Logfile of random's system information tool 1.08 (written by random/random) Run by User at 2011-02-28 08:49:04 Microsoft Windows XP Professional Service Pack 3 System drive C: has 13 GB (59%) free of 22 GB Total RAM: 767 MB (37% free) HijackThis download failed ======Scheduled tasks folder====== C:\WINDOWS\tasks\Dr.Web Daily scan.job C:\WINDOWS\tasks\Dr.Web Update.job C:\WINDOWS\tasks\MyDefrag v4.3.1 Daily.job C:\WINDOWS\tasks\MyDefrag v4.3.1 Monthly.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00011268-E188-40DF-A514-835FCD78B1BF}] IE7Pro BHO - C:\Program Files\IEPro\IEPro.dll [2009-09-02 777392] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-12-27 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-12-27 79648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0E06662-71F5-4fb0-A9A2-70DBA996EAC3}] ToolBHO - C:\Program Files\ToolBHO\module.dll [2010-06-30 111104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - QT TabBar - C:\WINDOWS\system32\mscoree.dll [2008-07-26 282112] {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - QT Tab Standard Buttons - C:\WINDOWS\system32\mscoree.dll [2008-07-26 282112] {af83e43c-dd2b-4787-826b-31b17dee52ed} - QT Breadcrumbs Address Bar - C:\WINDOWS\system32\mscoree.dll [2008-07-26 282112] {a84524f0-d48b-4cff-8012-5e67decaf1d5} - QTToolBar2 - C:\WINDOWS\system32\mscoree.dll [2008-07-26 282112] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "USB Antivirus"=C:\Program Files\USBGuard\USBGuard.exe [2008-10-09 798720] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "USB Safely Remove"=C:\Program Files\USB Safely Remove\USBSafelyRemove.exe [2008-12-18 737792] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2009-10-04 30208] "SpIDerAgent"=C:\Program Files\DrWeb\SpIDerAgent.exe [2010-02-02 447728] "SpIDerMail"=C:\Program Files\DrWeb\spiderml.exe [2009-07-01 644336] "SpIDerNT"=C:\PROGRA~1\DrWeb\spiderui.exe [2011-02-10 232352] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrystalDiskInfo] I:\Железо\CrystalDiskInfo10\DiskInfo.exe /Startup [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe [2009-10-04 30208] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonUtilities] C:\Program Files\Norton Utilities 14\nu.exe [2010-01-31 4395520] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll [2003-02-13 4595712] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysInfoMW] C:\Program Files\SysInfoMW\SysInfoMW.exe [2005-08-09 100352] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB Antivirus] C:\Program Files\USBGuard\USBGuard.exe [2008-10-09 798720] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe [2008-12-18 737792] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "xmlprov"=3 "WudfSvc"=3 "wscsvc"=3 "WMPNetworkSvc"=3 "WmiApSrv"=3 "Wmi"=2 "WinRM"=3 "winmgmt"=2 "W32Time"=3 "VSS"=3 "USBSafelyRemoveService"=2 "upnphost"=2 "TrkWks"=2 "Themes"=2 "TermService"=3 "TCSFileServer"=3 "TapiSrv"=3 "SwPrv"=2 "SSDPSRV"=3 "srservice"=2 "SQLWriter"=2 "SQLSERVERAGENT"=3 "SQLBrowser"=3 "SQLAgent$CSD"=3 "Spooler"=3 "SPIDERNT"=2 "ShellHWDetection"=2 "SENS"=2 "seclogon"=2 "Schedule"=2 "SCardSvr"=3 "SamSs"=3 "RSVP"=3 "RemoteAccess"=2 "RasMan"=3 "RasAuto"=3 "ProtectedStorage"=2 "PolicyAgent"=3 "PNRPSvc"=3 "PlugPlay"=2 "p2psvc"=3 "p2pimsvc"=3 "p2pgasvc"=3 "ose"=3 "odserv"=3 "NVSvc"=2 "NtmsSvc"=3 "NtLmSsp"=3 "Nla"=3 "nhksrv"=2 "Netman"=3 "Netlogon"=3 "napagent"=3 "MSSQLServerADHelper"=3 "MSSQLSERVER"=3 "MSSQL$CSD"=3 "MSIServer"=3 "MSDTC"=2 "MDM"=2 "LmHosts"=3 "lanmanworkstation"=2 "LanmanServer"=2 "ImapiService"=3 "idsvc"=3 "HTTPFilter"=3 "hkmsvc"=3 "HidServ"=2 "helpsvc"=3 "FontCache3.0.0.0"=3 "FastUserSwitchingCompatibility"=3 "EventSystem"=2 "Eventlog"=2 "EapHost"=3 "DrWebEngine"=2 "Dot3svc"=3 "Dnscache"=3 "dmserver"=2 "dmadmin"=3 "Dhcp"=3 "CryptSvc"=3 "COMSysApp"=2 "clr_optimization_v2.0.50727_32"=3 "CiSvc"=2 "Browser"=3 "AudioSrv"=3 "aspnet_state"=3 "AppMgmt"=3 "ALG"=3 "6to4"=3 "IS360service"=2 C:\Documents and Settings\User\Главное меню\Программы\Автозагрузка setup_9.0.0.722_26.02.2011_04-18.lnk - C:\Documents and Settings\User\Рабочий стол\Virus Removal Tool\setup_9.0.0.722_26.02.2011_04-18\startup.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="prio.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2007-06-18 133632] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Windows 7\Windows 7.msstyles "InstallTheme"=C:\WINDOWS\Resources\Themes\Windows 7.theme "DisableStatusMessages"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=255 "NoThumbnailCache"=1 "NoSMConfigurePrograms"=1 "NoRecentDocsNetHood"=1 "NoDriveAutoRun"=67108863 "HonorAutorunSetting"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"=1 "NoResolveSearch"=1 "NoDriveTypeAutoRun"=255 "NoDriveAutoRun"=67108863 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" ======File associations====== .bat - edit - .cmd - edit - .inf - open - .ini - open - notepad.exe %1 .js - edit - .js - open - "C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" .txt - open - notepad.exe %1 .vbs - edit - ======List of files/folders created in the last 3 months====== 2011-02-28 08:49:04 ----D---- C:\rsit 2011-02-28 08:49:04 ----D---- C:\Program Files\trend micro 2011-02-28 08:45:41 ----A---- C:\WINDOWS\system32\drivers\utiwmjyy.sys 2011-02-26 14:26:41 ----A---- C:\WINDOWS\system32\drivers\19571082.sys 2011-02-26 14:26:41 ----A---- C:\WINDOWS\system32\drivers\19571081.sys 2011-02-26 14:26:41 ----A---- C:\WINDOWS\system32\drivers\1957108.sys 2011-02-26 09:35:53 ----A---- C:\WINDOWS\ntbtlog.txt 2011-02-25 08:50:59 ----A---- C:\WINDOWS\system32\drivers\hardlock.sys 2011-02-21 15:43:36 ----A---- C:\WINDOWS\system32\UNWISE.EXE 2011-02-21 15:43:34 ----D---- C:\Program Files\Aladdin 2011-02-18 15:40:10 ----D---- C:\Program Files\xp-AntiSpy 2011-02-16 11:29:39 ----A---- C:\WINDOWS\system32\drivers\haspflt.sys 2011-02-16 11:26:56 ----A---- C:\WINDOWS\system32\haspvdd.dll 2011-02-16 11:26:56 ----A---- C:\WINDOWS\system32\haspdos.sys 2011-02-16 11:26:56 ----A---- C:\WINDOWS\system32\drivers\Haspnt.sys 2011-02-16 11:25:34 ----D---- C:\Program Files\1cv82 2011-02-16 11:25:31 ----D---- C:\Documents and Settings\User\Application Data\1C 2011-02-14 13:11:36 ----D---- C:\Documents and Settings\User\Application Data\eSMI 2011-02-11 16:56:06 ----A---- C:\WINDOWS\IE4 Error Log.txt 2011-02-10 16:27:29 ----D---- C:\Documents and Settings\User\Application Data\Norton Utilities 14 2011-02-10 15:38:47 ----D---- C:\Program Files\Norton Utilities 14 2011-02-10 08:24:33 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys 2011-02-10 08:24:09 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator 2011-02-10 08:23:50 ----D---- C:\Documents and Settings\User\Application Data\Spyware Terminator 2011-02-08 08:33:23 ----A---- C:\WINDOWS\system32\snapapi.dll 2011-02-07 08:42:30 ----D---- C:\Documents and Settings\User\Application Data\Acronis 2011-02-07 08:39:15 ----A---- C:\WINDOWS\system32\drivers\tdrpm147.sys 2011-02-07 08:39:08 ----D---- C:\Documents and Settings\All Users\Application Data\Acronis 2011-02-07 08:39:08 ----A---- C:\WINDOWS\system32\drivers\timntr.sys 2011-02-07 08:39:08 ----A---- C:\WINDOWS\system32\drivers\tifsfilt.sys 2011-02-07 08:38:54 ----A---- C:\WINDOWS\system32\drivers\snman380.sys 2011-02-07 08:37:43 ----D---- C:\Program Files\Acronis 2011-02-07 08:37:39 ----D---- C:\Program Files\Common Files\Acronis 2011-02-04 14:52:56 ----D---- C:\Мой проект вебсайта 2011-02-04 14:13:01 ----D---- C:\Program Files\WebSite X5 v8 - Evolution 2011-02-04 14:12:22 ----A---- C:\WINDOWS\system32\VB5STKIT.DLL 2011-02-04 14:12:22 ----A---- C:\WINDOWS\system32\iwpsetup.exe 2011-01-31 08:41:51 ----D---- C:\Program Files\Blaze Media Pro 2011-01-31 08:38:43 ----D---- C:\Documents and Settings\User\Application Data\Opera 2011-01-31 08:38:30 ----D---- C:\Program Files\Opera 2011-01-27 09:15:39 ----D---- C:\Program Files\ElcomSoft 2011-01-25 16:12:37 ----D---- C:\WINDOWS\system32\AGEIA 2011-01-25 16:12:36 ----D---- C:\Program Files\AGEIA Technologies 2011-01-19 16:56:34 ----D---- C:\Temp 2011-01-11 15:29:38 ----D---- C:\Documents and Settings\User\Application Data\Auslogics 2011-01-11 15:27:11 ----D---- C:\Program Files\Auslogics 2011-01-11 15:01:41 ----D---- C:\Documents and Settings\All Users\Application Data\IObit 2010-12-29 14:55:47 ----D---- C:\Program Files\Common Files\Vbox 2010-12-29 14:51:31 ----A---- C:\WINDOWS\unlite3.exe 2010-12-29 14:51:14 ----D---- C:\Program Files\Bradbury 2010-12-29 10:41:49 ----D---- C:\Documents and Settings\All Users\Application Data\Macrovision 2010-12-29 10:33:13 ----D---- C:\Program Files\Common Files\Macromedia Shared 2010-12-29 10:30:17 ----D---- C:\Program Files\Common Files\Macromedia 2010-12-29 10:21:06 ----D---- C:\Program Files\Macromedia 2010-12-28 14:37:13 ----A---- C:\WINDOWS\hpbafd.ini 2010-12-27 14:41:58 ----D---- C:\Documents and Settings\User\Application Data\OpenOffice.org 2010-12-27 14:35:50 ----D---- C:\Program Files\JRE 2010-12-27 14:35:35 ----D---- C:\Program Files\OpenOffice.org 3 2010-12-27 14:27:40 ----D---- C:\Documents and Settings\All Users\Application Data\Sun 2010-12-27 14:27:30 ----A---- C:\WINDOWS\system32\javaws.exe 2010-12-27 14:27:30 ----A---- C:\WINDOWS\system32\javaw.exe 2010-12-27 14:27:30 ----A---- C:\WINDOWS\system32\java.exe 2010-12-27 14:27:30 ----A---- C:\WINDOWS\system32\deployJava1.dll 2010-12-23 09:23:21 ----D---- C:\Documents and Settings\All Users\Application Data\CrystalIdea Software 2010-12-22 15:05:20 ----D---- C:\Program Files\Jufsoft 2010-12-15 16:37:25 ----D---- C:\Program Files\Common Files\browser 2010-12-15 16:14:46 ----A---- C:\WINDOWS\system32\att_zlib.dll 2010-12-15 14:37:16 ----A---- C:\WINDOWS\system32\sw.dll 2010-12-15 14:37:16 ----A---- C:\WINDOWS\system32\bjd.dll 2010-12-13 13:44:31 ----D---- C:\WINDOWS\Downloaded Installations 2010-12-13 11:43:26 ----D---- C:\Program Files\Soft Gold 2010-12-11 10:46:10 ----D---- C:\Documents and Settings\User\Application Data\Efficient To-Do List Free 2010-12-11 09:01:02 ----D---- C:\Documents and Settings\User\Application Data\Malwarebytes 2010-12-11 09:00:51 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2010-12-09 16:16:37 ----D---- C:\Documents and Settings\User\Application Data\OpenOffice.org2 2010-12-09 16:12:36 ----D---- C:\Program Files\OpenOffice.org 2.4 2010-12-09 16:11:00 ----D---- C:\Program Files\Common Files\Java 2010-12-03 13:09:17 ----AC---- C:\WINDOWS\BPwin40.ini 2010-12-03 13:08:50 ----C---- C:\WINDOWS\Bpwinrpt.ini 2010-12-03 13:08:39 ----D---- C:\Program Files\Computer Associates 2010-12-03 13:08:39 ----C---- C:\WINDOWS\system32\Tngremov.exe 2010-12-03 13:08:39 ----C---- C:\WINDOWS\system32\Tngremo_.exe 2010-12-03 13:08:35 ----D---- C:\CA_LIC 2010-12-02 10:09:08 ----D---- C:\Program Files\TrendMicro ======List of files/folders modified in the last 3 months====== 2011-02-28 08:49:04 ----D---- C:\Program Files 2011-02-28 08:45:41 ----D---- C:\WINDOWS\system32\drivers 2011-02-28 08:39:19 ----D---- C:\Program Files\DrWeb 2011-02-28 08:38:51 ----D---- C:\WINDOWS\system32\CatRoot2 2011-02-28 08:38:16 ----D---- C:\WINDOWS\Temp 2011-02-28 08:37:55 ----D---- C:\WINDOWS\Registration 2011-02-26 15:37:14 ----AC---- C:\WINDOWS\system.ini 2011-02-26 15:25:55 ----D---- C:\WINDOWS 2011-02-26 15:24:06 ----D---- C:\WINDOWS\security 2011-02-26 14:40:39 ----D---- C:\Documents and Settings\User\Application Data\winxrar 2011-02-26 14:36:29 ----SHD---- C:\System Volume Information 2011-02-26 14:27:19 ----HD---- C:\WINDOWS\inf 2011-02-26 10:56:04 ----D---- C:\WINDOWS\Help 2011-02-26 10:48:31 ----D---- C:\WINDOWS\system32\NtmsData 2011-02-26 09:46:40 ----D---- C:\WINDOWS\system32 2011-02-26 09:46:40 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI 2011-02-25 11:26:47 ----D---- C:\WINDOWS\system32\wbem 2011-02-25 11:21:11 ----D---- C:\WINDOWS\system32\config 2011-02-25 08:51:41 ----D---- C:\WINDOWS\system32\CatRoot 2011-02-25 08:50:52 ----D---- C:\WINDOWS\system32\Setup 2011-02-18 15:31:42 ----AC---- C:\Documents and Settings\User\Application Data\docXConverter.ini 2011-02-16 11:26:33 ----SHD---- C:\WINDOWS\Installer 2011-02-11 16:08:11 ----AC---- C:\WINDOWS\ODBCINST.INI 2011-02-11 16:08:06 ----AC---- C:\WINDOWS\ODBC.INI 2011-02-11 08:05:48 ----D---- C:\WINDOWS\system32\Restore 2011-02-10 16:34:46 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP 2011-02-10 16:27:29 ----D---- C:\Program Files\NetMeeting 2011-02-10 16:25:38 ----RAD---- C:\Documents and Settings\User\Application Data\Microsoft 2011-02-09 07:55:56 ----SH---- C:\boot.ini 2011-02-09 07:55:56 ----AC---- C:\WINDOWS\win.ini 2011-02-08 08:45:17 ----D---- C:\Program Files\Common Files\Borland Shared 2011-02-07 09:38:35 ----D---- C:\WINDOWS\Prefetch 2011-02-07 08:37:39 ----D---- C:\Program Files\Common Files 2011-02-02 09:38:21 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2011-01-28 16:48:10 ----D---- C:\Program Files\MyDefrag v4.3.1 2011-01-28 15:51:50 ----AC---- C:\WINDOWS\NeroDigital.ini 2011-01-25 16:11:20 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2011-01-24 09:09:44 ----D---- C:\Program Files\GSmartControl 2011-01-24 09:09:43 ----D---- C:\Documents and Settings\User\Application Data\gsmartcontrol 2011-01-11 15:31:24 ----SD---- C:\WINDOWS\Downloaded Program Files 2011-01-11 15:23:46 ----D---- C:\WINDOWS\SoftwareDistribution 2011-01-11 15:21:53 ----RSHDC---- C:\WINDOWS\system32\dllcache 2011-01-11 15:21:53 ----D---- C:\Program Files\FastStone Image Viewer 2011-01-11 15:01:44 ----D---- C:\Documents and Settings\User\Application Data\IObit 2011-01-11 15:01:21 ----D---- C:\Program Files\IObit 2011-01-11 14:14:01 ----D---- C:\Documents and Settings\User\Application Data\Media Player Classic 2010-12-29 14:45:39 ----HD---- C:\Program Files\InstallShield Installation Information 2010-12-29 10:20:21 ----D---- C:\Program Files\Common Files\Microsoft Shared 2010-12-28 07:57:20 ----RD---- C:\WINDOWS\OemDrv 2010-12-27 15:20:13 ----D---- C:\Program Files\The Bat 2010-12-27 14:39:19 ----RSD---- C:\WINDOWS\assembly 2010-12-27 14:36:40 ----RSD---- C:\WINDOWS\Fonts 2010-12-27 14:26:49 ----D---- C:\Program Files\Java 2010-12-27 09:01:45 ----D---- C:\Program Files\Photo Story 3 for Windows 2010-12-23 09:05:07 ----D---- C:\Program Files\Common Files\Pervasive Software 2010-12-23 09:04:59 ----A---- C:\AUTOEXEC.BAT 2010-12-21 16:04:37 ----D---- C:\Program Files\Notepad++ 2010-12-14 10:03:30 ----D---- C:\Documents and Settings\User\Application Data\Audacity 2010-12-11 09:01:38 ----D---- C:\Program Files\CCleaner 2010-12-11 08:47:15 ----D---- C:\WINDOWS\repair 2010-12-11 08:45:17 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft 2010-12-08 14:42:04 ----D---- C:\Program Files\MSECache 2010-12-07 09:28:14 ----HD---- C:\WINDOWS\$hf_mig$ 2010-12-02 13:13:21 ----D---- C:\WINDOWS\Network Diagnostic 2010-12-01 14:32:11 ----AC---- C:\WINDOWS\WININT.INI 2010-12-01 14:28:31 ----D---- C:\Documents and Settings\All Users\Application Data\Alwil Software 2010-12-01 14:26:46 ----D---- C:\Program Files\via 2010-12-01 14:23:36 ----AD---- C:\Program Files\CrystalSoft ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 19571082;19571082 Boot Guard Driver; C:\WINDOWS\system32\DRIVERS\19571082.sys [2009-10-22 37392] R0 agp440;Intel - фильтр шины AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-14 42368] R0 DwProt;DrWeb Protection; C:\WINDOWS\system32\drivers\dwprot.sys [2010-11-22 131192] R0 snapman380;Acronis Snapshots Manager (Build 380); C:\WINDOWS\system32\DRIVERS\snman380.sys [2011-02-07 134272] R1 19571081;19571081; C:\WINDOWS\system32\DRIVERS\19571081.sys [2009-09-25 128016] R1 intelppm;Драйвер Intel процессора; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-15 40704] R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys [] R1 msikbd2k;Multimedia Keyboard Filter Driver; C:\WINDOWS\System32\DRIVERS\msikbd2k.sys [2001-12-20 6656] R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [] R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [] R1 setup_9.0.0.722_26.02.2011_04-18drv;setup_9.0.0.722_26.02.2011_04-18drv; C:\WINDOWS\system32\DRIVERS\1957108.sys [2009-10-09 315408] R1 Tcpip6;Драйвер протокола IPv6 (Microsoft); C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880] R1 WS2IFSL;Среда Windows Socket 2.0 поддержки поставщиков не-IFS служб; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-15 12032] R2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2005-03-14 41984] R2 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2009-01-29 133632] R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys [] R2 haspflt;haspflt; \??\C:\WINDOWS\system32\drivers\haspflt.sys [] R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys [] R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS-совместимый транспортный протокол; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-15 88320] R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-15 63232] R2 NwlnkSpx;Протокол NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-15 55936] R2 rspndr;Ответчик обнаружения топологии уровня связи; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2008-10-11 62848] R2 SPIDER;SpIDer Guard File System Monitor; \??\C:\PROGRA~1\DrWeb\spider.sys [] R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2006-06-26 1372992] R3 HidUsb;Драйвер класса HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368] R3 hpusbfd;Hewlett-Packard USB Filter Class; C:\WINDOWS\System32\DRIVERS\hpusbfd.sys [2002-05-22 7552] R3 mouhid;Драйвер мыши HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-20 12160] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2003-02-13 1248474] R3 tunmp;Драйвер адаптера минипорта Microsoft Tun; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2009-10-04 12288] R3 USBSTOR;Драйвер запоминающих устройств для USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368] R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608] S1 kbdhid;Драйвер клавиатуры HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-15 14720] S3 akshasp;Aladdin HASP Key; C:\WINDOWS\system32\DRIVERS\akshasp.sys [] S3 aksusb;Aladdin USB Key; C:\WINDOWS\system32\DRIVERS\aksusb.sys [] S3 Ext2Fsd;Linux ext2 File system driver; C:\WINDOWS\system32\drivers\Ext2Fsd.sys [2008-06-04 654480] S3 PSSDK42;PSSDK42; \??\C:\WINDOWS\system32\Drivers\pssdk42.sys [] S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet адаптер, драйвер для NT; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-14 20992] S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [] S3 tmeter;TMeter Service; C:\WINDOWS\system32\DRIVERS\tmeter.sys [] S3 tmeterMP;tmeterMP; C:\WINDOWS\system32\DRIVERS\tmeter.sys [] S3 usbccgp;Драйвер универсального родительского устройства USB (Microsoft); C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384] S3 usbprint;Класс принтеров Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856] S3 utiwmjyy;AVZ Kernel Driver; \??\C:\WINDOWS\system32\Drivers\utiwmjyy.sys [] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2010-03-25 99728] S3 VBoxNetFlt;VBoxNetFlt Service; C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys [] S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys [] S3 WINIO;WINIO; \??\D:\Мои документы\сети\psc2071\winio.sys [] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2007-06-18 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2007-06-18 82944] S4 RsFx0102;RsFx0102 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine); C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [2009-09-29 869688] R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-12-27 153376] R2 LogWatch;Event Log Watch; C:\WINDOWS\LogWatNT.exe [2000-06-08 50176] R2 sp_rssrv;Spyware Terminator Realtime Shield Service; H:\distr\антитроян\port\Spyware Terminator 2.8.0.18\sp_rsser.exe [2011-02-09 488960] R2 SPIDERNT;SpIDer Guard for Windows; C:\PROGRA~1\DrWeb\spidernt.exe [2011-02-10 231816] R2 USBSafelyRemoveService;USB Safely Remove Assistant; C:\Program Files\USBSRService.exe [2008-12-16 208144] S3 HASP Loader;HASP Loader; C:\WINDOWS\system32\nhsrvice.exe -service [] S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2010-12-29 68096] S3 MSSQL$CSD;SQL Server (CSD); C:\Program Files\Microsoft SQL Server\MSSQL10.CSD\MSSQL\Binn\sqlservr.exe [2008-11-05 40999448] S3 MSSQLSERVER;MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [2002-12-17 7520337] S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 SQLAgent$CSD;Агент SQL Server (CSD); C:\Program Files\Microsoft SQL Server\MSSQL10.CSD\MSSQL\Binn\SQLAGENT.EXE [2008-11-05 369688] S3 SQLBrowser;SQL Server, обозреватель; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072] S3 SQLSERVERAGENT;SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [2002-12-17 311872] S3 SQLWriter;Модуль сервера SQL Server для записи VSS; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840] S4 6to4;Служба поддержки IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] S4 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-26 34312] S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-26 69632] S4 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-30 46104] S4 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-30 881664] S4 IS360service;IS360service; C:\Program Files\IObit\IObit Security 360\IS360srv.exe [] S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120] S4 MSSQLServerADHelper100;Служба поддержки Active Directory сервера SQL Server; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-11-05 47128] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-30 132096] S4 nhksrv;Netropa NHK Server; C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 28672] S4 NMSAccess;NMSAccess; C:\Program Files\Blaze Media Pro\NMSAccess32.exe [] S4 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2003-02-13 65536] S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136] S4 p2pgasvc;Одноранговая групповая проверка подлинности; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] S4 p2pimsvc;Диспетчер удостоверений для одноранговых сетей; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] S4 p2psvc;Службы одноранговой сети; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] S4 PNRPSvc;Протокол однорангового разрешения имен; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] S4 Squid;Squid; c:\squid\sbin\squid.exe --ntservice:Squid [] S4 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\wmpnetwk.exe [2006-10-19 913408] S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336] -----------------EOF-----------------