• Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы

SPYWARE-RU.COM

Меню
  • Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы
В начало › Как удалить всплывающие окна
Adguard
 

Как удалить всплывающие окна

Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Как удалить всплывающие окна

  • This topic has 5 ответов, 2 участника, and was last updated 16 years, 2 months назад by Admin.
Просмотр 6 сообщений - с 1 по 6 (из 6 всего)
  • Автор
    Сообщения
  • 7 марта, 2009 в 5:14 пп #16380
    Аноним
    Гость
    • Темы:532
    • Сообщений:1553
    • ☆☆☆☆☆

    Logfile of random’s system information tool 1.05 (written by random/random)
    Run by Сергей at 2009-03-07 20:10:57
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 147 GB (96%) free of 153 GB
    Total RAM: 511 MB (44% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:10:59, on 07.03.2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20772)
    Boot mode: Normal

    Running processes:
    C:WINDOWSSystem32smss.exe
    C:WINDOWSsystem32winlogon.exe
    C:WINDOWSsystem32services.exe
    C:WINDOWSsystem32lsass.exe
    C:WINDOWSsystem32Ati2evxx.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:WINDOWSsystem32Ati2evxx.exe
    C:WINDOWSsystem32spoolsv.exe
    C:WINDOWSExplorer.EXE
    C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
    C:globglobax_daemon.exe
    C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSsystem32uphclean.exe
    C:WINDOWSInfzpx2.exe
    C:DistribспутникsatcalcSatCalc_TT.exe
    C:WINDOWSsystem32ctfmon.exe
    C:Program FilesMozilla Firefoxfirefox.exe
    C:Documents and SettingsСергейРабочий столRSIT.exe
    C:Program Filestrend microСергей.exe

    R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://google.ru
    R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://samlab.ws
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
    R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
    R1 — HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = http=127.0.0.1:8600;ftp=127.0.0.1:3128;https=127.0.0.1:3128;gopher=127.0.0.1:3128;socks=127.0.0.1:3128
    R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
    O2 — BHO: asllibP — {064017AB-B55B-4CFD-B065-A9EE88BC19BF} — C:Documents and SettingsAll UsersApplication Dataasllib.dll
    O2 — BHO: kmblibP — {73D92B2D-63D7-4107-8A41-0B14D8016BBA} — C:Documents and SettingsAll UsersApplication Datakmblib.dll
    O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
    O4 — HKLM..Run: [TaskSwitchXP] C:Program FilesTaskSwitchXPTaskSwitchXP.exe
    O4 — HKLM..Run: [Samsung Common SM] «C:WINDOWSSamsungComSMMgrssmmgr.exe» /autorun
    O4 — HKLM..Run: [avgnt] «C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe» /min
    O4 — HKLM..Run: [zzzHPSETUP] D:Setup.exe
    O4 — HKLM..RunOnce: [ZZ_WSE] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%infwse.inf,WSESetting,0
    O4 — HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
    O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [Rebuild Icon Cache] REBUILDI.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [IE7_011] regsvr32 /s /n /i:u shell32 (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
    O4 — HKUSS-1-5-20..RunOnce: [Rebuild Icon Cache] REBUILDI.EXE (User ‘NETWORK SERVICE’)
    O4 — Startup: globax_daemon.lnk = C:globglobax_daemon.exe
    O4 — Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
    O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
    O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
    O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O17 — HKLMSystemCCSServicesTcpip..{AFC9C10A-6A41-4997-983F-E296939D2962}: NameServer = 80.69.145.67 80.69.156.226
    O23 — Service: Avira AntiVir Personal — Free Antivirus Scheduler (AntiVirScheduler) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
    O23 — Service: Avira AntiVir Personal — Free Antivirus Guard (AntiVirService) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
    O23 — Service: Ati HotKey Poller — ATI Technologies Inc. — C:WINDOWSsystem32Ati2evxx.exe
    O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
    O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
    O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
    O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
    O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
    O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
    O23 — Service: Windows Security Guard (winsecguard) — Unknown owner — C:WINDOWSInfzpx2.exe
    O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe

    —
    End of file — 6083 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{064017AB-B55B-4CFD-B065-A9EE88BC19BF}]
    Streaming Media Helper Object — C:Documents and SettingsAll UsersApplication Dataasllib.dll [2009-03-03 510464]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{73D92B2D-63D7-4107-8A41-0B14D8016BBA}]
    LA Video Feeder — C:Documents and SettingsAll UsersApplication Datakmblib.dll [2009-03-03 510464]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
    «SoundMan»=C:WINDOWSSOUNDMAN.EXE [2007-04-16 577536]
    «TaskSwitchXP»=C:Program FilesTaskSwitchXPTaskSwitchXP.exe [2007-03-09 62976]
    «Samsung Common SM»=C:WINDOWSSamsungComSMMgrssmmgr.exe [2005-07-03 372736]
    «avgnt»=C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe [2008-06-12 266497]
    «zzzHPSETUP»=D:Setup.exe [2007-12-23 221184]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce]
    «ZZ_WSE»=C:WINDOWSsystem32advpack.dll [2008-06-01 124928]

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
    «CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2008-04-15 15360]

    C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
    Microsoft Office.lnk — C:Program FilesMicrosoft OfficeOffice10OSA.EXE

    C:Documents and SettingsСергейГлавное менюПрограммыАвтозагрузка
    globax_daemon.lnk — C:globglobax_daemon.exe

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAtiExtEvent]
    C:WINDOWSsystem32Ati2evxx.dll [2008-02-26 126976]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
    WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2007-06-18 133632]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    «dontdisplaylastusername»=0
    «legalnoticecaption»=
    «legalnoticetext»=
    «shutdownwithoutlogon»=1
    «undockwithoutlogon»=1

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=145
    «ForceClassicControlPanel»=1
    «NoSharedDocuments»=1
    «NoThumbnailCache»=1

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    ======List of files/folders created in the last 1 months======

    2009-03-07 12:24:27 —-D—- C:Documents and SettingsСергейApplication DataMozilla
    2009-03-07 12:24:19 —-D—- C:Program FilesMozilla Firefox
    2009-03-07 11:40:46 —-D—- C:Program Filestrend micro
    2009-03-07 11:40:45 —-D—- C:rsit
    2009-03-06 17:40:12 —-SHD—- C:Config.Msi
    2009-03-03 14:26:35 —-A—- C:Documents and SettingsAll UsersApplication Datakmblib.dll
    2009-03-03 14:20:55 —-D—- C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}
    2009-03-03 14:18:36 —-A—- C:Documents and SettingsAll UsersApplication Dataasllib.dll
    2009-03-02 18:44:27 —-D—- C:Documents and SettingsСергейApplication DataПапка выгрузки Share-to-Web
    2009-03-02 18:43:05 —-D—- C:Program FilesCommon FilesHewlett-Packard
    2009-03-02 18:42:55 —-D—- C:Program FilesHewlett-Packard
    2009-03-02 18:42:19 —-D—- C:UniScan
    2009-03-02 18:42:14 —-RA—- C:WINDOWSsystem32hpsjvset.dll
    2009-03-02 18:42:13 —-RA—- C:WINDOWSsystem32hpgt2436.dll
    2009-03-02 18:42:12 —-RA—- C:WINDOWSsystem32hpgwiamd.dll
    2009-02-28 21:10:23 —-D—- C:Documents and SettingsСергейApplication DataMacromedia
    2009-02-28 07:59:15 —-D—- C:ИГРЫ
    2009-02-27 17:27:12 —-D—- C:Program FilesCommon FilesDirectX
    2009-02-22 18:31:13 —-A—- C:WINDOWSsystem32h323log.txt
    2009-02-22 18:28:49 —-A—- C:WINDOWSsystem32ksuser.dll
    2009-02-22 18:28:38 —-A—- C:WINDOWSsystem32usbui.dll
    2009-02-22 18:26:30 —-A—- C:WINDOWSimsins.BAK
    2009-02-22 18:26:27 —-SHD—- C:WINDOWSInstaller
    2009-02-22 18:26:27 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
    2009-02-22 18:26:26 —-D—- C:Program FilesCommon FilesODBC
    2009-02-22 18:26:26 —-A—- C:WINDOWSODBCINST.INI
    2009-02-22 18:26:22 —-D—- C:Program FilesCommon FilesSpeechEngines
    2009-02-22 18:26:21 —-RD—- C:Program Files
    2009-02-22 18:26:21 —-D—- C:Program FilesCommon FilesMicrosoft Shared
    2009-02-22 18:26:21 —-D—- C:Program FilesCommon Files
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdtuq.dll
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdtuf.dll
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdazel.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhept.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhela3.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhela2.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe319.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe220.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdgkl.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlv1.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlv.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlt1.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlt.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdest.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdycl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdsl1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdsl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdro.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdpl1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdpl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdhu1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdhu.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz2.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcr.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32KBDAL.DLL
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdycc.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbduzb.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdur.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdtat.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdmon.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdkyr.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdkaz.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdbu.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdblr.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdaze.dll
    2009-02-22 18:25:53 —-A—- C:WINDOWSsystem32irclass.dll
    2009-02-22 18:25:52 —-A—- C:WINDOWSsystem32dgsetup.dll
    2009-02-22 18:25:52 —-A—- C:WINDOWSsystem32dgrpsetu.dll
    2009-02-22 18:25:51 —-A—- C:WINDOWSsystem32spxcoins.dll
    2009-02-22 18:25:51 —-A—- C:WINDOWSsystem32EqnClass.Dll
    2009-02-22 18:25:47 —-N—- C:WINDOWSsystem32CONFIG.TMP
    2009-02-22 18:25:47 —-A—- C:WINDOWSTASKMAN.EXE
    2009-02-22 18:25:46 —-A—- C:WINDOWSsystem32batt.dll
    2009-02-22 18:25:44 —-A—- C:WINDOWSNOTEPAD.EXE
    2009-02-22 18:25:43 —-A—- C:WINDOWSsystem32storprop.dll
    2009-02-22 18:25:35 —-ASH—- C:Documents and SettingsAll UsersApplication Datadesktop.ini
    2009-02-22 18:25:23 —-RA—- C:WINDOWSSET8.tmp
    2009-02-22 18:25:17 —-RA—- C:WINDOWSSET4.tmp
    2009-02-22 18:25:15 —-RA—- C:WINDOWSSET3.tmp
    2009-02-22 18:25:08 —-D—- C:WINDOWSsystem32CatRoot2
    2009-02-22 18:25:08 —-D—- C:WINDOWSsystem32CatRoot
    2009-02-22 18:25:03 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
    2009-02-22 18:24:47 —-A—- C:WINDOWSsetuplog.txt
    2009-02-22 18:21:34 —-A—- C:WINDOWSsystem32RTLCPAPI.dll
    2009-02-22 18:21:34 —-A—- C:WINDOWSSOUNDMAN.EXE
    2009-02-22 18:21:33 —-A—- C:WINDOWSsystem32RTLCPL.EXE
    2009-02-22 18:21:32 —-A—- C:WINDOWSAlcrmv.exe
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32Oemdspif.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32ativvaxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32ativcoxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atitvo32.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atipdlxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atiok3x2.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atioglxx.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atioglx2.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atikvmag.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atiiiexx.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32ATIDEMGX.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32ATIDDC.DLL
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati3duag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32Ati2mdxx.exe
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2evxx.exe
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2evxx.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2edxx.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2dvag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2cqag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32amdpcom32.dll
    2009-02-22 18:19:23 —-A—- C:changelog.txt
    2009-02-22 18:19:14 —-SHD—- C:System Volume Information
    2009-02-22 18:19:14 —-D—- C:Documents and Settings
    2009-02-22 18:18:23 —-SH—- C:boot.ini
    2009-02-22 18:13:58 —-RSHDC—- C:WINDOWSsystem32dllcache
    2009-02-22 18:13:58 —-RSD—- C:WINDOWSFonts
    2009-02-22 18:13:58 —-RD—- C:WINDOWSWeb
    2009-02-22 18:13:58 —-HD—- C:WINDOWSinf
    2009-02-22 18:13:58 —-D—- C:WINDOWSWinSxS
    2009-02-22 18:13:58 —-D—- C:WINDOWStwain_32
    2009-02-22 18:13:58 —-D—- C:WINDOWSTemp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32wins
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32wbem
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32usmt
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32spool
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ShellExt
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32Setup
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ru-ru
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ru
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ras
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32oobe
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32npp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32mui
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32inetsrv
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32IME
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32icsxml
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ias
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32export
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32drivers
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32dhcp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32config
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem323com_dmi
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem323076
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem322052
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321054
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321049
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321042
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321041
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321037
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321033
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321031
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321028
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321025
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem
    2009-02-22 18:13:58 —-D—- C:WINDOWSsecurity
    2009-02-22 18:13:58 —-D—- C:WINDOWSResources
    2009-02-22 18:13:58 —-D—- C:WINDOWSrepair
    2009-02-22 18:13:58 —-D—- C:WINDOWSProvisioning
    2009-02-22 18:13:58 —-D—- C:WINDOWSPeerNet
    2009-02-22 18:13:58 —-D—- C:WINDOWSpchealth
    2009-02-22 18:13:58 —-D—- C:WINDOWSNetwork Diagnostic
    2009-02-22 18:13:58 —-D—- C:WINDOWSmui
    2009-02-22 18:13:58 —-D—- C:WINDOWSmsapps
    2009-02-22 18:13:58 —-D—- C:WINDOWSmsagent
    2009-02-22 18:13:58 —-D—- C:WINDOWSMedia
    2009-02-22 18:13:58 —-D—- C:WINDOWSL2Schemas
    2009-02-22 18:13:58 —-D—- C:WINDOWSjava
    2009-02-22 18:13:58 —-D—- C:WINDOWSime
    2009-02-22 18:13:58 —-D—- C:WINDOWSHelp
    2009-02-22 18:13:58 —-D—- C:WINDOWSehome
    2009-02-22 18:13:58 —-D—- C:WINDOWSDriver Cache
    2009-02-22 18:13:58 —-D—- C:WINDOWSDebug
    2009-02-22 18:13:58 —-D—- C:WINDOWSCursors
    2009-02-22 18:13:58 —-D—- C:WINDOWSConnection Wizard
    2009-02-22 18:13:58 —-D—- C:WINDOWSConfig
    2009-02-22 18:13:58 —-D—- C:WINDOWSAppPatch
    2009-02-22 18:13:58 —-D—- C:WINDOWSaddins
    2009-02-22 18:13:58 —-D—- C:WINDOWS
    2009-02-22 18:10:06 —-D—- C:Program FilesAvira
    2009-02-22 18:10:06 —-D—- C:Documents and SettingsAll UsersApplication DataAvira
    2009-02-22 17:37:43 —-D—- C:glob
    2009-02-22 16:52:58 —-D—- C:Program FilesSamsung ML-2010 Series
    2009-02-22 16:52:28 —-N—- C:WINDOWSsystem32SSRemove.exe
    2009-02-22 16:52:28 —-D—- C:WINDOWSSamsung
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SUGS2LMK.DLL
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SSCoInst.exe
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SSCoInst.dll
    2009-02-22 16:47:56 —-A—- C:WINDOWSModemLog_Motorola USB Modem.txt
    2009-02-22 16:45:45 —-D—- C:Program FilesAvanquest update
    2009-02-22 16:44:53 —-HD—- C:Program FilesInstallShield Installation Information
    2009-02-22 16:44:53 —-D—- C:Program FilesMotorola Phone Tools
    2009-02-22 16:44:53 —-D—- C:Documents and SettingsAll UsersApplication DataBVRP Software
    2009-02-22 16:44:29 —-D—- C:Program FilesCommon FilesInstallShield
    2009-02-22 16:41:20 —-D—- C:WINDOWSRegisteredPackages
    2009-02-22 16:41:05 —-A—- C:WINDOWSsystem32psisdecd.dll
    2009-02-22 16:41:03 —-A—- C:WINDOWSsystem32dxdllreg.exe
    2009-02-22 16:41:02 —-D—- C:WINDOWSsystem32DirectX
    2009-02-22 16:38:23 —-D—- C:Program FilesLight Alloy
    2009-02-22 16:37:56 —-SHD—- C:RECYCLER
    2009-02-22 16:37:45 —-D—- C:Program FilesWinRAR
    2009-02-22 15:59:42 —-D—- C:Program FilesMicrosoft.NET
    2009-02-22 15:58:15 —-A—- C:WINDOWSODBC.INI
    2009-02-22 15:57:39 —-D—- C:Program FilesCommon FilesDesigner
    2009-02-22 15:57:24 —-D—- C:WINDOWSShellNew
    2009-02-22 15:57:19 —-D—- C:Program FilesMicrosoft Office
    2009-02-22 15:52:19 —-D—- C:Distrib
    2009-02-22 15:45:35 —-D—- C:Documents and SettingsСергейApplication DataIdentities
    2009-02-22 15:45:31 —-HD—- C:Program FilesUninstall Information
    2009-02-22 15:45:19 —-D—- C:WINDOWSInstall
    2009-02-22 15:45:14 —-SD—- C:Documents and SettingsСергейApplication DataMicrosoft
    2009-02-22 15:45:14 —-ASH—- C:Documents and SettingsСергейApplication Datadesktop.ini
    2009-02-22 15:44:23 —-D—- C:WINDOWSPrefetch
    2009-02-22 15:44:22 —-SD—- C:WINDOWSsystem32Microsoft
    2009-02-22 15:44:22 —-A—- C:WINDOWSSchedLgU.Txt
    2009-02-22 15:40:55 —-D—- C:WINDOWSsystem32xircom
    2009-02-22 15:40:55 —-D—- C:Program Filesxerox
    2009-02-22 15:40:55 —-D—- C:Program Filesmicrosoft frontpage
    2009-02-22 15:40:37 —-D—- C:Program FilesCommon FilesAdobe
    2009-02-22 15:39:22 —-RSD—- C:WINDOWSassembly
    2009-02-22 15:39:22 —-D—- C:WINDOWSMicrosoft.NET
    2009-02-22 15:39:20 —-D—- C:WINDOWSsystem32URTTemp
    2009-02-22 15:38:49 —-D—- C:Program FilesMSXML 4.0
    2009-02-22 15:38:37 —-A—- C:WINDOWScontrol.ini
    2009-02-22 15:38:37 —-A—- C:AUTOEXEC.BAT
    2009-02-22 15:38:24 —-A—- C:WINDOWSOEWABLog.txt
    2009-02-22 15:38:18 —-A—- C:WINDOWSsystem32mapi32.dll
    2009-02-22 15:37:05 —-RAH—- C:WINDOWSsystem32logonui.exe.manifest
    2009-02-22 15:36:59 —-RAH—- C:WINDOWSsystem32cdplayer.exe.manifest
    2009-02-22 15:36:52 —-HD—- C:Program FilesWindowsUpdate
    2009-02-22 15:36:39 —-A—- C:WINDOWSsystem32atrace.dll
    2009-02-22 15:36:38 —-A—- C:WINDOWSsystem32nmevtmsg.dll
    2009-02-22 15:36:36 —-D—- C:Program FilesCommon FilesServices
    2009-02-22 15:36:36 —-A—- C:WINDOWSsystem32acctres.dll
    2009-02-22 15:36:34 —-SD—- C:WINDOWSTasks
    2009-02-22 15:36:34 —-A—- C:WINDOWSsystem32icfgnt5.dll
    2009-02-22 15:36:33 —-D—- C:Program FilesCommon FilesMSSoap
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuweb.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wucltui.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuauserv.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuaueng1.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wups.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuaueng.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuauclt1.exe
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuauclt.exe
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuapi.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx4.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx3.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx2.dll
    2009-02-22 15:36:27 —-A—- C:WINDOWSsystem32qmgrprxy.dll
    2009-02-22 15:36:27 —-A—- C:WINDOWSsystem32qmgr.dll
    2009-02-22 15:36:24 —-D—- C:Program FilesMovie Maker
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrslv.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrdm.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrcdlg.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32racpldlg.dll
    2009-02-22 15:35:55 —-A—- C:WINDOWSsystem32fltMc.exe
    2009-02-22 15:35:55 —-A—- C:WINDOWSsystem32fltlib.dll
    2009-02-22 15:35:54 —-D—- C:WINDOWSsystem32Restore
    2009-02-22 15:35:54 —-A—- C:WINDOWSsystem32srsvc.dll
    2009-02-22 15:35:54 —-A—- C:WINDOWSsystem32srrstr.dll
    2009-02-22 15:35:53 —-A—- C:WINDOWSsystem32srclient.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32nmmkcert.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32msconf.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32mnmsrvc.exe
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32mnmdd.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32isrdbg32.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32ils.dll
    2009-02-22 15:35:46 —-D—- C:Program FilesNetMeeting
    2009-02-22 15:35:45 —-A—- C:WINDOWSsystem32msoert2.dll
    2009-02-22 15:35:45 —-A—- C:WINDOWSsystem32msoeacct.dll
    2009-02-22 15:35:43 —-A—- C:WINDOWSsystem32inetres.dll
    2009-02-22 15:35:42 —-A—- C:WINDOWSsystem32inetcomm.dll
    2009-02-22 15:35:40 —-D—- C:Program FilesOutlook Express
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32schedsvc.dll
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32mstinit.exe
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32mstask.dll
    2009-02-22 15:35:39 —-A—- C:WINDOWSsystem32icwphbk.dll
    2009-02-22 15:35:39 —-A—- C:WINDOWSsystem32icwdial.dll
    2009-02-22 15:35:38 —-A—- C:WINDOWSsystem32isign32.dll
    2009-02-22 15:35:38 —-A—- C:WINDOWSsystem32inetcfg.dll
    2009-02-22 15:35:29 —-D—- C:Program FilesCommon FilesSystem
    2009-02-22 15:34:33 —-D—- C:Program FilesComPlus Applications
    2009-02-22 15:34:31 —-A—- C:WINDOWSvbaddin.ini
    2009-02-22 15:34:31 —-A—- C:WINDOWSvb.ini
    2009-02-22 15:34:26 —-D—- C:WINDOWSRegistration
    2009-02-22 15:34:05 —-D—- C:Program FilesTaskSwitchXP
    2009-02-22 15:33:59 —-D—- C:WINDOWSsystem32Macromed
    2009-02-22 15:33:57 —-A—- C:WINDOWSsystem32wiaaut.dll
    2009-02-22 15:33:53 —-D—- C:Program FilesPaint.NET
    2009-02-22 15:33:52 —-A—- C:WINDOWSsystem32REBUILDI.EXE
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32Path2Clipboard.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32HashTab.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32FileNote.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32DirSize.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32CDClose.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSExt2Mgr.exe
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32target.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32mp3tagv.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32Layout.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32DLLINFO.DLL
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32cpext.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32xvidvfw.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32xvidcore.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32x264vfw.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32WMV9VCM.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32VSFilter.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32vorbisfile.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32vct3216.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32ts.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32StreamIO.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32qt-dx331.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32pncrt.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32ogm.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32MP4FileLib.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32mp4.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32mmfinfo.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkzlib.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkx.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkunicode.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32Ir50_lcs.dll
    2009-02-22 15:33:42 —-A—- C:WINDOWSsystem32dxr.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drvc.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drv2.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drv1.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32dllzAAC.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32divxsm.exe
    2009-02-22 15:33:39 —-A—- C:WINDOWSsystem32cook.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avss.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avs.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avi.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32AudioCodec.dll
    2009-02-22 15:33:37 —-A—- C:WINDOWSsystem324codeDecoder.dll
    2009-02-22 15:33:26 —-D—- C:Program FilesWindows Media Player
    2009-02-22 15:33:26 —-D—- C:Program FilesWindows Media Connect 2
    2009-02-22 15:33:21 —-SD—- C:WINDOWSDownloaded Program Files
    2009-02-22 15:33:21 —-RD—- C:WINDOWSOffline Web Pages
    2009-02-22 15:33:21 —-A—- C:WINDOWSsystem32winfxdocobj.exe
    2009-02-22 15:33:20 —-D—- C:WINDOWSwbem
    2009-02-22 15:33:20 —-A—- C:WINDOWSsystem32msfeedssync.exe
    2009-02-22 15:33:20 —-A—- C:WINDOWSsystem32msfeedsbs.dll
    2009-02-22 15:33:18 —-A—- C:WINDOWSsystem32ieframe.dll.mui
    2009-02-22 15:33:17 —-D—- C:Program FilesInternet Explorer
    2009-02-22 15:33:17 —-A—- C:WINDOWSsystem32advpack.dll.mui
    2009-02-22 15:33:16 —-D—- C:WINDOWSSoftwareDistribution
    2009-02-22 15:33:16 —-A—- C:WINDOWSsystem32muweb.dll
    2009-02-22 15:33:15 —-A—- C:WINDOWSsystem32gpprefcl.dll
    2009-02-22 15:33:14 —-A—- C:WINDOWSsystem32write.exe
    2009-02-22 15:33:02 —-A—- C:WINDOWSsystem32sndvol32.exe
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32hticons.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avwav.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avtapi.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avmeter.dll
    2009-02-22 15:32:59 —-A—- C:WINDOWSsystem32winchat.exe
    2009-02-22 15:32:49 —-A—- C:WINDOWSsystem32getuname.dll
    2009-02-22 15:32:49 —-A—- C:WINDOWSsystem32charmap.exe
    2009-02-22 15:32:48 —-A—- C:WINDOWSsystem32calc.exe
    2009-02-22 15:32:47 —-A—- C:WINDOWSsystem32winmine.exe
    2009-02-22 15:32:47 —-A—- C:WINDOWSsystem32sol.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32usrlogon.cmd
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32reset.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32mshearts.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32freecell.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tsshutdn.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tslabels.ini
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tskill.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tsdiscon.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tscon.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32shadow.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32rwinsta.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32regini.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32rdpcfgex.dll
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32qwinsta.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32qappsrv.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32msg.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32logoff.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32cdmodem.dll
    2009-02-22 15:32:43 —-A—- C:WINDOWSsystem32msdtcprf.ini
    2009-02-22 15:32:34 —-A—- C:WINDOWSsystem32wmimgmt.msc
    2009-02-22 15:32:32 —-A—- C:WINDOWSsystem32sndrec32.exe
    2009-02-22 15:32:32 —-A—- C:WINDOWSsystem32accwiz.exe
    2009-02-22 15:32:31 —-A—- C:WINDOWSsystem32mplay32.exe
    2009-02-22 15:32:31 —-A—- C:WINDOWSsystem32hypertrm.dll
    2009-02-22 15:32:30 —-D—- C:Program FilesWindows NT
    2009-02-22 15:32:30 —-A—- C:WINDOWSsystem32mspaint.exe
    2009-02-22 15:32:29 —-A—- C:WINDOWSsystem32clipbrd.exe
    2009-02-22 15:32:28 —-A—- C:WINDOWSsystem32spider.exe
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32tsgqec.dll
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32tscfgwmi.dll
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32rhttpaa.dll
    2009-02-22 15:32:25 —-A—- C:WINDOWSsystem32aaclient.dll
    2009-02-22 15:32:24 —-A—- C:WINDOWSsystem32mstscax.dll
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32sessmgr.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32remotepg.dll
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32rdshost.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32rdsaddin.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32mstsc.exe
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32termsrv.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpwsx.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpsnd.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpclip.exe
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdchost.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32qprocess.exe
    2009-02-22 15:32:21 —-A—- C:WINDOWSsystem32icaapi.dll
    2009-02-22 15:32:21 —-A—- C:WINDOWSsystem32cfgbkend.dll
    2009-02-22 15:32:20 —-D—- C:WINDOWSsystem32MsDtc
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32mtxoci.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtcuiu.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtctm.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtcprx.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32xolehlp.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32msdtclog.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32msdtc.exe
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxlegih.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxex.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxdm.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32dcomcnfg.exe
    2009-02-22 15:32:16 —-D—- C:WINDOWSsystem32Com
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32comrepl.dll
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32comaddin.dll
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32colbact.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32stclient.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32clbcatex.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32catsrvps.dll
    2009-02-22 15:32:14 —-A—- C:WINDOWSsystem32catsrvut.dll
    2009-02-22 15:32:14 —-A—- C:WINDOWSsystem32catsrv.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comuid.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comsvcs.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comsnap.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32clbcatq.dll
    2009-02-22 15:32:04 —-A—- C:WINDOWSsystem32servdeps.dll
    2009-02-22 15:32:04 —-A—- C:WINDOWSsystem32mmfutil.dll
    2009-02-22 15:32:03 —-A—- C:WINDOWSsystem32licwmi.dll
    2009-02-22 15:32:03 —-A—- C:WINDOWSsystem32cmprops.dll

    ======List of files/folders modified in the last 1 months======

    2009-03-06 17:40:16 —-A—- C:WINDOWSwin.ini
    2009-02-22 18:26:20 —-A—- C:WINDOWSsystem.ini

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AFS2K;AFS2k; C:WINDOWSsystem32driversAFS2K.sys [2009-03-02 82380]
    R1 avgio;avgio; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgio.sys []
    R1 avipbb;avipbb; C:WINDOWSsystem32DRIVERSavipbb.sys [2008-10-30 75072]
    R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-15 40704]
    R1 ssmdrv;ssmdrv; C:WINDOWSsystem32DRIVERSssmdrv.sys [2007-03-01 28352]
    R2 DgiVecp;Team MFP Comm Driver; C:WINDOWSSystem32DriversDgiVecp.sys [2005-03-14 41984]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2008-01-25 4127488]
    R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2008-02-26 2863616]
    R3 avgntflt;avgntflt; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgntflt.sys []
    R3 msloop;Драйвер адаптера Microsoft замыкания на себя; C:WINDOWSsystem32DRIVERSloop.sys [2008-06-01 4992]
    R3 nvmpu401;Service for NVIDIA(R) nForce(TM) MIDI UART; C:WINDOWSsystem32driversnvmpu401.sys [2006-02-26 10240]
    R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet адаптер, драйвер для NT; C:WINDOWSsystem32DRIVERSRTL8139.SYS [2008-06-02 20992]
    R3 TTDVBLCD;TechnoTrend DVB PCI budget Driver; C:WINDOWSsystem32DRIVERSttdvblcd.sys [2006-02-03 66176]
    R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-06-01 30336]
    R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-06-02 59520]
    R3 usbsermpt;Motorola USB Modem Driver for MPT; C:WINDOWSsystem32DRIVERSusbsermpt.sys [2009-02-22 22768]
    R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-06-02 20608]
    S3 Ext2Fsd;Linux ext2 File system driver; C:WINDOWSsystem32driversExt2Fsd.sys [2008-01-27 644240]
    S3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-06-01 15104]
    S3 usbser;Motorola USB Modem Driver; C:WINDOWSsystem32DRIVERSusbser.sys [2008-06-01 26112]
    S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-06-01 26368]
    S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2007-06-18 77568]
    S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2007-06-18 82944]
    S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AntiVirScheduler;Avira AntiVir Personal — Free Antivirus Scheduler; C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe [2008-10-15 68865]
    R2 AntiVirService;Avira AntiVir Personal — Free Antivirus Guard; C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe [2008-10-15 151297]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:WINDOWSsystem32Ati2evxx.exe [2008-02-26 520192]
    R2 UPHClean;User Profile Hive Cleanup; C:WINDOWSsystem32uphclean.exe [2006-01-16 241725]
    R2 winsecguard;Windows Security Guard; C:WINDOWSInfzpx2.exe [2009-03-03 331264]
    S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv1.1.4322aspnet_state.exe [2004-07-15 32768]
    S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]


    EOF


    8 марта, 2009 в 3:39 пп #22472
    Admin
    Keymaster
    • Темы:40
    • Сообщений:5676
    • ☆☆☆☆☆

    Здравствуйте, добро пожаловать на Spyware-ru форум.

    Скачайте OTMoveIt3 by OldTimer кликнув по этой ссылке.
    Запустите OTMoveIt3 и в большое поле ввода (заголовок этого поля выделен желтым цветом) скопируйте следующий текст.

    :Processes
    explorer.exe

    :services
    winsecguard

    :reg
    [-HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{064017AB-B55B-4CFD-B065-A9EE88BC19BF}]
    [-HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{73D92B2D-63D7-4107-8A41-0B14D8016BBA}]

    :files
    C:WINDOWSInfzpx2.exe
    C:Documents and SettingsAll UsersApplication Datakmblib.dll
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}
    C:Documents and SettingsAll UsersApplication Dataasllib.dll

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]

    Проверьте вставленный скрипт, если слева перед директивами появились пробелы, то удалите их, скрипт должен выглядеть так же как в сообщении. Кликните по кнопке MoveIt!. В процессе работы возможна перезагрузка компьютера.
    По-завершении работы программы должен будет показан лог. Если лог не будет показан, то его можно найти в папке C:_OTMoveItMovedFiles.

    Запустите HijackThis, для этого кликните Пуск, Выполнить, введите

    C:Program Filestrend microСергей.exe

    и нажмите Enter.
    Запустите HijackThis.
    Кликните по кнопке Do a system scan only.
    Далее отметьте галочкой (слева) следующую строку, если она присутствует:

    R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = http=127.0.0.1:8600;ftp=127.0.0.1:3128;https=127.0.0.1:3128;gopher=127.0.0.1:3128;socks=127.0.0.1:3128

    Закройте все запущенные программы (включая InternetExplorer) и окна Windows.
    Кликните по кнопке Fix checked и подтвердите свои действия выбрав YES.
    Перезагрузите компьютер.

    Жду от вас OTMoveIt лог + свежий RSIT лог.

    9 марта, 2009 в 6:49 дп #22473
    Аноним
    Гость
    • Темы:532
    • Сообщений:1553
    • ☆☆☆☆☆

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    Unable to stop service winsecguard .
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{064017AB-B55B-4CFD-B065-A9EE88BC19BF}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{73D92B2D-63D7-4107-8A41-0B14D8016BBA}\ deleted successfully.
    ========== FILES ==========
    C:WINDOWSInfzpx2.exe moved successfully.
    C:Documents and SettingsAll UsersApplication Datakmblib.dll unregistered successfully.
    C:Documents and SettingsAll UsersApplication Datakmblib.dll moved successfully.
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}componentswatchers moved successfully.
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}componentssystempudata moved successfully.
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}componentssystem moved successfully.
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}components moved successfully.
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z} moved successfully.
    C:Documents and SettingsAll UsersApplication Dataasllib.dll unregistered successfully.
    C:Documents and SettingsAll UsersApplication Dataasllib.dll moved successfully.
    ========== COMMANDS ==========
    File delete failed. C:WINDOWSTempetilqs_u9JPHEHdStAPDyNOGP2y scheduled to be deleted on reboot.
    User’s Temp folder emptied.
    User’s Temporary Internet Files folder emptied.
    User’s Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:Documents and SettingsLocalServiceLocal SettingsTemporary Internet FilesContent.IE5index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:WINDOWStempetilqs_u9JPHEHdStAPDyNOGP2y scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    File delete failed. C:Documents and SettingsСергейLocal SettingsApplication DataMozillaFirefoxProfilespgp8jl4k.defaulturlclassifier3.sqlite scheduled to be deleted on reboot.
    File delete failed. C:Documents and SettingsСергейLocal SettingsApplication DataMozillaFirefoxProfilespgp8jl4k.defaultXUL.mfl scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer — Version 1.0.8.0 log created on 03092009_091139

    Files moved on Reboot…
    File C:WINDOWSTempetilqs_u9JPHEHdStAPDyNOGP2y not found!
    C:Documents and SettingsLocalServiceLocal SettingsTemporary Internet FilesContent.IE5index.dat moved successfully.
    C:Documents and SettingsСергейLocal SettingsApplication DataMozillaFirefoxProfilespgp8jl4k.defaulturlclassifier3.sqlite moved successfully.
    C:Documents and SettingsСергейLocal SettingsApplication DataMozillaFirefoxProfilespgp8jl4k.defaultXUL.mfl moved successfully.

    Logfile of random’s system information tool 1.05 (written by random/random)
    Run by Сергей at 2009-03-09 09:48:10
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 147 GB (96%) free of 153 GB
    Total RAM: 511 MB (55% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:48:12, on 09.03.2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20772)
    Boot mode: Normal

    Running processes:
    C:WINDOWSSystem32smss.exe
    C:WINDOWSsystem32winlogon.exe
    C:WINDOWSsystem32services.exe
    C:WINDOWSsystem32lsass.exe
    C:WINDOWSsystem32Ati2evxx.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:WINDOWSsystem32Ati2evxx.exe
    C:WINDOWSsystem32spoolsv.exe
    C:WINDOWSExplorer.EXE
    C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
    C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSsystem32uphclean.exe
    C:WINDOWSSOUNDMAN.EXE
    C:Program FilesTaskSwitchXPTaskSwitchXP.exe
    C:WINDOWSSamsungComSMMgrssmmgr.exe
    C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
    C:WINDOWSsystem32ctfmon.exe
    C:globglobax_daemon.exe
    C:DistribспутникsatcalcSatCalc_TT.exe
    C:Program FilesInternet ExplorerIEXPLORE.EXE
    C:Documents and SettingsСергейРабочий столRSIT.exe
    C:Program Filestrend microСергей.exe

    R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://google.ru
    R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://samlab.ws
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
    R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
    R1 — HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 127.0.0.1:3128
    R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
    O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
    O4 — HKLM..Run: [TaskSwitchXP] C:Program FilesTaskSwitchXPTaskSwitchXP.exe
    O4 — HKLM..Run: [Samsung Common SM] «C:WINDOWSSamsungComSMMgrssmmgr.exe» /autorun
    O4 — HKLM..Run: [avgnt] «C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe» /min
    O4 — HKLM..Run: [zzzHPSETUP] D:Setup.exe
    O4 — HKLM..RunOnce: [ZZ_WSE] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%infwse.inf,WSESetting,0
    O4 — HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
    O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [Rebuild Icon Cache] REBUILDI.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [IE7_011] regsvr32 /s /n /i:u shell32 (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
    O4 — HKUSS-1-5-20..RunOnce: [Rebuild Icon Cache] REBUILDI.EXE (User ‘NETWORK SERVICE’)
    O4 — Startup: globax_daemon.lnk = C:globglobax_daemon.exe
    O4 — Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
    O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
    O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
    O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O17 — HKLMSystemCCSServicesTcpip..{AFC9C10A-6A41-4997-983F-E296939D2962}: NameServer = 80.69.145.67 80.69.156.226
    O23 — Service: Avira AntiVir Personal — Free Antivirus Scheduler (AntiVirScheduler) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
    O23 — Service: Avira AntiVir Personal — Free Antivirus Guard (AntiVirService) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
    O23 — Service: Ati HotKey Poller — ATI Technologies Inc. — C:WINDOWSsystem32Ati2evxx.exe
    O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
    O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
    O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
    O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
    O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
    O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
    O23 — Service: Windows Security Guard (winsecguard) — Unknown owner — C:WINDOWSInfzpx2.exe (file missing)
    O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe

    —
    End of file — 5914 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
    «SoundMan»=C:WINDOWSSOUNDMAN.EXE [2007-04-16 577536]
    «TaskSwitchXP»=C:Program FilesTaskSwitchXPTaskSwitchXP.exe [2007-03-09 62976]
    «Samsung Common SM»=C:WINDOWSSamsungComSMMgrssmmgr.exe [2005-07-03 372736]
    «avgnt»=C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe [2008-06-12 266497]
    «zzzHPSETUP»=D:Setup.exe [2007-12-23 221184]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce]
    «ZZ_WSE»=C:WINDOWSsystem32advpack.dll [2008-06-01 124928]

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
    «CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2008-04-15 15360]

    C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
    Microsoft Office.lnk — C:Program FilesMicrosoft OfficeOffice10OSA.EXE

    C:Documents and SettingsСергейГлавное менюПрограммыАвтозагрузка
    globax_daemon.lnk — C:globglobax_daemon.exe

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAtiExtEvent]
    C:WINDOWSsystem32Ati2evxx.dll [2008-02-26 126976]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
    WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2007-06-18 133632]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    «dontdisplaylastusername»=0
    «legalnoticecaption»=
    «legalnoticetext»=
    «shutdownwithoutlogon»=1
    «undockwithoutlogon»=1

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=145
    «ForceClassicControlPanel»=1
    «NoSharedDocuments»=1
    «NoThumbnailCache»=1

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    [HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{4ff355b7-00f3-11de-b8ca-806d6172696f}]
    shellAutoRuncommand — D:SETUP.EXE

    ======List of files/folders created in the last 1 months======

    2009-03-09 09:11:53 —-D—- C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}
    2009-03-09 09:11:39 —-D—- C:_OTMoveIt
    2009-03-07 12:24:27 —-D—- C:Documents and SettingsСергейApplication DataMozilla
    2009-03-07 12:24:19 —-D—- C:Program FilesMozilla Firefox
    2009-03-07 11:40:46 —-D—- C:Program Filestrend micro
    2009-03-07 11:40:45 —-D—- C:rsit
    2009-03-06 17:40:12 —-SHD—- C:Config.Msi
    2009-03-02 18:44:27 —-D—- C:Documents and SettingsСергейApplication DataПапка выгрузки Share-to-Web
    2009-03-02 18:43:05 —-D—- C:Program FilesCommon FilesHewlett-Packard
    2009-03-02 18:42:55 —-D—- C:Program FilesHewlett-Packard
    2009-03-02 18:42:19 —-D—- C:UniScan
    2009-03-02 18:42:14 —-RA—- C:WINDOWSsystem32hpsjvset.dll
    2009-03-02 18:42:13 —-RA—- C:WINDOWSsystem32hpgt2436.dll
    2009-03-02 18:42:12 —-RA—- C:WINDOWSsystem32hpgwiamd.dll
    2009-02-28 21:10:23 —-D—- C:Documents and SettingsСергейApplication DataMacromedia
    2009-02-28 07:59:15 —-D—- C:ИГРЫ
    2009-02-27 17:27:12 —-D—- C:Program FilesCommon FilesDirectX
    2009-02-22 18:31:13 —-A—- C:WINDOWSsystem32h323log.txt
    2009-02-22 18:28:49 —-A—- C:WINDOWSsystem32ksuser.dll
    2009-02-22 18:28:38 —-A—- C:WINDOWSsystem32usbui.dll
    2009-02-22 18:26:30 —-A—- C:WINDOWSimsins.BAK
    2009-02-22 18:26:27 —-SHD—- C:WINDOWSInstaller
    2009-02-22 18:26:27 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
    2009-02-22 18:26:26 —-D—- C:Program FilesCommon FilesODBC
    2009-02-22 18:26:26 —-A—- C:WINDOWSODBCINST.INI
    2009-02-22 18:26:22 —-D—- C:Program FilesCommon FilesSpeechEngines
    2009-02-22 18:26:21 —-RD—- C:Program Files
    2009-02-22 18:26:21 —-D—- C:Program FilesCommon FilesMicrosoft Shared
    2009-02-22 18:26:21 —-D—- C:Program FilesCommon Files
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdtuq.dll
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdtuf.dll
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdazel.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhept.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhela3.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhela2.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe319.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe220.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdgkl.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlv1.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlv.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlt1.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlt.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdest.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdycl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdsl1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdsl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdro.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdpl1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdpl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdhu1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdhu.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz2.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcr.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32KBDAL.DLL
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdycc.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbduzb.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdur.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdtat.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdmon.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdkyr.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdkaz.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdbu.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdblr.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdaze.dll
    2009-02-22 18:25:53 —-A—- C:WINDOWSsystem32irclass.dll
    2009-02-22 18:25:52 —-A—- C:WINDOWSsystem32dgsetup.dll
    2009-02-22 18:25:52 —-A—- C:WINDOWSsystem32dgrpsetu.dll
    2009-02-22 18:25:51 —-A—- C:WINDOWSsystem32spxcoins.dll
    2009-02-22 18:25:51 —-A—- C:WINDOWSsystem32EqnClass.Dll
    2009-02-22 18:25:47 —-N—- C:WINDOWSsystem32CONFIG.TMP
    2009-02-22 18:25:47 —-A—- C:WINDOWSTASKMAN.EXE
    2009-02-22 18:25:46 —-A—- C:WINDOWSsystem32batt.dll
    2009-02-22 18:25:44 —-A—- C:WINDOWSNOTEPAD.EXE
    2009-02-22 18:25:43 —-A—- C:WINDOWSsystem32storprop.dll
    2009-02-22 18:25:35 —-ASH—- C:Documents and SettingsAll UsersApplication Datadesktop.ini
    2009-02-22 18:25:23 —-RA—- C:WINDOWSSET8.tmp
    2009-02-22 18:25:17 —-RA—- C:WINDOWSSET4.tmp
    2009-02-22 18:25:15 —-RA—- C:WINDOWSSET3.tmp
    2009-02-22 18:25:08 —-D—- C:WINDOWSsystem32CatRoot2
    2009-02-22 18:25:08 —-D—- C:WINDOWSsystem32CatRoot
    2009-02-22 18:25:03 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
    2009-02-22 18:24:47 —-A—- C:WINDOWSsetuplog.txt
    2009-02-22 18:21:34 —-A—- C:WINDOWSsystem32RTLCPAPI.dll
    2009-02-22 18:21:34 —-A—- C:WINDOWSSOUNDMAN.EXE
    2009-02-22 18:21:33 —-A—- C:WINDOWSsystem32RTLCPL.EXE
    2009-02-22 18:21:32 —-A—- C:WINDOWSAlcrmv.exe
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32Oemdspif.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32ativvaxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32ativcoxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atitvo32.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atipdlxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atiok3x2.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atioglxx.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atioglx2.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atikvmag.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atiiiexx.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32ATIDEMGX.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32ATIDDC.DLL
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati3duag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32Ati2mdxx.exe
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2evxx.exe
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2evxx.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2edxx.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2dvag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2cqag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32amdpcom32.dll
    2009-02-22 18:19:23 —-A—- C:changelog.txt
    2009-02-22 18:19:14 —-SHD—- C:System Volume Information
    2009-02-22 18:19:14 —-D—- C:Documents and Settings
    2009-02-22 18:18:23 —-SH—- C:boot.ini
    2009-02-22 18:13:58 —-RSHDC—- C:WINDOWSsystem32dllcache
    2009-02-22 18:13:58 —-RSD—- C:WINDOWSFonts
    2009-02-22 18:13:58 —-RD—- C:WINDOWSWeb
    2009-02-22 18:13:58 —-HD—- C:WINDOWSinf
    2009-02-22 18:13:58 —-D—- C:WINDOWSWinSxS
    2009-02-22 18:13:58 —-D—- C:WINDOWStwain_32
    2009-02-22 18:13:58 —-D—- C:WINDOWSTemp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32wins
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32wbem
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32usmt
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32spool
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ShellExt
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32Setup
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ru-ru
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ru
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ras
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32oobe
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32npp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32mui
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32inetsrv
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32IME
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32icsxml
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ias
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32export
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32drivers
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32dhcp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32config
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem323com_dmi
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem323076
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem322052
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321054
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321049
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321042
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321041
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321037
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321033
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321031
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321028
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321025
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem
    2009-02-22 18:13:58 —-D—- C:WINDOWSsecurity
    2009-02-22 18:13:58 —-D—- C:WINDOWSResources
    2009-02-22 18:13:58 —-D—- C:WINDOWSrepair
    2009-02-22 18:13:58 —-D—- C:WINDOWSProvisioning
    2009-02-22 18:13:58 —-D—- C:WINDOWSPeerNet
    2009-02-22 18:13:58 —-D—- C:WINDOWSpchealth
    2009-02-22 18:13:58 —-D—- C:WINDOWSNetwork Diagnostic
    2009-02-22 18:13:58 —-D—- C:WINDOWSmui
    2009-02-22 18:13:58 —-D—- C:WINDOWSmsapps
    2009-02-22 18:13:58 —-D—- C:WINDOWSmsagent
    2009-02-22 18:13:58 —-D—- C:WINDOWSMedia
    2009-02-22 18:13:58 —-D—- C:WINDOWSL2Schemas
    2009-02-22 18:13:58 —-D—- C:WINDOWSjava
    2009-02-22 18:13:58 —-D—- C:WINDOWSime
    2009-02-22 18:13:58 —-D—- C:WINDOWSHelp
    2009-02-22 18:13:58 —-D—- C:WINDOWSehome
    2009-02-22 18:13:58 —-D—- C:WINDOWSDriver Cache
    2009-02-22 18:13:58 —-D—- C:WINDOWSDebug
    2009-02-22 18:13:58 —-D—- C:WINDOWSCursors
    2009-02-22 18:13:58 —-D—- C:WINDOWSConnection Wizard
    2009-02-22 18:13:58 —-D—- C:WINDOWSConfig
    2009-02-22 18:13:58 —-D—- C:WINDOWSAppPatch
    2009-02-22 18:13:58 —-D—- C:WINDOWSaddins
    2009-02-22 18:13:58 —-D—- C:WINDOWS
    2009-02-22 18:10:06 —-D—- C:Program FilesAvira
    2009-02-22 18:10:06 —-D—- C:Documents and SettingsAll UsersApplication DataAvira
    2009-02-22 17:37:43 —-D—- C:glob
    2009-02-22 16:52:58 —-D—- C:Program FilesSamsung ML-2010 Series
    2009-02-22 16:52:28 —-N—- C:WINDOWSsystem32SSRemove.exe
    2009-02-22 16:52:28 —-D—- C:WINDOWSSamsung
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SUGS2LMK.DLL
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SSCoInst.exe
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SSCoInst.dll
    2009-02-22 16:47:56 —-A—- C:WINDOWSModemLog_Motorola USB Modem.txt
    2009-02-22 16:45:45 —-D—- C:Program FilesAvanquest update
    2009-02-22 16:44:53 —-HD—- C:Program FilesInstallShield Installation Information
    2009-02-22 16:44:53 —-D—- C:Program FilesMotorola Phone Tools
    2009-02-22 16:44:53 —-D—- C:Documents and SettingsAll UsersApplication DataBVRP Software
    2009-02-22 16:44:29 —-D—- C:Program FilesCommon FilesInstallShield
    2009-02-22 16:41:20 —-D—- C:WINDOWSRegisteredPackages
    2009-02-22 16:41:05 —-A—- C:WINDOWSsystem32psisdecd.dll
    2009-02-22 16:41:03 —-A—- C:WINDOWSsystem32dxdllreg.exe
    2009-02-22 16:41:02 —-D—- C:WINDOWSsystem32DirectX
    2009-02-22 16:38:23 —-D—- C:Program FilesLight Alloy
    2009-02-22 16:37:56 —-SHD—- C:RECYCLER
    2009-02-22 16:37:45 —-D—- C:Program FilesWinRAR
    2009-02-22 15:59:42 —-D—- C:Program FilesMicrosoft.NET
    2009-02-22 15:58:15 —-A—- C:WINDOWSODBC.INI
    2009-02-22 15:57:39 —-D—- C:Program FilesCommon FilesDesigner
    2009-02-22 15:57:24 —-D—- C:WINDOWSShellNew
    2009-02-22 15:57:19 —-D—- C:Program FilesMicrosoft Office
    2009-02-22 15:52:19 —-D—- C:Distrib
    2009-02-22 15:45:35 —-D—- C:Documents and SettingsСергейApplication DataIdentities
    2009-02-22 15:45:31 —-HD—- C:Program FilesUninstall Information
    2009-02-22 15:45:19 —-D—- C:WINDOWSInstall
    2009-02-22 15:45:14 —-SD—- C:Documents and SettingsСергейApplication DataMicrosoft
    2009-02-22 15:45:14 —-ASH—- C:Documents and SettingsСергейApplication Datadesktop.ini
    2009-02-22 15:44:23 —-D—- C:WINDOWSPrefetch
    2009-02-22 15:44:22 —-SD—- C:WINDOWSsystem32Microsoft
    2009-02-22 15:44:22 —-A—- C:WINDOWSSchedLgU.Txt
    2009-02-22 15:40:55 —-D—- C:WINDOWSsystem32xircom
    2009-02-22 15:40:55 —-D—- C:Program Filesxerox
    2009-02-22 15:40:55 —-D—- C:Program Filesmicrosoft frontpage
    2009-02-22 15:40:37 —-D—- C:Program FilesCommon FilesAdobe
    2009-02-22 15:39:22 —-RSD—- C:WINDOWSassembly
    2009-02-22 15:39:22 —-D—- C:WINDOWSMicrosoft.NET
    2009-02-22 15:39:20 —-D—- C:WINDOWSsystem32URTTemp
    2009-02-22 15:38:49 —-D—- C:Program FilesMSXML 4.0
    2009-02-22 15:38:37 —-A—- C:WINDOWScontrol.ini
    2009-02-22 15:38:37 —-A—- C:AUTOEXEC.BAT
    2009-02-22 15:38:24 —-A—- C:WINDOWSOEWABLog.txt
    2009-02-22 15:38:18 —-A—- C:WINDOWSsystem32mapi32.dll
    2009-02-22 15:37:05 —-RAH—- C:WINDOWSsystem32logonui.exe.manifest
    2009-02-22 15:36:59 —-RAH—- C:WINDOWSsystem32cdplayer.exe.manifest
    2009-02-22 15:36:52 —-HD—- C:Program FilesWindowsUpdate
    2009-02-22 15:36:39 —-A—- C:WINDOWSsystem32atrace.dll
    2009-02-22 15:36:38 —-A—- C:WINDOWSsystem32nmevtmsg.dll
    2009-02-22 15:36:36 —-D—- C:Program FilesCommon FilesServices
    2009-02-22 15:36:36 —-A—- C:WINDOWSsystem32acctres.dll
    2009-02-22 15:36:34 —-SD—- C:WINDOWSTasks
    2009-02-22 15:36:34 —-A—- C:WINDOWSsystem32icfgnt5.dll
    2009-02-22 15:36:33 —-D—- C:Program FilesCommon FilesMSSoap
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuweb.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wucltui.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuauserv.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuaueng1.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wups.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuaueng.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuauclt1.exe
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuauclt.exe
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuapi.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx4.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx3.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx2.dll
    2009-02-22 15:36:27 —-A—- C:WINDOWSsystem32qmgrprxy.dll
    2009-02-22 15:36:27 —-A—- C:WINDOWSsystem32qmgr.dll
    2009-02-22 15:36:24 —-D—- C:Program FilesMovie Maker
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrslv.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrdm.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrcdlg.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32racpldlg.dll
    2009-02-22 15:35:55 —-A—- C:WINDOWSsystem32fltMc.exe
    2009-02-22 15:35:55 —-A—- C:WINDOWSsystem32fltlib.dll
    2009-02-22 15:35:54 —-D—- C:WINDOWSsystem32Restore
    2009-02-22 15:35:54 —-A—- C:WINDOWSsystem32srsvc.dll
    2009-02-22 15:35:54 —-A—- C:WINDOWSsystem32srrstr.dll
    2009-02-22 15:35:53 —-A—- C:WINDOWSsystem32srclient.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32nmmkcert.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32msconf.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32mnmsrvc.exe
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32mnmdd.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32isrdbg32.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32ils.dll
    2009-02-22 15:35:46 —-D—- C:Program FilesNetMeeting
    2009-02-22 15:35:45 —-A—- C:WINDOWSsystem32msoert2.dll
    2009-02-22 15:35:45 —-A—- C:WINDOWSsystem32msoeacct.dll
    2009-02-22 15:35:43 —-A—- C:WINDOWSsystem32inetres.dll
    2009-02-22 15:35:42 —-A—- C:WINDOWSsystem32inetcomm.dll
    2009-02-22 15:35:40 —-D—- C:Program FilesOutlook Express
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32schedsvc.dll
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32mstinit.exe
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32mstask.dll
    2009-02-22 15:35:39 —-A—- C:WINDOWSsystem32icwphbk.dll
    2009-02-22 15:35:39 —-A—- C:WINDOWSsystem32icwdial.dll
    2009-02-22 15:35:38 —-A—- C:WINDOWSsystem32isign32.dll
    2009-02-22 15:35:38 —-A—- C:WINDOWSsystem32inetcfg.dll
    2009-02-22 15:35:29 —-D—- C:Program FilesCommon FilesSystem
    2009-02-22 15:34:33 —-D—- C:Program FilesComPlus Applications
    2009-02-22 15:34:31 —-A—- C:WINDOWSvbaddin.ini
    2009-02-22 15:34:31 —-A—- C:WINDOWSvb.ini
    2009-02-22 15:34:26 —-D—- C:WINDOWSRegistration
    2009-02-22 15:34:05 —-D—- C:Program FilesTaskSwitchXP
    2009-02-22 15:33:59 —-D—- C:WINDOWSsystem32Macromed
    2009-02-22 15:33:57 —-A—- C:WINDOWSsystem32wiaaut.dll
    2009-02-22 15:33:53 —-D—- C:Program FilesPaint.NET
    2009-02-22 15:33:52 —-A—- C:WINDOWSsystem32REBUILDI.EXE
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32Path2Clipboard.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32HashTab.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32FileNote.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32DirSize.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32CDClose.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSExt2Mgr.exe
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32target.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32mp3tagv.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32Layout.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32DLLINFO.DLL
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32cpext.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32xvidvfw.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32xvidcore.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32x264vfw.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32WMV9VCM.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32VSFilter.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32vorbisfile.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32vct3216.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32ts.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32StreamIO.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32qt-dx331.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32pncrt.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32ogm.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32MP4FileLib.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32mp4.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32mmfinfo.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkzlib.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkx.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkunicode.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32Ir50_lcs.dll
    2009-02-22 15:33:42 —-A—- C:WINDOWSsystem32dxr.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drvc.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drv2.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drv1.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32dllzAAC.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32divxsm.exe
    2009-02-22 15:33:39 —-A—- C:WINDOWSsystem32cook.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avss.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avs.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avi.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32AudioCodec.dll
    2009-02-22 15:33:37 —-A—- C:WINDOWSsystem324codeDecoder.dll
    2009-02-22 15:33:26 —-D—- C:Program FilesWindows Media Player
    2009-02-22 15:33:26 —-D—- C:Program FilesWindows Media Connect 2
    2009-02-22 15:33:21 —-SD—- C:WINDOWSDownloaded Program Files
    2009-02-22 15:33:21 —-RD—- C:WINDOWSOffline Web Pages
    2009-02-22 15:33:21 —-A—- C:WINDOWSsystem32winfxdocobj.exe
    2009-02-22 15:33:20 —-D—- C:WINDOWSwbem
    2009-02-22 15:33:20 —-A—- C:WINDOWSsystem32msfeedssync.exe
    2009-02-22 15:33:20 —-A—- C:WINDOWSsystem32msfeedsbs.dll
    2009-02-22 15:33:18 —-A—- C:WINDOWSsystem32ieframe.dll.mui
    2009-02-22 15:33:17 —-D—- C:Program FilesInternet Explorer
    2009-02-22 15:33:17 —-A—- C:WINDOWSsystem32advpack.dll.mui
    2009-02-22 15:33:16 —-D—- C:WINDOWSSoftwareDistribution
    2009-02-22 15:33:16 —-A—- C:WINDOWSsystem32muweb.dll
    2009-02-22 15:33:15 —-A—- C:WINDOWSsystem32gpprefcl.dll
    2009-02-22 15:33:14 —-A—- C:WINDOWSsystem32write.exe
    2009-02-22 15:33:02 —-A—- C:WINDOWSsystem32sndvol32.exe
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32hticons.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avwav.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avtapi.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avmeter.dll
    2009-02-22 15:32:59 —-A—- C:WINDOWSsystem32winchat.exe
    2009-02-22 15:32:49 —-A—- C:WINDOWSsystem32getuname.dll
    2009-02-22 15:32:49 —-A—- C:WINDOWSsystem32charmap.exe
    2009-02-22 15:32:48 —-A—- C:WINDOWSsystem32calc.exe
    2009-02-22 15:32:47 —-A—- C:WINDOWSsystem32winmine.exe
    2009-02-22 15:32:47 —-A—- C:WINDOWSsystem32sol.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32usrlogon.cmd
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32reset.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32mshearts.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32freecell.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tsshutdn.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tslabels.ini
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tskill.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tsdiscon.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tscon.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32shadow.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32rwinsta.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32regini.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32rdpcfgex.dll
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32qwinsta.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32qappsrv.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32msg.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32logoff.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32cdmodem.dll
    2009-02-22 15:32:43 —-A—- C:WINDOWSsystem32msdtcprf.ini
    2009-02-22 15:32:34 —-A—- C:WINDOWSsystem32wmimgmt.msc
    2009-02-22 15:32:32 —-A—- C:WINDOWSsystem32sndrec32.exe
    2009-02-22 15:32:32 —-A—- C:WINDOWSsystem32accwiz.exe
    2009-02-22 15:32:31 —-A—- C:WINDOWSsystem32mplay32.exe
    2009-02-22 15:32:31 —-A—- C:WINDOWSsystem32hypertrm.dll
    2009-02-22 15:32:30 —-D—- C:Program FilesWindows NT
    2009-02-22 15:32:30 —-A—- C:WINDOWSsystem32mspaint.exe
    2009-02-22 15:32:29 —-A—- C:WINDOWSsystem32clipbrd.exe
    2009-02-22 15:32:28 —-A—- C:WINDOWSsystem32spider.exe
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32tsgqec.dll
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32tscfgwmi.dll
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32rhttpaa.dll
    2009-02-22 15:32:25 —-A—- C:WINDOWSsystem32aaclient.dll
    2009-02-22 15:32:24 —-A—- C:WINDOWSsystem32mstscax.dll
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32sessmgr.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32remotepg.dll
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32rdshost.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32rdsaddin.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32mstsc.exe
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32termsrv.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpwsx.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpsnd.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpclip.exe
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdchost.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32qprocess.exe
    2009-02-22 15:32:21 —-A—- C:WINDOWSsystem32icaapi.dll
    2009-02-22 15:32:21 —-A—- C:WINDOWSsystem32cfgbkend.dll
    2009-02-22 15:32:20 —-D—- C:WINDOWSsystem32MsDtc
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32mtxoci.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtcuiu.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtctm.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtcprx.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32xolehlp.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32msdtclog.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32msdtc.exe
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxlegih.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxex.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxdm.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32dcomcnfg.exe
    2009-02-22 15:32:16 —-D—- C:WINDOWSsystem32Com
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32comrepl.dll
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32comaddin.dll
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32colbact.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32stclient.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32clbcatex.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32catsrvps.dll
    2009-02-22 15:32:14 —-A—- C:WINDOWSsystem32catsrvut.dll
    2009-02-22 15:32:14 —-A—- C:WINDOWSsystem32catsrv.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comuid.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comsvcs.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comsnap.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32clbcatq.dll
    2009-02-22 15:32:04 —-A—- C:WINDOWSsystem32servdeps.dll
    2009-02-22 15:32:04 —-A—- C:WINDOWSsystem32mmfutil.dll
    2009-02-22 15:32:03 —-A—- C:WINDOWSsystem32licwmi.dll
    2009-02-22 15:32:03 —-A—- C:WINDOWSsystem32cmprops.dll

    ======List of files/folders modified in the last 1 months======

    2009-03-06 17:40:16 —-A—- C:WINDOWSwin.ini
    2009-02-22 18:26:20 —-A—- C:WINDOWSsystem.ini

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AFS2K;AFS2k; C:WINDOWSsystem32driversAFS2K.sys [2009-03-02 82380]
    R1 avgio;avgio; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgio.sys []
    R1 avipbb;avipbb; C:WINDOWSsystem32DRIVERSavipbb.sys [2008-10-30 75072]
    R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-15 40704]
    R1 ssmdrv;ssmdrv; C:WINDOWSsystem32DRIVERSssmdrv.sys [2007-03-01 28352]
    R2 DgiVecp;Team MFP Comm Driver; C:WINDOWSSystem32DriversDgiVecp.sys [2005-03-14 41984]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2008-01-25 4127488]
    R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2008-02-26 2863616]
    R3 avgntflt;avgntflt; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgntflt.sys []
    R3 msloop;Драйвер адаптера Microsoft замыкания на себя; C:WINDOWSsystem32DRIVERSloop.sys [2008-06-01 4992]
    R3 nvmpu401;Service for NVIDIA(R) nForce(TM) MIDI UART; C:WINDOWSsystem32driversnvmpu401.sys [2006-02-26 10240]
    R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet адаптер, драйвер для NT; C:WINDOWSsystem32DRIVERSRTL8139.SYS [2008-06-02 20992]
    R3 TTDVBLCD;TechnoTrend DVB PCI budget Driver; C:WINDOWSsystem32DRIVERSttdvblcd.sys [2006-02-03 66176]
    R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-06-01 30336]
    R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-06-02 59520]
    R3 usbsermpt;Motorola USB Modem Driver for MPT; C:WINDOWSsystem32DRIVERSusbsermpt.sys [2009-02-22 22768]
    R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-06-02 20608]
    S3 Ext2Fsd;Linux ext2 File system driver; C:WINDOWSsystem32driversExt2Fsd.sys [2008-01-27 644240]
    S3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-06-01 15104]
    S3 usbser;Motorola USB Modem Driver; C:WINDOWSsystem32DRIVERSusbser.sys [2008-06-01 26112]
    S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-06-01 26368]
    S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2007-06-18 77568]
    S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2007-06-18 82944]
    S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AntiVirScheduler;Avira AntiVir Personal — Free Antivirus Scheduler; C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe [2008-10-15 68865]
    R2 AntiVirService;Avira AntiVir Personal — Free Antivirus Guard; C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe [2008-10-15 151297]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:WINDOWSsystem32Ati2evxx.exe [2008-02-26 520192]
    R2 UPHClean;User Profile Hive Cleanup; C:WINDOWSsystem32uphclean.exe [2006-01-16 241725]
    S2 winsecguard;Windows Security Guard; C:WINDOWSInfzpx2.exe winsecguard C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}components []
    S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv1.1.4322aspnet_state.exe [2004-07-15 32768]
    S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]


    EOF


    11 марта, 2009 в 3:14 пп #22474
    Admin
    Keymaster
    • Темы:40
    • Сообщений:5676
    • ☆☆☆☆☆

    Получше, но осталось ещё немножко.
    Запустите OTMoveIt3 и в большое поле ввода (заголовок этого поля выделен желтым цветом) скопируйте следующий текст.

    :Processes
    explorer.exe

    :services
    winsecguard

    :files
    C:WINDOWSInfzpx2.exe
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z}

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]

    Проверьте вставленный скрипт, если слева перед директивами появились пробелы, то удалите их, скрипт должен выглядеть так же как в сообщении. Кликните по кнопке MoveIt!. В процессе работы возможна перезагрузка компьютера.
    По-завершении работы программы должен будет показан лог. Если лог не будет показан, то его можно найти в папке C:_OTMoveItMovedFiles.

    Вставьте в ваше ответное сообщение содержимое этого лога. И ещё раз приложите свежий RSIT лог.

    13 марта, 2009 в 7:13 дп #22475
    Аноним
    Гость
    • Темы:532
    • Сообщений:1553
    • ☆☆☆☆☆

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    Service winsecguard stopped successfully.
    Service winsecguard deleted successfully.
    ========== FILES ==========
    File/Folder C:WINDOWSInfzpx2.exe not found.
    C:Program FilesCommon Files{6EA9B29A-C801-4F76-805F-E41ACF9ED16Z} moved successfully.
    ========== COMMANDS ==========
    User’s Temp folder emptied.
    User’s Temporary Internet Files folder emptied.
    User’s Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:Documents and SettingsLocalServiceLocal SettingsTemporary Internet FilesContent.IE5index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer — Version 1.0.8.0 log created on 03132009_100026

    Logfile of random’s system information tool 1.05 (written by random/random)
    Run by Сергей at 2009-03-13 10:12:02
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 147 GB (96%) free of 153 GB
    Total RAM: 511 MB (55% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:12:04, on 13.03.2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20772)
    Boot mode: Normal

    Running processes:
    C:WINDOWSSystem32smss.exe
    C:WINDOWSsystem32winlogon.exe
    C:WINDOWSsystem32services.exe
    C:WINDOWSsystem32lsass.exe
    C:WINDOWSsystem32Ati2evxx.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:WINDOWSsystem32Ati2evxx.exe
    C:WINDOWSsystem32spoolsv.exe
    C:WINDOWSExplorer.EXE
    C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
    C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSsystem32uphclean.exe
    C:WINDOWSSOUNDMAN.EXE
    C:Program FilesTaskSwitchXPTaskSwitchXP.exe
    C:WINDOWSSamsungComSMMgrssmmgr.exe
    C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
    C:Program FilesJavaj2re1.4.2_01binjusched.exe
    C:WINDOWSsystem32ctfmon.exe
    C:globglobax_daemon.exe
    C:DistribспутникsatcalcSatCalc_TT.exe
    C:Program FilesInternet ExplorerIEXPLORE.EXE
    C:Documents and SettingsСергейРабочий столRSIT.exe
    C:Program Filestrend microСергей.exe

    R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://google.ru
    R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://samlab.ws
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
    R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
    R1 — HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 127.0.0.1:3128
    R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
    O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
    O4 — HKLM..Run: [TaskSwitchXP] C:Program FilesTaskSwitchXPTaskSwitchXP.exe
    O4 — HKLM..Run: [Samsung Common SM] «C:WINDOWSSamsungComSMMgrssmmgr.exe» /autorun
    O4 — HKLM..Run: [avgnt] «C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe» /min
    O4 — HKLM..Run: [zzzHPSETUP] D:Setup.exe
    O4 — HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_01binjusched.exe
    O4 — HKLM..RunOnce: [ZZ_WSE] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%infwse.inf,WSESetting,0
    O4 — HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
    O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [Rebuild Icon Cache] REBUILDI.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [IE7_011] regsvr32 /s /n /i:u shell32 (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-19..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
    O4 — HKUSS-1-5-20..RunOnce: [Rebuild Icon Cache] REBUILDI.EXE (User ‘NETWORK SERVICE’)
    O4 — Startup: globax_daemon.lnk = C:globglobax_daemon.exe
    O4 — Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
    O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
    O9 — Extra button: (no name) — {08B0E5C0-4FCB-11CF-AAA5-00401C608501} — C:Program FilesJavaj2re1.4.2_01binnpjpi142_01.dll
    O9 — Extra ‘Tools’ menuitem: Sun Java Console — {08B0E5C0-4FCB-11CF-AAA5-00401C608501} — C:Program FilesJavaj2re1.4.2_01binnpjpi142_01.dll
    O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
    O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O17 — HKLMSystemCCSServicesTcpip..{AFC9C10A-6A41-4997-983F-E296939D2962}: NameServer = 80.69.145.67 80.69.156.226
    O23 — Service: Avira AntiVir Personal — Free Antivirus Scheduler (AntiVirScheduler) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
    O23 — Service: Avira AntiVir Personal — Free Antivirus Guard (AntiVirService) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
    O23 — Service: Ati HotKey Poller — ATI Technologies Inc. — C:WINDOWSsystem32Ati2evxx.exe
    O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
    O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
    O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
    O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
    O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
    O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
    O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe

    —
    End of file — 6221 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
    «SoundMan»=C:WINDOWSSOUNDMAN.EXE [2007-04-16 577536]
    «TaskSwitchXP»=C:Program FilesTaskSwitchXPTaskSwitchXP.exe [2007-03-09 62976]
    «Samsung Common SM»=C:WINDOWSSamsungComSMMgrssmmgr.exe [2005-07-03 372736]
    «avgnt»=C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe [2008-06-12 266497]
    «zzzHPSETUP»=D:Setup.exe []
    «SunJavaUpdateSched»=C:Program FilesJavaj2re1.4.2_01binjusched.exe [2003-08-19 32873]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce]
    «ZZ_WSE»=C:WINDOWSsystem32advpack.dll [2008-06-01 124928]

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
    «CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2008-04-15 15360]

    C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
    Microsoft Office.lnk — C:Program FilesMicrosoft OfficeOffice10OSA.EXE

    C:Documents and SettingsСергейГлавное менюПрограммыАвтозагрузка
    globax_daemon.lnk — C:globglobax_daemon.exe

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAtiExtEvent]
    C:WINDOWSsystem32Ati2evxx.dll [2008-02-26 126976]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
    WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2007-06-18 133632]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    «dontdisplaylastusername»=0
    «legalnoticecaption»=
    «legalnoticetext»=
    «shutdownwithoutlogon»=1
    «undockwithoutlogon»=1

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=145
    «ForceClassicControlPanel»=1
    «NoSharedDocuments»=1
    «NoThumbnailCache»=1

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    ======List of files/folders created in the last 1 months======

    2009-03-09 17:42:44 —-D—- C:Program FilesMozilla Firefox
    2009-03-09 17:36:55 —-D—- C:Documents and SettingsСергейApplication DataOpera
    2009-03-09 17:36:44 —-D—- C:Documents and SettingsСергейApplication DataSun
    2009-03-09 17:36:43 —-A—- C:WINDOWSsystem32javaw.exe
    2009-03-09 17:36:42 —-A—- C:WINDOWSsystem32java.exe
    2009-03-09 17:36:29 —-D—- C:Program FilesJava
    2009-03-09 17:36:29 —-D—- C:Program FilesCommon FilesJava
    2009-03-09 17:36:08 —-D—- C:Program FilesOpera75
    2009-03-09 09:11:39 —-D—- C:_OTMoveIt
    2009-03-07 12:24:27 —-D—- C:Documents and SettingsСергейApplication DataMozilla
    2009-03-07 11:40:46 —-D—- C:Program Filestrend micro
    2009-03-07 11:40:45 —-D—- C:rsit
    2009-03-02 18:44:27 —-D—- C:Documents and SettingsСергейApplication DataПапка выгрузки Share-to-Web
    2009-03-02 18:43:05 —-D—- C:Program FilesCommon FilesHewlett-Packard
    2009-03-02 18:42:55 —-D—- C:Program FilesHewlett-Packard
    2009-03-02 18:42:19 —-D—- C:UniScan
    2009-03-02 18:42:14 —-RA—- C:WINDOWSsystem32hpsjvset.dll
    2009-03-02 18:42:13 —-RA—- C:WINDOWSsystem32hpgt2436.dll
    2009-03-02 18:42:12 —-RA—- C:WINDOWSsystem32hpgwiamd.dll
    2009-02-28 21:10:23 —-D—- C:Documents and SettingsСергейApplication DataMacromedia
    2009-02-28 07:59:15 —-D—- C:ИГРЫ
    2009-02-27 17:27:12 —-D—- C:Program FilesCommon FilesDirectX
    2009-02-22 18:31:13 —-A—- C:WINDOWSsystem32h323log.txt
    2009-02-22 18:28:49 —-A—- C:WINDOWSsystem32ksuser.dll
    2009-02-22 18:28:38 —-A—- C:WINDOWSsystem32usbui.dll
    2009-02-22 18:26:30 —-A—- C:WINDOWSimsins.BAK
    2009-02-22 18:26:27 —-SHD—- C:WINDOWSInstaller
    2009-02-22 18:26:27 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
    2009-02-22 18:26:26 —-D—- C:Program FilesCommon FilesODBC
    2009-02-22 18:26:26 —-A—- C:WINDOWSODBCINST.INI
    2009-02-22 18:26:22 —-D—- C:Program FilesCommon FilesSpeechEngines
    2009-02-22 18:26:21 —-RD—- C:Program Files
    2009-02-22 18:26:21 —-D—- C:Program FilesCommon FilesMicrosoft Shared
    2009-02-22 18:26:21 —-D—- C:Program FilesCommon Files
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdtuq.dll
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdtuf.dll
    2009-02-22 18:26:15 —-RA—- C:WINDOWSsystem32kbdazel.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhept.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhela3.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhela2.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe319.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe220.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdhe.dll
    2009-02-22 18:26:11 —-RA—- C:WINDOWSsystem32kbdgkl.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlv1.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlv.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlt1.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdlt.dll
    2009-02-22 18:26:07 —-RA—- C:WINDOWSsystem32kbdest.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdycl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdsl1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdsl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdro.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdpl1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdpl.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdhu1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdhu.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz2.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz1.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcz.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32kbdcr.dll
    2009-02-22 18:26:03 —-RA—- C:WINDOWSsystem32KBDAL.DLL
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdycc.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbduzb.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdur.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdtat.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdmon.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdkyr.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdkaz.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdbu.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdblr.dll
    2009-02-22 18:25:55 —-A—- C:WINDOWSsystem32kbdaze.dll
    2009-02-22 18:25:53 —-A—- C:WINDOWSsystem32irclass.dll
    2009-02-22 18:25:52 —-A—- C:WINDOWSsystem32dgsetup.dll
    2009-02-22 18:25:52 —-A—- C:WINDOWSsystem32dgrpsetu.dll
    2009-02-22 18:25:51 —-A—- C:WINDOWSsystem32spxcoins.dll
    2009-02-22 18:25:51 —-A—- C:WINDOWSsystem32EqnClass.Dll
    2009-02-22 18:25:47 —-N—- C:WINDOWSsystem32CONFIG.TMP
    2009-02-22 18:25:47 —-A—- C:WINDOWSTASKMAN.EXE
    2009-02-22 18:25:46 —-A—- C:WINDOWSsystem32batt.dll
    2009-02-22 18:25:44 —-A—- C:WINDOWSNOTEPAD.EXE
    2009-02-22 18:25:43 —-A—- C:WINDOWSsystem32storprop.dll
    2009-02-22 18:25:35 —-ASH—- C:Documents and SettingsAll UsersApplication Datadesktop.ini
    2009-02-22 18:25:23 —-RA—- C:WINDOWSSET8.tmp
    2009-02-22 18:25:17 —-RA—- C:WINDOWSSET4.tmp
    2009-02-22 18:25:15 —-RA—- C:WINDOWSSET3.tmp
    2009-02-22 18:25:08 —-D—- C:WINDOWSsystem32CatRoot2
    2009-02-22 18:25:08 —-D—- C:WINDOWSsystem32CatRoot
    2009-02-22 18:25:03 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
    2009-02-22 18:24:47 —-A—- C:WINDOWSsetuplog.txt
    2009-02-22 18:21:34 —-A—- C:WINDOWSsystem32RTLCPAPI.dll
    2009-02-22 18:21:34 —-A—- C:WINDOWSSOUNDMAN.EXE
    2009-02-22 18:21:33 —-A—- C:WINDOWSsystem32RTLCPL.EXE
    2009-02-22 18:21:32 —-A—- C:WINDOWSAlcrmv.exe
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32Oemdspif.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32ativvaxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32ativcoxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atitvo32.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atipdlxx.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atiok3x2.dll
    2009-02-22 18:20:31 —-A—- C:WINDOWSsystem32atioglxx.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atioglx2.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atikvmag.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32atiiiexx.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32ATIDEMGX.dll
    2009-02-22 18:20:30 —-A—- C:WINDOWSsystem32ATIDDC.DLL
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati3duag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32Ati2mdxx.exe
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2evxx.exe
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2evxx.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2edxx.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2dvag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32ati2cqag.dll
    2009-02-22 18:20:29 —-A—- C:WINDOWSsystem32amdpcom32.dll
    2009-02-22 18:19:23 —-A—- C:changelog.txt
    2009-02-22 18:19:14 —-SHD—- C:System Volume Information
    2009-02-22 18:19:14 —-D—- C:Documents and Settings
    2009-02-22 18:18:23 —-SH—- C:boot.ini
    2009-02-22 18:13:58 —-RSHDC—- C:WINDOWSsystem32dllcache
    2009-02-22 18:13:58 —-RSD—- C:WINDOWSFonts
    2009-02-22 18:13:58 —-RD—- C:WINDOWSWeb
    2009-02-22 18:13:58 —-HD—- C:WINDOWSinf
    2009-02-22 18:13:58 —-D—- C:WINDOWSWinSxS
    2009-02-22 18:13:58 —-D—- C:WINDOWStwain_32
    2009-02-22 18:13:58 —-D—- C:WINDOWSTemp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32wins
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32wbem
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32usmt
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32spool
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ShellExt
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32Setup
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ru-ru
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ru
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ras
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32oobe
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32npp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32mui
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32inetsrv
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32IME
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32icsxml
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32ias
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32export
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32drivers
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32dhcp
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32config
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem323com_dmi
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem323076
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem322052
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321054
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321049
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321042
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321041
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321037
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321033
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321031
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321028
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem321025
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem32
    2009-02-22 18:13:58 —-D—- C:WINDOWSsystem
    2009-02-22 18:13:58 —-D—- C:WINDOWSsecurity
    2009-02-22 18:13:58 —-D—- C:WINDOWSResources
    2009-02-22 18:13:58 —-D—- C:WINDOWSrepair
    2009-02-22 18:13:58 —-D—- C:WINDOWSProvisioning
    2009-02-22 18:13:58 —-D—- C:WINDOWSPeerNet
    2009-02-22 18:13:58 —-D—- C:WINDOWSpchealth
    2009-02-22 18:13:58 —-D—- C:WINDOWSNetwork Diagnostic
    2009-02-22 18:13:58 —-D—- C:WINDOWSmui
    2009-02-22 18:13:58 —-D—- C:WINDOWSmsapps
    2009-02-22 18:13:58 —-D—- C:WINDOWSmsagent
    2009-02-22 18:13:58 —-D—- C:WINDOWSMedia
    2009-02-22 18:13:58 —-D—- C:WINDOWSL2Schemas
    2009-02-22 18:13:58 —-D—- C:WINDOWSjava
    2009-02-22 18:13:58 —-D—- C:WINDOWSime
    2009-02-22 18:13:58 —-D—- C:WINDOWSHelp
    2009-02-22 18:13:58 —-D—- C:WINDOWSehome
    2009-02-22 18:13:58 —-D—- C:WINDOWSDriver Cache
    2009-02-22 18:13:58 —-D—- C:WINDOWSDebug
    2009-02-22 18:13:58 —-D—- C:WINDOWSCursors
    2009-02-22 18:13:58 —-D—- C:WINDOWSConnection Wizard
    2009-02-22 18:13:58 —-D—- C:WINDOWSConfig
    2009-02-22 18:13:58 —-D—- C:WINDOWSAppPatch
    2009-02-22 18:13:58 —-D—- C:WINDOWSaddins
    2009-02-22 18:13:58 —-D—- C:WINDOWS
    2009-02-22 18:10:06 —-D—- C:Program FilesAvira
    2009-02-22 18:10:06 —-D—- C:Documents and SettingsAll UsersApplication DataAvira
    2009-02-22 17:37:43 —-D—- C:glob
    2009-02-22 16:52:58 —-D—- C:Program FilesSamsung ML-2010 Series
    2009-02-22 16:52:28 —-N—- C:WINDOWSsystem32SSRemove.exe
    2009-02-22 16:52:28 —-D—- C:WINDOWSSamsung
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SUGS2LMK.DLL
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SSCoInst.exe
    2009-02-22 16:52:08 —-A—- C:WINDOWSsystem32SSCoInst.dll
    2009-02-22 16:47:56 —-A—- C:WINDOWSModemLog_Motorola USB Modem.txt
    2009-02-22 16:45:45 —-D—- C:Program FilesAvanquest update
    2009-02-22 16:44:53 —-HD—- C:Program FilesInstallShield Installation Information
    2009-02-22 16:44:53 —-D—- C:Program FilesMotorola Phone Tools
    2009-02-22 16:44:53 —-D—- C:Documents and SettingsAll UsersApplication DataBVRP Software
    2009-02-22 16:44:29 —-D—- C:Program FilesCommon FilesInstallShield
    2009-02-22 16:41:20 —-D—- C:WINDOWSRegisteredPackages
    2009-02-22 16:41:05 —-A—- C:WINDOWSsystem32psisdecd.dll
    2009-02-22 16:41:03 —-A—- C:WINDOWSsystem32dxdllreg.exe
    2009-02-22 16:41:02 —-D—- C:WINDOWSsystem32DirectX
    2009-02-22 16:38:23 —-D—- C:Program FilesLight Alloy
    2009-02-22 16:37:56 —-SHD—- C:RECYCLER
    2009-02-22 16:37:45 —-D—- C:Program FilesWinRAR
    2009-02-22 15:59:42 —-D—- C:Program FilesMicrosoft.NET
    2009-02-22 15:58:15 —-A—- C:WINDOWSODBC.INI
    2009-02-22 15:57:39 —-D—- C:Program FilesCommon FilesDesigner
    2009-02-22 15:57:24 —-D—- C:WINDOWSShellNew
    2009-02-22 15:57:19 —-D—- C:Program FilesMicrosoft Office
    2009-02-22 15:52:19 —-D—- C:Distrib
    2009-02-22 15:45:35 —-D—- C:Documents and SettingsСергейApplication DataIdentities
    2009-02-22 15:45:31 —-HD—- C:Program FilesUninstall Information
    2009-02-22 15:45:19 —-D—- C:WINDOWSInstall
    2009-02-22 15:45:14 —-SD—- C:Documents and SettingsСергейApplication DataMicrosoft
    2009-02-22 15:45:14 —-ASH—- C:Documents and SettingsСергейApplication Datadesktop.ini
    2009-02-22 15:44:23 —-D—- C:WINDOWSPrefetch
    2009-02-22 15:44:22 —-SD—- C:WINDOWSsystem32Microsoft
    2009-02-22 15:44:22 —-A—- C:WINDOWSSchedLgU.Txt
    2009-02-22 15:40:55 —-D—- C:WINDOWSsystem32xircom
    2009-02-22 15:40:55 —-D—- C:Program Filesxerox
    2009-02-22 15:40:55 —-D—- C:Program Filesmicrosoft frontpage
    2009-02-22 15:40:37 —-D—- C:Program FilesCommon FilesAdobe
    2009-02-22 15:39:22 —-RSD—- C:WINDOWSassembly
    2009-02-22 15:39:22 —-D—- C:WINDOWSMicrosoft.NET
    2009-02-22 15:39:20 —-D—- C:WINDOWSsystem32URTTemp
    2009-02-22 15:38:49 —-D—- C:Program FilesMSXML 4.0
    2009-02-22 15:38:37 —-A—- C:WINDOWScontrol.ini
    2009-02-22 15:38:37 —-A—- C:AUTOEXEC.BAT
    2009-02-22 15:38:24 —-A—- C:WINDOWSOEWABLog.txt
    2009-02-22 15:38:18 —-A—- C:WINDOWSsystem32mapi32.dll
    2009-02-22 15:37:05 —-RAH—- C:WINDOWSsystem32logonui.exe.manifest
    2009-02-22 15:36:59 —-RAH—- C:WINDOWSsystem32cdplayer.exe.manifest
    2009-02-22 15:36:52 —-HD—- C:Program FilesWindowsUpdate
    2009-02-22 15:36:39 —-A—- C:WINDOWSsystem32atrace.dll
    2009-02-22 15:36:38 —-A—- C:WINDOWSsystem32nmevtmsg.dll
    2009-02-22 15:36:36 —-D—- C:Program FilesCommon FilesServices
    2009-02-22 15:36:36 —-A—- C:WINDOWSsystem32acctres.dll
    2009-02-22 15:36:34 —-SD—- C:WINDOWSTasks
    2009-02-22 15:36:34 —-A—- C:WINDOWSsystem32icfgnt5.dll
    2009-02-22 15:36:33 —-D—- C:Program FilesCommon FilesMSSoap
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuweb.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wucltui.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuauserv.dll
    2009-02-22 15:36:29 —-A—- C:WINDOWSsystem32wuaueng1.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wups.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuaueng.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuauclt1.exe
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuauclt.exe
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32wuapi.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx4.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx3.dll
    2009-02-22 15:36:28 —-A—- C:WINDOWSsystem32bitsprx2.dll
    2009-02-22 15:36:27 —-A—- C:WINDOWSsystem32qmgrprxy.dll
    2009-02-22 15:36:27 —-A—- C:WINDOWSsystem32qmgr.dll
    2009-02-22 15:36:24 —-D—- C:Program FilesMovie Maker
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrslv.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrdm.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32safrcdlg.dll
    2009-02-22 15:36:02 —-A—- C:WINDOWSsystem32racpldlg.dll
    2009-02-22 15:35:55 —-A—- C:WINDOWSsystem32fltMc.exe
    2009-02-22 15:35:55 —-A—- C:WINDOWSsystem32fltlib.dll
    2009-02-22 15:35:54 —-D—- C:WINDOWSsystem32Restore
    2009-02-22 15:35:54 —-A—- C:WINDOWSsystem32srsvc.dll
    2009-02-22 15:35:54 —-A—- C:WINDOWSsystem32srrstr.dll
    2009-02-22 15:35:53 —-A—- C:WINDOWSsystem32srclient.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32nmmkcert.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32msconf.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32mnmsrvc.exe
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32mnmdd.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32isrdbg32.dll
    2009-02-22 15:35:52 —-A—- C:WINDOWSsystem32ils.dll
    2009-02-22 15:35:46 —-D—- C:Program FilesNetMeeting
    2009-02-22 15:35:45 —-A—- C:WINDOWSsystem32msoert2.dll
    2009-02-22 15:35:45 —-A—- C:WINDOWSsystem32msoeacct.dll
    2009-02-22 15:35:43 —-A—- C:WINDOWSsystem32inetres.dll
    2009-02-22 15:35:42 —-A—- C:WINDOWSsystem32inetcomm.dll
    2009-02-22 15:35:40 —-D—- C:Program FilesOutlook Express
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32schedsvc.dll
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32mstinit.exe
    2009-02-22 15:35:40 —-A—- C:WINDOWSsystem32mstask.dll
    2009-02-22 15:35:39 —-A—- C:WINDOWSsystem32icwphbk.dll
    2009-02-22 15:35:39 —-A—- C:WINDOWSsystem32icwdial.dll
    2009-02-22 15:35:38 —-A—- C:WINDOWSsystem32isign32.dll
    2009-02-22 15:35:38 —-A—- C:WINDOWSsystem32inetcfg.dll
    2009-02-22 15:35:29 —-D—- C:Program FilesCommon FilesSystem
    2009-02-22 15:34:33 —-D—- C:Program FilesComPlus Applications
    2009-02-22 15:34:31 —-A—- C:WINDOWSvbaddin.ini
    2009-02-22 15:34:31 —-A—- C:WINDOWSvb.ini
    2009-02-22 15:34:26 —-D—- C:WINDOWSRegistration
    2009-02-22 15:34:05 —-D—- C:Program FilesTaskSwitchXP
    2009-02-22 15:33:59 —-D—- C:WINDOWSsystem32Macromed
    2009-02-22 15:33:57 —-A—- C:WINDOWSsystem32wiaaut.dll
    2009-02-22 15:33:53 —-D—- C:Program FilesPaint.NET
    2009-02-22 15:33:52 —-A—- C:WINDOWSsystem32REBUILDI.EXE
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32Path2Clipboard.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32HashTab.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32FileNote.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32DirSize.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSsystem32CDClose.dll
    2009-02-22 15:33:51 —-A—- C:WINDOWSExt2Mgr.exe
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32target.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32mp3tagv.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32Layout.dll
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32DLLINFO.DLL
    2009-02-22 15:33:50 —-A—- C:WINDOWSsystem32cpext.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32xvidvfw.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32xvidcore.dll
    2009-02-22 15:33:49 —-A—- C:WINDOWSsystem32x264vfw.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32WMV9VCM.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32VSFilter.dll
    2009-02-22 15:33:48 —-A—- C:WINDOWSsystem32vorbisfile.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32vct3216.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32ts.dll
    2009-02-22 15:33:47 —-A—- C:WINDOWSsystem32StreamIO.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32qt-dx331.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32pncrt.dll
    2009-02-22 15:33:45 —-A—- C:WINDOWSsystem32ogm.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32MP4FileLib.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32mp4.dll
    2009-02-22 15:33:44 —-A—- C:WINDOWSsystem32mmfinfo.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkzlib.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkx.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32mkunicode.dll
    2009-02-22 15:33:43 —-A—- C:WINDOWSsystem32Ir50_lcs.dll
    2009-02-22 15:33:42 —-A—- C:WINDOWSsystem32dxr.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drvc.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drv2.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32drv1.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32dllzAAC.dll
    2009-02-22 15:33:41 —-A—- C:WINDOWSsystem32divxsm.exe
    2009-02-22 15:33:39 —-A—- C:WINDOWSsystem32cook.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avss.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avs.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32avi.dll
    2009-02-22 15:33:38 —-A—- C:WINDOWSsystem32AudioCodec.dll
    2009-02-22 15:33:37 —-A—- C:WINDOWSsystem324codeDecoder.dll
    2009-02-22 15:33:26 —-D—- C:Program FilesWindows Media Player
    2009-02-22 15:33:26 —-D—- C:Program FilesWindows Media Connect 2
    2009-02-22 15:33:21 —-SD—- C:WINDOWSDownloaded Program Files
    2009-02-22 15:33:21 —-RD—- C:WINDOWSOffline Web Pages
    2009-02-22 15:33:21 —-A—- C:WINDOWSsystem32winfxdocobj.exe
    2009-02-22 15:33:20 —-D—- C:WINDOWSwbem
    2009-02-22 15:33:20 —-A—- C:WINDOWSsystem32msfeedssync.exe
    2009-02-22 15:33:20 —-A—- C:WINDOWSsystem32msfeedsbs.dll
    2009-02-22 15:33:18 —-A—- C:WINDOWSsystem32ieframe.dll.mui
    2009-02-22 15:33:17 —-D—- C:Program FilesInternet Explorer
    2009-02-22 15:33:17 —-A—- C:WINDOWSsystem32advpack.dll.mui
    2009-02-22 15:33:16 —-D—- C:WINDOWSSoftwareDistribution
    2009-02-22 15:33:16 —-A—- C:WINDOWSsystem32muweb.dll
    2009-02-22 15:33:15 —-A—- C:WINDOWSsystem32gpprefcl.dll
    2009-02-22 15:33:14 —-A—- C:WINDOWSsystem32write.exe
    2009-02-22 15:33:02 —-A—- C:WINDOWSsystem32sndvol32.exe
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32hticons.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avwav.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avtapi.dll
    2009-02-22 15:33:01 —-A—- C:WINDOWSsystem32avmeter.dll
    2009-02-22 15:32:59 —-A—- C:WINDOWSsystem32winchat.exe
    2009-02-22 15:32:49 —-A—- C:WINDOWSsystem32getuname.dll
    2009-02-22 15:32:49 —-A—- C:WINDOWSsystem32charmap.exe
    2009-02-22 15:32:48 —-A—- C:WINDOWSsystem32calc.exe
    2009-02-22 15:32:47 —-A—- C:WINDOWSsystem32winmine.exe
    2009-02-22 15:32:47 —-A—- C:WINDOWSsystem32sol.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32usrlogon.cmd
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32reset.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32mshearts.exe
    2009-02-22 15:32:46 —-A—- C:WINDOWSsystem32freecell.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tsshutdn.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tslabels.ini
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tskill.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tsdiscon.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32tscon.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32shadow.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32rwinsta.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32regini.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32rdpcfgex.dll
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32qwinsta.exe
    2009-02-22 15:32:45 —-A—- C:WINDOWSsystem32qappsrv.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32msg.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32logoff.exe
    2009-02-22 15:32:44 —-A—- C:WINDOWSsystem32cdmodem.dll
    2009-02-22 15:32:43 —-A—- C:WINDOWSsystem32msdtcprf.ini
    2009-02-22 15:32:34 —-A—- C:WINDOWSsystem32wmimgmt.msc
    2009-02-22 15:32:32 —-A—- C:WINDOWSsystem32sndrec32.exe
    2009-02-22 15:32:32 —-A—- C:WINDOWSsystem32accwiz.exe
    2009-02-22 15:32:31 —-A—- C:WINDOWSsystem32mplay32.exe
    2009-02-22 15:32:31 —-A—- C:WINDOWSsystem32hypertrm.dll
    2009-02-22 15:32:30 —-D—- C:Program FilesWindows NT
    2009-02-22 15:32:30 —-A—- C:WINDOWSsystem32mspaint.exe
    2009-02-22 15:32:29 —-A—- C:WINDOWSsystem32clipbrd.exe
    2009-02-22 15:32:28 —-A—- C:WINDOWSsystem32spider.exe
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32tsgqec.dll
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32tscfgwmi.dll
    2009-02-22 15:32:26 —-A—- C:WINDOWSsystem32rhttpaa.dll
    2009-02-22 15:32:25 —-A—- C:WINDOWSsystem32aaclient.dll
    2009-02-22 15:32:24 —-A—- C:WINDOWSsystem32mstscax.dll
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32sessmgr.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32remotepg.dll
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32rdshost.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32rdsaddin.exe
    2009-02-22 15:32:23 —-A—- C:WINDOWSsystem32mstsc.exe
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32termsrv.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpwsx.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpsnd.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdpclip.exe
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32rdchost.dll
    2009-02-22 15:32:22 —-A—- C:WINDOWSsystem32qprocess.exe
    2009-02-22 15:32:21 —-A—- C:WINDOWSsystem32icaapi.dll
    2009-02-22 15:32:21 —-A—- C:WINDOWSsystem32cfgbkend.dll
    2009-02-22 15:32:20 —-D—- C:WINDOWSsystem32MsDtc
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32mtxoci.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtcuiu.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtctm.dll
    2009-02-22 15:32:20 —-A—- C:WINDOWSsystem32msdtcprx.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32xolehlp.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32msdtclog.dll
    2009-02-22 15:32:19 —-A—- C:WINDOWSsystem32msdtc.exe
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxlegih.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxex.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32mtxdm.dll
    2009-02-22 15:32:17 —-A—- C:WINDOWSsystem32dcomcnfg.exe
    2009-02-22 15:32:16 —-D—- C:WINDOWSsystem32Com
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32comrepl.dll
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32comaddin.dll
    2009-02-22 15:32:16 —-A—- C:WINDOWSsystem32colbact.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32stclient.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32clbcatex.dll
    2009-02-22 15:32:15 —-A—- C:WINDOWSsystem32catsrvps.dll
    2009-02-22 15:32:14 —-A—- C:WINDOWSsystem32catsrvut.dll
    2009-02-22 15:32:14 —-A—- C:WINDOWSsystem32catsrv.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comuid.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comsvcs.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32comsnap.dll
    2009-02-22 15:32:13 —-A—- C:WINDOWSsystem32clbcatq.dll
    2009-02-22 15:32:04 —-A—- C:WINDOWSsystem32servdeps.dll
    2009-02-22 15:32:04 —-A—- C:WINDOWSsystem32mmfutil.dll
    2009-02-22 15:32:03 —-A—- C:WINDOWSsystem32licwmi.dll
    2009-02-22 15:32:03 —-A—- C:WINDOWSsystem32cmprops.dll

    ======List of files/folders modified in the last 1 months======

    2009-03-09 17:39:56 —-A—- C:WINDOWSwin.ini
    2009-02-22 18:26:20 —-A—- C:WINDOWSsystem.ini

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AFS2K;AFS2k; C:WINDOWSsystem32driversAFS2K.sys [2009-03-02 82380]
    R1 avgio;avgio; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgio.sys []
    R1 avipbb;avipbb; C:WINDOWSsystem32DRIVERSavipbb.sys [2008-10-30 75072]
    R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-15 40704]
    R1 ssmdrv;ssmdrv; C:WINDOWSsystem32DRIVERSssmdrv.sys [2007-03-01 28352]
    R2 DgiVecp;Team MFP Comm Driver; C:WINDOWSSystem32DriversDgiVecp.sys [2005-03-14 41984]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2008-01-25 4127488]
    R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2008-02-26 2863616]
    R3 avgntflt;avgntflt; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgntflt.sys []
    R3 msloop;Драйвер адаптера Microsoft замыкания на себя; C:WINDOWSsystem32DRIVERSloop.sys [2008-06-01 4992]
    R3 nvmpu401;Service for NVIDIA(R) nForce(TM) MIDI UART; C:WINDOWSsystem32driversnvmpu401.sys [2006-02-26 10240]
    R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet адаптер, драйвер для NT; C:WINDOWSsystem32DRIVERSRTL8139.SYS [2008-06-02 20992]
    R3 TTDVBLCD;TechnoTrend DVB PCI budget Driver; C:WINDOWSsystem32DRIVERSttdvblcd.sys [2006-02-03 66176]
    R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-06-01 30336]
    R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-06-02 59520]
    R3 usbsermpt;Motorola USB Modem Driver for MPT; C:WINDOWSsystem32DRIVERSusbsermpt.sys [2009-02-22 22768]
    R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-06-02 20608]
    S3 Ext2Fsd;Linux ext2 File system driver; C:WINDOWSsystem32driversExt2Fsd.sys [2008-01-27 644240]
    S3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-06-01 15104]
    S3 usbser;Motorola USB Modem Driver; C:WINDOWSsystem32DRIVERSusbser.sys [2008-06-01 26112]
    S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-06-01 26368]
    S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2007-06-18 77568]
    S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2007-06-18 82944]
    S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AntiVirScheduler;Avira AntiVir Personal — Free Antivirus Scheduler; C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe [2008-10-15 68865]
    R2 AntiVirService;Avira AntiVir Personal — Free Antivirus Guard; C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe [2008-10-15 151297]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:WINDOWSsystem32Ati2evxx.exe [2008-02-26 520192]
    R2 UPHClean;User Profile Hive Cleanup; C:WINDOWSsystem32uphclean.exe [2006-01-16 241725]
    S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv1.1.4322aspnet_state.exe [2004-07-15 32768]
    S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]


    EOF



    Спасибо уже лучше.

    14 марта, 2009 в 3:54 пп #22476
    Admin
    Keymaster
    • Темы:40
    • Сообщений:5676
    • ☆☆☆☆☆

    Лог выглядит нормально, есть ли проблемы с компьютером ?

  • Автор
    Сообщения
Просмотр 6 сообщений - с 1 по 6 (из 6 всего)
  • Для ответа в этой теме необходимо авторизоваться.
Войти

Добро пожаловать

На нашем сайте размещены инструкции и программы, которые помогут вам абсолютно бесплатно и самостоятельно удалить навязчивую рекламу, вирусы и трояны.

Поиск

Последние темы

  • Странность в Malwebytes опубликовано Artem225
    5 years, 6 months назад
  • SUSPICIOUS.FakedMBR.1 что делать, помогите!!! опубликовано White
    5 years, 7 months назад
  • Помогите пожалуйста вирус замучил. опубликовано dimazons1233211
    5 years, 9 months назад
  • Замучила реклама опубликовано Данила Беспятов
    5 years, 10 months назад
  • Замучила реклама опубликовано Марк
    5 years, 7 months назад
  • Вирус S1.video.ru.net опубликовано ludovik
    6 years назад
  • Чертов Safe Finder!!!! опубликовано kosta savo
    5 years, 9 months назад
  • ESET блокирует неизвестный сайт , вход на который не осуществлялся. опубликовано trollhamaren
    6 years, 1 month назад

СПАЙВАРЕ РУ

  • О Спайваре Ру
  • Контакты
  • Реклама на сайте
  • Политика конфиденциальности
  • Правила использования

Нужна помощь?

Задайте свой вопрос прямо сейчас кликнув по следующей ссылке Задать вопрос.

Или обратитесь на наш форум, где команда Spyware-ru поможет вам. Узнайте, как попросить о помощи здесь.

Ссылки

  • Инструкции
  • Скачать программы
  • Помощь в удалении вирусов
  • Как вылечить компьютер
Copyright © 2008 - 2024 Spyware-RU.com (en)