﻿Лог утилиты random's system information tool 1.09 (автор: random/random)
Run by Nikita at 2014-09-26 17:17:51
Microsoft Windows 7 Максимальная  Service Pack 1
Системный раздел C: размер 32 GB (45%) Свободно 71 GB
Total RAM: 8188 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:17:53, on 26.09.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe
C:\Program Files (x86)\2gis\3.0\2GISTrayNotifier.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe
C:\Users\Nikita\AppData\Local\Temp\RarSFX0\2938607.exe
C:\Users\Nikita\AppData\Local\Temp\3824608\2938607.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\klwtblfs.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
G:\Рабочий стол\Моё\Программы\AutoLogger.exe
G:\Рабочий стол\Моё\Программы\AutoLogger\AVZ\avz.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe
G:\Рабочий стол\Моё\Программы\AutoLogger\RSIT\Nikita.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://babyuser.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IE 4.x-6.x BHO for Download Master - {9961627E-4059-41B4-8E0E-A7D6B3854ADF} - C:\PROGRA~2\DOWNLO~1\dmiehlp.dll (file missing)
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: (no name) - {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe"
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\RunOnce: [Application Restart #1] C:\Users\Nikita\AppData\Local\Yandex\YandexBrowser\Application\browser.exe  --flag-switches-begin --conflicting-modules-check --disable-accelerated-video-decode --enable-d3d11 --enable-encrypted-media --enable-accelerated-overflow-scroll --flag-switches-end --disable-ssl-false-start --disable-webkit-media-source --disable-direct-npapi-requests --disable-client-side-phishing-detection --disable-breadcrumbs-api --google-profile-info --sync-try-ssltcp-first-for-xmpp --restore-last-session
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Sothink Flash Downloader For IE - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: Добавить в Анти-Баннер - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Виртуальная клавиатура - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: (no name) - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Проверка ссылок - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\UrlAdvisor\klwtbbho.dll
O9 - Extra button: Sothink Flash Downloader For IE - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink Flash Downloader For IE - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 2GIS UpdateService (2GISUpdateService) - ООО ДубльГИС - C:\Program Files (x86)\2gis\3.0\2GISUpdateService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe
O23 - Service: Сервис управления системы CryproStorage (CSObjectsSrv) - Infowatch - C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Служба Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit (mi-raysat_3dsmax2013_64) - Unknown owner - G:\3ds max\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\Windows\system32\UAService7.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12487 bytes

======Список процессов======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2e0
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe" -r
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\2gis\3.0\2GISTrayNotifier.exe" -delayed_start
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe" 
taskeng.exe {D6494CBC-4C87-4DA3-87B3-C872107465E0}
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k SDRSVC
"taskhost.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b9d93128-d22e-4231-832e-603a0765e7dd -SystemEventPortName:HostProcess-690f50ed-3b9f-48bd-9fcb-c7573ac6f7a3 -IoCancelEventPortName:HostProcess-623cc473-d18d-40f2-abb2-be59ce718a27 -NonStateChangingEventPortName:HostProcess-39f48946-fe23-4d8c-8a1c-25aa113ec847 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6f130e5b-4bd0-42f4-9149-82c9bcc9f84c
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Nikita\AppData\Local\Temp\RarSFX0\2938607.exe" 
C:\Users\Nikita\AppData\Local\Temp\3824608\2938607.exe
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --load-extension="C:\Users\Nikita\AppData\Roaming\extensions\extensions_yandex","C:\Users\Nikita\AppData\Roaming\extensions\extension_yandex"
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=gpu-process --channel="6656.0.1225237846\1332902936" --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,27 --gpu-vendor-id=0x1002 --gpu-device-id=0x68d8 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.100.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.1.1321581007\1075420397" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.2.1755552090\1389621245" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.4.1725038594\1393944760" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=plugin --plugin-path="C:\Users\Nikita\AppData\Local\Nichrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.2.558_0\plugin/npUrlAdvisor.dll" --lang=ru --channel="6656.5.1123154039\2110005514" /prefetch:-390060480
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.6.1399494269\1870330644" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.9.2129615559\83729421" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.10.1461801548\369366209" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.12.599783075\1500498435" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.13.911620849\26476584" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --enable-software-compositing --channel="6656.14.1869048474\140721658" /prefetch:673131151
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\klwtblfs.exe" -Embedding
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=plugin --plugin-path="C:\Users\Nikita\AppData\Local\Nichrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.2.558_0\plugin/npABPlugin.dll" --lang=ru --channel="6656.18.500738886\1628093805" /prefetch:-390060480
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --lang=ru --channel="6656.20.756910839\869800512" /prefetch:-390060480
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.21.1526494968\946327935" /prefetch:673131151
"C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe"
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.22.624798240\1317207235" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.23.189439637\1197714485" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.35.1739724837\601307761" /prefetch:673131151
"C:\Program Files (x86)\Skype\Phone\Skype.exe" 
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.38.657509130\612928951" /prefetch:673131151
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.40.1064850708\2011437708" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6916.0.189394990\1511497707" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x68d8 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.100.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=ru --force-fieldtrials="ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_66/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="6916.1.639091024\722759769" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=ru --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_66/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="6916.2.1306780528\58402110" /prefetch:673131151
"G:\Рабочий стол\Моё\Программы\AutoLogger.exe" 
"G:\Рабочий стол\Моё\Программы\AutoLogger\AVZ\avz.exe" Script=AVZ\Script2.txt HiddenMode=0
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://google.ru
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=ru --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group3 pct:10c stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_66/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="6916.11.1147281533\52351155" /prefetch:673131151
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:6680 CREDAT:79873
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Nikita\AppData\Local\Nichrome\Application\ramblerbrowser.exe" --type=renderer --lang=ru --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prerender/PrerenderControl/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_42/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-50-Percent/default/ --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="6656.41.1925281973\1969691888" /prefetch:673131151
"G:\Рабочий стол\Моё\Программы\AutoLogger\RSIT\RSITx64.exe" 
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding

======Папка назначеных зданий======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Nikita\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default

prefs.js - "browser.search.useDBForOrder" -  false
prefs.js - "browser.startup.homepage" -  "http://www.yandex.ru/?win=142&clid=1985535"
prefs.js - "browser.search.suggest.enabled" -  true
prefs.js - "keyword.enabled" -  true

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.65.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.65.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@raidcall.en/RCplugin]
"Description"=Raidcall plugin
"Path"=C:\Users\Nikita\AppData\Roaming\raidcall\plugins\nprcplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll


C:\Users\Nikita\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\
info4@etranslator.pro
staged
vb@yandex.ru
yasearch@yandex.ru

C:\Users\Nikita\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\
mailru.xml
rambler.xml
yandex.ru-152013.xml
yqs-barff-yandex.xml

======Снимок реестра======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-08-09 658624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-08-09 1074368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-08-12 553896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-08-09 518336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}]
Визуальные закладки

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-08-12 211880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-08-09 584384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-08-09 542400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-08-09 885952]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-01 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master - C:\PROGRA~2\DOWNLO~1\dmiehlp.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}]
Safe Money Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-08-09 428224]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-01 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-08-09 488640]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Application Restart #1"=C:\Users\Nikita\AppData\Local\Yandex\YandexBrowser\Application\browser.exe [2014-07-18 1454384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2Gis Update Notifier]
C:\Program Files (x86)\2gis\3.0\2GISTrayNotifier.exe [2014-07-25 4650520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03 472984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD CATALYST™ HydraVision Dynamic Link]
C:\Users\Nikita\AppData\Roaming\Innuendo Logic\aticfx32.exe [2013-08-13 275968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Application Restart #2]
C:\Users\Nikita\AppData\Local\Yandex\YandexBrowser\Application\browser.exe [2014-07-18 1454384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_F09C4B2134E863D167072BEFE62AF26B]
C:\Users\Nikita\Desktop\chrome-win32\chrome.exe --no-startup-window []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
D:\hamachi\hamachi-2-ui.exe [2014-09-04 3802448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
C:\Users\Nikita\AppData\Roaming\QipGuard\QipGuard.exe [2014-01-13 435696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rambler Update]
C:\Users\Nikita\AppData\Local\Rambler\RamblerUpdater\rupdate.exe\ /startscheduler []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-08-27 22037088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Users\Nikita\AppData\Roaming\uTorrent\uTorrent.exe [2014-02-26 1520208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Nikita^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^adobe-updater.lnk]
C:\PROGRA~2\Adobe\ADOBE-~1.EXE [2013-10-12 317283]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Nikita^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CurseClientStartup.ccip]
C:\Users\Nikita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Nikita^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^_uninst_45623507.lnk]
C:\Users\Nikita\AppData\Local\Temp\_uninst_45623507.bat  []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AVP"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe [2013-11-12 356128]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"=grpconv -o []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=60

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv

======Ассоциации файлов======

.ini - open - "C:\Program Files (x86)\Notepad++\notepad++.exe" "%1"
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"

======Список файлов и папок, созданных за последние 3 месяца======

2014-09-26 17:17:51 ----D---- C:\rsit
2014-09-26 17:15:41 ----A---- C:\Windows\SYSWOW64\drivers\utewoti5.sys
2014-09-26 16:24:59 ----A---- C:\Windows\system32\drivers\45623507.sys
2014-09-26 16:21:36 ----A---- C:\TDSSKiller.3.0.0.40_26.09.2014_16.21.36_log.txt
2014-09-26 16:11:03 ----AH---- C:\Windows\memofor.ini
2014-09-26 16:10:56 ----A---- C:\Windows\Protection.INI
2014-09-26 16:10:22 ----A---- C:\Windows\fileCBinst.ini
2014-09-18 15:30:48 ----D---- C:\Users\Nikita\AppData\Roaming\extensions
2014-09-18 15:19:58 ----D---- C:\ProgramData\Media Get LLC
2014-09-09 00:03:38 ----D---- C:\Windows\SYSWOW64\Wat
2014-09-09 00:03:38 ----D---- C:\Windows\system32\Wat
2014-09-05 22:21:30 ----D---- C:\Users\Nikita\AppData\Roaming\Rambler
2014-09-03 19:28:14 ----D---- C:\ProgramData\Tunngle
2014-09-03 19:28:13 ----D---- C:\Program Files (x86)\Tunngle
2014-09-01 23:02:23 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-01 23:02:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-08-29 16:48:11 ----D---- C:\ProgramData\FlyVPN
2014-08-29 06:21:02 ----A---- C:\Windows\system32\FNTCACHE.DAT
2014-08-27 13:33:00 ----D---- C:\ProgramData\CyberTank
2014-08-26 18:39:45 ----D---- C:\Users\Nikita\AppData\Roaming\Wargaming.net
2014-08-21 00:20:00 ----A---- C:\log.txt
2014-08-19 21:29:23 ----D---- C:\Users\Nikita\AppData\Roaming\.minecraft
2014-08-13 21:42:16 ----D---- C:\Users\Nikita\AppData\Roaming\.minecraftonly
2014-08-12 02:15:51 ----D---- C:\Program Files\Java
2014-08-09 00:38:23 ----A---- C:\Windows\system32\klfphc.dll
2014-08-09 00:37:29 ----A---- C:\Windows\system32\drivers\CSVirtualDiskDrv.sys
2014-08-09 00:37:25 ----A---- C:\Windows\system32\drivers\CSCrySec.sys
2014-08-09 00:37:00 ----D---- C:\Windows\ELAMBKUP
2014-08-09 00:36:57 ----D---- C:\Program Files (x86)\Kaspersky Lab
2014-08-09 00:36:46 ----A---- C:\Windows\system32\drivers\klif.sys
2014-08-09 00:36:46 ----A---- C:\Windows\system32\drivers\klflt.sys
2014-08-08 21:46:37 ----D---- C:\AdwCleaner
2014-08-07 15:29:00 ----D---- C:\ProgramData\Adguard
2014-08-07 01:36:07 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-08-07 01:36:07 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-08-07 01:36:07 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-08-07 01:36:07 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-08-07 01:36:06 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-08-07 01:36:06 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-08-03 22:45:04 ----D---- C:\Program Files (x86)\HideME.ru VPN
2014-08-03 19:16:29 ----D---- C:\ProgramData\SuperHideIP
2014-08-03 09:32:50 ----D---- C:\ProgramData\WNR
2014-08-03 09:16:28 ----D---- C:\ProgramData\notracks.com
2014-08-03 09:14:44 ----A---- C:\Windows\SYSWOW64\EasyRedirectOff.ini
2014-08-03 09:14:44 ----A---- C:\Windows\SYSWOW64\EasyRedirect.ini
2014-08-03 09:14:44 ----A---- C:\Windows\system32\EasyRedirectOff.ini
2014-08-03 09:14:40 ----A---- C:\Windows\system32\EasyRedirect64.dll
2014-08-03 09:14:38 ----A---- C:\Windows\SYSWOW64\EasyRedirect.dll
2014-08-02 11:08:13 ----D---- C:\ProgramData\Mozilla
2014-08-01 01:22:20 ----D---- C:\Program Files (x86)\Java
2014-07-31 10:14:37 ----D---- C:\cristalix1
2014-07-30 14:14:24 ----D---- C:\ProgramData\LumaEmu_SteamCloud
2014-07-30 13:48:46 ----D---- C:\Program Files (x86)\Facepunch Studios
2014-07-28 16:01:20 ----D---- C:\Windows\SYSWOW64\URTTEMP
2014-07-28 15:34:18 ----D---- C:\Program Files\Sony
2014-07-28 15:33:11 ----D---- C:\Users\Nikita\AppData\Roaming\Sony
2014-07-19 20:09:31 ----D---- C:\Program Files (x86)\Cheat Engine 6.4
2014-07-19 17:53:21 ----D---- C:\Windows\SYSWOW64\Adobe
2014-07-18 23:17:24 ----A---- C:\Windows\system32\javaws.exe
2014-07-18 23:17:18 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-18 23:17:18 ----A---- C:\Windows\system32\javaw.exe
2014-07-18 23:17:18 ----A---- C:\Windows\system32\java.exe
2014-07-18 23:14:22 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-07-18 23:14:17 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-07-18 23:14:17 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-07-18 23:14:17 ----A---- C:\Windows\SYSWOW64\java.exe
2014-07-13 19:47:45 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2014-07-13 19:42:31 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2014-06-29 20:41:43 ----D---- C:\Users\Nikita\AppData\Roaming\NovoPerf
2014-06-29 06:18:44 ----SHD---- C:\ProgramData\SecuROM

======Список файлов и папок, измененных за последние 3 месяца======

2014-09-26 17:17:52 ----D---- C:\Windows\Temp
2014-09-26 17:16:18 ----HD---- C:\Windows
2014-09-26 17:15:47 ----D---- C:\Users\Nikita\AppData\Roaming\Skype
2014-09-26 17:15:41 ----D---- C:\Windows\SYSWOW64\drivers
2014-09-26 17:05:47 ----D---- C:\ProgramData\Kaspersky Lab
2014-09-26 17:03:29 ----D---- C:\Program Files (x86)\Google
2014-09-26 17:03:22 ----RD---- C:\Program Files (x86)
2014-09-26 17:02:01 ----SHD---- C:\Windows\Installer
2014-09-26 17:00:16 ----D---- C:\Users\Nikita\AppData\Roaming\SYSTEMAX Software Development
2014-09-26 16:57:37 ----D---- C:\Windows\Tasks
2014-09-26 16:57:37 ----D---- C:\Windows\system32\Tasks
2014-09-26 16:53:11 ----D---- C:\Program Files (x86)\Adobe
2014-09-26 16:43:16 ----D---- C:\Windows\pss
2014-09-26 16:25:05 ----D---- C:\Windows\system32\drivers
2014-09-26 07:34:39 ----D---- C:\Windows\System32
2014-09-26 07:34:39 ----D---- C:\Windows\inf
2014-09-26 07:34:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-26 07:12:23 ----D---- C:\The KMPlayer
2014-09-26 05:16:04 ----SD---- C:\Users\Nikita\AppData\Roaming\Microsoft
2014-09-25 17:11:49 ----D---- C:\Program Files (x86)\QIP 2012
2014-09-25 08:29:15 ----D---- C:\Users\Nikita\AppData\Roaming\uTorrent
2014-09-25 00:47:04 ----HD---- C:\ProgramData
2014-09-25 00:14:30 ----RD---- C:\Program Files
2014-09-25 00:08:13 ----D---- C:\Windows\SysWOW64
2014-09-25 00:08:11 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-25 00:01:40 ----D---- C:\Windows\Prefetch
2014-09-21 19:29:16 ----SHD---- C:\System Volume Information
2014-09-21 19:20:19 ----D---- C:\Windows\system32\config
2014-09-19 18:31:08 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-09-19 15:26:34 ----D---- C:\ProgramData\Skype
2014-09-19 15:26:27 ----RD---- C:\Program Files (x86)\Skype
2014-09-19 15:26:27 ----D---- C:\Program Files (x86)\Common Files
2014-09-18 16:41:14 ----D---- C:\Windows\SYSWOW64\directx
2014-09-18 16:37:21 ----D---- C:\Users\Nikita\AppData\Roaming\Yandex
2014-09-18 10:27:46 ----D---- C:\Windows\Logs
2014-09-17 19:17:14 ----D---- C:\Program Files (x86)\Opera
2014-09-09 17:25:46 ----D---- C:\Users\Nikita\AppData\Roaming\Tunngle
2014-09-09 00:03:49 ----A---- C:\Windows\SYSWOW64\slwga.dll
2014-09-09 00:03:49 ----A---- C:\Windows\system32\systemcpl.dll
2014-09-09 00:03:49 ----A---- C:\Windows\system32\slwga.dll
2014-09-09 00:03:48 ----A---- C:\Windows\SYSWOW64\user32.dll
2014-09-09 00:03:48 ----A---- C:\Windows\system32\user32.dll
2014-09-09 00:03:43 ----D---- C:\Windows\winsxs
2014-09-09 00:03:36 ----D---- C:\Windows\system32\catroot
2014-09-07 17:09:40 ----RSD---- C:\Windows\Fonts
2014-09-03 19:35:22 ----D---- C:\Windows\system32\catroot2
2014-08-20 00:20:25 ----D---- C:\Windows\Microsoft.NET
2014-08-20 00:20:16 ----RSD---- C:\Windows\assembly
2014-08-17 16:37:22 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2014-08-09 00:38:03 ----D---- C:\Windows\system32\DriverStore
2014-08-09 00:37:29 ----DC---- C:\Windows\system32\DRVSTORE
2014-08-09 00:29:48 ----D---- C:\Program Files\Get-Styles 2.0
2014-08-09 00:20:40 ----D---- C:\ProgramData\Package Cache
2014-08-09 00:17:08 ----D---- C:\Windows\Minidump
2014-08-09 00:08:19 ----D---- C:\Program Files\Common Files\Autodesk Shared
2014-08-09 00:05:10 ----D---- C:\ProgramData\Autodesk
2014-08-07 12:24:02 ----D---- C:\Windows\SYSWOW64\config
2014-08-05 09:20:00 ----N---- C:\Windows\system32\MpSigStub.exe
2014-08-03 09:55:07 ----D---- C:\Windows\ShellNew
2014-08-03 09:52:44 ----D---- C:\Users\Nikita\AppData\Roaming\Opera Software
2014-08-01 01:22:32 ----D---- C:\ProgramData\Oracle
2014-07-28 16:02:01 ----D---- C:\Windows\Registration
2014-07-28 16:01:43 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-07-28 16:01:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-15 12:32:19 ----A---- C:\Windows\system32\user32.dll.old
2014-07-15 12:18:58 ----A---- C:\Windows\SYSWOW64\user32.dll.old
2014-07-09 16:18:19 ----D---- C:\Users\Nikita\AppData\Roaming\Mozilla
2014-07-01 13:55:45 ----A---- C:\Windows\WORDPAD.INI

======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)======

R0 45623507;45623507; C:\Windows\system32\DRIVERS\45623507.sys [2014-09-26 458336]
R0 CSCrySec;InfoWatch Encrypt Sector Library driver; C:\Windows\system32\DRIVERS\CSCrySec.sys [2011-06-02 84536]
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2014-08-09 458336]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AsrAppCharger;AsrAppCharger; C:\Windows\system32\DRIVERS\AsrAppCharger.sys [2011-05-10 17192]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver; C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys [2011-06-02 66616]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-07-13 283064]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2014-08-09 628288]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2014-08-09 29792]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2013-11-12 54368]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2013-11-12 178448]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2013-11-19 43168]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-07-29 56960]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-07-29 79104]
R3 FETNDIS;Драйвер адаптера VIA Rhine-Family Fast Ethernet; C:\Windows\system32\DRIVERS\fet6x64.sys [2009-06-11 47872]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2013-11-12 29280]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-11-12 29280]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-04-22 471144]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
S1 adgnetworktdi;adgnetworktdi; C:\Windows\system32\drivers\adgnetworktdi.sys []
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-01-05 311968]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-06-21 103448]
S3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 massfilter;ZTE Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2013-01-08 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sprd_enum;sprd_enum; C:\Windows\system32\DRIVERS\sprd_enum.sys [2011-08-22 100352]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-06-21 203672]
S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudobex.sys [2013-06-21 203672]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 40664]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 taphss6;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2014-05-17 42184]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usb_rndisx;Адаптер USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 utewoti5;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\utewoti5.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUSB;Android USB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]

======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-04-18 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 344064]
R2 AVP;Kaspersky Anti-Virus Service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky CRYSTAL 3.0\avp.exe [2013-11-12 356128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CSObjectsSrv;Сервис управления системы CryproStorage; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2013-09-25 818888]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Служба Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-26 116648]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; D:\hamachi\hamachi-2.exe [2014-09-04 2525008]
S2 mi-raysat_3dsmax2013_64;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit; G:\3ds max\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe []
S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-08-17 76152]
S2 UserAccess7;SecuROM User Access Service (V7); C:\Windows\syswow64\UAService7.exe [2014-02-23 143360]
S3 2GISUpdateService;2GIS UpdateService; C:\Program Files (x86)\2gis\3.0\2GISUpdateService.exe [2014-07-25 3820568]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-25 267440]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-03-15 1432400]
S3 gupdatem;Служба Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-26 116648]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-03-12 136120]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-17 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2013-11-06 758224]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-09-09 1255736]
S4 MSSQLServerADHelper100;Служба поддержки Active Directory сервера SQL Server; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-21 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 SQLAgent$SQLEXPRESS;Агент SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]

-----------------EOF-----------------
