8BD9-A15E88704E0F} - System32\Tasks\RTSS => C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe [436544 2022-11-05] (Alexey Nicolaychuk -> ) Task: {C3AAD448-B340-4E71-864C-98020376B3ED} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation) Task: {C9141AD7-02BE-4A48-9329-D87BA51752DF} - System32\Tasks\Обновление Браузера Яндекс => C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\Application\browser.exe [4579480 2023-03-09] (YANDEX LLC -> YANDEX LLC) Task: {D3B628D2-8DB6-47FC-80C3-4D5006E8783D} - System32\Tasks\Восстановление сервиса обновлений Яндекс Браузера => C:\Program Files (x86)\Yandex\YandexBrowser\23.1.5.708\service_update.exe [3223192 2023-03-15] (YANDEX LLC -> YANDEX LLC) Task: {E1A48B52-3B4D-4338-BD58-7392D9F99C6E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {E4861DA8-2FBA-4F88-B708-6E05AB36CE96} - System32\Tasks\ASUS\GpuFanHelper => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe [4329008 2021-10-13] (ASUSTeK Computer Inc. -> TODO: ) Task: {ED8C3F1B-4DC9-4470-A63B-12D4BE084208} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {F1578C4C-8E8E-41E2-BF97-D86E23D7F157} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144232 2023-03-18] (Microsoft Corporation -> Microsoft Corporation) Task: {FA4E95BE-8D90-4D3D-A643-3B5A7C35E5D0} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2159944 2021-10-18] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) Task: {FC55032A-6182-423A-BB89-835EDC926354} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26296808 2023-03-18] (Microsoft Corporation -> Microsoft Corporation) Task: {FE2CC0CF-A392-42EE-8698-26FBAC957D83} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) (Если запись включена в fixlist, файл задачи (.job) будет перемещён. Файл, выполняемый задачей, не будет перемещён.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe Task: C:\Windows\Tasks\Восстановление сервиса обновлений Яндекс.Браузера.job => C:\Program Files (x86)\Yandex\YandexBrowser\22.9.1.1095\service_update.exe Task: C:\Windows\Tasks\Восстановление сервиса обновлений Яндекс Браузера.job => C:\Program Files (x86)\Yandex\YandexBrowser\23.1.5.708\service_update.exe Task: C:\Windows\Tasks\Обновление Браузера Яндекс.job => C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\Application\browser.exe Task: C:\Windows\Tasks\Системное обновление Браузера Яндекс.job => C:\Program Files (x86)\Yandex\YandexBrowser\23.1.5.708\service_update.exe ==================== Internet (В белом списке) ==================== (Если элемент включён в fixlist, если он является элементом реестра, он будет удалён или сброшен на значение по умолчанию.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{c6c146bf-f805-488d-acd7-274066115167}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{f0691418-63ee-418b-82ea-b1b29a97c340}: [DhcpNameServer] 192.168.1.1 HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ограничение <==== ВНИМАНИЕ Edge: ======= Edge HomeButtonPage: HKU\S-1-5-21-2127754763-3569965573-3384584848-1002 -> hxxps://www.yandex.ru/?win=557&clid=2630729-16 Edge DefaultProfile: Default Edge Profile: C:\Users\vexte\AppData\Local\Microsoft\Edge\User Data\Default [2023-03-17] Edge Notifications: Default -> hxxps://store.ubi.com; hxxps://www.youtube.com Edge Extension: (Kaspersky Protection) - C:\Users\vexte\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2023-02-03] Edge Extension: (CryptoPro Extension for CAdES Browser Plug-in) - C:\Users\vexte\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\iifchhfnnmpdbibifmljnfjhpififfog [2022-12-03] Edge Extension: (XML Signer Extension) - C:\Users\vexte\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kiijhgpgjnhkhpagmcgihhigiolpogec [2022-12-03] Edge Extension: (Закладки Top Page) - C:\Users\vexte\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pgabmkcldlelbhcookaealohoeknnapn [2021-09-21] Edge HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] Edge HKLM-x32\...\Edge\Extension: [iifchhfnnmpdbibifmljnfjhpififfog] FireFox: ======== FF ProfilePath: C:\Users\vexte\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default [2022-08-30] FF Homepage: Mozilla\Firefox\Profiles\nahd6ha2.default -> hxxps://www.yandex.ru/?win=557&clid=2630729-16 FF SearchPlugin: C:\Users\vexte\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\yandex.ru-20220230.xml [2022-08-30] FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-06-26] FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\FFExt\light_plugin_firefox\addon.xpi => не найдено FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\FFExt\light_plugin_firefox\addon.xpi => не найдено FF Plugin: @java.com/DTPlugin,version=11.361.2 -> C:\Program Files\Java\jre1.8.0_361\bin\dtplugin\npDeployJava1.dll [2023-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.361.2 -> C:\Program Files\Java\jre1.8.0_361\bin\plugin2\npjp2.dll [2023-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-03] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: www.croc.ru/CrocXmlSigner -> C:\Program Files (x86)\CrocInc\Croc.XmlSigner\CurrentVersion\x64\npCrocXmlSigner.dll [2017-11-28] (Croc Inc.) [Файл не подписан] FF Plugin-x32: @cryptopro.ru/CAdES,version=1.0 -> C:\Program Files (x86)\Crypto Pro\CAdES Browser Plug-in\npcades.dll [2022-11-21] (CRYPTO-PRO LLC -> ) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-03] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2021-06-27] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: www.croc.ru/CrocXmlSigner -> C:\Program Files (x86)\CrocInc\Croc.XmlSigner\CurrentVersion\npCrocXmlSigner.dll [2018-02-06] (Croc Inc.) [Файл не подписан] Chrome: ======= CHR Profile: C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default [2022-09-15] CHR StartupUrls: Default -> "hxxps://mail.yahoo.com/" CHR Extension: (FUTBIN) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\adicaaffkmhgnfheifkjhopmambgfihl [2021-09-09] CHR Extension: (Kaspersky Protection) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2022-09-05] CHR Extension: (FUTBIN Updater) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\beejegoimbgpafoobegjmhjnehlmnbcn [2021-09-09] CHR Extension: (Touch VPN - Secure and unlimited VPN proxy) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihmplhobchoageeokmgbdihknkjbknd [2021-09-09] CHR Extension: (Нет имени) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\didmnjajdjnmjecjdckhfcbfbngdcdjl [2022-06-13] CHR Extension: (Adobe Acrobat: инструменты для редактирования, преобразования и подписания документов PDF) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-09-15] CHR Extension: (Google Документы офлайн) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-06] CHR Extension: (IE Tab) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2022-09-05] CHR Extension: (Контур.Плагин) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnhppcgejeffnbnioloohhmndpmclaga [2022-05-21] CHR Extension: (CryptoPro Extension for CAdES Browser Plug-in) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\iifchhfnnmpdbibifmljnfjhpififfog [2022-09-05] CHR Extension: (Помощник диагностики) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\inlmamahcfioibldbpbaechbpeeaelin [2021-09-09] CHR Extension: (Яндекс) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgpjdiadomhinpimgchmeembbgojnjk [2022-09-05] CHR Extension: (mydlink services plugin) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldibdoepbjbkkcbgndfljnphngpglhbb [2021-09-09] CHR Extension: (Программа запуска приложений для Диска, разработанная Google) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2022-09-05] CHR Extension: (Нет имени) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\molacmnjfpddlbmlaegaljhpadobkkhi [2022-06-13] CHR Extension: (Платежная система Интернет-магазина Chrome) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-09-09] CHR Extension: (Обход блокировок Рунета) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\npgcnondjocldhldegnakemclmfkngch [2021-09-17] CHR Extension: (Закладки Top Page) - C:\Users\vexte\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgabmkcldlelbhcookaealohoeknnapn [2021-09-09] CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm CHR HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ldgpjdiadomhinpimgchmeembbgojnjk] CHR HKU\S-1-5-21-2127754763-3569965573-3384584848-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [iifchhfnnmpdbibifmljnfjhpififfog] Yandex: ======= YAN Profile: C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\User Data\Default [2023-03-18] YAN DownloadDir: H:\Downloads Browser YAN Extension: (CryptoPro Extension for CAdES Browser Plug-in) - C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\epebfcehmdedogndhlcacafjaacknbcm [2023-01-24] YAN Extension: (Контур.Плагин) - C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\hnhppcgejeffnbnioloohhmndpmclaga [2022-05-12] YAN Extension: (Помощник диагностики) - C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\inlmamahcfioibldbpbaechbpeeaelin [2022-03-29] YAN Extension: (XML Signer Extension) - C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\kiijhgpgjnhkhpagmcgihhigiolpogec [2023-01-23] YAN Extension: (Browsec VPN - Free VPN for Chrome) - C:\Users\vexte\AppData\Local\Yandex\YandexBrowser\User Data\Default\Extensions\omghfjlpggmjjaagoclmmobgdodcjboh [2023-03-14] ==================== Службы (В белом списке) =================== (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-26] (Adobe Inc. -> Adobe Inc.) R2 ArmouryCrateService; C:\Program Files\ASUS\ARMOURY CRATE Lite Service\ArmouryCrate.Service.exe [399984 2023-02-17] (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe [457544 2021-10-01] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S2 asus; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [558104 2022-05-19] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) S2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.01.12\AsusFanControlService.exe [2203464 2021-10-13] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) S3 asusm; C:\Program Files (x86)\ASUS\Update\AsusUpdate.exe [156008 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.) S2 AsusROGLSLService; C:\Program Files (x86)\ASUS\AsusROGLSLService\AsusROGLSLService.exe [678760 2023-03-18] (ASUSTeK COMPUTER INC. -> ASUS) R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\avp.exe [184768 2022-10-24] (Kaspersky Lab JSC -> AO Kaspersky Lab) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12512768 2023-03-18] (Microsoft Corporation -> Microsoft Corporation) S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [9966696 2022-12-20] (Electronic Arts, Inc. -> Electronic Arts) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2021-10-01] (Epic Games Inc. -> Epic Games, Inc.) R2 FirebirdGuardianBazisSoftBuild; C:\Program Files (x86)\BazisSoft\BazisFirebird 2.5\bin\fbguard.exe [98304 2013-03-19] (Firebird Project) [Файл не подписан] R3 FirebirdServerBazisSoftBuild; C:\Program Files (x86)\BazisSoft\BazisFirebird 2.5\bin\fbserver.exe [3784704 2013-03-19] (Firebird Project) [Файл не подписан] S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.3 (1)\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab) R2 LightingService; C:\Program Files (x86)\LightingService\LightingService.exe [4210536 2023-02-10] (ASUSTeK COMPUTER INC. -> ASUSTek Computer Inc.) R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc) R2 qcmtusvc; C:\Program Files (x86)\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe [83456 2015-07-09] (QUALCOMM, Inc.) [Файл не подписан] R2 ROG Live Service; C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe [1574512 2023-02-13] (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [226976 2023-02-23] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\NisSrv.exe [3191256 2023-02-16] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\MsMpEng.exe [133576 2023-02-16] (Microsoft Windows Publisher -> Microsoft Corporation) R2 YandexBrowserService; C:\Program Files (x86)\Yandex\YandexBrowser\23.1.5.708\service_update.exe [3223192 2023-03-15] (YANDEX LLC -> YANDEX LLC) R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_059948e396d205d5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Драйверы (В белом списке) =================== (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [35360 2022-06-01] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R3 AMDXE; C:\Windows\System32\drivers\amdxe.sys [59920 2022-05-31] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [34112 2019-07-02] (ASUSTeK Computer Inc. -> ) R1 Asusgio2; C:\Windows\system32\drivers\AsIO2.sys [34384 2021-06-01] (ASUSTeK Computer Inc. -> ) R1 Asusgio3; C:\Windows\system32\drivers\AsIO3.sys [49256 2022-08-16] (ASUSTeK COMPUTER INC. -> ) R3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [69016 2019-03-04] (Microsoft Windows Hardware Compatibility Publisher -> www.winchiphead.com) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [237288 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 CProCtrl; C:\Windows\system32\DRIVERS\CProCtrl.5.0.0.10011.sys [116000 2022-11-21] (CRYPTO-PRO LLC -> Компания КРИПТО-ПРО) R1 googledrivefs31092; C:\Windows\System32\DRIVERS\googledrivefs31092.sys [384600 2023-02-11] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.) R1 klbackupdisk; C:\Windows\system32\DRIVERS\klbackupdisk.sys [105280 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [206600 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [119568 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [41656 2021-02-19] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R1 klflt; C:\Windows\system32\DRIVERS\klflt.sys [522504 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [717448 2022-11-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [1729160 2022-11-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys [235720 2023-03-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1049864 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [90896 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [104728 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [107328 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [78088 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [88328 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [370496 2023-03-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [359976 2023-03-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [190048 2023-03-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [270672 2023-03-15] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [150280 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [325400 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [294680 2022-10-24] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab) R3 mt7612US; C:\Windows\System32\drivers\mt7612US.sys [377864 2015-12-09] (Windows Central Build Account - X -> MediaTek Inc.) R3 NvModuleTracker; C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [36824 2020-07-13] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) S3 tapwindscribe0901; C:\Windows\System32\drivers\tapwindscribe0901.sys [57768 2022-04-25] (Windscribe Limited -> The OpenVPN Project) S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49576 2023-02-16] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [473336 2023-02-16] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [99576 2023-02-16] (Microsoft Windows -> Microsoft Corporation) S3 windtun420; C:\Windows\System32\drivers\windtun420.sys [47544 2022-04-25] (Windscribe Limited -> WireGuard LLC) S3 bntap; \SystemRoot\System32\drivers\bntap.sys [X] ==================== NetSvcs (В белом списке) =================== (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) ==================== Один месяц (создан) (В белом списке) ========= (Если запись включена в лист исправлений, файл/папка будут перемещены.) 2023-03-18 22:48 - 2023-03-18 22:48 - 000000000 ____D C:\Program Files (x86)\LightingService 2023-03-18 22:48 - 2023-03-18 22:48 - 000000000 ____D C:\MainSDK 2023-03-18 22:46 - 2023-03-18 22:49 - 000000000 ____D C:\Users\vexte\AppData\Local\AcSdkInsLog 2023-03-18 22:46 - 2023-03-18 22:46 - 000000000 ____D C:\Users\vexte\AppData\Local\ASUS 2023-03-18 22:45 - 2023-03-18 22:49 - 000000000 ____D C:\FRST 2023-03-18 22:43 - 2023-03-18 22:43 - 000001115 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Pet.lnk 2023-03-18 22:42 - 2023-03-18 22:48 - 000000000 ____D C:\Program Files\ASUS 2023-03-18 22:42 - 2023-03-18 22:42 - 000000000 ____D C:\Program Files (x86)\Windows Kits 2023-03-18 22:42 - 2023-03-18 22:42 - 000000000 ____D C:\Program Files (x86)\Microsoft GameInput 2023-03-18 22:39 - 2023-03-18 22:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2023-03-18 22:38 - 2023-03-18 22:48 - 000000000 ____D C:\Windows\system32\Tasks\ASUS 2023-03-17 21:10 - 2023-03-17 21:14 - 000000000 ____D C:\AdwCleaner 2023-03-17 20:58 - 2023-03-17 20:58 - 000000000 ____D C:\Users\vexte\AppData\Local\mbam 2023-03-17 01:25 - 2023-03-17 01:25 - 000000000 ____D C:\Windows\LastGood.Tmp 2023-03-17 00:16 - 2023-03-09 10:57 - 002172512 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe 2023-03-17 00:16 - 2023-03-09 10:57 - 002172512 _____ C:\Windows\system32\vulkaninfo.exe 2023-03-17 00:16 - 2023-03-09 10:57 - 001607776 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2023-03-17 00:16 - 2023-03-09 10:57 - 001607776 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2023-03-17 00:16 - 2023-03-09 10:57 - 001487336 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2023-03-17 00:16 - 2023-03-09 10:57 - 001479264 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll 2023-03-17 00:16 - 2023-03-09 10:57 - 001479264 _____ C:\Windows\system32\vulkan-1.dll 2023-03-17 00:16 - 2023-03-09 10:57 - 001226736 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2023-03-17 00:16 - 2023-03-09 10:57 - 001211488 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll 2023-03-17 00:16 - 2023-03-09 10:57 - 001211488 _____ C:\Windows\SysWOW64\vulkan-1.dll 2023-03-17 00:16 - 2023-03-09 10:54 - 000671744 _____ C:\Windows\system32\nvofapi64.dll 2023-03-17 00:16 - 2023-03-09 10:54 - 000506344 _____ C:\Windows\SysWOW64\nvofapi.dll 2023-03-17 00:16 - 2023-03-09 10:53 - 001534448 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2023-03-17 00:16 - 2023-03-09 10:53 - 001192960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2023-03-17 00:16 - 2023-03-09 10:53 - 000851432 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll 2023-03-17 00:16 - 2023-03-09 10:53 - 000741360 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe 2023-03-17 00:16 - 2023-03-09 10:52 - 002163736 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2023-03-17 00:16 - 2023-03-09 10:52 - 001620016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2023-03-17 00:16 - 2023-03-09 10:52 - 000977944 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2023-03-17 00:16 - 2023-03-09 10:52 - 000758272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2023-03-17 00:16 - 2023-03-09 10:51 - 013765632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2023-03-17 00:16 - 2023-03-09 10:51 - 011645952 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2023-03-17 00:16 - 2023-03-09 10:51 - 003430400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2023-03-17 00:16 - 2023-03-09 10:51 - 000457752 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe 2023-03-17 00:16 - 2023-03-09 10:50 - 006084136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2023-03-17 00:16 - 2023-03-09 10:50 - 005911600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll 2023-03-17 00:16 - 2023-03-09 10:50 - 005835312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2023-03-17 00:16 - 2023-03-09 10:50 - 000852976 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe 2023-03-17 00:16 - 2023-03-08 14:17 - 000104256 _____ C:\Windows\system32\nvinfo.pb 2023-03-15 22:02 - 2021-02-19 21:09 - 000110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2023-03-14 22:30 - 2023-03-14 22:30 - 000000000 ___HD C:\$WinREAgent 2023-03-10 21:10 - 2023-03-10 21:49 - 000000000 ____D C:\ProgramData\Hogwarts Legacy 2023-03-10 21:10 - 2023-03-10 21:10 - 000000000 ____D C:\Users\vexte\AppData\Local\Phoenix 2023-03-08 01:49 - 2023-03-08 08:49 - 000000000 ____D C:\Program Files (x86)\SpeedFan 2023-03-08 01:49 - 2023-03-08 01:49 - 000000045 _____ C:\Windows\SysWOW64\initdebug.nfo 2023-03-07 23:47 - 2023-03-07 23:47 - 011905648 _____ (Tim Kosse) C:\Users\vexte\Downloads\FileZilla_3.62.2_win64-setup.exe 2023-03-06 22:51 - 2023-03-06 22:51 - 000002682 _____ C:\Windows\system32\Tasks\Kontur.Plugin.Assistant-v3.17.1.682-S-1-5-21-2127754763-3569965573-3384584848-1002 2023-03-01 01:25 - 2023-03-01 03:06 - 000000000 ____D C:\ProgramData\AMD AutoUpdate 2023-03-01 01:25 - 2023-03-01 01:25 - 000003528 _____ C:\Windows\system32\Tasks\AMDAutoUpdate 2023-03-01 01:25 - 2023-03-01 01:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Ryzen Master 2023-03-01 01:23 - 2023-03-01 01:24 - 000000000 ____D C:\AMD 2023-03-01 01:09 - 2023-03-01 01:09 - 000007602 _____ C:\Users\vexte\AppData\Local\Resmon.ResmonCfg 2023-03-01 01:07 - 2023-03-16 21:59 - 000003126 _____ C:\Windows\system32\Tasks\RTSS 2023-02-28 03:16 - 2023-02-28 03:16 - 000000000 ____D C:\Users\vexte\AppData\Local\HouseOfAshes 2023-02-27 23:39 - 2023-02-27 23:39 - 000000000 ____D C:\Users\vexte\AppData\Local\KingsBounty2 2023-02-27 23:35 - 2023-02-27 23:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\King's Bounty II [GOG.com] 2023-02-27 22:25 - 2023-03-18 00:30 - 000003142 _____ C:\Windows\system32\Tasks\MSIAfterburner 2023-02-27 21:33 - 2023-03-17 00:15 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2023-02-27 21:33 - 2023-02-27 21:33 - 000000000 ____D C:\Users\vexte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server 2023-02-27 21:32 - 2023-03-17 22:37 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2023-02-27 21:32 - 2023-02-27 21:32 - 000000000 ____D C:\Users\vexte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2023-02-27 01:37 - 2023-02-27 01:37 - 000000000 ____D C:\Users\vexte\ansel 2023-02-27 01:35 - 2023-02-27 01:35 - 000004308 _____ C:\Windows\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003976 _____ C:\Windows\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003940 _____ C:\Windows\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003894 _____ C:\Windows\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003858 _____ C:\Windows\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000003654 _____ C:\Windows\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2023-02-27 01:35 - 2023-02-27 01:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2023-02-27 01:35 - 2023-02-27 01:35 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2023-02-27 01:35 - 2023-01-20 19:45 - 002904632 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2023-02-27 01:35 - 2023-01-20 19:45 - 002234920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2023-02-27 01:35 - 2023-01-20 19:45 - 001297464 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll 2023-02-27 01:35 - 2023-01-13 05:34 - 000086568 _____ C:\Windows\system32\FvSDK_x64.dll 2023-02-27 01:35 - 2023-01-13 05:34 - 000075304 _____ C:\Windows\SysWOW64\FvSDK_x86.dll 2023-02-27 01:35 - 2022-12-13 12:27 - 000169512 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2023-02-27 01:35 - 2022-12-13 12:27 - 000148520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2023-02-27 01:33 - 2023-02-27 01:33 - 000000000 ____D C:\Windows\system32\lxss 2023-02-27 01:33 - 2023-02-27 01:33 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation 2023-02-27 01:32 - 2023-03-09 10:49 - 007924696 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2023-02-27 01:32 - 2022-07-14 02:32 - 000060112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys 2023-02-27 01:31 - 2023-02-27 01:31 - 000000000 ____D C:\Users\vexte\AppData\Roaming\NVIDIA 2023-02-27 01:31 - 2023-02-03 14:59 - 000041984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhdap64.dll 2023-02-27 01:31 - 2022-10-14 10:06 - 000059928 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2023-02-27 01:30 - 2023-03-09 10:48 - 006788432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2023-02-27 01:28 - 2023-02-27 01:35 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2023-02-27 01:27 - 2023-02-25 05:00 - 000121880 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2023-02-26 16:14 - 2023-02-26 16:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D 2023-02-26 16:13 - 2023-02-26 16:13 - 000000000 ____D C:\Program Files (x86)\Geeks3D 2023-02-23 13:06 - 2023-01-19 21:54 - 005128768 _____ (Intel Corporation) C:\Windows\system32\Drivers\Netwtw10.sys 2023-02-23 13:06 - 2023-01-19 21:54 - 001470528 _____ (Intel Corporation) C:\Windows\system32\IntelIHVRouter10.dll ==================== Один месяц (изменён) ================== (Если запись включена в лист исправлений, файл/папка будут перемещены.) 2023-03-18 22:49 - 2023-01-09 22:40 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2023-03-18 22:49 - 2021-09-09 23:08 - 000000000 ____D C:\ProgramData\Package Cache 2023-03-18 22:48 - 2023-02-02 01:08 - 000000000 ____D C:\ProgramData\ASUS 2023-03-18 22:48 - 2023-02-02 01:08 - 000000000 ____D C:\Program Files (x86)\ASUS 2023-03-18 22:48 - 2019-12-07 12:13 - 000000000 ____D C:\Windows\INF 2023-03-18 22:43 - 2022-03-29 20:27 - 000000460 _____ C:\Windows\Tasks\Обновление Браузера Яндекс.job 2023-03-18 22:42 - 2021-09-09 22:56 - 000000000 ____D C:\Users\vexte\AppData\Local\Packages 2023-03-18 22:42 - 2021-07-27 03:31 - 001753404 _____ C:\Windows\system32\PerfStringBackup.INI 2023-03-18 22:42 - 2021-07-27 03:27 - 000000000 ____D C:\ProgramData\Packages 2023-03-18 22:42 - 2019-12-07 17:34 - 000770694 _____ C:\Windows\system32\perfh019.dat 2023-03-18 22:42 - 2019-12-07 17:34 - 000151940 _____ C:\Windows\system32\perfc019.dat 2023-03-18 22:42 - 2019-12-07 12:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-03-18 22:42 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\AppReadiness 2023-03-18 22:41 - 2022-10-25 23:36 - 000079352 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe 2023-03-18 22:41 - 2022-10-25 23:36 - 000062928 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe 2023-03-18 22:41 - 2021-12-08 20:15 - 002786768 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll 2023-03-18 22:41 - 2021-12-08 20:15 - 000476624 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll 2023-03-18 22:41 - 2021-12-08 20:15 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll 2023-03-18 22:41 - 2021-12-08 20:15 - 000202192 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll 2023-03-18 22:41 - 2021-12-08 20:15 - 000165328 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll 2023-03-18 22:41 - 2021-12-08 20:15 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll 2023-03-18 22:41 - 2021-07-27 03:57 - 000000000 ____D C:\Program Files\Microsoft Office 2023-03-18 22:39 - 2022-05-15 00:01 - 000004190 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{FEE79D54-A018-4166-A3A7-3CC99727799A} 2023-03-18 22:39 - 2021-09-09 23:02 - 000000000 ____D C:\Program Files (x86)\Google 2023-03-18 22:38 - 2022-06-25 10:04 - 000003336 _____ C:\Windows\system32\Tasks\CorelUpdateHelperTask-7609E3187205CBEAB403D54E66CC7FBE 2023-03-18 22:38 - 2021-10-24 19:28 - 000000000 ____D C:\ProgramData\NVIDIA 2023-03-18 22:35 - 2022-10-04 00:32 - 000000464 _____ C:\Windows\Tasks\Восстановление сервиса обновлений Яндекс Браузера.job 2023-03-18 22:35 - 2022-03-29 20:27 - 000000504 _____ C:\Windows\Tasks\Системное обновление Браузера Яндекс.job 2023-03-18 22:35 - 2021-09-09 22:27 - 000008192 ___SH C:\DumpStack.log.tmp 2023-03-18 22:35 - 2021-07-27 03:24 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2023-03-18 22:35 - 2019-12-07 12:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-03-18 00:30 - 2019-12-07 12:03 - 000524288 _____ C:\Windows\system32\config\BBI 2023-03-17 21:09 - 2019-12-07 12:14 - 000000000 ___HD C:\Windows\ELAMBKUP 2023-03-17 21:05 - 2022-03-29 20:27 - 000000000 ____D C:\Users\vexte\AppData\Local\Yandex 2023-03-17 20:47 - 2021-09-09 22:56 - 000000000 ____D C:\Users\vexte\AppData\Local\D3DSCache 2023-03-17 01:25 - 2021-10-24 19:26 - 000000000 ____D C:\Users\vexte\AppData\Local\NVIDIA 2023-03-16 21:52 - 2021-09-28 21:27 - 000000000 ____D C:\Users\vexte\AppData\Roaming\Telegram Desktop 2023-03-16 21:51 - 2022-02-03 23:17 - 000793570 _____ C:\Windows\ntbtlog.txt 2023-03-16 21:51 - 2021-07-27 03:24 - 000000000 ____D C:\Windows\system32\SleepStudy 2023-03-16 21:19 - 2022-02-03 23:17 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job 2023-03-16 21:12 - 2022-08-20 22:41 - 000002057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk 2023-03-15 23:38 - 2022-10-04 00:32 - 000003568 _____ C:\Windows\system32\Tasks\Восстановление сервиса обновлений Яндекс Браузера 2023-03-15 23:38 - 2022-03-29 20:27 - 000003678 _____ C:\Windows\system32\Tasks\Системное обновление Браузера Яндекс 2023-03-15 23:38 - 2022-03-29 20:27 - 000002615 _____ C:\Users\vexte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex.lnk 2023-03-15 22:55 - 2021-09-09 22:29 - 000000000 ____D C:\Windows\KMSAutoS 2023-03-15 22:11 - 2022-03-31 14:01 - 000000000 ____D C:\Program Files\Common Files\AV 2023-03-15 22:11 - 2022-03-31 13:59 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2023-03-15 22:02 - 2022-04-03 16:23 - 000002336 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Cloud.lnk 2023-03-15 22:02 - 2022-03-31 14:00 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2023-03-15 22:02 - 2022-03-31 14:00 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab 2023-03-15 22:02 - 2019-12-07 12:03 - 000032768 _____ C:\Windows\system32\config\ELAM 2023-03-15 21:53 - 2023-01-17 11:40 - 000002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-03-15 01:59 - 2021-07-27 03:24 - 000538976 _____ C:\Windows\system32\FNTCACHE.DAT 2023-03-15 01:59 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\SystemResources 2023-03-15 01:59 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\bcastdvr 2023-03-14 22:37 - 2019-12-07 12:03 - 000000000 ____D C:\Windows\CbsTemp 2023-03-14 22:35 - 2021-07-27 03:27 - 003015680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll 2023-03-14 22:30 - 2021-09-10 00:24 - 000000000 ____D C:\Windows\system32\MRT 2023-03-14 22:28 - 2021-09-10 00:24 - 153620824 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2023-03-10 21:53 - 2023-01-28 23:36 - 000208896 _____ C:\Users\vexte\AppData\Roaming\emp.bin 2023-03-10 21:49 - 2021-11-19 01:03 - 000000000 ____D C:\Users\vexte\AppData\Roaming\qBittorrent 2023-03-10 21:10 - 2021-12-26 21:07 - 000000000 ____D C:\Program Files (x86)\Steam 2023-03-10 21:10 - 2021-09-11 12:55 - 000000000 ____D C:\Users\vexte\AppData\Local\UnrealEngine 2023-03-08 19:15 - 2021-10-24 19:26 - 000000000 ____D C:\Users\vexte\AppData\Local\CrashDumps 2023-03-07 23:52 - 2022-09-05 11:40 - 000000000 ____D C:\Users\vexte\AppData\Roaming\FileZilla 2023-03-03 21:35 - 2021-07-27 03:24 - 000003668 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2023-03-03 21:35 - 2021-07-27 03:24 - 000003544 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2023-03-01 03:19 - 2021-09-09 22:54 - 000000000 ____D C:\Users\vexte 2023-03-01 01:58 - 2021-12-18 11:41 - 000001332 __RSH C:\ProgramData\ntuser.pol 2023-03-01 01:25 - 2023-01-27 22:30 - 000000000 ____D C:\Users\vexte\AppData\Local\Downloaded Installations 2023-03-01 01:25 - 2021-09-09 23:16 - 000000000 ____D C:\Program Files\AMD 2023-02-28 23:39 - 2021-10-24 19:26 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2023-02-28 23:35 - 2021-10-24 19:26 - 000000000 ____D C:\Users\vexte\AppData\Local\NVIDIA Corporation 2023-02-28 03:16 - 2021-12-28 20:14 - 000000000 ____D C:\ProgramData\Epic 2023-02-28 02:15 - 2022-11-14 23:00 - 000000000 ____D C:\Windows\Minidumps 2023-02-27 21:34 - 2021-11-21 14:25 - 000000000 ____D C:\Windows\SysWOW64\directx 2023-02-27 01:25 - 2021-09-09 22:56 - 000000000 ____D C:\Users\vexte\AppData\Local\AMD 2023-02-26 16:49 - 2021-09-09 22:35 - 000065536 _____ C:\Windows\system32\spu_storage.bin 2023-02-26 16:45 - 2021-09-09 23:06 - 000000000 ____D C:\Users\vexte\AppData\Local\AMD_Common 2023-02-26 04:39 - 2022-06-11 01:01 - 000370176 _____ (Microsoft Corporation) C:\Windows\system32\GameInputRedist.dll 2023-02-26 03:11 - 2022-06-11 01:01 - 000242168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GameInputRedist.dll 2023-02-24 13:56 - 2021-12-08 20:15 - 000243152 _____ (Microsoft Corporation) C:\Windows\system32\gamingservicesproxy.dll.0 2023-02-23 22:02 - 2019-12-07 17:37 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2023-02-23 22:02 - 2019-12-07 12:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 2023-02-23 22:02 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\oobe 2023-02-23 22:02 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\PolicyDefinitions 2023-02-16 23:41 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\SysWOW64\oobe 2023-02-16 23:41 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\setup 2023-02-16 23:41 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\DDFs 2023-02-16 22:31 - 2021-07-27 03:24 - 000000000 ____D C:\Windows\system32\Drivers\wd ==================== Файлы в корне каталогов ======== 2023-01-28 23:36 - 2023-03-10 21:53 - 000208896 _____ () C:\Users\vexte\AppData\Roaming\emp.bin 2023-03-01 01:09 - 2023-03-01 01:09 - 000007602 _____ () C:\Users\vexte\AppData\Local\Resmon.ResmonCfg 2022-07-09 00:10 - 2022-07-09 00:10 - 000000000 _____ () C:\Users\vexte\AppData\Local\{79C93835-F411-4DAE-AE4A-A2C4014263DA} ==================== SigCheck ============================ (Нет автоматического исправления файлов, которые не проходят проверку.) ==================== Конец от FRST.txt ========================