Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › проблема с Antivirus 2009
- This topic has 7 ответов, 2 участника, and was last updated 16 years, 3 months назад by
Admin.
-
АвторСообщения
-
16 января, 2009 в 7:38 пп #16150
Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Здравствуйте! Опять же проблема с Antivirus 2009. Он не исчезает, пробовала через Avenger, несколько раз. Все равно блокирует страницы и мешает работе в интернете. Но не возникает при включении компьютера. Очень прошу помочь. Вот, что показал RSIT:
info.txt logfile of random’s system information tool 1.05 2009-01-16 21:26:00
======Uninstall list======
—>C:Program FilesNeroNero 7nerouninstallUNNERO.exe /UNINSTALL
—>C:WINDOWSUNNeroBackItUp.exe /UNINSTALL
—>C:WINDOWSUNRecode.exe /UNINSTALL
—>MsiExec /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
—>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:WINDOWSINFPCHealth.inf
3Planesoft Screensaver Manager 1.2—>»C:Program Files3Planesoft Screensaver Managerunins000.exe»
7-Zip 4.32—>»C:Program Files7-ZipUninstall.exe»
ABBYY Lingvo 11 Six Languages—>MsiExec.exe /I{AA11000A-C75E-487C-88FC-37AA1AACFB63}
Adobe Flash Player 10 ActiveX—>C:windowssystem32MacromedFlashuninstall_activeX.exe
Adobe Photoshop CS—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime 701Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{EFB21DE7-8C19-4A88-BB28-A766E16493BC}setup.exe» -l0x9
Adobe Reader 7.0—>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Adobe® Photoshop® Album Starter Edition 3.0—>MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
AGEIA PhysX v7.11.13—>MsiExec.exe /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
Aqua Real—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime 701Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{1E66C7FF-F827-4AEF-A998-932EA824998B}setup.exe» -l0x9
ArcSoft PhotoImpression 4—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{546C7D0B-1E12-4573-BCD0-F5B0D3C66A74}Setup.exe» -l0x9
BootSkin—>C:PROGRA~1StardockWINCUS~1BootSkinUNWISE.EXE C:PROGRA~1StardockWINCUS~1BootSkinINSTALL.LOG
Christmas Bells 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerChristmas Bells 3D Screensaverunins000.exe»
CleanCenter v1.35.02—>»C:Program FilesCleanCenterunins000.exe»
Cuckoo Clock 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerCuckoo Clock 3D Screensaverunins000.exe»
CursorXP—>C:Program FilesCursorXPCurXPUtil.exe -u
DAEMON Tools—>MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
Dance eJay 7—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1050Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{A18BB607-BC5A-474E-88FD-C215B91A0F97}setup.exe» -l0x9 -removeonly
Deep Space 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerDeep Space 3D Screensaverunins000.exe»
Deer Hunter—>C:Program FilesInstallShield Installation Information{480AD4E5-1DF3-42B7-AC19-D25DEE38069E}setup.exe
Deutsch Platinum—>C:windowsuninst.exe -fd:языкиGermanDeIsL1.isu -cd:языкиGerman_ISREG32.DLL
Deutz Engine—>C:windowssystem32Deutz Engine.scr u
Digimax A402—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{34120FE7-1567-42E0-97DB-5D5CE614A93D}Setup.exe» anything
Digimax Viewer 2.1—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{9EE54C1F-FC99-44D6-916A-0CA2D45E740F}Setup.exe»
Download Master version 5.5.6.1139—>»D:InstallDownload Masterunins000.exe»
Dream Aquarium—>»D:ЗаставкиDream AquariumUnInstall.exe»
Dreamfall — The Longest Journey—>»D:GamesDreamfallDreamfall — The Longest Journeyunins000.exe»
Earth 3D Screensaver 1.0—>»D:ЗаставкиEarth 3D Screensaverunins000.exe»
Equestrian Challenge—>»D:GamesEquestrian Challengeunins000.exe»
EVGA Display Driver—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime11 0Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{BEF3EFE7-5159-436D-9BF0-CCC633179EB4}setup.exe» -l0x19 -removeonly
Fireplace 3D Screensaver 1.0—>»D:ЗаставкиFireplace 3D Screensaverunins000.exe»
Fireside Christmas 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerFireside Christmas 3D Screensaverunins000.exe»
Flag 3D Screensaver 1.0—>»D:ЗаставкиFlag 3D Screensaverunins000.exe»
Forest World 3D Screensaver 1.2—>»D:ЗаставкиForest World 3D Screensaverunins000.exe»
Galleon 3D Screensaver 1.3—>»D:ЗаставкиGalleon 3D Screensaverunins000.exe»
Google Toolbar for Internet Explorer—>MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer—>regsvr32 /u /s «c:program filesgooglegoogletoolbar1.dll»
Google Планета Земля—>MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
GUN—>»D:GamesGUNunins000.exe»
Halloween 3D Screensaver 1.1—>»D:Заставки3Planesoft Screensaver ManagerHalloween 3D Screensaverunins000.exe»
Harry Potter — GOF—>»D:GamesHarry Potter and the Goblet of Fireunins000.exe»
Heroes of Might & Magic V — Hammers of Fate—>»D:GamesHeroes of Might & Magic V — Hammers of Fateunins000.exe»
High Definition Audio Driver Package — KB888111—>C:WINDOWS$NtUninstallKB888111WXPSP2$spuninstspuninst.exe
HijackThis 2.0.2—>»C:Program Filestrend microHijackThis.exe» /uninstall
Hotfix for Windows XP (KB926239)—>»C:WINDOWS$NtUninstallKB926239$spuninstspuninst.exe»
ICQ6.5—>»C:Program FilesInstallShield Installation Information{60DE4033-9503-48D1-A483-7846BD217CA9}setup.exe» -runfromtemp -l0x0009 -removeonly
InterActual Player—>C:Program FilesInterActualInterActual Playerinuninst.exe
Japanese Platinum—>C:windowsunin0419.exe -fd:языкиjapaneseDeIsL1.isu -cd:языкиjapanese_ISREG32.DLL
jetAudio Basic—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1050Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}setup.exe» -l0x19 -removeonly
K-Lite Codec Pack 2.77 Basic—>»C:Program FilesK-Lite Codec Packunins000.exe»
Lantern 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerLantern 3D Screensaverunins000.exe»
LifeGlobe Goldfish Aquarium—>»D:ЗаставкиGoldfish Aquariumunins000.exe»
LifeGlobe Sharks, Terrors of the Deep 2—>»D:ЗаставкиSharks2unins000.exe»
Lizardtech DjVu Control—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{105CFC7C-6992-11D5-BD9D-000102C10FD8}Setup.exe» -l0x9
LogonStudio—>D:InstallLOGONS~1UNWISE.EXE D:InstallLOGONS~1INSTALL.LOG
Lost. Остаться в живых—>»C:Program FilesInstallShield Installation Information{2702B8FC-6003-4AC6-ADBC-EC65746D800A}setup.exe» -runfromtemp -l0x0019 -removeonly
Macromedia Flash MX—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}Setup.exe» -l0x9 UNINSTALL
Malwarebytes’ Anti-Malware—>»D:InstallMalwarebytes’ Anti-Malwareunins000.exe»
Mayan Waterfall 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerMayan Waterfall 3D Screensaverunins000.exe»
Microsoft .NET Framework 1.1—>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP—>»C:WINDOWS$NtUninstallMSCompPackV1$spuninstspuninst.exe»
Microsoft Office Access MUI (English) 2007—>MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access MUI (Russian) 2007—>MsiExec.exe /X{90120000-0015-0419-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007—>MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007—>»C:Program FilesCommon FilesMicrosoft SharedOFFICE12Office Setup Controllersetup.exe» /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007—>MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007—>MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Russian) 2007—>MsiExec.exe /X{90120000-0016-0419-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007—>MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (Russian) 2007—>MsiExec.exe /X{90120000-00BA-0419-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007—>MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007—>MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Russian) 2007—>MsiExec.exe /X{90120000-0044-0419-0000-0000000FF1CE}
Microsoft Office Language Pack 2007 — Russian/русский—>»C:Program FilesCommon FilesMicrosoft SharedOFFICE12Office Setup Controllersetup.exe» /uninstall OMUI.RU-RU /dll OSETUP.DLL
Microsoft Office O MUI (Russian) 2007—>MsiExec.exe /X{90120000-0100-0419-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007—>MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Russian) 2007—>MsiExec.exe /X{90120000-00A1-0419-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007—>MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Russian) 2007—>MsiExec.exe /X{90120000-001A-0419-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007—>MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Russian) 2007—>MsiExec.exe /X{90120000-0018-0419-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007—>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007—>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007—>MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Russian) 2007—>MsiExec.exe /X{90120000-001F-0419-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007—>MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proof (Ukrainian) 2007—>MsiExec.exe /X{90120000-001F-0422-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007—>MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing (Russian) 2007—>MsiExec.exe /X{90120000-002C-0419-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007—>MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Russian) 2007—>MsiExec.exe /X{90120000-0019-0419-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007—>MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (Russian) 2007—>MsiExec.exe /X{90120000-006E-0419-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007—>MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office SharePoint Designer MUI (Russian) 2007—>MsiExec.exe /X{90120000-0017-0419-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007—>MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (Russian) 2007—>MsiExec.exe /X{90120000-001B-0419-0000-0000000FF1CE}
Microsoft Office X MUI (Russian) 2007—>MsiExec.exe /X{90120000-0101-0419-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.0—>»C:WINDOWS$NtUninstallWudf01000$spuninstspuninst.exe»
Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mount and Blade—>»D:GamesMount and Bladeunins000.exe»
Nancy Drew Secret of Shadow Ranch—>»D:GamesSecret of Shadow Ranchunins000.exe»
Nature 3D Screensaver 1.1—>»D:ЗаставкиNature 3D Screensaverunins000.exe»
Nero 7 Ultra Edition—>MsiExec.exe /I{4908C75E-E5E2-43F7-B1DF-023CBA831049}
NVIDIA Drivers—>C:windowssystem32nvuninst.exe UninstallGUI
NVIDIA WDM Drivers—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{B023185F-F1EF-4F97-B0BD-AE6D802226D1}setup.exe»
Oblivion—>C:Program FilesInstallShield Installation Information{7EE1AAD4-0E84-4A90-8614-AA6E4E9764D4}setup.exe
OpenAL—>»C:Program FilesOpenALoalinst.exe» /U
Opera 9.21—>MsiExec.exe /X{39619863-8A11-4B60-A166-E6747C986EBE}
PCI SoftV92 Modem—>C:Program FilesCONEXANTCNXT_MODEM_PCI_VEN_14F1&DEV_2F30&SUBSYS_205514F1HXFSETUP.EXE -U -IPSCRCTR5K.INF
QIP Infium 2.0.9020 RC3—>»D:InstallQIP Infiumunins000.exe»
QIP.Online—>D:InstallQIP.OnlineUninstall.exe
QuickTime—>C:PROGRA~1COMMON~1INSTAL~1Driver11INTEL3~1IDriver.exe /M{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083} /l1033
REALTEK GbE & FE Ethernet PCI-E NIC Driver—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime11 0Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{C9BED750-1211-4480-B1A5-718A3BE15525}Setup.exe» -l0x19 -removeonly
Ripple Screensaver—>»D:ЗаставкиRipple ScreensaverUninstall.exe»
SereneScreen Aquarium—>D:ЗаставкиAquariumunins000.exe
SereneScreen Marine Aquarium Time—>»D:ЗаставкиMarine Aquarium Timeunins000.exe»
SimAQUARIUM2 Tank-1 Screensaver—>D:ЗаставкиSimAQUARIUM2unins000.exe
Skype™ 3.8—>MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Sony Ericsson PC Suite—>MsiExec.exe /I{FE6397C1-CECA-4EC3-B064-42AED7676898}
SoundMAX—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime10 0Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{F0A37341-D692-11D4-A984-009027EC0A9C}setup.exe» -l0x19 -removeonly
The Sims 2—>»D:GamesThe Sims 2unins000.exe»
Total Commander 7.00 PowerPack—>»C:Program FilesTotal Commanderuninstall.exe»
Tropical Fish 3D Screensaver 1.1—>»D:Заставки3Planesoft Screensaver ManagerTropical Fish 3D Screensaverunins000.exe»
Two Worlds—>C:Program FilesInstallShield Installation Information{AD87E219-8627-409B-8042-D769163A8662}setup.exe
Underwater World 3D Screensaver 1.0—>»D:ЗаставкиUnderwater World 3D Screensaverunins000.exe»
Valentine 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerValentine 3D Screensaverunins000.exe»
Vista Transformation Pack 6.0 RC1—>C:WINDOWSSystem32vimc.exe
Vtune 6.4—>»C:Program FilesVtuneunins000.exe»
Watermill 3D Screensaver 2.0—>»D:ЗаставкиWatermill 3D Screensaverunins000.exe»
Western Railway 3D Screensaver 1.0—>»D:Заставки3Planesoft Screensaver ManagerWestern Railway 3D Screensaverunins000.exe»
Winamp (remove only)—>»C:Program FilesWinampUninstWA.exe»
Windows Installer 3.1 (KB893803)—>»C:windows$MSI31Uninstall_KB893803v2$spuninstspuninst.exe»
Windows Internet Explorer 7—>»C:WINDOWSie7spuninstspuninst.exe»
Windows Media Format 11 runtime—>»C:Program FilesWindows Media Playerwmsetsdk.exe» /UninstallAll
Windows Media Format 11 runtime—>»C:WINDOWS$NtUninstallWMFDist11$spuninstspuninst.exe»
Windows Media Player 11—>»C:WINDOWS$NtUninstallwmp11$spuninstspuninst.exe»
WLP2 Долина лошадей—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime10 1Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{3B3D9493-5300-4388-A8A9-8E0388D2A519}setup.exe» -l0x19 -removeonly
Your Uninstaller! 2004 Version 3—>»C:Program FilesYour Uninstaller 2004unins000.exe»
Антивирус Касперского 7.0—>MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Антивирус Касперского 7.0—>MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Гарри Поттер и Философский камень—>D:GamesHARRYP~1UNWISE.EXE D:GamesHARRYP~1INSTALL.LOG
Кубок Долины Роз—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime 9 1Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{29AE2BE7-661F-43C1-AAF9-3E1D3D5D5BC2}setup.exe» -l0x19
Нэнси Дрю. Легенда о хрустальном черепе—>C:Program FilesInstallShield Installation Information{1BDAAF92-7EC3-4A31-A96E-003721731024}setup.exe -runfromtemp -l0x0019 -removeonly
Нэнси Дрю. Похищение в театре—>C:Program FilesInstallShield Installation Information{4E2275E9-85C9-41BD-A2C3-B18DDDC1FB4D}setup.exe -runfromtemp -l0x0019 -removeonly
Озеро черного лебедя Заставка—>»C:Program FilesEleFun DesktopsОзеро черного лебедя Заставкаuninstall.exe» u
Проигрыватель Windows Media 11—>»C:Program FilesWindows Media PlayerSetup_wm.exe» /Uninstall
ЯРКСИ 2.6—>»D:ЯзыкиJapaneseYarxiunins000.exe»======Hosts File======
127.0.0.1 localhost
127.0.0.1 mpa.one.microsoft.com======Security center information======
AV: Антивирус Касперского
System event log
Computer Name: GALE4KA
Event Code: 7036
Message: Служба «Службы терминалов» перешла в состояние Работает.Record Number: 5
Source Name: Service Control Manager
Time Written: 20090116205908.000000+180
Event Type: информация
User:Computer Name: GALE4KA
Event Code: 7026
Message: Сбой при загрузке драйвера(ов) перезагрузки или запуска системы:
brgi
ST77busRecord Number: 4
Source Name: Service Control Manager
Time Written: 20090116205908.000000+180
Event Type: ошибка
User:Computer Name: GALE4KA
Event Code: 7000
Message: Сбой при запуске службы «CLCV0» из-за ошибки
%1 не является приложением Win32.Record Number: 3
Source Name: Service Control Manager
Time Written: 20090116205908.000000+180
Event Type: ошибка
User:Computer Name: GALE4KA
Event Code: 6005
Message: Запущена служба журнала событий.Record Number: 2
Source Name: EventLog
Time Written: 20090116205852.000000+180
Event Type: информация
User:Computer Name: GALE4KA
Event Code: 6009
Message: Microsoft (R) Windows 2000 (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.Record Number: 1
Source Name: EventLog
Time Written: 20090116205852.000000+180
Event Type: информация
User:Application event log
Computer Name: GALE4KA
Event Code: 1
Message:
Record Number: 3454
Source Name: AVGEMS
Time Written: 20080412103613.000000+240
Event Type: информация
User:Computer Name: GALE4KA
Event Code: 1
Message:
Record Number: 3453
Source Name: Avg7UpdSvc
Time Written: 20080412103612.000000+240
Event Type: информация
User:Computer Name: GALE4KA
Event Code: 1517
Message: Реестр пользователя GALE4KA1111 был сохранен в то время, как приложение или служба продолжали использовать его во время выхода из системы. Используемая реестром пользователя память не была освобождена. Реестр будет выгружен, когда он не будет использоваться.Возможная причина — службы, выполняемые от имени пользователя. Попробуйте изменить настройку служб и задать их выполнение с учетными записями LocalService или NetworkService.
Record Number: 3452
Source Name: Userenv
Time Written: 20080412021300.000000+240
Event Type: предупреждение
User: NT AUTHORITYSYSTEMComputer Name: GALE4KA
Event Code: 101
Message: wuauclt (2212) Ядро базы данных остановлено.Record Number: 3451
Source Name: ESENT
Time Written: 20080411204316.000000+240
Event Type: информация
User:Computer Name: GALE4KA
Event Code: 103
Message: wuaueng.dll (2212) SUS20ClientDataStore: Ядро базы данных остановило работу экземпляра (0).Record Number: 3450
Source Name: ESENT
Time Written: 20080411204316.000000+240
Event Type: информация
User:======Environment variables======
«ComSpec»=%SystemRoot%system32cmd.exe
«Path»=%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem;C:Program FilesCommon FilesTeleca Shared;C:Program FilesQuickTimeQTSystem
«windir»=%SystemRoot%
«FP_NO_HOST_CHECK»=NO
«OS»=Windows_NT
«PROCESSOR_ARCHITECTURE»=x86
«PROCESSOR_LEVEL»=6
«PROCESSOR_IDENTIFIER»=x86 Family 6 Model 15 Stepping 2, GenuineIntel
«PROCESSOR_REVISION»=0f02
«NUMBER_OF_PROCESSORS»=2
«PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
«TEMP»=%SystemRoot%TEMP
«TMP»=%SystemRoot%TEMP
«CLASSPATH»=C:Program FilesQuickTimeQTSystemQTJava.zip
«QTJAVA»=C:Program FilesQuickTimeQTSystemQTJava.zip
EOF
Logfile of random’s system information tool 1.05 (written by random/random)
Run by 1111 at 2009-01-16 21:16:05
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 64 GB (80%) free of 80 GB
Total RAM: 1023 MB (58% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:25:56, on 16.01.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: NormalRunning processes:
C:windowsSystem32smss.exe
C:windowssystem32winlogon.exe
C:windowssystem32services.exe
C:windowssystem32lsass.exe
C:windowssystem32svchost.exe
C:windowsSystem32svchost.exe
C:windowssystem32spoolsv.exe
C:windowsExplorer.EXE
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:windowssystem32RUNDLL32.EXE
C:windowssystem32ctfmon.exe
C:Program FilesCursorXPCursorXP.exe
C:Program FilesVtuneTBPanel.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:windowssystem32nvsvc32.exe
D:InstallQIP Infiuminfium.exe
C:Program FilesOperaOpera.exe
C:Documents and Settings1111Рабочий столRSIT.exe
C:Program Filestrend micro1111.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: (no name) — — shell32.dll (file missing)
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 — BHO: &Research — {0B014B81-4E12-46F9-806F-55867AF8FD3C} — C:WINDOWSsystem32winsystems.dll
O2 — BHO: Skype add-on (mastermind) — {22BF413B-C6D2-4d91-82A9-A0F997BA588C} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — D:InstallDOWNLO~1dmiehlp.dll
O2 — BHO: Google Toolbar Helper — {AA58ED58-01DD-4d91-8333-CF10577473F7} — c:program filesgooglegoogletoolbar1.dll
O3 — Toolbar: &Google — {2318C2B1-4965-11d4-9B18-009027A5CD4F} — c:program filesgooglegoogletoolbar1.dll
O4 — HKLM..Run: [AVP] «C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe»
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:windowssystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:windowssystem32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 — HKCU..Run: [ctfmon.exe] C:windowssystem32ctfmon.exe
O4 — HKCU..Run: [CursorXP] C:Program FilesCursorXPCursorXP.exe
O4 — HKCU..Run: [TBPanel] C:Program FilesVtuneTBPanel.exe /A
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O8 — Extra context menu item: E&xport to Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O8 — Extra context menu item: Translate with ABBYY &Lingvo — res://D:InstallABBYY Lingvo 11 Six LanguagesLingvo.exe/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — D:InstallDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — D:InstallDownload Masterdmie.htm
O9 — Extra button: Cтатистика Веб-Антивируса — {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0SCIEPlgn.dll
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — shell32.dll (file missing)
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — shell32.dll (file missing)
O9 — Extra button: Skype — {77BF5300-1474-4EC7-9980-D32B190E9B07} — shell32.dll (file missing)
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — D:InstallDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — D:InstallDownload Masterdmaster.exe
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 — Extra button: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — D:InstallICQ6.5ICQ.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — D:InstallICQ6.5ICQ.exe (file missing)
O9 — Extra button: Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O9 — Extra ‘Tools’ menuitem: Windows Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O17 — HKLMSystemCCSServicesTcpip..{5336BB58-E4F9-4CDE-9EDF-B5A47F332542}: NameServer = 192.168.36.1,217.73.142.1
O17 — HKLMSystemCCSServicesTcpip..{F3831A1A-2577-46B5-A8E0-E6C28F20D174}: NameServer = 217.73.142.1 217.117.64.1
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:PROGRA~1MICROS~2Office12GR99D3~1.DLL
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Adobe LM Service — Unknown owner — C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 — Service: Kaspersky Anti-Virus 7.0 (AVP) — Kaspersky Lab — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:windowssystem32services.exe
O23 — Service: Google Updater Service (gusvc) — Google — C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Macrovision Corporation — C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
O23 — Service: NBService — Nero AG — C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:windowssystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:windowssystem32services.exe
O23 — Service: Two Worlds Drivers Auto Removal (pr2ak9jb) (pr2ak9jb) — Akella — C:windowssystem32pr2ak9jb.exe
O23 — Service: Wildlife Park 2 AddOn2 Horses Drivers Auto Removal (pr2aluab) (pr2aluab) — Koch Media — C:windowssystem32pr2aluab.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:windowsSystem32SCardSvr.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:windowssystem32smlogsvc.exe
O23 — Service: CLCV0 (UTSCSI) — Unknown owner — C:windowssystem32UTSCSI.EXE
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:windowsSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe
O24 — Desktop Component 1: Aqua Real — 7db39a0d-580f-4be9-9195-8bfcd226f6c2—
End of file — 7708 bytes======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll [2004-12-14 63136][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0B014B81-4E12-46F9-806F-55867AF8FD3C}]
&Research — C:WINDOWSsystem32winsystems.dll [2006-03-02 298496][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll [2008-11-07 1088296][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-26 2210608][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — D:InstallDOWNLO~1dmiehlp.dll [2008-10-24 157696][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper — c:program filesgooglegoogletoolbar1.dll [2008-11-12 2427968][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} — &Google — c:program filesgooglegoogletoolbar1.dll [2008-11-12 2427968][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«»= []
«AVP»=C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
«NvCplDaemon»=C:windowssystem32NvCpl.dll [2008-06-25 13529088]
«nwiz»=nwiz.exe /install []
«NvMediaCenter»=C:windowssystem32NvMcTray.dll [2008-06-25 86016]
«KernelFaultCheck»=C:windowssystem32dumprep 0 -k [][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«ctfmon.exe»=C:windowssystem32ctfmon.exe [2006-03-02 15360]
«CursorXP»=C:Program FilesCursorXPCursorXP.exe [2005-01-19 140288]
«TBPanel»=C:Program FilesVtuneTBPanel.exe [2008-07-10 2154496][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Photo Downloader]
C:Program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe [2005-06-06 57344][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAVG7_CC]
C:PROGRA~1GrisoftAVGFRE~1avgcc.exe /STARTUP [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:Program FilesCommon FilesAheadLibNMBgMonitor.exe [2006-11-16 139264][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBootSkin Startup Jobs]
C:PROGRA~1StardockWINCUS~1BootSkinBootSkin.exe [2004-04-26 270336][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
C:WINDOWSsystem32ctfmon.exe [2006-03-02 15360][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregDAEMON Tools-1033]
D:InstallDRToolsdaemon.exe [2004-08-22 81920][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGlass2k]
C:Program FilesGlass2kGlass2k.exe [2003-12-12 56325][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGrooveMonitor]
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe [2006-10-26 31016][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregICQ]
D:InstallICQ6.5ICQ.exe silent [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLingvo Launcher]
D:InstallABBYY Lingvo 11 Six LanguagesLvagent.exe [2005-09-01 106496][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLingvoTraining]
D:InstallABBYY Lingvo 11 Six LanguagesTutor.exe [2005-09-01 1282048][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogonStudio]
C:Program FilesWinCustomizeLogonStudiologonstudio.exe [2002-09-03 987187][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
C:Program FilesCommon FilesAheadLibNeroCheck.exe [2006-01-12 155648][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvCplDaemon]
C:WINDOWSsystem32NvCpl.dll [2008-06-25 13529088][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
C:WINDOWSsystem32NvMcTray.dll [2008-06-25 86016][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregnwiz]
nwiz.exe /install [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregQuickTime Task]
C:Program FilesQuickTimeqttask.exe [2007-09-30 155648][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSony Ericsson PC Suite]
C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe [2007-03-28 593920][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMAX]
C:Program FilesAnalog DevicesSoundMAXSmax4.exe [2006-04-10 729088][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMAXPnP]
C:Program FilesAnalog DevicesCoresmax4pnp.exe [2006-05-01 843776][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Adobe Gamma Loader.lnk]
C:PROGRA~1COMMON~1AdobeCALIBR~1ADOBEG~1.EXE [1999-11-04 113664][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Digimax Viewer 2.1.lnk]
D:InstallSamsungDIGIMA~1.1STIMGB~1.EXE [2004-08-20 634880][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyklogon]
C:windowssystem32klogon.dll [2007-06-28 206088][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32WPDShServiceObj.dll [2006-10-18 133632][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-26 2210608][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=36
«NoDriveAutoRun»=FFFFFFFF[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«E:GSC World PublishingS.T.A.L.K.E.RbinXR_3DA.exe»=»E:GSC World PublishingS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«E:GSC World PublishingS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»E:GSC World PublishingS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE»=»C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook»
«C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE»=»C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE:*:Enabled:Microsoft Office Groove»
«C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE»=»C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE:*:Enabled:Microsoft Office OneNote»
«D:SanekGamesUnreal Tournament 2004_1SystemUT2004.exe»=»D:SanekGamesUnreal Tournament 2004_1SystemUT2004.exe:*:Enabled:UT2004»
«D:SanekGamesCShl.exe»=»D:SanekGamesCShl.exe:*:Disabled:Half-Life Launcher»
«D:SanekGamesCShlds.exe»=»D:SanekGamesCShlds.exe:*:Disabled:HLDS Launcher»
«D:SanekGamesCShltv.exe»=»D:SanekGamesCShltv.exe:*:Disabled:HLTV Launcher»
«D:SanekGamesS.T.A.L.K.E.RbinXR_3DA.exe»=»D:SanekGamesS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«D:SanekGamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»D:SanekGamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«D:SanekGamesQuake III Arenaquake3.exe»=»D:SanekGamesQuake III Arenaquake3.exe:*:Disabled:quake3»
«D:GamesS.T.A.L.K.E.RbinXR_3DA.exe»=»D:GamesS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«D:GamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»D:GamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«D:Gamessoldat2dSoldat.exe»=»D:Gamessoldat2dSoldat.exe:*:Disabled:Soldat»
«D:GamesUnrealT3BinariesUT3.exe»=»D:GamesUnrealT3BinariesUT3.exe:*:Disabled:UT3»
«D:SashenkaOldGamesUnreal Tournament 2004SystemUT2004.exe»=»D:SashenkaOldGamesUnreal Tournament 2004SystemUT2004.exe:*:Enabled:UT2004»
«D:GamesLostLost. Остаться в живыхYeti_Final_Win32.exe»=»D:GamesLostLost. Остаться в живыхYeti_Final_Win32.exe:*:Enabled:Lost. Остаться в живых Game»
«D:GamesLostLost. Остаться в живыхgu.exe»=»D:GamesLostLost. Остаться в живыхgu.exe:*:Enabled:Lost. Остаться в живых Updater»
«D:GamesLostLost. Остаться в живыхdetectionLauncher.exe»=»D:GamesLostLost. Остаться в живыхdetectionLauncher.exe:*:Enabled:Lost. Остаться в живых Requirements Tool»
«D:InstallICQ6.5ICQ.exe»=»D:InstallICQ6.5ICQ.exe:*:Enabled:ICQ6»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{0bdfc960-69eb-11dc-8527-a0a9db2e8f47}]
shellAutoRuncommand — F:run.exe[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2b0f8c0b-c1d5-11dc-8591-da31361b0455}]
shellAutoRuncommand — G:
shellopencommand — rundll32.exe .\kmerror.dll,InstallM[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2b0f8c0c-c1d5-11dc-8591-da31361b0455}]
shellAutoRuncommand — H:USBNB.exe[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{88472d86-2e61-11dc-8482-e88c6d6a6a0a}]
shellAutoRuncommand — F:
shellopencommand — rundll32.exe .\sks2cpg.dll,InstallM[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{ac904c6b-2e45-11dc-8480-eb63824e56be}]
shellAutoRuncommand — F:
shellopencommand — rundll32.exe .\wmbasf.dll,InstallM[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{b253a403-3d8d-11dc-84b8-9b95a1a2421c}]
shellAutoRuncommand — H:
shellopencommand — rundll32.exe .\wkssl.dll,InstallM[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{b5f1f8e8-6851-11dd-91ce-b5c3978229eb}]
shellAutoRuncommand — H:
shellopencommand — rundll32.exe .\wmbasf.dll,InstallM[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{eb3e70c6-1b50-11dc-845a-93eccf615298}]
shellAutoRuncommand — H:
shellopencommand — rundll32.exe .\lnmpapi.dll,InstallM[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{f8eb18ce-1e74-11dc-8460-899987038c9c}]
shellAutoRuncommand — G:
shellopencommand — rundll32.exe .\ddbc16gt.dll,InstallM======List of files/folders created in the last 1 months======
2009-01-16 21:16:06 —-D—- C:Program Filestrend micro
2009-01-16 21:16:05 —-D—- C:rsit
2009-01-16 20:58:22 —-A—- C:avenger.txt
2009-01-16 20:32:21 —-RASHD—- C:autorun.inf
2009-01-16 19:53:03 —-D—- C:Program FilesEnigma Software Group
2009-01-16 14:49:55 —-D—- C:Documents and Settings1111Application DataMalwarebytes
2009-01-16 14:49:50 —-D—- C:Documents and SettingsAll UsersApplication DataMalwarebytes
2009-01-16 14:46:48 —-D—- C:Avenger
2009-01-16 14:44:46 —-A—- C:zip.exe
2009-01-16 14:44:46 —-A—- C:cleanup.exe
2009-01-16 14:44:46 —-A—- C:cleanup.bat
2009-01-16 14:03:45 —-D—- C:Documents and SettingsAll UsersApplication DataAvg7
2009-01-16 11:47:35 —-A—- C:windowsModemLog_PCI SoftV92 Modem.txt
2009-01-12 14:43:14 —-D—- C:Documents and Settings1111Application DataMount&Blade
2008-12-23 01:07:22 —-A—- C:windowsApplian FLV Player Uninstall Log.txt
2008-12-23 00:39:17 —-D—- C:windowsApplian FLV Player
2008-12-23 00:38:26 —-A—- C:windowsApplian FLV Player Setup Log.txt
2008-12-23 00:38:19 —-D—- C:Program FilesMyCentria
2008-12-22 13:39:48 —-D—- C:Documents and Settings1111Application DataskypePM
2008-12-20 14:36:51 —-D—- C:windowsNV39483952.TMP
2008-12-20 14:23:11 —-D—- C:windowsNV32483436.TMP
2008-12-20 12:23:45 —-A—- C:windowssystem32XAudio2_1.dll
2008-12-20 12:23:45 —-A—- C:windowssystem32XAPOFX1_0.dll
2008-12-20 12:23:44 —-A—- C:windowssystem32xactengine3_1.dll
2008-12-20 12:23:43 —-A—- C:windowssystem32X3DAudio1_4.dll
2008-12-20 12:23:43 —-A—- C:windowssystem32d3dx10_38.dll
2008-12-20 12:23:43 —-A—- C:windowssystem32D3DCompiler_38.dll
2008-12-20 12:23:42 —-A—- C:windowssystem32D3DX9_38.dll
2008-12-20 12:23:41 —-A—- C:windowssystem32XAudio2_0.dll
2008-12-20 12:23:40 —-A—- C:windowssystem32xactengine3_0.dll
2008-12-20 12:23:40 —-A—- C:windowssystem32X3DAudio1_3.dll
2008-12-20 12:23:39 —-A—- C:windowssystem32d3dx10_37.dll
2008-12-20 12:23:39 —-A—- C:windowssystem32D3DCompiler_37.dll
2008-12-20 12:23:38 —-A—- C:windowssystem32D3DX9_37.dll
2008-12-20 12:16:47 —-D—- C:windowsNV13923628.TMP
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrszht.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrszhc.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrstr.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsth.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrssv.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrssl.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrssk.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsru.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsptb.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrspt.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrspl.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsno.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsnl.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsko.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsja.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsit.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrshu.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrshe.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsfr.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsfi.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsesm.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrses.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrseng.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsel.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsde.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsda.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrscs.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvwrsar.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrszht.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrszhc.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrstr.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsth.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrssv.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrssl.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrssk.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsru.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsptb.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrspt.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrspl.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsno.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsnl.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsko.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsja.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsit.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrshu.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrshe.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsfr.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsfi.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsesm.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrses.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrseng.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsel.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsde.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsda.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrscs.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvrsar.dll
2008-12-20 12:15:32 —-A—- C:windowssystem32nvcuda.dll
2008-12-20 12:13:50 —-D—- C:windowsLogs
2008-12-20 12:11:48 —-D—- C:Program FilesVtune======List of files/folders modified in the last 1 months======
2009-01-16 21:25:14 —-D—- C:windowsTemp
2009-01-16 21:16:06 —-RD—- C:Program Files
2009-01-16 20:59:10 —-D—- C:windowssystem32CatRoot2
2009-01-16 20:59:08 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab
2009-01-16 20:58:22 —-D—- C:windowssystem32drivers
2009-01-16 20:58:22 —-D—- C:windowssystem32
2009-01-16 20:56:38 —-A—- C:windowsSchedLgU.Txt
2009-01-16 20:00:49 —-D—- C:windowssystem32Restore
2009-01-16 19:16:08 —-D—- C:WINDOWS
2009-01-16 19:00:58 —-SHD—- C:windowsInstaller
2009-01-16 14:03:43 —-D—- C:windowssystem
2009-01-16 13:45:54 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab Setup Files
2009-01-16 12:18:14 —-A—- C:windowswin.ini
2009-01-12 14:24:22 —-D—- C:windowsPrefetch
2009-01-03 01:26:04 —-D—- C:windowsMinidump
2009-01-02 20:45:25 —-A—- C:windowsNeroDigital.ini
2008-12-23 01:04:58 —-D—- C:Documents and Settings1111Application DataSkype
2008-12-21 12:19:14 —-A—- C:windowsjapPlat.ini
2008-12-21 12:19:01 —-HD—- C:windowsinf
2008-12-20 20:23:34 —-D—- C:Documents and SettingsAll UsersApplication DataAdobe
2008-12-20 20:23:34 —-D—- C:Documents and Settings1111Application DataAdobe
2008-12-20 15:34:00 —-A—- C:windowsBlendSettings.ini
2008-12-20 14:38:53 —-D—- C:windowsHelp
2008-12-20 14:38:50 —-D—- C:windowsnview
2008-12-20 14:34:18 —-D—- C:windowssystem32DirectX
2008-12-20 14:01:26 —-HD—- C:Program FilesInstallShield Installation Information
2008-12-20 12:16:19 —-RSHDC—- C:windowssystem32dllcache
2008-12-17 17:31:45 —-SD—- C:Documents and Settings1111Application DataMicrosoft======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Драйвер Intel процессора; C:windowssystem32DRIVERSintelppm.sys [2006-03-02 40448]
R1 klif;Klif; ??C:windowssystem32driversklif.sys []
R1 prodrv05;StarForce Protection Environment Driver v5; C:windowsSystem32driversprodrv05.sys [2002-11-22 76704]
R2 mdmxsdk;mdmxsdk; C:windowssystem32DRIVERSmdmxsdk.sys [2004-03-17 13059]
R2 TBPanel;TBPanel; C:windowssystem32driversTBPanel.sys [2007-03-16 12256]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:windowssystem32driversADIHdAud.sys [2006-05-02 229376]
R3 AEAudio;AE Audio Service; C:windowssystem32driversAEAudio.sys [2006-04-27 93824]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:windowssystem32DRIVERSHDAudBus.sys [2004-10-27 138240]
R3 HSF_DP;HSF_DP; C:windowssystem32DRIVERSHSF_DP.sys [2004-09-29 1036928]
R3 HSFHWBS2;HSFHWBS2; C:windowssystem32DRIVERSHSFHWBS2.sys [2004-09-29 219136]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:windowssystem32DRIVERSklim5.sys [2007-04-04 24344]
R3 MODEMCSA;Устройство фильтрации потока Unimodem; C:windowssystem32driversMODEMCSA.sys [2001-08-17 16128]
R3 MTsensor;ATK0110 ACPI UTILITY; C:windowssystem32DRIVERSASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:windowssystem32DRIVERSnv4_mini.sys [2008-06-25 6555168]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:windowssystem32DRIVERSRtenicxp.sys [2006-07-27 83712]
R3 SenFiltService;SenFilt Service; C:windowssystem32driversSenfilt.sys [2006-03-17 392960]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:windowssystem32DRIVERSusbehci.sys [2004-08-03 26624]
R3 usbhub;Драйвер стандартного концентратора USB (Microsoft); C:windowssystem32DRIVERSusbhub.sys [2004-08-03 57600]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:windowssystem32DRIVERSusbuhci.sys [2004-08-03 20480]
R3 winachsf;winachsf; C:windowssystem32DRIVERSHSF_CNXT.sys [2004-09-29 702592]
S3 apnqj3fx;apnqj3fx; C:windowssystem32driversapnqj3fx.sys []
S3 Cardex;Cardex; ??C:windowssystem32driversTBPANEL.SYS []
S3 PciCon;PciCon; ??D:PciCon.sys []
S3 se58bus;Sony Ericsson Device 088 driver (WDM); C:windowssystem32DRIVERSse58bus.sys [2006-09-05 61536]
S3 se58mdfl;Sony Ericsson Device 088 USB WMC Modem Filter; C:windowssystem32DRIVERSse58mdfl.sys [2006-09-05 9360]
S3 se58mdm;Sony Ericsson Device 088 USB WMC Modem Driver; C:windowssystem32DRIVERSse58mdm.sys [2006-09-05 97088]
S3 se58mgmt;Sony Ericsson Device 088 USB WMC Device Management Drivers (WDM); C:windowssystem32DRIVERSse58mgmt.sys [2006-09-05 88624]
S3 se58nd5;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (NDIS); C:windowssystem32DRIVERSse58nd5.sys [2006-09-05 18704]
S3 se58obex;Sony Ericsson Device 088 USB WMC OBEX Interface; C:windowssystem32DRIVERSse58obex.sys [2006-09-05 86432]
S3 se58unic;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (WDM); C:windowssystem32DRIVERSse58unic.sys [2006-09-05 90800]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:windowssystem32DRIVERSUSBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:windowssystem32DRIVERSWudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:windowssystem32DRIVERSwudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:windowssystem32driversIntelIde.sys []======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Kaspersky Anti-Virus 7.0; C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
R2 NVSvc;NVIDIA Display Driver Service; C:windowssystem32nvsvc32.exe [2008-06-25 159812]
S2 pr2ak9jb;Two Worlds Drivers Auto Removal (pr2ak9jb); C:windowssystem32pr2ak9jb.exe [2007-05-19 407160]
S2 pr2aluab;Wildlife Park 2 AddOn2 Horses Drivers Auto Removal (pr2aluab); C:windowssystem32pr2aluab.exe [2008-04-09 411032]
S2 UTSCSI;CLCV0; C:windowssystem32UTSCSI.EXE []
S3 Adobe LM Service;Adobe LM Service; C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe [2007-06-03 68096]
S3 aspnet_state;ASP.NET State Service; C:windowsMicrosoft.NETFrameworkv1.1.4322aspnet_state.exe [2003-02-21 32768]
S3 gusvc;Google Updater Service; C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe [2008-11-12 138168]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe [2005-11-14 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2006-10-26 65824]
S3 NBService;NBService; C:Program FilesNeroNero 7Nero BackItUpNBService.exe [2006-11-10 774144]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Служба общих сетевых ресурсов проигрывателя Windows Media; C:Program FilesWindows Media PlayerWMPNetwk.exe [2006-11-02 914944]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:windowssystem32svchost.exe [2006-03-02 14336]
EOF
18 января, 2009 в 9:56 пп #21271Здравствуйте, добро пожаловать на Spyware-ru форум.
Скачайте OTMoveIt3 by OldTimer кликнув по этой ссылке.
Запустите программу и в большое поле ввода (заголовок этого поля выделено желтым цветом) скопируйте следующий текст.:Processes
explorer.exe
:reg
[-HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0B014B81-4E12-46F9-806F-55867AF8FD3C}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{0bdfc960-69eb-11dc-8527-a0a9db2e8f47}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2b0f8c0b-c1d5-11dc-8591-da31361b0455}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2b0f8c0c-c1d5-11dc-8591-da31361b0455}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{88472d86-2e61-11dc-8482-e88c6d6a6a0a}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{ac904c6b-2e45-11dc-8480-eb63824e56be}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{b253a403-3d8d-11dc-84b8-9b95a1a2421c}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{b5f1f8e8-6851-11dd-91ce-b5c3978229eb}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{eb3e70c6-1b50-11dc-845a-93eccf615298}]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{f8eb18ce-1e74-11dc-8460-899987038c9c}]
:files
C:Program FilesMyCentria
C:WINDOWSsystem32winsystems.dll
:Commands
[emptytemp]
[start explorer]
[Reboot]Кликните по кнопке MoveIt!. В процессе работы возможна перезагрузка компьютера.
По-завершении работы программы должен будет показан лог, вставьте его в ваш ответ.
Так же к ответу приложите свежий RSIT лог.20 января, 2009 в 10:45 пп #21272Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Спасибо большое за инструкцию. Вот лог по завершению OTMoveit:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowserHelper Objects{0B014B81-4E12-46F9-806F-55867AF8FD3C}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{0bdfc960-69eb-
11dc-8527-a0a9db2e8f47}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2b0f8c0b-c1d5-
11dc-8591-da31361b0455}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2b0f8c0c-c1d5-
11dc-8591-da31361b0455}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{88472d86-2e61
-11dc-8482-e88c6d6a6a0a}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{ac904c6b-2e45
-11dc-8480-eb63824e56be}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{b253a403-3d8d
-11dc-84b8-9b95a1a2421c}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{b5f1f8e8-6851-
11dd-91ce-b5c3978229eb}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{eb3e70c6-1b50
-11dc-845a-93eccf615298}\ deleted successfully.
Registry keyHKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{f8eb18ce-1e74-
11dc-8460-899987038c9c}\ deleted successfully.
========== FILES ==========
C:Program FilesMyCentriaInfoBar moved successfully.
C:Program FilesMyCentriaFirefox moved successfully.
C:Program FilesMyCentria moved successfully.
C:WINDOWSsystem32winsystems.dll unregistered successfully.
C:WINDOWSsystem32winsystems.dll moved successfully.
========== COMMANDS ==========
User’s Temp folder emptied.
User’s Temporary Internet Files folder emptied.
User’s Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:Documents and SettingsLocalServiceLocal SettingsTemporary InternetFilesContent.IE5index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:windowstempPerflib_Perfdata_58c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfullyOTMoveIt3 by OldTimer — Version 1.0.8.0 log created on 01212009_003224
Files moved on Reboot…
C:Documents and SettingsLocalServiceLocal SettingsTemporary Internet FilesContent.IE5index.datmoved successfully.
File C:windowstempPerflib_Perfdata_58c.dat not found!А вот от RSIT:
Logfile of random’s system information tool 1.05 (written by random/random)
Run by 1111 at 2009-01-21 00:39:48
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 64 GB (80%) free of 80 GB
Total RAM: 1023 MB (59% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:39:50, on 21.01.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: NormalRunning processes:
C:windowsSystem32smss.exe
C:windowssystem32winlogon.exe
C:windowssystem32services.exe
C:windowssystem32lsass.exe
C:windowssystem32svchost.exe
C:windowsSystem32svchost.exe
C:windowssystem32spoolsv.exe
C:windowsExplorer.EXE
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:windowssystem32RUNDLL32.EXE
C:Program FilesJavajre6binjusched.exe
C:windowssystem32ctfmon.exe
C:Program FilesCursorXPCursorXP.exe
C:Program FilesVtuneTBPanel.exe
D:InstallDAEMON Tools Litedaemon.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:Program FilesJavajre6binjqs.exe
C:windowssystem32nvsvc32.exe
C:windowssystem32wuauclt.exe
C:Program FilesOperaOpera.exe
C:Documents and Settings1111Рабочий столRSIT.exe
C:Program Filestrend micro1111.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: (no name) — — shell32.dll (file missing)
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 — BHO: Skype add-on (mastermind) — {22BF413B-C6D2-4d91-82A9-A0F997BA588C} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL
O2 — BHO: Java(tm) Plug-In SSV Helper — {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} — C:Program FilesJavajre6binssv.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — D:InstallDOWNLO~1dmiehlp.dll
O2 — BHO: Google Toolbar Helper — {AA58ED58-01DD-4d91-8333-CF10577473F7} — c:program filesgooglegoogletoolbar1.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: JQSIEStartDetectorImpl — {E7E6F031-17CE-4C07-BC86-EABFE594F69C} — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O3 — Toolbar: &Google — {2318C2B1-4965-11d4-9B18-009027A5CD4F} — c:program filesgooglegoogletoolbar1.dll
O4 — HKLM..Run: [AVP] «C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe»
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:windowssystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:windowssystem32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 — HKLM..Run: [SunJavaUpdateSched] «C:Program FilesJavajre6binjusched.exe»
O4 — HKCU..Run: [ctfmon.exe] C:windowssystem32ctfmon.exe
O4 — HKCU..Run: [CursorXP] C:Program FilesCursorXPCursorXP.exe
O4 — HKCU..Run: [TBPanel] C:Program FilesVtuneTBPanel.exe /A
O4 — HKCU..Run: [DAEMON Tools Lite] «D:InstallDAEMON Tools Litedaemon.exe» -autorun
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O8 — Extra context menu item: E&xport to Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O8 — Extra context menu item: Translate with ABBYY &Lingvo — res://D:InstallABBYY Lingvo 11 Six LanguagesLingvo.exe/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — D:InstallDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — D:InstallDownload Masterdmie.htm
O9 — Extra button: Cтатистика Веб-Антивируса — {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0SCIEPlgn.dll
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — shell32.dll (file missing)
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — shell32.dll (file missing)
O9 — Extra button: Skype — {77BF5300-1474-4EC7-9980-D32B190E9B07} — shell32.dll (file missing)
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — D:InstallDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — D:InstallDownload Masterdmaster.exe
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 — Extra button: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — D:InstallICQ6.5ICQ.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — D:InstallICQ6.5ICQ.exe (file missing)
O9 — Extra button: Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O9 — Extra ‘Tools’ menuitem: Windows Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O17 — HKLMSystemCCSServicesTcpip..{5336BB58-E4F9-4CDE-9EDF-B5A47F332542}: NameServer = 192.168.36.1,217.73.142.1
O17 — HKLMSystemCCSServicesTcpip..{F3831A1A-2577-46B5-A8E0-E6C28F20D174}: NameServer = 217.73.142.1 87.238.159.160
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:PROGRA~1MICROS~2Office12GR99D3~1.DLL
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Adobe LM Service — Unknown owner — C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 — Service: Kaspersky Anti-Virus 7.0 (AVP) — Kaspersky Lab — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:windowssystem32services.exe
O23 — Service: Google Updater Service (gusvc) — Google — C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Macrovision Corporation — C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Java Quick Starter (JavaQuickStarterService) — Sun Microsystems, Inc. — C:Program FilesJavajre6binjqs.exe
O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
O23 — Service: NBService — Nero AG — C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:windowssystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:windowssystem32services.exe
O23 — Service: Two Worlds Drivers Auto Removal (pr2ak9jb) (pr2ak9jb) — Akella — C:windowssystem32pr2ak9jb.exe
O23 — Service: Wildlife Park 2 AddOn2 Horses Drivers Auto Removal (pr2aluab) (pr2aluab) — Koch Media — C:windowssystem32pr2aluab.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:windowsSystem32SCardSvr.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:windowssystem32smlogsvc.exe
O23 — Service: CLCV0 (UTSCSI) — Unknown owner — C:windowssystem32UTSCSI.EXE
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:windowsSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe
O24 — Desktop Component 1: Aqua Real — 7db39a0d-580f-4be9-9195-8bfcd226f6c2—
End of file — 8420 bytes======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll [2004-12-14 63136][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll [2008-11-07 1088296][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-26 2210608][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper — C:Program FilesJavajre6binssv.dll [2009-01-17 320920][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — D:InstallDOWNLO~1dmiehlp.dll [2008-10-24 157696][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper — c:program filesgooglegoogletoolbar1.dll [2008-11-12 2427968][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2009-01-17 34816][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2009-01-17 73728][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} — &Google — c:program filesgooglegoogletoolbar1.dll [2008-11-12 2427968][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«»= []
«AVP»=C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
«NvCplDaemon»=C:windowssystem32NvCpl.dll [2008-06-25 13529088]
«nwiz»=nwiz.exe /install []
«NvMediaCenter»=C:windowssystem32NvMcTray.dll [2008-06-25 86016]
«KernelFaultCheck»=C:windowssystem32dumprep 0 -k []
«SunJavaUpdateSched»=C:Program FilesJavajre6binjusched.exe [2009-01-17 136600][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«ctfmon.exe»=C:windowssystem32ctfmon.exe [2006-03-02 15360]
«CursorXP»=C:Program FilesCursorXPCursorXP.exe [2005-01-19 140288]
«TBPanel»=C:Program FilesVtuneTBPanel.exe [2008-07-10 2154496]
«DAEMON Tools Lite»=D:InstallDAEMON Tools Litedaemon.exe [2008-02-14 486856][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Photo Downloader]
C:Program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe [2005-06-06 57344][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAVG7_CC]
C:PROGRA~1GrisoftAVGFRE~1avgcc.exe /STARTUP [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:Program FilesCommon FilesAheadLibNMBgMonitor.exe [2006-11-16 139264][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBootSkin Startup Jobs]
C:PROGRA~1StardockWINCUS~1BootSkinBootSkin.exe [2004-04-26 270336][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
C:WINDOWSsystem32ctfmon.exe [2006-03-02 15360][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregDAEMON Tools-1033]
D:InstallDRToolsdaemon.exe [2004-08-22 81920][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGlass2k]
C:Program FilesGlass2kGlass2k.exe [2003-12-12 56325][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGrooveMonitor]
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe [2006-10-26 31016][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregICQ]
D:InstallICQ6.5ICQ.exe silent [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLingvo Launcher]
D:InstallABBYY Lingvo 11 Six LanguagesLvagent.exe [2005-09-01 106496][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLingvoTraining]
D:InstallABBYY Lingvo 11 Six LanguagesTutor.exe [2005-09-01 1282048][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogonStudio]
C:Program FilesWinCustomizeLogonStudiologonstudio.exe [2002-09-03 987187][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
C:Program FilesCommon FilesAheadLibNeroCheck.exe [2006-01-12 155648][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvCplDaemon]
C:WINDOWSsystem32NvCpl.dll [2008-06-25 13529088][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
C:WINDOWSsystem32NvMcTray.dll [2008-06-25 86016][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregnwiz]
nwiz.exe /install [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregQuickTime Task]
C:Program FilesQuickTimeqttask.exe [2007-09-30 155648][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSony Ericsson PC Suite]
C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe [2007-03-28 593920][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMAX]
C:Program FilesAnalog DevicesSoundMAXSmax4.exe [2006-04-10 729088][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMAXPnP]
C:Program FilesAnalog DevicesCoresmax4pnp.exe [2006-05-01 843776][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Adobe Gamma Loader.lnk]
C:PROGRA~1COMMON~1AdobeCALIBR~1ADOBEG~1.EXE [1999-11-04 113664][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Digimax Viewer 2.1.lnk]
D:InstallSamsungDIGIMA~1.1STIMGB~1.EXE [2004-08-20 634880][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyklogon]
C:windowssystem32klogon.dll [2007-06-28 206088][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:windowssystem32WPDShServiceObj.dll [2006-10-18 133632][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-26 2210608][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=36
«NoDriveAutoRun»=FFFFFFFF[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«E:GSC World PublishingS.T.A.L.K.E.RbinXR_3DA.exe»=»E:GSC World PublishingS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«E:GSC World PublishingS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»E:GSC World PublishingS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE»=»C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook»
«C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE»=»C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE:*:Enabled:Microsoft Office Groove»
«C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE»=»C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE:*:Enabled:Microsoft Office OneNote»
«D:SanekGamesUnreal Tournament 2004_1SystemUT2004.exe»=»D:SanekGamesUnreal Tournament 2004_1SystemUT2004.exe:*:Enabled:UT2004»
«D:SanekGamesCShl.exe»=»D:SanekGamesCShl.exe:*:Disabled:Half-Life Launcher»
«D:SanekGamesCShlds.exe»=»D:SanekGamesCShlds.exe:*:Disabled:HLDS Launcher»
«D:SanekGamesCShltv.exe»=»D:SanekGamesCShltv.exe:*:Disabled:HLTV Launcher»
«D:SanekGamesS.T.A.L.K.E.RbinXR_3DA.exe»=»D:SanekGamesS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«D:SanekGamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»D:SanekGamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«D:SanekGamesQuake III Arenaquake3.exe»=»D:SanekGamesQuake III Arenaquake3.exe:*:Disabled:quake3»
«D:GamesS.T.A.L.K.E.RbinXR_3DA.exe»=»D:GamesS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«D:GamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»D:GamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«D:Gamessoldat2dSoldat.exe»=»D:Gamessoldat2dSoldat.exe:*:Disabled:Soldat»
«D:GamesUnrealT3BinariesUT3.exe»=»D:GamesUnrealT3BinariesUT3.exe:*:Disabled:UT3»
«D:SashenkaOldGamesUnreal Tournament 2004SystemUT2004.exe»=»D:SashenkaOldGamesUnreal Tournament 2004SystemUT2004.exe:*:Enabled:UT2004»
«D:GamesLostLost. Остаться в живыхYeti_Final_Win32.exe»=»D:GamesLostLost. Остаться в живыхYeti_Final_Win32.exe:*:Enabled:Lost. Остаться в живых Game»
«D:GamesLostLost. Остаться в живыхgu.exe»=»D:GamesLostLost. Остаться в живыхgu.exe:*:Enabled:Lost. Остаться в живых Updater»
«D:GamesLostLost. Остаться в живыхdetectionLauncher.exe»=»D:GamesLostLost. Остаться в живыхdetectionLauncher.exe:*:Enabled:Lost. Остаться в живых Requirements Tool»
«D:InstallICQ6.5ICQ.exe»=»D:InstallICQ6.5ICQ.exe:*:Enabled:ICQ6»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»
«D:InstalluTorrentuTorrent.exe»=»D:InstalluTorrentuTorrent.exe:*:Enabled:µTorrent»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»======List of files/folders created in the last 1 months======
2009-01-18 23:19:53 —-D—- C:Program FilesMozilla Firefox
2009-01-17 17:14:01 —-N—- C:windowssystem32spmsg.dll
2009-01-17 13:33:59 —-D—- C:windowsSun
2009-01-17 13:11:12 —-A—- C:windowssystem32deploytk.dll
2009-01-17 13:11:11 —-A—- C:windowssystem32javaws.exe
2009-01-17 13:11:11 —-A—- C:windowssystem32javaw.exe
2009-01-17 13:11:09 —-A—- C:windowssystem32java.exe
2009-01-17 13:10:41 —-D—- C:Program FilesJava
2009-01-17 12:54:34 —-D—- C:Documents and Settings1111Application DataSun
2009-01-17 12:22:45 —-D—- C:Documents and Settings1111Application DatauTorrent
2009-01-17 00:00:02 —-D—- C:Program FilesAct-3D
2009-01-16 23:38:51 —-D—- C:Program FilesTale of Tales
2009-01-16 22:57:56 —-D—- C:Program FilesWolfQuest
2009-01-16 21:16:06 —-D—- C:Program Filestrend micro
2009-01-16 21:16:05 —-D—- C:rsit
2009-01-16 20:58:22 —-A—- C:avenger.txt
2009-01-16 20:32:21 —-RASHD—- C:autorun.inf
2009-01-16 19:53:03 —-D—- C:Program FilesEnigma Software Group
2009-01-16 14:49:55 —-D—- C:Documents and Settings1111Application DataMalwarebytes
2009-01-16 14:49:50 —-D—- C:Documents and SettingsAll UsersApplication DataMalwarebytes
2009-01-16 14:46:48 —-D—- C:Avenger
2009-01-16 14:44:46 —-A—- C:zip.exe
2009-01-16 14:44:46 —-A—- C:cleanup.exe
2009-01-16 14:44:46 —-A—- C:cleanup.bat
2009-01-16 14:03:45 —-D—- C:Documents and SettingsAll UsersApplication DataAvg7
2009-01-16 11:47:35 —-A—- C:windowsModemLog_PCI SoftV92 Modem.txt
2009-01-12 14:43:14 —-D—- C:Documents and Settings1111Application DataMount&Blade
2008-12-23 01:07:22 —-A—- C:windowsApplian FLV Player Uninstall Log.txt
2008-12-23 00:39:17 —-D—- C:windowsApplian FLV Player
2008-12-23 00:38:26 —-A—- C:windowsApplian FLV Player Setup Log.txt
2008-12-22 13:39:48 —-D—- C:Documents and Settings1111Application DataskypePM======List of files/folders modified in the last 1 months======
2009-01-21 00:39:50 —-D—- C:windowsPrefetch
2009-01-21 00:38:02 —-D—- C:windowsTemp
2009-01-21 00:36:36 —-D—- C:windowssystem32CatRoot2
2009-01-21 00:36:36 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab
2009-01-21 00:34:59 —-A—- C:windowsSchedLgU.Txt
2009-01-21 00:32:26 —-RD—- C:Program Files
2009-01-21 00:32:26 —-D—- C:windowssystem32
2009-01-19 17:58:29 —-A—- C:windowsNeroDigital.ini
2009-01-18 23:20:11 —-D—- C:WINDOWS
2009-01-18 23:20:11 —-D—- C:Documents and Settings1111Application DataMozilla
2009-01-18 02:57:51 —-D—- C:windowssystem32DirectX
2009-01-18 02:57:46 —-HD—- C:windowsinf
2009-01-18 02:51:46 —-HD—- C:Program FilesInstallShield Installation Information
2009-01-17 17:14:21 —-D—- C:windowssystem32CatRoot
2009-01-17 17:14:01 —-RSHDC—- C:windowssystem32dllcache
2009-01-17 15:46:17 —-SHD—- C:windowsInstaller
2009-01-17 15:46:17 —-D—- C:windowsWinSxS
2009-01-16 20:58:22 —-D—- C:windowssystem32drivers
2009-01-16 20:00:49 —-D—- C:windowssystem32Restore
2009-01-16 14:03:43 —-D—- C:windowssystem
2009-01-16 13:45:54 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab Setup Files
2009-01-16 12:18:14 —-A—- C:windowswin.ini
2009-01-03 01:26:04 —-D—- C:windowsMinidump
2008-12-23 01:04:58 —-D—- C:Documents and Settings1111Application DataSkype======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Драйвер Intel процессора; C:windowssystem32DRIVERSintelppm.sys [2006-03-02 40448]
R1 klif;Klif; ??C:windowssystem32driversklif.sys []
R1 prodrv05;StarForce Protection Environment Driver v5; C:windowsSystem32driversprodrv05.sys [2002-11-22 76704]
R2 mdmxsdk;mdmxsdk; C:windowssystem32DRIVERSmdmxsdk.sys [2004-03-17 13059]
R2 TBPanel;TBPanel; C:windowssystem32driversTBPanel.sys [2007-03-16 12256]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:windowssystem32driversADIHdAud.sys [2006-05-02 229376]
R3 AEAudio;AE Audio Service; C:windowssystem32driversAEAudio.sys [2006-04-27 93824]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:windowssystem32DRIVERSHDAudBus.sys [2004-10-27 138240]
R3 HSF_DP;HSF_DP; C:windowssystem32DRIVERSHSF_DP.sys [2004-09-29 1036928]
R3 HSFHWBS2;HSFHWBS2; C:windowssystem32DRIVERSHSFHWBS2.sys [2004-09-29 219136]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:windowssystem32DRIVERSklim5.sys [2007-04-04 24344]
R3 MODEMCSA;Устройство фильтрации потока Unimodem; C:windowssystem32driversMODEMCSA.sys [2001-08-17 16128]
R3 MTsensor;ATK0110 ACPI UTILITY; C:windowssystem32DRIVERSASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:windowssystem32DRIVERSnv4_mini.sys [2008-06-25 6555168]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:windowssystem32DRIVERSRtenicxp.sys [2006-07-27 83712]
R3 SenFiltService;SenFilt Service; C:windowssystem32driversSenfilt.sys [2006-03-17 392960]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:windowssystem32DRIVERSusbehci.sys [2004-08-03 26624]
R3 usbhub;Драйвер стандартного концентратора USB (Microsoft); C:windowssystem32DRIVERSusbhub.sys [2004-08-03 57600]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:windowssystem32DRIVERSusbuhci.sys [2004-08-03 20480]
R3 winachsf;winachsf; C:windowssystem32DRIVERSHSF_CNXT.sys [2004-09-29 702592]
S3 a1rzu6l5;a1rzu6l5; C:windowssystem32driversa1rzu6l5.sys []
S3 Cardex;Cardex; ??C:windowssystem32driversTBPANEL.SYS []
S3 PciCon;PciCon; ??D:PciCon.sys []
S3 se58bus;Sony Ericsson Device 088 driver (WDM); C:windowssystem32DRIVERSse58bus.sys [2006-09-05 61536]
S3 se58mdfl;Sony Ericsson Device 088 USB WMC Modem Filter; C:windowssystem32DRIVERSse58mdfl.sys [2006-09-05 9360]
S3 se58mdm;Sony Ericsson Device 088 USB WMC Modem Driver; C:windowssystem32DRIVERSse58mdm.sys [2006-09-05 97088]
S3 se58mgmt;Sony Ericsson Device 088 USB WMC Device Management Drivers (WDM); C:windowssystem32DRIVERSse58mgmt.sys [2006-09-05 88624]
S3 se58nd5;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (NDIS); C:windowssystem32DRIVERSse58nd5.sys [2006-09-05 18704]
S3 se58obex;Sony Ericsson Device 088 USB WMC OBEX Interface; C:windowssystem32DRIVERSse58obex.sys [2006-09-05 86432]
S3 se58unic;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (WDM); C:windowssystem32DRIVERSse58unic.sys [2006-09-05 90800]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:windowssystem32DRIVERSUSBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:windowssystem32DRIVERSWudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:windowssystem32DRIVERSwudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:windowssystem32driversIntelIde.sys []======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Kaspersky Anti-Virus 7.0; C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
R2 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2009-01-17 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:windowssystem32nvsvc32.exe [2008-06-25 159812]
S2 pr2ak9jb;Two Worlds Drivers Auto Removal (pr2ak9jb); C:windowssystem32pr2ak9jb.exe [2007-05-19 407160]
S2 pr2aluab;Wildlife Park 2 AddOn2 Horses Drivers Auto Removal (pr2aluab); C:windowssystem32pr2aluab.exe [2008-04-09 411032]
S2 UTSCSI;CLCV0; C:windowssystem32UTSCSI.EXE []
S3 Adobe LM Service;Adobe LM Service; C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe [2007-06-03 68096]
S3 aspnet_state;ASP.NET State Service; C:windowsMicrosoft.NETFrameworkv1.1.4322aspnet_state.exe [2003-02-21 32768]
S3 gusvc;Google Updater Service; C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe [2008-11-12 138168]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe [2005-11-14 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2006-10-26 65824]
S3 NBService;NBService; C:Program FilesNeroNero 7Nero BackItUpNBService.exe [2006-11-10 774144]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Служба общих сетевых ресурсов проигрывателя Windows Media; C:Program FilesWindows Media PlayerWMPNetwk.exe [2006-11-02 914944]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:windowssystem32svchost.exe [2006-03-02 14336]
EOF
22 января, 2009 в 11:54 дп #21273Нужно ещё немножко подчистить компьютер.
Запустите HijackThis. Для этого кликните Пуск, Выполнить, введите C:Program Filestrend micro1111.exe и нажмите Enter.
Кликните по кнопке Do a system scan only.
Далее отметьте галочкой (слева) следующую строку:R3 - URLSearchHook: (no name) - - shell32.dll (file missing)
Кликните по кнопке Fix checked и подтвердите свои действия выбрав YES.
Перезагрузите компьютер.Сообщите как работает компьютер.
30 января, 2009 в 9:12 дп #21274Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Спасибо большое! Я почистила, Антивирус пока не появлялся! Но вот станная вещь: когда я нахожусь в Internet Explorer, указатель мыши какой-то нестабильный. Он постоянно исчезает на доли секунды, потом опять появляется, особенно в нижней части экрана. Похоже на дрожь. Это случилось вроде бы после HijackThis. Причем в Opera или на рабочем столе — ничего подобного. Может вы сталкивались с таким. Но все равно, огромное спасибо!!!
30 января, 2009 в 4:17 пп #21275Нет, с таким странным поведением курсора я не сталкивался.
Пожалуйста просканируйте компьютер с помощью RSIT и получившийся лог вставьте в ваше следующее сообщение.3 февраля, 2009 в 5:08 дп #21276Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Вот log:
Logfile of random’s system information tool 1.05 (written by random/random)
Run by 1111 at 2009-02-03 07:02:19
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 62 GB (78%) free of 80 GB
Total RAM: 1023 MB (60% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:02:25, on 03.02.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: NormalRunning processes:
C:windowsSystem32smss.exe
C:windowssystem32winlogon.exe
C:windowssystem32services.exe
C:windowssystem32lsass.exe
C:windowssystem32svchost.exe
C:windowsSystem32svchost.exe
C:windowssystem32spoolsv.exe
C:windowsExplorer.EXE
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:windowssystem32RUNDLL32.EXE
C:Program FilesJavajre6binjusched.exe
C:windowssystem32ctfmon.exe
C:Program FilesCursorXPCursorXP.exe
C:Program FilesVtuneTBPanel.exe
D:InstallDAEMON Tools Litedaemon.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:Program FilesJavajre6binjqs.exe
C:windowssystem32nvsvc32.exe
D:InstalluTorrentuTorrent.exe
D:InstallDownload Masterdmaster.exe
C:Program FilesOperaOpera.exe
C:Documents and Settings1111Рабочий столRSIT.exe
C:Program Filestrend micro1111.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 — BHO: Skype add-on (mastermind) — {22BF413B-C6D2-4d91-82A9-A0F997BA588C} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL
O2 — BHO: Java(tm) Plug-In SSV Helper — {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} — C:Program FilesJavajre6binssv.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — D:InstallDOWNLO~1dmiehlp.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: JQSIEStartDetectorImpl — {E7E6F031-17CE-4C07-BC86-EABFE594F69C} — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O4 — HKLM..Run: [AVP] «C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe»
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:windowssystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:windowssystem32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 — HKLM..Run: [SunJavaUpdateSched] «C:Program FilesJavajre6binjusched.exe»
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeqttask.exe» -atboottime
O4 — HKCU..Run: [ctfmon.exe] C:windowssystem32ctfmon.exe
O4 — HKCU..Run: [CursorXP] C:Program FilesCursorXPCursorXP.exe
O4 — HKCU..Run: [TBPanel] C:Program FilesVtuneTBPanel.exe /A
O4 — HKCU..Run: [DAEMON Tools Lite] «D:InstallDAEMON Tools Litedaemon.exe» -autorun
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O8 — Extra context menu item: E&xport to Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O8 — Extra context menu item: Translate with ABBYY &Lingvo — res://D:InstallABBYY Lingvo 11 Six LanguagesLingvo.exe/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — D:InstallDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — D:InstallDownload Masterdmie.htm
O9 — Extra button: Cтатистика Веб-Антивируса — {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0SCIEPlgn.dll
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — shell32.dll (file missing)
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — shell32.dll (file missing)
O9 — Extra button: Skype — {77BF5300-1474-4EC7-9980-D32B190E9B07} — shell32.dll (file missing)
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — D:InstallDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — D:InstallDownload Masterdmaster.exe
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 — Extra button: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — D:InstallICQ6.5ICQ.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — D:InstallICQ6.5ICQ.exe (file missing)
O9 — Extra button: Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O9 — Extra ‘Tools’ menuitem: Windows Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O17 — HKLMSystemCCSServicesTcpip..{5336BB58-E4F9-4CDE-9EDF-B5A47F332542}: NameServer = 192.168.36.1,217.73.142.1
O17 — HKLMSystemCCSServicesTcpip..{F3831A1A-2577-46B5-A8E0-E6C28F20D174}: NameServer = 217.73.142.1 217.117.64.1
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:PROGRA~1MICROS~2Office12GR99D3~1.DLL
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Adobe LM Service — Unknown owner — C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 — Service: Kaspersky Anti-Virus 7.0 (AVP) — Kaspersky Lab — C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:windowssystem32services.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Macrovision Corporation — C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Java Quick Starter (JavaQuickStarterService) — Sun Microsystems, Inc. — C:Program FilesJavajre6binjqs.exe
O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
O23 — Service: NBService — Nero AG — C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:windowssystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:windowssystem32services.exe
O23 — Service: Two Worlds Drivers Auto Removal (pr2ak9jb) (pr2ak9jb) — Akella — C:windowssystem32pr2ak9jb.exe
O23 — Service: Wildlife Park 2 AddOn2 Horses Drivers Auto Removal (pr2aluab) (pr2aluab) — Koch Media — C:windowssystem32pr2aluab.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:windowsSystem32SCardSvr.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:windowssystem32smlogsvc.exe
O23 — Service: CLCV0 (UTSCSI) — Unknown owner — C:windowssystem32UTSCSI.EXE
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:windowsSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe
O24 — Desktop Component 1: Aqua Real — 7db39a0d-580f-4be9-9195-8bfcd226f6c2—
End of file — 8127 bytes======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll [2004-12-14 63136][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll [2008-11-07 1088296][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-26 2210608][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper — C:Program FilesJavajre6binssv.dll [2009-01-17 320920][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — D:InstallDOWNLO~1dmiehlp.dll [2008-10-24 157696][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2009-01-17 34816][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2009-01-17 73728][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«»= []
«AVP»=C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
«NvCplDaemon»=C:windowssystem32NvCpl.dll [2008-06-25 13529088]
«nwiz»=nwiz.exe /install []
«NvMediaCenter»=C:windowssystem32NvMcTray.dll [2008-06-25 86016]
«KernelFaultCheck»=C:windowssystem32dumprep 0 -k []
«SunJavaUpdateSched»=C:Program FilesJavajre6binjusched.exe [2009-01-17 136600]
«QuickTime Task»=C:Program FilesQuickTimeqttask.exe [2007-09-30 155648][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«ctfmon.exe»=C:windowssystem32ctfmon.exe [2006-03-02 15360]
«CursorXP»=C:Program FilesCursorXPCursorXP.exe [2005-01-19 140288]
«TBPanel»=C:Program FilesVtuneTBPanel.exe [2008-07-10 2154496]
«DAEMON Tools Lite»=D:InstallDAEMON Tools Litedaemon.exe [2008-02-14 486856][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Photo Downloader]
C:Program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe [2005-06-06 57344][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAVG7_CC]
C:PROGRA~1GrisoftAVGFRE~1avgcc.exe /STARTUP [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:Program FilesCommon FilesAheadLibNMBgMonitor.exe [2006-11-16 139264][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBootSkin Startup Jobs]
C:PROGRA~1StardockWINCUS~1BootSkinBootSkin.exe [2004-04-26 270336][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
C:WINDOWSsystem32ctfmon.exe [2006-03-02 15360][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregDAEMON Tools-1033]
D:InstallDRToolsdaemon.exe [2004-08-22 81920][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGlass2k]
C:Program FilesGlass2kGlass2k.exe [2003-12-12 56325][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGrooveMonitor]
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe [2006-10-26 31016][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregICQ]
D:InstallICQ6.5ICQ.exe silent [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLingvo Launcher]
D:InstallABBYY Lingvo 11 Six LanguagesLvagent.exe [2005-09-01 106496][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLingvoTraining]
D:InstallABBYY Lingvo 11 Six LanguagesTutor.exe [2005-09-01 1282048][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogonStudio]
C:Program FilesWinCustomizeLogonStudiologonstudio.exe [2002-09-03 987187][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
C:Program FilesCommon FilesAheadLibNeroCheck.exe [2006-01-12 155648][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvCplDaemon]
C:WINDOWSsystem32NvCpl.dll [2008-06-25 13529088][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
C:WINDOWSsystem32NvMcTray.dll [2008-06-25 86016][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregnwiz]
nwiz.exe /install [][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregQuickTime Task]
C:Program FilesQuickTimeqttask.exe [2007-09-30 155648][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSony Ericsson PC Suite]
C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe [2007-03-28 593920][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMAX]
C:Program FilesAnalog DevicesSoundMAXSmax4.exe [2006-04-10 729088][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMAXPnP]
C:Program FilesAnalog DevicesCoresmax4pnp.exe [2006-05-01 843776][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Adobe Gamma Loader.lnk]
C:PROGRA~1COMMON~1AdobeCALIBR~1ADOBEG~1.EXE [1999-11-04 113664][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Digimax Viewer 2.1.lnk]
D:InstallSamsungDIGIMA~1.1STIMGB~1.EXE [2004-08-20 634880][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyklogon]
C:windowssystem32klogon.dll [2007-06-28 206088][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:windowssystem32WPDShServiceObj.dll [2006-10-18 133632][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-26 2210608][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=36
«NoDriveAutoRun»=FFFFFFFF[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«E:GSC World PublishingS.T.A.L.K.E.RbinXR_3DA.exe»=»E:GSC World PublishingS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«E:GSC World PublishingS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»E:GSC World PublishingS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE»=»C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook»
«C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE»=»C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE:*:Enabled:Microsoft Office Groove»
«C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE»=»C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE:*:Enabled:Microsoft Office OneNote»
«D:SanekGamesUnreal Tournament 2004_1SystemUT2004.exe»=»D:SanekGamesUnreal Tournament 2004_1SystemUT2004.exe:*:Enabled:UT2004»
«D:SanekGamesCShl.exe»=»D:SanekGamesCShl.exe:*:Disabled:Half-Life Launcher»
«D:SanekGamesCShlds.exe»=»D:SanekGamesCShlds.exe:*:Disabled:HLDS Launcher»
«D:SanekGamesCShltv.exe»=»D:SanekGamesCShltv.exe:*:Disabled:HLTV Launcher»
«D:SanekGamesS.T.A.L.K.E.RbinXR_3DA.exe»=»D:SanekGamesS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«D:SanekGamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»D:SanekGamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«D:SanekGamesQuake III Arenaquake3.exe»=»D:SanekGamesQuake III Arenaquake3.exe:*:Disabled:quake3»
«D:GamesS.T.A.L.K.E.RbinXR_3DA.exe»=»D:GamesS.T.A.L.K.E.RbinXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (CLI)»
«D:GamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe»=»D:GamesS.T.A.L.K.E.RbindedicatedXR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. (SRV)»
«D:Gamessoldat2dSoldat.exe»=»D:Gamessoldat2dSoldat.exe:*:Disabled:Soldat»
«D:GamesUnrealT3BinariesUT3.exe»=»D:GamesUnrealT3BinariesUT3.exe:*:Disabled:UT3»
«D:SashenkaOldGamesUnreal Tournament 2004SystemUT2004.exe»=»D:SashenkaOldGamesUnreal Tournament 2004SystemUT2004.exe:*:Enabled:UT2004»
«D:InstallICQ6.5ICQ.exe»=»D:InstallICQ6.5ICQ.exe:*:Enabled:ICQ6»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»
«D:InstalluTorrentuTorrent.exe»=»D:InstalluTorrentuTorrent.exe:*:Enabled:µTorrent»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»======List of files/folders created in the last 1 months======
2009-01-30 15:20:59 —-A—- C:windowsAssassin’s Creed Director’s Cut Edition Final to Rus Patch Patch Log.txt
2009-01-24 02:15:43 —-D—- C:Documents and Settings1111Application DataUbisoft
2009-01-21 14:46:54 —-D—- C:Documents and SettingsAll UsersApplication DataMy Horse and Me
2009-01-21 11:53:10 —-A—- C:Info.txt
2009-01-18 23:19:53 —-D—- C:Program FilesMozilla Firefox
2009-01-17 17:14:01 —-N—- C:windowssystem32spmsg.dll
2009-01-17 13:33:59 —-D—- C:windowsSun
2009-01-17 13:11:12 —-A—- C:windowssystem32deploytk.dll
2009-01-17 13:11:11 —-A—- C:windowssystem32javaws.exe
2009-01-17 13:11:11 —-A—- C:windowssystem32javaw.exe
2009-01-17 13:11:09 —-A—- C:windowssystem32java.exe
2009-01-17 13:10:41 —-D—- C:Program FilesJava
2009-01-17 12:54:34 —-D—- C:Documents and Settings1111Application DataSun
2009-01-17 12:22:45 —-D—- C:Documents and Settings1111Application DatauTorrent
2009-01-17 00:00:02 —-D—- C:Program FilesAct-3D
2009-01-16 23:38:51 —-D—- C:Program FilesTale of Tales
2009-01-16 22:57:56 —-D—- C:Program FilesWolfQuest
2009-01-16 21:16:06 —-D—- C:Program Filestrend micro
2009-01-16 21:16:05 —-D—- C:rsit
2009-01-16 20:58:22 —-A—- C:avenger.txt
2009-01-16 20:32:21 —-RASHD—- C:autorun.inf
2009-01-16 19:53:03 —-D—- C:Program FilesEnigma Software Group
2009-01-16 14:49:55 —-D—- C:Documents and Settings1111Application DataMalwarebytes
2009-01-16 14:49:50 —-D—- C:Documents and SettingsAll UsersApplication DataMalwarebytes
2009-01-16 14:46:48 —-D—- C:Avenger
2009-01-16 14:44:46 —-A—- C:zip.exe
2009-01-16 14:44:46 —-A—- C:cleanup.exe
2009-01-16 14:44:46 —-A—- C:cleanup.bat
2009-01-16 14:03:45 —-D—- C:Documents and SettingsAll UsersApplication DataAvg7
2009-01-16 11:47:35 —-A—- C:windowsModemLog_PCI SoftV92 Modem.txt
2009-01-12 14:43:14 —-D—- C:Documents and Settings1111Application DataMount&Blade======List of files/folders modified in the last 1 months======
2009-02-03 07:02:20 —-D—- C:windowsPrefetch
2009-02-03 07:01:52 —-D—- C:windowsTemp
2009-02-03 00:02:02 —-A—- C:windowswin.ini
2009-02-02 18:01:55 —-A—- C:windowsNeroDigital.ini
2009-02-02 13:53:16 —-D—- C:windowssystem32CatRoot2
2009-02-02 13:53:15 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab
2009-02-02 01:13:41 —-A—- C:windowsSchedLgU.Txt
2009-02-01 03:31:37 —-A—- C:windowsBlendSettings.ini
2009-01-31 22:15:14 —-HD—- C:Program FilesInstallShield Installation Information
2009-01-30 15:20:59 —-D—- C:WINDOWS
2009-01-22 11:40:07 —-D—- C:Program FilesGoogle
2009-01-22 03:26:33 —-D—- C:windowssystem32
2009-01-22 03:04:32 —-SHD—- C:windowsInstaller
2009-01-22 03:04:30 —-D—- C:Documents and SettingsAll UsersApplication DataGoogle
2009-01-21 14:05:08 —-RD—- C:Program Files
2009-01-21 13:39:41 —-D—- C:windowssystem32DirectX
2009-01-21 11:53:08 —-D—- C:windowssystem32drivers
2009-01-21 11:43:10 —-HD—- C:windowsinf
2009-01-18 23:20:11 —-D—- C:Documents and Settings1111Application DataMozilla
2009-01-17 17:14:21 —-D—- C:windowssystem32CatRoot
2009-01-17 17:14:01 —-RSHDC—- C:windowssystem32dllcache
2009-01-17 15:46:17 —-D—- C:windowsWinSxS
2009-01-16 20:00:49 —-D—- C:windowssystem32Restore
2009-01-16 14:03:43 —-D—- C:windowssystem
2009-01-16 13:45:54 —-D—- C:Documents and SettingsAll UsersApplication DataKaspersky Lab Setup Files======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Драйвер Intel процессора; C:windowssystem32DRIVERSintelppm.sys [2006-03-02 40448]
R1 klif;Klif; ??C:windowssystem32driversklif.sys []
R1 prodrv05;StarForce Protection Environment Driver v5; C:windowsSystem32driversprodrv05.sys [2002-11-22 76704]
R2 atksgt;atksgt; C:windowssystem32DRIVERSatksgt.sys [2009-01-21 278984]
R2 lirsgt;lirsgt; C:windowssystem32DRIVERSlirsgt.sys [2009-01-21 25416]
R2 mdmxsdk;mdmxsdk; C:windowssystem32DRIVERSmdmxsdk.sys [2004-03-17 13059]
R2 TBPanel;TBPanel; C:windowssystem32driversTBPanel.sys [2007-03-16 12256]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:windowssystem32driversADIHdAud.sys [2006-05-02 229376]
R3 AEAudio;AE Audio Service; C:windowssystem32driversAEAudio.sys [2006-04-27 93824]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:windowssystem32DRIVERSHDAudBus.sys [2004-10-27 138240]
R3 HSF_DP;HSF_DP; C:windowssystem32DRIVERSHSF_DP.sys [2004-09-29 1036928]
R3 HSFHWBS2;HSFHWBS2; C:windowssystem32DRIVERSHSFHWBS2.sys [2004-09-29 219136]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:windowssystem32DRIVERSklim5.sys [2007-04-04 24344]
R3 MODEMCSA;Устройство фильтрации потока Unimodem; C:windowssystem32driversMODEMCSA.sys [2001-08-17 16128]
R3 MTsensor;ATK0110 ACPI UTILITY; C:windowssystem32DRIVERSASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:windowssystem32DRIVERSnv4_mini.sys [2008-06-25 6555168]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:windowssystem32DRIVERSRtenicxp.sys [2006-07-27 83712]
R3 SenFiltService;SenFilt Service; C:windowssystem32driversSenfilt.sys [2006-03-17 392960]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:windowssystem32DRIVERSusbehci.sys [2004-08-03 26624]
R3 usbhub;Драйвер стандартного концентратора USB (Microsoft); C:windowssystem32DRIVERSusbhub.sys [2004-08-03 57600]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:windowssystem32DRIVERSusbuhci.sys [2004-08-03 20480]
R3 winachsf;winachsf; C:windowssystem32DRIVERSHSF_CNXT.sys [2004-09-29 702592]
S3 a28bpn7c;a28bpn7c; C:windowssystem32driversa28bpn7c.sys []
S3 Cardex;Cardex; ??C:windowssystem32driversTBPANEL.SYS []
S3 PciCon;PciCon; ??D:PciCon.sys []
S3 se58bus;Sony Ericsson Device 088 driver (WDM); C:windowssystem32DRIVERSse58bus.sys [2006-09-05 61536]
S3 se58mdfl;Sony Ericsson Device 088 USB WMC Modem Filter; C:windowssystem32DRIVERSse58mdfl.sys [2006-09-05 9360]
S3 se58mdm;Sony Ericsson Device 088 USB WMC Modem Driver; C:windowssystem32DRIVERSse58mdm.sys [2006-09-05 97088]
S3 se58mgmt;Sony Ericsson Device 088 USB WMC Device Management Drivers (WDM); C:windowssystem32DRIVERSse58mgmt.sys [2006-09-05 88624]
S3 se58nd5;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (NDIS); C:windowssystem32DRIVERSse58nd5.sys [2006-09-05 18704]
S3 se58obex;Sony Ericsson Device 088 USB WMC OBEX Interface; C:windowssystem32DRIVERSse58obex.sys [2006-09-05 86432]
S3 se58unic;Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (WDM); C:windowssystem32DRIVERSse58unic.sys [2006-09-05 90800]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:windowssystem32DRIVERSUSBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:windowssystem32DRIVERSWudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:windowssystem32DRIVERSwudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:windowssystem32driversIntelIde.sys []======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVP;Kaspersky Anti-Virus 7.0; C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe [2007-06-28 218376]
R2 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2009-01-17 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:windowssystem32nvsvc32.exe [2008-06-25 159812]
S2 pr2ak9jb;Two Worlds Drivers Auto Removal (pr2ak9jb); C:windowssystem32pr2ak9jb.exe [2007-05-19 407160]
S2 pr2aluab;Wildlife Park 2 AddOn2 Horses Drivers Auto Removal (pr2aluab); C:windowssystem32pr2aluab.exe [2008-04-09 411032]
S2 UTSCSI;CLCV0; C:windowssystem32UTSCSI.EXE []
S3 Adobe LM Service;Adobe LM Service; C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe [2007-06-03 68096]
S3 aspnet_state;ASP.NET State Service; C:windowsMicrosoft.NETFrameworkv1.1.4322aspnet_state.exe [2003-02-21 32768]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe [2005-11-14 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2006-10-26 65824]
S3 NBService;NBService; C:Program FilesNeroNero 7Nero BackItUpNBService.exe [2006-11-10 774144]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Служба общих сетевых ресурсов проигрывателя Windows Media; C:Program FilesWindows Media PlayerWMPNetwk.exe [2006-11-02 914944]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:windowssystem32svchost.exe [2006-03-02 14336]
EOF
6 февраля, 2009 в 3:51 пп #21277RSIT лог выглдяит нормально, дрожаший курсор появляется исключительно в IE ?
-
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.