start
CreateRestorePoint:
Task: {0CD679B2-85D0-40D7-9954-3A7B8FCDE4DD} - System32\Tasks\free1newsnetxzxc => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" free1news.net/xzxc <==== ATTENTION
FirewallRules: [{FC6D301D-3DBA-4EF2-9105-20C0F2C61CB9}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E66ABDA7-82C9-4CDD-88D6-449F9BE91E1F}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{90880B2F-396B-40B3-A924-7BD100FB180B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{9B361E84-DB64-4C26-B870-99F411D7CB29}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{3A0E8513-8AEE-49E9-ACB5-FC9A332A0C18}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{61186C16-A4B4-4F36-984E-AB16EA7B177A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{8EA33BC1-516D-4508-B220-6A31D6ADD10F}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{837CB184-90BF-479E-9C55-A8A6F09B7BA5}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
CHR StartupUrls: Default -> "hxxps://www.google.ru/?gfe_rd=cr&ei=uZgsVJfKA5LDNPXxgJgI&gws_rd=ssl","hxxp://mail.ru/cnt/10445?gp=openpart4","hxxps://www.google.md/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8","hxxp://nilavets.ru/?utm_source=startpage03&utm_content=8f6d4503ab6fae3230d697202021f8eb","hxxp://mail.ru/cnt/10445?gp=profitraf7","hxxp://mail.ru/cnt/10445?gp=profitraf3","hxxp://mail.ru/cnt/10445?gp=blackbear1","hxxp://www.mystartsearch.com/?type=hp&ts=1446616461&z=a56c165edf736dcaf055035g3z0z5qdq3g5qbz1q7g&from=cor&uid=st3320418as_5vmjtygn","hxxp://mail.ru/cnt/10445?gp=820031","hxxp://mail.ru/cnt/10445?gp=818410","hxxp://mail.ru/cnt/10445?gp=811036"
CHR Extension: (VkOpt) - C:\Users\Евгений\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoboppgpbgclpfnjfdidokiilachfcbb [2017-09-18]
2017-09-17 18:32 - 2016-11-28 09:21 - 001027864 _____ (McAfee, Inc.) C:\Users\Евгений\AppData\Local\Temp\0213591505662360McInst.exe
2010-02-05 18:46 - 2010-02-05 18:46 - 000779600 ____N (CANON INC.) C:\Users\Евгений\AppData\Local\Temp\MSETUP4.EXE
EmptyTemp:
Reboot:
end