Результат сканирования Farbar Recovery Scan Tool (FRST) (x64) Версия: 22-08.2024 Запущено с помощью Admin (Администратор) на DESKTOP-OTMRLMR (06-09-2024 16:12:38) Запущено из C:\Users\Kolya\Desktop\2\FRST64.exe Загруженные профили: Admin & Kolya Платформа: Майкрософт Windows 10 IoT Корпоративная LTSC Версия 21H2 19044.4780 (X64) Язык: Русский (Россия) Браузер по умолчанию: Chrome Режим загрузки: Normal ==================== Процессы (В белом списке) ================= (Если запись включена в fixlist, процесс будет закрыт. Файл не будет перемещён.) (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5> (explorer.exe ->) (QuestSoft) [Файл не подписан] C:\Program Files (x86)\QTranslate\QTranslate.exe (explorer.exe ->) (Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe <6> (explorer.exe ->) (VIA Technologies Inc. -> VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe <2> (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <10> (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe <2> (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe <2> (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe <2> (services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (services.exe ->) (ManyCam -> Visicom Media Inc.) C:\ProgramData\ManyCam\Service\ManyCamService.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe (services.exe ->) (Rosetta Stone Ltd -> Rosetta Stone Ltd.) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe (services.exe ->) (VIA Technologies Inc. -> VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe (winlogon.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LogonUI.exe ==================== Реестр Windows (В белом списке) =================== (Если запись включена в fixlist, элемент реестра будет сброшен на значение по умолчанию или удалён. Файл не будет перемещён.) HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5299320 2012-10-25] (VIA Technologies Inc. -> VIA) HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2022-02-19] (Adobe Inc. -> ) HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\Run: [movavi_srecorder_22.0.0_screenrecorder] => [X] HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [123172768 2024-06-13] (Skype Software Sarl -> Skype Technologies S.A.) HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [5861376 2022-05-20] (Tonec Inc.) [Файл не подписан] HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [22485296 2022-09-20] (PALTALK, INC. -> ManyCam ULC) HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\Run: [OpenVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe (Нет файла) HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\Run: [MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3741248 2024-09-03] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [123172768 2024-06-13] (Skype Software Sarl -> Skype Technologies S.A.) HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\Run: [QTranslate] => C:\Program Files (x86)\QTranslate\QTranslate.exe [1462272 2022-02-09] (QuestSoft) [Файл не подписан] HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\Run: [HotFolder.FR15] => C:\Program Files (x86)\ABBYY FineReader 15\HotFolder.exe [1608352 2020-09-09] (ABBYY Production LLC -> ABBYY Production LLC.) HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\Run: [Lync] => C:\Program Files\Microsoft Office\root\Office16\lync.exe [26409080 2024-08-19] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe (Нет файла) HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\Run: [YandexBrowserAutoLaunch_9BA8AE2F7617899C9233D699976ADEF6] => C:\Users\Kolya\AppData\Local\Yandex\YandexBrowser\Application\browser.exe [4560560 2024-08-26] (YANDEX LLC -> YANDEX LLC) HKU\S-1-5-21-2577881769-356289266-1155278238-1003\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [5861376 2022-05-20] (Tonec Inc.) [Файл не подписан] HKU\S-1-5-21-2577881769-356289266-1155278238-1003\...\Run: [QTranslate] => C:\Program Files (x86)\QTranslate\QTranslate.exe [1462272 2022-02-09] (QuestSoft) [Файл не подписан] HKU\S-1-5-21-2577881769-356289266-1155278238-1003\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [123172768 2024-06-13] (Skype Software Sarl -> Skype Technologies S.A.) HKU\S-1-5-21-2577881769-356289266-1155278238-1003\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe (Нет файла) HKLM\...\Print\Monitors\HP E111 Status Monitor: C:\Windows\system32\hpinkstsE111LM.dll [393352 2017-04-14] (Hewlett Packard -> HP Inc.) HKLM\...\Print\Monitors\Wondershare PDFelement Monitor: C:\Windows\system32\PEPrinterMonitor.dll [285232 2022-11-29] (Wondershare Technology Co.,Ltd -> Wondershare Software) HKLM\Software\Microsoft\Active Setup\Installed Components: [>OpenVPN_UserSetup] -> reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v OPENVPN-GUI /t REG_SZ /d "C:\Program Files\OpenVPN\bin\openvpn-gui.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\128.0.6613.120\Installer\chrmstp.exe [2024-09-06] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEScreenshot.lnk [2023-03-03] ShortcutTarget: Wondershare PEScreenshot.lnk -> C:\Program Files\Wondershare\PDFelement\PENotify.exe (Wondershare) [Файл не подписан] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEToolbox.lnk [2023-03-03] ShortcutTarget: Wondershare PEToolbox.lnk -> C:\Program Files\Wondershare\PDFelement\PENotify.exe (Wondershare) [Файл не подписан] ==================== Запланированные задачи (В белом списке) ================= (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) Task: {B460B61A-9F12-4095-AA50-0FA03FE69A94} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem130.0.6679.0{84324460-054F-44AC-AADB-B514310CBD2B} => C:\Program Files (x86)\Google\GoogleUpdater\130.0.6679.0\updater.exe [4884584 2024-08-26] (Google LLC -> Google LLC) Task: {F2C8A001-27BA-41D5-8783-AE1E6AFF470E} - System32\Tasks\HPCustParticipation HP DeskJet 2130 series => C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPCustPartic.exe [6439584 2021-11-15] (HP Inc. -> HP Inc.) Task: {3C432796-A4F7-4D97-8EB9-C058879C5D61} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21918696 2024-08-01] (Microsoft Corporation -> Microsoft Corporation) Task: {40ECC702-5435-4911-95B6-A2011BDEFBA5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21918696 2024-08-01] (Microsoft Corporation -> Microsoft Corporation) Task: {35043F8B-5811-4C19-8EEB-A2DB6809C023} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141384 2024-08-19] (Microsoft Corporation -> Microsoft Corporation) Task: {06760264-053E-439F-98FA-7E1740913D59} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141384 2024-08-19] (Microsoft Corporation -> Microsoft Corporation) Task: {93607F16-348D-4876-8D49-C09AF4EE1945} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {B0D5EEBA-4FD9-46CE-82E5-69754BB000D2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FD69A3C8-451C-4F41-BA14-8916C484A125} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {664147C4-5946-4A90-8CB6-D43F07BC785A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpCmdRun.exe [1687320 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A6C1A9BE-B3BA-497F-BD42-EA719B51DA04} - System32\Tasks\SmartShare => C:\Program Files (x86)\LG Software\LG Smart Share\SmartShareStart.exe tray (Нет файла) Task: {A23DCCAF-EEDE-4F34-AED1-89DF00EBAFBE} - System32\Tasks\Uninstaller_SkipUac_Admin => "C:\Users\Admin\Desktop\IObitUninstallerPortable\App\ProgramFiles\IObitUninstaler.exe" -> C:\Users\Admin\Desktop\IObitUninstallerPortable\App\ProgramFiles\\/UninstallExplorer Task: {2F0FA34D-B1C0-48C8-84A8-0A74797532EA} - System32\Tasks\Uninstaller_SkipUac_Kolya => "C:\Users\Admin\Desktop\IObitUninstallerPortable\App\ProgramFiles\IObitUninstaler.exe" -> C:\Users\Admin\Desktop\IObitUninstallerPortable\App\ProgramFiles\\/UninstallExplorer Task: {B1B86F5E-F23F-4102-9823-D547C5924670} - System32\Tasks\Uninstaller_SkipUac_Lyuda => "C:\Users\Admin\Desktop\IObitUninstallerPortable\App\ProgramFiles\IObitUninstaler.exe" -> C:\Users\Admin\Desktop\IObitUninstallerPortable\App\ProgramFiles\\/UninstallExplorer Task: {D147494B-A5DA-4FE4-B0E7-71357ADB4DDF} - System32\Tasks\Обновление Браузера Яндекс => C:\Users\Kolya\AppData\Local\Yandex\YandexBrowser\Application\browser.exe [4560560 2024-08-26] (YANDEX LLC -> YANDEX LLC) (Если запись включена в fixlist, файл задачи (.job) будет перемещён. Файл, выполняемый задачей, не будет перемещён.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe Task: C:\Windows\Tasks\Обновление Браузера Яндекс.job => C:\Users\Kolya\AppData\Local\Yandex\YandexBrowser\Application\browser.exe ==================== Internet (В белом списке) ==================== (Если элемент включён в fixlist, если он является элементом реестра, он будет удалён или сброшен на значение по умолчанию.) ProxyServer: [S-1-5-21-2577881769-356289266-1155278238-1002] => 127.0.0.1:8086 Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{065FD3A3-47E3-45C7-8291-B105C1666811}: [DhcpNameServer] 10.211.254.254 8.8.8.8 Tcpip\..\Interfaces\{48fe9c82-0071-41e3-99ad-cefe863b346d}: [NameServer] 10.255.255.1,10.255.255.2 Tcpip\..\Interfaces\{5699e46e-fd2f-4a46-9880-5a967ba4d29a}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{5699e46e-fd2f-4a46-9880-5a967ba4d29a}: [DhcpDomain] netis.cc Tcpip\..\Interfaces\{685ff960-2683-430d-bb87-d20bd272db50}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{685ff960-2683-430d-bb87-d20bd272db50}: [DhcpDomain] netis.cc Tcpip\..\Interfaces\{7cd74d52-99d0-4504-a01f-12cf5f766086}: [DhcpNameServer] 192.168.175.176 Tcpip\..\Interfaces\{CC4FF04A-63E5-418D-B77A-B054AE7D7829}: [DhcpNameServer] 10.211.254.254 8.8.8.8 Tcpip\..\Interfaces\{EAA4D758-3171-4878-8697-57D067C04FD2}: [DhcpNameServer] 10.211.254.254 8.8.8.8 Edge: ======= Edge HomeButtonPage: HKU\S-1-5-21-2577881769-356289266-1155278238-1002 -> hxxps://www.ya.ru/?win=576&clid=2337627-17 Edge Profile: C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default [2024-09-06] Edge Extension: (Google Документы офлайн) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-08-28] Edge Extension: (Edge relevant text changes) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-08-28] Edge Extension: (IDM Integration Module) - C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\llbjbkhnmlidjebalopleeepgdfgcpec [2024-08-28] Edge HKU\S-1-5-21-2577881769-356289266-1155278238-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx [2022-03-24] Edge HKU\S-1-5-21-2577881769-356289266-1155278238-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx [2022-03-24] Edge HKU\S-1-5-21-2577881769-356289266-1155278238-1003\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx [2022-03-24] FireFox: ======== FF HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Admin\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\Admin\AppData\Roaming\IDM\idmmzcc5 [2022-05-20] [Устаревший] [не подписан] FF HKU\S-1-5-21-2577881769-356289266-1155278238-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Устаревший] FF HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Kolya\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\Kolya\AppData\Roaming\IDM\idmmzcc5 [2022-02-24] [Устаревший] [не подписан] FF HKU\S-1-5-21-2577881769-356289266-1155278238-1002\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF HKU\S-1-5-21-2577881769-356289266-1155278238-1003\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Lyuda\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\Lyuda\AppData\Roaming\IDM\idmmzcc5 [2022-02-22] [Устаревший] [не подписан] FF HKU\S-1-5-21-2577881769-356289266-1155278238-1003\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-02-19] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-09] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-09] (VideoLAN -> VideoLAN) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [Нет файла] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [Нет файла] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [Нет файла] FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitReaderPlugin.dll [Нет файла] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-02-19] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-02-19] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default [2024-09-06] CHR Extension: (AdGuard Антибаннер) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2024-08-30] CHR Extension: (Google Документы офлайн) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-08-30] CHR Extension: (Absolute Enable Right Click & Copy) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdocbkpgdakpekjlhemmfcncgdjeiika [2022-02-20] CHR Extension: (IDM Integration Module) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2024-08-26] CHR Extension: (Платежная система Интернет-магазина Chrome) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-02-19] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2022-03-24] CHR HKU\S-1-5-21-2577881769-356289266-1155278238-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2022-03-24] CHR HKU\S-1-5-21-2577881769-356289266-1155278238-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fhkbfkkohcdgpckffakhbllifkakihmh] CHR HKU\S-1-5-21-2577881769-356289266-1155278238-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2022-03-24] CHR HKU\S-1-5-21-2577881769-356289266-1155278238-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2022-03-24] CHR HKLM-x32\...\Chrome\Extension: [kadaohckdkghfaclhjmkmplebcdcnfnp] CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2022-03-24] ==================== Службы (В белом списке) =================== (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9202688 2024-08-01] (Microsoft Corporation -> Microsoft Corporation) R2 ManyCam Service; C:\ProgramData\ManyCam\Service\ManyCamService.exe [544984 2016-03-31] (ManyCam -> Visicom Media Inc.) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe [1427024 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522096 2024-08-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies Inc. -> VIA Technologies, Inc.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\NisSrv.exe [3199648 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe [133704 2024-08-08] (Microsoft Windows Publisher -> Microsoft Corporation) S2 OpenVPNService; "C:\Program Files\OpenVPN\bin\openvpnserv2.exe" [X] S2 OpenVPNServiceInteractive; "C:\Program Files\OpenVPN\bin\openvpnserv.exe" [X] S3 ProtonVPN Service; "C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe" [X] S3 ProtonVPN Update Service; "C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.UpdateService.exe" [X] S3 ProtonVPN WireGuard; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPN.WireGuardService.exe C:\ProgramData\ProtonVPN\WireGuard\ProtonVPN.conf ===================== Драйверы (В белом списке) =================== (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [282624 2023-12-18] (Microsoft Corporation) [Файл не подписан] S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [147968 2023-12-18] (Microsoft Corporation) [Файл не подписан] R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv.sys [66952 2018-07-30] (ManyCam (VISICOM MÉDIA INC.) -> Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (ManyCam -> Visicom Media Inc.) R3 ovpn-dco; C:\Windows\System32\drivers\ovpn-dco.sys [91696 2023-10-08] (WDKTestCert lev,133391533294737317 -> OpenVPN, Inc) R3 phantomtap; C:\Windows\System32\drivers\phantomtap.sys [50248 2024-04-23] (Avira Operations GmbH & Co. KG -> The OpenVPN Project) R3 tap0901; C:\Windows\System32\drivers\tap0901.sys [40448 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) R3 tapprotonvpn; C:\Windows\System32\drivers\tapprotonvpn.sys [49024 2021-05-28] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [22080 2024-08-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [602504 2024-08-08] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105864 2024-08-08] (Microsoft Windows -> Microsoft Corporation) S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489984 2022-02-24] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) S3 ProtonVPNCallout; \??\C:\Program Files (x86)\Proton Technologies\ProtonVPN\x64\Win10\ProtonVPN.CalloutDriver.sys [X] ==================== NetSvcs (В белом списке) =================== (Если запись включена в fixlist, она будет удалена из реестра. Файл не будет удалён, если он не указан отдельно.) ==================== Один месяц (создан) (В белом списке) ========= (Если запись включена в лист исправлений, файл/папка будут перемещены.) 2024-09-06 16:12 - 2024-09-06 16:13 - 000000000 ____D C:\FRST 2024-09-06 16:10 - 2024-09-06 16:12 - 000000000 ____D C:\Users\Kolya\Desktop\2 2024-09-06 15:55 - 2024-09-06 15:55 - 000481552 _____ C:\Users\Kolya\Downloads\Не подтвержден 17170.crdownload 2024-09-06 10:22 - 2024-09-05 16:02 - 000075550 _____ C:\Users\Kolya\Desktop\CollectionLog-2024.09.05-16.02.zip 2024-09-06 10:18 - 2024-09-06 10:19 - 000000000 ____D C:\Users\Kolya\Desktop\CollectionLog-2024.09.05-16.02 2024-09-05 16:24 - 2024-09-05 16:24 - 000140958 _____ C:\Users\Kolya\Downloads\log.rar 2024-09-05 14:28 - 2024-09-03 05:30 - 001533256 _____ (Dragokas & regist) C:\Users\Kolya\Desktop\Check Browsers LNK.exe 2024-09-05 14:01 - 2024-09-05 14:08 - 000000000 ____D C:\Users\Kolya\Desktop\Лечение от вирусов в компьютере 2024-09-04 17:58 - 2024-09-04 17:58 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files 2024-09-04 12:43 - 2024-09-04 12:44 - 000000000 ____D C:\Users\Kolya\Downloads\Не подтвержден 901629.crdownload 2024-09-04 12:39 - 2024-09-04 12:39 - 045411140 _____ C:\Users\Kolya\Downloads\Не подтвержден 901629.crdownload.zip 2024-09-04 12:38 - 2024-09-04 12:38 - 002335464 _____ (Gridinsoft LLC) C:\Users\Kolya\Downloads\setup-gridinsoft-fix.exe 2024-09-04 11:19 - 2024-09-04 11:19 - 000000139 _____ C:\Users\Kolya\Downloads\link.txt 2024-09-04 10:11 - 2024-09-04 10:11 - 003868516 _____ C:\Users\Kolya\Downloads\Radiolocman_2024-07-08.pdf 2024-09-02 14:28 - 2024-09-02 14:29 - 291324824 _____ C:\Users\Admin\Downloads\ofxk9f0k.exe 2024-09-02 11:51 - 2024-09-02 13:24 - 000000579 _____ C:\Users\Kolya\Desktop\Замена оголовья наушников Marshall Major 2.txt 2024-08-30 14:23 - 2024-09-02 20:13 - 000000000 ____D C:\Users\Kolya\Desktop\vpn windovs 2024-08-30 14:08 - 2024-08-30 14:09 - 000000000 ____D C:\Users\Admin\Desktop\vpn windows 2024-08-29 12:36 - 2024-08-29 12:36 - 000003216 _____ C:\Windows\system32\Tasks\Uninstaller_SkipUac_Admin 2024-08-29 12:36 - 2024-08-29 12:36 - 000000000 ____D C:\Users\Admin\AppData\Roaming\IObit 2024-08-29 12:36 - 2024-08-29 12:36 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\IObit 2024-08-29 12:36 - 2024-08-29 12:36 - 000000000 ____D C:\ProgramData\IObit 2024-08-29 12:28 - 2024-09-02 14:30 - 000000000 ____D C:\Users\Admin\Desktop\Проверка на вирусы 2024-08-29 11:26 - 2024-08-29 12:36 - 000000000 ____D C:\ProgramData\ProductData 2024-08-28 20:26 - 2024-08-28 20:26 - 291014928 _____ C:\Users\Kolya\Downloads\9xh5zjj8.exe 2024-08-28 18:33 - 2024-08-28 18:33 - 000000000 ____D C:\Users\Kolya\Doctor Web 2024-08-28 15:49 - 2024-08-28 15:49 - 000000000 ____D C:\Users\Admin\Desktop\Dr.Web Security Space 12 2024-08-28 14:45 - 2024-08-29 12:00 - 000000000 ____D C:\Users\Admin\Doctor Web 2024-08-28 14:35 - 2024-08-29 12:38 - 000000000 ____D C:\Windows\system32\Tasks\Doctor Web 2024-08-28 14:32 - 2024-08-29 12:40 - 000000000 ____D C:\Program Files\DrWeb 2024-08-28 14:28 - 2024-08-29 12:40 - 000000000 ____D C:\ProgramData\Doctor Web 2024-08-28 12:41 - 2024-08-28 12:41 - 000282078 _____ C:\Users\Kolya\Downloads\Microsoft-Activation-Scripts-master (1).zip 2024-08-27 15:41 - 2024-08-27 15:42 - 028417164 _____ C:\Users\Kolya\Downloads\videoplayback.mp4 2024-08-26 13:10 - 2024-08-26 18:08 - 000000000 ____D C:\KVRT2020_Data 2024-08-25 15:43 - 2024-08-25 16:44 - 000000000 ____D C:\Users\Kolya\Desktop\Обход блокировок интернета 2024-08-24 17:37 - 2024-08-24 17:43 - 001881734 _____ C:\Users\Kolya\Downloads\Не подтвержден 138189.crdownload 2024-08-24 16:59 - 2024-08-24 17:03 - 008331992 _____ C:\Users\Kolya\Downloads\psiphon3.exe 2024-08-21 20:30 - 2024-08-23 12:02 - 000000000 ____D C:\Users\Kolya\AppData\Roaming\oblivion-desktop 2024-08-21 19:57 - 2024-08-21 19:57 - 033665738 _____ C:\Users\Kolya\Downloads\oblivion-v4-signed.apk 2024-08-15 19:04 - 2024-08-15 19:04 - 048194555 _____ C:\Users\Kolya\Desktop\BAHCO 2015_RU.pdf 2024-08-15 10:48 - 2024-08-15 10:49 - 080648440 _____ C:\Users\Kolya\Desktop\Bahco_2024_General_cat_English.pdf 2024-08-14 11:36 - 2024-08-14 11:36 - 000000000 ___HD C:\$WinREAgent 2024-08-13 21:13 - 2024-08-13 21:14 - 000018840 _____ C:\Users\Kolya\Downloads\[NNMClub.to]_Proekt Alekseya Sitnikova - Sitnikov Aleksey - Karmacoach [2023, FB2 RTF PDF EPUB, RUS] (1).torrent 2024-08-13 21:13 - 2024-08-13 21:13 - 000018840 _____ C:\Users\Kolya\Downloads\[NNMClub.to]_Proekt Alekseya Sitnikova - Sitnikov Aleksey - Karmacoach [2023, FB2 RTF PDF EPUB, RUS].torrent 2024-08-13 21:10 - 2024-08-13 21:10 - 000055859 _____ C:\Users\Kolya\Downloads\Ситников Алексей - Karmacoach «Проект Алексея Ситникова Karmalogic» [Ростислав Парцевский, 2024, 128 kbps, MP3] [rutracker-6485917] (2).torrent 2024-08-13 21:10 - 2024-08-13 21:10 - 000055859 _____ C:\Users\Kolya\Downloads\Ситников Алексей - Karmacoach «Проект Алексея Ситникова Karmalogic» [Ростислав Парцевский, 2024, 128 kbps, MP3] [rutracker-6485917] (1).torrent 2024-08-13 21:08 - 2024-08-13 21:08 - 000055859 _____ C:\Users\Kolya\Downloads\Ситников Алексей - Karmacoach «Проект Алексея Ситникова Karmalogic» [Ростислав Парцевский, 2024, 128 kbps, MP3] [rutracker-6485917].torrent 2024-08-11 11:35 - 2024-08-11 11:36 - 000579961 _____ C:\Users\Kolya\Desktop\youtube-ban.pdf 2024-08-10 19:01 - 2024-08-10 19:01 - 000011021 _____ C:\Users\Kolya\Downloads\[NNMClub.to]_oblivion-v4-signed.apk.torrent ==================== Один месяц (изменён) ================== (Если запись включена в лист исправлений, файл/папка будут перемещены.) 2024-09-06 16:02 - 2024-05-07 13:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2024-09-06 16:02 - 2024-05-07 12:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlanetVPN 2024-09-06 16:02 - 2024-05-07 11:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN 2024-09-06 16:02 - 2022-02-19 17:06 - 000000000 ____D C:\Users\Lyuda\Desktop\Новая папка 2024-09-06 16:02 - 2022-02-19 11:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProtonVPN 2024-09-06 15:56 - 2019-12-07 12:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2024-09-06 15:47 - 2022-02-18 14:41 - 001753404 _____ C:\Windows\system32\PerfStringBackup.INI 2024-09-06 15:47 - 2019-12-07 17:34 - 000770694 _____ C:\Windows\system32\perfh019.dat 2024-09-06 15:47 - 2019-12-07 17:34 - 000151940 _____ C:\Windows\system32\perfc019.dat 2024-09-06 15:47 - 2019-12-07 12:13 - 000000000 ____D C:\Windows\INF 2024-09-06 15:42 - 2022-02-20 10:45 - 000000000 ____D C:\Users\Kolya\AppData\Roaming\Microsoft\Skype for Desktop 2024-09-06 15:41 - 2022-02-19 16:45 - 000000000 __SHD C:\Users\Kolya\IntelGraphicsProfiles 2024-09-06 15:41 - 2022-02-18 15:38 - 000000000 __SHD C:\Users\Admin\IntelGraphicsProfiles 2024-09-06 15:41 - 2022-02-18 14:35 - 000008192 ___SH C:\DumpStack.log.tmp 2024-09-06 15:41 - 2022-02-18 14:35 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2024-09-06 15:40 - 2019-12-07 12:03 - 000262144 _____ C:\Windows\system32\config\BBI 2024-09-06 15:19 - 2022-02-19 16:29 - 000001003 _____ C:\Users\Admin\Desktop\Новый текстовый документ.txt 2024-09-06 12:24 - 2022-04-04 11:19 - 000000000 ____D C:\Users\Kolya\AppData\Roaming\vlc 2024-09-06 12:18 - 2022-02-18 15:36 - 000000000 ____D C:\Windows\SystemTemp 2024-09-06 10:27 - 2022-02-20 10:45 - 000000000 ____D C:\Users\Kolya\AppData\Roaming\Microsoft\Word 2024-09-06 09:37 - 2023-06-30 10:30 - 000002249 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2024-09-05 19:17 - 2022-02-18 14:35 - 000000000 ____D C:\Windows\system32\SleepStudy 2024-09-05 16:57 - 2022-02-24 10:10 - 000000000 ____D C:\Users\Kolya\AppData\Roaming\DMCache 2024-09-05 10:57 - 2022-02-24 10:20 - 000000000 ____D C:\Users\Kolya\Downloads\Compressed 2024-09-04 11:00 - 2022-02-18 14:35 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2024-09-02 20:53 - 2023-07-17 12:15 - 000000000 ____D C:\Users\Kolya\AppData\Local\CrashDumps 2024-09-02 18:32 - 2022-02-18 14:43 - 000000000 ____D C:\Users\Admin 2024-09-02 14:56 - 2022-07-07 18:01 - 000000000 ____D C:\Users\Admin\Desktop\FotoShow PRO 21.0ru 2024-09-02 14:08 - 2022-12-19 17:14 - 000000460 _____ C:\Windows\Tasks\Обновление Браузера Яндекс.job 2024-09-01 13:20 - 2023-07-31 18:45 - 000000000 ____D C:\Users\Lyuda\AppData\Roaming\Microsoft\Skype for Desktop 2024-09-01 13:19 - 2022-12-19 17:14 - 000002572 _____ C:\Users\Kolya\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex.lnk 2024-09-01 10:52 - 2022-02-19 16:55 - 000000000 __SHD C:\Users\Lyuda\IntelGraphicsProfiles 2024-08-29 12:38 - 2019-12-07 12:14 - 000000000 ___HD C:\Windows\ELAMBKUP 2024-08-29 12:17 - 2024-05-07 14:33 - 000000000 ____D C:\Users\Admin\Downloads\Не подтвержден 350647 2024-08-29 12:17 - 2024-05-07 11:48 - 000000000 ____D C:\Program Files\FreeVpnGuard 2024-08-28 18:33 - 2022-02-19 16:45 - 000000000 ____D C:\Users\Kolya 2024-08-28 15:52 - 2023-08-24 12:28 - 000000000 ____D C:\Users\Admin\Desktop\kms Активатор Офиса 2024-08-26 17:10 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\AppReadiness 2024-08-26 17:09 - 2023-03-20 10:38 - 000000000 ____D C:\Users\Admin\AppData\Local\ElevatedDiagnostics 2024-08-23 16:55 - 2022-02-18 14:44 - 000000000 ____D C:\Users\Admin\AppData\Local\Packages 2024-08-23 16:50 - 2024-07-15 15:03 - 000003899 _____ C:\Users\Kolya\Desktop\Автомобильный насос.txt 2024-08-23 11:41 - 2022-02-19 16:45 - 000000000 ____D C:\Users\Kolya\AppData\Local\Packages 2024-08-23 11:41 - 2019-12-07 12:14 - 000000000 ___HD C:\Program Files\WindowsApps 2024-08-21 19:08 - 2024-07-17 11:03 - 000006313 _____ C:\Users\Kolya\Desktop\Заказ.txt 2024-08-21 19:08 - 2022-02-19 16:58 - 000000000 ____D C:\Users\Lyuda\AppData\Roaming\Microsoft\Word 2024-08-19 20:14 - 2022-02-19 10:57 - 000000000 ____D C:\Program Files\Microsoft Office 2024-08-14 16:55 - 2022-04-23 20:16 - 000000000 ____D C:\ProgramData\Packages 2024-08-14 16:55 - 2022-02-19 16:55 - 000000000 ____D C:\Users\Lyuda\AppData\Local\Packages 2024-08-14 12:30 - 2022-02-18 14:35 - 000444176 _____ C:\Windows\system32\FNTCACHE.DAT 2024-08-14 12:29 - 2019-12-07 17:38 - 000000000 __SHD C:\Windows\BitLockerDiscoveryVolumeContents 2024-08-14 12:29 - 2019-12-07 17:38 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\SysWOW64\setup 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\SysWOW64\Dism 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\SystemResources 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\WinMetadata 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\setup 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\oobe 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\system32\Dism 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\ShellExperiences 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\Provisioning 2024-08-14 12:29 - 2019-12-07 12:14 - 000000000 ____D C:\Windows\bcastdvr 2024-08-14 11:47 - 2019-12-07 12:03 - 000000000 ____D C:\Windows\CbsTemp 2024-08-14 11:42 - 2022-02-18 14:37 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll 2024-08-14 11:35 - 2022-02-18 14:49 - 000000000 ____D C:\Windows\system32\MRT 2024-08-14 11:31 - 2022-02-18 14:49 - 197093640 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2024-08-08 12:00 - 2022-02-18 14:35 - 000000000 ____D C:\Windows\system32\Drivers\wd ==================== Файлы в корне каталогов ======== 2022-09-13 16:27 - 2022-09-13 16:27 - 000000911 _____ () C:\Users\Admin\AppData\Local\recently-used.xbel 2023-04-07 13:26 - 2023-09-30 13:41 - 000007597 _____ () C:\Users\Admin\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Нет автоматического исправления файлов, которые не проходят проверку.) ==================== Конец от FRST.txt ========================