Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

The virus ciphered files


  • This topic is locked This topic is locked
13 replies to this topic

#1 Andrei2015

Andrei2015

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 30 July 2015 - 03:00 AM

Получил письмо от судебных приставов с угрозами , там было вложение , нажал на вложение ничего не произошло , на следующий день включил компьютер и удивился файлы и на рабочем столе объявление , зашифрованы и вымогатель просит выкуп , помогите расшифровать файлы

 

I received the letter from bailiffs with threats, there was an investment, pressed an investment occurred of nothing, next day turned on the computer and was surprised files and on a desktop the announcement, are ciphered and the extortioner asks repayment, help to decipher files



BC AdBot (Login to Remove)

 


#2 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,087 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:07:13 AM

Posted 31 July 2015 - 05:00 AM

Greetings and :welcome: to BleepingComputer,
My name is xXToffeeXx, but feel free to call me Toffee if it is easier for you. I will be helping you with your malware problems.
 
A few points to cover before we start:

  • Do not run any tools without being instructed to as this makes my job much harder in trying to figure out what you have done.
  • Make sure to read my instructions fully before attempting a step.
  • If you have problems or questions with any of the steps, feel free to ask me. I will be happy to answer any questions you have.
  • Please follow the topic by clicking on the "Follow this topic" button, and make sure a tick is in the "receive notifications" and is set to "Instantly". Any replies should be made in this topic by clicking the "Reply to this topic" button.
  • Important information in my posts will often be in bold, make sure to take note of these.
  • I will attempt to reply as soon as possible, and normally within 24 hours of your reply. If this is not possible or I have a delay then I will let you know.
  • I will bump a topic after 3 days of no activity, and then will give you another 2 days to reply before a topic is closed. If you need more time than this please let me know.
  • Let's get going now :thumbup2:

==========================
 
Hi Andrei2015,
 
Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right-click FRST then click "Run as administrator" (XP users: click run after receipt of Windows Security Warning - Open File).
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
  • Please copy and paste the log in your next reply.

Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.
 
--------------
 
To recap, in your next reply I would like to see the following. Make sure to copy & paste them unless I ask otherwise:

  • FRST.txt
  • Addition.txt

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#3 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 31 July 2015 - 08:23 AM

СПАСИБО ЗА ОТВЕТ , СМОГУ ТОЛЬКО 3.08.2015

 

THANKS FOR THE ANSWER, I WILL BE ABLE ONLY 3.08.2015



#4 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 02 August 2015 - 11:51 PM

Здравствуйте я обращался на этот сайт , тема по этой ссылке

http://virusinfo.info/showthread.php?t=187123&page=2&p=1299839#post1299839

также прикрепляю файлы которые вы просили

 

Hello I addressed on this site, a subject according to this link

http://virusinfo.info/showthread.php?t=187123&page=2&p=1299839#post1299839

also I attach files which you asked

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by Администратор (administrator) on NOY-45754998C6B (03-08-2015 11:46:00)
Running from C:\Documents and Settings\1\Рабочий стол\новый сайт помощи\сканер
Loaded Profiles: 1 & Администратор (Available Profiles: 1 & Администратор)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: Русский
Internet Explorer Version 6 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Корпорация Майкрософт) C:\WINDOWS\system32\smss.exe
(Корпорация Майкрософт) C:\WINDOWS\system32\winlogon.exe
(Корпорация Майкрософт) C:\WINDOWS\system32\services.exe
(Корпорация Майкрософт) C:\WINDOWS\system32\scardsvr.exe
(Корпорация Майкрософт) C:\WINDOWS\explorer.exe
(ООО ДубльГИС) C:\Program Files\2gis\3.0\2GISTrayNotifier.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Software 2000 Limited) C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1005MC.EXE
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Корпорация Майкрософт) C:\WINDOWS\system32\notepad.exe
(Корпорация Майкрософт) C:\WINDOWS\system32\notepad.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NeroFilterCheck] => C:\WINDOWS\system32\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [HPUsageTracking] => C:\Program Files\Hewlett-Packard\HP UT\bin\hppusg.exe [36864 2006-06-09] ( )
HKLM\...\Run: [2Gis Update Notifier] => C:\Program Files\2gis\3.0\2GISTrayNotifier.exe [4582936 2014-12-18] (ООО ДубльГИС)
HKLM\...\Run: [OrderReminder] => C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2005-12-21] (Hewlett-Packard)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [16861184 2008-04-10] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] => C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2015-05-02] (Adobe Systems Incorporated)
HKLM\...\Winlogon: [Userinit] C:\WINDOWS\system32\userinit.exe, [26624 2008-04-15] (Корпорация Майкрософт)
HKLM\...\Winlogon: [Shell] Explorer.exe [1034240 2008-04-15] (Корпорация Майкрософт)
HKLM\...\Winlogon: [UIHost] C:\WINDOWS\system32\logonui.exe [515072 2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\crypt32chain: C:\WINDOWS\system32\crypt32.dll [2013-10-07] (Корпорация Майкрософт)
Winlogon\Notify\cscdll: C:\WINDOWS\system32\cscdll.dll [2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\ScCertProp: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\Schedule: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\sclgntfy: C:\WINDOWS\system32\sclgntfy.dll [2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\SensLogn: C:\WINDOWS\system32\WlNotify.dll [2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\termsrv: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт)
Winlogon\Notify\wlballoon: C:\WINDOWS\system32\wlnotify.dll [2008-04-15] (Корпорация Майкрософт)
HKU\S-1-5-18\...\Run: [VistaIcon] => C:\Program Files\VistaDriveIcon\VistaDrv.exe [132096 2008-01-02] ()
HKU\S-1-5-18\...\RunOnce: [ZZZZ1_FirstLogonSetting] => %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,OnceFirstLogonInstall,0
HKU\S-1-5-18\...\RunOnce: [ZZZZ2_FirstLogonSetting] => %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,NewUserFirstLogonInstall,0
HKU\S-1-5-18\...\RunOnce: [IE7_011] => regsvr32 /s /n /i:u shell32
HKU\S-1-5-18\...\RunOnce: [IE7_012] => rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N
HKU\S-1-5-18\...\RunOnce: [tscuninstall] => %systemroot%\system32\tscupgrd.exe
SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll (Корпорация Майкрософт)
SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll (Корпорация Майкрософт)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %SystemRoot%\system32\webcheck.dll (Корпорация Майкрософт)
SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Корпорация Майкрософт)
ShellIconOverlayIdentifiers: [Offline Files] -> {750fdf0e-2a26-11d1-a3ea-080036587f03} => C:\WINDOWS\System32\cscui.dll [2008-04-15] (Корпорация Майкрософт)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-2052111302-1326574676-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?win=185&clid=2121023
HKU\S-1-5-21-2052111302-1326574676-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 - Обработчик поиска Microsoft Url - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Корпорация Майкрософт)
URLSearchHook: [S-1-5-21-2052111302-1326574676-1417001333-500] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> DefaultScope {B2A025AA-2242-4E2F-8FC6-6DC64A736A80} URL = http://yandex.ru/yandsearch?win=185&clid=2121024&text={searchTerms}
SearchScopes: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> {058C66B2-4CB7-4EFD-BC18-D2ACA9E04F73} URL = http://ru.wikipedia.org/wiki/{searchTerms}
SearchScopes: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> {399C4D3F-AB20-4D91-A26A-06F47F9EA438} URL = http://www.rambler.ru/srch?set=www&words={searchTerms}&btnG=%CD%E0%E9%F2%E8%21
SearchScopes: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> {95F663C0-C370-4955-8B39-63069DB1F6C0} URL = http://www.google.ru/search?hl=ru&q={searchTerms}&btnG=%D0%9F%D0%BE%D0%B8%D1%81%D0%BA+%D0%B2+Google&lr=
SearchScopes: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> {B2A025AA-2242-4E2F-8FC6-6DC64A736A80} URL = http://yandex.ru/yandsearch?win=185&clid=2121024&text={searchTerms}
SearchScopes: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> {FA6CC280-3AEA-4DC3-9C5B-9B729779EC31} URL = http://search.microsoft.com/results.aspx?mkt=ru-RU&setlang=ru-RU&q={searchTerms}
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-29] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-29] (Oracle Corporation)
BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll No File
Toolbar: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> &Адрес - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2013-10-12] (Корпорация Майкрософт)
Toolbar: HKU\S-1-5-21-2052111302-1326574676-1417001333-1003 -> &Ссылки - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll [2012-06-08] (Корпорация Майкрософт)
Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll [2013-10-12] (Корпорация Майкрософт)
Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll [2008-04-15] (Корпорация Майкрософт)
Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll [2013-10-12] (Корпорация Майкрософт)
Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll [2013-10-12] (Корпорация Майкрософт)
Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll [2013-10-12] (Корпорация Майкрософт)
Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll [2013-10-12] (Корпорация Майкрософт)
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll [2008-04-15] (Корпорация Майкрософт)
Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll [2013-10-12] (Корпорация Майкрософт)
Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2013-10-12] (Корпорация Майкрософт)
Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\SHELL32.dll [2012-06-08] (Корпорация Майкрософт)
ShellExecuteHooks: Обработчик URL - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8480256 2012-06-08] (Корпорация Майкрософт)
Winsock: Catalog5 01 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog5 03 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 01 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 02 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 03 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 06 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 07 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 08 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 09 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 10 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 11 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 12 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Winsock: Catalog9 13 C:\WINDOWS\system32\mswsock.dll [247296 2008-04-15] (Корпорация Майкрософт)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3D434EC6-E3EF-4FA6-B85C-400E6736D681}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5C133432-C689-4AD7-86BF-D400F09E795E}: [DhcpNameServer] 192.168.0.1
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll [2008-10-05] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-29] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-29] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-09-11] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-09-11] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2052111302-1326574676-1417001333-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\1\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-24] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-07-29]
 
Chrome: 
=======
CHR Profile: C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-15]
CHR Extension: (Google Docs) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-15]
CHR Extension: (Google Drive) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-15]
CHR Extension: (YouTube) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-15]
CHR Extension: (Google Search) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-15]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-15]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-15]
CHR Extension: (Gmail) - C:\Documents and Settings\Администратор\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-15]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 2GISUpdateService; C:\Program Files\2gis\3.0\2GISUpdateService.exe [3764760 2014-12-18] (ООО ДубльГИС)
S3 AppMgmt; C:\WINDOWS\System32\appmgmts.dll [171008 2008-04-15] (Корпорация Майкрософт)
R3 BITS; C:\WINDOWS\system32\qmgr.dll [409088 2008-04-15] (Корпорация Майкрософт)
R2 Dhcp; C:\WINDOWS\System32\dhcpcsvc.dll [126464 2008-04-15] (Корпорация Майкрософт)
S3 dmadmin; C:\WINDOWS\System32\dmadmin.exe [224768 2008-04-15] (Корпорация Microsoft и VERITAS Software)
R2 dmserver; C:\WINDOWS\System32\dmserver.dll [24064 2008-04-15] (Корпорация Майкрософт)
R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [45568 2009-04-21] (Корпорация Майкрософт)
R2 Eventlog; C:\WINDOWS\system32\services.exe [111104 2009-02-09] (Корпорация Майкрософт)
R3 FastUserSwitchingCompatibility; C:\WINDOWS\System32\shsvcs.dll [135680 2009-07-28] (Корпорация Майкрософт)
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [150528 2008-04-15] (Корпорация Майкрософт)
S3 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2008-04-15] (Корпорация Майкрософт)
S4 NetDDE; C:\WINDOWS\system32\netdde.exe [113664 2008-04-15] (Корпорация Майкрософт)
S4 NetDDEdsdm; C:\WINDOWS\system32\netdde.exe [113664 2008-04-15] (Корпорация Майкрософт)
R3 Netman; C:\WINDOWS\System32\netman.dll [198144 2008-04-15] (Корпорация Майкрософт)
R3 Nla; C:\WINDOWS\System32\mswsock.dll [247296 2008-06-20] (Корпорация Майкрософт)
S3 NtmsSvc; C:\WINDOWS\system32\ntmssvc.dll [436736 2008-04-15] (Корпорация Майкрософт)
R2 PlugPlay; C:\WINDOWS\system32\services.exe [111104 2009-02-09] (Корпорация Майкрософт)
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [141824 2008-04-15] (Корпорация Майкрософт)
R2 SCardSvr; C:\WINDOWS\System32\SCardSvr.exe [96768 2008-04-15] (Корпорация Майкрософт)
R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [193024 2008-04-15] (Корпорация Майкрософт)
R2 seclogon; C:\WINDOWS\System32\seclogon.dll [18944 2008-04-15] (Корпорация Майкрософт)
R2 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [331264 2008-04-15] (Корпорация Майкрософт)
R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [135680 2009-07-28] (Корпорация Майкрософт)
R2 srservice; C:\WINDOWS\system32\srsvc.dll [171008 2008-04-15] (Корпорация Майкрософт)
R2 stisvc; C:\WINDOWS\system32\wiaservc.dll [333824 2008-04-15] (Корпорация Майкрософт)
S3 SysmonLog; C:\WINDOWS\system32\smlogsvc.exe [91648 2008-04-15] (Корпорация Майкрософт)
R3 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [249856 2008-04-15] (Корпорация Майкрософт)
R3 TermService; C:\WINDOWS\System32\termsrv.dll [295936 2008-04-15] (Корпорация Майкрософт)
R2 Themes; C:\WINDOWS\System32\shsvcs.dll [135680 2009-07-28] (Корпорация Майкрософт)
S4 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [73216 2008-04-15] (Корпорация Майкрософт)
S3 upnphost; C:\WINDOWS\System32\upnphost.dll [186368 2008-04-15] (Корпорация Майкрософт)
S3 VSS; C:\WINDOWS\System32\vssvc.exe [290304 2008-04-15] (Корпорация Майкрософт)
R2 W32Time; C:\WINDOWS\system32\w32time.dll [175616 2008-04-15] (Корпорация Майкрософт)
R2 winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [145408 2008-04-15] (Корпорация Майкрософт)
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [52736 2008-04-15] (Корпорация Майкрософт (Microsoft Corp.))
S3 Wmi; C:\WINDOWS\System32\advapi32.dll [687616 2009-02-09] (Корпорация Майкрософт)
S3 WmiApSrv; C:\WINDOWS\system32\wbem\wmiapsrv.exe [126464 2008-04-15] (Корпорация Майкрософт)
S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [913408 2006-10-18] (Microsoft Corporation) [File not signed]
R2 WZCSVC; C:\WINDOWS\System32\wzcsvc.dll [483840 2008-04-15] (Корпорация Майкрософт)
S2 JavaQuickStarterService; "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 ACPI; C:\WINDOWS\System32\DRIVERS\ACPI.sys [188288 2008-04-15] (Корпорация Майкрософт)
S4 ACPIEC; C:\WINDOWS\system32\Drivers\ACPIEC.sys [11776 2008-04-15] (Корпорация Майкрософт)
R1 adgnetworktdidrv; C:\WINDOWS\System32\drivers\adgnetworktdidrv.sys [57336 2015-06-02] ( )
S4 dmboot; C:\WINDOWS\System32\drivers\dmboot.sys [799872 2008-04-15] (Корпорация Microsoft и VERITAS Software)
R0 dmio; C:\WINDOWS\System32\DRIVERS\dmio.sys [153600 2008-04-15] (Корпорация Microsoft и VERITAS Software)
R2 exFat; C:\WINDOWS\system32\Drivers\exFat.sys [133632 2009-01-28] (Microsoft Corporation) [File not signed]
R1 Fips; C:\WINDOWS\system32\Drivers\Fips.sys [44544 2008-04-15] (Корпорация Майкрософт)
R0 Ftdisk; C:\WINDOWS\System32\DRIVERS\ftdisk.sys [125440 2008-04-15] (Корпорация Майкрософт)
R1 i8042prt; C:\WINDOWS\System32\DRIVERS\i8042prt.sys [53120 2008-04-15] (Корпорация Майкрософт)
S3 iBank2Key; C:\WINDOWS\System32\DRIVERS\ibank2key.sys [23208 2011-11-24] ()
R3 ip100xp; C:\WINDOWS\System32\DRIVERS\ipfnd51.sys [26752 2005-02-02] (IC Plus Corp.                                                                                                                                                                                                                                                 )
R0 isapnp; C:\WINDOWS\System32\DRIVERS\isapnp.sys [37504 2008-04-15] (Корпорация Майкрософт)
R1 Kbdclass; C:\WINDOWS\System32\DRIVERS\kbdclass.sys [24832 2008-04-15] (Корпорация Майкрософт)
S3 Modem; C:\WINDOWS\system32\Drivers\Modem.sys [30208 2008-04-15] (Корпорация Майкрософт)
R1 Mouclass; C:\WINDOWS\System32\DRIVERS\mouclass.sys [23296 2008-04-15] (Корпорация Майкрософт)
R3 Parport; C:\WINDOWS\System32\DRIVERS\parport.sys [80128 2008-04-15] (Корпорация Майкрософт)
R2 ParVdm; C:\WINDOWS\system32\Drivers\ParVdm.sys [6912 2008-04-15] (Корпорация Майкрософт)
R0 PCI; C:\WINDOWS\System32\DRIVERS\pci.sys [68480 2008-04-15] (Корпорация Майкрософт)
R0 PCIIde; C:\WINDOWS\System32\DRIVERS\pciide.sys [3328 2008-04-15] (Корпорация Майкрософт)
S4 Pcmcia; C:\WINDOWS\system32\Drivers\Pcmcia.sys [120192 2008-04-15] (Корпорация Майкрософт)
R3 R5BaseSmc; C:\WINDOWS\System32\DRIVERS\smccard.sys [12800 2015-03-30] (OEM)
R1 redbook; C:\WINDOWS\System32\DRIVERS\redbook.sys [58368 2008-04-15] (Корпорация Майкрософт)
R2 rspndr; C:\WINDOWS\System32\DRIVERS\rspndr.sys [62848 2008-10-11] (Microsoft Corporation) [File not signed]
R1 Serial; C:\WINDOWS\System32\DRIVERS\serial.sys [65024 2008-04-15] (Корпорация Майкрософт)
S0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [717296 2008-08-19] (Duplex Secure Ltd.)
R0 sr; C:\WINDOWS\System32\DRIVERS\sr.sys [73472 2008-04-15] (Корпорация Майкрософт)
R1 uzexnjux; C:\WINDOWS\system32\Drivers\uzexnjux.sys [11264 2015-07-24] () [File not signed]
R0 VolSnap; C:\WINDOWS\system32\Drivers\VolSnap.sys [51968 2008-04-15] (Корпорация Майкрософт)
U2 CertPropSvc; No ImagePath
S4 IntelIde; No ImagePath
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
U1 WS2IFSL; No ImagePath
 
========================== Drivers MD5 =======================
 
C:\WINDOWS\System32\DRIVERS\ACPI.sys E28AFA761D7ECAA705A00B4A86F68DA9
C:\WINDOWS\system32\Drivers\ACPIEC.sys CEA8D1DA7696ACBFC69A3823BCF1C738
C:\WINDOWS\System32\drivers\adgnetworktdidrv.sys 1A50EDED4A26F8BA3788BBBA40A0AEC2
C:\WINDOWS\System32\drivers\aec.sys 8BED39E3C35D6A489438B8141717A557
C:\WINDOWS\System32\drivers\afd.sys 1E44BC1E83D8FD2305F8D452DB109CF9
C:\WINDOWS\System32\DRIVERS\asyncmac.sys B153AFFAC761E7F5FCFA822B9C4E97BC
C:\WINDOWS\System32\DRIVERS\atapi.sys 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\System32\DRIVERS\atmarpc.sys 9916C1225104BA14794209CFA8012159
C:\WINDOWS\System32\DRIVERS\audstub.sys D9F724AA26C010A217C97606B160ED68
C:\WINDOWS\system32\Drivers\Beep.sys DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\system32\Drivers\cbidf2k.sys 90A673FC8E12A79AFBED2576F6A7AAF9
C:\WINDOWS\system32\Drivers\Cdaudio.sys C1B486A7658353D33A10CC15211A873B
C:\WINDOWS\system32\Drivers\Cdfs.sys C885B02847F5D2FD45A24E219ED93B32
C:\WINDOWS\System32\DRIVERS\cdrom.sys 1F4260CC5B42272D71F79E570A27A4FE
C:\WINDOWS\System32\DRIVERS\disk.sys 044452051F3E02E7963599FC8F4F3E25
C:\WINDOWS\System32\drivers\dmboot.sys D71BE7C02B8B147E85456238D0660478
C:\WINDOWS\System32\DRIVERS\dmio.sys 5F25DE6F05C986DCC36ADAF532C3CE0D
C:\WINDOWS\system32\Drivers\dmload.sys E9317282A63CA4D188C0DF5E09C6AC5F
C:\WINDOWS\System32\drivers\DMusic.sys 8A208DFCF89792A484E76C40E5F50B45
C:\WINDOWS\System32\drivers\drmkaud.sys 8F5FCFF8E8848AFAC920905FBD9D33C8
C:\WINDOWS\system32\Drivers\exFat.sys 4D893323DAE445E34A4C9038B0551BC9
C:\WINDOWS\system32\Drivers\Fastfat.sys 38D332A6D56AF32635675F132548343E
C:\WINDOWS\System32\DRIVERS\fdc.sys 92CDD60B6730B9F50F6A1A0C1F8CDC81
C:\WINDOWS\system32\Drivers\Fips.sys 1541A3A7A460DECD6A2221065794A0DE
C:\WINDOWS\System32\DRIVERS\flpydisk.sys 9D27E7B80BFCDF1CDD9B555862D5E7F0
C:\WINDOWS\System32\DRIVERS\fltMgr.sys B2CF4B0786F8212CB92ED2B50C6DB6B0
C:\WINDOWS\system32\Drivers\Fs_Rec.sys 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A
C:\WINDOWS\System32\DRIVERS\ftdisk.sys FDD9E4CF0C558F64A58115CB2FC197AC
C:\WINDOWS\System32\DRIVERS\msgpc.sys 0A02C63C8B144BD8C86B103DEE7C86A2
C:\WINDOWS\System32\DRIVERS\HDAudBus.sys 573C7D0A32852B48F3058CFD8026F511
C:\WINDOWS\System32\Drivers\HTTP.sys F6AACF5BCE2893E0C1754AFEB672E5C9
C:\WINDOWS\System32\DRIVERS\i8042prt.sys F9850BDD47DFFD2797E984FE60C8B3B6
C:\WINDOWS\System32\DRIVERS\igxpmp32.sys 0F68E2EC713F132FFB19E45415B09679
C:\WINDOWS\System32\DRIVERS\ibank2key.sys 97B7684AA3A8259C23BD5DCB1F5D747C
C:\WINDOWS\System32\DRIVERS\imapi.sys 083A052659F5310DD8B6A6CB05EDCF8E
C:\WINDOWS\System32\drivers\RtkHDAud.sys B2957D6C1226F029230DAC2C46D34286
C:\WINDOWS\System32\DRIVERS\intelppm.sys 5151DFF0FAA3CCCC38A9DE9B4001D09B
C:\WINDOWS\System32\DRIVERS\ipfnd51.sys 8A1C8AC6BDFD0A378B0E657FD3E41270
C:\WINDOWS\System32\DRIVERS\Ip6Fw.sys 3BB22519A194418D5FEC05D800A19AD0
C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys 731F22BA402EE4B62748ADAF6363C182
C:\WINDOWS\System32\DRIVERS\ipinip.sys B87AB476DCF76E72010632B5550955F5
C:\WINDOWS\System32\DRIVERS\ipnat.sys CC748EA12C6EFFDE940EE98098BF96BB
C:\WINDOWS\System32\DRIVERS\ipsec.sys 23C74D75E36E7158768DD63D92789A91
C:\WINDOWS\System32\DRIVERS\irenum.sys C93C9FF7B04D772627A3646D89F7BF89
C:\WINDOWS\System32\DRIVERS\isapnp.sys 1C93959977CAD7168B4C816E8B29FE9B
C:\WINDOWS\System32\DRIVERS\kbdclass.sys 2B0018DE01BFB628D0A49A301F34B46F
C:\WINDOWS\System32\drivers\kmixer.sys 692BCF44383D056AED41B045A323D378
C:\WINDOWS\system32\Drivers\KSecDD.sys B467646C54CC746128904E1654C750C1
C:\WINDOWS\system32\Drivers\mnmdd.sys 4AE068242760A1FB6E1A44BF4E16AFA6
C:\WINDOWS\system32\Drivers\Modem.sys 5BCED2C68331A18534AB8DBAE71D93FC
C:\WINDOWS\System32\DRIVERS\mouclass.sys CBB891FDA0C5EC9F557ABBA86CA5CB76
C:\WINDOWS\system32\Drivers\MountMgr.sys A80B9A0BAD1B73637DBCBBA7DF72D3FD
C:\WINDOWS\System32\DRIVERS\mrxdav.sys 11D42BB6206F33FBB3BA0288D3EF81BD
C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 7D304A5EB4344EBEEAB53A2FE3FFB9F0
C:\WINDOWS\system32\Drivers\Msfs.sys C941EA2454BA8350021D774DAF0F1027
C:\WINDOWS\System32\drivers\MSKSSRV.sys D1575E71568F4D9E14CA56B7B0453BF1
C:\WINDOWS\System32\drivers\MSPCLOCK.sys 325BB26842FC7CCC1FCCE2C457317F3E
C:\WINDOWS\System32\drivers\MSPQM.sys BAD59648BA099DA4A17680B39730CB3D
C:\WINDOWS\System32\DRIVERS\mssmbios.sys AF5F4F3F14A8EA2C26DE30F7A1E17136
C:\WINDOWS\system32\Drivers\Mup.sys DE6A75F5C270E756C5508D94B6CF68F5
C:\WINDOWS\system32\Drivers\NDIS.sys 1DF7F42665C94B825322FAE71721130D
C:\WINDOWS\System32\DRIVERS\ndistapi.sys 0109C4F3850DFBAB279542515386AE22
C:\WINDOWS\System32\DRIVERS\ndisuio.sys F927A4434C5028758A842943EF1A3849
C:\WINDOWS\System32\DRIVERS\ndiswan.sys EDC1531A49C80614B2CFDA43CA8659AB
C:\WINDOWS\system32\Drivers\NDProxy.sys 2F597BB467E05B1FE3830EABD821B8E0
C:\WINDOWS\System32\DRIVERS\netbios.sys 5D81CF9A2F1A3A756B66CF684911CDF0
C:\WINDOWS\System32\DRIVERS\netbt.sys 74B2B2F5BEA5E9A3DC021D685551BD3D
C:\WINDOWS\system32\Drivers\Npfs.sys 3182D64AE053D6FB034F44B6DEF8034A
C:\WINDOWS\system32\Drivers\Ntfs.sys 78A08DD6A8D65E697C18E1DB01C5CDCA
C:\WINDOWS\system32\Drivers\Null.sys 73C1E1F395918BC2C6DD67AF7591A3AD
C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys B305F3FAD35083837EF46A0BBCE2FC57
C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys C99B3415198D1AAB7227F2C88FD664B9
C:\WINDOWS\System32\DRIVERS\parport.sys FA3A44ADE1D355BE8E29D3B6BF0BA702
C:\WINDOWS\system32\Drivers\PartMgr.sys BEB3BA25197665D82EC7065B724171C6
C:\WINDOWS\system32\Drivers\ParVdm.sys F6167F46184C50A9BC2FEB87067D1B97
C:\WINDOWS\System32\DRIVERS\pci.sys F9B93D158C4D9F54FBDF1A9C807A1A5A
C:\WINDOWS\System32\DRIVERS\pciide.sys 0D5EA82E0B16FA4C162635FA78E2DDC3
C:\WINDOWS\system32\Drivers\Pcmcia.sys B266A636C370476F25D307B30894D990
C:\WINDOWS\System32\DRIVERS\raspptp.sys EFEEC01B1D3CF84F16DDD24D9D9D8F99
C:\WINDOWS\System32\DRIVERS\psched.sys 09298EC810B07E5D582CB3A3F9255424
C:\WINDOWS\System32\DRIVERS\ptilink.sys 80D317BD1C3DBC5D4FE7B1678C60CADD
C:\WINDOWS\System32\DRIVERS\smccard.sys E545DE0D80BFD0D03788DB1D6D028DE3
C:\WINDOWS\System32\DRIVERS\rasacd.sys FE0D99D6F31E4FAD8159F690D68DED9C
C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 11B4A627BC9614B885C4969BFA5FF8A6
C:\WINDOWS\System32\DRIVERS\raspppoe.sys 5BC962F2654137C9909C3D4603587DEE
C:\WINDOWS\System32\DRIVERS\raspti.sys FDBB1D60066FCFBB7452FD8F9829B242
C:\WINDOWS\System32\DRIVERS\rdbss.sys 7AD224AD1A1437FE28D89CF22B17780A
C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 4912D5B403614CE99C28420F75353332
C:\WINDOWS\System32\DRIVERS\rdpdr.sys 15CABD0F7C00C47C70124907916AF3F1
C:\WINDOWS\system32\Drivers\RDPWD.sys 43AF5212BD8FB5BA6EED9754358BD8F7
C:\WINDOWS\System32\DRIVERS\redbook.sys 868C8DE05325F3B250F806666DE18F0D
C:\WINDOWS\System32\DRIVERS\rspndr.sys 743D7D59767073A617B1DCC6C546F234
C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys 839141088AD7EE90F5B441B2D1AFD22C
C:\WINDOWS\System32\DRIVERS\secdrv.sys ==> MD5 is legit
C:\WINDOWS\System32\DRIVERS\serenum.sys 0F29512CCD6BEAD730039FB4BD2C85CE
C:\WINDOWS\System32\DRIVERS\serial.sys 27645AE9DCC60BE467F3C92DDABED1B0
C:\WINDOWS\system32\Drivers\Sfloppy.sys 8E6B8C671615D126FDC553D1E2DE5562
C:\WINDOWS\System32\drivers\splitter.sys AB8B92451ECB048A4D1DE7C3FFCB4A9F
C:\WINDOWS\System32\Drivers\sptd.sys 71E276F6D189413266EA22171806597B
C:\WINDOWS\System32\DRIVERS\sr.sys 4A7B3B22C87F0897A68821734AFE9528
C:\WINDOWS\System32\DRIVERS\srv.sys 47DDFC2F003F7F9F0592C6874962A2E7
C:\WINDOWS\System32\DRIVERS\swenum.sys 3941D127AEF12E93ADDF6FE6EE027E0F
C:\WINDOWS\System32\drivers\swmidi.sys 8CE882BCC6CF8A62F2B2323D95CB3D01
C:\WINDOWS\System32\drivers\sysaudio.sys 8B83F3ED0F1688B4958F77CD6D2BF290
C:\WINDOWS\System32\DRIVERS\tcpip.sys 9AEFA14BD6B182D61E3119FA5F436D3D
C:\WINDOWS\system32\Drivers\TDPIPE.sys 6471A66807F5E104E4885F5B67349397
C:\WINDOWS\system32\Drivers\TDTCP.sys C56B6D0402371CF3700EB322EF3AAF61
C:\WINDOWS\System32\DRIVERS\termdd.sys 88155247177638048422893737429D9E
C:\WINDOWS\system32\Drivers\Udfs.sys 5787B80C2E3C5E2F56C2A233D91FA2C9
C:\WINDOWS\System32\DRIVERS\update.sys 402DDC88356B1BAC0EE3DD1580C76A31
C:\WINDOWS\System32\DRIVERS\usbccgp.sys 1B611611C28D2DF25BC057D79C6F13FC
C:\WINDOWS\System32\DRIVERS\usbehci.sys 4BAC8DF07F1D8434FC640E677A62204E
C:\WINDOWS\System32\DRIVERS\usbhub.sys 1AB3CDDE553B6E064D2E754EFE20285C
C:\WINDOWS\System32\DRIVERS\usbprint.sys A717C8721046828520C9EDF31288FC00
C:\WINDOWS\System32\DRIVERS\usbscan.sys F8EDE2B6928970DCE3D5614C27D9E7F6
C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS A32426D9B14A089EAA1D922E0C5801A9
C:\WINDOWS\System32\DRIVERS\usbuhci.sys 26496F9DEE2D787FC3E61AD54821FFE6
C:\WINDOWS\system32\Drivers\uzexnjux.sys D565AD44C6C4D934AFAD3CA4196B09AA
C:\WINDOWS\System32\drivers\vga.sys 0D3A8FAFCEACD8B7625CD549757A7DF1
C:\WINDOWS\system32\Drivers\VolSnap.sys A79D899DFD0467C4DF29AF19902ECD18
C:\WINDOWS\System32\DRIVERS\wanarp.sys E20B95BAEDB550F32DD489265C1DA1F6
C:\WINDOWS\System32\drivers\wdmaud.sys 6768ACF64B18196494413695F0C3A00F
C:\WINDOWS\System32\DRIVERS\WudfPf.sys F15FEAFFFBB3644CCC80C5DA584E6311
C:\WINDOWS\System32\DRIVERS\wudfrd.sys 28B524262BCE6DE1F7EF9F510BA3985B
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Three Months Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-03 11:44 - 2015-08-03 11:46 - 00000000 ____D C:\FRST
2015-08-03 11:39 - 2015-08-03 11:40 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\новый сайт помощи
2015-08-03 11:39 - 2015-08-03 11:39 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Новая папка
2015-07-29 17:04 - 2015-07-29 17:04 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Application Data\www.shadowexplorer.com
2015-07-29 16:49 - 2015-07-29 16:49 - 00065536 _____ C:\WINDOWS\Minidump\Mini072915-01.dmp
2015-07-29 16:29 - 2015-07-29 16:29 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\www.shadowexplorer.com
2015-07-29 16:27 - 2015-07-29 16:27 - 00000000 ____D C:\Documents and Settings\1\Application Data\www.shadowexplorer.com
2015-07-29 16:21 - 2015-07-29 16:21 - 00006766 _____ C:\WINDOWS\iis6.log
2015-07-29 16:21 - 2015-07-29 16:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallXPSEPSCLP$
2015-07-29 16:18 - 2008-07-06 19:06 - 01676288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpssvcs.dll
2015-07-29 16:18 - 2008-07-06 19:06 - 00575488 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\xpsshhdr.dll
2015-07-29 16:18 - 2008-07-06 19:06 - 00089088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll
2015-07-29 16:18 - 2008-07-06 17:50 - 00597504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
2015-07-29 16:12 - 2015-07-29 16:12 - 00000000 __RHD C:\AHCache
2015-07-29 15:44 - 2015-07-29 15:44 - 00001804 _____ C:\Documents and Settings\All Users\Главное меню\Программы\Adobe Reader XI.lnk
2015-07-29 15:44 - 2015-07-29 15:44 - 00001734 _____ C:\Documents and Settings\All Users\Рабочий стол\Adobe Reader XI.lnk
2015-07-29 15:44 - 2015-07-29 15:44 - 00000000 ____D C:\Program Files\Adobe
2015-07-29 14:37 - 2015-07-29 14:59 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-07-29 14:12 - 2015-07-29 14:12 - 00000000 ____D C:\Documents and Settings\1\Application Data\gnupg
2015-07-29 13:16 - 2015-07-29 13:39 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HitmanPro
2015-07-29 13:08 - 2015-07-29 16:09 - 00000000 ___RD C:\Documents and Settings\1\Рабочий стол\и опять снова
2015-07-29 12:39 - 2015-07-29 12:54 - 00000000 ____D C:\WINDOWS\pss
2015-07-27 15:25 - 2015-07-29 15:34 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\только что
2015-07-27 11:02 - 2015-07-28 11:26 - 00000000 ___RD C:\Documents and Settings\1\Рабочий стол\Farbar
2015-07-23 11:37 - 2015-07-23 11:37 - 00065536 _____ C:\WINDOWS\Minidump\Mini072315-01.dmp
2015-07-21 17:21 - 2015-07-21 17:21 - 00009208 _____ C:\WINDOWS\KB968389.log
2015-07-21 17:21 - 2015-07-21 17:21 - 00008660 _____ C:\WINDOWS\KB975467.log
2015-07-21 17:21 - 2015-07-21 17:21 - 00008404 _____ C:\WINDOWS\KB973815.log
2015-07-21 17:21 - 2015-07-21 17:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB975467$
2015-07-21 17:21 - 2015-07-21 17:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB973815$
2015-07-21 17:21 - 2015-07-21 17:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB968389$
2015-07-21 15:12 - 2015-07-21 15:12 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2015-07-21 15:11 - 2015-07-21 15:11 - 00000124 _____ C:\Documents and Settings\1\Local Settings\Application Data\fusioncache.dat
2015-07-21 15:07 - 2015-07-21 15:07 - 00000000 ____D C:\Documents and Settings\All Users\Главное меню\Программы\HP
2015-07-21 15:07 - 2015-07-21 15:07 - 00000000 ____D C:\Documents and Settings\1\Главное меню\Программы\HP
2015-07-21 15:02 - 2006-05-26 14:10 - 00049152 _____ C:\WINDOWS\system32\HPMLVS.dll
2015-07-21 15:02 - 2006-05-25 13:44 - 00014848 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\agmcrdrv.dll
2015-07-21 15:02 - 2006-05-25 13:40 - 00178176 _____ (Software 2000 Limited) C:\WINDOWS\system32\HP1005LM.DLL
2015-07-21 15:02 - 2005-10-08 00:35 - 00182784 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lfpng13n.dll
2015-07-21 15:02 - 2005-10-08 00:35 - 00145920 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lttw213n.dll
2015-07-21 15:02 - 2005-10-08 00:35 - 00067072 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltpdg13n.dll
2015-07-21 15:02 - 2005-10-08 00:34 - 00388608 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lfcmp13n.dll
2015-07-21 15:02 - 2005-10-08 00:33 - 01009664 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\Ltwvc13n.dll
2015-07-21 15:02 - 2005-10-08 00:33 - 00142848 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lftif13n.dll
2015-07-21 15:02 - 2005-10-08 00:32 - 01693696 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltclr13n.dll
2015-07-21 15:02 - 2005-10-08 00:31 - 01402368 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltdlg13n.dll
2015-07-21 15:02 - 2005-10-08 00:30 - 00090112 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lfjbg13n.dll
2015-07-21 15:02 - 2005-10-08 00:30 - 00027648 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lfiff13n.dll
2015-07-21 15:02 - 2005-10-08 00:29 - 00445440 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltimg13n.dll
2015-07-21 15:02 - 2005-10-08 00:29 - 00265216 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\LTDIS13n.dll
2015-07-21 15:02 - 2005-10-08 00:29 - 00206848 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltefx13n.dll
2015-07-21 15:02 - 2005-10-08 00:29 - 00154112 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltfil13n.dll
2015-07-21 15:02 - 2005-10-08 00:29 - 00030208 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltwnd13n.dll
2015-07-21 15:02 - 2005-10-08 00:29 - 00030208 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lfbmp13n.dll
2015-07-21 15:02 - 2005-10-08 00:28 - 00453120 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltkrn13n.dll
2015-07-21 15:02 - 2005-09-15 07:00 - 00080384 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\LTCON13n.dll
2015-07-21 15:02 - 2005-07-26 22:40 - 00237568 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\lteml13n.dll
2015-07-21 15:02 - 2003-11-13 23:06 - 00158720 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltpnt13n.dll
2015-07-21 15:02 - 2003-02-06 23:15 - 00897536 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltrtn13n.dll
2015-07-21 15:02 - 2002-12-12 03:49 - 00708608 _____ C:\WINDOWS\system32\ltcry13n.dll
2015-07-21 15:02 - 2001-11-20 03:27 - 00825344 _____ (LEAD Technologies, Inc.) C:\WINDOWS\system32\ltwen13n.dll
2015-07-21 14:44 - 2015-07-21 14:44 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\PCHealth
2015-07-21 14:44 - 2006-05-25 13:44 - 01060864 ____R (Hewlett-Packard Company) C:\WINDOWS\system32\agtwain.ds
2015-07-20 12:38 - 2015-07-20 12:39 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\Grym
2015-07-20 11:29 - 2015-07-20 11:29 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\GHISLER
2015-07-20 10:32 - 2015-07-21 14:37 - 00000232 _____ C:\WINDOWS\Tasks\Уведомление о завершении поддержки Microsoft Windows XP ежемесячно.job
2015-07-20 10:31 - 2015-07-29 16:29 - 00069232 _____ C:\Documents and Settings\Администратор\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-07-20 10:31 - 2015-07-20 10:31 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\HP
2015-07-20 10:18 - 2015-07-24 12:33 - 00000000 ____D C:\Documents and Settings\Администратор\Мои документы\Заново
2015-07-20 10:17 - 2015-07-20 10:17 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\WinRAR
2015-07-17 15:33 - 2015-07-17 15:33 - 00045779 _____ C:\WINDOWS\KB952954.log
2015-07-17 15:33 - 2015-07-17 15:33 - 00045607 _____ C:\WINDOWS\KB951376-v2.log
2015-07-17 15:33 - 2015-07-17 15:33 - 00045408 _____ C:\WINDOWS\KB959426.log
2015-07-17 15:33 - 2015-07-17 15:33 - 00044331 _____ C:\WINDOWS\KB946648.log
2015-07-17 15:33 - 2015-07-17 15:33 - 00044060 _____ C:\WINDOWS\KB2868626.log
2015-07-17 15:33 - 2015-07-17 15:33 - 00043419 _____ C:\WINDOWS\KB2922229.log
2015-07-17 15:33 - 2015-07-17 15:33 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB959426$
2015-07-17 15:33 - 2015-07-17 15:33 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB952954$
2015-07-17 15:33 - 2015-07-17 15:33 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB951376-v2$
2015-07-17 15:33 - 2015-07-17 15:33 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB946648$
2015-07-17 15:33 - 2015-07-17 15:33 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2922229$
2015-07-17 15:33 - 2015-07-17 15:33 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2015-07-17 15:31 - 2015-07-17 15:31 - 00044439 _____ C:\WINDOWS\KB2387149.log
2015-07-17 15:31 - 2015-07-17 15:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2387149$
2015-07-17 15:30 - 2015-07-17 15:31 - 00044244 _____ C:\WINDOWS\KB2712808.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00043918 _____ C:\WINDOWS\KB960859.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00043801 _____ C:\WINDOWS\KB2479943.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00041422 _____ C:\WINDOWS\KB2659262.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00041288 _____ C:\WINDOWS\KB2478971.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00041084 _____ C:\WINDOWS\KB2564958.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00039477 _____ C:\WINDOWS\KB2916036.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00038779 _____ C:\WINDOWS\KB2934207.log
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB960859$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2934207$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2916036$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2712808$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2659262$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2564958$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2479943$
2015-07-17 15:30 - 2015-07-17 15:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2478971$
2015-07-17 15:28 - 2015-07-21 17:21 - 00051070 _____ C:\WINDOWS\KB2585542.log
2015-07-17 15:28 - 2015-07-17 15:28 - 00040906 _____ C:\WINDOWS\KB2536276-v2.log
2015-07-17 15:28 - 2015-07-17 15:28 - 00040505 _____ C:\WINDOWS\KB2544893-v2.log
2015-07-17 15:28 - 2015-07-17 15:28 - 00038135 _____ C:\WINDOWS\KB2834886.log
2015-07-17 15:28 - 2015-07-17 15:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2015-07-17 15:28 - 2015-07-17 15:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2585542$
2015-07-17 15:28 - 2015-07-17 15:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2544893-v2$
2015-07-17 15:28 - 2015-07-17 15:28 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2536276-v2$
2015-07-17 15:27 - 2015-07-17 15:28 - 00040512 _____ C:\WINDOWS\KB2631813.log
2015-07-17 15:27 - 2015-07-17 15:27 - 00040988 _____ C:\WINDOWS\KB2691442.log
2015-07-17 15:27 - 2015-07-17 15:27 - 00040007 _____ C:\WINDOWS\KB2115168.log
2015-07-17 15:27 - 2015-07-17 15:27 - 00038291 _____ C:\WINDOWS\KB2296011.log
2015-07-17 15:27 - 2015-07-17 15:27 - 00037549 _____ C:\WINDOWS\KB2900986.log
2015-07-17 15:27 - 2015-07-17 15:27 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2015-07-17 15:27 - 2015-07-17 15:27 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2691442$
2015-07-17 15:27 - 2015-07-17 15:27 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2631813$
2015-07-17 15:27 - 2015-07-17 15:27 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2296011$
2015-07-17 15:27 - 2015-07-17 15:27 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2115168$
2015-07-17 15:26 - 2015-08-03 11:28 - 00000260 _____ C:\WINDOWS\Tasks\WGASetup.job
2015-07-17 15:26 - 2015-07-21 17:21 - 00050191 _____ C:\WINDOWS\KB955759.log
2015-07-17 15:26 - 2015-07-17 15:26 - 00040784 _____ C:\WINDOWS\KB975558.log
2015-07-17 15:26 - 2015-07-17 15:26 - 00037467 _____ C:\WINDOWS\KB2847311.log
2015-07-17 15:26 - 2015-07-17 15:26 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB975558_WM8$
2015-07-17 15:26 - 2015-07-17 15:26 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB955759$
2015-07-17 15:26 - 2015-07-17 15:26 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2015-07-17 15:22 - 2015-07-17 15:22 - 00038841 _____ C:\WINDOWS\KB974318.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00038388 _____ C:\WINDOWS\KB951978.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00037706 _____ C:\WINDOWS\KB2655992.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00037669 _____ C:\WINDOWS\KB2378111.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00037397 _____ C:\WINDOWS\KB2443105.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00037373 _____ C:\WINDOWS\KB969059.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00037017 _____ C:\WINDOWS\KB2802968.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00036526 _____ C:\WINDOWS\KB2229593.log
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB974318$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB969059$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB951978$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2802968$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2655992$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2443105$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2378111_WM9$
2015-07-17 15:22 - 2015-07-17 15:22 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2229593$
2015-07-17 15:21 - 2015-07-17 15:22 - 00035700 _____ C:\WINDOWS\KB2888505.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00034181 _____ C:\WINDOWS\KB950974.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00034036 _____ C:\WINDOWS\KB2481109.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00033153 _____ C:\WINDOWS\KB975713.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00032839 _____ C:\WINDOWS\KB2598479.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00032286 _____ C:\WINDOWS\KB2485663.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00032273 _____ C:\WINDOWS\KB2686509.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00031939 _____ C:\WINDOWS\KB971657.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00031860 _____ C:\WINDOWS\KB2898715.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00031799 _____ C:\WINDOWS\KB982132.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00030479 _____ C:\WINDOWS\KB2862335.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00029417 _____ C:\WINDOWS\KB2929961.log
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB982132$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB975713$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB971657$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB950974$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2929961$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2898715$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2888505$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2686509$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2598479$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2485663$
2015-07-17 15:21 - 2015-07-17 15:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2481109$
2015-07-17 15:20 - 2015-07-17 15:20 - 00031976 _____ C:\WINDOWS\KB978338.log
2015-07-17 15:20 - 2015-07-17 15:20 - 00031528 _____ C:\WINDOWS\KB2507938.log
2015-07-17 15:20 - 2015-07-17 15:20 - 00030894 _____ C:\WINDOWS\KB954155.log
2015-07-17 15:20 - 2015-07-17 15:20 - 00029390 _____ C:\WINDOWS\KB2834904-v2.log
2015-07-17 15:20 - 2015-07-17 15:20 - 00029369 _____ C:\WINDOWS\KB2909212.log
2015-07-17 15:20 - 2015-07-17 15:20 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB978338$
2015-07-17 15:20 - 2015-07-17 15:20 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB954155_WM9$
2015-07-17 15:20 - 2015-07-17 15:20 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2909212$
2015-07-17 15:20 - 2015-07-17 15:20 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2015-07-17 15:20 - 2015-07-17 15:20 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2507938$
2015-07-17 15:19 - 2015-07-17 15:20 - 00031660 _____ C:\WINDOWS\KB2780091.log
2015-07-17 15:19 - 2015-07-17 15:20 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2780091$
2015-07-17 15:19 - 2015-07-17 15:19 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB972270$
2015-07-17 15:18 - 2015-07-17 15:18 - 00033587 _____ C:\WINDOWS\KB956572.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00032276 _____ C:\WINDOWS\KB2510581.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00031441 _____ C:\WINDOWS\KB974112.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00028033 _____ C:\WINDOWS\KB956844.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00026507 _____ C:\WINDOWS\KB2876217.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00026440 _____ C:\WINDOWS\KB2904266.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00006810 _____ C:\WINDOWS\system32\TZLog.log
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB974112$
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB956844$
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB956572$
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2904266$
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876217$
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2510581$
2015-07-17 15:18 - 2015-07-17 15:18 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2347290$
2015-07-17 15:17 - 2015-07-17 15:18 - 00029124 _____ C:\WINDOWS\KB2483185.log
2015-07-17 15:17 - 2015-07-17 15:17 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2483185$
2015-07-17 15:15 - 2015-07-17 15:15 - 00029366 _____ C:\WINDOWS\KB979687.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00028282 _____ C:\WINDOWS\KB952004.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00027895 _____ C:\WINDOWS\KB2719985.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00027520 _____ C:\WINDOWS\KB973869.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00027420 _____ C:\WINDOWS\KB975025.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00026745 _____ C:\WINDOWS\KB974571.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00025682 _____ C:\WINDOWS\KB2930275.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00025104 _____ C:\WINDOWS\KB2864063.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00024440 _____ C:\WINDOWS\KB2862152.log
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB979687$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB975025$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB974571$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB973869$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB952004$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2930275$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2864063$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2015-07-17 15:15 - 2015-07-17 15:15 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2719985$
2015-07-17 15:14 - 2015-07-17 15:15 - 00026262 _____ C:\WINDOWS\KB2592799.log
2015-07-17 15:14 - 2015-07-17 15:14 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB975560$
2015-07-17 15:14 - 2015-07-17 15:14 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2592799$
2015-07-17 15:12 - 2015-07-17 15:12 - 00026235 _____ C:\WINDOWS\KB973507.log
2015-07-17 15:12 - 2015-07-17 15:12 - 00025782 _____ C:\WINDOWS\KB2535512.log
2015-07-17 15:12 - 2015-07-17 15:12 - 00025780 _____ C:\WINDOWS\KB950762.log
2015-07-17 15:12 - 2015-07-17 15:12 - 00025513 _____ C:\WINDOWS\KB977816.log
2015-07-17 15:12 - 2015-07-17 15:12 - 00023062 _____ C:\WINDOWS\KB2850869.log
2015-07-17 15:12 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB977816$
2015-07-17 15:12 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB973507$
2015-07-17 15:12 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB950762$
2015-07-17 15:12 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850869$
2015-07-17 15:12 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2770660$
2015-07-17 15:12 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2535512$
2015-07-17 15:11 - 2015-07-17 15:12 - 00023370 _____ C:\WINDOWS\KB2876331.log
2015-07-17 15:11 - 2015-07-17 15:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2015-07-17 15:11 - 2015-07-17 15:11 - 00025498 _____ C:\WINDOWS\KB2807986.log
2015-07-17 15:11 - 2015-07-17 15:11 - 00024960 _____ C:\WINDOWS\KB2570947.log
2015-07-17 15:11 - 2015-07-17 15:11 - 00023773 _____ C:\WINDOWS\KB2859537.log
2015-07-17 15:11 - 2015-07-17 15:11 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2859537$
2015-07-17 15:11 - 2015-07-17 15:11 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2807986$
2015-07-17 15:11 - 2015-07-17 15:11 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2570947$
2015-07-17 15:09 - 2015-07-17 15:09 - 00025259 _____ C:\WINDOWS\KB2820917.log
2015-07-17 15:09 - 2015-07-17 15:09 - 00024953 _____ C:\WINDOWS\KB952287.log
2015-07-17 15:09 - 2015-07-17 15:09 - 00024358 _____ C:\WINDOWS\KB978695.log
2015-07-17 15:09 - 2015-07-17 15:09 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB978695_WM9$
2015-07-17 15:09 - 2015-07-17 15:09 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB952287$
2015-07-17 15:09 - 2015-07-17 15:09 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2820917$
2015-07-17 15:06 - 2015-07-17 15:06 - 00025516 _____ C:\WINDOWS\KB973904.log
2015-07-17 15:06 - 2015-07-17 15:06 - 00024395 _____ C:\WINDOWS\KB2603381.log
2015-07-17 15:06 - 2015-07-17 15:06 - 00022357 _____ C:\WINDOWS\KB2893294.log
2015-07-17 15:06 - 2015-07-17 15:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB973904$
2015-07-17 15:06 - 2015-07-17 15:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893294$
2015-07-17 15:06 - 2015-07-17 15:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2603381$
2015-07-17 15:04 - 2015-07-29 16:21 - 00003350 _____ C:\WINDOWS\spupdsvc.log
2015-07-17 15:04 - 2015-07-17 15:04 - 00025984 _____ C:\WINDOWS\KB2419632.log
2015-07-17 15:04 - 2015-07-17 15:04 - 00024435 _____ C:\WINDOWS\KB2757638.log
2015-07-17 15:04 - 2015-07-17 15:04 - 00019119 _____ C:\WINDOWS\KB2508429.log
2015-07-17 15:04 - 2015-07-17 15:04 - 00018382 _____ C:\WINDOWS\KB2653956.log
2015-07-17 15:04 - 2015-07-17 15:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB973540_WM9$
2015-07-17 15:04 - 2015-07-17 15:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2757638$
2015-07-17 15:04 - 2015-07-17 15:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2653956$
2015-07-17 15:04 - 2015-07-17 15:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2508429$
2015-07-17 15:04 - 2015-07-17 15:04 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2419632$
2015-07-17 15:03 - 2015-07-17 15:03 - 00017967 _____ C:\WINDOWS\KB974392.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00017465 _____ C:\WINDOWS\KB2749655.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00017025 _____ C:\WINDOWS\KB971029.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00016888 _____ C:\WINDOWS\KB952069.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00016747 _____ C:\WINDOWS\KB977914.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00016707 _____ C:\WINDOWS\KB2698365.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00015781 _____ C:\WINDOWS\KB2506212.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00015398 _____ C:\WINDOWS\KB2705219-v2.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00014912 _____ C:\WINDOWS\KB2619339.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00013751 _____ C:\WINDOWS\KB2803821-v2.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00013182 _____ C:\WINDOWS\KB2892075.log
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB977914$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB974392$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB971029$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB952069_WM9$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2892075$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2803821-v2_WM9$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2749655$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2705219-v2$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2698365$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2619339$
2015-07-17 15:03 - 2015-07-17 15:03 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2506212$
2015-07-17 15:01 - 2015-07-17 15:01 - 00014061 _____ C:\WINDOWS\KB978542.log
2015-07-17 15:01 - 2015-07-17 15:01 - 00013869 _____ C:\WINDOWS\KB2727528.log
2015-07-17 15:01 - 2015-07-17 15:01 - 00013849 _____ C:\WINDOWS\KB979309.log
2015-07-17 15:01 - 2015-07-17 15:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB979309$
2015-07-17 15:01 - 2015-07-17 15:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB978542$
2015-07-17 15:01 - 2015-07-17 15:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2727528$
2015-07-17 15:00 - 2015-07-21 17:21 - 00022919 _____ C:\WINDOWS\KB2509553.log
2015-07-17 15:00 - 2015-07-21 17:21 - 00022623 _____ C:\WINDOWS\KB960803.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00309306 _____ C:\WINDOWS\msxml4-KB973688-enu.LOG
2015-07-17 15:00 - 2015-07-17 15:00 - 00014256 _____ C:\WINDOWS\KB2723135-v2.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00013932 _____ C:\WINDOWS\KB2813345.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00013864 _____ C:\WINDOWS\KB981997.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00013852 _____ C:\WINDOWS\KB979482.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00013850 _____ C:\WINDOWS\KB978706.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00013705 _____ C:\WINDOWS\KB2676562.log
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB981997$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB979482$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB978706$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB960803$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2813345$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2723135-v2$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2676562$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2509553$
2015-07-17 15:00 - 2015-07-17 15:00 - 00000000 ____D C:\Program Files\MSXML 4.0
2015-07-17 14:57 - 2015-07-17 14:57 - 00010984 _____ C:\WINDOWS\KB982665.log
2015-07-17 14:57 - 2015-07-17 14:57 - 00008995 _____ C:\WINDOWS\KB954154.log
2015-07-17 14:57 - 2015-07-17 14:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB982665$
2015-07-17 14:57 - 2015-07-17 14:57 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB954154_WM11$
2015-07-17 14:55 - 2015-07-29 16:19 - 00030925 _____ C:\WINDOWS\updspapi.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00012721 _____ C:\WINDOWS\KB2393802.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00011148 _____ C:\WINDOWS\KB923561.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00009357 _____ C:\WINDOWS\KB2620712.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00009199 _____ C:\WINDOWS\KB2566454.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00009032 _____ C:\WINDOWS\KB2584146.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00008994 _____ C:\WINDOWS\KB2661637.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00007137 _____ C:\WINDOWS\KB2914368.log
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB923561$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2661637$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2620712$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2584146$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2566454$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2478960$
2015-07-17 14:55 - 2015-07-17 14:55 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2393802$
2015-07-17 14:54 - 2015-07-21 17:21 - 00000000 ___HD C:\WINDOWS\$hf_mig$
2015-07-17 14:54 - 2015-07-17 14:55 - 00009198 _____ C:\WINDOWS\KB2423089.log
2015-07-17 14:54 - 2015-07-17 14:54 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2423089$
2015-07-17 14:54 - 2007-11-30 19:39 - 00017272 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsg.dll
2015-07-17 14:44 - 2015-07-29 13:53 - 00000000 ___RD C:\Documents and Settings\1\Рабочий стол\ВСЁ ЗАНОВО
2015-07-17 14:32 - 2015-07-17 14:33 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\1235468886888
2015-07-17 14:29 - 2011-11-16 21:21 - 00354816 ____N (Microsoft Corporation) C:\WINDOWS\system32\SET1462.tmp
2015-07-17 14:28 - 2009-11-28 00:13 - 00017920 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msyuv.dll
2015-07-17 14:28 - 2008-06-15 00:35 - 00272512 ____N (Корпорация Майкрософт) C:\WINDOWS\system32\Drivers\bthport.sys
2015-07-17 14:28 - 2008-06-15 00:35 - 00272512 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\bthport.sys
2015-07-17 14:27 - 2014-02-27 06:28 - 00013312 ____N (Корпорация Майкрософт) C:\WINDOWS\system32\xp_eos.exe
2015-07-17 14:27 - 2014-02-27 06:28 - 00013312 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\xp_eos.exe
2015-07-17 14:26 - 2011-07-15 20:29 - 00456320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mrxsmb.sys
2015-07-17 14:24 - 2009-11-27 23:09 - 00048128 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\iyuv_32.dll
2015-07-17 14:24 - 2009-11-27 23:09 - 00008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tsbyuv.dll
2015-07-17 14:23 - 2013-07-03 09:12 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hidparse.sys
2015-07-17 14:23 - 2013-07-03 08:59 - 00014976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbscan.sys
2015-07-17 14:22 - 2011-03-03 13:54 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SET515.tmp
2015-07-17 14:21 - 2013-02-12 07:32 - 00012928 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usb8023x.sys
2015-07-17 14:16 - 2013-08-09 07:55 - 00144128 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbport.sys
2015-07-17 14:16 - 2013-08-09 07:55 - 00032384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbccgp.sys
2015-07-17 14:16 - 2013-08-09 07:55 - 00005376 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbd.sys
2015-07-17 14:16 - 2009-03-18 18:02 - 00030336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\usbehci.sys
2015-07-17 14:15 - 2013-07-04 14:34 - 02195328 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2015-07-17 14:15 - 2013-07-04 14:34 - 02151936 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2015-07-17 14:15 - 2013-07-04 14:34 - 02071936 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2015-07-17 14:15 - 2013-07-04 14:33 - 02030592 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2015-07-17 14:14 - 2012-01-12 02:07 - 00003072 ____N C:\WINDOWS\system32\iacenc.dll
2015-07-17 14:14 - 2012-01-12 02:07 - 00003072 ____C C:\WINDOWS\system32\dllcache\iacenc.dll
2015-07-17 13:31 - 2015-07-17 13:31 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Application Data\GHISLER
2015-07-17 13:31 - 2015-07-17 13:31 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Application Data\ABBYY
2015-07-17 13:31 - 2015-07-17 13:31 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\ABBYY
2015-07-17 13:27 - 2015-07-17 13:32 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Application Data\Adobe
2015-07-17 13:18 - 2015-07-17 14:07 - 00000000 ____D C:\Documents and Settings\Администратор\Doctor Web
2015-07-17 12:56 - 2007-12-19 16:11 - 00180224 _____ (Intel Corporation) C:\WINDOWS\system32\igfxres.dll
2015-07-17 12:55 - 2015-07-17 12:55 - 00000792 _____ C:\Documents and Settings\1\Главное меню\Программы\Проигрыватель Windows Media.lnk
2015-07-17 12:52 - 2008-04-15 19:00 - 00571392 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlgnt.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00482304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlgnt.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00461824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpsvc.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00455168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintsetp.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00426041 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\voicepad.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00364544 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\w3svc.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00358400 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpincl.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00259072 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpcl.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00236544 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smi2smir.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00229439 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\multibox.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00221696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\seo.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00188416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpsmir.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00185344 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\thawbrkr.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00175104 ____C C:\WINDOWS\system32\dllcache\pintlcsa.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winzm.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winsp.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00156672 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winpy.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00143422 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\softkey.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00131584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmxviceo.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00119808 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mtstocom.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00103936 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\uihelper.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00101376 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\srusbusd.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00086073 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\voicesub.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00083748 ____C C:\WINDOWS\system32\dllcache\prcp.nls
2015-07-17 12:52 - 2008-04-15 19:00 - 00083748 ____C C:\WINDOWS\system32\dllcache\prc.nls
2015-07-17 12:52 - 2008-04-15 19:00 - 00080384 ____C (Ricoh Co., Ltd.) C:\WINDOWS\system32\dllcache\rwia330.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00080384 ____C (Ricoh Co., Ltd.) C:\WINDOWS\system32\dllcache\rwia001.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00079360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winar30.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00079360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\phon.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00077824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\quick.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00076800 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\wam51.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00076288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\uniime.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00074240 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\w3ext.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00072704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wingb.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00070144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlphr.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00067584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmigrate.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00065536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\winime.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00065024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\unicdime.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00053760 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\nextlink.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00053760 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pintlcsd.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00053248 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wamreg51.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00048256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w32.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00046592 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\svcext51.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00046592 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sspifilt.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00045056 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\ssinc51.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00044544 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\nsepm.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00044032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tintlphr.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00041600 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\weitekp9.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00039936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpthrd.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00038912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm9aw.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00036927 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs411.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00033792 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\tools.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00032768 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\snmp.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smb6w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sma3w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pagecnt.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00031232 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\weitekp9.sys
2015-07-17 12:52 - 2008-04-15 19:00 - 00030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm87w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm81w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00029184 ____C (Ricoh Co.. Ltd.) C:\WINDOWS\system32\dllcache\rw330ext.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00029184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm8cw.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00028288 ____C C:\WINDOWS\system32\dllcache\xjis.nls
2015-07-17 12:52 - 2008-04-15 19:00 - 00027648 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\rw001ext.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm93w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm92w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm90w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm8dw.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm8aw.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm89w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\romanime.ime
2015-07-17 12:52 - 2008-04-15 19:00 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\sm59w.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00021896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdipx.sys
2015-07-17 12:52 - 2008-04-15 19:00 - 00020992 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\permchk.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00020736 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ramdisk.sys
2015-07-17 12:52 - 2008-04-15 19:00 - 00019464 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdspx.sys
2015-07-17 12:52 - 2008-04-15 19:00 - 00018944 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\simptcp.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00016896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\status.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00016384 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\quser.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smierrsm.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00015872 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs404.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00015360 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs804.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00014848 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\register.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00014336 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\tsprof.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\padrs412.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00013192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tdasync.sys
2015-07-17 12:52 - 2008-04-15 19:00 - 00011264 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\pmxmcro.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00010752 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpapi.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tmigrate.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpstup.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00009728 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\query.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00009728 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rwnh.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wamps51.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmptrap.exe
2015-07-17 12:52 - 2008-04-15 19:00 - 00007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pwsdata.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\snmpmib.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\pmxgl.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\w3svapi.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smimsgif.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smierrsy.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00004608 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\w3ctrs51.dll
2015-07-17 12:52 - 2008-04-15 19:00 - 00004096 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\rpcref.dll
2015-07-17 12:52 - 2001-10-19 22:06 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2015-07-17 12:52 - 2001-10-19 22:06 - 00038912 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2015-07-17 12:52 - 2001-10-19 22:06 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_seos.dll
2015-07-17 12:52 - 2001-10-19 22:06 - 00023040 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_regtrace.exe
2015-07-17 12:52 - 2001-10-19 22:06 - 00012800 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_smtpctrs.dll
2015-07-17 12:52 - 2001-10-19 22:06 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 13463552 ____C C:\WINDOWS\system32\dllcache\hwxjpn.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 10129408 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hwxkor.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 10096640 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hwxcht.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 01875968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msir3jp.lex
2015-07-17 12:51 - 2008-04-15 19:00 - 01677824 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chsbrkr.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 01158818 ____C C:\WINDOWS\system32\dllcache\korwbrkr.lex
2015-07-17 12:51 - 2008-04-15 19:00 - 00838144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtbrkr.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00811064 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjp81k.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00716856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpcus.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00562176 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsst.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00480256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintsetp.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00471102 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imskdic.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00451584 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsapi.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00400384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsxp32.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00397312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxstiff.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00373760 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\asp51.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00368696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpcic.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00340023 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjp81.ime
2015-07-17 12:51 - 2008-04-15 19:00 - 00332288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\aqueue.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00315455 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imskf.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00311359 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsv.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00307257 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00285184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscomex.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00274489 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputyc.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00268288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\httpext.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00268288 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxssvc.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00262200 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjputy.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00257024 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\infocomm.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00246272 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxst30.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00233984 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscover.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00233527 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjprw.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00218112 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_g18030.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00208952 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpmig.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00198656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintime.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00196665 ____C C:\WINDOWS\system32\dllcache\imjpinst.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00195618 ____C C:\WINDOWS\system32\dllcache\c_10002.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00193536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxswzrd.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00189986 ____C C:\WINDOWS\system32\dllcache\c_1361.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00187938 ____C C:\WINDOWS\system32\dllcache\c_20005.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00186402 ____C C:\WINDOWS\system32\dllcache\c_20001.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00185378 ____C C:\WINDOWS\system32\dllcache\c_20003.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00180770 ____C C:\WINDOWS\system32\dllcache\c_20932.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00180258 ____C C:\WINDOWS\system32\dllcache\c_20004.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00180258 ____C C:\WINDOWS\system32\dllcache\c_20000.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00177698 ____C C:\WINDOWS\system32\dllcache\c_20949.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00177698 ____C C:\WINDOWS\system32\dllcache\c_10003.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00173602 ____C C:\WINDOWS\system32\dllcache\c_20936.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00173602 ____C C:\WINDOWS\system32\dllcache\c_20002.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00173602 ____C C:\WINDOWS\system32\dllcache\c_10008.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00173568 ____C C:\WINDOWS\system32\dllcache\chtskf.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00162850 ____C C:\WINDOWS\system32\dllcache\c_10001.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00155705 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdsvr.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00155136 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsui.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00145408 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iische51.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00142848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsclnt.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00136704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsclntr.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00134339 ____C C:\WINDOWS\system32\dllcache\imekr.lex
2015-07-17 12:51 - 2008-04-15 19:00 - 00125952 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\ftpsv251.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00111104 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscfgwz.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00109056 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\appconf.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00108827 ____C C:\WINDOWS\system32\dllcache\hanja.lex
2015-07-17 12:51 - 2008-04-15 19:00 - 00106496 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrcic.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00104448 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\evntagnt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00102463 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imepadsm.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00102456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imlang.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00098304 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\msir3jp.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00097792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtmbx.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00094720 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekr61.ime
2015-07-17 12:51 - 2008-04-15 19:00 - 00092672 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\evntwin.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00092416 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mga.sys
2015-07-17 12:51 - 2008-04-15 19:00 - 00092032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mga.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00086016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmbx.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00085504 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\metada51.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00082172 ____C C:\WINDOWS\system32\dllcache\bopomofo.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00081976 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdct.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00079872 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iislog51.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00078848 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\dayi.ime
2015-07-17 12:51 - 2008-04-15 19:00 - 00078336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chajei.ime
2015-07-17 12:51 - 2008-04-15 19:00 - 00072192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxscom.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00070656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\korwbrkr.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00066728 ____C C:\WINDOWS\system32\dllcache\big5.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066594 ____C C:\WINDOWS\system32\dllcache\c_864.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066594 ____C C:\WINDOWS\system32\dllcache\c_862.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066594 ____C C:\WINDOWS\system32\dllcache\c_858.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066594 ____C C:\WINDOWS\system32\dllcache\c_720.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_870.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_708.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_28596.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_21027.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_21025.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20924.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20880.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20871.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20838.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20833.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20424.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20423.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20420.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20297.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20290.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20285.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20284.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20280.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20278.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20277.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20273.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20269.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20108.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20107.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20106.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_20105.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1149.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1148.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1147.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1146.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1145.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1144.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1143.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1142.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1141.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1140.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_1047.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_10021.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_10005.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00066082 ____C C:\WINDOWS\system32\dllcache\c_10004.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00061440 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\httpod51.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00060928 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iisclex4.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00059904 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imkrinst.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00059392 ____C C:\WINDOWS\system32\dllcache\imscinst.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00058368 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsevent.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00057856 ____C (SEIKO EPSON CORP.) C:\WINDOWS\system32\dllcache\esuimgd.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00057399 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cplexe.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00057398 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpdadm.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00056320 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\convlog.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00056320 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\chtskdic.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00054528 ____C (Philips Semiconductors GmbH) C:\WINDOWS\system32\dllcache\cap7146.sys
2015-07-17 12:51 - 2008-04-15 19:00 - 00050176 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\adrot.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00047066 ____C C:\WINDOWS\system32\dllcache\ksc.nls
2015-07-17 12:51 - 2008-04-15 19:00 - 00045568 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\browscap.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00045109 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imjpuex.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00045056 ____C (SEIKO EPSON CORP.) C:\WINDOWS\system32\dllcache\esunid.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00044032 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imekrmig.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00042496 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\davcdata.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00039936 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hostmib.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00037888 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\md5filt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00036864 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\hanjadic.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00035328 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\iprip.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lmmib2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00033792 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\controt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00032256 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\gzip.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00031744 ____C (SEIKO EPSON CORP.) C:\WINDOWS\system32\dllcache\esucmd.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00031744 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsroute.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00029696 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admexs.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00029184 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\asptxn.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00027136 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iscomlog.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\mdsync.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00026624 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsdrv.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00025856 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\et4000.sys
2015-07-17 12:51 - 2008-04-15 19:00 - 00025088 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\evntcmd.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00025088 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisadmin.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00024064 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\compfilt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00023552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsmon.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00023552 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsext32.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00022528 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\lpdsvc.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00022016 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\logscrpt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00021504 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cintlgnt.ime
2015-07-17 12:51 - 2008-04-15 19:00 - 00020480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\counters.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\cprofile.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iiscrmap.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0804.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0412.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0411.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt040d.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0404.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\agt0401.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00018944 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\lprmon.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00018432 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\jupiw.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00015872 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\chgport.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00015872 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\inetin51.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00014848 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\flattemp.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00014848 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\chgusr.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00014336 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\exstrace.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00013312 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\chglogon.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\lonsint.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00011264 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxssend.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00010752 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_iscii.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00010240 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\aspperf.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00009728 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\change.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnecat.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iwrps.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00009216 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\authfilt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00008704 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\infoctrs.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00008704 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsperf.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00008192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\httpmb51.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007680 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\ftpctrs2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\migregdb.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00007680 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnecnt.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdnec95.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdibm02.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isapips.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisfecnv.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\f3ahvoas.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006656 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iissync.exe
2015-07-17 12:51 - 2008-04-15 19:00 - 00006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlk41a.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fxsres.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006656 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\c_is2022.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth3.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdlk41j.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinpun.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdax2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd106n.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101a.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbd101.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftpmib.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftlx041e.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admxprox.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdvntc.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdusa.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdurdu.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth1.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdth0.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdsyr2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdsyr1.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdintel.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdintam.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinmar.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinkan.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinhin.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdinguj.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdindev.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdheb.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdfa.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbddiv2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbddiv1.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbda3.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbda2.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbda1.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdgeo.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdarmw.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00005120 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\kbdarme.dll
2015-07-17 12:51 - 2008-04-15 19:00 - 00003584 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iismui.dll
2015-07-17 12:51 - 2003-03-24 16:52 - 00024632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpadmcgi.exe
2015-07-17 12:51 - 2003-03-24 16:52 - 00020541 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpadmdll.dll
2015-07-17 12:51 - 2002-05-14 14:08 - 00094208 ____C C:\WINDOWS\system32\dllcache\fpencode.dll
2015-07-17 12:51 - 2001-10-19 22:06 - 00065536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_mailmsg.dll
2015-07-17 12:51 - 2001-10-19 22:06 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_fcachdll.dll
2015-07-17 12:51 - 2001-10-19 22:05 - 00045056 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_aqadmin.dll
2015-07-17 12:51 - 2001-10-19 22:05 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 02134528 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpsnap.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00832000 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\inetmgr.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00290816 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\adsiis51.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00274944 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\certwiz.ocx
2015-07-17 12:50 - 2008-04-15 19:00 - 00189952 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\smtpadm.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00171520 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iisui.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00133632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisrtl.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00095232 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\certmap.ocx
2015-07-17 12:50 - 2008-04-15 19:00 - 00077824 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\logui.ocx
2015-07-17 12:50 - 2008-04-15 19:00 - 00076288 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\cnfgprts.ocx
2015-07-17 12:50 - 2008-04-15 19:00 - 00068608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isatq.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00068608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisext51.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00064512 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iismap.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00046592 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\coadmin.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00043520 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admwprox.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00030720 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iisrstas.exe
2015-07-17 12:50 - 2008-04-15 19:00 - 00019968 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\inetsloc.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00014848 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\iisreset.exe
2015-07-17 12:50 - 2008-04-15 19:00 - 00013312 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\infoadmn.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00008192 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\staxmem.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00007680 ____C (Корпорация Майкрософт (Microsoft Corp.)) C:\WINDOWS\system32\dllcache\inetmgr.exe
2015-07-17 12:50 - 2008-04-15 19:00 - 00007168 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\wamregps.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00006144 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\ftpsapi2.dll
2015-07-17 12:50 - 2008-04-15 19:00 - 00005632 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\iisrstap.dll
2015-07-17 12:50 - 2004-05-13 01:39 - 00876653 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4awel.dll
2015-07-17 12:50 - 2004-05-13 01:39 - 00598071 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpmmc.dll
2015-07-17 12:50 - 2004-05-13 01:39 - 00184435 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4amsft.dll
2015-07-17 12:50 - 2003-04-14 21:36 - 00208896 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpmmcsat.dll
2015-07-17 12:50 - 2003-04-14 21:36 - 00016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tcptsat.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00188494 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpcount.exe
2015-07-17 12:50 - 2003-03-24 16:52 - 00188480 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\cfgwiz.exe
2015-07-17 12:50 - 2003-03-24 16:52 - 00147513 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4apws.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00102509 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4atxt.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00082035 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4anscp.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00049212 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4awebs.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00049210 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4areg.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00041020 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4avnb.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00032827 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\tcptest.exe
2015-07-17 12:50 - 2003-03-24 16:52 - 00032826 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp4avss.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00020541 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpexedll.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00020540 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\author.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00020540 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admin.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00020538 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fpremadm.exe
2015-07-17 12:50 - 2003-03-24 16:52 - 00020536 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shtml.dll
2015-07-17 12:50 - 2003-03-24 16:52 - 00016439 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\author.exe
2015-07-17 12:50 - 2003-03-24 16:52 - 00016439 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\admin.exe
2015-07-17 12:50 - 2003-03-24 16:52 - 00016437 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\shtml.exe
2015-07-17 12:50 - 2002-05-14 14:08 - 00109328 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp98swin.exe
2015-07-17 12:50 - 2002-05-14 14:08 - 00014608 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\fp98sadm.exe
2015-07-17 12:49 - 2015-07-17 12:49 - 00000749 ___RH C:\WINDOWS\WindowsShell.Manifest
2015-07-17 12:49 - 2015-07-17 12:49 - 00000749 ___RH C:\WINDOWS\system32\wuaucpl.cpl.manifest
2015-07-17 12:49 - 2015-07-17 12:49 - 00000749 ___RH C:\WINDOWS\system32\sapi.cpl.manifest
2015-07-17 12:49 - 2015-07-17 12:49 - 00000749 ___RH C:\WINDOWS\system32\nwc.cpl.manifest
2015-07-17 12:49 - 2015-07-17 12:49 - 00000749 ___RH C:\WINDOWS\system32\ncpa.cpl.manifest
2015-07-17 12:49 - 2015-07-17 12:49 - 00000488 ___RH C:\WINDOWS\system32\logonui.exe.manifest
2015-07-17 12:37 - 2015-07-29 16:18 - 00317966 _____ C:\WINDOWS\setupapi.log
2015-07-17 12:37 - 2008-04-15 19:00 - 02039397 ____C C:\WINDOWS\system32\dllcache\NT5.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 01233791 ____C C:\WINDOWS\system32\dllcache\SP3.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 01088840 ____C C:\WINDOWS\system32\dllcache\NTPRINT.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00809104 ____C C:\WINDOWS\system32\dllcache\NT5IIS.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00634592 ____C C:\WINDOWS\system32\dllcache\NT5INF.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00399670 ____C C:\WINDOWS\system32\dllcache\MAPIMIG.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00144484 ____C C:\WINDOWS\system32\dllcache\netfx.cat
2015-07-17 12:37 - 2008-04-15 19:00 - 00105628 ____C C:\WINDOWS\system32\dllcache\tabletpc.cat
2015-07-17 12:37 - 2008-04-15 19:00 - 00037509 ____C C:\WINDOWS\system32\dllcache\MW770.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00034747 ____C C:\WINDOWS\system32\dllcache\mediactr.cat
2015-07-17 12:37 - 2008-04-15 19:00 - 00033765 ____C C:\WINDOWS\system32\dllcache\FP4.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00024661 ____C (Perle Systems Ltd.) C:\WINDOWS\system32\dllcache\spxcoins.dll
2015-07-17 12:37 - 2008-04-15 19:00 - 00024661 _____ (Perle Systems Ltd.) C:\WINDOWS\system32\spxcoins.dll
2015-07-17 12:37 - 2008-04-15 19:00 - 00016825 ____C C:\WINDOWS\system32\dllcache\IMS.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00013497 ____C C:\WINDOWS\system32\dllcache\HPCRDP.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00013312 ____C (Корпорация Майкрософт) C:\WINDOWS\system32\dllcache\irclass.dll
2015-07-17 12:37 - 2008-04-15 19:00 - 00013312 _____ (Корпорация Майкрософт) C:\WINDOWS\system32\irclass.dll
2015-07-17 12:37 - 2008-04-15 19:00 - 00012363 ____C C:\WINDOWS\system32\dllcache\MSMSGS.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00010027 ____C C:\WINDOWS\system32\dllcache\MSTSWEB.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00008599 ____C C:\WINDOWS\system32\dllcache\IASNT4.CAT
2015-07-17 12:37 - 2008-04-15 19:00 - 00007382 ____C C:\WINDOWS\system32\dllcache\OEMBIOS.CAT
2015-07-17 12:18 - 2015-07-17 12:50 - 00001507 _____ C:\Documents and Settings\All Users\Главное меню\Windows Update.lnk
2015-07-17 12:17 - 2008-04-15 19:00 - 00016384 ____C (Microsoft Corporation) C:\WINDOWS\system32\dllcache\isignup.exe
2015-07-17 12:16 - 2015-07-17 12:50 - 00000792 _____ C:\Documents and Settings\Default User\Главное меню\Программы\Проигрыватель Windows Media.lnk
2015-07-17 12:16 - 2015-07-17 12:50 - 00000786 _____ C:\Documents and Settings\Default User\Рабочий стол\Проигрыватель Windows Media.lnk
2015-07-16 14:20 - 2015-07-17 11:45 - 00411504 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2052111302-1326574676-1417001333-1003-0.dat
2015-07-16 12:31 - 2015-07-29 14:53 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Package Cache
2015-07-16 12:31 - 2015-07-16 12:31 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Nichrome
2015-07-16 12:31 - 2015-07-16 12:31 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Chromium
2015-07-16 12:31 - 2015-07-16 12:31 - 00000000 ____D C:\Documents and Settings\1\Application Data\Opera Software
2015-07-16 12:30 - 2015-06-02 18:38 - 00057336 _____ ( ) C:\WINDOWS\system32\Drivers\adgnetworktdidrv.sys
2015-07-16 12:29 - 2015-07-17 10:46 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Temp
2015-07-16 12:29 - 2015-07-16 12:29 - 00000429 _____ C:\WINDOWS\system32\Drivers\vwifikerneldrv.sys
2015-07-16 12:29 - 2015-07-16 12:29 - 00000429 _____ C:\WINDOWS\system32\d3dx9_11.dll.tmp
2015-07-16 12:29 - 2015-07-16 12:29 - 00000429 _____ C:\Documents and Settings\All Users\Application Data\fontcacheev1.dat
2015-07-16 12:28 - 2015-07-16 12:28 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\Performix LLC
2015-07-16 12:28 - 2015-07-16 12:28 - 00000000 ____D C:\Documents and Settings\1\Application Data\Performix LLC
2015-07-16 12:27 - 2015-07-16 12:27 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache
2015-07-15 12:33 - 2015-07-17 13:27 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\Adobe
2015-07-15 12:33 - 2015-07-15 12:33 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\Macromedia
2015-07-15 12:32 - 2015-07-15 12:32 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Application Data\Yandex
2015-07-15 12:32 - 2015-07-15 12:32 - 00000000 ____D C:\Documents and Settings\Администратор\Application Data\Yandex
2015-07-15 12:31 - 2015-07-15 12:31 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Application Data\Google
2015-07-15 12:27 - 2015-07-15 13:59 - 00067327 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-VKFKIQDLFNHWDHKETMGHLMXPBCEFRSUVHIKL-15.07.2015 12@56@213160979.randomname-GLZGZNQARTVPUWHJVXQSWYRTXQJLPI.TDH.cbf
2015-07-15 12:27 - 2015-07-15 12:27 - 00000000 __SHD C:\WINDOWS\CSC
2015-07-15 10:35 - 2015-07-29 15:44 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Adobe
2015-07-15 10:33 - 2015-07-15 10:40 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\ПРГ 111111111
2015-07-13 10:54 - 2015-07-24 12:34 - 00011264 _____ C:\WINDOWS\system32\Drivers\uzexnjux.sys
2015-07-13 10:52 - 2015-07-17 11:39 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\AVZ
2015-07-13 10:31 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Новая папка (4)
2015-07-09 11:37 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\ЗАКЛЮЧЕНИЕ РУБЦОВСК
2015-07-08 11:14 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Заявление
2015-07-08 10:16 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\СНАПОК
2015-07-06 13:28 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Разьяснение оэкспертизе
2015-07-02 13:19 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Стройгаз
2015-06-23 12:38 - 2015-07-15 12:24 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\ЭКСПЕРТЫ
2015-06-23 12:38 - 2015-06-23 12:38 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Новая папка (3)
2015-06-19 13:10 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\временная аттестация экспертов
2015-06-18 11:01 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\заявление о переоформлении лецензии
2015-06-10 10:36 - 2015-07-15 12:24 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\ЮРИСТУ
2015-06-04 13:38 - 2015-07-24 13:23 - 00341810 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2015-06-04 12:40 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\положение об аттестации экспертов
2015-06-04 11:48 - 2015-06-04 11:48 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\DTClient
2015-06-04 10:35 - 2015-06-04 10:35 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\DAEMON Tools Ultra
2015-06-04 10:34 - 2015-06-04 10:34 - 00000000 ____D C:\Documents and Settings\1\Application Data\DAEMON Tools Ult
2015-06-04 10:19 - 2015-06-04 10:36 - 00000000 ____D C:\Documents and Settings\1\Application Data\DAEMON Tools Ultra
2015-06-04 10:18 - 2015-06-04 10:34 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\DAEMON Tools Ultra
2015-06-04 10:12 - 2015-06-04 10:12 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Ahead
2015-06-04 09:53 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\ГОСТДЕТАЛЬ
2015-06-03 14:57 - 2015-07-29 16:03 - 00459978 _____ C:\Documents and Settings\1\Рабочий стол\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-WOEJXJCNBDFHLNGZTMFYSLEXRKDWQJ.TUF.cbf
2015-06-02 10:40 - 2015-06-02 10:41 - 00000448 _____ C:\WINDOWS\nsw.log
2015-05-27 13:15 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Наталья
2015-05-20 15:06 - 2015-07-15 12:23 - 00039512 _____ C:\Documents and Settings\1\Рабочий стол\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-SVATSVZCGKWRVPIKUKKPNDURXCBYKP.QZQ.cbf
2015-05-20 14:50 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\билеты
2015-05-20 13:06 - 2015-07-15 12:24 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\фз 116
2015-05-20 11:48 - 2015-07-15 12:21 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Атест по пром безопасности
2015-05-18 20:39 - 2015-07-15 12:22 - 00037971 _____ C:\Documents and Settings\1\Рабочий стол\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-BOESFSDXVXZBGIBDGZBDGZBDXZBDXZ.UUF.cbf
2015-05-13 11:00 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\картинка
2015-05-13 10:03 - 2015-07-29 16:49 - 00000000 ____D C:\WINDOWS\Minidump
2015-05-07 11:19 - 2015-07-15 12:23 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\МЭГ
2015-05-05 12:17 - 2015-07-15 12:21 - 00033870 _____ C:\Documents and Settings\1\Мои документы\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-FCOQPTFANPALGRTEYALNHJUWQSDOZK.SBU.cbf
2015-05-05 12:10 - 2015-07-15 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Желонкин
 
==================== Three Months Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-03 11:46 - 2015-03-12 13:17 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Temp
2015-08-03 11:46 - 2008-08-19 01:11 - 00000000 ____D C:\Documents and Settings\Администратор\Local Settings\Temp
2015-08-03 11:43 - 2015-03-12 13:17 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол
2015-08-03 11:35 - 2008-08-19 01:41 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Google
2015-08-03 11:29 - 2015-03-12 12:49 - 01161557 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-03 11:28 - 2015-03-30 10:53 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-03 11:28 - 2015-03-12 18:43 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-08-03 11:28 - 2015-03-12 18:43 - 00000050 _____ C:\WINDOWS\wiaservc.log
2015-08-03 11:28 - 2015-03-12 13:15 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-03 11:28 - 2008-04-15 19:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-07-29 17:17 - 2015-03-12 13:17 - 00000178 ___SH C:\Documents and Settings\1\ntuser.ini
2015-07-29 17:17 - 2015-03-12 13:15 - 00032414 _____ C:\WINDOWS\SchedLgU.Txt
2015-07-29 17:10 - 2015-03-30 10:53 - 00000956 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-29 17:05 - 2015-03-12 18:40 - 00000000 ___RD C:\Documents and Settings\All Users\Главное меню\Программы
2015-07-29 17:05 - 2008-08-19 01:11 - 00000178 ___SH C:\Documents and Settings\Администратор\ntuser.ini
2015-07-29 17:02 - 2008-08-19 01:11 - 00000000 ____D C:\Documents and Settings\Администратор\Рабочий стол
2015-07-29 16:49 - 2015-04-22 12:08 - 2138390528 _____ C:\WINDOWS\MEMORY.DMP
2015-07-29 16:49 - 2015-03-12 18:39 - 01557504 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-29 16:27 - 2015-03-12 13:36 - 00069232 _____ C:\Documents and Settings\1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-07-29 16:24 - 2008-08-19 03:52 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2015-07-29 16:22 - 2015-03-12 17:06 - 00000000 ____D C:\Documents and Settings\1\Application Data\uTorrent
2015-07-29 16:21 - 2015-03-12 18:40 - 00862300 _____ C:\WINDOWS\FaxSetup.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00459212 _____ C:\WINDOWS\ocgen.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00418468 _____ C:\WINDOWS\tsoc.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00349628 _____ C:\WINDOWS\comsetup.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00295654 _____ C:\WINDOWS\msmqinst.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00209607 _____ C:\WINDOWS\ntdtcsetup.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00154116 _____ C:\WINDOWS\netfxocm.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00062492 _____ C:\WINDOWS\MedCtrOC.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00053607 _____ C:\WINDOWS\ocmsn.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00046060 _____ C:\WINDOWS\tabletoc.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00044440 _____ C:\WINDOWS\msgsocm.log
2015-07-29 16:21 - 2015-03-12 18:40 - 00001374 _____ C:\WINDOWS\imsins.log
2015-07-29 16:20 - 2015-04-20 14:37 - 00002272 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-07-29 16:19 - 2015-04-20 14:35 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2015-07-29 16:18 - 2015-03-12 18:40 - 01217642 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-29 16:18 - 2008-04-15 19:00 - 00548474 _____ C:\WINDOWS\system32\perfh019.dat
2015-07-29 16:18 - 2008-04-15 19:00 - 00104180 _____ C:\WINDOWS\system32\perfc019.dat
2015-07-29 15:48 - 2015-03-13 12:33 - 00002553 _____ C:\Documents and Settings\1\Рабочий стол\ABBYY FineReader 8.0 Professional Edition.lnk
2015-07-29 15:47 - 2015-03-12 13:17 - 00000000 ___RD C:\Documents and Settings\1\Главное меню\Программы
2015-07-29 15:47 - 2008-08-19 04:03 - 00000000 ____D C:\Documents and Settings\1\Application Data\Yandex
2015-07-29 15:44 - 2015-03-12 18:40 - 00000000 ____D C:\Documents and Settings\All Users\Рабочий стол
2015-07-29 15:44 - 2015-03-12 16:56 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-07-29 15:13 - 2015-03-12 13:17 - 00000000 ___RD C:\Documents and Settings\1\Мои документы\Мои рисунки
2015-07-29 13:00 - 2015-03-12 13:28 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-07-29 12:58 - 2008-08-19 04:10 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Yandex
2015-07-29 12:54 - 2015-03-12 18:38 - 00000223 ___SH C:\boot.ini
2015-07-29 12:54 - 2015-03-12 13:17 - 00000000 ___RD C:\Documents and Settings\1\Главное меню\Программы\Автозагрузка
2015-07-29 12:54 - 2008-04-15 19:00 - 00000652 _____ C:\WINDOWS\win.ini
2015-07-29 12:54 - 2008-04-15 19:00 - 00000227 _____ C:\WINDOWS\system.ini
2015-07-27 15:15 - 2015-03-13 14:04 - 00000000 ____D C:\Program Files\HP
2015-07-27 11:12 - 2015-03-30 10:59 - 00001809 _____ C:\Documents and Settings\All Users\Рабочий стол\Google Chrome.lnk
2015-07-21 17:21 - 2015-03-12 18:40 - 00001374 _____ C:\WINDOWS\imsins.BAK
2015-07-21 15:07 - 2015-03-24 15:58 - 00000000 ____D C:\Program Files\Hewlett-Packard
2015-07-21 15:02 - 2015-03-13 14:02 - 00000000 ___HD C:\Program Files\Agilent-HP
2015-07-21 14:59 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\twain_32
2015-07-20 10:34 - 2015-03-12 13:17 - 00000000 ___RD C:\Documents and Settings\1\Мои документы
2015-07-20 10:28 - 2015-03-12 18:33 - 00000000 ___RD C:\WINDOWS\Web
2015-07-20 10:27 - 2015-03-12 13:17 - 00000000 ____D C:\Documents and Settings\1
2015-07-20 10:18 - 2008-08-19 01:11 - 00000000 ____D C:\Documents and Settings\Администратор\Мои документы
2015-07-17 18:35 - 2015-03-12 18:38 - 28311552 _____ C:\WINDOWS\system32\config\software.sav
2015-07-17 18:35 - 2015-03-12 18:38 - 02072576 _____ C:\WINDOWS\system32\config\system.sav
2015-07-17 18:35 - 2015-03-12 18:38 - 00323584 _____ C:\WINDOWS\system32\config\default.sav
2015-07-17 18:35 - 2015-03-12 18:38 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2015-07-17 18:34 - 2015-03-12 18:38 - 00001024 ____H C:\WINDOWS\system32\config\TempKey.LOG
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\usmt
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\ru-ru
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\PeerNet
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\Media
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-07-17 18:34 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\ime
2015-07-17 18:33 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\ru
2015-07-17 18:33 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\npp
2015-07-17 18:33 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\msagent
2015-07-17 18:30 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\icsxml
2015-07-17 18:30 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\1049
2015-07-17 18:29 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\ias
2015-07-17 18:29 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\system32\1033
2015-07-17 18:28 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\Driver Cache
2015-07-17 15:33 - 2015-03-12 12:46 - 00000000 ____D C:\Program Files\Messenger
2015-07-17 15:22 - 2015-03-12 12:46 - 00007864 _____ C:\WINDOWS\wmsetup.log
2015-07-17 15:01 - 2015-03-12 12:47 - 00000000 ____D C:\Program Files\Outlook Express
2015-07-17 15:00 - 2015-03-12 12:48 - 00000000 ____D C:\Program Files\Movie Maker
2015-07-17 13:18 - 2008-08-19 01:11 - 00000000 ____D C:\Documents and Settings\Администратор
2015-07-17 13:03 - 2015-03-12 13:15 - 00000178 ___SH C:\Documents and Settings\LocalService\ntuser.ini
2015-07-17 12:56 - 2015-03-12 17:07 - 00002808 _____ C:\WINDOWS\COM+.log
2015-07-17 12:56 - 2015-03-12 12:46 - 00000000 ____D C:\WINDOWS\Registration
2015-07-17 12:55 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\Help
2015-07-17 12:55 - 2015-03-12 13:17 - 00000767 _____ C:\Documents and Settings\1\Главное меню\Программы\Internet Explorer.lnk
2015-07-17 12:55 - 2015-03-12 13:17 - 00000000 ___RD C:\Documents and Settings\1\Мои документы\Моя музыка
2015-07-17 12:55 - 2015-03-12 13:17 - 00000000 ___RD C:\Documents and Settings\1\Избранное
2015-07-17 12:54 - 2015-03-12 12:47 - 00000000 ____D C:\WINDOWS\system32\Restore
2015-07-17 12:53 - 2015-03-12 18:39 - 00450330 _____ C:\WINDOWS\setupact.log
2015-07-17 12:52 - 2015-03-12 18:40 - 00000000 ___RD C:\Documents and Settings\All Users\Главное меню
2015-07-17 12:50 - 2015-03-12 18:40 - 00004337 _____ C:\WINDOWS\ODBCINST.INI
2015-07-17 12:50 - 2015-03-12 18:40 - 00000000 ___RD C:\Documents and Settings\Default User\Главное меню\Программы
2015-07-17 12:50 - 2015-03-12 18:38 - 00001024 ____H C:\WINDOWS\system32\config\userdiff.LOG
2015-07-17 12:50 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\security
2015-07-17 12:50 - 2015-03-12 12:50 - 00316640 _____ C:\WINDOWS\WMSysPr9.prx
2015-07-17 12:50 - 2015-03-12 12:50 - 00023392 _____ C:\WINDOWS\system32\nscompat.tlb
2015-07-17 12:50 - 2015-03-12 12:50 - 00016832 _____ C:\WINDOWS\system32\amcompat.tlb
2015-07-17 12:50 - 2015-03-12 12:50 - 00001607 _____ C:\Documents and Settings\All Users\Главное меню\Выбор программ по умолчанию.lnk
2015-07-17 12:50 - 2015-03-12 12:50 - 00001599 _____ C:\Documents and Settings\Default User\Главное меню\Программы\Удаленный помощник.lnk
2015-07-17 12:50 - 2015-03-12 12:50 - 00000398 _____ C:\Documents and Settings\All Users\Главное меню\Каталог Windows.lnk
2015-07-17 12:50 - 2015-03-12 12:46 - 00000000 ___RD C:\Documents and Settings\All Users\Главное меню\Программы\Администрирование
2015-07-17 12:50 - 2008-08-19 03:55 - 01048576 _____ C:\WINDOWS\system32\config\userdifr
2015-07-17 12:50 - 2008-08-19 03:55 - 00001024 ____H C:\WINDOWS\system32\config\userdifr.LOG
2015-07-17 12:49 - 2015-03-12 12:49 - 00000786 _____ C:\Documents and Settings\All Users\Главное меню\Программы\Windows Movie Maker.lnk
2015-07-17 12:49 - 2015-03-12 12:49 - 00000749 ___RH C:\WINDOWS\system32\cdplayer.exe.manifest
2015-07-17 12:49 - 2015-03-12 12:49 - 00000488 ___RH C:\WINDOWS\system32\WindowsLogon.manifest
2015-07-17 12:49 - 2015-03-12 12:49 - 00000000 ___RD C:\Documents and Settings\Default User\Главное меню\Программы\Стандартные
2015-07-17 12:49 - 2015-03-12 12:47 - 00004145 _____ C:\WINDOWS\sessmgr.setup.log
2015-07-17 12:49 - 2015-03-12 12:45 - 00000000 ___RD C:\Documents and Settings\All Users\Главное меню\Программы\Стандартные
2015-07-17 12:48 - 2015-03-12 12:47 - 00024380 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-07-17 12:48 - 2015-03-12 12:47 - 00000629 _____ C:\Documents and Settings\All Users\Главное меню\Программы\Windows Messenger.lnk
2015-07-17 12:48 - 2015-03-12 12:46 - 00000481 _____ C:\WINDOWS\DtcInstall.log
2015-07-17 12:48 - 2015-03-12 12:46 - 00000000 ____D C:\WINDOWS\system32\Com
2015-07-17 12:47 - 2015-03-12 12:45 - 00000746 _____ C:\WINDOWS\cmsetacl.log
2015-07-17 12:37 - 2015-03-12 18:40 - 00005834 _____ C:\WINDOWS\regopt.log
2015-07-17 12:21 - 2015-03-12 18:39 - 00262144 _____ C:\WINDOWS\system32\config\security.sav
2015-07-17 12:21 - 2015-03-12 18:39 - 00000159 _____ C:\WINDOWS\setuperr.log
2015-07-17 12:18 - 2008-08-19 03:17 - 00280649 _____ C:\WINDOWS\setupapi.old
2015-07-17 12:17 - 2015-03-12 12:47 - 00000000 ____D C:\Program Files\Common Files\System
2015-07-17 12:16 - 2015-03-12 18:40 - 00000000 ____D C:\Documents and Settings\Default User\Рабочий стол
2015-07-17 12:15 - 2015-03-12 18:40 - 00000000 ___HD C:\Documents and Settings\Default User\Шаблоны
2015-07-17 12:15 - 2015-03-12 18:33 - 00000000 ____D C:\WINDOWS\Cursors
2015-07-17 12:15 - 2015-03-12 12:46 - 00000000 ____D C:\Program Files\Windows NT
2015-07-17 12:13 - 2015-03-12 18:44 - 00004444 _____ C:\WINDOWS\system32\pid.PNF
2015-07-17 11:33 - 2008-08-19 04:03 - 00004740 _____ C:\WINDOWS\system32\akelpad.ini
2015-07-17 11:31 - 2015-03-13 12:33 - 00000000 ____D C:\temp
2015-07-16 12:31 - 2015-03-12 17:05 - 00000000 ____D C:\Documents and Settings\1\Application Data\Mozilla
2015-07-15 12:26 - 2015-03-24 16:24 - 00017538 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-EVCHDYBVVHTWTEYLQCFQDOZKVGRCOZ.VEY.cbf
2015-07-15 12:26 - 2015-03-13 12:27 - 00017889 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-MQHDZUOIPALNACEPRTEGJUWYKMOQCE.RRL.cbf
2015-07-15 12:26 - 2008-08-19 04:03 - 00030062 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-FUYAIEQBFQBMPRTMXZBDOQSUFHACNP.CKK.cbf
2015-07-15 12:26 - 2008-08-19 01:40 - 00019593 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-LWSCJNZCYRLWRTVXIKMOZKEGALNYJL.HHP.cbf
2015-07-15 12:25 - 2015-03-24 16:28 - 00000000 ___HD C:\WINDOWS\ShellNew
2015-07-15 12:25 - 2015-03-12 18:40 - 01499647 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-CQWKPLXAXAUXTVXZCVXZCVXZCVXZCV.QIT.cbf
2015-07-15 12:25 - 2015-03-12 18:39 - 00802028 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-DLAXVRCNUFHJEGZBUWYRUNPILEGZCV.IIT.cbf
2015-07-15 12:25 - 2015-03-12 12:52 - 00022083 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-CNCYIXKWTNHSOITEITEPRCEPBDOQCN.IIC.cbf
2015-07-15 12:25 - 2015-03-12 12:49 - 00015167 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-PJGJIXBWBEHBOILXITNHKNHBEYSMPJ.FPH.cbf
2015-07-15 12:25 - 2008-08-22 05:02 - 00014094 _____ C:\WINDOWS\system32\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-KQMKPDGSQBDFSUFHKMOZCEGIUWYAMN.SSD.cbf
2015-07-15 12:25 - 2008-08-19 04:03 - 00000000 ____D C:\WINDOWS\system32\AkelFiles
2015-07-15 12:25 - 2008-04-15 23:00 - 00014539 _____ C:\WINDOWS\system32\Drivers\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-YLXIHLFIEYSDQKVPSLWQTNYSVPAUXI.VVE.cbf
2015-07-15 12:25 - 2008-04-15 19:00 - 00096966 _____ C:\WINDOWS\email-Seven_Legion2@aol.com.ver-CL 1.0.0.0.id-HIXLYLORXRTVHJLNYACEQSUWIKMOACEGSUWY-15.07.2015 9@13@465197241.randomname-RVWPFADXKVXZCEGITVXYJLNPACEGRT.OXX.cbf
2015-07-15 12:24 - 2015-03-31 10:47 - 00000000 ___RD C:\Documents and Settings\1\Рабочий стол\торги
2015-07-15 12:24 - 2015-03-12 13:17 - 00000000 ___HD C:\Documents and Settings\1\Шаблоны
2015-07-15 12:24 - 2008-08-19 01:11 - 00000000 ___HD C:\Documents and Settings\Администратор\Шаблоны
2015-07-15 12:23 - 2015-04-29 12:22 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Новая папка (2)
2015-07-15 12:23 - 2015-04-23 12:19 - 00000000 ___RD C:\Documents and Settings\1\Рабочий стол\Проект работы
2015-07-15 12:23 - 2015-04-20 13:30 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\томск
2015-07-15 12:23 - 2015-03-13 11:28 - 00000000 ___RD C:\Documents and Settings\1\Рабочий стол\Лецензирование
2015-07-15 12:22 - 2015-04-02 11:24 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Банк
2015-07-15 12:22 - 2015-03-23 10:35 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\договор образец
2015-07-15 12:22 - 2015-03-16 11:13 - 00000000 ____D C:\Documents and Settings\1\Рабочий стол\Дёмин
2015-07-15 10:40 - 2015-03-17 10:36 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Adobe
2015-07-15 10:40 - 2015-03-12 16:52 - 00000000 ____D C:\Documents and Settings\1\Application Data\Adobe
2015-07-13 10:47 - 2015-03-12 17:06 - 00000000 ____D C:\Program Files\Unlocker
 
Some files in TEMP:
====================
C:\Documents and Settings\1\Local Settings\Temp\dotnetfx35setup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of log ============================
 
 
 
 

Attached Files


Edited by xXToffeeXx, 03 August 2015 - 03:15 AM.
Added log for ease~


#5 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,087 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:07:13 AM

Posted 03 August 2015 - 03:36 AM

Hi Andrei2015,
 
Do you have a text file made by the malware or something which tells you your files are locked? If so please copy the text into your next reply.
 
xXToffeeXx~


Edited by xXToffeeXx, 03 August 2015 - 03:36 AM.

~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#6 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 04 August 2015 - 11:22 PM

добрый день 

если я правильно понял вам нужен зашифрованный файл

высылаю зашифрованный файл

 

 

good afternoon 
if I correctly understood to you the ciphered file is necessary
I send the ciphered file

 



#7 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,087 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:07:13 AM

Posted 05 August 2015 - 07:35 AM

Hi Andrei2015,
 
Where did you send the ciphered file? I don't see any attachment.
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#8 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 05 August 2015 - 11:27 PM

разобрался антивирусник не пускает зашифрованный файл

загружаю на файлообменник

все файлы заархивированы пароля нет

1) это папка образцы рисунков из окна, сам не знаю как так получилось что картинки востановились и остались ещё и зашифрованные файлы

2) это зашифрованный файл

 

Hi xXToffeeXx

 
the anti-virus program understood isn't started ciphered the file
I load on a hosting of files
to vsa files are archived the password isn't present
1) these are samples of the folder of drawings from windows, itself I don't know how so it turned out that photos were restored and remained also ciphered files
http://файлообменник.рф/pzta4aftl7wa.html
2) it is the ciphered file
http://файлообменник.рф/tcv767qljwf6.html

Edited by Andrei2015, 06 August 2015 - 12:04 AM.


#9 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,087 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:07:13 AM

Posted 06 August 2015 - 12:40 PM

Hi Andrei2015,

 

Please try the shadow explorer instructions here to see if you can restore your files.

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#10 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 06 August 2015 - 11:26 PM

HI xXToffeeXx~

Many thanks, I will try about the rezultakh I will report



#11 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 12 August 2015 - 02:42 AM

прочитал и ничего не понял )))



#12 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,087 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:07:13 AM

Posted 13 August 2015 - 12:57 PM

Hi Andrei2015,
 
Please download Shadow Explorer and start the program. Change the date to the date before you got infected and then navigate to the folder where the files you want are. Once you are there then right click on the folder and click on export, and choose the desktop as where you want to export the folder to.
 
xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~


#13 Andrei2015

Andrei2015
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 15 August 2015 - 10:38 PM

HI xXToffeeXx~

 

 

Спасибо

У меня эта программа не работает

 

 

thanks
I have this program does not work


#14 xXToffeeXx

xXToffeeXx

    Bleepin' Polar Bear


  • Malware Response Instructor
  • 6,087 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Arctic Circle
  • Local time:07:13 AM

Posted 17 August 2015 - 01:13 PM

Hi Andrei2015,

 

Then I am sorry to tell you that currently there is no way to recover your files.

 

xXToffeeXx~


~If I am helping you and you have not had a reply from me in two days, please send me a PM~

 

logo-25.pngID Ransomware - Identify What Ransomware Encrypted Your Files [Support Topic] - If we have helped you out and you want to support what we do, you can do so here

 

 ~Twitter~ | ~Malware Analyst at Emsisoft~





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users