OTMoveIt3 log
========== FILES ==========
File/Folder [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] not found.
File/Folder soundmix"= not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\soundmix not found.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c82824e-481b-11dc-bc2e-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a3a73d8-1926-11dc-9911-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bf12e5d-4816-11dc-bc2d-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ca1d1f2-d8b0-11dc-bc78-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f84b0d8-2954-11dd-bcbf-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{99a90d8a-434a-11dc-9942-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c15375c-57a2-11dd-bce3-0019214f8e73}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d11b2b64-ec4f-11dc-bc8b-0019214f8e73}\\ deleted successfully.
OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11012008_074010
logs fromOTViewIt
OTViewIt.txt
OTViewIt logfile created on: 01.11.2008 7:41:32 - Run
OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\Documents and Settings\Администратор\Рабочий стол
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000419 | Country: Россия | Language: RUS | Date Format: dd.MM.yyyy
1023,48 Mb Total Physical Memory | 681,52 Mb Available Physical Memory | 66,59% Memory free
2,40 Gb Paging File | 2,16 Gb Available in Paging File | 89,64% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 60,50 Gb Free Space | 81,19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TYCOON-A36CE861
Current User Name: Администратор
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2004.08.17 18:05:06 | 00,050,688 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\smss.exe
[2004.08.17 18:05:10 | 00,503,808 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\winlogon.exe
[2004.08.17 18:05:04 | 00,108,544 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\services.exe
[2008.07.19 20:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[2008.07.19 20:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
[2004.08.17 18:04:48 | 01,032,704 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\explorer.exe
[2006.09.12 14:58:14 | 16,264,192 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe
[2004.11.02 22:24:46 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[2003.09.30 07:09:28 | 00,425,984 | ---- | M] (Netropa Corp.) -- C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
[2007.06.14 23:07:08 | 00,282,624 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\QuickTime\qttask.exe
[2008.07.19 20:38:34 | 00,078,008 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
[2001.08.06 07:41:48 | 00,028,672 | ---- | M] () -- C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
[2006.08.11 19:42:50 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
[2008.07.19 20:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
[2004.09.06 07:48:32 | 00,094,208 | ---- | M] () -- C:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe
[2001.11.14 05:03:12 | 00,090,112 | ---- | M] (Netropa Corp.) -- C:\Program Files\Netropa\Onscreen Display\osd.exe
[2008.07.23 20:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
[2004.08.17 18:05:12 | 00,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauclt.exe
[2008.11.01 07:40:46 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Администратор\Рабочий стол\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008.07.19 20:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
[2008.07.19 20:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
[2008.07.19 20:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
[2008.07.23 20:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
[2004.08.17 18:05:04 | 00,108,544 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\services.exe -- (Eventlog [Auto | Running])
[2005.04.04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2004.08.17 18:04:52 | 00,150,016 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\imapi.exe -- (ImapiService [On_Demand | Stopped])
[2004.08.17 18:04:54 | 00,032,768 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\mnmsrvc.exe -- (mnmsrvc [On_Demand | Stopped])
[2004.08.17 18:04:58 | 00,113,664 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\netdde.exe -- (NetDDE [Disabled | Stopped])
[2004.08.17 18:04:58 | 00,113,664 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\netdde.exe -- (NetDDEdsdm [Disabled | Stopped])
[2001.08.06 07:41:48 | 00,028,672 | ---- | M] () -- C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe -- (nhksrv [Auto | Running])
[2006.08.11 19:42:50 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2006.10.26 21:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2006.10.26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2004.08.17 18:05:04 | 00,108,544 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\services.exe -- (PlugPlay [Auto | Running])
[2004.08.17 18:05:06 | 00,141,312 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\sessmgr.exe -- (RDSessMgr [On_Demand | Stopped])
[2004.08.17 18:05:04 | 00,096,768 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\scardsvr.exe -- (SCardSvr [On_Demand | Stopped])
[2004.08.17 18:05:06 | 00,091,648 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\smlogsvc.exe -- (SysmonLog [On_Demand | Stopped])
[2004.08.17 18:05:08 | 00,073,216 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\tlntsvr.exe -- (TlntSvr [Disabled | Stopped])
[2004.08.17 18:05:10 | 00,290,304 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\vssvc.exe -- (VSS [On_Demand | Stopped])
[2004.08.17 18:05:12 | 00,126,464 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\wbem\wmiapsrv.exe -- (WmiApSrv [On_Demand | Stopped])
========== Driver Services ==========
[2004.04.30 09:37:02 | 00,160,640 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\a347bus.sys -- (a347bus [Boot | Running])
[2004.04.30 09:33:00 | 00,005,248 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\a347scsi.sys -- (a347scsi [Boot | Running])
[2008.07.19 20:32:15 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
[2004.08.17 17:46:54 | 00,188,288 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\acpi.sys -- (ACPI [Boot | Running])
[2001.10.21 04:00:00 | 00,011,776 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\System32\drivers\acpiec.sys -- (ACPIEC [Disabled | Stopped])
[2008.07.19 20:37:42 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
[2008.07.19 20:37:21 | 00,094,416 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
[2008.07.19 20:33:42 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
[2008.07.19 20:35:18 | 00,078,416 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
[2008.07.19 20:32:36 | 00,042,912 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
[2004.08.03 22:59:44 | 00,095,360 | ---- | M] () -- C:\WINDOWS\system32\drivers\atapi.sys -- (atapi [Boot | Running])
[2001.10.21 04:00:00 | 00,034,944 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\System32\drivers\fips.sys -- (Fips [System | Running])
[2001.10.21 04:00:00 | 00,125,440 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\ftdisk.sys -- (Ftdisk [Boot | Running])
[2005.01.07 19:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2004.08.17 17:51:24 | 00,053,376 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\i8042prt.sys -- (i8042prt [System | Stopped])
[2006.09.12 17:27:00 | 04,381,184 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService [On_Demand | Running])
[2001.10.19 22:22:20 | 00,036,096 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\isapnp.sys -- (isapnp [Boot | Running])
[2004.08.17 17:54:38 | 00,024,832 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\kbdclass.sys -- (Kbdclass [System | Running])
[2004.08.17 17:54:38 | 00,014,848 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid [System | Running])
[2004.08.17 18:16:30 | 00,030,208 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\System32\drivers\modem.sys -- (Modem [On_Demand | Stopped])
[2004.08.17 17:47:34 | 00,023,296 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\mouclass.sys -- (Mouclass [System | Running])
[2001.10.19 22:33:10 | 00,012,160 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\mouhid.sys -- (mouhid [On_Demand | Running])
[2001.12.20 10:02:12 | 00,006,656 | ---- | M] (Netropa Corporation) -- C:\WINDOWS\system32\drivers\Msikbd2k.sys -- (msikbd2k [System | Running])
[2006.08.11 19:42:42 | 03,958,496 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2004.08.17 18:16:30 | 00,080,128 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\parport.sys -- (Parport [On_Demand | Running])
[2001.10.21 04:00:00 | 00,006,912 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\System32\drivers\parvdm.sys -- (ParVdm [Auto | Running])
[2004.08.17 17:46:56 | 00,068,480 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\pci.sys -- (PCI [Boot | Running])
[2001.10.19 22:32:14 | 00,003,328 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\pciide.sys -- (PCIIde [Boot | Running])
[2004.08.17 17:47:02 | 00,119,936 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\System32\drivers\pcmcia.sys -- (Pcmcia [Disabled | Stopped])
[2001.10.21 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2004.08.17 21:49:32 | 00,058,112 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\redbook.sys -- (redbook [System | Running])
[2006.02.27 03:46:20 | 00,081,408 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp [On_Demand | Running])
[2007.06.25 18:02:59 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [Auto | Running])
[2004.08.17 17:51:24 | 00,065,408 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\serial.sys -- (Serial [System | Running])
[2005.03.03 23:53:57 | 00,048,640 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01 [Boot | Running])
[2005.02.23 21:59:54 | 00,006,656 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02 [Boot | Running])
[2004.10.06 15:47:16 | 00,019,840 | ---- | M] (Protection Technology) -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02 [Boot | Running])
[2004.08.17 17:58:30 | 00,073,472 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\drivers\sr.sys -- (sr [Boot | Running])
[2005.08.30 01:47:38 | 00,058,320 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus [On_Demand | Stopped])
[2005.08.30 01:49:34 | 00,008,336 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl [On_Demand | Stopped])
[2005.08.30 01:49:38 | 00,094,000 | ---- | M] (MCCI) -- C:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm [On_Demand | Stopped])
[2004.08.17 17:53:24 | 00,051,968 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\System32\drivers\volsnap.sys -- (VolSnap [Boot | Running])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.apeha.ru
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Корпорация Майкрософт)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.apeha.ru
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Корпорация Майкрософт)
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O3) Toolbars ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" (HKLM) -- C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" (HKLM) -- C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0E5CBF21-D15F-11D0-8301-00AA005B4383}" (HKLM) -- C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" (HKLM) -- C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" (HKLM) -- C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0E5CBF21-D15F-11D0-8301-00AA005B4383}" (HKLM) -- C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=ALCMTR.EXE (Realtek Semiconductor Corp.)
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
"MULTIMEDIA KEYBOARD"=C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe (Netropa Corp.)
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
"nwiz"=nwiz.exe /install ()
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
"RTHDCPL"=RTHDCPL.EXE (Realtek Semiconductor Corp.)
"SkyTel"=SkyTel.EXE (Realtek Semiconductor Corp.)
========== (O4) Startup Folders ==========
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&Экспорт в Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2006.10.27 17:07:36 | 17,891,112 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\Software\Microsoft\Internet Explorer\MenuExt\]
&Экспорт в Microsoft Excel: C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [2006.10.27 17:07:36 | 17,891,112 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006.10.26 22:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004.08.17 18:17:40 | 01,667,584 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004.08.17 18:17:40 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006.10.26 22:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004.08.17 18:17:40 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1547161642-583907252-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2006.10.26 22:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004.08.17 18:17:40 | 01,667,584 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O17) DNS Name Servers ==========
{D86BBC12-4D04-4580-8D02-CC63B4DE5EEC} (Servers: | Description: Realtek RTL8169/8110 Family Gigabit Ethernet NIC)
========== (O20) HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=Explorer.exe
>[2004.08.17 18:04:48 | 01,032,704 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\explorer.exe
"UserInit"=C:\WINDOWS\system32\userinit.exe,
>[2004.08.17 18:05:10 | 00,025,088 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\userinit.exe
"UIHost"=logonui.exe
>[2004.08.17 18:04:52 | 00,515,072 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\logonui.exe
"VMApplet"=rundll32 shell32,Control_RunDLL "sysdm.cpl"
>[2004.08.17 18:04:30 | 08,401,408 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\shell32.dll
>[2004.08.17 18:05:12 | 00,300,032 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\sysdm.cpl
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll -- C:\WINDOWS\system32\crypt32.dll (Корпорация Майкрософт)
cscdll: "DllName" = cscdll.dll -- C:\WINDOWS\system32\cscdll.dll (Корпорация Майкрософт)
ScCertProp: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Корпорация Майкрософт)
Schedule: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Корпорация Майкрософт)
sclgntfy: "DllName" = sclgntfy.dll -- C:\WINDOWS\system32\sclgntfy.dll (Корпорация Майкрософт)
SensLogn: "DllName" = WlNotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Корпорация Майкрософт)
termsrv: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Корпорация Майкрософт)
wlballoon: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Корпорация Майкрософт)
========== (O21) SSODL Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CDBurn"={fbeb8a05-beee-4442-804e-409d6c4515e9} (HKLM) -- C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"={7849596a-48ea-486e-8937-a2a3009f31a9} (HKLM) -- C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysTray"={35CEC8A3-2BE6-11D2-8773-92E220524153} (HKLM) -- C:\WINDOWS\system32\stobject.dll (Корпорация Майкрософт)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} (HKLM) -- C:\WINDOWS\system32\webcheck.dll (Корпорация Майкрософт)
========== (O22) Shared Task Scheduler ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}" (HKLM) = Предзагрузчик Browseui -- C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{8C7461EF-2B13-11d2-BE35-3078302C2030}" (HKLM) = Демон кэша категорий компонентов -- C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) -- C:\WINDOWS\system32\shell32.dll (Корпорация Майкрософт)
========== HKLM *SecurityProviders* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>[2004.08.17 18:04:14 | 00,068,608 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\digest.dll
>[2004.08.17 18:04:24 | 00,290,816 | ---- | M] (Корпорация Майкрософт) -- C:\WINDOWS\system32\msnsspc.dll
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2007.06.06 18:47:59 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[2008.11.01 07:40:45 | 00,422,400 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Администратор\Рабочий стол\OTViewIt.exe
[2008.11.01 07:40:10 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2008.10.31 11:16:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Администратор\Рабочий стол\temp
[2008.10.31 10:52:14 | 00,000,000 | ---D | C] -- C:\rsit
[2008.10.31 10:23:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Администратор\Application Data\Malwarebytes
[2008.10.31 10:22:59 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008.10.31 10:22:56 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008.10.31 10:22:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008.10.31 10:22:55 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008.10.31 10:01:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Документы\мои документы
[2008.10.31 08:15:02 | 00,010,174 | ---- | C] () -- C:\Documents and Settings\Администратор\Рабочий стол\Документ Microsoft Office Word.docx
[2008.10.31 07:25:05 | 00,069,614 | ---- | C] () -- C:\Documents and Settings\Администратор\Рабочий стол\audio.htm
[2008.10.31 05:33:15 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Администратор\Рабочий стол\HijackThis.lnk
[2008.10.31 04:34:19 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2008.10.31 04:34:18 | 00,042,912 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2008.10.31 04:34:17 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2008.10.31 04:34:16 | 00,094,392 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2008.10.31 04:34:15 | 00,094,416 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2008.10.31 04:34:15 | 00,093,264 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2008.10.31 04:34:15 | 00,078,416 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2008.10.31 04:34:15 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2008.10.31 04:34:03 | 01,163,960 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2008.10.31 04:34:03 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2008.10.31 04:34:01 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2008.10.31 02:34:52 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2008.10.31 02:34:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008.10.30 06:55:20 | 00,000,000 | ---D | C] -- C:\$AVG8.VAULT$
[2008.10.30 05:05:18 | 27,321,964 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\incavi.avm
[2008.10.30 05:05:18 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\avi7.avg
[2008.10.30 05:05:18 | 00,211,986 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\miniavi.avg
[2008.10.30 05:05:18 | 00,106,501 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg(2)\microavi.avg
[2008.10.30 05:05:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg(2)
[2008.10.30 05:05:06 | 00,000,000 | ---D | C] -- C:\Program Files\AVG(2)
[2008.10.30 05:05:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8(2)
[2008.10.30 04:28:35 | 00,000,000 | ---D | C] -- C:\Program Files\The Cleaner Demo
[2008.10.30 04:24:38 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008.10.08 18:57:12 | 00,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2008.10.08 11:11:32 | 00,000,275 | ---- | C] () -- C:\Documents and Settings\Администратор\Рабочий стол\Ярлык для Локальный диск (D).lnk
[2008.10.08 10:46:46 | 00,000,792 | ---- | C] () -- C:\Documents and Settings\Администратор\Рабочий стол\Проигрыватель Windows Media.lnk
[2008.10.08 10:46:42 | 00,001,491 | ---- | C] () -- C:\Documents and Settings\Администратор\Рабочий стол\Косынка.lnk
[2008.10.08 08:58:48 | 00,000,000 | ---D | C] -- C:\Games
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2008.11.01 07:40:46 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Администратор\Рабочий стол\OTViewIt.exe
[2008.11.01 07:39:07 | 00,000,245 | ---- | M] () -- C:\WINDOWS\Msiosd.ini
[2008.11.01 07:36:46 | 00,000,698 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2008.11.01 07:12:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008.11.01 07:12:03 | 00,081,191 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2008.11.01 07:11:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008.11.01 01:08:29 | 04,307,140 | -H-- | M] () -- C:\Documents and Settings\Администратор\Local Settings\Application Data\IconCache.db
[2008.10.31 09:54:54 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008.10.31 08:17:45 | 00,010,174 | ---- | M] () -- C:\Documents and Settings\Администратор\Рабочий стол\Документ Microsoft Office Word.docx
[2008.10.31 07:25:18 | 00,069,614 | ---- | M] () -- C:\Documents and Settings\Администратор\Рабочий стол\audio.htm
[2008.10.31 05:33:15 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Администратор\Рабочий стол\HijackThis.lnk
[2008.10.31 04:34:18 | 00,005,758 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2008.10.30 05:05:21 | 27,321,964 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\incavi.avm
[2008.10.30 05:05:18 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\avi7.avg
[2008.10.30 05:05:18 | 00,211,986 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\miniavi.avg
[2008.10.30 05:05:18 | 00,106,501 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg(2)\microavi.avg
[2008.10.22 16:10:38 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008.10.22 16:10:22 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008.10.10 20:46:13 | 00,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2008.10.08 11:11:32 | 00,000,275 | ---- | M] () -- C:\Documents and Settings\Администратор\Рабочий стол\Ярлык для Локальный диск (D).lnk
< End of report >