• Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы

SPYWARE-RU.COM

Меню
  • Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы
В начало › Помогите удалить вирус
Adguard
 

Помогите удалить вирус

Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Помогите удалить вирус

  • This topic has 2 ответа, 2 участника, and was last updated 16 years, 2 months назад by Admin.
Просмотр 3 сообщений - с 1 по 3 (из 3 всего)
  • Автор
    Сообщения
  • 21 февраля, 2009 в 5:16 пп #16295
    Kathrine
    Participant
    • Темы:1
    • Сообщений:2
    • ☆

    Здрасьте.

    Я не знаю что это за вирус.. Я не знаю по какому принципу он действует. Но могу описать что у меня случилось.
    На компе не стоял никакой антивирус. Попал вирус, после которого экзешные файлы перестали работать. Не запускаются программы именно те, которые установлены после того, как попал этот вирус. Пыталась установить Касперского, ничего не вышло, программа не запускается.
    И диспетчер заач не работает, говорит, что отключен, хотя ничего не отключали. Помогите… Воспользовалась Вашей инструкцией. Вот результат сканирования RSIT:

    log:
    Logfile of random’s system information tool 1.05 (written by random/random)
    Run by Admin at 2009-02-21 20:06:17
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 348 GB (73%) free of 477 GB
    Total RAM: 3582 MB (87% free)

    HijackThis download failed

    ======Registry dump======

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll [2006-10-23 62080]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
    IEVkbdBHO Class — C:Program FilesKaspersky LabKaspersky Anti-Virus 2009ievkbd.dll [2008-11-11 62728]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper — C:Program FilesJavajre6binssv.dll [2009-01-27 320920]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2009-01-27 34816]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2009-01-27 73728]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
    «RTHDCPL»=C:WINDOWSRTHDCPL.EXE [2008-04-10 16861184]
    «Alcmtr»=C:WINDOWSALCMTR.EXE [2005-05-03 147456]
    «NeroFilterCheck»=C:WINDOWSsystem32NeroCheck.exe [2006-01-12 229376]
    «GEST»=C:Program FilesGIGABYTEGESTRUN.e_e []
    «DriverCD»=D:Run.exe []
    «WinampAgent»=C:Program FilesWinampwinampa.exe [2008-08-04 36352]
    «StarBoardCtrlBox»=C:Program FilesHitachi Software EngineeringStarBoard SoftwareStarBoardControlBox.exe [2007-10-19 131072]
    «StarBoardPrintListener»=C:Program FilesHitachi Software EngineeringStarBoard SoftwareStarBoardPrintListener.exe [2007-10-25 135168]
    «StarBoardDriver»=C:Program FilesHitachi Software EngineeringStarBoard DriverDGBoard.exe [2007-08-29 736456]
    «SYS1″=C:WINDOWSsystem32system.exe []
    «SYS2″=C:WINDOWSsystem32bad1.exe [2009-02-19 102400]
    «SYS3″=C:WINDOWSsystem32bad2.exe [2009-02-19 102400]
    «SYS4″=C:WINDOWSsystem32bad3.exe [2009-02-19 102400]
    «Msmsgs»=C:WINDOWSsystem32Msmsgs.exe [2007-07-18 293280]
    «AVP»=C:Program FilesKaspersky LabKaspersky Anti-Virus 2009avp.exe [2008-11-11 206088]

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
    «VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2008-01-02 132096]
    «Punto Switcher»=C:Program FilesPunto Switcherpunto.exe [2008-10-30 734504]
    «Skype»=C:Program FilesSkypePhoneSkype.exe [2009-01-29 23975720]

    C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
    Adobe Reader Speed Launch.lnk — C:Program FilesAdobeReader 8.0Readerreader_sl.exe
    Adobe Reader Synchronizer.lnk — C:Program FilesAdobeReader 8.0ReaderAdobeCollabSync.exe

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows]
    «AppInit_DLLS»=»C:PROGRA~1KASPER~1KASPER~1mzvkbd.dll,C:PROGRA~1KASPER~1KASPER~1mzvkbd3.dll»

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAtiExtEvent]
    C:WINDOWSsystem32Ati2evxx.dll [2008-12-01 143360]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyklogon]
    C:WINDOWSsystem32klogon.dll [2008-11-11 218376]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
    WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2008-03-02 133632]

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    «DisableTaskMgr»=1
    «DisableRegistryTools»=1

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    «dontdisplaylastusername»=0
    «legalnoticecaption»=
    «legalnoticetext»=
    «shutdownwithoutlogon»=1
    «undockwithoutlogon»=1
    «EnableLUA»=0

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=91
    «NoSharedDocuments»=1
    «NoSMConfigurePrograms»=1
    «NoFind»=1
    «NoFolderOptions»=1

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
    «C:Program FilesuTorrentuTorrent.exe»=»C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent»
    «C:Program FilesHitachi Software EngineeringStarBoard SoftwareTRex.exe»=»C:Program FilesHitachi Software EngineeringStarBoard SoftwareTRex.exe:*:Enabled:StarBoard Software»
    «C:Program FilesHitachi Software EngineeringStarBoard SoftwareZuttoMatte.exe»=»C:Program FilesHitachi Software EngineeringStarBoard SoftwareZuttoMatte.exe:*:Enabled:StarBoard Software DDC service»
    «F:StarBoard 08.exe»=»F:StarBoard 08.exe:*:Enabled:ipsec»
    «C:WINDOWSALCMTR.EXE»=»C:WINDOWSALCMTR.EXE:*:Enabled:ipsec»
    «C:WINDOWSRTHDCPL.EXE»=»C:WINDOWSRTHDCPL.EXE:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinlbfvj.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinlbfvj.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempyourmt.exe»=»C:DOCUME~1AdminLOCALS~1Tempyourmt.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempjiga.exe»=»C:DOCUME~1AdminLOCALS~1Tempjiga.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinvdekh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinvdekh.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempkeqh.exe»=»C:DOCUME~1AdminLOCALS~1Tempkeqh.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinwxlx.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinwxlx.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinckqwaq.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinckqwaq.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Temptemprc.exe»=»C:DOCUME~1AdminLOCALS~1Temptemprc.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempclkuu.exe»=»C:DOCUME~1AdminLOCALS~1Tempclkuu.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinewrvp.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinewrvp.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Temptyxbio.exe»=»C:DOCUME~1AdminLOCALS~1Temptyxbio.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinbbaeug.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinbbaeug.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempcuil.exe»=»C:DOCUME~1AdminLOCALS~1Tempcuil.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempjqrnro.exe»=»C:DOCUME~1AdminLOCALS~1Tempjqrnro.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempxykm.exe»=»C:DOCUME~1AdminLOCALS~1Tempxykm.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempallm.exe»=»C:DOCUME~1AdminLOCALS~1Tempallm.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinebxdi.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinebxdi.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Temphwwfe.exe»=»C:DOCUME~1AdminLOCALS~1Temphwwfe.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinirtn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinirtn.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinlrhnxc.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinlrhnxc.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Temptodvxc.exe»=»C:DOCUME~1AdminLOCALS~1Temptodvxc.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinljqhv.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinljqhv.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwiniadtof.exe»=»C:DOCUME~1AdminLOCALS~1Tempwiniadtof.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwineyyego.exe»=»C:DOCUME~1AdminLOCALS~1Tempwineyyego.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinmnnmws.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinmnnmws.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinxgrnvb.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinxgrnvb.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinwupv.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinwupv.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwiniiubrw.exe»=»C:DOCUME~1AdminLOCALS~1Tempwiniiubrw.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinsqnd.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinsqnd.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwindfby.exe»=»C:DOCUME~1AdminLOCALS~1Tempwindfby.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwintbpfgy.exe»=»C:DOCUME~1AdminLOCALS~1Tempwintbpfgy.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempvnoka.exe»=»C:DOCUME~1AdminLOCALS~1Tempvnoka.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinnnqb.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinnnqb.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinqeqib.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinqeqib.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinqluadr.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinqluadr.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinttmvp.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinttmvp.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinbklxxo.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinbklxxo.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinrwxd.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinrwxd.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempxmqm.exe»=»C:DOCUME~1AdminLOCALS~1Tempxmqm.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempfqca.exe»=»C:DOCUME~1AdminLOCALS~1Tempfqca.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwintvwp.exe»=»C:DOCUME~1AdminLOCALS~1Tempwintvwp.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinbmtlq.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinbmtlq.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinapxkb.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinapxkb.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinppqjin.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinppqjin.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Templybt.exe»=»C:DOCUME~1AdminLOCALS~1Templybt.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempoajiun.exe»=»C:DOCUME~1AdminLOCALS~1Tempoajiun.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinushprh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinushprh.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwela.exe»=»C:DOCUME~1AdminLOCALS~1Tempwela.exe:*:Enabled:ipsec»
    «C:Program FilesMozilla Firefoxfirefox.exe»=»C:Program FilesMozilla Firefoxfirefox.exe:*:Enabled:ipsec»
    «C:WINDOWSsystem32NeroCheck.exe»=»C:WINDOWSsystem32NeroCheck.exe:*:Enabled:ipsec»
    «C:WINDOWSsystem32Msmsgs.exe»=»C:WINDOWSsystem32Msmsgs.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinpiqk.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinpiqk.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwindssj.exe»=»C:DOCUME~1AdminLOCALS~1Tempwindssj.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempnnuo.exe»=»C:DOCUME~1AdminLOCALS~1Tempnnuo.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinngksa.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinngksa.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwintqtokh.exe»=»C:DOCUME~1AdminLOCALS~1Tempwintqtokh.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinkyftm.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinkyftm.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinnhttnn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinnhttnn.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinvsendq.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinvsendq.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempirgimp.exe»=»C:DOCUME~1AdminLOCALS~1Tempirgimp.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinlpalk.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinlpalk.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinfrmd.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinfrmd.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinalyitd.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinalyitd.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempbtidm.exe»=»C:DOCUME~1AdminLOCALS~1Tempbtidm.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinxvfn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinxvfn.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinmwpn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinmwpn.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinhvsf.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinhvsf.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempvjkpw.exe»=»C:DOCUME~1AdminLOCALS~1Tempvjkpw.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinftoonu.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinftoonu.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinhjyew.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinhjyew.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempgiven.exe»=»C:DOCUME~1AdminLOCALS~1Tempgiven.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwincxbxu.exe»=»C:DOCUME~1AdminLOCALS~1Tempwincxbxu.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwiniyyt.exe»=»C:DOCUME~1AdminLOCALS~1Tempwiniyyt.exe:*:Enabled:ipsec»
    «C:Program FilesSims 2 Teen Style Stuffsims2_teenTSBinSims2SP6.exe»=»C:Program FilesSims 2 Teen Style Stuffsims2_teenTSBinSims2SP6.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinvvkuhg.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinvvkuhg.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempqcxie.exe»=»C:DOCUME~1AdminLOCALS~1Tempqcxie.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinlydhi.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinlydhi.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinhsxfvb.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinhsxfvb.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinythlo.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinythlo.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinuiji.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinuiji.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinmxhqaf.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinmxhqaf.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinaltip.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinaltip.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinigxo.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinigxo.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinvfjnp.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinvfjnp.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinynaa.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinynaa.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinrkdn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinrkdn.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempenvfb.exe»=»C:DOCUME~1AdminLOCALS~1Tempenvfb.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinnhux.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinnhux.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinjbhiv.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinjbhiv.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempbfsfhr.exe»=»C:DOCUME~1AdminLOCALS~1Tempbfsfhr.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinnoqji.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinnoqji.exe:*:Enabled:ipsec»
    «C:DOCUME~1AdminLOCALS~1Tempwinmisbn.exe»=»C:DOCUME~1AdminLOCALS~1Tempwinmisbn.exe:*:Enabled:ipsec»

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    [HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{972c569a-f21f-11dd-807c-001d7dd6cf96}]
    shellAutoRuncommand — C:WINDOWSsystem32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system.exe
    shellExplorecommand — F:system.exe
    shellOpencommand — F:system.exe

    ======File associations======

    .js — edit — «C:Program FilesMacromediaDreamweaver 8dreamweaver.exe» «%1»

    ======List of files/folders created in the last 1 months======

    2009-02-21 20:06:17 —-D—- C:rsit
    2009-02-21 20:06:17 —-D—- C:Program Filestrend micro
    2009-02-21 17:00:08 —-D—- C:Program FilesКаспер
    2009-02-21 15:37:12 —-D—- C:Program FilesKaspersky Lab
    2009-02-21 15:37:12 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab
    2009-02-21 15:31:33 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab Setup Files
    2009-02-21 15:25:28 —-A—- C:Program FilesSkypeSetup.exe
    2009-02-21 14:50:25 —-D—- C:Program FilesKAV 2009 (8.0.0.506)
    2009-02-19 06:41:45 —-A—- C:WINDOWSsystem32bad1.exe
    2009-02-19 06:41:37 —-A—- C:WINDOWSsystem32bad3.exe
    2009-02-19 06:41:33 —-A—- C:WINDOWSsystem32bad2.exe
    2009-02-19 06:35:01 —-RASH—- C:WINDOWSsystem32msmsgs.exe
    2009-02-18 17:33:43 —-D—- C:Documents and SettingsAdminApplication DataskypePM
    2009-02-18 17:31:04 —-D—- C:Documents and SettingsAdminApplication DataSkype
    2009-02-18 17:30:30 —-D—- C:Program FilesCommon FilesSkype
    2009-02-18 17:30:29 —-RD—- C:Program FilesSkype
    2009-02-18 17:30:26 —-D—- C:Documents and SettingsAll UsersApplication DataSkype
    2009-02-12 07:54:28 —-D—- C:Documents and SettingsAdminApplication DataHSW_Driver
    2009-02-12 07:53:40 —-D—- C:Program FilesEverNote
    2009-02-12 07:52:25 —-D—- C:WINDOWSsystem32windows media
    2009-02-12 07:52:23 —-D—- C:WINDOWSRegisteredPackages
    2009-02-12 07:52:22 —-HD—- C:WINDOWSmsdownld.tmp
    2009-02-12 07:52:22 —-D—- C:Program FilesWindows Media Components
    2009-02-12 07:47:44 —-D—- C:Program FilesHitachi Software Engineering
    2009-02-12 07:47:44 —-D—- C:Documents and SettingsAll UsersApplication DataHitachi Software Engineering
    2009-02-10 15:01:44 —-D—- C:Program FilesGothic 3
    2009-02-10 05:51:10 —-A—- C:WINDOWSsystem32appdrvrem01.exe
    2009-02-10 02:33:45 —-D—- C:Program FilesGFI
    2009-02-09 21:13:41 —-D—- C:Documents and SettingsAdminApplication DataOpera
    2009-02-05 01:59:14 —-D—- C:Documents and SettingsAdminApplication Datadvdcss
    2009-02-04 17:17:38 —-D—- C:Documents and SettingsAll UsersApplication DataSimCity Societies
    2009-02-04 16:53:14 —-D—- C:WINDOWSsystem32appmgmt
    2009-02-04 12:50:45 —-D—- C:Documents and SettingsAdminApplication DataSPORE Creature Creator
    2009-02-04 12:50:42 —-A—- C:WINDOWSsystem32CmdLineExt.dll
    2009-02-04 12:41:39 —-D—- C:Program FilesElectronic Arts
    2009-02-04 12:25:07 —-D—- C:simcity
    2009-02-04 04:28:01 —-D—- C:Program FilesReplay Converter 3
    2009-02-04 04:27:58 —-D—- C:Program FilesOpera
    2009-02-04 04:27:44 —-D—- C:Program FilesNero
    2009-02-04 04:22:39 —-D—- C:Program FilesCyberLink
    2009-02-04 04:22:39 —-D—- C:Program FilesCheMaxRus
    2009-02-04 04:22:32 —-D—- C:Program FilesBitComet
    2009-02-04 03:47:18 —-D—- C:Physicon
    2009-02-04 03:47:17 —-D—- C:Photo Frames PRO 2.91
    2009-02-04 03:19:30 —-RD—- C:Мои документы
    2009-02-04 02:22:39 —-D—- C:Мамина флеха
    2009-02-04 02:11:07 —-D—- C:музычка
    2009-02-04 02:09:15 —-D—- C:Димарик
    2009-02-04 00:04:08 —-D—- C:Documents and SettingsAdminApplication DataQIP
    2009-02-04 00:01:08 —-D—- C:Program FilesЛунтик. Математика
    2009-02-03 23:46:22 —-D—- C:Documents and SettingsAdminApplication DataMacromedia
    2009-02-03 23:43:20 —-A—- C:WINDOWSNeroDigital.ini
    2009-02-03 23:43:18 —-D—- C:Documents and SettingsAdminApplication DataMedia Player Classic
    2009-02-03 01:40:14 —-D—- C:Program FilesРуссобит-М
    2009-02-03 01:38:55 —-D—- C:Patches
    2009-02-03 01:37:31 —-A—- C:setup.exe
    2009-02-03 01:37:30 —-A—- C:Autorun.exe
    2009-02-02 19:45:13 —-D—- C:Program FilesПодарочек
    2009-02-02 19:45:07 —-A—- C:WINDOWSIsUn0419.exe
    2009-02-02 18:32:02 —-D—- C:Program FilesSchool Tycoon
    2009-02-02 18:22:35 —-D—- C:Program FilesGSC Game World
    2009-02-01 18:18:27 —-D—- C:Documents and SettingsAdminApplication DataHelp
    2009-01-30 01:16:31 —-A—- C:Program FilesSims2Pack Clean Installer.ini
    2009-01-30 01:08:02 —-D—- C:Program FilesSims2Pack Clean Installer
    2009-01-30 01:05:17 —-D—- C:Documents and SettingsAll UsersApplication DataFLEXnet
    2009-01-30 00:48:47 —-D—- C:Documents and SettingsAdminApplication DataWinRAR
    2009-01-30 00:24:03 —-D—- C:Колюня
    2009-01-30 00:23:51 —-D—- C:Катюфан!
    2009-01-28 03:09:28 —-D—- C:Program FilesSims 2 Teen Style Stuff
    2009-01-27 23:55:38 —-D—- C:Program Filesdirectx
    2009-01-27 23:55:28 —-D—- C:URL
    2009-01-27 23:55:26 —-D—- C:Manual
    2009-01-27 23:53:13 —-D—- C:Data
    2009-01-27 23:53:13 —-A—- C:win95.txt
    2009-01-27 23:53:13 —-A—- C:wigHelper.exe
    2009-01-27 23:53:12 —-A—- C:Wiggles.exe
    2009-01-27 23:53:12 —-A—- C:wig_launcher.exe
    2009-01-27 23:53:12 —-A—- C:setmode.exe
    2009-01-27 23:53:12 —-A—- C:player_poll.exe
    2009-01-27 23:51:23 —-A—- C:WINDOWSIsUninst.exe
    2009-01-27 15:18:36 —-D—- C:Program FilesGothic 2 GOLD
    2009-01-27 15:02:53 —-D—- C:Documents and SettingsAdminApplication DataDAEMON Tools
    2009-01-27 06:48:22 —-N—- C:WINDOWSsystem32ati2sgag.exe
    2009-01-27 06:48:18 —-D—- C:WINDOWSsystem32ReinstallBackups
    2009-01-27 06:47:50 —-D—- C:ATI
    2009-01-27 06:33:38 —-A—- C:WINDOWSsystem32H@tKeysH@@k.DLL
    2009-01-27 06:06:17 —-D—- C:WINDOWSsystem32DirectX
    2009-01-27 05:59:29 —-A—- C:WINDOWSsystem32msdia80.dll
    2009-01-27 05:59:04 —-D—- C:Documents and SettingsAdminApplication DataDAEMON Tools Pro
    2009-01-27 05:57:36 —-D—- C:gothic
    2009-01-27 03:10:14 —-A—- C:WINDOWSsystem32h323log.txt
    2009-01-27 03:09:40 —-A—- C:WINDOWSsystem32hidserv.dll
    2009-01-27 03:09:15 —-D—- C:WINDOWSsystem32RTCOM
    2009-01-27 03:09:14 —-A—- C:WINDOWSsystem32ksuser.dll
    2009-01-27 03:07:48 —-A—- C:WINDOWSsystem32usbui.dll
    2009-01-27 03:06:11 —-SHD—- C:WINDOWSInstaller
    2009-01-27 03:06:11 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
    2009-01-27 03:06:10 —-D—- C:Program FilesCommon FilesODBC
    2009-01-27 03:06:10 —-A—- C:WINDOWSODBCINST.INI
    2009-01-27 03:06:07 —-D—- C:Program FilesCommon FilesSpeechEngines
    2009-01-27 03:06:07 —-AD—- C:Program FilesCommon FilesMicrosoft Shared
    2009-01-27 03:06:07 —-AD—- C:Program FilesCommon Files
    2009-01-27 03:06:07 —-AD—- C:Program Files
    2009-01-27 03:06:03 —-RA—- C:WINDOWSsystem32kbdtuq.dll
    2009-01-27 03:06:03 —-RA—- C:WINDOWSsystem32kbdtuf.dll
    2009-01-27 03:06:03 —-RA—- C:WINDOWSsystem32kbdazel.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdhept.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdhela3.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdhela2.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdhe319.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdhe220.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdhe.dll
    2009-01-27 03:06:01 —-RA—- C:WINDOWSsystem32kbdgkl.dll
    2009-01-27 03:05:59 —-RA—- C:WINDOWSsystem32kbdlv1.dll
    2009-01-27 03:05:59 —-RA—- C:WINDOWSsystem32kbdlv.dll
    2009-01-27 03:05:59 —-RA—- C:WINDOWSsystem32kbdlt1.dll
    2009-01-27 03:05:59 —-RA—- C:WINDOWSsystem32kbdlt.dll
    2009-01-27 03:05:59 —-RA—- C:WINDOWSsystem32kbdest.dll
    2009-01-27 03:05:57 —-RA—- C:WINDOWSsystem32kbdsl1.dll
    2009-01-27 03:05:57 —-RA—- C:WINDOWSsystem32kbdsl.dll
    2009-01-27 03:05:57 —-RA—- C:WINDOWSsystem32kbdro.dll
    2009-01-27 03:05:57 —-RA—- C:WINDOWSsystem32kbdpl1.dll
    2009-01-27 03:05:57 —-RA—- C:WINDOWSsystem32kbdpl.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdycl.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdhu1.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdhu.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdcz2.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdcz1.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdcz.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32kbdcr.dll
    2009-01-27 03:05:56 —-RA—- C:WINDOWSsystem32KBDAL.DLL
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdycc.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbduzb.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdur.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdtat.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdmon.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdkyr.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdkaz.dll
    2009-01-27 03:05:53 —-A—- C:WINDOWSsystem32kbdaze.dll
    2009-01-27 03:05:52 —-A—- C:WINDOWSsystem32kbdbu.dll
    2009-01-27 03:05:52 —-A—- C:WINDOWSsystem32kbdblr.dll
    2009-01-27 03:05:51 —-A—- C:WINDOWSsystem32spxcoins.dll
    2009-01-27 03:05:51 —-A—- C:WINDOWSsystem32irclass.dll
    2009-01-27 03:05:51 —-A—- C:WINDOWSsystem32EqnClass.Dll
    2009-01-27 03:05:51 —-A—- C:WINDOWSsystem32dgsetup.dll
    2009-01-27 03:05:51 —-A—- C:WINDOWSsystem32dgrpsetu.dll
    2009-01-27 03:05:48 —-N—- C:WINDOWSsystem32CONFIG.TMP
    2009-01-27 03:05:48 —-A—- C:WINDOWSTASKMAN.EXE
    2009-01-27 03:05:47 —-A—- C:WINDOWSsystem32batt.dll
    2009-01-27 03:05:47 —-A—- C:WINDOWSNOTEPAD.EXE
    2009-01-27 03:05:45 —-A—- C:WINDOWSsystem32storprop.dll
    2009-01-27 03:05:38 —-ASH—- C:Documents and SettingsAll UsersApplication Datadesktop.ini
    2009-01-27 03:04:19 —-RA—- C:WINDOWSSET8.tmp
    2009-01-27 03:04:17 —-RA—- C:WINDOWSSET4.tmp
    2009-01-27 03:04:15 —-RA—- C:WINDOWSSET3.tmp
    2009-01-27 03:04:11 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
    2009-01-27 03:03:20 —-A—- C:WINDOWSsetuplog.txt
    2009-01-27 03:02:13 —-A—- C:WINDOWSSOUNDMAN.EXE
    2009-01-27 03:02:13 —-A—- C:WINDOWSSkyTel.exe
    2009-01-27 03:02:13 —-A—- C:WINDOWSRtlUpd.exe
    2009-01-27 03:02:13 —-A—- C:WINDOWSRTLCPL.EXE
    2009-01-27 03:02:12 —-A—- C:WINDOWSRTHDCPL.EXE
    2009-01-27 03:02:12 —-A—- C:WINDOWSMicCal.exe
    2009-01-27 03:02:12 —-A—- C:WINDOWSALCWZRD.EXE
    2009-01-27 03:02:12 —-A—- C:WINDOWSALCMTR.EXE
    2009-01-27 03:01:12 —-A—- C:WINDOWSsystem32RtNicProp32.dll
    2009-01-27 03:01:06 —-A—- C:WINDOWSsystem32Oemdspif.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ativvaxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ativcoxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atitvo32.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atipdlxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atiok3x2.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atioglxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atikvmag.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atiiiexx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ATIDEMGX.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ATIDDC.DLL
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32atiadlxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ati3duag.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ati2evxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ati2edxx.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ati2dvag.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32ati2cqag.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32amdpcom32.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32amdcalrt.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32Amdcaldd.dll
    2009-01-27 03:01:02 —-A—- C:WINDOWSsystem32amdcalcl.dll
    2009-01-27 03:01:01 —-A—- C:WINDOWSsystem32atibrtmon.exe
    2009-01-27 03:01:01 —-A—- C:WINDOWSsystem32Ati2mdxx.exe
    2009-01-27 03:01:01 —-A—- C:WINDOWSsystem32ati2evxx.exe
    2009-01-27 02:59:43 —-D—- C:WINDOWSsystem32CatRoot2
    2009-01-27 02:59:43 —-D—- C:WINDOWSsystem32CatRoot
    2009-01-27 02:58:16 —-SHD—- C:System Volume Information
    2009-01-27 02:58:16 —-D—- C:Documents and Settings
    2009-01-27 02:57:34 —-SH—- C:boot.ini
    2009-01-27 02:53:01 —-RSHDC—- C:WINDOWSsystem32dllcache
    2009-01-27 02:53:01 —-RSD—- C:WINDOWSFonts
    2009-01-27 02:53:01 —-RD—- C:WINDOWSWeb
    2009-01-27 02:53:01 —-HD—- C:WINDOWSinf
    2009-01-27 02:53:01 —-D—- C:WINDOWSWinSxS
    2009-01-27 02:53:01 —-D—- C:WINDOWStwain_32
    2009-01-27 02:53:01 —-D—- C:WINDOWSTemp
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32wins
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32wbem
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32usmt
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32spool
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32ShellExt
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32Setup
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32ru-ru
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32ru
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32ras
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32oobe
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32npp
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32mui
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32inetsrv
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32IME
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32icsxml
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32ias
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32export
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem32dhcp
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem323com_dmi
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem323076
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem322052
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321054
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321049
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321042
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321041
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321037
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321033
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321031
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321028
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem321025
    2009-01-27 02:53:01 —-D—- C:WINDOWSsystem
    2009-01-27 02:53:01 —-D—- C:WINDOWSsecurity
    2009-01-27 02:53:01 —-D—- C:WINDOWSResources
    2009-01-27 02:53:01 —-D—- C:WINDOWSrepair
    2009-01-27 02:53:01 —-D—- C:WINDOWSProvisioning
    2009-01-27 02:53:01 —-D—- C:WINDOWSPeerNet
    2009-01-27 02:53:01 —-D—- C:WINDOWSpchealth
    2009-01-27 02:53:01 —-D—- C:WINDOWSNetwork Diagnostic
    2009-01-27 02:53:01 —-D—- C:WINDOWSmui
    2009-01-27 02:53:01 —-D—- C:WINDOWSmsapps
    2009-01-27 02:53:01 —-D—- C:WINDOWSmsagent
    2009-01-27 02:53:01 —-D—- C:WINDOWSMedia
    2009-01-27 02:53:01 —-D—- C:WINDOWSL2Schemas
    2009-01-27 02:53:01 —-D—- C:WINDOWSjava
    2009-01-27 02:53:01 —-D—- C:WINDOWSime
    2009-01-27 02:53:01 —-D—- C:WINDOWSHelp
    2009-01-27 02:53:01 —-D—- C:WINDOWSehome
    2009-01-27 02:53:01 —-D—- C:WINDOWSDriver Cache
    2009-01-27 02:53:01 —-D—- C:WINDOWSDebug
    2009-01-27 02:53:01 —-D—- C:WINDOWSCursors
    2009-01-27 02:53:01 —-D—- C:WINDOWSConnection Wizard
    2009-01-27 02:53:01 —-D—- C:WINDOWSConfig
    2009-01-27 02:53:01 —-D—- C:WINDOWSAppPatch
    2009-01-27 02:53:01 —-D—- C:WINDOWSaddins
    2009-01-27 02:53:00 —-D—- C:WINDOWSsystem32drivers
    2009-01-27 02:53:00 —-D—- C:WINDOWSsystem32config
    2009-01-27 02:53:00 —-D—- C:WINDOWS
    2009-01-27 02:53:00 —-AD—- C:WINDOWSsystem32
    2009-01-27 00:57:14 —-SHD—- C:RECYCLER
    2009-01-27 00:53:10 —-D—- C:Documents and SettingsAdminApplication Datavlc
    2009-01-27 00:48:16 —-RA—- C:WINDOWSsystem32CSVer.dll
    2009-01-27 00:48:16 —-D—- C:Program FilesIntel
    2009-01-27 00:48:11 —-D—- C:Intel
    2009-01-27 00:47:58 —-HD—- C:Program FilesInstallShield Installation Information
    2009-01-27 00:47:58 —-D—- C:Program FilesGIGABYTE
    2009-01-27 00:41:39 —-D—- C:WINDOWSsystem32Lang
    2009-01-27 00:41:37 —-A—- C:WINDOWSsystem32oeminfo.ini
    2009-01-27 00:41:36 —-A—- C:WINDOWSsystem32Reg2Inf.exe
    2009-01-27 00:41:32 —-RA—- C:WINDOWSsystem32OEMINFO.CMD
    2009-01-27 00:41:32 —-A—- C:WINDOWSsystem32hidcon.exe
    2009-01-27 00:41:25 —-D—- C:Documents and SettingsAdminApplication DataIdentities
    2009-01-27 00:41:25 —-A—- C:WINDOWSsystem32wmpns.dll
    2009-01-27 00:41:23 —-HD—- C:Program FilesUninstall Information
    2009-01-27 00:40:46 —-RD—- C:WINDOWSOemDrv
    2009-01-27 00:40:39 —-D—- C:Documents and SettingsAll UsersApplication DataDAEMON Tools Lite
    2009-01-27 00:40:38 —-D—- C:Documents and SettingsAdminApplication DataDAEMON Tools Lite
    2009-01-27 00:40:29 —-D—- C:Program FilesDaemon Tools Lite
    2009-01-27 00:40:27 —-D—- C:Program FilesUltraISO
    2009-01-27 00:40:27 —-D—- C:Program FilesCommon FilesEZB Systems
    2009-01-27 00:40:09 —-N—- C:WINDOWSsystem32TwnLib4.dll
    2009-01-27 00:40:09 —-N—- C:WINDOWSsystem32ImagXRA7.dll
    2009-01-27 00:40:09 —-N—- C:WINDOWSsystem32ImagXR7.dll
    2009-01-27 00:40:09 —-N—- C:WINDOWSsystem32ImagXpr7.dll
    2009-01-27 00:40:09 —-N—- C:WINDOWSsystem32ImagX7.dll
    2009-01-27 00:40:09 —-D—- C:Program FilesCommon FilesAhead
    2009-01-27 00:40:09 —-D—- C:Program FilesAhead
    2009-01-27 00:40:09 —-A—- C:WINDOWSsystem32TwnLib20.dll
    2009-01-27 00:40:09 —-A—- C:WINDOWSsystem32NeroCheck.exe
    2009-01-27 00:39:53 —-D—- C:Program FilesTeamViewer 4
    2009-01-27 00:39:48 —-A—- C:WINDOWSsystem32VBoxNetFltNotify.dll
    2009-01-27 00:39:44 —-DC—- C:WINDOWSsystem32DRVSTORE
    2009-01-27 00:39:43 —-D—- C:Program FilesSun xVM VirtualBox
    2009-01-27 00:39:35 —-D—- C:Program FilesuTorrent
    2009-01-27 00:39:35 —-D—- C:Documents and SettingsAdminApplication DatauTorrent
    2009-01-27 00:39:33 —-D—- C:Program FilesUnlocker
    2009-01-27 00:39:33 —-D—- C:Program FilesTotal Commander
    2009-01-27 00:39:28 —-D—- C:Program Files7-Zip
    2009-01-27 00:39:26 —-D—- C:Program FilesWinRAR
    2009-01-27 00:39:23 —-D—- C:Program FilesEverest
    2009-01-27 00:39:16 —-D—- C:Program FilesMozilla Firefox
    2009-01-27 00:39:15 —-D—- C:Documents and SettingsAdminApplication DataMozilla
    2009-01-27 00:39:09 —-D—- C:Program FilesOperaAC
    2009-01-27 00:39:05 —-D—- C:Documents and SettingsAdminApplication DataWinamp
    2009-01-27 00:39:03 —-D—- C:Program FilesWinamp
    2009-01-27 00:38:58 —-D—- C:Program FilesFlash Player Pro
    2009-01-27 00:38:56 —-D—- C:Documents and SettingsAll UsersApplication DataApple Computer
    2009-01-27 00:38:54 —-D—- C:Program FilesQuickTime Alternative
    2009-01-27 00:38:51 —-D—- C:Program FilesReal Alternative
    2009-01-27 00:38:47 —-A—- C:WINDOWSsystem32unrar.dll
    2009-01-27 00:38:47 —-A—- C:WINDOWSsystem32rmoc3260.dll
    2009-01-27 00:38:47 —-A—- C:WINDOWSsystem32pndx5032.dll
    2009-01-27 00:38:47 —-A—- C:WINDOWSsystem32pndx5016.dll
    2009-01-27 00:38:47 —-A—- C:WINDOWSsystem32pncrt.dll
    2009-01-27 00:38:47 —-A—- C:WINDOWSavisplitter.ini
    2009-01-27 00:38:46 —-A—- C:WINDOWSsystem32yv12vfw.dll
    2009-01-27 00:38:46 —-A—- C:WINDOWSsystem32xvidvfw.dll
    2009-01-27 00:38:46 —-A—- C:WINDOWSsystem32xvidcore.dll
    2009-01-27 00:38:46 —-A—- C:WINDOWSsystem32qt-dx331.dll
    2009-01-27 00:38:46 —-A—- C:WINDOWSsystem32dpl100.dll
    2009-01-27 00:38:46 —-A—- C:WINDOWSsystem32divx.dll
    2009-01-27 00:38:45 —-A—- C:WINDOWSsystem32ff_vfw.dll.manifest
    2009-01-27 00:38:45 —-A—- C:WINDOWSsystem32ff_vfw.dll
    2009-01-27 00:38:44 —-D—- C:Program FilesK-Lite Codec Pack
    2009-01-27 00:38:44 —-D—- C:Documents and SettingsAll UsersApplication DataReal
    2009-01-27 00:38:44 —-D—- C:Documents and SettingsAdminApplication DataReal
    2009-01-27 00:38:42 —-D—- C:Program FilesPocketDivXEncoder
    2009-01-27 00:38:35 —-D—- C:Program FilesVLC
    2009-01-27 00:38:29 —-D—- C:Program FilesThe KMPlayer
    2009-01-27 00:38:25 —-D—- C:Program FilesQIP Infium
    2009-01-27 00:38:22 —-D—- C:Program FilesRegshot
    2009-01-27 00:38:21 —-D—- C:Program FilesVDSoft
    2009-01-27 00:38:20 —-D—- C:Program FilesCCleaner
    2009-01-27 00:38:20 —-A—- C:WINDOWSsystem32Uninstall.ini
    2009-01-27 00:38:19 —-D—- C:Program FilesUninstall Tool
    2009-01-27 00:38:17 —-D—- C:Program FilesFastStone
    2009-01-27 00:38:17 —-D—- C:Documents and SettingsAdminApplication DataFastStone
    2009-01-27 00:37:47 —-D—- C:Program FilesAdobe
    2009-01-27 00:37:33 —-D—- C:Documents and SettingsAll UsersApplication DataAdobe
    2009-01-27 00:36:44 —-D—- C:Documents and SettingsAdminApplication DataAdobe
    2009-01-27 00:34:04 —-D—- C:Program FilesCommon FilesMacrovision Shared
    2009-01-27 00:33:44 —-D—- C:Program FilesCommon FilesAdobe
    2009-01-27 00:32:54 —-D—- C:Program FilesCommon FilesMacromedia
    2009-01-27 00:32:36 —-D—- C:Documents and SettingsAll UsersApplication DataMacromedia
    2009-01-27 00:32:35 —-D—- C:Program FilesMacromedia
    2009-01-27 00:32:30 —-D—- C:Program FilesCommon FilesInstallShield
    2009-01-27 00:30:02 —-A—- C:WINDOWSODBC.INI
    2009-01-27 00:28:00 —-D—- C:WINDOWSSHELLNEW
    2009-01-27 00:27:10 —-D—- C:Program FilesMicrosoft Works
    2009-01-27 00:27:06 —-D—- C:Program FilesCommon FilesDESIGNER
    2009-01-27 00:27:02 —-D—- C:Program FilesMicrosoft.NET
    2009-01-27 00:26:15 —-D—- C:Program FilesMicrosoft Office
    2009-01-27 00:26:15 —-D—- C:Documents and SettingsAll UsersApplication DataMicrosoft Help
    2009-01-27 00:26:00 —-RHD—- C:MSOCache
    2009-01-27 00:25:37 —-D—- C:Program FilesPunto Switcher
    2009-01-27 00:25:37 —-AD—- C:Documents and SettingsAdminApplication DataYandex
    2009-01-27 00:25:30 —-A—- C:WINDOWSWPI_Log_2009.01.27_00.25.30.txt
    2009-01-27 00:21:01 —-SD—- C:Documents and SettingsAdminApplication DataMicrosoft
    2009-01-27 00:21:01 —-D—- C:Documents and SettingsAdminApplication DataSun
    2009-01-27 00:21:01 —-ASH—- C:Documents and SettingsAdminApplication Datadesktop.ini
    2009-01-27 00:20:39 —-SD—- C:WINDOWSsystem32Microsoft
    2009-01-27 00:20:38 —-A—- C:WINDOWSSchedLgU.Txt
    2009-01-27 00:18:23 —-D—- C:WINDOWSsystem32xircom
    2009-01-27 00:18:23 —-D—- C:Program Filesmsn gaming zone
    2009-01-27 00:17:37 —-D—- C:Program FilesVistaDriveIcon
    2009-01-27 00:17:26 —-AD—- C:Program FilesPaint.NET
    2009-01-27 00:17:26 —-A—- C:WINDOWSsystem32wiaaut.dll
    2009-01-27 00:17:25 —-RA—- C:WINDOWSdelete.bat
    2009-01-27 00:17:24 —-A—- C:WINDOWSinnounp.exe
    2009-01-27 00:17:20 —-A—- C:WINDOWSsystem32javaws.exe
    2009-01-27 00:17:20 —-A—- C:WINDOWSsystem32javaw.exe
    2009-01-27 00:17:20 —-A—- C:WINDOWSsystem32java.exe
    2009-01-27 00:17:20 —-A—- C:WINDOWSsystem32deploytk.dll
    2009-01-27 00:17:14 —-D—- C:Program FilesJava
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xinput9_1_0.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xinput1_3.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xinput1_2.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xinput1_1.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAudio2_3.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAudio2_2.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAudio2_1.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAudio2_0.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAPOFX1_2.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAPOFX1_1.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32XAPOFX1_0.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine3_3.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine3_2.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine3_1.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine3_0.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine2_9.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine2_8.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine2_7.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine2_6.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine2_5.dll
    2009-01-27 00:17:07 —-A—- C:WINDOWSsystem32xactengine2_4.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32xactengine2_3.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32xactengine2_2.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32xactengine2_10.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32xactengine2_1.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32xactengine2_0.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32X3DAudio1_5.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32X3DAudio1_4.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32X3DAudio1_3.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32x3daudio1_2.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32x3daudio1_1.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32x3daudio1_0.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_40.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_39.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_38.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_37.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_36.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_35.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_34.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_33.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_32.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_31.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_30.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_29.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_28.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_27.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_26.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_25.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx9_24.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_40.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_39.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_38.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_37.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_36.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_35.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_34.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10_33.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dx10.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32D3DCompiler_40.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32D3DCompiler_39.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32D3DCompiler_38.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32D3DCompiler_37.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dcompiler_36.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dcompiler_35.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32d3dcompiler_34.dll
    2009-01-27 00:17:06 —-A—- C:WINDOWSsystem32D3DCompiler_33.dll
    2009-01-27 00:15:54 —-RSD—- C:WINDOWSassembly
    2009-01-27 00:15:54 —-D—- C:WINDOWSMicrosoft.NET
    2009-01-27 00:15:53 —-D—- C:WINDOWSsystem32URTTemp
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32zlib1.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32wrap_oal.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32wnaspi32.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32Vbrun300.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32vbrun200.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32vbrun100.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32Vb40032.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32Vb40016.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32ssleay32.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32OpenAL32.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32msvcrt10.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32msvcr71.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32msvcr70.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32msvcp71.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MSVCP70.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32msvci70.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MSSTKPRP.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32msstdfmt.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71u.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71KOR.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71JPN.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71ITA.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71FRA.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71ESP.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71ENU.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71DEU.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71CHT.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71CHS.DLL
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32MFC71.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70u.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70kor.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70jpn.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70ita.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70fra.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70esp.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70enu.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70deu.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70cht.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70chs.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32mfc70.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32libssl32.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32libeay32.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32atl71.dll
    2009-01-27 00:15:30 —-A—- C:WINDOWSsystem32atl70.dll
    2009-01-27 00:15:13 —-A—- C:WINDOWScontrol.ini
    2009-01-27 00:15:13 —-A—- C:AUTOEXEC.BAT
    2009-01-27 00:15:06 —-A—- C:WINDOWSOEWABLog.txt
    2009-01-27 00:15:02 —-A—- C:WINDOWSsystem32mapi32.dll
    2009-01-27 00:14:19 —-RAH—- C:WINDOWSsystem32logonui.exe.manifest
    2009-01-27 00:14:15 —-RAH—- C:WINDOWSsystem32cdplayer.exe.manifest
    2009-01-27 00:14:11 —-HD—- C:Program FilesWindowsUpdate
    2009-01-27 00:14:08 —-D—- C:Program FilesOnline Services
    2009-01-27 00:13:59 —-A—- C:WINDOWSsystem32atrace.dll
    2009-01-27 00:13:58 —-A—- C:WINDOWSsystem32desktop.ini
    2009-01-27 00:13:58 —-A—- C:WINDOWSdesktop.ini
    2009-01-27 00:13:48 —-D—- C:Program FilesCommon FilesServices
    2009-01-27 00:13:48 —-A—- C:WINDOWSsystem32acctres.dll
    2009-01-27 00:13:45 —-SD—- C:WINDOWSTasks
    2009-01-27 00:13:45 —-A—- C:WINDOWSsystem32icfgnt5.dll
    2009-01-27 00:13:44 —-D—- C:Program FilesCommon FilesMSSoap
    2009-01-27 00:13:40 —-D—- C:WINDOWSsystem32Macromed
    2009-01-27 00:13:40 —-D—- C:WINDOWSsrchasst
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wuweb.dll
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wups.dll
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wucltui.dll
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wuauserv.dll
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wuaueng1.dll
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wuaueng.dll
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wuauclt1.exe
    2009-01-27 00:13:37 —-A—- C:WINDOWSsystem32wuauclt.exe
    2009-01-27 00:13:36 —-A—- C:WINDOWSsystem32wuapi.dll
    2009-01-27 00:13:36 —-A—- C:WINDOWSsystem32qmgrprxy.dll
    2009-01-27 00:13:36 —-A—- C:WINDOWSsystem32qmgr.dll
    2009-01-27 00:13:36 —-A—- C:WINDOWSsystem32bitsprx4.dll
    2009-01-27 00:13:36 —-A—- C:WINDOWSsystem32bitsprx3.dll
    2009-01-27 00:13:36 —-A—- C:WINDOWSsystem32bitsprx2.dll
    2009-01-27 00:13:33 —-D—- C:Program FilesMovie Maker
    2009-01-27 00:13:13 —-A—- C:WINDOWSsystem32safrslv.dll
    2009-01-27 00:13:13 —-A—- C:WINDOWSsystem32safrdm.dll
    2009-01-27 00:13:13 —-A—- C:WINDOWSsystem32safrcdlg.dll
    2009-01-27 00:13:13 —-A—- C:WINDOWSsystem32racpldlg.dll
    2009-01-27 00:13:10 —-D—- C:WINDOWSsystem32Restore
    2009-01-27 00:13:10 —-A—- C:WINDOWSsystem32srsvc.dll
    2009-01-27 00:13:10 —-A—- C:WINDOWSsystem32srrstr.dll
    2009-01-27 00:13:10 —-A—- C:WINDOWSsystem32srclient.dll
    2009-01-27 00:13:10 —-A—- C:WINDOWSsystem32fltMc.exe
    2009-01-27 00:13:10 —-A—- C:WINDOWSsystem32fltlib.dll
    2009-01-27 00:13:09 —-A—- C:WINDOWSsystem32msoert2.dll
    2009-01-27 00:13:09 —-A—- C:WINDOWSsystem32msoeacct.dll
    2009-01-27 00:13:08 —-A—- C:WINDOWSsystem32inetres.dll
    2009-01-27 00:13:07 —-A—- C:WINDOWSsystem32inetcomm.dll
    2009-01-27 00:13:05 —-D—- C:Program FilesOutlook Express
    2009-01-27 00:13:05 —-A—- C:WINDOWSsystem32schedsvc.dll
    2009-01-27 00:13:05 —-A—- C:WINDOWSsystem32mstinit.exe
    2009-01-27 00:13:05 —-A—- C:WINDOWSsystem32mstask.dll
    2009-01-27 00:13:04 —-A—- C:WINDOWSsystem32isign32.dll
    2009-01-27 00:13:04 —-A—- C:WINDOWSsystem32inetcfg.dll
    2009-01-27 00:13:04 —-A—- C:WINDOWSsystem32icwphbk.dll
    2009-01-27 00:13:04 —-A—- C:WINDOWSsystem32icwdial.dll
    2009-01-27 00:12:59 —-D—- C:Program FilesCommon FilesSystem
    2009-01-27 00:12:29 —-D—- C:Program FilesComPlus Applications
    2009-01-27 00:12:27 —-A—- C:WINDOWSvbaddin.ini
    2009-01-27 00:12:27 —-A—- C:WINDOWSvb.ini

    21 февраля, 2009 в 5:18 пп #22032
    Kathrine
    Participant
    • Темы:1
    • Сообщений:2
    • ☆

    там дальше еще есть в файле лог.. но что-то и так много.. думаю, что что-то лишнее вам прислала((((
    уж извините…

    22 февраля, 2009 в 4:56 пп #22033
    Admin
    Keymaster
    • Темы:40
    • Сообщений:5676
    • ☆☆☆☆☆

    Здравствуйте, добро пожаловать на Spyware-ru форум.

    Судя по логу ваш компьютер заражён несколькими троянами, включая autorun.inf троян.
    Прочитайте эту инструкцию Flash_Disinfector ещё одно оружие против autorun.inf троянов.

    * Отключите ваш антивирус.
    * Скачайте и запустите Flash_Disinfector.
    * По требованию программы вставьте ваш флэш диск или подключите другие внешние устройства хранения информации.

    Примечание: запускайте программу столько раз, сколько нужно чтобы очистить все ваши подключаемые диски.

    Скачайте OTMoveIt3 by OldTimer кликнув по этой ссылке.
    Запустите OTMoveIt3 и в большое поле ввода (заголовок этого поля выделен желтым цветом) скопируйте следующий текст.

    :Processes
    explorer.exe

    :reg
    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
    "DriverCD"=-
    "SYS1"=-
    "SYS2"=-
    "SYS3"=-
    "SYS4"=-

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    "DisableTaskMgr"=0
    "DisableRegistryTools"=0

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    "NoFind"=0
    "NoFolderOptions"=0

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
    "C:DOCUME~1AdminLOCALS~1Tempwinlbfvj.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempyourmt.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempjiga.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinvdekh.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempkeqh.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinwxlx.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinckqwaq.exe"=-
    "C:DOCUME~1AdminLOCALS~1Temptemprc.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempclkuu.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinewrvp.exe"=-
    "C:DOCUME~1AdminLOCALS~1Temptyxbio.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinbbaeug.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempcuil.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempjqrnro.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempxykm.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempallm.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinebxdi.exe"=-
    "C:DOCUME~1AdminLOCALS~1Temphwwfe.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinirtn.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinlrhnxc.exe"=-
    "C:DOCUME~1AdminLOCALS~1Temptodvxc.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinljqhv.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwiniadtof.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwineyyego.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinmnnmws.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinxgrnvb.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinwupv.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwiniiubrw.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinsqnd.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwindfby.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwintbpfgy.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempvnoka.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinnnqb.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinqeqib.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinqluadr.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinttmvp.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinbklxxo.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinrwxd.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempxmqm.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempfqca.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwintvwp.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinbmtlq.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinapxkb.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinppqjin.exe"=-
    "C:DOCUME~1AdminLOCALS~1Templybt.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempoajiun.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinushprh.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwela.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinpiqk.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwindssj.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempnnuo.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinngksa.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwintqtokh.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinkyftm.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinnhttnn.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinvsendq.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempirgimp.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinlpalk.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinfrmd.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinalyitd.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempbtidm.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinxvfn.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinmwpn.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinhvsf.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempvjkpw.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinftoonu.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinhjyew.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempgiven.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwincxbxu.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwiniyyt.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinvvkuhg.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempqcxie.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinlydhi.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinhsxfvb.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinythlo.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinuiji.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinmxhqaf.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinaltip.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinigxo.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinvfjnp.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinynaa.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinrkdn.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempenvfb.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinnhux.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinjbhiv.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempbfsfhr.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinnoqji.exe"=-
    "C:DOCUME~1AdminLOCALS~1Tempwinmisbn.exe"=-

    [-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{972c569a-f21f-11dd-807c-001d7dd6cf96}]

    :files
    C:WINDOWSsystem32bad1.exe
    C:WINDOWSsystem32bad3.exe
    C:WINDOWSsystem32bad2.exe

    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]

    Проверьте вставленный скрипт, если слева перед директивами появились пробелы, то удалите их, скрипт должен вглядить так же как в сообщении. Кликните по кнопке MoveIt!. В процессе работы возможна перезагрузка компьютера.
    По-завершении работы программы должен будет показан лог. Если лог не будет показан, то его можно найти в папке C:_OTMoveItMovedFiles.

    Вставьте в ваше ответное сообщение содержимое этого лога. И приложите свежий RSIT лог.

  • Автор
    Сообщения
Просмотр 3 сообщений - с 1 по 3 (из 3 всего)
  • Для ответа в этой теме необходимо авторизоваться.
Войти

Добро пожаловать

На нашем сайте размещены инструкции и программы, которые помогут вам абсолютно бесплатно и самостоятельно удалить навязчивую рекламу, вирусы и трояны.

Поиск

Последние темы

  • Странность в Malwebytes опубликовано Artem225
    5 years, 6 months назад
  • SUSPICIOUS.FakedMBR.1 что делать, помогите!!! опубликовано White
    5 years, 6 months назад
  • Помогите пожалуйста вирус замучил. опубликовано dimazons1233211
    5 years, 9 months назад
  • Замучила реклама опубликовано Данила Беспятов
    5 years, 9 months назад
  • Замучила реклама опубликовано Марк
    5 years, 7 months назад
  • Вирус S1.video.ru.net опубликовано ludovik
    6 years назад
  • Чертов Safe Finder!!!! опубликовано kosta savo
    5 years, 9 months назад
  • ESET блокирует неизвестный сайт , вход на который не осуществлялся. опубликовано trollhamaren
    6 years, 1 month назад

СПАЙВАРЕ РУ

  • О Спайваре Ру
  • Контакты
  • Реклама на сайте
  • Политика конфиденциальности
  • Правила использования

Нужна помощь?

Задайте свой вопрос прямо сейчас кликнув по следующей ссылке Задать вопрос.

Или обратитесь на наш форум, где команда Spyware-ru поможет вам. Узнайте, как попросить о помощи здесь.

Ссылки

  • Инструкции
  • Скачать программы
  • Помощь в удалении вирусов
  • Как вылечить компьютер
Copyright © 2008 - 2024 Spyware-RU.com (en)