﻿Лог утилиты random's system information tool 1.12(автор: random/random)
Run by Natali at 2016-04-08 13:10:13
Microsoft Windows 7 Домашняя расширенная  Service Pack 1
Системный раздел C: размер 27 GB (38%) Свободно 70 GB
Total RAM: 1790 MB (7% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:10:21, on 08.04.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16737)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\System32\svchost.exe
C:\Windows\KMS-R@1n.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\1.3.29.5\GoogleCrashHandler.exe
C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\NSBU.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\svchost.exe
D:\Распаковка архивов\AutoLogger\AVZ\avz.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\NSBU.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\WacomHost.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\conhost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
C:\Program Files\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
D:\Распаковка архивов\AutoLogger\RSIT\RSIT.exe
D:\Распаковка архивов\AutoLogger\RSIT\Natali_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com.ua/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yandex.ru/?win=192&clid=2233381
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\coIEPlg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\coIEPlg.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Отправить в OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O9 - Extra button: Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Звонок щелчком Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Звонок щелчком Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Связанные заметки OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Связанные заметки OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Служба Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: KMS-R@1n - Unknown owner - C:\Windows\KMS-R@1n.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton Security with Backup (NSBU) - Symantec Corporation - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\NSBU.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Wacom Consumer Service (WTabletServiceCon) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\WTabletServiceCon.exe

--
End of file - 9862 bytes

======Папка назначеных зданий======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 
C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-Natali-ПК-Natali - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -mode=scheduled
C:\Windows\system32\tasks\BatteryLifeExtender - C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe /2
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Norton WSC Integration - "C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\WSCStub.exe" /taskschd
C:\Windows\system32\tasks\SearchGo Task - C:\Users\Natali\AppData\Local\SearchGo\searchgo.exe 
C:\Windows\system32\tasks\{F723961F-A48E-4DA6-9C67-3E9B031B383F} - C:\Windows\system32\pcalua.exe -a D:\Games\setup.exe -d D:\Games
C:\Windows\system32\tasks\Remediation\AntimalwareMigrationTask - "C:\Program Files\Common Files\AV\Norton Security + резервное копирование\Upgrade.exe" /upgrade /user_logon
C:\Windows\system32\tasks\R@1n-KMS\Office15ProPlus - wmic path OfficeSoftwareProtectionProduct where (ID="b322da9c-a2e2-4058-9e4e-f59a6970bd69") call Activate
C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - %systemroot%\system32\sc.exe start osppsvc
C:\Windows\system32\tasks\Norton Security with Backup\Norton Error Analyzer - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\SymErr.exe /analyze
C:\Windows\system32\tasks\Norton Security with Backup\Norton Error Processor - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\SymErr.exe /submit
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" 
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\TabletPC\InputPersonalization - %CommonProgramFiles%\Microsoft Shared\Ink\InputPersonalization.exe 
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess - %windir%\system32\GWX\GWX.exe /tasklaunch
C:\Windows\system32\tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig - %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfig
C:\Windows\system32\tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent - %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfigAndContent
C:\Windows\system32\tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent - %windir%\system32\GWX\GWXConfigManager.exe /RefreshContent
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs 
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe 
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe 
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe 
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe 
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent 
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe 
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe 
C:\Windows\system32\tasks\Microsoft\Office\Office 15 Subscription Heartbeat - %ProgramFiles%\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe 
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack - "C:\Program Files\Microsoft Office\Office15\msoia.exe" scan upload mininterval:2880
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn - "C:\Program Files\Microsoft Office\Office15\msoia.exe" scan upload

=========Mozilla firefox=========

ProfilePath - C:\Users\Natali\AppData\Roaming\Mozilla\Firefox\Profiles\9f1rwq5n.default

prefs.js - "browser.startup.homepage" -  "https://www.google.com.ua/?gws_rd=ssl#q=%D0%B2%D0%BE%D1%80%D0%BA+%D1%8E%D0%B0"

"{C1A2A613-35F1-4FCF-B27F-2840527B6556}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\wacom.com/WacomTabletPlugin]
"Description"=
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll


C:\Program Files\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll

C:\Users\Natali\AppData\Roaming\Mozilla\Firefox\Profiles\9f1rwq5n.default\addons.json
Firefox Hello Beta - extension - loop@mozilla.org
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org

C:\Users\Natali\AppData\Roaming\Mozilla\Firefox\Profiles\9f1rwq5n.default\extensions.json
Norton Identity Safe - extension - {C1A2A613-35F1-4FCF-B27F-2840527B6556} - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
Firefox Hello Beta - extension - loop@mozilla.org - C:\Program Files\Mozilla Firefox\browser\features\loop@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

C:\Users\Natali\AppData\Roaming\Mozilla\Firefox\Profiles\9f1rwq5n.default\pluginreg.dat
Plugin - Adobe Acrobat - 11.0.15.2 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll
Plugin - AdobeAAMDetect - 3.0.0.0 - C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
Plugin - Adobe Acrobat - 11.0.15.2 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
Plugin - WacomTabletPlugin - 2.1.0.7 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll
Plugin - Google Update - 1.3.29.5 - C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
Plugin - Microsoft Office 2013 - 15.0.4514.1000 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
Plugin - Silverlight Plug-In - 5.1.41212.0 - C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
Plugin - Microsoft Office 2013 - 15.0.4777.1000 - C:\Program Files\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll

=========Google Chrome=========

C:\Users\Natali\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Google Презентации 4.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Интернет-магазин Chrome 0.2
Extension ahkmpjnmnhjkpkacdhkliipnncobgkhk   
Extension aohghmighlieiainnegkcijnfilokake 1 Документы Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Диск Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0  
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension cjabmdjcfcfdmffimndhafhblfmpjdpe 1 Norton Security Toolbar 2015.5.6.94
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Google Таблицы 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Документы офлайн 1.4
Extension iikflkcanblccfahdhdonehdalibjnif 1 Norton Identity Safe 1.0.5
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.31
Extension lpeeaghdjmhlakojjcgfdhgcejdaefmi 2 Kaspersky Protection 4.6.1.170
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.2.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Платежная система Интернет-магазина Chrome 1.0.0.0
Extension oelpkepjlgmehajehfeicfbjdiobdkfj   
Extension phokcamelcbnjikjgomjjadeihhbbidh   
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Homepage: 
default_search_provider.search_url: 
C:\Users\Natali\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage: 
default_search_provider.search_url: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe]
"Path"=C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\Exts\Chrome.crx

[HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif]
"Path"=


======Снимок реестра======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{09CD854E-149E-4460-B0D3-172D7D897F4D}]
"URL"=http://yandex.ru/yandsearch?text={searchTerms}&win=192&clid=2233382

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-02-09 163016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\coIEPlg.dll [2016-02-21 805560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office15\URLREDIR.DLL [2014-01-23 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2016-03-15 1741104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\coIEPlg.dll [2016-02-21 805560]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2015-06-18 12336856]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-01-07 508128]
"Adobe Creative Cloud"=C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-02-12 2312896]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-04-30 642304]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-18 1085656]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-03-11 6667992]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\05273882.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\05273882.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files\Google\Chrome\Application\49.0.2623.112\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.VP70"=vp7vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.HFYU"=huffyuv.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======Ассоциации файлов======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======Список файлов и папок, созданных за последние 3 месяца======

2016-04-08 12:56:34 ----A---- C:\Windows\system32\drivers\utm4mtkw.sys
2016-04-08 10:37:55 ----D---- C:\ProgramData\Malwarebytes
2016-04-07 20:16:30 ----D---- C:\KVRT_Data
2016-04-07 17:58:22 ----D---- C:\Program Files\Mozilla Firefox
2016-04-07 17:30:14 ----D---- C:\Users\Natali\AppData\Roaming\Mozilla
2016-04-07 17:29:41 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-07 16:56:17 ----D---- C:\AdwCleaner
2016-04-06 20:51:15 ----D---- C:\Program Files\Common Files\AV
2016-04-06 20:48:37 ----D---- C:\Program Files\Common Files\Symantec Shared
2016-04-06 20:48:37 ----A---- C:\Windows\system32\drivers\SYMEVENT.SYS
2016-04-06 20:46:05 ----D---- C:\Windows\system32\drivers\NSBU
2016-04-06 20:46:04 ----D---- C:\Program Files\Norton Security with Backup
2016-04-06 20:44:32 ----D---- C:\ProgramData\NortonInstaller
2016-04-06 20:44:32 ----D---- C:\Program Files\NortonInstaller
2016-04-06 20:42:43 ----D---- C:\ProgramData\Norton
2016-04-06 15:53:19 ----D---- C:\Windows\system32\Чистилка
2016-04-06 15:40:38 ----D---- C:\Users\Natali\AppData\Roaming\Macromedia
2016-04-06 15:40:19 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-04-06 15:40:18 ----D---- C:\Windows\system32\Macromed
2016-04-06 15:39:37 ----HD---- C:\Windows\AxInstSV
2016-04-06 14:44:01 ----D---- C:\ProgramData\Чистилка
2016-04-06 14:01:25 ----D---- C:\Program Files\CCleaner
2016-04-03 16:51:54 ----A---- C:\Windows\system32\invagent.dll
2016-04-03 16:51:54 ----A---- C:\Windows\system32\generaltel.dll
2016-04-03 16:51:54 ----A---- C:\Windows\system32\devinv.dll
2016-04-03 16:51:54 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-04-03 16:51:54 ----A---- C:\Windows\system32\appraiser.dll
2016-04-03 16:51:54 ----A---- C:\Windows\system32\aepic.dll
2016-04-03 16:51:54 ----A---- C:\Windows\system32\acmigration.dll
2016-04-03 16:51:53 ----A---- C:\Windows\system32\aeinv.dll
2016-03-25 11:57:15 ----D---- C:\Users\Natali\AppData\Roaming\WTablet
2016-03-25 11:57:08 ----D---- C:\Program Files\TabletPlugins
2016-03-25 11:57:05 ----A---- C:\Windows\system32\drivers\wacomrouterfilter.sys
2016-03-25 11:57:01 ----A---- C:\Windows\system32\wdfcoinstaller01009.dll
2016-03-25 11:57:01 ----A---- C:\Windows\system32\drivers\wdfcoinstaller01009.dll
2016-03-25 11:57:01 ----A---- C:\Windows\system32\drivers\wachidrouter.sys
2016-03-25 11:57:01 ----A---- C:\Windows\system32\drivers\hidkmdf.sys
2016-03-25 11:56:53 ----A---- C:\Windows\system32\Wintab32.dll
2016-03-25 11:56:53 ----A---- C:\Windows\system32\WacomMT.dll
2016-03-25 11:56:53 ----A---- C:\Windows\system32\Pen_Touch_Tablet.dll
2016-03-25 11:56:53 ----A---- C:\Windows\system32\Pen_Tablet.dll
2016-03-25 11:56:49 ----D---- C:\Program Files\Tablet
2016-03-22 18:33:06 ----D---- C:\Users\Natali\AppData\Roaming\Media Player Classic
2016-03-22 18:30:49 ----A---- C:\Windows\system32\unrar.dll
2016-03-22 18:30:49 ----A---- C:\Windows\avisplitter.ini
2016-03-22 18:30:48 ----A---- C:\Windows\system32\yv12vfw.dll
2016-03-22 18:30:48 ----A---- C:\Windows\system32\vp7vfw.dll
2016-03-22 18:30:48 ----A---- C:\Windows\system32\huffyuv.dll
2016-03-22 18:30:47 ----A---- C:\Windows\system32\xvidvfw.dll
2016-03-22 18:30:47 ----A---- C:\Windows\system32\xvidcore.dll
2016-03-22 18:30:46 ----A---- C:\Windows\system32\ff_vfw.dll
2016-03-20 15:37:47 ----A---- C:\Windows\KMS-R@1nHook.dll
2016-03-20 15:37:47 ----A---- C:\Windows\KMS-R@1n.exe
2016-03-19 13:25:37 ----D---- C:\Windows\AutoKMS
2016-03-19 13:24:35 ----D---- C:\ProgramData\Microsoft Toolkit
2016-03-17 16:35:41 ----D---- C:\Program Files\AMD AVT
2016-03-17 16:35:34 ----D---- C:\Program Files\AMD APP
2016-03-17 16:33:23 ----D---- C:\ProgramData\ATI
2016-03-17 13:24:28 ----D---- C:\Program Files\Common Files\ATI Technologies
2016-03-17 12:46:53 ----SHD---- C:\Config.Msi
2016-03-17 11:20:20 ----D---- C:\Program Files\ATI Technologies
2016-03-16 14:55:18 ----A---- C:\Windows\system32\vbscript.dll
2016-03-16 14:55:18 ----A---- C:\Windows\system32\urlmon.dll
2016-03-16 14:55:18 ----A---- C:\Windows\system32\mshta.exe
2016-03-16 14:55:18 ----A---- C:\Windows\system32\msfeedssync.exe
2016-03-16 14:55:18 ----A---- C:\Windows\system32\msfeedsbs.dll
2016-03-16 14:55:17 ----A---- C:\Windows\system32\msfeeds.dll
2016-03-16 14:55:17 ----A---- C:\Windows\system32\jsproxy.dll
2016-03-16 14:55:17 ----A---- C:\Windows\system32\jscript.dll
2016-03-16 14:55:17 ----A---- C:\Windows\system32\iertutil.dll
2016-03-16 14:55:16 ----A---- C:\Windows\system32\wininet.dll
2016-03-16 14:55:16 ----A---- C:\Windows\system32\url.dll
2016-03-16 14:55:16 ----A---- C:\Windows\system32\jscript9.dll
2016-03-16 14:55:16 ----A---- C:\Windows\system32\ieUnatt.exe
2016-03-16 14:55:16 ----A---- C:\Windows\system32\dxtmsft.dll
2016-03-16 14:55:15 ----A---- C:\Windows\system32\ieframe.dll
2016-03-16 14:55:12 ----A---- C:\Windows\system32\ieui.dll
2016-03-16 14:55:12 ----A---- C:\Windows\system32\dxtrans.dll
2016-03-16 14:55:11 ----A---- C:\Windows\system32\mshtmled.dll
2016-03-16 14:55:10 ----A---- C:\Windows\system32\mshtml.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\wextract.exe
2016-03-16 14:38:26 ----A---- C:\Windows\system32\webcheck.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2016-03-16 14:38:26 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2016-03-16 14:38:26 ----A---- C:\Windows\system32\msrating.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\msls31.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\mshtmler.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\licmgr10.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\inseng.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\iexpress.exe
2016-03-16 14:38:26 ----A---- C:\Windows\system32\iesysprep.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\iesetup.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\iernonce.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\iedkcs32.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\ieapfltr.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\ieapfltr.dat
2016-03-16 14:38:26 ----A---- C:\Windows\system32\ieakeng.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\IEAdvpack.dll
2016-03-16 14:38:26 ----A---- C:\Windows\system32\ie4uinit.exe
2016-03-16 14:38:26 ----A---- C:\Windows\system32\icardie.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\pngfilt.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\occache.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\imgutil.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\iepeers.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\ieakui.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\ieaksie.dll
2016-03-16 14:38:25 ----A---- C:\Windows\system32\admparse.dll
2016-03-16 13:19:33 ----A---- C:\Windows\system32\msi.dll
2016-03-16 13:19:32 ----A---- C:\Windows\system32\msimsg.dll
2016-03-16 13:19:32 ----A---- C:\Windows\system32\msihnd.dll
2016-03-16 13:19:32 ----A---- C:\Windows\system32\consent.exe
2016-03-16 13:19:32 ----A---- C:\Windows\system32\authui.dll
2016-03-16 13:19:32 ----A---- C:\Windows\system32\appinfo.dll
2016-03-16 13:19:29 ----A---- C:\Windows\system32\rpcss.dll
2016-03-16 13:19:29 ----A---- C:\Windows\system32\drivers\disk.sys
2016-03-16 13:19:09 ----A---- C:\Windows\system32\fveapi.dll
2016-03-16 13:19:08 ----A---- C:\Windows\system32\tbs.dll
2016-03-16 13:19:08 ----A---- C:\Windows\system32\fveapibase.dll
2016-03-16 12:25:43 ----A---- C:\Windows\system32\drivers\SABI.sys
2016-03-16 12:25:35 ----D---- C:\Program Files\Samsung
2016-03-15 20:36:30 ----D---- C:\Program Files\AMD
2016-03-15 19:01:30 ----D---- C:\Windows\Minidump
2016-03-13 18:31:52 ----D---- C:\Users\Natali\AppData\Roaming\ATI
2016-03-13 18:26:30 ----D---- C:\Program Files\ATI
2016-03-11 14:56:22 ----D---- C:\ProgramData\SAMSUNG
2016-03-11 14:55:16 ----A---- C:\Windows\system32\drivers\KMDFMEMIO.sys
2016-03-10 18:55:45 ----D---- C:\Users\Natali\AppData\Roaming\Skype
2016-03-10 18:55:19 ----D---- C:\Program Files\Common Files\Skype
2016-03-10 18:55:18 ----RD---- C:\Program Files\Skype
2016-03-10 18:54:59 ----D---- C:\ProgramData\Skype
2016-03-10 18:44:56 ----D---- C:\Program Files\Microsoft Silverlight
2016-03-10 16:22:39 ----D---- C:\Users\Natali\AppData\Roaming\PDAppFlex
2016-03-10 16:13:30 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2016-03-10 14:19:36 ----D---- C:\ProgramData\boost_interprocess
2016-03-10 14:17:42 ----D---- C:\Users\Natali\AppData\Roaming\Adobe
2016-03-10 14:12:00 ----D---- C:\ProgramData\Adobe
2016-03-10 14:11:26 ----D---- C:\Program Files\Adobe
2016-03-10 14:11:25 ----D---- C:\Program Files\Common Files\Adobe
2016-03-10 11:31:00 ----HD---- C:\$Windows.~WS
2016-03-09 13:01:58 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2016-03-09 13:01:56 ----A---- C:\Windows\system32\seclogon.dll
2016-03-09 13:01:39 ----A---- C:\Windows\system32\win32k.sys
2016-03-09 13:01:38 ----A---- C:\Windows\system32\mfds.dll
2016-03-09 13:01:32 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-03-09 13:01:32 ----A---- C:\Windows\system32\ntkrnlpa.exe
2016-03-09 13:01:31 ----A---- C:\Windows\system32\schannel.dll
2016-03-09 13:01:31 ----A---- C:\Windows\system32\msv1_0.dll
2016-03-09 13:01:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-03-09 13:01:31 ----A---- C:\Windows\system32\kerberos.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\wdigest.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\TSpkg.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\srcore.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\rpcrt4.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\ntdll.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\ncrypt.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-03-09 13:01:30 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-03-09 13:01:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-03-09 13:01:30 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-03-09 13:01:30 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-03-09 13:01:30 ----A---- C:\Windows\system32\csrsrv.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\advapi32.dll
2016-03-09 13:01:30 ----A---- C:\Windows\system32\adtschema.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\sspicli.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\srclient.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\smss.exe
2016-03-09 13:01:29 ----A---- C:\Windows\system32\secur32.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\rstrui.exe
2016-03-09 13:01:29 ----A---- C:\Windows\system32\msaudite.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\lsass.exe
2016-03-09 13:01:29 ----A---- C:\Windows\system32\cryptbase.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\credssp.dll
2016-03-09 13:01:29 ----A---- C:\Windows\system32\auditpol.exe
2016-03-09 13:01:28 ----A---- C:\Windows\system32\sspisrv.dll
2016-03-09 13:01:28 ----A---- C:\Windows\system32\msobjs.dll
2016-03-09 13:01:28 ----A---- C:\Windows\system32\apisetschema.dll
2016-03-09 13:01:10 ----A---- C:\Windows\system32\olepro32.dll
2016-03-09 13:01:10 ----A---- C:\Windows\system32\oleaut32.dll
2016-03-09 13:01:10 ----A---- C:\Windows\system32\asycfilt.dll
2016-03-09 13:01:07 ----A---- C:\Windows\system32\lpk.dll
2016-03-09 13:01:07 ----A---- C:\Windows\system32\fontsub.dll
2016-03-09 13:01:07 ----A---- C:\Windows\system32\dciman32.dll
2016-03-09 13:01:07 ----A---- C:\Windows\system32\atmlib.dll
2016-03-09 13:01:07 ----A---- C:\Windows\system32\atmfd.dll
2016-03-09 13:01:05 ----A---- C:\Windows\system32\wmp.dll
2016-03-09 13:01:04 ----A---- C:\Windows\system32\wmploc.DLL
2016-03-09 13:01:04 ----A---- C:\Windows\system32\spwmp.dll
2016-03-09 13:01:04 ----A---- C:\Windows\system32\dxmasf.dll
2016-03-09 11:40:49 ----D---- C:\$WINDOWS.~BT
2016-03-09 10:45:04 ----SD---- C:\Windows\system32\CompatTel
2016-03-09 10:45:04 ----D---- C:\Windows\system32\appraiser
2016-03-07 23:37:43 ----A---- C:\Windows\system32\aitstatic.exe
2016-03-07 23:37:34 ----A---- C:\Windows\system32\spoolsv.exe
2016-03-07 23:37:30 ----A---- C:\Windows\system32\rdpudd.dll
2016-03-07 23:37:30 ----A---- C:\Windows\system32\rdpcorets.dll
2016-03-07 23:37:29 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2016-03-07 23:37:12 ----A---- C:\Windows\system32\fsutil.exe
2016-03-07 23:37:12 ----A---- C:\Windows\system32\esent.dll
2016-03-07 23:37:12 ----A---- C:\Windows\system32\drivers\nvstor.sys
2016-03-07 23:37:12 ----A---- C:\Windows\system32\drivers\nvraid.sys
2016-03-07 23:37:12 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2016-03-07 23:37:12 ----A---- C:\Windows\system32\drivers\amdxata.sys
2016-03-07 23:37:12 ----A---- C:\Windows\system32\drivers\amdsata.sys
2016-03-07 23:36:33 ----A---- C:\Windows\system32\TSWbPrxy.exe
2016-03-07 23:36:26 ----A---- C:\Windows\system32\mstscax.dll
2016-03-07 23:36:25 ----A---- C:\Windows\system32\wksprt.exe
2016-03-07 23:36:25 ----A---- C:\Windows\system32\tsgqec.dll
2016-03-07 23:36:25 ----A---- C:\Windows\system32\rdvidcrl.dll
2016-03-07 23:35:52 ----A---- C:\Windows\system32\KBDYAK.DLL
2016-03-07 23:35:52 ----A---- C:\Windows\system32\KBDTAT.DLL
2016-03-07 23:35:52 ----A---- C:\Windows\system32\KBDRU1.DLL
2016-03-07 23:35:52 ----A---- C:\Windows\system32\KBDRU.DLL
2016-03-07 23:35:52 ----A---- C:\Windows\system32\KBDBASH.DLL
2016-03-07 16:08:12 ----D---- C:\Program Files\Common Files\DESIGNER
2016-03-07 16:07:27 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2016-03-07 16:06:55 ----D---- C:\Windows\PCHEALTH
2016-03-07 16:06:54 ----D---- C:\Program Files\Microsoft SQL Server
2016-03-07 16:01:45 ----D---- C:\Program Files\Microsoft Analysis Services
2016-03-07 16:01:18 ----D---- C:\Program Files\Microsoft Office
2016-03-07 16:01:16 ----D---- C:\ProgramData\Microsoft Help
2016-03-07 12:06:00 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2016-03-07 12:05:57 ----A---- C:\Windows\system32\rdpendp_winip.dll
2016-03-07 11:59:26 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2016-03-07 11:59:25 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2016-03-07 11:59:24 ----A---- C:\Windows\system32\wksprtPS.dll
2016-03-07 11:59:24 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2016-03-07 11:59:24 ----A---- C:\Windows\system32\mstsc.exe
2016-03-07 11:59:24 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2016-03-07 11:59:24 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2016-03-07 11:57:08 ----A---- C:\Windows\system32\nlsbres.dll
2016-03-07 11:57:08 ----A---- C:\Windows\system32\kbdgeoqw.dll
2016-03-07 11:57:08 ----A---- C:\Windows\system32\KBDAZEL.DLL
2016-03-07 11:57:08 ----A---- C:\Windows\system32\KBDAZE.DLL
2016-03-07 11:56:55 ----A---- C:\Windows\system32\icaapi.dll
2016-03-07 11:56:55 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wuwebv.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wups2.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wups.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wudriver.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wucltux.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wuaueng.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wuauclt.exe
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wuapp.exe
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wuapi.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2016-03-07 11:56:47 ----A---- C:\Windows\system32\WinSetupUI.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\ucrtbase.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-03-07 11:56:19 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-03-07 11:54:48 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-03-07 11:02:51 ----D---- C:\Windows\system32\MRT
2016-03-07 11:02:45 ----A---- C:\Windows\system32\MRT.exe
2016-03-07 10:00:10 ----D---- C:\Windows\CheckSur
2016-03-07 09:33:45 ----SD---- C:\Windows\system32\GWX
2016-03-06 23:56:29 ----A---- C:\Windows\system32\WUDFSvc.dll
2016-03-06 23:56:29 ----A---- C:\Windows\system32\WUDFPlatform.dll
2016-03-06 23:56:29 ----A---- C:\Windows\system32\WUDFHost.exe
2016-03-06 23:56:29 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2016-03-06 23:56:29 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2016-03-06 23:56:29 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2016-03-06 23:56:28 ----A---- C:\Windows\system32\WUDFx.dll
2016-03-06 23:54:41 ----A---- C:\Windows\system32\infocardapi.dll
2016-03-06 23:54:39 ----A---- C:\Windows\system32\icardres.dll
2016-03-06 23:54:29 ----A---- C:\Windows\system32\icardagt.exe
2016-03-06 23:54:27 ----A---- C:\Windows\system32\TsWpfWrp.exe
2016-03-06 23:53:26 ----A---- C:\Windows\system32\wmi.dll
2016-03-06 23:53:26 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2016-03-06 23:42:22 ----D---- C:\Windows\Migration
2016-03-06 23:06:11 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-03-06 22:39:00 ----A---- C:\Windows\system32\wdi.dll
2016-03-06 22:39:00 ----A---- C:\Windows\system32\powertracker.dll
2016-03-06 22:39:00 ----A---- C:\Windows\system32\perftrack.dll
2016-03-06 22:34:51 ----A---- C:\Windows\system32\FntCache.dll
2016-03-06 22:34:51 ----A---- C:\Windows\system32\DWrite.dll
2016-03-06 22:34:50 ----A---- C:\Windows\system32\user32.dll
2016-03-06 22:34:47 ----A---- C:\Windows\system32\WindowsCodecs.dll
2016-03-06 22:34:45 ----A---- C:\Windows\system32\drivers\hidparse.sys
2016-03-06 22:34:45 ----A---- C:\Windows\system32\drivers\hidclass.sys
2016-03-06 22:34:42 ----A---- C:\Windows\system32\mswsock.dll
2016-03-06 22:34:36 ----A---- C:\Windows\system32\wpdshext.dll
2016-03-06 22:34:33 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2016-03-06 22:34:30 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2016-03-06 22:34:30 ----A---- C:\Windows\system32\credui.dll
2016-03-06 22:33:54 ----A---- C:\Windows\system32\drivers\srvnet.sys
2016-03-06 22:33:54 ----A---- C:\Windows\system32\drivers\srv2.sys
2016-03-06 22:33:54 ----A---- C:\Windows\system32\drivers\srv.sys
2016-03-06 22:33:42 ----A---- C:\Windows\system32\ole32.dll
2016-03-06 22:33:26 ----A---- C:\Windows\system32\drivers\usb8023.sys
2016-03-06 22:32:51 ----A---- C:\Windows\system32\comsvcs.dll
2016-03-06 22:32:50 ----A---- C:\Windows\system32\catsrvut.dll
2016-03-06 22:32:26 ----A---- C:\Windows\system32\WebClnt.dll
2016-03-06 22:32:26 ----A---- C:\Windows\system32\davclnt.dll
2016-03-06 22:32:23 ----A---- C:\Windows\system32\xmllite.dll
2016-03-06 22:32:21 ----A---- C:\Windows\system32\dpnet.dll
2016-03-06 22:32:19 ----A---- C:\Windows\system32\prevhost.exe
2016-03-06 22:32:18 ----A---- C:\Windows\system32\notepad.exe
2016-03-06 22:32:18 ----A---- C:\Windows\notepad.exe
2016-03-06 22:32:16 ----A---- C:\Windows\system32\msieftp.dll
2016-03-06 22:32:08 ----A---- C:\Windows\system32\shell32.dll
2016-03-06 22:32:06 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-03-06 22:32:06 ----A---- C:\Windows\explorer.exe
2016-03-06 22:31:23 ----A---- C:\Windows\system32\jnwmon.dll
2016-03-06 22:31:23 ----A---- C:\Windows\system32\InkEd.dll
2016-03-06 22:31:18 ----A---- C:\Windows\system32\msxml6r.dll
2016-03-06 22:31:18 ----A---- C:\Windows\system32\msxml6.dll
2016-03-06 22:31:18 ----A---- C:\Windows\system32\msxml3r.dll
2016-03-06 22:31:18 ----A---- C:\Windows\system32\msxml3.dll
2016-03-06 22:31:13 ----A---- C:\Windows\system32\drivers\fvevol.sys
2016-03-06 22:31:12 ----A---- C:\Windows\system32\schedsvc.dll
2016-03-06 22:31:03 ----A---- C:\Windows\system32\pku2u.dll
2016-03-06 22:30:53 ----A---- C:\Windows\system32\msiexec.exe
2016-03-06 22:30:46 ----A---- C:\Windows\system32\dnsrslvr.dll
2016-03-06 22:30:46 ----A---- C:\Windows\system32\dnscacheugc.exe
2016-03-06 22:30:46 ----A---- C:\Windows\system32\dnsapi.dll
2016-03-06 22:30:14 ----A---- C:\Windows\system32\imagehlp.dll
2016-03-06 22:30:13 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-03-06 22:30:13 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-03-06 22:30:13 ----A---- C:\Windows\system32\cdd.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\wincredprovider.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\objsel.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\dpapiprovider.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\dimsroam.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\cngprovider.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\capiprovider.dll
2016-03-06 22:30:03 ----A---- C:\Windows\system32\adprovider.dll
2016-03-06 22:29:44 ----A---- C:\Windows\system32\IMJP10K.DLL
2016-03-06 22:29:42 ----A---- C:\Windows\system32\wscript.exe
2016-03-06 22:29:42 ----A---- C:\Windows\system32\scrrun.dll
2016-03-06 22:29:42 ----A---- C:\Windows\system32\cscript.exe
2016-03-06 22:29:40 ----A---- C:\Windows\system32\shimeng.dll
2016-03-06 22:29:40 ----A---- C:\Windows\system32\sdbinst.exe
2016-03-06 22:29:40 ----A---- C:\Windows\system32\apphelp.dll
2016-03-06 22:29:40 ----A---- C:\Windows\system32\aelupsvc.dll
2016-03-06 22:29:38 ----A---- C:\Windows\system32\OxpsConverter.exe
2016-03-06 22:29:24 ----A---- C:\Windows\system32\sysmain.dll
2016-03-06 22:29:24 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2016-03-06 22:29:23 ----A---- C:\Windows\system32\msmmsp.dll
2016-03-06 22:29:05 ----A---- C:\Windows\system32\psisdecd.dll
2016-03-06 22:28:36 ----A---- C:\Windows\system32\tzres.dll
2016-03-06 22:28:29 ----A---- C:\Windows\system32\umpnpmgr.dll
2016-03-06 22:28:27 ----A---- C:\Windows\system32\drivers\tdx.sys
2016-03-06 22:28:27 ----A---- C:\Windows\system32\drivers\afd.sys
2016-03-06 22:28:22 ----A---- C:\Windows\system32\cryptdlg.dll
2016-03-06 22:28:14 ----A---- C:\Windows\system32\oleacc.dll
2016-03-06 22:28:05 ----A---- C:\Windows\system32\rastls.dll
2016-03-06 22:27:40 ----A---- C:\Windows\system32\drivers\ndis.sys
2016-03-06 22:27:32 ----A---- C:\Windows\system32\wwansvc.dll
2016-03-06 22:27:32 ----A---- C:\Windows\system32\wwanprotdim.dll
2016-03-06 22:27:28 ----A---- C:\Windows\system32\els.dll
2016-03-06 22:27:26 ----A---- C:\Windows\system32\drivers\stream.sys
2016-03-06 22:27:25 ----A---- C:\Windows\system32\clfsw32.dll
2016-03-06 22:27:25 ----A---- C:\Windows\system32\clfs.sys
2016-03-06 22:27:24 ----A---- C:\Windows\system32\win32spl.dll
2016-03-06 22:27:22 ----A---- C:\Windows\system32\inetcomm.dll
2016-03-06 22:27:21 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-03-06 22:27:19 ----A---- C:\Windows\system32\scavengeui.dll
2016-03-06 22:27:13 ----A---- C:\Windows\system32\certutil.exe
2016-03-06 22:27:13 ----A---- C:\Windows\system32\certenc.dll
2016-03-06 22:26:51 ----A---- C:\Windows\system32\msctf.dll
2016-03-06 22:26:48 ----A---- C:\Windows\system32\iologmsg.dll
2016-03-06 22:26:48 ----A---- C:\Windows\system32\drivers\storport.sys
2016-03-06 22:26:48 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2016-03-06 22:26:48 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2016-03-06 22:26:42 ----A---- C:\Windows\system32\netevent.dll
2016-03-06 22:26:42 ----A---- C:\Windows\system32\netcorehc.dll
2016-03-06 22:26:42 ----A---- C:\Windows\system32\iphlpsvc.dll
2016-03-06 22:26:42 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2016-03-06 22:26:27 ----A---- C:\Windows\system32\UtcResources.dll
2016-03-06 22:26:27 ----A---- C:\Windows\system32\diagtrack.dll
2016-03-06 22:26:26 ----A---- C:\Windows\system32\tdh.dll
2016-03-06 22:25:44 ----A---- C:\Windows\system32\tquery.dll
2016-03-06 22:25:44 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2016-03-06 22:25:44 ----A---- C:\Windows\system32\SearchIndexer.exe
2016-03-06 22:25:44 ----A---- C:\Windows\system32\mssvp.dll
2016-03-06 22:25:44 ----A---- C:\Windows\system32\mssrch.dll
2016-03-06 22:25:44 ----A---- C:\Windows\system32\mssph.dll
2016-03-06 22:25:43 ----A---- C:\Windows\system32\SearchFilterHost.exe
2016-03-06 22:25:43 ----A---- C:\Windows\system32\mssphtb.dll
2016-03-06 22:25:43 ----A---- C:\Windows\system32\msscntrs.dll
2016-03-06 22:25:42 ----A---- C:\Windows\system32\dwmcore.dll
2016-03-06 22:25:41 ----A---- C:\Windows\system32\dwmapi.dll
2016-03-06 22:25:40 ----A---- C:\Windows\system32\cdosys.dll
2016-03-06 22:25:32 ----A---- C:\Windows\system32\FXSCOVER.exe
2016-03-06 22:25:26 ----A---- C:\Windows\system32\osk.exe
2016-03-06 22:25:22 ----A---- C:\Windows\system32\d3d10warp.dll
2016-03-06 22:25:20 ----A---- C:\Windows\system32\netapi32.dll
2016-03-06 22:25:20 ----A---- C:\Windows\system32\browser.dll
2016-03-06 22:25:20 ----A---- C:\Windows\system32\browcli.dll
2016-03-06 22:25:00 ----A---- C:\Windows\system32\tracerpt.exe
2016-03-06 22:24:59 ----A---- C:\Windows\system32\typeperf.exe
2016-03-06 22:24:59 ----A---- C:\Windows\system32\sechost.dll
2016-03-06 22:24:59 ----A---- C:\Windows\system32\relog.exe
2016-03-06 22:24:59 ----A---- C:\Windows\system32\logman.exe
2016-03-06 22:24:59 ----A---- C:\Windows\system32\diskperf.exe
2016-03-06 22:24:34 ----A---- C:\Windows\system32\EncDec.dll
2016-03-06 22:24:34 ----A---- C:\Windows\system32\CPFilters.dll
2016-03-06 22:24:33 ----A---- C:\Windows\system32\KernelBase.dll
2016-03-06 22:24:33 ----A---- C:\Windows\system32\kernel32.dll
2016-03-06 22:24:32 ----A---- C:\Windows\system32\mtxoci.dll
2016-03-06 22:24:32 ----A---- C:\Windows\system32\msorcl32.dll
2016-03-06 22:24:32 ----A---- C:\Windows\system32\drivers\cng.sys
2016-03-06 22:24:32 ----A---- C:\Windows\system32\bcryptprimitives.dll
2016-03-06 22:24:31 ----A---- C:\Windows\system32\winsrv.dll
2016-03-06 22:24:30 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-03-06 22:24:30 ----A---- C:\Windows\system32\conhost.exe
2016-03-06 22:24:29 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-03-06 22:24:29 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-03-06 22:24:28 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-03-06 22:24:27 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-03-06 22:24:09 ----A---- C:\Windows\system32\certcli.dll
2016-03-06 22:24:01 ----A---- C:\Windows\system32\sbe.dll
2016-03-06 22:23:58 ----A---- C:\Windows\system32\wintrust.dll
2016-03-06 22:23:58 ----A---- C:\Windows\system32\cryptsvc.dll
2016-03-06 22:23:58 ----A---- C:\Windows\system32\cryptnet.dll
2016-03-06 22:23:58 ----A---- C:\Windows\system32\crypt32.dll
2016-03-06 22:23:51 ----A---- C:\Windows\system32\usp10.dll
2016-03-06 22:23:42 ----A---- C:\Windows\system32\services.exe
2016-03-06 22:23:23 ----A---- C:\Windows\system32\gdi32.dll
2016-03-06 22:23:22 ----A---- C:\Windows\system32\TSWorkspace.dll
2016-03-06 22:23:15 ----A---- C:\Windows\system32\drivers\tcpip.sys
2016-03-06 22:23:15 ----A---- C:\Windows\system32\drivers\netio.sys
2016-03-06 22:23:15 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2016-03-06 22:23:08 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-03-06 22:23:08 ----A---- C:\Windows\system32\drivers\appid.sys
2016-03-06 22:23:08 ----A---- C:\Windows\system32\appidsvc.dll
2016-03-06 22:23:08 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-03-06 22:23:08 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-03-06 22:23:08 ----A---- C:\Windows\system32\appidapi.dll
2016-03-06 22:22:57 ----A---- C:\Windows\system32\qedit.dll
2016-03-06 22:22:40 ----A---- C:\Windows\system32\mscories.dll
2016-03-06 22:22:40 ----A---- C:\Windows\system32\mscorier.dll
2016-03-06 22:22:40 ----A---- C:\Windows\system32\dfshim.dll
2016-03-06 22:22:34 ----A---- C:\Windows\system32\Wpc.dll
2016-03-06 22:22:34 ----A---- C:\Windows\system32\gameux.dll
2016-03-06 22:21:56 ----A---- C:\Windows\system32\packager.dll
2016-03-06 22:21:51 ----A---- C:\Windows\system32\profsvc.dll
2016-03-06 22:21:49 ----A---- C:\Windows\system32\webio.dll
2016-03-06 22:21:45 ----A---- C:\Windows\system32\odbctrac.dll
2016-03-06 22:21:45 ----A---- C:\Windows\system32\odbcjt32.dll
2016-03-06 22:21:45 ----A---- C:\Windows\system32\odbccu32.dll
2016-03-06 22:21:45 ----A---- C:\Windows\system32\odbccr32.dll
2016-03-06 22:21:45 ----A---- C:\Windows\system32\odbccp32.dll
2016-03-06 22:21:43 ----A---- C:\Windows\system32\wshrm.dll
2016-03-06 22:21:43 ----A---- C:\Windows\system32\drivers\rmcast.sys
2016-03-06 22:21:40 ----A---- C:\Windows\system32\msvcrt.dll
2016-03-06 22:21:26 ----A---- C:\Windows\system32\drivers\partmgr.sys
2016-03-06 22:21:25 ----A---- C:\Windows\system32\synceng.dll
2016-03-06 22:21:24 ----A---- C:\Windows\system32\ubpm.dll
2016-03-06 22:21:20 ----A---- C:\Windows\system32\shdocvw.dll
2016-03-06 22:21:14 ----A---- C:\Windows\system32\drivers\ataport.sys
2016-03-06 22:21:11 ----A---- C:\Windows\system32\charmap.exe
2016-03-06 22:21:09 ----A---- C:\Windows\system32\nshwfp.dll
2016-03-06 22:21:09 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-03-06 22:21:09 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2016-03-06 22:21:07 ----A---- C:\Windows\system32\poqexec.exe
2016-03-06 22:21:06 ----A---- C:\Windows\system32\mapistub.dll
2016-03-06 22:21:06 ----A---- C:\Windows\system32\mapi32.dll
2016-03-06 22:21:06 ----A---- C:\Windows\system32\fixmapi.exe
2016-03-06 22:21:04 ----A---- C:\Windows\system32\localspl.dll
2016-03-06 22:21:03 ----A---- C:\Windows\system32\ntshrui.dll
2016-03-06 22:20:56 ----A---- C:\Windows\system32\winlogon.exe
2016-03-06 22:20:55 ----A---- C:\Windows\system32\winsta.dll
2016-03-06 22:20:55 ----A---- C:\Windows\system32\rdrmemptylst.exe
2016-03-06 22:20:55 ----A---- C:\Windows\system32\rdpwsx.dll
2016-03-06 22:20:55 ----A---- C:\Windows\system32\rdpcorekmts.dll
2016-03-06 22:20:55 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2016-03-06 22:20:43 ----A---- C:\Windows\system32\taskhost.exe
2016-03-06 22:20:30 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2016-03-06 22:20:30 ----A---- C:\Windows\system32\dhcpcore6.dll
2016-03-06 22:19:52 ----A---- C:\Windows\system32\basesrv.dll
2016-03-06 22:19:35 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2016-03-06 22:19:35 ----A---- C:\Windows\system32\drivers\usbcir.sys
2016-03-06 22:19:30 ----A---- C:\Windows\system32\drivers\http.sys
2016-03-06 22:19:21 ----A---- C:\Windows\system32\wer.dll
2016-03-06 22:19:19 ----A---- C:\Windows\system32\mfc42u.dll
2016-03-06 22:19:19 ----A---- C:\Windows\system32\mfc42.dll
2016-03-06 22:19:16 ----A---- C:\Windows\system32\nlasvc.dll
2016-03-06 22:19:16 ----A---- C:\Windows\system32\nlaapi.dll
2016-03-06 22:19:16 ----A---- C:\Windows\system32\ncsi.dll
2016-03-06 22:19:12 ----A---- C:\Windows\system32\cewmdm.dll
2016-03-06 22:19:10 ----A---- C:\Windows\system32\drivers\bowser.sys
2016-03-06 22:19:03 ----A---- C:\Windows\system32\WMVDECOD.DLL
2016-03-06 22:19:02 ----A---- C:\Windows\system32\msmpeg2adec.dll
2016-03-06 22:19:02 ----A---- C:\Windows\system32\mf.dll
2016-03-06 22:19:01 ----A---- C:\Windows\system32\WMVSDECD.DLL
2016-03-06 22:19:01 ----A---- C:\Windows\system32\WMVENCOD.DLL
2016-03-06 22:19:01 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2016-03-06 22:19:01 ----A---- C:\Windows\system32\wmpmde.dll
2016-03-06 22:19:01 ----A---- C:\Windows\system32\WMADMOE.DLL
2016-03-06 22:19:01 ----A---- C:\Windows\system32\WMADMOD.DLL
2016-03-06 22:19:01 ----A---- C:\Windows\system32\quartz.dll
2016-03-06 22:19:01 ----A---- C:\Windows\system32\qdvd.dll
2016-03-06 22:19:01 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2016-03-06 22:19:01 ----A---- C:\Windows\system32\mcmde.dll
2016-03-06 22:19:01 ----A---- C:\Windows\system32\evr.dll
2016-03-06 22:19:01 ----A---- C:\Windows\system32\COLORCNV.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\WMVXENCD.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\WMVSENCD.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\qasf.dll
2016-03-06 22:19:00 ----A---- C:\Windows\system32\MPG4DECD.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\MP43DECD.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2016-03-06 22:19:00 ----A---- C:\Windows\system32\mfplat.dll
2016-03-06 22:19:00 ----A---- C:\Windows\system32\devenum.dll
2016-03-06 22:18:59 ----A---- C:\Windows\system32\VIDRESZR.DLL
2016-03-06 22:18:59 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2016-03-06 22:18:59 ----A---- C:\Windows\system32\MP4SDECD.DLL
2016-03-06 22:18:59 ----A---- C:\Windows\system32\MP3DMOD.DLL
2016-03-06 22:18:59 ----A---- C:\Windows\system32\mfvdsp.dll
2016-03-06 22:18:58 ----A---- C:\Windows\system32\rrinstaller.exe
2016-03-06 22:18:58 ----A---- C:\Windows\system32\mfps.dll
2016-03-06 22:18:58 ----A---- C:\Windows\system32\mfpmp.exe
2016-03-06 22:18:58 ----A---- C:\Windows\system32\mferror.dll
2016-03-06 22:18:58 ----A---- C:\Windows\system32\ksuser.dll
2016-03-06 22:18:49 ----A---- C:\Windows\system32\Wdfres.dll
2016-03-06 22:18:49 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2016-03-06 22:18:49 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2016-03-06 22:18:46 ----A---- C:\Windows\system32\WMPhoto.dll
2016-03-06 22:18:31 ----A---- C:\Windows\system32\blackbox.dll
2016-03-06 22:18:30 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2016-03-06 22:18:30 ----A---- C:\Windows\system32\drmv2clt.dll
2016-03-06 22:18:29 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-03-06 22:18:25 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-03-06 22:18:23 ----A---- C:\Windows\system32\ci.dll
2016-03-06 22:18:23 ----A---- C:\Windows\system32\AUDIOKSE.dll
2016-03-06 22:18:22 ----A---- C:\Windows\system32\winload.exe
2016-03-06 22:18:22 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2016-03-06 22:18:21 ----A---- C:\Windows\system32\winresume.exe
2016-03-06 22:18:21 ----A---- C:\Windows\system32\audiosrv.dll
2016-03-06 22:18:20 ----A---- C:\Windows\system32\cryptui.dll
2016-03-06 22:18:19 ----A---- C:\Windows\system32\pcasvc.dll
2016-03-06 22:18:19 ----A---- C:\Windows\system32\AudioEng.dll
2016-03-06 22:18:18 ----A---- C:\Windows\system32\EncDump.dll
2016-03-06 22:18:18 ----A---- C:\Windows\system32\cryptsp.dll
2016-03-06 22:18:18 ----A---- C:\Windows\system32\AudioSes.dll
2016-03-06 22:18:16 ----A---- C:\Windows\system32\msscp.dll
2016-03-06 22:18:15 ----A---- C:\Windows\system32\msnetobj.dll
2016-03-06 22:18:15 ----A---- C:\Windows\system32\audiodg.exe
2016-03-06 22:18:13 ----A---- C:\Windows\system32\pcadm.dll
2016-03-06 22:18:10 ----A---- C:\Windows\system32\pcawrk.exe
2016-03-06 22:18:10 ----A---- C:\Windows\system32\pcalua.exe
2016-03-06 22:18:09 ----A---- C:\Windows\system32\pcaevts.dll
2016-03-06 22:17:31 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2016-03-06 22:17:31 ----A---- C:\Windows\system32\secproc_ssp.dll
2016-03-06 22:17:31 ----A---- C:\Windows\system32\secproc_isv.dll
2016-03-06 22:17:31 ----A---- C:\Windows\system32\secproc.dll
2016-03-06 22:17:31 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2016-03-06 22:17:31 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2016-03-06 22:17:31 ----A---- C:\Windows\system32\RMActivate_isv.exe
2016-03-06 22:17:31 ----A---- C:\Windows\system32\RMActivate.exe
2016-03-06 22:17:31 ----A---- C:\Windows\system32\msdrm.dll
2016-03-06 22:17:03 ----A---- C:\Windows\system32\scesrv.dll
2016-03-06 22:17:02 ----A---- C:\Windows\system32\comctl32.dll
2016-03-06 22:16:56 ----A---- C:\Windows\system32\termsrv.dll
2016-03-06 21:47:23 ----A---- C:\Windows\system32\WsmSvc.dll
2016-03-06 21:47:22 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-03-06 21:47:22 ----A---- C:\Windows\system32\WsmAuto.dll
2016-03-06 21:47:22 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2016-03-06 21:47:22 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2016-03-06 21:38:35 ----A---- C:\Windows\system32\rdpcore.dll
2016-03-06 21:38:35 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2016-03-06 17:30:54 ----D---- C:\Windows\system32\SRSLabs
2016-03-06 17:30:50 ----D---- C:\Windows\system32\RTCOM
2016-03-06 17:29:54 ----A---- C:\Windows\system32\WavesLib.dll
2016-03-06 17:29:53 ----A---- C:\Windows\system32\SRSWOW.dll
2016-03-06 17:29:52 ----A---- C:\Windows\system32\SRSTSXT.dll
2016-03-06 17:29:52 ----A---- C:\Windows\system32\SRSTSHD.dll
2016-03-06 17:29:52 ----A---- C:\Windows\system32\SRSHP360.dll
2016-03-06 17:29:48 ----A---- C:\Windows\system32\SFSS_APO.dll
2016-03-06 17:29:48 ----A---- C:\Windows\system32\SFNHK.dll
2016-03-06 17:29:47 ----A---- C:\Windows\system32\SFCOM.dll
2016-03-06 17:29:47 ----A---- C:\Windows\system32\SFAPO.dll
2016-03-06 17:29:45 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2016-03-06 17:29:44 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2016-03-06 17:29:43 ----A---- C:\Windows\system32\RtkPgExt.dll
2016-03-06 17:29:40 ----A---- C:\Windows\system32\RtkCoLDR.dll
2016-03-06 17:29:40 ----A---- C:\Windows\system32\RtkCoInstII.dll
2016-03-06 17:29:38 ----A---- C:\Windows\system32\RtkApoApi.dll
2016-03-06 17:29:34 ----A---- C:\Windows\system32\RTEEP32A.dll
2016-03-06 17:29:34 ----A---- C:\Windows\system32\RTEEL32A.dll
2016-03-06 17:29:34 ----A---- C:\Windows\system32\RTEEG32A.dll
2016-03-06 17:29:34 ----A---- C:\Windows\system32\RTEED32A.dll
2016-03-06 17:29:30 ----A---- C:\Windows\system32\RP3DHT32.dll
2016-03-06 17:29:30 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2016-03-06 17:29:28 ----A---- C:\Windows\system32\RP3DAA32.dll
2016-03-06 17:29:26 ----A---- C:\Windows\system32\RltkAPO.dll
2016-03-06 17:29:16 ----A---- C:\Windows\system32\RCoRes.dat
2016-03-06 17:29:09 ----A---- C:\Windows\system32\R4EEP32A.dll
2016-03-06 17:29:09 ----A---- C:\Windows\system32\R4EEL32A.dll
2016-03-06 17:29:08 ----A---- C:\Windows\system32\R4EEG32A.dll
2016-03-06 17:29:08 ----A---- C:\Windows\system32\R4EED32A.dll
2016-03-06 17:29:08 ----A---- C:\Windows\system32\R4EEA32A.dll
2016-03-06 17:29:04 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-03-06 17:28:57 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2016-03-06 17:28:55 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2016-03-06 17:28:55 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-03-06 17:28:54 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2016-03-06 17:28:54 ----A---- C:\Windows\system32\KAAPORT.dll
2016-03-06 17:28:43 ----A---- C:\Windows\system32\FMAPO.dll
2016-03-06 17:28:43 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll
2016-03-06 17:28:42 ----A---- C:\Windows\system32\DTSSymmetryDLL.dll
2016-03-06 17:28:42 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll
2016-03-06 17:28:42 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll
2016-03-06 17:28:42 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSLimiterDLL.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSLFXAPO.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSGFXAPONS.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSGFXAPO.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSBoostDLL.dll
2016-03-06 17:28:41 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll
2016-03-06 17:28:37 ----A---- C:\Windows\system32\DDPP32A.dll
2016-03-06 17:28:37 ----A---- C:\Windows\system32\DDPO32A.dll
2016-03-06 17:28:37 ----A---- C:\Windows\system32\DDPD32A.dll
2016-03-06 17:28:37 ----A---- C:\Windows\system32\DDPA32.dll
2016-03-06 17:28:34 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-03-06 17:28:31 ----A---- C:\Windows\system32\AERTARen.dll
2016-03-06 17:28:30 ----D---- C:\Program Files\Realtek
2016-03-06 17:28:30 ----A---- C:\Windows\system32\AERTACap.dll
2016-03-06 17:27:43 ----HD---- C:\Program Files\Temp
2016-03-06 17:27:39 ----A---- C:\Windows\RtlExUpd.dll
2016-03-06 15:32:39 ----D---- C:\Users\Natali\AppData\Roaming\GHISLER
2016-03-06 15:32:39 ----A---- C:\Windows\UC.PIF
2016-03-06 15:32:39 ----A---- C:\Windows\RAR.PIF
2016-03-06 15:32:39 ----A---- C:\Windows\PKZIP.PIF
2016-03-06 15:32:39 ----A---- C:\Windows\PKUNZIP.PIF
2016-03-06 15:32:39 ----A---- C:\Windows\LHA.PIF
2016-03-06 15:32:39 ----A---- C:\Windows\ARJ.PIF
2016-03-06 15:11:06 ----D---- C:\ProgramData\Kaspersky Lab
2016-03-06 15:11:01 ----A---- C:\ProgramData\ntuser.dat
2016-03-06 14:18:44 ----D---- C:\Users\Natali\AppData\Roaming\library_dir
2016-03-06 14:18:34 ----D---- C:\Program Files\Raptr Inc
2016-03-06 14:07:00 ----D---- C:\ProgramData\Package Cache
2016-03-05 19:41:00 ----D---- C:\ProgramData\Qualcomm Atheros
2016-03-05 17:43:11 ----A---- C:\Windows\system32\drivers\tap0901.sys
2016-03-05 17:39:56 ----D---- C:\Program Files\Microsoft.NET
2016-03-05 17:11:12 ----D---- C:\Users\Natali\AppData\Roaming\uTorrent
2016-03-05 16:57:40 ----N---- C:\Windows\system32\MpSigStub.exe
2016-03-05 16:56:11 ----D---- C:\ProgramData\AMD
2016-03-05 16:56:05 ----A---- C:\Windows\system32\drivers\amdiox86.sys
2016-03-05 16:54:00 ----SHD---- C:\Windows\Installer
2016-03-05 16:49:54 ----D---- C:\Program Files\Google
2016-03-05 16:40:33 ----D---- C:\Program Files\Atheros
2016-03-05 16:40:11 ----N---- C:\Windows\system32\athr.sys
2016-03-05 16:40:11 ----D---- C:\Windows\Options
2016-03-05 16:40:11 ----A---- C:\Windows\system32\drivers\athr.sys
2016-03-05 16:40:10 ----HD---- C:\Program Files\InstallShield Installation Information
2016-03-05 16:40:05 ----D---- C:\ProgramData\Atheros
2016-03-05 15:18:12 ----D---- C:\Users\Natali\AppData\Roaming\Identities
2016-03-05 15:18:00 ----SD---- C:\Users\Natali\AppData\Roaming\Microsoft
2016-03-05 15:18:00 ----D---- C:\Users\Natali\AppData\Roaming\Media Center Programs
2016-03-05 15:17:48 ----SHD---- C:\ProgramData\Шаблоны
2016-03-05 15:17:48 ----SHD---- C:\ProgramData\Рабочий стол
2016-03-05 15:17:48 ----SHD---- C:\ProgramData\Избранное
2016-03-05 15:17:48 ----SHD---- C:\ProgramData\Документы
2016-03-05 15:17:48 ----SHD---- C:\ProgramData\Главное меню
2016-03-05 15:06:37 ----D---- C:\Windows\SoftwareDistribution
2016-03-05 15:04:32 ----D---- C:\Windows\Prefetch
2016-03-05 15:02:57 ----D---- C:\Windows\Panther
2016-03-05 14:55:31 ----D---- C:\Windows.old.000
2016-03-04 14:02:06 ----ASH---- C:\hiberfil.sys
2016-03-04 13:50:09 ----ASH---- C:\swapfile.sys
2016-03-04 13:40:44 ----D---- C:\Windows.old
2016-03-03 18:24:20 ----RASH---- C:\MSDOS.SYS
2016-03-03 18:24:20 ----RASH---- C:\IO.SYS
2016-03-03 18:05:41 ----ASH---- C:\pagefile.sys
2016-03-03 17:50:20 ----D---- C:\$SysReset
2016-02-26 23:23:14 ----A---- C:\Windows\system32\amdlvr32.dll
2016-02-26 23:04:20 ----A---- C:\Windows\system32\dgtrayicon.exe
2016-02-26 23:04:14 ----A---- C:\Windows\system32\GameManager32.dll
2016-02-26 23:00:54 ----A---- C:\Windows\system32\ativvsvl.dat
2016-02-26 23:00:54 ----A---- C:\Windows\system32\ativvsva.dat
2016-02-25 13:24:30 ----D---- C:\AMD
2016-02-25 11:39:05 ----RHD---- C:\ESD
2016-02-25 11:32:09 ----SHD---- C:\Recovery

======Список файлов и папок, измененных за последние 3 месяца======

2016-04-08 13:06:56 ----D---- C:\Windows\system32\config
2016-04-08 13:02:28 ----D---- C:\Windows\Temp
2016-04-08 13:02:12 ----D---- C:\Windows\inf
2016-04-08 13:01:50 ----D---- C:\Windows
2016-04-08 13:01:33 ----SHD---- C:\System Volume Information
2016-04-08 12:56:34 ----D---- C:\Windows\system32\drivers
2016-04-08 10:37:55 ----HD---- C:\ProgramData
2016-04-07 22:08:51 ----D---- C:\Windows\system32\Tasks
2016-04-07 22:02:54 ----RD---- C:\Program Files
2016-04-07 17:00:15 ----A---- C:\Windows\win.ini
2016-04-07 16:59:12 ----RSD---- C:\Windows\assembly
2016-04-07 14:56:37 ----D---- C:\Windows\Tasks
2016-04-06 22:58:47 ----D---- C:\TEMP
2016-04-06 21:18:59 ----D---- C:\Program Files\Internet Explorer
2016-04-06 20:51:15 ----D---- C:\Program Files\Common Files
2016-04-06 20:33:22 ----D---- C:\Windows\System32
2016-04-06 20:33:11 ----D---- C:\Windows\system32\DriverStore
2016-04-06 15:40:37 ----D---- C:\Windows\Downloaded Program Files
2016-04-06 14:56:45 ----D---- C:\Windows\Logs
2016-04-06 14:56:45 ----D---- C:\Windows\debug
2016-04-06 11:40:02 ----HD---- C:\Windows\system32\GroupPolicy
2016-04-03 17:59:18 ----D---- C:\Windows\winsxs
2016-04-03 16:52:33 ----D---- C:\Windows\system32\catroot2
2016-03-29 10:15:29 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-03-17 16:36:33 ----D---- C:\Windows\system32\catroot
2016-03-17 12:47:20 ----D---- C:\Windows\Microsoft.NET
2016-03-16 15:34:17 ----D---- C:\Windows\rescache
2016-03-16 14:59:32 ----D---- C:\Windows\system32\migration
2016-03-16 14:41:24 ----D---- C:\Windows\system32\ru-RU
2016-03-16 14:41:22 ----D---- C:\Windows\system32\en-US
2016-03-16 14:41:22 ----D---- C:\Windows\PolicyDefinitions
2016-03-16 14:34:36 ----D---- C:\Windows\system32\wdi
2016-03-16 13:33:55 ----D---- C:\Windows\system32\wbem
2016-03-16 13:33:55 ----D---- C:\Windows\system32\drivers\ru-RU
2016-03-15 19:37:16 ----D---- C:\Windows\LiveKernelReports
2016-03-10 18:45:26 ----SD---- C:\ProgramData\Microsoft
2016-03-10 13:45:55 ----D---- C:\Program Files\Windows Media Player
2016-03-10 11:31:43 ----D---- C:\Windows\AppCompat
2016-03-09 10:45:04 ----D---- C:\Windows\AppPatch
2016-03-07 22:17:02 ----RSD---- C:\Windows\Fonts
2016-03-07 22:11:09 ----D---- C:\Program Files\Common Files\microsoft shared
2016-03-07 22:04:03 ----D---- C:\Program Files\Common Files\System
2016-03-07 16:08:26 ----D---- C:\Windows\ShellNew
2016-03-07 14:56:37 ----D---- C:\Windows\tracing
2016-03-07 12:13:39 ----D---- C:\Windows\ehome
2016-03-07 12:07:51 ----D---- C:\Windows\system32\drivers\en-US
2016-03-07 09:34:25 ----D---- C:\Windows\ru-RU
2016-03-07 09:34:25 ----D---- C:\Program Files\Windows Journal
2016-03-07 09:34:12 ----D---- C:\Windows\system32\AdvancedInstallers
2016-03-07 09:34:00 ----D---- C:\Windows\system32\Dism
2016-03-07 09:33:49 ----D---- C:\Windows\system32\CodeIntegrity
2016-03-07 09:33:20 ----D---- C:\Program Files\Windows Defender
2016-03-06 23:12:06 ----D---- C:\Windows\system32\Boot
2016-03-06 14:15:41 ----SHD---- C:\$Recycle.Bin
2016-03-05 16:57:19 ----D---- C:\Windows\system32\restore
2016-03-05 16:43:42 ----D---- C:\Windows\system32\LogFiles
2016-03-05 15:52:32 ----D---- C:\Windows\system32\NDF
2016-03-05 15:18:00 ----RD---- C:\Users
2016-03-05 15:17:48 ----D---- C:\Program Files\Windows NT
2016-03-05 15:07:51 ----D---- C:\Windows\system32\sysprep
2016-03-05 15:05:58 ----D---- C:\Windows\system32\drivers\UMDF

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed
======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 173440]
R0 SymEFASI;Symantec Extended File Attributes (SI); C:\Windows\system32\drivers\NSBU\1606000.08E\SYMEFASI.SYS [2016-02-24 1287408]
R1 BHDrvx86;BHDrvx86; \??\C:\Program Files\Norton Security with Backup\NortonData\22.6.0.142\Definitions\BASHDefs\20160405.001\BHDrvx86.sys [2016-04-05 1269488]
R1 ccSet_NSBU;NSBU Settings Manager; C:\Windows\system32\drivers\NSBU\1606000.08E\ccSetx86.sys [2016-02-24 137456]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2016-02-04 389968]
R1 IDSVix86;IDSVix86; \??\C:\Program Files\Norton Security with Backup\NortonData\22.6.0.142\Definitions\IPSDefs\20160407.001\IDSvix86.sys [2016-04-04 580344]
R1 SABI;SAMSUNG Kernel Driver For Windows 7; \??\C:\Windows\system32\Drivers\SABI.sys [2010-03-31 10752]
R1 SRTSP;Symantec Real Time Storage Protection; C:\Windows\system32\drivers\NSBU\1606000.08E\SRTSP.SYS [2016-02-24 713968]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NSBU\1606000.08E\SRTSPX.SYS [2016-02-24 44792]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NSBU\1606000.08E\Ironx86.SYS [2016-02-24 234736]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\NSBU\1606000.08E\SYMNETS.SYS [2016-02-24 431328]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 AODDriver4.1;AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-03-05 45184]
R2 KMDFMEMIO;SAMSUNG Kernel Driver; C:\Windows\system32\DRIVERS\kmdfmemio.sys [2006-11-14 13312]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-04-30 290304]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2012-04-23 2910720]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2012-05-14 86656]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2016-04-06 125264]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2015-06-18 3522264]
R3 NAVENG;NAVENG; \??\C:\Program Files\Norton Security with Backup\NortonData\22.6.0.142\Definitions\VirusDefs\20160407.024\NAVENG.SYS [2016-04-06 104440]
R3 NAVEX15;NAVEX15; \??\C:\Program Files\Norton Security with Backup\NortonData\22.6.0.142\Definitions\VirusDefs\20160407.024\NAVEX15.SYS [2016-04-06 1647216]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2016-04-06 103152]
R3 utm4mtkw;AVZ Kernel Driver; \??\C:\Windows\system32\Drivers\utm4mtkw.sys [2016-04-08 7168]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 hidkmdf;KMDF Driver; C:\Windows\system32\DRIVERS\hidkmdf.sys [2014-08-06 12088]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 35288]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
S3 WacHidRouter;Wacom Hid Router; C:\Windows\system32\DRIVERS\wachidrouter.sys [2014-08-06 85304]
S3 wacomrouterfilter;Wacom Router Filter Driver; C:\Windows\system32\DRIVERS\wacomrouterfilter.sys [2014-08-06 13112]

======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-18 82128]
R2 AdobeUpdateService;AdobeUpdateService; C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-01-28 693440]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-02-09 2020056]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-04-30 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-04-30 291840]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 KMS-R@1n;KMS-R@1n; C:\Windows\KMS-R@1n.exe [2016-03-20 23040]
R2 NSBU;Norton Security with Backup; C:\Program Files\Norton Security with Backup\Engine\22.6.0.142\NSBU.exe [2016-02-26 289080]
R2 WTabletServiceCon;Wacom Consumer Service; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [2014-08-19 567064]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 4846168]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 gupdate;Служба Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-04-07 154440]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-06 269504]
S3 aspnet_state;Служба состояний ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2015-11-05 45744]
S3 gupdatem;Служба Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-04-07 154440]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-07 146888]
S3 ose;Office  Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]

-----------------EOF-----------------
