Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Mary13
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 22 kvě 2009 12:15

Prosím o kontrolu

#1 Příspěvek od Mary13 »

Zdravím,prosila bych kontrolu PC :)

Лог утилиты random's system information tool 1.09 (автор: random/random)
Run by Alexey at 2012-10-11 11:16:11
Microsoft Windows XP Professional Service Pack 3
Системный раздел C: размер 21 GB (29%) Свободно 73 GB
Total RAM: 2043 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:16:20, on 11/10/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\AccelerometerSt.Exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtblfs.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Alexey\Мои документы\Downloads\RSIT.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\trend micro\Alexey.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com/406
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.155:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Спутник@Mail.Ru - {8984B388-A5BB-4DF7-B274-77B879E179DB} - (no file)
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~1\SEARCH~1\Datamngr\BROWSE~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] c:\WINDOWS\system32\AccelerometerSt.Exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [VistaIcon] C:\Program Files\VistaDriveIcon\VistaDrv.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,NewUserFirstLogonInstall,0 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%\System32\rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\custom.inf,NewUserFirstLogonInstall,0 (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O9 - Extra button: (no name) - DctMapping - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: &Виртуальная клавиатура - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Справочные материалы - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Проверка ссы&лок - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1740976578
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} (Active602XMLFiller Control) - https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 5862975187
O16 - DPF: {7E0FDFBB-87D4-43A1-9AD4-41F0EA8AFF7B} (Net6Launcher Class) - https://portti1.deltamotor.fi/net6helper.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Ddlacradoc?ce Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Aleii eyrr ernlaidce eiediilinia - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: FinePrint Диспетчер v6 - FinePrint Software, LLC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NitroPDFReaderDriverCreatorReadSpool (NitroReaderDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Telnet (TlntSvr) - Корпорация Майкрософт - C:\WINDOWS\system32\tlntsvr.exe
O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe

--
End of file - 15424 bytes

======Папка назначеных зданий======

C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job

======Снимок реестра======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll [2011-04-24 86416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}]
Searchqu Toolbar - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll [2012-02-27 88976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]
DataMngr - C:\PROGRA~1\SEARCH~1\Datamngr\BROWSE~1.DLL [2012-09-02 89016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-09-20 192144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll [2012-08-21 1002992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll [2011-04-24 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-09-20 192144]
{99079a25-328f-4bd4-be04-00955acaa0a7} - Searchqu Toolbar - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll [2012-02-27 88976]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AccelerometerSysTrayApplet"=c:\WINDOWS\system32\AccelerometerSt.Exe [2008-06-09 82224]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2008-10-14 1871872]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2008-04-04 1044480]
"ToolBoxFX"=C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe [2007-10-03 53248]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-02-16 49152]
""= []
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe [2011-04-24 202296]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2012-03-27 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-02 843712]
"DATAMNGR"=C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE [2012-09-02 1890744]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-15 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-08-19 39408]
"Facebook Update"=C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2012-07-12 138096]
"Google Update"=C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-04 136176]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17418928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2012-07-12 138096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-04 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VistaIcon]
C:\Program Files\VistaDriveIcon\VistaDrv.exe [2008-01-02 132096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Documents and Settings\Alexey\Главное меню\Программы\Автозагрузка
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-05-08 126976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2011-04-24 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2008-03-02 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-15 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoSharedDocuments"=1
"NoSMConfigurePrograms"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoBandCustomize"=0
"NoMovingBands"=0
"NoCloseDragDropBands"=0
"NoActiveDesktop"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"D:\utorrent(3).exe"="D:\utorrent(3).exe:*:Enabled:µTorrent"
"C:\Program Files\Sibelius Software\Sibelius 6\RegTool.exe"="C:\Program Files\Sibelius Software\Sibelius 6\RegTool.exe:*:Enabled:RegTool.exe"
"C:\Program Files\Sibelius Software\Sibelius 6\Sibelius.exe"="C:\Program Files\Sibelius Software\Sibelius 6\Sibelius.exe:*:Enabled:Sibelius.exe"
"C:\Program Files\HP\hp laserjet m1522\hppfaxnc1.exe"="C:\Program Files\HP\hp laserjet m1522\hppfaxnc1.exe:*:Enabled:HP Networked Printer Installer"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe"="C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin"
"C:\WINDOWS\system32\muzapp.exe"="C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe"="C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe:*:Enabled:WorldWide Telescope"
"D:\uTorrent.exe"="D:\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe"="C:\Program Files\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe:*:Enabled:DTX broker"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"vidc.XVID"=xvidvfw.dll
"VIDC.DIVX"=divx.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======Ассоциации файлов======

.js - edit - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1"

======Список файлов и папок, созданных за последние 1 месяц======

2012-10-11 09:52:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2724197$
2012-10-11 09:47:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2756822$
2012-10-11 09:47:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2012-10-11 09:47:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2661254-v2$
2012-10-08 17:12:01 ----D---- C:\Documents and Settings\Alexey\Application Data\searchquband
2012-10-08 17:10:59 ----D---- C:\Program Files\iLivid
2012-10-08 17:10:51 ----D---- C:\Documents and Settings\Alexey\Application Data\searchqutoolbar
2012-10-08 17:10:40 ----D---- C:\Documents and Settings\All Users\Application Data\boost_interprocess
2012-10-08 17:10:31 ----D---- C:\Program Files\Searchqu Toolbar
2012-09-13 19:30:14 ----HDC---- C:\WINDOWS\$NtUninstallKB2736233$

======Список файлов и папок, измененных за последние 1 месяц======

2012-10-11 11:16:20 ----D---- C:\WINDOWS\Prefetch
2012-10-11 11:16:15 ----D---- C:\Program Files\trend micro
2012-10-11 11:04:28 ----D---- C:\Documents and Settings\Alexey\Application Data\Skype
2012-10-11 11:01:26 ----AD---- C:\WINDOWS\system32
2012-10-11 11:01:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-10-11 11:01:04 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2012-10-11 11:00:27 ----D---- C:\WINDOWS\temp
2012-10-11 10:54:16 ----D---- C:\WINDOWS
2012-10-11 10:51:58 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-10-11 10:51:56 ----D---- C:\WINDOWS\system32\CatRoot2
2012-10-11 09:52:27 ----HD---- C:\WINDOWS\inf
2012-10-11 09:52:25 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-10-11 09:52:13 ----HD---- C:\WINDOWS\$hf_mig$
2012-10-11 09:52:11 ----SHD---- C:\WINDOWS\Installer
2012-10-11 09:52:11 ----HD---- C:\Config.Msi
2012-10-11 09:48:02 ----A---- C:\WINDOWS\system32\MRT.exe
2012-10-11 09:47:51 ----A---- C:\WINDOWS\imsins.BAK
2012-10-10 21:17:45 ----D---- C:\Documents and Settings\Alexey\Application Data\Nitro PDF
2012-10-08 17:10:59 ----RAD---- C:\Program Files
2012-10-04 22:50:51 ----D---- C:\WINDOWS\Minidump
2012-09-30 21:57:07 ----D---- C:\Documents and Settings\Alexey\Application Data\uTorrent
2012-09-22 10:36:31 ----D---- C:\Program Files\Internet Explorer
2012-09-22 10:08:48 ----D---- C:\WINDOWS\ie8updates

======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)======

R0 hpdskflt;HP Disk Filter Driver; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2008-05-23 24624]
R0 KL1;kl1; C:\WINDOWS\system32\DRIVERS\kl1.sys [2011-03-04 133208]
R0 SFAUDIO;Sonic Focus DSP Driver; C:\WINDOWS\system32\drivers\sfaudio.sys [2008-03-28 24064]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-03-02 77568]
R1 intelppm;Драйвер Intel процессора; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-15 40704]
R1 kbdhid;Драйвер клавиатуры HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-15 14720]
R1 kl2;kl2; C:\WINDOWS\system32\DRIVERS\kl2.sys [2011-03-04 11352]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2011-10-25 565552]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-08-15 5632]
R1 WmiAcpi;Интерфейс управления для ACPI Microsoft Windows; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-15 8832]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2008-07-08 62848]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver; C:\WINDOWS\system32\DRIVERS\thdudf.sys [2011-12-28 66944]
R3 Accelerometer;HP Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2008-05-23 28592]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2008-04-11 338944]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-07-13 94976]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-05-08 2880512]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-04-03 879624]
R3 HBtnKey;HBtnKey; C:\WINDOWS\system32\DRIVERS\cpqbttn.sys [2005-09-19 9344]
R3 HDAudBus;Драйвер шины Microsoft UAA для High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-15 144384]
R3 HidUsb;Драйвер класса HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-15 10368]
R3 HPFXBULK;HPFXBULK; C:\WINDOWS\system32\drivers\hpfxbulk.sys [2007-07-16 17432]
R3 HPFXFAX;HPFXFAX; C:\WINDOWS\system32\drivers\hpfxfax.sys [2007-07-16 20504]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2011-03-10 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-11-02 19472]
R3 mouhid;Драйвер мыши HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-15 12160]
R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2008-11-17 3636864]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2009-03-27 1810992]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2010-06-04 1303728]
R3 usbccgp;Драйвер универсального родительского устройства USB (Microsoft); C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-15 32128]
R3 usbprint;Класс принтеров Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-08-19 25856]
R3 usbscan;Драйвер USB-сканера; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-08-19 15104]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-15 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-04-29 288896]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-04-03 74688]
S3 catchme;catchme; \??\C:\DOCUME~1\Alexey\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption декодер; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-08-19 17024]
S3 eabfiltr;eabfiltr; C:\WINDOWS\system32\DRIVERS\eabfiltr.sys [2005-09-19 7808]
S3 eabusb;eabusb; C:\WINDOWS\system32\DRIVERS\eabusb.sys [2005-09-19 5760]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI кодек; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-08-19 85248]
S3 NdisIP;Microsoft видео или ТВ подключение; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-15 10880]
S3 Net6IM;Net6; C:\WINDOWS\system32\DRIVERS\net6im51.sys []
S3 SCR3XX2K;SCR3xx USB SmartCardReader; C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys [2007-06-21 56448]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver; C:\WINDOWS\system32\DRIVERS\silabenm.sys [2009-05-20 17920]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver; C:\WINDOWS\system32\DRIVERS\silabser.sys [2009-05-20 61568]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-15 11136]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\ssadbus.sys [2011-12-08 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys [2011-12-08 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\WINDOWS\system32\DRIVERS\ssadmdm.sys [2011-12-08 136808]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-15 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys []
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-15 26368]
S3 usbvideo;USB-видеоустройство (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-08-19 121984]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2008-03-02 38528]
S3 WSTCODEC;World Standard Teletext кодек; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-08-19 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-03-02 82944]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-10-09 717296]

======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)======

R2 602XML Updater;602Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-05-08 536576]
R2 AVP;Kaspersky Anti-Virus Service; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe [2011-04-24 202296]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-03-31 264800]
R2 FinePrint Диспетчер v6;FinePrint Диспетчер v6; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe [2008-07-11 557056]
R2 hpqddsvc;Служба HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-03-17 73728]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MySQL;MySQL; C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=C:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL []
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-15 14336]
R2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool; C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [2011-01-14 196912]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-15 14336]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE [2008-10-14 24064]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-15 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-06 136176]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe [2010-04-26 256512]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;Служба состояний ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-09 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Служба Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-06 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-21 194032]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-15 14336]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\wmpnetwk.exe [2006-10-18 913408]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Search
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mary13
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 22 kvě 2009 12:15

Re: Prosím o kontrolu

#3 Příspěvek od Mary13 »

Tu je :)

# AdwCleaner v2.004 - Logfile created 10/12/2012 at 00:37:24
# Updated 06/10/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Alexey - ALEXBG
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Alexey\Мои документы\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\DOCUME~1\Alexey\LOCALS~1\Temp\Searchqu.ini
File Found : C:\DOCUME~1\Alexey\LOCALS~1\Temp\searchqutoolbar-manifest.xml
File Found : C:\DOCUME~1\Alexey\LOCALS~1\Temp\SetupDataMngr_Searchqu.exe
File Found : C:\DOCUME~1\Alexey\LOCALS~1\Temp\Uninstall.exe
File Found : C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\searchplugins\Search_Results.xml
File Found : C:\Documents and Settings\All Users\Рабочий стол\Get The Best Facebook Chat Messenger.lnk
File Found : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml
Folder Found : C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
Folder Found : C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\Searchqutoolbar
Folder Found : C:\Documents and Settings\Alexey\Application Data\OpenCandy
Folder Found : C:\Documents and Settings\Alexey\Application Data\searchquband
Folder Found : C:\Documents and Settings\Alexey\Application Data\Searchqutoolbar
Folder Found : C:\Documents and Settings\Alexey\Local Settings\Application Data\Ilivid Player
Folder Found : C:\Documents and Settings\Alexey\Local Settings\Application Data\OpenCandy
Folder Found : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Found : C:\Program Files\Searchqu Toolbar

***** [Registry] *****

Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\DataMngr_Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKCU\Software\searchqutoolbar
Key Found : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
Key Found : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Searchqu Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Found : HKLM\Software\SearchquMediabarTb
Key Found : HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [DataMngr]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v3.6.13 (ru)

Profile name : default
File : C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\prefs.js

Found : user_pref("browser.search.selectedEngine", "Search Results");
Found : user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/406");
Found : user_pref("browser.search.defaultenginename", "Search Results");
Found : user_pref("browser.search.order.1", "Search Results");
Found : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&appid=488&systemid=406&sr=0&q=");

-\\ Google Chrome v22.0.1229.94

File : C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

Found [l.16] : homepage = "hxxp://www.searchnu.com/406",
Found [l.20] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406", "hxxp://google.com/" ]
Found [l.62] : search_url = "hxxp://dts.search-results.com/sr?src=crb&appid=488&systemid=406&sr=0&q={searchTerms}",
Found [l.1476] : homepage = "hxxp://www.searchnu.com/406",
Found [l.2214] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406", "hxxp://google.com/" ]

*************************

AdwCleaner[R1].txt - [6053 octets] - [12/10/2012 00:37:24]

########## EOF - C:\AdwCleaner[R1].txt - [6113 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#4 Příspěvek od vyosek »

:arrow: Spustte znovu AdwCleaner
  • Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Delete
  • PC provede opravu, restartuje se a da Vam log (C:\AdwCleaner [S1].txt) , jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mary13
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 22 kvě 2009 12:15

Re: Prosím o kontrolu

#5 Příspěvek od Mary13 »

# AdwCleaner v2.004 - Logfile created 10/12/2012 at 09:31:48
# Updated 06/10/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Alexey - ALEXBG
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Alexey\Рабочий стол\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\DOCUME~1\Alexey\LOCALS~1\Temp\Searchqu.ini
File Deleted : C:\DOCUME~1\Alexey\LOCALS~1\Temp\searchqutoolbar-manifest.xml
File Deleted : C:\DOCUME~1\Alexey\LOCALS~1\Temp\SetupDataMngr_Searchqu.exe
File Deleted : C:\DOCUME~1\Alexey\LOCALS~1\Temp\Uninstall.exe
File Deleted : C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\searchplugins\Search_Results.xml
File Deleted : C:\Documents and Settings\All Users\Рабочий стол\Get The Best Facebook Chat Messenger.lnk
File Deleted : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml
Folder Deleted : C:\Documents and Settings\Alexey\Application Data\OpenCandy
Folder Deleted : C:\Documents and Settings\Alexey\Application Data\searchquband
Folder Deleted : C:\Documents and Settings\Alexey\Local Settings\Application Data\Ilivid Player
Folder Deleted : C:\Documents and Settings\Alexey\Local Settings\Application Data\OpenCandy
Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Deleted : C:\Program Files\Searchqu Toolbar

***** [Registry] *****

Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v3.6.13 (ru)

Profile name : default
File : C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\prefs.js

Deleted : user_pref("browser.search.selectedEngine", "Search Results");
Deleted : user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/406");
Deleted : user_pref("browser.search.defaultenginename", "Search Results");
Deleted : user_pref("browser.search.order.1", "Search Results");
Deleted : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&appid=488&systemid=406&sr=0&q=");

-\\ Google Chrome v22.0.1229.94

File : C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

Deleted [l.16] : homepage = "hxxp://www.searchnu.com/406",
Deleted [l.20] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406", "hxxp://google.com/" ]
Deleted [l.62] : search_url = "hxxp://dts.search-results.com/sr?src=crb&appid=488&systemid=406&sr=0&q={searchTerms}",
Deleted [l.1475] : homepage = "hxxp://www.searchnu.com/406",
Deleted [l.2213] : urls_to_restore_on_startup = [ "hxxp://www.searchnu.com/406", "hxxp://google.com/" ]

*************************

AdwCleaner[R1].txt - [6182 octets] - [12/10/2012 00:37:24]
AdwCleaner[S1].txt - [4128 octets] - [12/10/2012 09:31:48]

########## EOF - C:\AdwCleaner[S1].txt - [4188 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#6 Příspěvek od vyosek »

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    services.exe
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
  • Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku[
[/list]
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mary13
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 22 kvě 2009 12:15

Re: Prosím o kontrolu

#7 Příspěvek od Mary13 »

Logy už mám,ale přesně, jak píšete-jsou moc dlouhé a...já si jaksi nevím rady,jak to rozdělit...prosím prosím... :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#8 Příspěvek od vyosek »

Poslete mi jej na mail, ktery mam v podpise :wink:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mary13
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 22 kvě 2009 12:15

Re: Prosím o kontrolu

#9 Příspěvek od Mary13 »

Ok,je to :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#10 Příspěvek od vyosek »

Ja si je sem dam :James008:

OTL logfile created on: 15/10/2012 00:42:52 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Alexey\Рабочий стол
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: Великобритания | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.56 Gb Available Physical Memory | 28.07% Memory free
3.84 Gb Paging File | 2.05 Gb Available in Paging File | 53.31% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 21.50 Gb Free Space | 30.08% Space Free | Partition Type: NTFS
Drive D: | 151.42 Gb Total Space | 27.15 Gb Free Space | 17.93% Space Free | Partition Type: NTFS
Drive E: | 1021.00 Mb Total Space | 795.74 Mb Free Space | 77.94% Space Free | Partition Type: FAT32
Drive F: | 9.00 Gb Total Space | 3.29 Gb Free Space | 36.50% Space Free | Partition Type: NTFS

Computer Name: ALEXBG | User Name: Alexey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012/10/15 00:41:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Alexey\Рабочий стол\OTL.exe
PRC - [2012/10/10 12:06:17 | 001,239,064 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/04/24 23:15:02 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe
PRC - [2011/04/24 23:12:42 | 000,197,008 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbws.exe
PRC - [2011/04/24 23:12:42 | 000,131,472 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtblfs.exe
PRC - [2011/01/14 13:35:56 | 000,196,912 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
PRC - [2009/03/26 00:46:11 | 004,554,752 | ---- | M] () -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
PRC - [2009/02/09 13:25:55 | 000,111,104 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\services.exe
PRC - [2008/09/30 16:18:40 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2008/09/30 16:12:58 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2008/08/15 18:33:08 | 001,473,536 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\TO2SSM\McciTrayApp.exe
PRC - [2008/07/11 14:41:45 | 000,557,056 | ---- | M] (FinePrint Software, LLC) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\fpdisp6.exe
PRC - [2008/07/01 18:34:30 | 003,256,320 | ---- | M] (The Author of QIP) -- C:\Program Files\QIP\qip.exe
PRC - [2008/06/09 06:10:04 | 000,082,224 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\accelerometerST.exe
PRC - [2008/04/15 03:00:00 | 001,034,240 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/15 03:00:00 | 000,509,440 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\winlogon.exe
PRC - [2008/04/15 03:00:00 | 000,096,768 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\scardsvr.exe
PRC - [2008/04/15 03:00:00 | 000,050,688 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\smss.exe
PRC - [2008/03/31 14:32:42 | 000,576,104 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007/12/11 10:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2007/10/03 17:17:14 | 000,053,248 | ---- | M] (HP) -- C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe


========== Modules (No Company Name) ==========

MOD - [2012/10/10 12:06:15 | 000,460,312 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\ppgooglenaclpluginchrome.dll
MOD - [2012/10/10 12:06:13 | 012,435,992 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\PepperFlash\pepflashplayer.dll
MOD - [2012/10/10 12:06:12 | 004,005,912 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\pdf.dll
MOD - [2012/10/10 12:04:44 | 000,156,712 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\avutil-51.dll
MOD - [2012/10/10 12:04:43 | 000,275,496 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\avformat-54.dll
MOD - [2012/10/10 12:04:42 | 002,168,360 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\avcodec-54.dll
MOD - [2012/06/14 10:16:30 | 011,817,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll
MOD - [2012/06/14 10:15:15 | 001,801,216 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\7a53d68ad544f8e9edfdbd5a90a48fd3\System.Deployment.ni.dll
MOD - [2012/06/14 10:15:08 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012/06/14 10:14:54 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012/05/10 19:49:46 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\9080c8e8e7b6dfb502c1328673d636f8\System.Management.ni.dll
MOD - [2012/05/10 19:46:05 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 19:44:33 | 000,311,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a644ec04e18202b60f9d828bc207972b\System.Runtime.Serialization.Formatters.Soap.ni.dll
MOD - [2012/05/10 19:44:12 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012/05/10 19:44:07 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012/05/10 19:43:57 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012/05/10 19:43:31 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012/04/12 08:25:54 | 000,266,240 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.resources\2.0.0.0_ru_b77a5c561934e089\System.resources.dll
MOD - [2012/04/12 08:25:50 | 000,540,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_ru_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2012/04/12 08:25:48 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_ru_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2012/04/12 08:25:45 | 000,397,312 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_ru_b77a5c561934e089\mscorlib.resources.dll
MOD - [2012/03/26 21:47:33 | 000,016,832 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll
MOD - [2011/04/24 23:13:30 | 007,008,656 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\qtgui4.dll
MOD - [2011/04/24 23:13:28 | 000,192,912 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\qtsql4.dll
MOD - [2011/04/24 23:13:26 | 001,270,160 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\qtscript4.dll
MOD - [2011/04/24 23:13:26 | 000,758,160 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\qtnetwork4.dll
MOD - [2011/04/24 23:13:24 | 002,118,032 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\qtcore4.dll
MOD - [2011/04/24 23:13:24 | 002,089,360 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\qtdeclarative4.dll
MOD - [2011/04/20 19:56:28 | 000,025,088 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\imageformats\qgif4.dll
MOD - [2009/03/26 00:46:11 | 004,554,752 | ---- | M] () -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
MOD - [2008/10/14 05:50:11 | 000,753,664 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2008/10/14 05:50:11 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2008/10/09 09:16:02 | 001,679,360 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3050.37261__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2008/10/09 09:16:02 | 000,253,952 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3050.37221__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2008/10/09 09:16:02 | 000,196,608 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3050.37274__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2008/10/09 09:16:02 | 000,077,824 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3050.37446__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2008/10/09 09:16:02 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3050.37253__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2008/10/09 09:16:02 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3050.37370__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2008/10/09 09:16:02 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3050.37240__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2008/10/09 09:16:01 | 000,483,328 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3050.37475__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2008/10/09 09:16:01 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3050.37411__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:55 | 000,352,256 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3050.37419__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:55 | 000,139,264 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay4.Graphics.Dashboard\2.0.3050.37487__90ba9c70f846762e\CLI.Aspect.PowerPlay4.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:55 | 000,135,168 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3050.37482__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:55 | 000,102,400 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3050.37267__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:55 | 000,090,112 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3050.37425__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2008/10/09 09:15:55 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3050.37234__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:55 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3050.37418__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:55 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay4.Graphics.Runtime\2.0.3050.37487__90ba9c70f846762e\CLI.Aspect.PowerPlay4.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:55 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3050.37267__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,802,816 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3050.37378__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,585,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3050.37287__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,479,232 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3050.37372__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,438,272 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3050.37241__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,401,408 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3050.37438__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2008/10/09 09:15:54 | 000,401,408 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3050.37405__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,307,200 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3050.37293__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2008/10/09 09:15:54 | 000,217,088 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3050.37281__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,118,784 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3050.37393__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2008/10/09 09:15:54 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3050.37378__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3050.37371__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.2939.23668__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2008/10/09 09:15:54 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2008/10/09 09:15:54 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3050.37292__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3050.37377__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,036,864 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3050.37392__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.2939.23662__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2008/10/09 09:15:54 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3050.37404__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2008/10/09 09:15:54 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2939.23802__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2008/10/09 09:15:54 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2939.23667__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2008/10/09 09:15:54 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2939.23717__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2008/10/09 09:15:54 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2939.23687__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2008/10/09 09:15:54 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2939.23679__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.2939.23707__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.2939.23717__90ba9c70f846762e\DEM.OS.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.2939.23718__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2939.23767__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2939.23710__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2008/10/09 09:15:54 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2939.23768__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2008/10/09 09:15:54 | 000,006,656 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2008/10/09 09:15:53 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2965.22300__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2939.23689__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2939.23743__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2939.23739__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,049,152 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2939.23740__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2939.23738__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2939.23764__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2939.23742__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2939.23708__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay4.Graphics.Shared\2.0.2939.23766__90ba9c70f846762e\CLI.Aspect.PowerPlay4.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2939.23735__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,028,672 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2939.23719__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2939.23741__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2939.23711__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Foundation\2.0.2939.23665__90ba9c70f846762e\AEM.Foundation.dll
MOD - [2008/10/09 09:15:53 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2939.23693__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2939.23687__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2939.23679__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.2939.23735__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2939.23719__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.2939.23709__90ba9c70f846762e\APM.Foundation.dll
MOD - [2008/10/09 09:15:53 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2939.23688__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2939.23734__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2939.23718__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2008/10/09 09:15:53 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2939.23687__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2008/10/09 09:15:51 | 000,491,520 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3050.37248__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2008/10/09 09:15:51 | 000,102,400 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3050.37467__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2008/10/09 09:15:51 | 000,061,440 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3050.37466__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2008/10/09 09:15:51 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2939.23713__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2008/10/09 09:15:51 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2939.23678__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2008/10/09 09:15:51 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3050.37493__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2008/10/09 09:15:51 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2939.23679__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2008/10/09 09:15:51 | 000,024,576 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2939.23694__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2008/10/09 09:15:51 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2939.23712__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2008/10/09 09:15:51 | 000,016,384 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.2939.23677__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll
MOD - [2008/10/09 09:15:51 | 000,006,656 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3050.37214__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2008/10/09 09:15:50 | 001,511,424 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3050.37228__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2008/10/09 09:15:50 | 000,073,728 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3050.37214__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2008/10/09 09:15:50 | 000,065,536 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3050.37215__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2008/10/09 09:15:50 | 000,053,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3050.37213__90ba9c70f846762e\APM.Server.dll
MOD - [2008/10/09 09:15:50 | 000,045,056 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3050.37213__90ba9c70f846762e\AEM.Server.dll
MOD - [2008/10/09 09:15:50 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2939.23689__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2008/10/09 09:15:50 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3050.37467__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2008/10/09 09:15:50 | 000,032,768 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2008/10/09 09:15:50 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2939.23711__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2008/10/09 09:15:50 | 000,020,480 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2939.23746__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2008/07/29 12:55:14 | 000,969,728 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2008/04/15 03:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/03/31 14:30:34 | 002,842,624 | ---- | M] () -- C:\WINDOWS\system32\btwicons.dll
MOD - [2008/03/31 14:28:26 | 000,040,960 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2008/02/04 11:29:02 | 000,688,128 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
MOD - [2007/10/03 17:16:58 | 000,102,400 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\HPFaxUtilities.dll
MOD - [2007/10/03 17:16:56 | 000,573,440 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\Alerts.dll
MOD - [2007/10/03 17:16:28 | 000,434,176 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\HPAppTools.dll
MOD - [2007/10/03 17:16:24 | 000,069,632 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\AppConstants.dll
MOD - [2007/10/03 17:16:20 | 000,040,960 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\Enumeration.dll
MOD - [2007/10/03 17:16:20 | 000,032,768 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\NamedPipeChannel.dll
MOD - [2007/10/03 17:16:18 | 000,122,880 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\HPToolkit.dll
MOD - [2007/10/03 17:16:14 | 000,016,384 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\HPStreamsInterface.dll
MOD - [2007/10/03 17:16:12 | 000,069,632 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\HPTools.dll
MOD - [2007/10/03 17:15:34 | 000,069,632 | ---- | M] () -- C:\Program Files\HP\ToolboxFX\bin\NativeUtils.dll
MOD - [2007/09/21 01:07:10 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2006/09/10 13:37:36 | 000,061,440 | ---- | M] () -- C:\Program Files\QIP\Plugins\docking.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Disabled | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/04/24 23:15:02 | 000,202,296 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe -- (AVP)
SRV - [2011/01/14 13:35:56 | 000,196,912 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe -- (NitroReaderDriverReadSpool)
SRV - [2009/07/28 01:19:10 | 000,135,680 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (Themes)
SRV - [2009/07/28 01:19:10 | 000,135,680 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (ShellHWDetection)
SRV - [2009/07/28 01:19:10 | 000,135,680 | ---- | M] (Корпорация Майкрософт) [On_Demand | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (FastUserSwitchingCompatibility)
SRV - [2009/04/20 19:19:45 | 000,045,568 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\dnsrslvr.dll -- (Dnscache)
SRV - [2009/03/26 00:46:11 | 004,554,752 | ---- | M] () [Auto | Running] -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe -- (MySQL)
SRV - [2009/02/09 13:25:55 | 000,111,104 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\services.exe -- (PlugPlay)
SRV - [2009/02/09 13:25:55 | 000,111,104 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\services.exe -- (Eventlog)
SRV - [2009/02/09 12:54:17 | 000,687,616 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\advapi32.dll -- (Wmi)
SRV - [2008/10/09 08:11:46 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/07/11 14:41:45 | 000,557,056 | ---- | M] (FinePrint Software, LLC) [Auto | Running] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp6.exe -- (FinePrint Диспетчер v6)
SRV - [2008/06/20 18:04:16 | 000,247,296 | ---- | M] (Корпорация Майкрософт) [On_Demand | Running] -- C:\WINDOWS\system32\mswsock.dll -- (Nla)
SRV - [2008/04/15 14:00:00 | 000,409,088 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\qmgr.dll -- (BITS)
SRV - [2008/04/15 14:00:00 | 000,295,936 | ---- | M] (Корпорация Майкрософт) [On_Demand | Running] -- C:\WINDOWS\system32\termsrv.dll -- (TermService)
SRV - [2008/04/15 14:00:00 | 000,193,024 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\schedsvc.dll -- (Schedule)
SRV - [2008/04/15 14:00:00 | 000,171,008 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\srsvc.dll -- (srservice)
SRV - [2008/04/15 14:00:00 | 000,145,408 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\wbem\wmisvc.dll -- (winmgmt)
SRV - [2008/04/15 14:00:00 | 000,141,824 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\sessmgr.exe -- (RDSessMgr)
SRV - [2008/04/15 14:00:00 | 000,126,464 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\wbem\wmiapsrv.exe -- (WmiApSrv)
SRV - [2008/04/15 03:00:00 | 000,483,840 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\wzcsvc.dll -- (WZCSVC)
SRV - [2008/04/15 03:00:00 | 000,436,736 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\ntmssvc.dll -- (NtmsSvc)
SRV - [2008/04/15 03:00:00 | 000,333,824 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\wiaservc.dll -- (stisvc)
SRV - [2008/04/15 03:00:00 | 000,331,264 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\ipnathlp.dll -- (SharedAccess)
SRV - [2008/04/15 03:00:00 | 000,290,304 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\vssvc.exe -- (VSS)
SRV - [2008/04/15 03:00:00 | 000,249,856 | ---- | M] (Корпорация Майкрософт) [On_Demand | Running] -- C:\WINDOWS\system32\tapisrv.dll -- (TapiSrv)
SRV - [2008/04/15 03:00:00 | 000,198,144 | ---- | M] (Корпорация Майкрософт) [On_Demand | Running] -- C:\WINDOWS\system32\netman.dll -- (Netman)
SRV - [2008/04/15 03:00:00 | 000,186,368 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\upnphost.dll -- (upnphost)
SRV - [2008/04/15 03:00:00 | 000,175,616 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\w32time.dll -- (W32Time)
SRV - [2008/04/15 03:00:00 | 000,171,008 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\appmgmts.dll -- (AppMgmt)
SRV - [2008/04/15 03:00:00 | 000,150,528 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\imapi.exe -- (ImapiService)
SRV - [2008/04/15 03:00:00 | 000,126,464 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\dhcpcsvc.dll -- (Dhcp)
SRV - [2008/04/15 03:00:00 | 000,113,664 | ---- | M] (Корпорация Майкрософт) [Disabled | Stopped] -- C:\WINDOWS\system32\netdde.exe -- (NetDDEdsdm)
SRV - [2008/04/15 03:00:00 | 000,113,664 | ---- | M] (Корпорация Майкрософт) [Disabled | Stopped] -- C:\WINDOWS\system32\netdde.exe -- (NetDDE)
SRV - [2008/04/15 03:00:00 | 000,096,768 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\scardsvr.exe -- (SCardSvr)
SRV - [2008/04/15 03:00:00 | 000,091,648 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\smlogsvc.exe -- (SysmonLog)
SRV - [2008/04/15 03:00:00 | 000,073,216 | ---- | M] (Корпорация Майкрософт) [On_Demand | Stopped] -- C:\WINDOWS\system32\tlntsvr.exe -- (TlntSvr)
SRV - [2008/04/15 03:00:00 | 000,024,064 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\dmserver.dll -- (dmserver)
SRV - [2008/04/15 03:00:00 | 000,018,944 | ---- | M] (Корпорация Майкрософт) [Auto | Running] -- C:\WINDOWS\system32\seclogon.dll -- (seclogon)
SRV - [2007/12/11 10:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\net6im51.sys -- (Net6IM)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS -- (MRESP50a64)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS -- (MREMP50a64)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Alexey\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2011/12/28 16:21:44 | 000,066,944 | ---- | M] (TOSHIBA Corporation) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\thdudf.sys -- (thdudf)
DRV - [2011/12/08 06:22:26 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/12/08 06:22:26 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011/12/08 06:22:26 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011/10/25 00:00:27 | 000,565,552 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2011/03/10 18:34:46 | 000,034,608 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2011/03/04 13:23:20 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2011/03/04 13:23:14 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (KL1)
DRV - [2009/11/02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009/08/15 21:20:38 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009/05/20 10:33:04 | 000,061,568 | ---- | M] (Silicon Laboratories) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\silabser.sys -- (silabser)
DRV - [2009/05/20 10:33:04 | 000,017,920 | ---- | M] (Silicon Laboratories, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\silabenm.sys -- (silabenm)
DRV - [2009/03/27 06:48:22 | 001,810,992 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2uvc.sys -- (SNP2UVC)
DRV - [2008/11/21 21:53:40 | 001,204,128 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/11/17 15:23:16 | 003,636,864 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32)
DRV - [2008/10/09 07:48:13 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2008/08/19 22:15:48 | 000,058,368 | ---- | M] (Корпорация Майкрософт) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\redbook.sys -- (redbook)
DRV - [2008/05/23 11:51:02 | 000,024,624 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\hpdskflt.sys -- (hpdskflt)
DRV - [2008/05/23 11:50:16 | 000,028,592 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2008/05/08 23:00:00 | 002,880,512 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008/04/29 10:00:00 | 000,288,896 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2008/04/15 14:00:00 | 000,073,472 | ---- | M] (Корпорация Майкрософт) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\sr.sys -- (sr)
DRV - [2008/04/15 03:00:00 | 000,188,288 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\acpi.sys -- (ACPI)
DRV - [2008/04/15 03:00:00 | 000,125,440 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\ftdisk.sys -- (Ftdisk)
DRV - [2008/04/15 03:00:00 | 000,120,192 | ---- | M] (Корпорация Майкрософт) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\pcmcia.sys -- (Pcmcia)
DRV - [2008/04/15 03:00:00 | 000,080,128 | ---- | M] (Корпорация Майкрософт) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\parport.sys -- (Parport)
DRV - [2008/04/15 03:00:00 | 000,068,480 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pci.sys -- (PCI)
DRV - [2008/04/15 03:00:00 | 000,065,024 | ---- | M] (Корпорация Майкрософт) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\serial.sys -- (Serial)
DRV - [2008/04/15 03:00:00 | 000,051,968 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\volsnap.sys -- (VolSnap)
DRV - [2008/04/15 03:00:00 | 000,044,544 | ---- | M] (Корпорация Майкрософт) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\fips.sys -- (Fips)
DRV - [2008/04/15 03:00:00 | 000,037,504 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\isapnp.sys -- (isapnp)
DRV - [2008/04/15 03:00:00 | 000,030,208 | ---- | M] (Корпорация Майкрософт) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\modem.sys -- (Modem)
DRV - [2008/04/15 03:00:00 | 000,024,832 | ---- | M] (Корпорация Майкрософт) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kbdclass.sys -- (Kbdclass)
DRV - [2008/04/15 03:00:00 | 000,014,720 | ---- | M] (Корпорация Майкрософт) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid)
DRV - [2008/04/15 03:00:00 | 000,012,160 | ---- | M] (Корпорация Майкрософт) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mouhid.sys -- (mouhid)
DRV - [2008/04/15 03:00:00 | 000,011,776 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\acpiec.sys -- (ACPIEC)
DRV - [2008/04/15 03:00:00 | 000,006,912 | ---- | M] (Корпорация Майкрософт) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\parvdm.sys -- (ParVdm)
DRV - [2008/04/15 03:00:00 | 000,003,328 | ---- | M] (Корпорация Майкрософт) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pciide.sys -- (PCIIde)
DRV - [2008/04/14 21:14:10 | 000,053,120 | ---- | M] (Корпорация Майкрософт) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\i8042prt.sys -- (i8042prt)
DRV - [2008/04/14 21:07:44 | 000,023,296 | ---- | M] (Корпорация Майкрософт) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mouclass.sys -- (Mouclass)
DRV - [2008/04/03 14:40:44 | 000,879,624 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008/04/03 14:40:44 | 000,074,688 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008/03/29 11:20:55 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2008/03/29 11:20:55 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008/03/28 08:14:02 | 000,024,064 | ---- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfaudio.sys -- (SFAUDIO)
DRV - [2007/07/16 23:29:43 | 000,020,504 | ---- | M] (Hewlett Packard) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hpfxfax.sys -- (HPFXFAX)
DRV - [2007/07/16 23:29:33 | 000,017,432 | R--- | M] (Hewlett Packard) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hpfxbulk.sys -- (HPFXBULK)
DRV - [2007/06/21 02:40:02 | 000,056,448 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys -- (SCR3XX2K)
DRV - [2005/09/19 10:24:20 | 000,005,760 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)
DRV - [2005/09/19 10:24:10 | 000,009,344 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2005/09/19 10:23:52 | 000,007,808 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\SearchScopes,DefaultScope = {8F3F980C-8561-4D4D-B860-8E6D1B225F1A}
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\SearchScopes\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}: "URL" = http://www.google.co.uk/search?hl=en&q= ... 1I7ADFA_ru
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}: "URL" = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.155:3128

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: true
FF - prefs.js..browser.search.defaulturl: "http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.463
FF - prefs.js..extensions.enabledItems: {54BB9F3F-07E5-486c-9B39-C7398B99391C}:4.0.2011021601
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8153
FF - prefs.js..extensions.enabledItems: {81514210-E22A-4e69-93D5-E1EFD45B4620}:0.3.10.01.23
FF - prefs.js..network.proxy.ftp: "192.168.1.155"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "192.168.1.155"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "192.168.1.155"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.1.155"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "192.168.1.155"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@software602.cz/602XML Filler: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Alexey\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\linkfilter@kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\FFExt\linkfilter@kaspersky.ru [2012/09/03 14:32:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtualKeyboard@kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\FFExt\virtualKeyboard@kaspersky.ru [2012/09/03 14:32:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/11 22:38:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/11 22:39:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\THBExt

[2012/10/12 00:59:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Extensions
[2012/10/12 00:59:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions
[2011/02/18 18:16:10 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2011/02/18 18:16:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/03 19:28:05 | 000,000,000 | ---D | M] (Спутник @Mail.Ru) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D}
[2011/02/18 18:16:06 | 000,000,000 | ---D | M] (Flashblock) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/05/27 14:47:49 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2011/02/18 18:16:06 | 000,000,000 | ---D | M] ("Text Link") -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{54BB9F3F-07E5-486c-9B39-C7398B99391C}
[2011/02/18 18:16:09 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/27 14:47:49 | 000,000,000 | ---D | M] (IE Tab) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2011/02/18 18:15:37 | 000,000,000 | ---D | M] (Past Modern) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{81514210-E22A-4e69-93D5-E1EFD45B4620}
[2010/05/27 14:47:49 | 000,000,000 | ---D | M] (MR Tech Toolkit) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}
[2011/02/18 18:16:12 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/18 18:15:40 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/02/18 18:16:07 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/02/18 18:15:40 | 000,000,000 | ---D | M] (Element Hiding Helper for Adblock Plus) -- C:\Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\elemhidehelper@adblockplus.org
[2012/10/12 00:59:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/24 23:40:56 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2009/10/07 00:28:53 | 000,000,000 | ---D | M] (Модуль проверки ссылок) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2011/01/25 01:28:39 | 000,005,568 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\ozonru.xml
[2011/01/25 01:28:39 | 000,001,122 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\priceru.xml
[2011/01/25 01:28:39 | 000,001,945 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\torgmailru.xml
[2011/01/25 01:28:39 | 000,001,304 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-ru.xml
[2011/01/25 01:28:39 | 000,001,384 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yandex-slovari.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=cr ... earchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Alexey\Application Data\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: \u041C\u043E\u0434\u0443\u043B\u044C \u043F\u0440\u043E\u0432\u0435\u0440\u043A\u0438 \u0441\u0441\u044B\u043B\u043E\u043A = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.477_0\
CHR - Extension: \u0412\u0438\u0440\u0442\u0443\u0430\u043B\u044C\u043D\u0430\u044F \u043A\u043B\u0430\u0432\u0438\u0430\u0442\u0443\u0440\u0430 = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.477_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: \u0410\u043D\u0442\u0438-\u0411\u0430\u043D\u043D\u0435\u0440 = C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\

O1 HOSTS File: ([2010/08/13 21:01:54 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\Toolbar\ShellBrowser: (&Ŕäđĺń) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O3 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\Toolbar\WebBrowser: (&Ŕäđĺń) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O3 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\Toolbar\WebBrowser: (&Ńńűëęč) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\accelerometerST.exe (Hewlett-Packard Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKU\.DEFAULT..\Run: [VistaIcon] C:\Program Files\VistaDriveIcon\VistaDrv.exe ()
O4 - HKU\S-1-5-18..\Run: [VistaIcon] C:\Program Files\VistaDriveIcon\VistaDrv.exe ()
O4 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005..\Run: [Facebook Update] C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [IE7_011] regsvr32 /s /n /i:u shell32 File not found
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [IE7_011] regsvr32 /s /n /i:u shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - Startup: C:\Documents and Settings\Alexey\Главное меню\Программы\Автозагрузка\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: &Виртуальная клавиатура - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Проверка ссы&лок - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
O15 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..Trusted Domains: microsoft.com ([www.update] http in Надежные узлы)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 1740976578 (WUWebControl Class)
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} https://www.mojedatovaschranka.cz/stati ... ?3,16,13,0 (Active602XMLFiller Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 5862975187 (MUWebControl Class)
O16 - DPF: {7E0FDFBB-87D4-43A1-9AD4-41F0EA8AFF7B} https://portti1.deltamotor.fi/net6helper.cab (Net6Launcher Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ADADFC48-EC90-4B34-B1D1-121AA857DA83}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Корпорация Майкрософт)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Корпорация Майкрософт)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Корпорация Майкрософт)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Корпорация Майкрософт)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Корпорация Майкрософт)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Корпорация Майкрософт)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Корпорация Майкрософт)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - C:\WINDOWS\System32\WgaLogon.dll (Корпорация Майкрософт)
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Корпорация Майкрософт)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Корпорация Майкрософт)
O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Корпорация Майкрософт)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Ďđĺäçŕăđóç÷čę Browseui - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Äĺěîí ęýřŕ ęŕňĺăîđčé ęîěďîíĺíňîâ - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O24 - Desktop Components:0 (Моя текущая домашняя страница) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Безмятежность.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Безмятежность.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Корпорация Майкрософт)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Корпорация Майкрософт)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/09/04 17:18:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#11 Příspěvek od vyosek »

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\system32\appmgmts.dll (Корпорация Майкрософт)
NetSvcs: DMServer - C:\WINDOWS\system32\dmserver.dll (Корпорация Майкрософт)
NetSvcs: DHCP - C:\WINDOWS\system32\dhcpcsvc.dll (Корпорация Майкрософт)
NetSvcs: FastUserSwitchingCompatibility - C:\WINDOWS\system32\shsvcs.dll (Корпорация Майкрософт)
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Netman - C:\WINDOWS\system32\netman.dll (Корпорация Майкрософт)
NetSvcs: Nla - C:\WINDOWS\system32\mswsock.dll (Корпорация Майкрософт)
NetSvcs: Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll (Корпорация Майкрософт)
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Schedule - C:\WINDOWS\system32\schedsvc.dll (Корпорация Майкрософт)
NetSvcs: Seclogon - C:\WINDOWS\system32\seclogon.dll (Корпорация Майкрософт)
NetSvcs: Sharedaccess - C:\WINDOWS\system32\ipnathlp.dll (Корпорация Майкрософт)
NetSvcs: SRService - C:\WINDOWS\system32\srsvc.dll (Корпорация Майкрософт)
NetSvcs: Tapisrv - C:\WINDOWS\system32\tapisrv.dll (Корпорация Майкрософт)
NetSvcs: Themes - C:\WINDOWS\system32\shsvcs.dll (Корпорация Майкрософт)
NetSvcs: W32Time - C:\WINDOWS\system32\w32time.dll (Корпорация Майкрософт)
NetSvcs: WZCSVC - C:\WINDOWS\system32\wzcsvc.dll (Корпорация Майкрософт)
NetSvcs: Wmi - C:\WINDOWS\system32\advapi32.dll (Корпорация Майкрософт)
NetSvcs: WmdmPmSp - File not found
NetSvcs: winmgmt - C:\WINDOWS\system32\wbem\wmisvc.dll (Корпорация Майкрософт)
NetSvcs: ShellHWDetection - C:\WINDOWS\system32\shsvcs.dll (Корпорация Майкрософт)
NetSvcs: BITS - C:\WINDOWS\system32\qmgr.dll (Корпорация Майкрософт)

Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Корпорация Майкрософт)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Корпорация Майкрософт)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Корпорация Майкрософт)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Корпорация Майкрософт)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Корпорация Майкрософт)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Корпорация Майкрософт)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Корпорация Майкрософт)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Корпорация Майкрософт)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Корпорация Майкрософт)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Корпорация Майкрософт)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (http://www.helixcommunity.org)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Корпорация Майкрософт)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012/10/15 00:40:56 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Alexey\Рабочий стол\OTL.exe
[2012/10/08 17:12:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Alexey\AppData
[2010/12/05 20:51:43 | 001,266,714 | ---- | C] (Citrix Systems, Inc.) -- C:\Documents and Settings\Alexey\Application Data\CitrixSAClient.exe
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2012/10/15 00:47:06 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012/10/15 00:41:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Alexey\Рабочий стол\OTL.exe
[2012/10/15 00:29:00 | 000,000,956 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/15 00:15:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
[2012/10/14 22:52:01 | 000,001,000 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
[2012/10/14 19:52:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
[2012/10/13 14:22:48 | 002,460,303 | ---- | M] () -- C:\Documents and Settings\Alexey\Рабочий стол\P1110074.JPG
[2012/10/13 14:22:29 | 002,876,259 | ---- | M] () -- C:\Documents and Settings\Alexey\Рабочий стол\P1110073.JPG
[2012/10/13 11:15:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
[2012/10/13 09:29:00 | 000,000,952 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/12 09:38:45 | 000,555,426 | ---- | M] () -- C:\WINDOWS\System32\perfh019.dat
[2012/10/12 09:38:45 | 000,486,680 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/10/12 09:38:45 | 000,107,822 | ---- | M] () -- C:\WINDOWS\System32\perfc019.dat
[2012/10/12 09:38:45 | 000,082,486 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/10/12 09:34:43 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/10/12 09:34:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/12 00:48:17 | 000,091,648 | ---- | M] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/12 00:36:49 | 000,538,327 | ---- | M] () -- C:\Documents and Settings\Alexey\Рабочий стол\adwcleaner.exe
[2012/10/11 09:47:51 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/10/11 00:17:13 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\Alexey\Рабочий стол\Google Chrome.lnk
[2012/10/11 00:17:13 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/10/10 19:30:16 | 001,784,730 | ---- | M] () -- C:\Documents and Settings\Alexey\Рабочий стол\liklikk — «Нам сверху видно все_» на Яндекс_Фотках.mht
[2012/10/10 19:27:58 | 000,384,170 | ---- | M] () -- C:\Documents and Settings\Alexey\Рабочий стол\0_88f7e_176b3798_XXXL.jpg
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/15 00:47:06 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012/10/13 14:22:40 | 002,460,303 | ---- | C] () -- C:\Documents and Settings\Alexey\Рабочий стол\P1110074.JPG
[2012/10/13 14:22:19 | 002,876,259 | ---- | C] () -- C:\Documents and Settings\Alexey\Рабочий стол\P1110073.JPG
[2012/10/12 00:36:49 | 000,538,327 | ---- | C] () -- C:\Documents and Settings\Alexey\Рабочий стол\adwcleaner.exe
[2012/10/10 19:30:14 | 001,784,730 | ---- | C] () -- C:\Documents and Settings\Alexey\Рабочий стол\liklikk — «Нам сверху видно все_» на Яндекс_Фотках.mht
[2012/10/10 19:27:38 | 000,384,170 | ---- | C] () -- C:\Documents and Settings\Alexey\Рабочий стол\0_88f7e_176b3798_XXXL.jpg
[2012/04/12 12:05:56 | 000,538,560 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1123561945-630328440-1417001333-1005-0.dat
[2012/04/12 12:05:54 | 000,413,590 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/04/11 11:33:37 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\fusioncache.dat
[2012/04/10 20:41:46 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\syn4635ky.dll
[2012/04/10 20:41:46 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msr8702ty.sys
[2012/04/08 12:57:24 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2012/02/16 21:56:18 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/31 01:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012/01/31 01:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012/01/31 01:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012/01/31 01:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2011/10/25 00:03:37 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\WebpageIcons.db
[2011/09/04 18:11:24 | 000,153,526 | ---- | C] () -- C:\WINDOWS\hppins08.dat
[2011/09/04 18:11:24 | 000,153,503 | ---- | C] () -- C:\WINDOWS\System32\hppins08.dat
[2011/09/04 18:11:24 | 000,001,116 | ---- | C] () -- C:\WINDOWS\hppmdl08.dat
[2011/09/04 18:05:05 | 000,000,316 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2011/08/13 14:27:23 | 000,000,604 | -H-- | C] () -- C:\Program Files\STLL Notifier
[2010/10/25 22:45:42 | 000,116,189 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010/10/25 22:45:42 | 000,098,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2009/08/15 21:21:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2008/10/10 01:19:23 | 000,091,648 | ---- | C] () -- C:\Documents and Settings\Alexey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/09 08:04:56 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\Alexey\PocketDivXEncoder.lnk

========== ZeroAccess Check ==========

[2008/10/09 07:45:48 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/15 03:00:00 | 001,499,136 | ---- | M] (Корпорация Майкрософт)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 12:54:16 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/15 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/05/03 20:46:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\602Installer
[2011/04/01 21:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\602XML
[2008/10/10 15:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\AWR
[2010/01/22 14:55:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Duncan Amplification
[2012/04/08 16:57:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\DVD Catalyst
[2010/02/22 12:56:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Facebook
[2011/09/01 17:25:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\FlexRadio Systems
[2012/04/09 21:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\FreeVideoConverter
[2012/10/10 21:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Nitro PDF
[2008/12/12 13:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\OpenOffice.org
[2012/05/08 23:53:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\PhotoScape
[2011/09/03 11:16:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Radmin
[2012/04/14 00:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Samsung
[2012/04/11 09:30:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\SolidDocuments
[2012/09/30 21:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\uTorrent
[2012/04/11 01:06:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Windows Desktop Search
[2010/12/28 22:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\XnView
[2012/06/05 10:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Yandex
[2008/12/20 14:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Advanced Chemistry Development
[2008/10/10 15:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AWR
[2008/10/14 06:00:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/09/05 21:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Media Get LLC
[2011/04/10 20:20:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2012/04/14 00:04:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2010/11/30 11:19:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Splan70
[2008/10/09 08:05:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2012/07/12 20:43:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/09/04 18:19:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zvprt50
[2010/04/03 14:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/25 22:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2012/06/03 19:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\{DCD48218-E972-4d0c-9E5F-43462BC13E3B}

========== Purity Check ==========



========== Custom Scans ==========

< >
[2008/10/09 07:43:10 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2008/10/09 07:51:25 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2010/07/06 12:34:07 | 000,000,952 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2010/07/06 12:34:08 | 000,000,956 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2011/09/03 10:40:57 | 000,000,930 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
[2011/09/03 10:40:59 | 000,000,982 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
[2011/11/09 23:42:00 | 000,000,978 | ---- | C] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
[2011/11/09 23:42:01 | 000,001,000 | ---- | C] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job

< >

< MD5 for: ATAPI.SYS >
[2008/04/15 03:00:00 | 020,118,444 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/19 22:15:48 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/15 03:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008/04/15 14:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=1504E93546B93A18F263485C58262897 -- C:\cmdcons\autochk.exe
[2008/04/15 03:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=1504E93546B93A18F263485C58262897 -- C:\WINDOWS\system32\autochk.exe
[2008/04/15 03:00:00 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=1504E93546B93A18F263485C58262897 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008/04/15 03:00:00 | 020,118,444 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008/04/15 03:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2008/04/15 03:00:00 | 001,034,240 | ---- | M] (Корпорация Майкрософт) MD5=847C01CA71883702CC7445364DD9D097 -- C:\WINDOWS\explorer.exe
[2008/04/15 03:00:00 | 001,034,240 | ---- | M] (Корпорация Майкрософт) MD5=847C01CA71883702CC7445364DD9D097 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2008/04/15 03:00:00 | 020,118,444 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008/04/15 03:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll

< MD5 for: SCECLI.DLL >
[2008/04/15 14:00:00 | 000,184,832 | ---- | M] (Корпорация Майкрософт) MD5=04423B01963ECF4BEEC4BD26A740D809 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/15 03:00:00 | 000,184,832 | ---- | M] (Корпорация Майкрософт) MD5=04423B01963ECF4BEEC4BD26A740D809 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009/02/09 13:18:41 | 000,111,104 | ---- | M] (Корпорация Майкрософт) MD5=0AF0D6AF45220ADB9C30B33CFEC41831 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/09 13:18:41 | 000,111,104 | ---- | M] (Корпорация Майкрософт) MD5=0AF0D6AF45220ADB9C30B33CFEC41831 -- C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/09 13:25:55 | 000,111,104 | ---- | M] (Корпорация Майкрософт) MD5=94824EEFEBE244036335E644EB5FF3AC -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/09 13:25:55 | 000,111,104 | ---- | M] (Корпорация Майкрософт) MD5=94824EEFEBE244036335E644EB5FF3AC -- C:\WINDOWS\system32\services.exe
[2008/04/15 03:00:00 | 000,109,056 | ---- | M] (Корпорация Майкрософт) MD5=AE5D25E59BC5D193ADD3DBF01864BDC5 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe

< MD5 for: SVCHOST.EXE >
[2008/04/15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=E948A9079D0E6350BE92D4D3E0077F81 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/15 03:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=E948A9079D0E6350BE92D4D3E0077F81 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008/04/15 03:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys
[2008/06/20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008/06/20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008/06/20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008/04/15 14:00:00 | 000,026,624 | ---- | M] (Корпорация Майкрософт) MD5=4F88778DD0CD6B99FCDA408E16B36AE7 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/15 03:00:00 | 000,026,624 | ---- | M] (Корпорация Майкрософт) MD5=4F88778DD0CD6B99FCDA408E16B36AE7 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/15 14:00:00 | 000,509,440 | ---- | M] (Корпорация Майкрософт) MD5=B3B5D5855127E240C88451030AAEE76E -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/15 03:00:00 | 000,509,440 | ---- | M] (Корпорация Майкрософт) MD5=B3B5D5855127E240C88451030AAEE76E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/15 03:00:00 | 000,509,440 | ---- | M] (Корпорация Майкрософт) MD5=B3B5D5855127E240C88451030AAEE76E -- C:\WINDOWS\system32\winlogon.exe

< >

< %systemroot%*.* /U /s >
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\inf\*.tmp files -> C:\WINDOWS\inf\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\system32\config\systemprofile\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\*.tmp -> ]
[768 C:\WINDOWS\temp\*.tmp files -> C:\WINDOWS\temp\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >
[2012/04/11 00:13:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/12/20 14:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Advanced Chemistry Development
[2012/04/08 11:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2012/04/12 10:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/09 09:17:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI
[2008/10/10 15:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AWR
[2008/10/10 17:24:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2012/10/12 00:53:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2011/09/04 18:22:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2008/10/21 22:29:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP
[2011/09/04 18:21:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2012/10/14 23:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2011/10/24 23:31:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2008/10/14 06:00:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2008/10/09 07:58:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macromedia
[2011/03/28 00:26:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011/09/05 21:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Media Get LLC
[2012/04/11 01:05:50 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/10/20 12:36:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2011/04/10 20:20:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2008/10/09 08:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Real
[2012/04/14 00:04:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2011/08/13 14:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sibelius Software
[2012/08/28 10:11:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2011/07/28 22:18:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype Extras
[2010/11/30 11:19:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Splan70
[2008/10/09 08:05:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2012/07/12 20:43:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/20 07:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2011/09/04 18:19:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zvprt50
[2010/04/03 14:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/25 22:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}

< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.4\ARM\15113\AcrobatUpdater.exe
[2012/01/03 09:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.4\ARM\15113\AdobeARM.exe
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.4\ARM\15113\AdobeARMHelper.exe
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.4\ARM\15113\ReaderUpdater.exe
[2012/01/03 19:46:15 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1029-7B44-A95000000001}\Setup.exe
[2011/08/22 21:11:47 | 000,527,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\All Users\Application Data\Google\Google Toolbar\Update\GoogleToolbarInstaller_updater_signed.exe
[2008/07/29 18:34:12 | 000,070,976 | ---- | M] (Лаборатория Касперского) -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\Russian\setup.exe
[2011/10/25 00:31:01 | 000,065,840 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP12\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav12\12.0.0.374\patch_a.exe
[2012/02/21 21:41:48 | 000,057,648 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP12\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav12\12.0.0.374\patch_h.exe
[2012/05/04 18:47:52 | 000,057,648 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP12\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav12\12.0.0.374\patch_i.exe

< %APPDATA%\*. >
[2011/05/03 20:46:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\602Installer
[2011/04/01 21:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\602XML
[2011/04/13 23:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Adobe
[2012/04/08 12:21:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Apple Computer
[2008/10/10 01:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\ATI
[2008/10/10 15:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\AWR
[2008/10/10 01:19:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\DivX
[2010/01/22 14:55:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Duncan Amplification
[2012/04/08 16:57:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\DVD Catalyst
[2010/02/22 12:56:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Facebook
[2011/09/01 17:25:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\FlexRadio Systems
[2012/04/09 21:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\FreeVideoConverter
[2011/08/20 09:35:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Google
[2010/01/24 18:22:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Help
[2011/09/04 18:22:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\HP
[2008/10/10 01:16:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Identities
[2008/10/14 05:50:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\InstallShield
[2011/09/01 10:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Macromedia
[2011/10/07 18:31:19 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Alexey\Application Data\Microsoft
[2008/10/20 12:44:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Motive
[2008/10/10 11:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Mozilla
[2008/10/14 05:38:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Nero
[2012/10/10 21:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Nitro PDF
[2008/12/12 13:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\OpenOffice.org
[2012/05/08 23:53:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\PhotoScape
[2010/09/21 13:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\PSpad
[2011/09/03 11:16:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Radmin
[2008/10/24 11:34:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Real
[2012/04/14 00:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Samsung
[2011/08/13 14:27:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Sibelius Software
[2012/10/15 00:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Skype
[2011/08/01 20:31:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\skypePM
[2012/04/11 09:30:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\SolidDocuments
[2008/10/20 12:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Sun
[2012/09/30 21:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\uTorrent
[2008/10/10 17:05:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\vlc
[2011/02/18 00:23:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Winamp
[2012/04/11 01:06:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Windows Desktop Search
[2008/10/13 13:17:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\WinRAR
[2010/12/28 22:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\XnView
[2012/06/05 10:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Alexey\Application Data\Yandex

< %APPDATA%\*.exe /s >
[2010/12/05 20:51:43 | 001,266,714 | ---- | M] (Citrix Systems, Inc.) -- C:\Documents and Settings\Alexey\Application Data\CitrixSAClient.exe
[2010/02/22 12:56:16 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Documents and Settings\Alexey\Application Data\Facebook\uninstall.exe
[2012/03/07 00:36:32 | 000,943,504 | ---- | M] (Samsung) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\Kies.exe
[2012/03/07 00:36:34 | 000,278,928 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
[2012/02/01 00:17:02 | 000,308,224 | ---- | M] (Samsung) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\KiesLogger.exe
[2012/03/07 00:36:32 | 003,508,624 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
[2012/01/31 01:16:12 | 000,290,816 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceDataService.exe
[2012/01/31 01:16:12 | 000,693,248 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
[2012/03/07 00:36:38 | 000,067,472 | ---- | M] (Samsung) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
[2012/02/03 00:43:58 | 000,106,408 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentInstaller.exe
[2012/02/03 00:43:58 | 000,101,288 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\AgentUpdate.exe
[2012/03/07 00:36:40 | 000,131,984 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012/03/07 00:36:42 | 000,021,392 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
[2012/03/07 00:36:42 | 003,570,312 | ---- | M] (Freeware) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
[2012/01/31 01:15:38 | 024,123,656 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2012/04/04 07:05:14 | 000,954,256 | ---- | M] (Samsung) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\Kies.exe
[2012/04/04 07:05:18 | 000,278,928 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\KiesDriverInstaller.exe
[2012/03/29 07:13:22 | 000,309,760 | ---- | M] (Samsung) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\KiesLogger.exe
[2012/04/04 07:05:16 | 003,521,424 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\KiesTrayAgent.exe
[2012/03/29 07:11:58 | 000,297,984 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceDataService.exe
[2012/03/29 07:12:02 | 000,694,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceManager.exe
[2012/04/04 07:05:20 | 000,067,472 | ---- | M] (Samsung) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\Kies_Tutorial.exe
[2012/03/29 07:11:38 | 000,106,920 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentInstaller.exe
[2012/03/29 07:11:38 | 000,101,288 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentUpdate.exe
[2012/04/04 07:05:26 | 000,183,696 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012/04/04 07:05:28 | 000,021,392 | ---- | M] () -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\KiesPDLR.exe
[2012/04/04 07:05:30 | 003,570,312 | ---- | M] (Freeware) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\MediaModules\MyFreeCodecPack.exe
[2012/03/29 07:11:06 | 000,024,576 | ---- | M] ((주)마크애니) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\System32\MASetupCleaner.exe
[2012/03/29 07:11:06 | 000,172,032 | ---- | M] (Musiccity Co.Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\System32\muzapp.exe
[2012/04/12 12:04:05 | 024,117,248 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2012/03/07 00:36:44 | 000,371,088 | ---- | M] (ml) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012/04/04 07:05:32 | 000,371,088 | ---- | M] (ml) -- C:\Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job >
[2012/10/14 19:52:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
[2012/10/14 22:52:01 | 000,001,000 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
[2012/10/13 09:29:00 | 000,000,952 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012/10/15 00:29:00 | 000,000,956 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2012/10/13 11:15:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
[2012/10/15 00:15:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2011/09/04 11:41:01 | 000,512,000 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2011/09/04 09:29:13 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\security.sav
[2011/09/04 11:41:01 | 035,913,728 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2011/09/04 11:41:01 | 005,242,880 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012/10/12 09:38:45 | 000,082,486 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2012/10/12 09:38:45 | 000,107,822 | ---- | M] () -- C:\WINDOWS\system32\perfc019.dat
[2012/10/12 09:38:45 | 000,486,680 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2012/10/12 09:38:45 | 000,555,426 | ---- | M] () -- C:\WINDOWS\system32\perfh019.dat
[2012/10/12 09:38:45 | 001,249,420 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2012/10/12 09:34:43 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008/04/15 03:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Facebook Update" = "C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver -- [2012/07/12 19:47:18 | 000,138,096 | ---- | M] (Facebook Inc.)
"Google Update" = "C:\Documents and Settings\Alexey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c -- [2011/08/04 20:54:20 | 000,136,176 | ---- | M] (Google Inc.)
"Skype" = "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun -- [2012/07/13 13:33:24 | 017,418,928 | R--- | M] (Skype Technologies S.A.)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012/10/15 00:47:06 | 000,000,512 | ---- | M] () MD5=59600B6290F94CACCB7070624AE142C5 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2005/08/30 13:13:16 | 000,003,556 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Content\Reference\PHP\CrackF.html

< *keygen* /s >
[2005/08/30 13:13:12 | 000,013,367 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Content\Reference\HTML\KEYGEN.html

< *loader* /s >
[2010/02/02 00:04:44 | 000,847,040 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Facebook\axfbootloader.dll
[2012/06/03 19:28:05 | 000,001,924 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D}\chrome\skin\tabs\ajax-loader.gif
[2012/06/03 19:28:05 | 000,001,924 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Mozilla\Firefox\Profiles\wjwy2xig.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D}\chrome\skin\tabs\ajax-loader_1.gif
[2012/02/21 21:53:48 | 000,069,120 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll
[2012/03/07 00:36:40 | 000,131,984 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012/04/12 12:00:48 | 000,028,638 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\CabFile\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll.cab
[2012/04/12 12:00:39 | 000,076,981 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\CabFile\External\FirmwareUpdate\BinaryLoaderMgr.exe.cab
[2012/03/30 12:24:00 | 000,069,120 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll
[2012/04/04 07:05:26 | 000,183,696 | ---- | M] () -- \Documents and Settings\Alexey\Application Data\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2010/10/25 07:08:54 | 000,005,438 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\temp\par-Alexey\cache-83438f8fd5027a13c54ee6b13d0c7862fdd9a0b9\inc\lib\AutoLoader.pm
[2010/10/25 07:08:54 | 000,012,979 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\temp\par-Alexey\cache-83438f8fd5027a13c54ee6b13d0c7862fdd9a0b9\inc\lib\DynaLoader.pm
[2010/10/25 07:08:54 | 000,003,399 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\temp\par-Alexey\cache-83438f8fd5027a13c54ee6b13d0c7862fdd9a0b9\inc\lib\XSLoader.pm
[2011/03/30 22:35:43 | 000,000,558 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\166YLWBP\adloader[1].htm
[2011/02/18 16:56:32 | 000,001,054 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\166YLWBP\flashloader[1].js
[2012/10/14 23:02:35 | 000,009,830 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\E46UDKNR\loader_nav10730_3[1].js
[2012/10/14 23:05:00 | 000,003,648 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\E46UDKNR\loader_v2_checker[1].php
[2012/10/14 13:59:51 | 000,108,078 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\E46UDKNR\Microsoft.Live.Messenger.Services.Loader[1].js
[2012/10/14 13:59:52 | 000,000,651 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RJFTSQOO\adloader[1].htm
[2012/10/14 13:59:52 | 000,014,823 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RJFTSQOO\adloader[1].js
[2012/10/14 23:01:13 | 000,004,959 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RJFTSQOO\loader[1].js
[2012/10/14 21:55:25 | 000,000,336 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RPDSZD6S\11883-1-loader[1].js
[2012/10/14 20:56:50 | 000,030,462 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RPDSZD6S\loader.cxp[1].js
[2012/10/14 23:05:00 | 000,000,773 | ---- | M] () -- \Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RPDSZD6S\loader_v2[1].php
[2012/06/18 12:39:40 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\loader.gif
[2012/06/18 12:39:40 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Application Data\Skype\Apps\login\images\loader.png
[2007/07/06 15:47:00 | 000,004,629 | ---- | M] () -- \Program Files\Common Files\Adobe\Startup Scripts CS3\Adobe Version Cue\VersionCueSDKLoader.jsx
[2001/01/16 04:55:36 | 000,053,248 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL
[2001/01/16 02:22:34 | 000,002,560 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.TLB
[2011/04/24 23:13:08 | 000,242,064 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\kas_loader.dll
[2011/04/24 23:13:22 | 000,270,736 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\prloader.dll
[2011/04/24 22:14:04 | 000,001,557 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_16.gif
[2011/04/24 22:14:04 | 000,000,419 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_16.png
[2011/04/24 22:14:04 | 000,006,377 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_32.gif
[2011/04/24 22:14:04 | 000,001,276 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_32.png
[2011/04/24 22:14:04 | 000,009,568 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_48.gif
[2011/04/24 22:14:04 | 000,001,805 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_48.png
[2011/04/24 22:14:04 | 000,020,462 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_96.gif
[2011/04/24 22:14:04 | 000,004,076 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\common\images\loader_96.png
[2011/04/24 22:14:06 | 000,000,745 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\skin\resources\neutral\decl\main_window\CustomLoader.qml
[2005/08/30 13:12:58 | 000,056,807 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Commands\FLVFileLoader.swf
[2005/08/30 13:13:18 | 000,000,681 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Content\Welcome\Flash\dynswfloader.swf
[2005/08/30 13:13:18 | 000,008,203 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Content\Welcome\Flash\testing_dynswfloader.swf
[2005/08/30 13:13:30 | 001,040,384 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\JSExtensions\swfloader.dll
[2008/09/30 14:12:22 | 000,006,308 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.py
[2008/07/29 16:19:06 | 000,022,528 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.dll
[2008/09/30 16:58:42 | 000,000,171 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.ini
[2008/07/29 14:04:50 | 000,029,696 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\bin\javaloader.uno.dll
[2008/07/29 13:26:36 | 000,003,688 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\java\unoloader.jar
[2008/02/25 08:05:22 | 000,856,064 | ---- | M] () -- \Program Files\The KMPlayer\ImLoader.dll
[2007/09/21 01:07:10 | 000,044,032 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[1 \Program Files\WinRAR\*.tmp files -> \Program Files\WinRAR\*.tmp -> ]
[2009/07/29 03:00:56 | 000,000,338 | ---- | M] () -- \WINDOWS\Downloaded Program Files\PhotoUploader55.inf
[2009/07/29 21:21:24 | 003,540,488 | ---- | M] () -- \WINDOWS\Downloaded Program Files\PhotoUploader55.ocx
[2008/04/15 03:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[6 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2008/04/15 03:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD

< End of report >
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#12 Příspěvek od vyosek »

OTL Extras logfile created on: 15/10/2012 00:42:52 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Alexey\Рабочий стол
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: Великобритания | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.56 Gb Available Physical Memory | 28.07% Memory free
3.84 Gb Paging File | 2.05 Gb Available in Paging File | 53.31% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.46 Gb Total Space | 21.50 Gb Free Space | 30.08% Space Free | Partition Type: NTFS
Drive D: | 151.42 Gb Total Space | 27.15 Gb Free Space | 17.93% Space Free | Partition Type: NTFS
Drive E: | 1021.00 Mb Total Space | 795.74 Mb Free Space | 77.94% Space Free | Partition Type: FAT32
Drive F: | 9.00 Gb Total Space | 3.29 Gb Free Space | 36.50% Space Free | Partition Type: NTFS

Computer Name: ALEXBG | User Name: Alexey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Корпорация Майкрософт)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Корпорация Майкрософт)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Корпорация Майкрософт)
.url [@ = InternetShortcut] -- C:\WINDOWS\System32\rundll32.exe (Корпорация Майкрософт)
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Корпорация Майкрософт)
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Корпорация Майкрософт)

[HKEY_USERS\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Корпорация Майкрософт)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Корпорация Майкрософт)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Корпорация Майкрософт)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Корпорация Майкрософт)
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- winhlp32.exe %1 (Корпорация Майкрософт)
hlpfile [open] -- %SystemRoot%\System32\winhlp32.exe %1 (Корпорация Майкрософт)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Корпорация Майкрософт)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Корпорация Майкрософт)
inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Корпорация Майкрософт)
inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Корпорация Майкрософт)
inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Корпорация Майкрософт)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Корпорация Майкрософт)
InternetShortcut [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Корпорация Майкрософт)
jsfile [edit] -- "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Корпорация Майкрософт)
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Корпорация Майкрософт)
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Корпорация Майкрософт)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Корпорация Майкрософт)
regfile [open] -- regedit.exe "%1" (Корпорация Майкрософт)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Корпорация Майкрософт)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Корпорация Майкрософт)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Корпорация Майкрософт)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Корпорация Майкрософт)
vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Корпорация Майкрософт)
vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Корпорация Майкрософт)
vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Корпорация Майкрософт)
vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Корпорация Майкрософт)
wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Корпорация Майкрософт)
wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Корпорация Майкрософт)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /k "cd %L" (Корпорация Майкрософт)
Directory [find] -- %SystemRoot%\Explorer.exe (Корпорация Майкрософт)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Directory [Обзор с XnView] -- "C:\Program Files\XnView\xnview.exe" "%1"
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Корпорация Майкрософт)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Корпорация Майкрософт)
Drive [find] -- %SystemRoot%\Explorer.exe (Корпорация Майкрософт)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"FirewallOverride" = 1
"UpdatesDisableNotify" = 0
"UpdatesOverride" = 1
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"5985:TCP" = 5985:TCP:*:Disabled:Удаленное управление Windows
"80:TCP" = 80:TCP:*:Disabled:Удаленное управление Windows - режим совместимости (HTTP - входящий трафик)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Корпорация Майкрософт)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Корпорация Майкрософт)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"D:\utorrent(3).exe" = D:\utorrent(3).exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\HP\hp laserjet m1522\hppfaxnc1.exe" = C:\Program Files\HP\hp laserjet m1522\hppfaxnc1.exe:*:Enabled:HP Networked Printer Installer -- (Hewlett-Packard Co.)
"C:\Program Files\QIP\qip.exe" = C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager -- (The Author of QIP)
"C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Alexey\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player -- (Musiccity Co.Ltd.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe" = C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe:*:Enabled:WorldWide Telescope -- (Microsoft Research)
"D:\uTorrent.exe" = D:\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{01E6CFB0-2EAA-A019-7894-18986696E711}" = Catalyst Control Center Localization Finnish
"{02E5B340-4E08-495E-94E1-FFC19B284767}" = hppTLBXFXM1522
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{096F7700-03BA-B421-703A-FE4D2CE88D08}" = Catalyst Control Center Graphics Light
"{10944289-8401-4B95-8E2A-61B0024C8C3A}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{1138C1CB-D830-40B8-A658-DC0C3AF50EB9}" = hppScanTo
"{12F80942-5FE0-7CE9-F1B3-121795A32054}" = CCC Help Swedish
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{14DEB605-8718-4112-BD4C-70AD5D54E165}_is1" = Path2Clipboard 1.0.8 (Remove only)
"{15030405-7B1E-7300-1C6C-9FE98BA68CB4}" = CCC Help Norwegian
"{154446FB-439A-2AF4-B124-9E31CD3B3E88}" = Catalyst Control Center Localization Chinese Standard
"{154E4F71-DFC0-4B31-8D99-F97615031B02}" = HP Webcam Application
"{176722EA-EB96-5AC0-9BC0-FD774C1A94FB}" = Catalyst Control Center Localization Russian
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1C7ADED3-C371-40DF-A69D-FE0EA73DC394}" = Windows Workflow Foundation RU Language Pack
"{1CDB842D-9C18-5EBC-91D4-C6F8DA0AE7CE}" = CCC Help Turkish
"{1CF67A1B-1063-D44B-3234-42717D7D3FF8}" = Catalyst Control Center Localization French
"{1E6029A8-622B-4F5B-A324-D8760CC8BEE7}" = hppscanM1522
"{1ED467FB-506A-4A00-BC8A-CEE4758842C6}" = hpzTLBXFX
"{1F15B51B-0622-486A-A751-6D4EDD56842A}" = hppusgM1522
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FE5BFA8-C0E0-68FD-52DD-42FB11B3B160}" = Catalyst Control Center Localization Norwegian
"{23170F69-40C1-2701-0457-000001000000}" = 7-Zip 4.57
"{243A6B8F-203D-EDAD-350D-15393AD822CD}" = CCC Help German
"{2480B673-194C-3C4B-1523-4C20F354E40C}" = Catalyst Control Center Localization Danish
"{263A0833-85A9-AF55-F3EE-5945FAC78614}" = Catalyst Control Center Graphics Full Existing
"{2696556B-1D2B-26B3-75B1-52F342C150D0}" = CCC Help Dutch
"{2744791F-4E7C-32F5-AB40-AEC6A6C86DBF}" = Microsoft .NET Framework 3.5 Language Pack SP1 - rus
"{2746C43F-4D85-73C6-8ADC-C38453C3531E}" = CCC Help Czech
"{2881063B-C58F-49EB-97FD-8BF58EC580F9}" = Nitro PDF Reader
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2B55F645-D18E-4903-B8B1-89B6F8924B5D}" = OpenOffice.org 3.0
"{2BB372D9-52B4-410A-BC1A-FEAB63181EEF}" = Microsoft .NET Framework 1.1 Russian Language Pack
"{2C0988B9-3BEA-7A45-2A67-BD0267973878}" = CCC Help Hungarian
"{30BF4E6C-D866-46F7-A4F6-81A45E97706E}" = Catalyst Control Center - Branding
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{33EFDAD7-1686-465A-AE0A-26F22E380315}" = Product_Min_QFolder
"{350C9419-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C511454-FCEA-450F-ACDA-ABF2A1FDCA90}" = hppManualsM1522
"{3C9643A7-ACF9-3431-3B42-89D553C20CCE}" = Catalyst Control Center Localization Portuguese
"{3D5238BD-B6F7-0325-4577-7B1DD3AC539F}" = CCC Help Thai
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{424BA315-C8B9-4677-BB01-4EEF98B8EA82}" = hppSendFax
"{43295C33-9D66-4F85-BBFD-74CEE78C67C9}" = Nuhertz Filter 4.36
"{434DEF64-89D3-F83B-E008-5200E5B2F2D9}" = ccc-utility
"{45E557D6-2271-4F13-8101-C620B4285AB0}" = Антивирус Касперского 2012
"{4841F481-1272-A1BE-D424-78628D252426}" = Catalyst Control Center Localization German
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4CE1CFF4-7F88-02DD-70BD-CD3B18F6CDC9}" = ccc-core-preinstall
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{5208FDB2-D561-3FB4-9763-6B10B06745B7}" = Microsoft .NET Framework 4 Client Profile RUS Language Pack
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5526E90B-7ED3-1881-4C96-35FF5E124225}" = Catalyst Control Center Localization Thai
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{6A990885-DC53-4F85-A821-8EBA1BB95E19}" = hppLJM1522
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6CF6A814-CE65-39FC-BBBC-6CB340A4028B}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - RUS
"{6D397775-EFF0-26D7-AC85-5993391AEC4F}" = Catalyst Control Center Localization Dutch
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736D8DEB-66C6-3655-9D59-DF6493A81F77}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - RUS
"{76582A2F-F5FD-BF58-C69F-1E9AB9CBDF6A}" = Catalyst Control Center Localization Spanish
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{82B6333C-10B0-6BF2-F02B-FB907129C44C}" = ccc-core-static
"{82C2F4FF-B768-12D6-E53D-62C8E17E8662}" = CCC Help Japanese
"{8452B997-80A4-B2F9-9CAD-00A3FA45AD92}" = Catalyst Control Center Localization Swedish
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = HP Integrated Module with Bluetooth wireless technology
"{855B04CC-4F7A-4FBB-B7BA-D965D23F7AD5}" = Microsoft .NET Framework 3.0 Russian Language Pack
"{865821E8-88E8-BE83-A4C0-4B2723352AE4}" = Catalyst Control Center Localization Japanese
"{8676226D-E23E-8701-778F-7DE0E12DA452}" = CCC Help Chinese Standard
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89CA8C53-9CE5-B628-AA17-11F232F1E726}" = CCC Help Danish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B68D7D1-258E-0B52-B216-DD8DD59B544A}" = Catalyst Control Center Localization Italian
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110419-6000-11D3-8CFE-0150048383C9}" = Microsoft Office - профессиональный выпуск версии 2003
"{90120000-0020-0419-0000-0000000FF1CE}" = Пакет обеспечения совместимости для выпуска 2007 системы Microsoft Office
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9342C233-8DB7-4E17-B263-695428CF4599}" = HP 3D DriveGuard
"{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{966CA8ED-5A5D-47F8-A478-794206AB1B3E}" = Microsoft WorldWide Telescope
"{983980FC-66FB-4ECC-A5D8-4565BE217733}" = SCR3xxx Smart Card Reader
"{9919B071-F93A-8BFD-6A65-01D560121DC5}" = CCC Help French
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
"{9E60B43A-50D6-057F-8EA6-8286CE00A65C}" = CCC Help Greek
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CBCBC-10B5-EBC0-1219-95830657FF98}" = CCC Help Portuguese
"{A3D2DFAA-85D7-4234-9088-D71E0FDAB2D5}" = hppFaxDrvM1522
"{A4502FB2-69C0-9F71-C697-0F0AC94656E3}" = Catalyst Control Center Localization Czech
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1029-7B44-A95000000001}" = Adobe Reader 9.5.1 - Czech
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADAE950C-FF76-F081-5861-FBD5AF48FE56}" = Catalyst Control Center Graphics Full New
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B00690AD-B4F5-4730-9110-5C495B89E647}" = Scan
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4205456-1F3F-7156-5EE2-DA1045FD7207}" = Catalyst Control Center Localization Turkish
"{B42A8EA7-2A15-2E30-651E-DD47C000301D}" = CCC Help Finnish
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C45FB733-E259-A7FF-5C9F-4FC68CC69365}" = CCC Help Italian
"{C8A37F1F-E13B-48ae-93F8-4669264969F9}" = HP LaserJet M1522 MFP Series 3.0
"{C94AAA8B-4152-3F32-E94E-E23503D21EAC}" = CCC Help Spanish
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE460C16-2340-481C-8A94-B6EDB841AD59}" = Windows Communication Foundation Language Pack - RUS
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D83A3DFC-8528-4E31-93DC-0A41C477109C}" = Windows Presentation Foundation Language Pack (RUS)
"{D889ECAE-D516-363D-0CEC-17F1D2E1AA81}" = CCC Help Korean
"{D8AC1EB5-E8B0-44A0-B113-899407188A2F}" = hppFonts
"{D9199DDB-B5EE-BF67-7C85-31790A8B5D85}" = CCC Help Chinese Traditional
"{D9803478-F222-AC9C-48FB-1F4D6B54F1FF}" = Catalyst Control Center Localization Chinese Traditional
"{DCA43467-6F0F-CC7B-B944-F54AA1752BBE}" = Catalyst Control Center Core Implementation
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E11D4FE9-718A-D54C-9C19-A13CA89B9E18}" = Skins
"{E277DDEB-9395-77FA-E273-A2BD084CEE0C}" = CCC Help Russian
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0DBF285-844C-48E0-BA75-C554759F1BCC}" = hppFaxUtility
"{F4306DF8-7B00-158B-435B-05FA42C81795}" = Catalyst Control Center Localization Greek
"{F4D0F248-2BF7-4912-814E-4FD751923838}" = Microsoft .NET Framework 2.0 Language Pack - RUS
"{F5D61F44-C37E-2015-BA9F-A718B9DBF69D}" = Catalyst Control Center Localization Korean
"{F6019CF2-24CA-F33D-091A-D6F65CB54D01}" = Catalyst Control Center Localization Polish
"{F9048FF8-45E1-8BD4-0161-468F777BA2B4}" = CCC Help English
"{FC00DD7E-8EBD-DAF9-B345-6643818AC242}" = Catalyst Control Center Localization Hungarian
"{FC1DCE80-2E83-A938-1450-A846B851E264}" = CCC Help Polish
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"AFPL Ghostscript 8.54" = AFPL Ghostscript 8.54
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AviSynth" = AviSynth 2.5
"Broadcom 802.11 Application" = Утилита беспроводной сети Broadcom
"Broadcom 802.11b Network Adapter" = Адаптер беспроводной локальной сети Broadcom 802.11
"Electronics_Workbench_V5" = Electronics Workbench V5.12
"Everest" = Everest
"FinePrint" = FinePrint
"Flash Player Pro" = Flash Player Pro
"Foxit Reader" = Foxit Reader
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"ie8" = Windows Internet Explorer 8
"InstallWIX_{45E557D6-2271-4F13-8101-C620B4285AB0}" = Антивирус Касперского 2012
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Антивирус Касперского 2011
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.1.7
"M0KGK SDR Decoder" = M0KGK SDR Decoder
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - RUS" = Microsoft .NET Framework 2.0 Language Pack - RUS
"Microsoft .NET Framework 3.0 Russian Language Pack" = Microsoft .NET Framework 3.0 Russian Language Pack
"Microsoft .NET Framework 3.5 Language Pack SP1 - rus" = Языковой пакет Microsoft .NET Framework 3.5 SP1 — RUS
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile RUS Language Pack" = Языковой пакет клиентского профиля Microsoft.NET Framework 4 - RUS
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero8360_Micro_is1" = Nero 8 Lite v8.3.6.0
"O2 Internet Konfigurator" = O2 Internet Konfigurator
"Paint.NET_addon" = Paint.NET v3.35
"PSPad editor_is1" = PSPad editor
"QIP" = QIP
"rajиe.net_is1" = rajиe prщvodce verze 1.59.25.240
"RealAlt_is1" = Real Alternative 1.8.2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The KMPlayer" = The KMPlayer (remove only)
"The KMPlayer_is1" = The KMPlayer 1432 R2
"VB Runtime" = VB Runtime
"Vista Drive Icon_addon" = Vista Drive Icon
"VLC" = VLC
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp 5.541" = Winamp 5.541
"WinDjView_is1" = WinDjView 0.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Проигрыватель Windows Media 11
"WinRAR archiver" = Архиватор WinRAR
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"Yandex.Internet" = Яндекс.Интернет

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 13/10/2012 12:42:43 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 64625

Error - 13/10/2012 12:42:43 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 64625

Error - 13/10/2012 17:51:56 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 13/10/2012 17:51:56 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2000

Error - 13/10/2012 17:51:56 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2000

Error - 13/10/2012 17:51:58 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 13/10/2012 17:51:58 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4032

Error - 13/10/2012 17:51:58 | Computer Name = ALEXBG | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4032

Error - 14/10/2012 07:23:59 | Computer Name = ALEXBG | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft WorldWide Telescope -- Error 1706. An installation
package for the product Microsoft WorldWide Telescope cannot be found. Try the
installation again using a valid copy of the installation package 'wwtsetupaphsp2.msi'.

Error - 14/10/2012 07:24:03 | Computer Name = ALEXBG | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft WorldWide Telescope -- Error 1706. An installation
package for the product Microsoft WorldWide Telescope cannot be found. Try the
installation again using a valid copy of the installation package 'wwtsetupaphsp2.msi'.

[ System Events ]
Error - 13/10/2012 03:17:47 | Computer Name = ALEXBG | Source = W32Time | ID = 39452689
Description = NTP-клиент поставщика времени: произошла ошибка при поиске в DNS настроенного
вручную узла 'ntp.colocall.net,0x1'. NTP-клиент вновь повторит поиск в DNS через
15 мин. Ошибка: Сделана попытка выполнить операцию на сокете для недоступного хоста.
(0x80072751)

Error - 13/10/2012 03:17:47 | Computer Name = ALEXBG | Source = W32Time | ID = 39452701
Description = The NTP-клиент поставщика времени настроен на получение времени из
одного или нескольких источников, однако ни один из этих источников недоступен.
Попытки подключения к источнику не будут выполняться в течение 15 мин. NTP-клиент
не имеет источника правильного времени.

Error - 13/10/2012 04:36:51 | Computer Name = ALEXBG | Source = W32Time | ID = 39452689
Description = NTP-клиент поставщика времени: произошла ошибка при поиске в DNS настроенного
вручную узла 'ntp.colocall.net,0x1'. NTP-клиент вновь повторит поиск в DNS через
15 мин. Ошибка: Сделана попытка выполнить операцию на сокете для недоступного хоста.
(0x80072751)

Error - 13/10/2012 04:36:51 | Computer Name = ALEXBG | Source = W32Time | ID = 39452701
Description = The NTP-клиент поставщика времени настроен на получение времени из
одного или нескольких источников, однако ни один из этих источников недоступен.
Попытки подключения к источнику не будут выполняться в течение 14 мин. NTP-клиент
не имеет источника правильного времени.

Error - 13/10/2012 04:36:51 | Computer Name = ALEXBG | Source = W32Time | ID = 39452689
Description = NTP-клиент поставщика времени: произошла ошибка при поиске в DNS настроенного
вручную узла 'ntp.colocall.net,0x1'. NTP-клиент вновь повторит поиск в DNS через
15 мин. Ошибка: Сделана попытка выполнить операцию на сокете для недоступного хоста.
(0x80072751)

Error - 13/10/2012 04:36:51 | Computer Name = ALEXBG | Source = W32Time | ID = 39452701
Description = The NTP-клиент поставщика времени настроен на получение времени из
одного или нескольких источников, однако ни один из этих источников недоступен.
Попытки подключения к источнику не будут выполняться в течение 15 мин. NTP-клиент
не имеет источника правильного времени.

Error - 13/10/2012 11:24:31 | Computer Name = ALEXBG | Source = W32Time | ID = 39452689
Description = NTP-клиент поставщика времени: произошла ошибка при поиске в DNS настроенного
вручную узла 'ntp.colocall.net,0x1'. NTP-клиент вновь повторит поиск в DNS через
15 мин. Ошибка: Сделана попытка выполнить операцию на сокете для недоступного хоста.
(0x80072751)

Error - 13/10/2012 11:24:31 | Computer Name = ALEXBG | Source = W32Time | ID = 39452701
Description = The NTP-клиент поставщика времени настроен на получение времени из
одного или нескольких источников, однако ни один из этих источников недоступен.
Попытки подключения к источнику не будут выполняться в течение 14 мин. NTP-клиент
не имеет источника правильного времени.

Error - 13/10/2012 11:24:31 | Computer Name = ALEXBG | Source = W32Time | ID = 39452689
Description = NTP-клиент поставщика времени: произошла ошибка при поиске в DNS настроенного
вручную узла 'ntp.colocall.net,0x1'. NTP-клиент вновь повторит поиск в DNS через
15 мин. Ошибка: Сделана попытка выполнить операцию на сокете для недоступного хоста.
(0x80072751)

Error - 13/10/2012 11:24:31 | Computer Name = ALEXBG | Source = W32Time | ID = 39452701
Description = The NTP-клиент поставщика времени настроен на получение времени из
одного или нескольких источников, однако ни один из этих источников недоступен.
Попытки подключения к источнику не будут выполняться в течение 15 мин. NTP-клиент
не имеет источника правильного времени.


< End of report >
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#13 Příspěvek od vyosek »

:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    SRV - File not found [Auto | Stopped] -- C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
    SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
    SRV - File not found [Disabled | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbaapl.sys -- (USBAAPL)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\net6im51.sys -- (Net6IM)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS -- (MRESP50a64)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS -- (MREMP50a64)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Alexey\LOCALS~1\Temp\catchme.sys -- (catchme)
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\SearchScopes,DefaultScope = {8F3F980C-8561-4D4D-B860-8E6D1B225F1A}
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\SearchScopes\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}: "URL" = http://www.google.co.uk/search?hl=en&q={searchTerms}&meta=&rlz=1I7ADFA_ru
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}: "URL" = http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
    IE - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.155:3128
    FF - prefs.js..browser.search.defaulturl: "http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb"
    FF - prefs.js..network.proxy.ftp: "192.168.1.155"
    FF - prefs.js..network.proxy.ftp_port: 3128
    FF - prefs.js..network.proxy.gopher: "192.168.1.155"
    FF - prefs.js..network.proxy.gopher_port: 3128
    FF - prefs.js..network.proxy.http: "192.168.1.155"
    FF - prefs.js..network.proxy.http_port: 3128
    FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
    FF - prefs.js..network.proxy.share_proxy_settings: true
    FF - prefs.js..network.proxy.socks: "192.168.1.155"
    FF - prefs.js..network.proxy.socks_port: 3128
    FF - prefs.js..network.proxy.ssl: "192.168.1.155"
    FF - prefs.js..network.proxy.ssl_port: 3128
    CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=cr ... 06&sr=0&q={searchTerms}
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
    O15 - HKU\S-1-5-21-1123561945-630328440-1417001333-1005\..Trusted Domains: microsoft.com ([www.update] http in Надежные узлы)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
    [2010/04/03 14:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2010/03/25 22:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2012/06/03 19:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\{DCD48218-E972-4d0c-9E5F-43462BC13E3B}
    [9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [15 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [1 C:\WINDOWS\inf\*.tmp files -> C:\WINDOWS\inf\*.tmp -> ]
    [2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
    [1 C:\WINDOWS\system32\config\systemprofile\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\*.tmp -> ]
    [1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]
    [2012/10/14 19:52:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
    [2012/10/14 22:52:01 | 000,001,000 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
    [2012/10/13 09:29:00 | 000,000,952 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    [2012/10/15 00:29:00 | 000,000,956 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    [2012/10/13 11:15:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job
    [2012/10/15 00:15:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job
    @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
    
    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update"=-
    ""=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "DATAMNGR"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"=-
    "swg"=-
    "Facebook Update"=-
    "Google Update"=-
    "Skype"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Windows Search.lnk]
    
    :files
    C:\Documents and Settings\Alexey\Application Data\searchquband
    C:\Documents and Settings\Alexey\Application Data\searchqutoolbar
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Mary13
Návštěvník
Návštěvník
Příspěvky: 86
Registrován: 22 kvě 2009 12:15

Re: Prosím o kontrolu

#14 Příspěvek od Mary13 »

All processes killed
========== OTL ==========
Error: No service named PEVSystemStart was found to stop!
No service named PEVSystemStart was found to delete!
File C:\ComboFix\PEV.cfxxe EXEC /i C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q not found.
Error: No service named HidServ was found to stop!
No service named HidServ was found to delete!
File %SystemRoot%\System32\hidserv.dll not found.
Error: No service named gusvc was found to stop!
No service named gusvc was found to delete!
File C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe not found.
Error: No service named WDICA was found to stop!
No service named WDICA was found to delete!
Error: No service named USBAAPL was found to stop!
No service named USBAAPL was found to delete!
File System32\Drivers\usbaapl.sys not found.
Error: No service named PDRFRAME was found to stop!
No service named PDRFRAME was found to delete!
Error: No service named PDRELI was found to stop!
No service named PDRELI was found to delete!
Error: No service named PDFRAME was found to stop!
No service named PDFRAME was found to delete!
Error: No service named PDCOMP was found to stop!
No service named PDCOMP was found to delete!
Error: No service named PCIDump was found to stop!
No service named PCIDump was found to delete!
Error: No service named Net6IM was found to stop!
No service named Net6IM was found to delete!
File system32\DRIVERS\net6im51.sys not found.
Error: No service named MRESP50a64 was found to stop!
No service named MRESP50a64 was found to delete!
File C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS not found.
Error: No service named MRENDIS5 was found to stop!
No service named MRENDIS5 was found to delete!
File C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS not found.
Error: No service named MREMPR5 was found to stop!
No service named MREMPR5 was found to delete!
File C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS not found.
Error: No service named MREMP50a64 was found to stop!
No service named MREMP50a64 was found to delete!
File C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS not found.
Error: No service named lbrtfdc was found to stop!
No service named lbrtfdc was found to delete!
Error: No service named i2omgmt was found to stop!
No service named i2omgmt was found to delete!
Error: No service named Changer was found to stop!
No service named Changer was found to delete!
Error: No service named catchme was found to stop!
No service named catchme was found to delete!
File C:\DOCUME~1\Alexey\LOCALS~1\Temp\catchme.sys not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}\ not found.
HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKU\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_USERS\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Internet Explorer\SearchScopes\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F3F980C-8561-4D4D-B860-8E6D1B225F1A}\ not found.
Registry key HKEY_USERS\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}\ not found.
HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\S-1-5-21-1123561945-630328440-1417001333-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Prefs.js: "http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb" removed from browser.search.defaulturl
Prefs.js: "192.168.1.155" removed from network.proxy.ftp
Prefs.js: 3128 removed from network.proxy.ftp_port
Prefs.js: "192.168.1.155" removed from network.proxy.gopher
Prefs.js: 3128 removed from network.proxy.gopher_port
Prefs.js: "192.168.1.155" removed from network.proxy.http
Prefs.js: 3128 removed from network.proxy.http_port
Prefs.js: "localhost,127.0.0.1" removed from network.proxy.no_proxies_on
Prefs.js: true removed from network.proxy.share_proxy_settings
Prefs.js: "192.168.1.155" removed from network.proxy.socks
Prefs.js: 3128 removed from network.proxy.socks_port
Prefs.js: "192.168.1.155" removed from network.proxy.ssl
Prefs.js: 3128 removed from network.proxy.ssl_port
Use Chrome's Settings page to remove the default_search_provider items.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_USERS\S-1-5-21-1123561945-630328440-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoft.com\www.update\ deleted successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} folder moved successfully.
C:\Documents and Settings\LocalService\Application Data\{DCD48218-E972-4d0c-9E5F-43462BC13E3B} folder moved successfully.
C:\WINDOWS\SET11C.tmp deleted successfully.
C:\WINDOWS\SET11F.tmp deleted successfully.
C:\WINDOWS\SET12B.tmp deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET4.tmp deleted successfully.
C:\WINDOWS\SET5B.tmp deleted successfully.
C:\WINDOWS\SET5E.tmp deleted successfully.
C:\WINDOWS\SET6A.tmp deleted successfully.
C:\WINDOWS\SET8.tmp deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11D4.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP15A.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1F0C.tmp\mscorlib.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1F0C.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP20A2.tmp\System.Data.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP20A2.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2188.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP22D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP23D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2A6.tmp\System.EnterpriseServices.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2A6.tmp\System.EnterpriseServices.Wrapper.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2A6.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP697.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP806.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP83D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP88C.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9B74.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPDBB.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPDE0.tmp folder deleted successfully.
C:\WINDOWS\inf\COM18F.tmp deleted successfully.
C:\WINDOWS\Installer\MSI4F2.tmp deleted successfully.
C:\WINDOWS\Installer\MSI533.tmp deleted successfully.
C:\WINDOWS\system32\CONFIG.TMP deleted successfully.
C:\WINDOWS\system32\SET1DF.tmp deleted successfully.
C:\WINDOWS\system32\SET1E0.tmp deleted successfully.
C:\WINDOWS\system32\SET1E6.tmp deleted successfully.
C:\WINDOWS\system32\SET4A.tmp deleted successfully.
C:\WINDOWS\system32\SETC3.tmp deleted successfully.
C:\WINDOWS\system32\config\systemprofile\nsv8A7.tmp\NSISArray.dll deleted successfully.
C:\WINDOWS\system32\config\systemprofile\nsv8A7.tmp folder deleted successfully.
C:\WINDOWS\twain_32\hpqgnds2.tmp deleted successfully.
C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job moved successfully.
C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005Core.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-630328440-1417001333-1005UA.job moved successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Skype deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Windows Search.lnk\ deleted successfully.
========== FILES ==========
File\Folder C:\Documents and Settings\Alexey\Application Data\searchquband not found.
File\Folder C:\Documents and Settings\Alexey\Application Data\searchqutoolbar not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 10068043 bytes
->Temporary Internet Files folder emptied: 1416004 bytes

User: Alexey
->Temp folder emptied: 1166111272 bytes
->Temporary Internet Files folder emptied: 97673229 bytes
->Java cache emptied: 2728325 bytes
->FireFox cache emptied: 96405544 bytes
->Google Chrome cache emptied: 278925526 bytes
->Flash cache emptied: 255335 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56466 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 36270 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Избранное

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 100118422 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 506488853 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1230260236 bytes

Total Files Cleaned = 3,329.00 mb


[EMPTYFLASH]

User: Admin

User: Alexey
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: Избранное

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: Admin

User: Alexey
->Java cache emptied: 0 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Избранное

Total Java Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10152012_172205

Files\Folders moved on Reboot...
C:\Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\RJFTSQOO\yandsearch[1].htm moved successfully.
C:\Documents and Settings\Alexey\Local Settings\Temporary Internet Files\Content.IE5\5X60D3JY\67372762[1].htm moved successfully.
C:\Documents and Settings\Alexey\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu

#15 Příspěvek od vyosek »

Jak se chova nas pacient?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno