Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Trojan.pandex + офигенные тормоза
- This topic has 1 ответ, 2 участника, and was last updated 16 years, 2 months назад by
Admin.
-
АвторСообщения
-
26 февраля, 2009 в 1:53 пп #16341
Добрый день!
Буду вам очень признателен, если поможете!
проблема заключаетя в следующем: «балбес я» 🙂
недавно пришло письмо на мэйл в котором был файл SMS.exe, и я с дуру, видимо не в себе был 🙂 скачал и запустил его, хотя никогда в жизни такие письма даже не открывал и удалял. после чего этот файл исчез и тут началось… антивирус Symantec начал получать или сканировать постоянно приходящие сообщения и до тех пор пока не выключишь сеть, они все валятся и валятся… вобщем дальнейшие действия такие TrojanRemover-ом просканировался и что-то снес и теперь постоянно ругается на файл userinit.exe что мол «не верный размер файла или устаревшая версия», Symantec постоянн ругается на Trojan.pandex и ко всему прочему комп тормозит очень сильно…
ну и логи RSITа:
Logfile of random’s system information tool 1.05 (written by random/random)
Run by AlexeyYB at 2009-02-26 16:19:30
Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (28%) free of 114 GB
Total RAM: 1015 MB (43% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:19:32, on 26.02.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesWIDCOMMBluetooth Softwarebinbtwdins.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAnalog DevicesCoresmax4pnp.exe
C:Program FilesHewlett-PackardHP ProtectTools Security ManagerPTHOSTTR.EXE
C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
C:Program FilesIntelIntel Matrix Storage ManagerIaanotif.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C:WINDOWSsystem32igfxpers.exe
C:WINDOWSsystem32igfxsrvc.exe
C:PROGRA~1CompaqCOMPAQ~1CHKADMIN.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:PROGRA~1SYMANT~1VPTray.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe
C:Program FilesJavajre6binjusched.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceISUSPM.exe
C:WINDOWSsystem32agrsmsvc.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesCompaqCompaq Management Agentscpqalert.exe
C:PROGRA~1CompaqCOMPAQ~1CPQWEB~1WebDmi.exe
C:Program FilesQIP Infiuminfium.exe
C:Program FilesSymantec AntiVirusDefWatch.exe
C:Program FilesDownload Masterdmaster.exe
C:Program FilesIntelIntel Matrix Storage ManagerIaantmon.exe
C:Program FilesMicrosoft Firewall Client 2004FwcMgmt.exe
C:Program FilesCommon FilesInterVideoRegMgriviRegMgr.exe
C:Program FilesJavajre6binjqs.exe
C:Program FilesSymantec AntiVirusSavRoam.exe
C:WINDOWSSystem32snmp.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesSymantec AntiVirusRtvscan.exe
C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe
C:Program FilesCompaqCompaq Management AgentsDmiWin32binWin32sl.exe
C:Program FilesHewlett-PackardSharedhpqwmiex.exe
C:PROGRA~1CompaqCOMPAQ~1cpqdmi.exe
C:Program FilesiPodbiniPodService.exe
C:WINDOWSsystem32wbemwmiapsrv.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe
C:Program FilesHewlett-PackardSharedHpqToaster.exe
C:Program FilesMicrosoft OfficeOFFICE11OUTLOOK.EXE
C:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXE
C:Program FilesInternet Exploreriexplore.exe
C:DownloadsАрхивыRSIT.exe
C:Program FilesTrend MicroHijackThisAlexeyYB.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://optima5:8080/default.aspx
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 — HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigURL = http://optima11.optima.local:8080/array.dll?Get.Routing.Script
R1 — HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.optima.local:8080
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll
O2 — BHO: Java(tm) Plug-In SSV Helper — {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} — C:Program FilesJavajre6binssv.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: JQSIEStartDetectorImpl — {E7E6F031-17CE-4C07-BC86-EABFE594F69C} — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O4 — HKLM..Run: [SoundMAXPnP] C:Program FilesAnalog DevicesCoresmax4pnp.exe
O4 — HKLM..Run: [SoundMAX] C:Program FilesAnalog DevicesSoundMAXSmax4.exe /tray
O4 — HKLM..Run: [PTHOSTTR] C:Program FilesHewlett-PackardHP ProtectTools Security ManagerPTHOSTTR.EXE /Start
O4 — HKLM..Run: [hpWirelessAssistant] %ProgramFiles%Hewlett-PackardHP Wireless AssistantHPWAMain.exe
O4 — HKLM..Run: [IAAnotif] «C:Program FilesIntelIntel Matrix Storage ManagerIaanotif.exe»
O4 — HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 — HKLM..Run: [QlbCtrl.exe] C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe /Start
O4 — HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 — HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 — HKLM..Run: [Persistence] C:WINDOWSsystem32igfxpers.exe
O4 — HKLM..Run: [ChkAdmin] C:PROGRA~1CompaqCOMPAQ~1CHKADMIN.EXE
O4 — HKLM..Run: [ccApp] «C:Program FilesCommon FilesSymantec SharedccApp.exe»
O4 — HKLM..Run: [vptray] C:PROGRA~1SYMANT~1VPTray.exe
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeQTTask.exe» -atboottime
O4 — HKLM..Run: [iTunesHelper] «C:Program FilesiTunesiTunesHelper.exe»
O4 — HKLM..Run: [GrooveMonitor] «C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe»
O4 — HKLM..Run: [SunJavaUpdateSched] «C:Program FilesJavajre6binjusched.exe»
O4 — HKLM..Run: [ISUSPM] «C:Program FilesCommon FilesInstallShieldUpdateServiceISUSPM.exe» -scheduler
O4 — HKLM..Run: [SysSrv] c:windowssystem32svrchost.exe
O4 — HKLM..Run: [UVS10 Preload] C:Program FilesUlead SystemsUlead VideoStudio 10uvPL.exe
O4 — HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 — HKLM..Run: [TrojanScanner] C:Program FilesTrojan RemoverTrjscan.exe /boot
O4 — HKCU..Run: [Infium] «C:Program FilesQIP Infiuminfium.exe»
O4 — HKCU..Run: [Download Master] C:Program FilesDownload Masterdmaster.exe -autorun
O4 — HKLM..PoliciesExplorerRun: [Mpk.exe] C:Program FilesKGBMpk.exe
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — Global Startup: Microsoft Firewall Client Management.lnk = C:Program FilesMicrosoft Firewall Client 2004FwcMgmt.exe
O8 — Extra context menu item: &Отправить на устройство Bluetooth… — C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie_ctx.htm
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 — Extra button: @btrez.dll,-4015 — {CCA281CA-C863-46ef-9331-5C8D4460577F} — C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm
O9 — Extra ‘Tools’ menuitem: @btrez.dll,-12650 — {CCA281CA-C863-46ef-9331-5C8D4460577F} — C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra button: Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O9 — Extra ‘Tools’ menuitem: Windows Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O10 — Unknown file in Winsock LSP: c:windowssystem32nwprovau.dll
O14 — IERESET.INF: START_PAGE_URL=http://optima5:8080/default.aspx
O16 — DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) — http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1222955392656
O17 — HKLMSystemCCSServicesTcpipParameters: Domain = optima.local
O17 — HKLMSoftware..Telephony: DomainName = optima.local
O17 — HKLMSystemCS1ServicesTcpipParameters: Domain = optima.local
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:Program FilesMicrosoft OfficeOffice12GrooveSystemServices.dll
O23 — Service: Agere Modem Call Progress Audio (AgereModemAudio) — Agere Systems — C:WINDOWSsystem32agrsmsvc.exe
O23 — Service: Apple Mobile Device — Apple Inc. — C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 — Service: Bonjour Service — Apple Inc. — C:Program FilesBonjourmDNSResponder.exe
O23 — Service: Bluetooth Service (btwdins) — Broadcom Corporation. — C:Program FilesWIDCOMMBluetooth Softwarebinbtwdins.exe
O23 — Service: Symantec Event Manager (ccEvtMgr) — Symantec Corporation — C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 — Service: Symantec Settings Manager (ccSetMgr) — Symantec Corporation — C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 — Service: Com4QLBEx — Hewlett-Packard Development Company, L.P. — C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe
O23 — Service: Insight Local Alerter (CPQALERT) — Hewlett-Packard Company — C:Program FilesCompaqCompaq Management Agentscpqalert.exe
O23 — Service: cpqdmi — Compaq Computer Corporation — C:PROGRA~1CompaqCOMPAQ~1cpqdmi.exe
O23 — Service: Insight Web Agent (cpqWebDmi) — Hewlett-Packard Company — C:PROGRA~1CompaqCOMPAQ~1CPQWEB~1WebDmi.exe
O23 — Service: Symantec AntiVirus Definition Watcher (DefWatch) — Symantec Corporation — C:Program FilesSymantec AntiVirusDefWatch.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: hpqwmiex — Hewlett-Packard Development Company, L.P. — C:Program FilesHewlett-PackardSharedhpqwmiex.exe
O23 — Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) — Intel Corporation — C:Program FilesIntelIntel Matrix Storage ManagerIaantmon.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Macrovision Corporation — C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Сервис iPod (iPod Service) — Apple Inc. — C:Program FilesiPodbiniPodService.exe
O23 — Service: IviRegMgr — InterVideo — C:Program FilesCommon FilesInterVideoRegMgriviRegMgr.exe
O23 — Service: Java Quick Starter (JavaQuickStarterService) — Sun Microsystems, Inc. — C:Program FilesJavajre6binjqs.exe
O23 — Service: LiveUpdate — Symantec Corporation — C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: SAVRoam (SavRoam) — symantec — C:Program FilesSymantec AntiVirusSavRoam.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: Symantec Network Drivers Service (SNDSrvc) — Symantec Corporation — C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 — Service: Служба SNMP (SNMP) — Корпорация Майкрософт — C:WINDOWSSystem32snmp.exe
O23 — Service: Symantec SPBBCSvc (SPBBCSvc) — Symantec Corporation — C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 — Service: Symantec AntiVirus — Symantec Corporation — C:Program FilesSymantec AntiVirusRtvscan.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: Ulead Burning Helper (UleadBurningHelper) — Ulead Systems, Inc. — C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Win32Sl (WIN32SL) — Intel — C:Program FilesCompaqCompaq Management AgentsDmiWin32binWin32sl.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe—
End of file — 13407 bytes======Scheduled tasks folder======
C:WINDOWStasksAppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class — C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll [2003-11-04 54248][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll [2007-08-24 2212224][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper — C:Program FilesJavajre6binssv.dll [2009-02-05 320920][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — C:PROGRA~1DOWNLO~1dmiehlp.dll [2008-10-24 157696][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2009-02-05 34816][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2009-02-05 73728][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«SoundMAXPnP»=C:Program FilesAnalog DevicesCoresmax4pnp.exe [2007-01-05 872448]
«SoundMAX»=C:Program FilesAnalog DevicesSoundMAXSmax4.exe [2006-07-13 729088]
«PTHOSTTR»=C:Program FilesHewlett-PackardHP ProtectTools Security ManagerPTHOSTTR.EXE [2007-01-09 145184]
«hpWirelessAssistant»=C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe [2007-05-11 472632]
«IAAnotif»=C:Program FilesIntelIntel Matrix Storage ManagerIaanotif.exe [2007-10-03 178712]
«SynTPEnh»=C:Program FilesSynapticsSynTPSynTPEnh.exe [2008-01-18 1028096]
«QlbCtrl.exe»=C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe [2008-06-03 177456]
«IgfxTray»=C:WINDOWSsystem32igfxtray.exe [2007-09-24 141848]
«HotKeysCmds»=C:WINDOWSsystem32hkcmd.exe [2007-09-24 166424]
«Persistence»=C:WINDOWSsystem32igfxpers.exe [2007-09-24 137752]
«ChkAdmin»=C:PROGRA~1CompaqCOMPAQ~1CHKADMIN.EXE [2004-07-19 81920]
«ccApp»=C:Program FilesCommon FilesSymantec SharedccApp.exe [2006-11-21 52840]
«vptray»=C:PROGRA~1SYMANT~1VPTray.exe [2007-03-14 125632]
«QuickTime Task»=C:Program FilesQuickTimeQTTask.exe [2009-01-05 413696]
«iTunesHelper»=C:Program FilesiTunesiTunesHelper.exe [2009-01-06 290088]
«GrooveMonitor»=C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe [2007-08-24 33648]
«SunJavaUpdateSched»=C:Program FilesJavajre6binjusched.exe [2009-02-05 136600]
«ISUSPM»=C:Program FilesCommon FilesInstallShieldUpdateServiceISUSPM.exe [2006-03-20 213936]
«SysSrv»=c:windowssystem32svrchost.exe []
«UVS10 Preload»=C:Program FilesUlead SystemsUlead VideoStudio 10uvPL.exe [2006-03-07 36864]
«KernelFaultCheck»=C:WINDOWSsystem32dumprep 0 -k []
«TrojanScanner»=C:Program FilesTrojan RemoverTrjscan.exe [2009-02-21 1211784][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRun]
«Mpk.exe»=C:Program FilesKGBMpk.exe [2007-10-09 930304][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«Infium»=C:Program FilesQIP Infiuminfium.exe [2009-02-12 5213184]
«Download Master»=C:Program FilesDownload Masterdmaster.exe [2009-02-06 3769856]C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
Microsoft Firewall Client Management.lnk — C:Program FilesMicrosoft Firewall Client 2004FwcMgmt.exe[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyigfxcui]
C:WINDOWSsystem32igfxdev.dll [2007-09-18 208896][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyNavLogon]
C:WINDOWSsystem32NavLogon.dll [2007-03-14 43712][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll [2007-08-24 2212224][HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa]
«authentication packages»=msv1_0
nwprovau[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati0bjxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati0hoxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati2vdxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati3bixx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati3irxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati3lsxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati3scxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati4eoxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati4tbxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati4vdxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati6cjxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati6wgxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati6xfxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati7ajxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati7ucxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati8cjxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalati8tdxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati0bjxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati0hoxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati2vdxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati3bixx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati3irxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati3lsxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati3scxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati4eoxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati4tbxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati4vdxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati6cjxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati6wgxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati6xfxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati7ajxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati7ucxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati8cjxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkati8tdxx.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworknm]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworknm.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkWdf01000.sys]
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«HideLegacyLogonScripts»=1[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=255
«NoOnlinePrintsWizard»=1[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«HonorAutoRunSetting»=
«NoAutorun»=
«NoDriveTypeAutoRun»=[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«C:Program FilesFlyLinkDC++FlylinkDC.exe»=»C:Program FilesFlyLinkDC++FlylinkDC.exe:*:Enabled:FlyLinkDC++»
«C:Program FilesBonjourmDNSResponder.exe»=»C:Program FilesBonjourmDNSResponder.exe:*:Enabled:Bonjour»
«C:Program FilesKGBMpk.exe»=»C:Program FilesKGBMpk.exe:*:Enabled:TCPIP»
«C:Program FilesKGBMpkView.exe»=»C:Program FilesKGBMpkView.exe:*:Enabled:TCPIP»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«C:Program FilesBonjourmDNSResponder.exe»=»C:Program FilesBonjourmDNSResponder.exe:*:Enabled:Bonjour»
«C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE»=»C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE:*:Enabled:Microsoft Office Groove»
«C:Program FilesiTunesiTunes.exe»=»C:Program FilesiTunesiTunes.exe:*:Enabled:iTunes»
«C:Program FilesWIBUKEYServerWkSvW32.exe»=»C:Program FilesWIBUKEYServerWkSvW32.exe:*:Enabled:WIBU-KEY Network Server»======List of files/folders created in the last 3 months======
2009-02-26 16:19:30 —-D—- C:rsit
2009-02-26 15:51:30 —-D—- C:ca32e7f9a9956d7b5aaf9a
2009-02-26 13:53:23 —-D—- C:Program FilesTrend Micro
2009-02-26 01:47:12 —-A—- C:WINDOWSexpuninst.exe
2009-02-25 10:44:20 —-HDC—- C:WINDOWS$NtUninstallKB967715$
2009-02-23 14:51:12 —-SHD—- C:Program FilesKGB
2009-02-23 14:51:12 —-SHD—- C:Documents and SettingsAll UsersApplication DataMPK
2009-02-23 14:03:26 —-AD—- C:Documents and SettingsAll UsersApplication DataTEMP
2009-02-23 14:02:53 —-A—- C:WINDOWSsystem32ztvunrar36.dll
2009-02-23 14:02:53 —-A—- C:WINDOWSsystem32ztvunace26.dll
2009-02-23 14:02:53 —-A—- C:WINDOWSsystem32ztvcabinet.dll
2009-02-23 14:02:53 —-A—- C:WINDOWSsystem32UNRAR3.dll
2009-02-23 14:02:53 —-A—- C:WINDOWSsystem32unacev2.dll
2009-02-23 14:02:49 —-D—- C:Program FilesTrojan Remover
2009-02-23 14:02:49 —-D—- C:Documents and SettingsAll UsersApplication DataSimply Super Software
2009-02-23 14:02:49 —-D—- C:Documents and SettingsAlexeyYBApplication DataSimply Super Software
2009-02-22 00:42:20 —-D—- C:WINDOWSMinidump
2009-02-21 23:31:15 —-A—- C:WINDOWSsystem32msvcr70.dll
2009-02-21 23:31:15 —-A—- C:WINDOWSsystem32msvcp70.dll
2009-02-21 23:31:14 —-D—- C:Program FilesAML Products
2009-02-21 23:31:14 —-A—- C:WINDOWSsystem32mfc70.dll
2009-02-21 22:02:42 —-A—- C:WINDOWSsystem32rs32net.exe.vir
2009-02-21 17:31:50 —-HD—- C:WINDOWSPIF
2009-02-14 02:01:39 —-D—- C:Program FilesCommon FilesUlead Systems
2009-02-14 01:15:35 —-D—- C:Program FilesArKaos VJ 3.6.1 FC2
2009-02-14 00:16:04 —-D—- C:Program FilesExtra Video Effect Editor
2009-02-14 00:16:04 —-A—- C:WINDOWSsystem32viscomwave.dll
2009-02-14 00:16:04 —-A—- C:WINDOWSsystem32viscomqtenc.dll
2009-02-14 00:16:04 —-A—- C:WINDOWSsystem32viscomqtde.dll
2009-02-14 00:16:04 —-A—- C:WINDOWSsystem32SkinCrafter.dll
2009-02-13 23:36:20 —-D—- C:Documents and SettingsAlexeyYBApplication DataUlead Systems
2009-02-13 23:32:14 —-D—- C:SmartSound Software
2009-02-13 23:31:41 —-D—- C:Documents and SettingsAll UsersApplication DataSmartSound Software Inc
2009-02-13 23:31:40 —-D—- C:Program FilesSmartSound Software
2009-02-13 23:30:29 —-D—- C:Program FilesWindows Media Components
2009-02-13 23:29:24 —-D—- C:Program FilesUlead Systems
2009-02-13 23:29:24 —-D—- C:Documents and SettingsAll UsersApplication DataUlead Systems
2009-02-13 13:11:33 —-D—- C:Documents and SettingsAlexeyYBApplication Data1C
2009-02-13 13:08:17 —-A—- C:WINDOWSsxlib32full.txt
2009-02-12 16:54:45 —-SHD—- C:WINDOWSexprep
2009-02-11 10:54:01 —-D—- C:Program FilesMSECache
2009-02-10 17:23:51 —-A—- C:WINDOWSsystem32WintSys.dll
2009-02-10 17:23:42 —-D—- C:Documents and SettingsAll UsersApplication Datawinsys
2009-02-09 12:56:27 —-D—- C:Program FilesMSXML 4.0
2009-02-09 00:15:49 —-A—- C:WINDOWSAviSplitter.INI
2009-02-08 21:57:24 —-D—- C:Program FilesXP Codec Pack
2009-02-07 16:49:19 —-D—- C:Documents and SettingsAlexeyYBApplication DataInterVideo
2009-02-07 16:47:23 —-D—- C:Program FilesInterVideo Information Service
2009-02-07 16:47:23 —-D—- C:Program FilesCommon FilesUlead
2009-02-07 16:46:42 —-D—- C:Documents and SettingsAll UsersApplication DataInstallShield
2009-02-07 16:46:08 —-D—- C:Program FilesCommon FilesInterVideo
2009-02-07 16:45:42 —-D—- C:Program FilesInterVideo
2009-02-07 16:32:29 —-A—- C:WINDOWSsystem32d3dx10_40.dll
2009-02-07 16:32:29 —-A—- C:WINDOWSsystem32D3DCompiler_40.dll
2009-02-07 16:32:28 —-A—- C:WINDOWSsystem32D3DX9_40.dll
2009-02-07 16:32:27 —-A—- C:WINDOWSsystem32XAudio2_3.dll
2009-02-07 16:32:27 —-A—- C:WINDOWSsystem32XAPOFX1_2.dll
2009-02-07 16:32:26 —-A—- C:WINDOWSsystem32xactengine3_3.dll
2009-02-07 16:32:26 —-A—- C:WINDOWSsystem32X3DAudio1_5.dll
2009-02-07 16:32:25 —-A—- C:WINDOWSsystem32XAudio2_2.dll
2009-02-07 16:32:25 —-A—- C:WINDOWSsystem32XAPOFX1_1.dll
2009-02-07 16:32:24 —-A—- C:WINDOWSsystem32xactengine3_2.dll
2009-02-07 16:32:24 —-A—- C:WINDOWSsystem32d3dx10_39.dll
2009-02-07 16:32:24 —-A—- C:WINDOWSsystem32D3DCompiler_39.dll
2009-02-07 16:32:22 —-A—- C:WINDOWSsystem32XAudio2_1.dll
2009-02-07 16:32:22 —-A—- C:WINDOWSsystem32XAPOFX1_0.dll
2009-02-07 16:32:22 —-A—- C:WINDOWSsystem32D3DX9_39.dll
2009-02-07 16:32:21 —-A—- C:WINDOWSsystem32xactengine3_1.dll
2009-02-07 16:32:20 —-A—- C:WINDOWSsystem32X3DAudio1_4.dll
2009-02-07 16:32:20 —-A—- C:WINDOWSsystem32d3dx10_38.dll
2009-02-07 16:32:20 —-A—- C:WINDOWSsystem32D3DCompiler_38.dll
2009-02-07 16:32:19 —-A—- C:WINDOWSsystem32D3DX9_38.dll
2009-02-07 16:32:18 —-A—- C:WINDOWSsystem32XAudio2_0.dll
2009-02-07 16:32:18 —-A—- C:WINDOWSsystem32xactengine3_0.dll
2009-02-07 16:32:17 —-A—- C:WINDOWSsystem32X3DAudio1_3.dll
2009-02-07 16:32:16 —-A—- C:WINDOWSsystem32d3dx10_37.dll
2009-02-07 16:32:16 —-A—- C:WINDOWSsystem32D3DCompiler_37.dll
2009-02-07 16:32:15 —-A—- C:WINDOWSsystem32xactengine2_10.dll
2009-02-07 16:32:15 —-A—- C:WINDOWSsystem32D3DX9_37.dll
2009-02-07 16:32:14 —-A—- C:WINDOWSsystem32d3dx10_36.dll
2009-02-07 16:32:14 —-A—- C:WINDOWSsystem32D3DCompiler_36.dll
2009-02-07 16:32:13 —-A—- C:WINDOWSsystem32d3dx9_36.dll
2009-02-07 16:32:12 —-A—- C:WINDOWSsystem32xactengine2_9.dll
2009-02-07 16:32:11 —-A—- C:WINDOWSsystem32d3dx9_35.dll
2009-02-07 16:32:11 —-A—- C:WINDOWSsystem32d3dx10_35.dll
2009-02-07 16:32:11 —-A—- C:WINDOWSsystem32D3DCompiler_35.dll
2009-02-07 16:32:10 —-A—- C:WINDOWSsystem32xactengine2_8.dll
2009-02-07 16:32:09 —-A—- C:WINDOWSsystem32X3DAudio1_2.dll
2009-02-07 16:32:09 —-A—- C:WINDOWSsystem32d3dx10_34.dll
2009-02-07 16:32:09 —-A—- C:WINDOWSsystem32D3DCompiler_34.dll
2009-02-07 16:32:08 —-A—- C:WINDOWSsystem32d3dx9_34.dll
2009-02-07 16:32:06 —-A—- C:WINDOWSsystem32xinput1_3.dll
2009-02-07 16:32:05 —-A—- C:WINDOWSsystem32xactengine2_7.dll
2009-02-07 16:31:59 —-A—- C:WINDOWSsystem32d3dx10_33.dll
2009-02-07 16:31:59 —-A—- C:WINDOWSsystem32D3DCompiler_33.dll
2009-02-07 16:31:54 —-A—- C:WINDOWSsystem32d3dx9_33.dll
2009-02-07 16:31:53 —-A—- C:WINDOWSsystem32xactengine2_6.dll
2009-02-07 16:31:52 —-A—- C:WINDOWSsystem32xactengine2_5.dll
2009-02-07 16:31:51 —-A—- C:WINDOWSsystem32xactengine2_4.dll
2009-02-07 16:31:51 —-A—- C:WINDOWSsystem32x3daudio1_1.dll
2009-02-07 16:31:51 —-A—- C:WINDOWSsystem32d3dx9_32.dll
2009-02-07 16:31:50 —-A—- C:WINDOWSsystem32d3dx9_31.dll
2009-02-07 16:31:49 —-A—- C:WINDOWSsystem32xactengine2_3.dll
2009-02-07 16:31:48 —-A—- C:WINDOWSsystem32xinput1_2.dll
2009-02-07 16:31:47 —-A—- C:WINDOWSsystem32xinput1_1.dll
2009-02-07 16:31:47 —-A—- C:WINDOWSsystem32xactengine2_2.dll
2009-02-07 16:31:46 —-A—- C:WINDOWSsystem32xactengine2_1.dll
2009-02-07 16:31:45 —-A—- C:WINDOWSsystem32d3dx9_30.dll
2009-02-07 16:31:44 —-A—- C:WINDOWSsystem32xactengine2_0.dll
2009-02-07 16:31:44 —-A—- C:WINDOWSsystem32x3daudio1_0.dll
2009-02-07 16:31:43 —-A—- C:WINDOWSsystem32d3dx9_29.dll
2009-02-07 16:31:42 —-A—- C:WINDOWSsystem32xinput9_1_0.dll
2009-02-07 16:31:42 —-A—- C:WINDOWSsystem32d3dx9_28.dll
2009-02-07 16:31:41 —-A—- C:WINDOWSsystem32d3dx9_27.dll
2009-02-07 16:31:40 —-A—- C:WINDOWSsystem32d3dx9_26.dll
2009-02-07 16:31:39 —-A—- C:WINDOWSsystem32d3dx9_25.dll
2009-02-07 16:31:37 —-A—- C:WINDOWSsystem32d3dx9_24.dll
2009-02-07 16:21:47 —-D—- C:WINDOWSLogs
2009-02-07 16:21:41 —-HD—- C:WINDOWSmsdownld.tmp
2009-02-07 15:00:08 —-D—- C:Program FilesBonjour
2009-02-06 19:09:30 —-A—- C:WINDOWSsystem32framedyn.dll
2009-02-06 19:08:48 —-D—- C:WINDOWSsystem32Samsung_USB_Drivers
2009-02-06 19:08:18 —-D—- C:Program FilesSamsung
2009-02-06 11:39:54 —-D—- C:Documents and SettingsAlexeyYBApplication DataDownload Master
2009-02-06 11:39:43 —-D—- C:Program FilesDownload Master
2009-02-06 11:21:21 —-A—- C:WINDOWSPlotFlow.INI
2009-02-06 03:37:51 —-A—- C:WINDOWSsystem32wmpns.dll
2009-02-05 22:10:55 —-A—- C:WINDOWSsystem32deploytk.dll
2009-02-05 22:03:46 —-D—- C:Documents and SettingsAlexeyYBApplication DataGraphisoft
2009-02-05 21:49:44 —-A—- C:WINDOWSsystem32WkExt32.dll
2009-02-05 21:49:44 —-A—- C:WINDOWSsystem32WibuXpm4J32.dll
2009-02-05 21:49:44 —-A—- C:WINDOWSsystem32wibuKJni.dll
2009-02-05 21:49:43 —-A—- C:WINDOWSsystem32WkDos.exe
2009-02-05 21:49:40 —-A—- C:WINDOWSsystem32WkWin32.dll
2009-02-05 21:49:37 —-D—- C:Program FilesWIBU-SYSTEMS
2009-02-05 21:49:37 —-D—- C:Program FilesWIBUKEY
2009-02-05 21:47:20 —-D—- C:Program FilesGraphisoft
2009-02-05 21:46:20 —-A—- C:WINDOWSsystem32javaws.exe
2009-02-05 21:46:20 —-A—- C:WINDOWSsystem32javaw.exe
2009-02-05 21:46:20 —-A—- C:WINDOWSsystem32java.exe
2009-02-05 21:46:00 —-D—- C:Program FilesJava
2009-02-05 21:45:58 —-D—- C:Program FilesCommon FilesJava
2009-02-05 21:45:30 —-D—- C:Documents and SettingsAlexeyYBApplication DataSun
2009-02-05 21:31:34 —-D—- C:downloads
2009-02-05 17:15:13 —-D—- C:Program FilesFantastic Flame Screensaver
2009-02-05 17:14:15 —-D—- C:Documents and SettingsAll UsersApplication DataLaconic Software
2009-02-05 11:35:19 —-D—- C:WINDOWSsystem32RNBOSENT
2009-02-05 11:35:19 —-A—- C:WINDOWSsystem32SNTI386.DLL
2009-02-05 11:35:19 —-A—- C:WINDOWSsystem32RNBOVDD.DLL
2009-02-05 11:34:46 —-D—- C:ArchiCAD 6.5
2009-02-05 01:06:53 —-D—- C:Temp
2009-02-05 00:59:44 —-D—- C:Program FilesFlyLinkDC++
2009-02-04 18:26:56 —-A—- C:WINDOWSVPC32.INI
2009-02-04 16:28:32 —-D—- C:Documents and SettingsAll UsersApplication DataTERMINAL Studio
2009-02-04 16:28:28 —-D—- C:Documents and SettingsAll UsersApplication DataAlawarWrapper
2009-02-04 16:09:21 —-D—- C:Documents and SettingsAlexeyYBApplication DataOpera
2009-02-04 16:09:04 —-D—- C:Program FilesOpera
2009-02-04 14:59:35 —-D—- C:Program FilesAlawar.ru
2009-02-03 18:02:19 —-D—- C:Documents and SettingsAlexeyYBApplication DataWeather Clock
2009-02-03 17:47:31 —-D—- C:Documents and SettingsAlexeyYBApplication DataMacromedia
2009-02-03 17:34:17 —-D—- C:Documents and SettingsAlexeyYBApplication DataAdobe
2009-02-03 16:40:25 —-D—- C:Рабочая
2009-02-03 16:25:27 —-HDC—- C:WINDOWS$NtUninstallKB951376-v2$
2009-02-03 16:25:23 —-HDC—- C:WINDOWS$NtUninstallKB952954$
2009-02-03 16:25:18 —-HDC—- C:WINDOWS$NtUninstallKB946648$
2009-02-03 16:25:14 —-HDC—- C:WINDOWS$NtUninstallKB956803$
2009-02-03 16:23:55 —-HDC—- C:WINDOWS$NtUninstallKB955839$
2009-02-03 16:23:49 —-HDC—- C:WINDOWS$NtUninstallKB956391$
2009-02-03 16:22:48 —-HDC—- C:WINDOWS$NtUninstallKB958215$
2009-02-03 16:22:41 —-HDC—- C:WINDOWS$NtUninstallKB951978$
2009-02-03 16:21:12 —-HDC—- C:WINDOWS$NtUninstallKB950974$
2009-02-03 16:21:06 —-HDC—- C:WINDOWS$NtUninstallKB943729$
2009-02-03 16:21:00 —-HDC—- C:WINDOWS$NtUninstallKB951698$
2009-02-03 16:20:55 —-HDC—- C:WINDOWS$NtUninstallKB954211$
2009-02-03 16:20:27 —-HDC—- C:WINDOWS$NtUninstallKB956841$
2009-02-03 16:20:20 —-HDC—- C:WINDOWS$NtUninstallKB960714$
2009-02-03 16:19:02 —-D—- C:Program FilesMicrosoft CAPICOM 2.1.0.2
2009-02-03 16:16:58 —-HDC—- C:WINDOWS$NtUninstallKB950762$
2009-02-03 16:16:53 —-HDC—- C:WINDOWS$NtUninstallKB957097$
2009-02-03 16:16:48 —-HDC—- C:WINDOWS$NtUninstallKB958687$
2009-02-03 16:16:43 —-HDC—- C:WINDOWS$NtUninstallKB952287$
2009-02-03 16:16:03 —-HDC—- C:WINDOWS$NtUninstallKB951066$
2009-02-03 16:15:17 —-HDC—- C:WINDOWS$NtUninstallKB954459$
2009-02-03 16:09:41 —-HDC—- C:WINDOWS$NtUninstallKB952069_WM9$
2009-02-03 16:09:36 —-HDC—- C:WINDOWS$NtUninstallKB951748$
2009-02-03 16:09:11 —-HDC—- C:WINDOWS$NtUninstallKB938464$
2009-02-03 16:08:50 —-HDC—- C:WINDOWS$NtUninstallKB954600$
2009-02-03 16:08:45 —-HDC—- C:WINDOWS$NtUninstallKB958644$
2009-02-03 16:08:40 —-HDC—- C:WINDOWS$NtUninstallKB955069$
2009-02-03 16:08:29 —-HDC—- C:WINDOWS$NtUninstallKB956802$
2009-02-03 15:26:41 —-D—- C: Root
2009-02-03 14:38:26 —-D—- C:проги
2009-02-03 14:35:40 —-A—- C:WINDOWSsystem32ptpusb.dll
2009-02-03 14:35:39 —-A—- C:WINDOWSsystem32ptpusd.dll
2009-02-03 14:28:54 —-D—- C:Documents and SettingsAlexeyYBApplication DataApple Computer
2009-02-03 14:26:14 —-A—- C:WINDOWSsxexp32.dll
2009-02-03 14:15:16 —-D—- C:Documents and SettingsAlexeyYBApplication DataQIP
2009-02-03 14:13:38 —-D—- C:WINDOWSSchCache
2009-02-03 14:02:37 —-D—- C:Program FilesQIP Infium
2009-02-03 14:00:52 —-A—- C:WINDOWSsystem32GEARAspi.dll
2009-02-03 14:00:39 —-D—- C:Program FilesiPod
2009-02-03 14:00:36 —-D—- C:Program FilesiTunes
2009-02-03 14:00:36 —-D—- C:Documents and SettingsAll UsersApplication Data{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-03 14:00:03 —-D—- C:Program FilesQuickTime
2009-02-03 14:00:01 —-D—- C:Documents and SettingsAll UsersApplication DataApple Computer
2009-02-03 13:59:46 —-D—- C:Program FilesApple Software Update
2009-02-03 13:59:29 —-D—- C:Program FilesCommon FilesApple
2009-02-03 13:59:28 —-D—- C:Documents and SettingsAll UsersApplication DataApple
2009-02-03 13:44:41 —-A—- C:project2007.txt
2009-02-03 11:54:47 —-D—- C:WINDOWSsystem32NtmsData
2009-02-03 11:34:30 —-D—- C:WINDOWSsystem32appmgmt
2009-02-03 11:09:57 —-D—- C:Documents and SettingsAlexeyYBApplication DataIdentities
2009-02-03 11:00:12 —-SD—- C:Documents and SettingsAlexeyYBApplication DataMicrosoft
2009-02-03 11:00:12 —-D—- C:Documents and SettingsAlexeyYBApplication DataACD Systems
2009-02-03 11:00:12 —-ASH—- C:Documents and SettingsAlexeyYBApplication Datadesktop.ini
2009-02-02 15:55:01 —-D—- C:Program FilesMicrosoft Firewall Client 2004
2009-02-02 15:54:39 —-D—- C:Program FilesMicrosoft Works
2009-02-02 15:53:10 —-D—- C:Documents and SettingsAll UsersApplication DataMicrosoft Help
2009-02-02 15:51:24 —-D—- C:Program Files1cv81
2009-02-02 15:48:41 —-A—- C:WINDOWSsystem32S32EVNT1.DLL
2009-02-02 15:48:35 —-D—- C:Program FilesSymantec
2009-02-02 15:48:35 —-A—- C:WINDOWSsystem32capicom.dll
2009-02-02 15:48:29 —-D—- C:Program FilesSymantec AntiVirus
2009-02-02 15:48:29 —-D—- C:Program FilesCommon FilesSymantec Shared
2009-02-02 15:48:29 —-D—- C:Documents and SettingsAll UsersApplication DataSymantec
2009-02-02 15:46:28 —-D—- C:Program FilesFar
2009-02-02 15:46:26 —-D—- C:Program FilesWinRAR
2009-02-02 15:46:18 —-D—- C:Program FilesCommon FilesACD Systems
2009-02-02 15:46:18 —-D—- C:Program FilesACD Systems
2009-02-02 15:46:18 —-D—- C:Documents and SettingsAll UsersApplication DataACD Systems
2009-02-02 15:45:28 —-D—- C:Documents and SettingsAll UsersApplication DataAdobe
2009-02-02 15:45:27 —-D—- C:Program FilesCommon FilesAdobe
2009-02-02 15:45:25 —-D—- C:Program FilesAdobe
2009-02-02 15:43:32 —-A—- C:WINDOWSODBC.INI
2009-02-02 15:43:27 —-A—- C:WINDOWSsystem32mdimon.dll
2009-02-02 15:43:02 —-D—- C:Program FilesMicrosoft.NET
2009-02-02 15:42:44 —-D—- C:Program FilesCommon FilesDESIGNER
2009-02-02 15:42:36 —-D—- C:WINDOWSSHELLNEW
2009-02-02 15:42:09 —-D—- C:Program FilesMicrosoft Office
2009-02-02 15:42:03 —-D—- C:Compaq
2009-02-02 15:41:56 —-A—- C:WINDOWSsystem32Mfc42enu.dll
2009-02-02 15:41:55 —-A—- C:SETUP.EXE
2009-02-02 15:41:49 —-A—- C:WINDOWSCpqi2c.dll
2009-02-02 15:41:47 —-RHD—- C:MSOCache
2009-02-02 15:41:47 —-D—- C:Program FilesCompaq
2009-02-02 15:41:30 —-A—- C:WINDOWSIsUn0419.exe
2009-02-02 15:41:12 —-A—- C:WINDOWSsystem32MRT.exe
2009-02-02 15:41:00 —-SHD—- C:WINDOWSCSC
2009-02-02 14:36:04 —-A—- C:WINDOWSsystem32igfxres.dll
2008-12-19 18:15:58 —-A—- C:WINDOWSsystem32libavcodec.dll
2008-12-17 20:41:18 —-A—- C:WINDOWSsystem32ff_x264.dll
2008-12-17 20:22:58 —-A—- C:WINDOWSsystem32ff_wmv9.dll
2008-12-17 20:22:48 —-A—- C:WINDOWSsystem32ff_vfw.dll
2008-12-17 20:17:34 —-A—- C:WINDOWSsystem32ff_theora.dll
2008-12-17 19:59:54 —-A—- C:WINDOWSsystem32libmplayer.dll
2008-12-12 11:18:16 —-A—- C:WINDOWSsystem32dns-sd.exe
2008-12-12 11:11:46 —-A—- C:WINDOWSsystem32dnssd.dll
2008-12-11 14:27:02 —-A—- C:WINDOWSsystem32ff_vfw.dll.manifest
2008-11-29 23:26:36 —-A—- C:WINDOWSsystem32VSFilter.dll======List of files/folders modified in the last 3 months======
2009-02-26 15:51:37 —-D—- C:WINDOWSTemp
2009-02-26 15:49:12 —-A—- C:WINDOWSSchedLgU.Txt
2009-02-26 14:18:55 —-D—- C:WINDOWSPrefetch
2009-02-26 14:17:58 —-D—- C:WINDOWSsystem32
2009-02-26 13:53:23 —-RD—- C:Program Files
2009-02-26 13:29:08 —-RSHDC—- C:WINDOWSsystem32dllcache
2009-02-26 11:38:19 —-D—- C:WINDOWSsecurity
2009-02-26 08:42:42 —-D—- C:WINDOWSsystem32CatRoot2
2009-02-26 01:47:15 —-D—- C:WINDOWS
2009-02-25 17:29:34 —-HD—- C:WINDOWSinf
2009-02-25 10:44:19 —-HD—- C:WINDOWS$hf_mig$
2009-02-23 13:59:04 —-D—- C:WINDOWSsystem32drivers
2009-02-21 22:15:48 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
2009-02-14 02:04:12 —-SHD—- C:WINDOWSInstaller
2009-02-14 02:01:39 —-D—- C:Program FilesCommon Files
2009-02-14 02:01:37 —-HD—- C:Program FilesInstallShield Installation Information
2009-02-13 23:30:29 —-RSD—- C:WINDOWSFonts
2009-02-13 23:29:52 —-D—- C:Program FilesCommon FilesInstallShield
2009-02-11 10:38:45 —-A—- C:WINDOWSvbaddin.ini
2009-02-09 12:56:29 —-D—- C:WINDOWSWinSxS
2009-02-07 16:46:07 —-SD—- C:WINDOWSDownloaded Program Files
2009-02-07 16:32:30 —-D—- C:WINDOWSsystem32DirectX
2009-02-04 01:14:42 —-D—- C:WINDOWSsystem32ias
2009-02-03 23:28:17 —-D—- C:WINDOWSnetwork diagnostic
2009-02-03 23:07:58 —-A—- C:WINDOWSsystem.ini
2009-02-03 16:39:00 —-D—- C:WINDOWSsystem32wbem
2009-02-03 16:25:30 —-A—- C:WINDOWSimsins.BAK
2009-02-03 16:25:20 —-D—- C:Program FilesMessenger
2009-02-03 16:23:39 —-A—- C:WINDOWSwin.ini
2009-02-03 16:11:34 —-D—- C:Program FilesCommon FilesMicrosoft Shared
2009-02-03 14:00:52 —-DC—- C:WINDOWSsystem32DRVSTORE
2009-02-03 14:00:21 —-D—- C:Program FilesInternet Explorer
2009-02-03 13:59:48 —-SD—- C:WINDOWSTasks
2009-02-03 13:58:51 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
2009-02-03 12:03:59 —-SHD—- C:RECYCLER
2009-02-03 11:00:11 —-D—- C:Documents and Settings
2009-02-02 15:54:48 —-D—- C:WINDOWSsystem32config
2009-02-02 15:42:37 —-D—- C:Program FilesCommon FilesSystem
2009-02-02 15:42:09 —-D—- C:WINDOWSpchealth
2009-02-02 15:41:58 —-D—- C:WINDOWSHelp
2009-02-02 15:41:53 —-D—- C:WINDOWSsystem
2009-02-02 15:41:14 —-D—- C:WINDOWSDebug
2008-12-12 20:03:18 —-A—- C:WINDOWSsystem32mshtml.dll======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ClntMgmt;HP Client Management Driver; C:WINDOWSSystem32DriversClntMgmt.sys [2003-10-29 59044]
R1 eeCtrl;Symantec Eraser Control driver; ??C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys []
R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-14 40704]
R1 kbdhid;Драйвер клавиатуры HID; C:WINDOWSsystem32DRIVERSkbdhid.sys [2008-04-14 14720]
R1 SAVRT;SAVRT; ??C:Program FilesSymantec AntiVirussavrt.sys []
R1 SAVRTPEL;SAVRTPEL; ??C:Program FilesSymantec AntiVirusSavrtpel.sys []
R1 SPBBCDrv;SPBBCDrv; ??C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCDrv.sys []
R1 StarOpen;StarOpen; C:WINDOWSsystem32driversStarOpen.sys [2006-07-24 5632]
R1 SYMTDI;SYMTDI; C:WINDOWSSystem32DriversSYMTDI.SYS [2007-02-12 196752]
R1 WmiAcpi;Интерфейс управления для ACPI Microsoft Windows; C:WINDOWSsystem32DRIVERSwmiacpi.sys [2008-04-13 8832]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS-совместимый транспортный протокол; C:WINDOWSsystem32DRIVERSnwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:WINDOWSsystem32DRIVERSnwlnknb.sys [2004-08-18 63232]
R2 NwlnkSpx;Протокол NWLink SPX/SPXII; C:WINDOWSsystem32DRIVERSnwlnkspx.sys [2004-08-18 55936]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:WINDOWSSYSTEM32DRIVERSWibuKey.sys [2006-11-22 72704]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:WINDOWSsystem32driversADIHdAud.sys [2008-02-05 281600]
R3 AEAudio;AE Audio Service; C:WINDOWSsystem32driversAEAudio.sys [2007-07-13 94976]
R3 AgereSoftModem;Agere Systems Soft Modem; C:WINDOWSsystem32DRIVERSAGRSM.sys [2008-02-29 1202560]
R3 BTKRNL;Нумератор шины Bluetooth; C:WINDOWSsystem32DRIVERSbtkrnl.sys [2007-02-14 868298]
R3 CmBatt;Драйвер AC-адаптера блока питания (Майкрософт); C:WINDOWSsystem32DRIVERSCmBatt.sys [2008-04-13 13952]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:WINDOWSsystem32DRIVERSe1e5132.sys [2007-04-12 250776]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; ??C:Program FilesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:WINDOWSsystem32DRIVERSGEARAspiWDM.sys [2008-04-17 15464]
R3 HBtnKey;HBtnKey; C:WINDOWSsystem32DRIVERScpqbttn.sys [2008-04-28 9344]
R3 HDAudBus;Драйвер шины Microsoft UAA для High Definition Audio; C:WINDOWSsystem32DRIVERSHDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Драйвер класса HID Microsoft; C:WINDOWSsystem32DRIVERShidusb.sys [2008-04-13 10368]
R3 HpqKbFiltr;HpqKbFilter Driver; C:WINDOWSsystem32DRIVERSHpqKbFiltr.sys [2007-06-18 16768]
R3 ialm;ialm; C:WINDOWSsystem32DRIVERSigxpmp32.sys [2007-09-18 5779296]
R3 mouhid;Драйвер мыши HID; C:WINDOWSsystem32DRIVERSmouhid.sys [2001-10-19 12160]
R3 NAVENG;NAVENG; ??C:PROGRA~1COMMON~1SYMANT~1VIRUSD~120090225.021naveng.sys []
R3 NAVEX15;NAVEX15; ??C:PROGRA~1COMMON~1SYMANT~1VIRUSD~120090225.021navex15.sys []
R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:WINDOWSsystem32DRIVERSNETw5x32.sys [2008-06-26 3630080]
R3 NWRDR;NetWare Rdr; C:WINDOWSsystem32DRIVERSnwrdr.sys [2008-04-13 163584]
R3 SymEvent;SymEvent; ??C:WINDOWSsystem32DriversSYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:WINDOWSSystem32DriversSYMREDRV.SYS [2007-02-12 24720]
R3 SynTP;Synaptics TouchPad Driver; C:WINDOWSsystem32DRIVERSSynTP.sys [2008-01-18 220640]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-13 59520]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Wdf01000; C:WINDOWSsystem32DRIVERSWdf01000.sys [2006-11-02 492000]
S2 Sentinel;Sentinel; C:WINDOWSSystem32DriversSENTINEL.SYS [1999-04-22 73216]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:WINDOWSSystem32Driversbtwusb.sys [2007-02-14 67960]
S3 nm;Драйвер сетевого монитора; C:WINDOWSsystem32DRIVERSNMnt.sys [2008-04-13 40320]
S3 tcpsr;tcpsr; C:WINDOWSsystem32driverstcpsr.sys []
S3 USBAAPL;Apple Mobile USB Driver; C:WINDOWSSystem32Driversusbaapl.sys [2008-11-07 32000]
S3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-04-14 15104]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []
S4 sr;Драйвер фильтра восстановления системы; C:WINDOWSsystem32DRIVERSsr.sys [2008-04-14 73472]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:WINDOWSsystem32agrsmsvc.exe [2007-12-11 12800]
R2 Apple Mobile Device;Apple Mobile Device; C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:Program FilesBonjourmDNSResponder.exe [2008-12-12 238888]
R2 btwdins;Bluetooth Service; C:Program FilesWIDCOMMBluetooth Softwarebinbtwdins.exe [2007-02-06 266295]
R2 ccEvtMgr;Symantec Event Manager; C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe [2006-11-21 192104]
R2 ccSetMgr;Symantec Settings Manager; C:Program FilesCommon FilesSymantec SharedccSetMgr.exe [2006-11-21 169576]
R2 CPQALERT;Insight Local Alerter; C:Program FilesCompaqCompaq Management Agentscpqalert.exe [2004-07-19 512000]
R2 cpqdmi;cpqdmi; C:PROGRA~1CompaqCOMPAQ~1cpqdmi.exe [2004-07-19 20480]
R2 cpqWebDmi;Insight Web Agent; C:PROGRA~1CompaqCOMPAQ~1CPQWEB~1WebDmi.exe [2004-07-19 24576]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:Program FilesSymantec AntiVirusDefWatch.exe [2007-03-14 31424]
R2 FwcAgent;Firewall Client Agent; C:Program FilesMicrosoft Firewall Client 2004FwcAgent.exe [2006-12-09 128832]
R2 hpqwmiex;hpqwmiex; C:Program FilesHewlett-PackardSharedhpqwmiex.exe [2008-05-01 165192]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:Program FilesIntelIntel Matrix Storage ManagerIaantmon.exe [2007-10-03 358936]
R2 IviRegMgr;IviRegMgr; C:Program FilesCommon FilesInterVideoRegMgriviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2009-02-05 152984]
R2 NWCWorkstation;Клиент для сетей NetWare; C:WINDOWSsystem32svchost.exe [2008-04-14 14336]
R2 NwSapAgent;Агент SAP; C:WINDOWSsystem32svchost.exe [2008-04-14 14336]
R2 SavRoam;SAVRoam; C:Program FilesSymantec AntiVirusSavRoam.exe [2007-03-14 116416]
R2 SNMP;Служба SNMP; C:WINDOWSSystem32snmp.exe [2004-08-18 32256]
R2 SPBBCSvc;Symantec SPBBCSvc; C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe [2007-01-10 1160792]
R2 Symantec AntiVirus;Symantec AntiVirus; C:Program FilesSymantec AntiVirusRtvscan.exe [2007-03-14 1816768]
R2 UleadBurningHelper;Ulead Burning Helper; C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe [2005-01-31 49152]
R2 WIN32SL;Win32Sl; C:Program FilesCompaqCompaq Management AgentsDmiWin32binWin32sl.exe [2001-04-11 215552]
R3 Com4QLBEx;Com4QLBEx; C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe [2008-04-03 193840]
R3 iPod Service;Сервис iPod; C:Program FilesiPodbiniPodService.exe [2009-01-06 536872]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe [2005-04-04 69632]
S3 LiveUpdate;LiveUpdate; C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE [2006-09-02 2528960]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 SNDSrvc;Symantec Network Drivers Service; C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe [2007-02-12 214672]
S3 SNMPTRAP;Служба ловушек SNMP; C:WINDOWSSystem32snmptrap.exe [2004-08-18 8704]
EOF
info.txt logfile of random’s system information tool 1.05 2009-02-26 16:19:35остальное не входит 🙁
28 февраля, 2009 в 3:21 пп #22313 -
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.