Созданные ответы форума
-
АвторСообщения
-
ComboFix 10-10-18.03 — User 19.10.2010 21:03:38.1.2 — x86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.2047.1543 [GMT 4:00]
Running from: c:documents and settingsUserРабочий столComboFix.exe
Command switches used :: c:documents and settingsUserРабочий столWindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.c:documents and settingsUserRecentThumbs.db
c:program filesMail.RuAgentMradllnewmrasearch.dll
c:windowsstruct~.ini
c:windowssystem32Thumbs.db.
((((((((((((((((((((((((( Files Created from 2010-09-19 to 2010-10-19 )))))))))))))))))))))))))))))))
.2010-10-14 13:48 . 2010-10-14 13:48
d
w- C:VKLife
2010-10-13 14:42 . 2010-10-13 14:42
d
w- c:documents and settingsUserLocal SettingsApplication DataHelp
2010-10-08 12:09 . 2010-10-08 12:09
d
w- c:documents and settingsAll UsersApplication DataPrettyMay
2010-10-06 11:59 . 2010-10-06 11:59
d
w- c:program filesIllustrate
2010-10-04 17:36 . 2010-10-04 17:36 65536 —-a-r- c:documents and settingsUserApplication DataMicrosoftInstaller{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2010-10-04 17:36 . 2010-10-04 17:36
d
w- c:documents and settingsAll UsersApplication DataInstallShield
2010-10-04 17:35 . 2010-10-04 17:35
d
w- c:program filesCorel
2010-10-04 17:35 . 2010-10-04 17:35
d
w- c:program filesCommon FilesCorel
2010-10-04 17:07 . 2010-10-04 17:08
d
w- c:documents and settingsAll UsersApplication DataProtexis
2010-10-04 15:28 . 2010-10-04 15:28 348256 —-a-w- c:documents and settingsAll UsersApplication DataMicrosoftVSTAHostCorelPHOTOPAINT9.01033ResourceCache.dll
2010-10-04 15:28 . 2010-10-04 15:28 348256 —-a-w- c:documents and settingsAll UsersApplication DataMicrosoftVSTAHostCorelDRAW9.01033ResourceCache.dll
2010-10-04 15:27 . 2010-10-04 15:27 416 —-a-w- c:documents and settingsAll UsersApplication DataMicrosoftMSDN9.01033ResourceCache.dll
2010-10-04 15:25 . 2010-10-04 15:25
d
w- c:program filesMicrosoft SDKs
2010-10-04 15:25 . 2010-10-04 15:25
d
w- c:program filesMicrosoft Visual Studio 9.0
2010-10-04 15:04 . 2010-10-04 15:04
d
w- c:program filesExlevel
2010-10-04 14:08 . 2010-10-04 14:08
d
w- c:program filesMAXON
2010-10-04 14:03 . 2010-10-04 15:03
d
w- c:program filesAutodesk
2010-10-04 09:35 . 2010-10-04 09:35
d
w- c:documents and settingsUserLocal SettingsApplication DataMicrosoft_Corporation
2010-09-30 17:52 . 2010-09-30 17:52
d
w- c:program filesSystemRequirementsLab
2010-09-30 17:52 . 2010-09-30 17:52
d
w- c:documents and settingsUserApplication DataSystemRequirementsLab
2010-09-30 17:31 . 2010-09-30 17:31
d—h—w- c:windowsPIF
2010-09-30 17:30 . 2010-09-30 17:30
d
w- c:program filesEverest
2010-09-30 13:54 . 2010-10-13 14:17
d
w- c:program filestrend micro
2010-09-25 19:40 . 2010-09-25 19:40
d
w- c:windowssystem32wbemRepository
2010-09-25 19:35 . 2010-09-25 19:35
d
w- c:program filesCommon FilesBorland
2010-09-25 19:34 . 2010-09-25 19:34
d
w- c:documents and settingsAll UsersApplication DataNOS.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 20:07 . 2010-05-14 17:13 119808 —-a-w- c:program filesmozilla firefoxcomponentsGoogleDesktopMozilla.dll
.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
«uTorrent»=»c:program filesuTorrentuTorrent.exe» [2010-09-26 328056][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
«egui»=»c:program filesESETESET NOD32 Antivirusegui.exe» [2010-04-07 2145000]
«Google Desktop Search»=»c:program filesGoogleGoogle Desktop SearchGoogleDesktop.exe» [2010-07-31 30192]
«Antirun»=»c:program filesAntirunantirun.exe» [2010-05-28 574976]
«NvCplDaemon»=»c:windowssystem32NvCpl.dll» [2010-04-03 13670504][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=»c:windowssystem32CTFMON.EXE» [2008-04-14 15360][HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrolsession manager]
BootExecute REG_MULTI_SZ autocheck autochk *OODBS[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMAgent]
2010-05-14 18:56 5598392 —-a-w- c:program filesMail.RuAgentmagent.exe[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMan]
2008-08-19 09:26 77824 —-a-w- c:windowsSOUNDMAN.EXE[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupreguTorrent]
2010-09-26 06:22 328056 —-a-w- c:program filesuTorrentuTorrent.exe[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionrun-]
«uTorrent»=»c:program filesuTorrentuTorrent.exe»
«Skype»=»c:program filesSkypePhoneSkype.exe» /nosplash /minimized[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionrun-]
«AlcWzrd»=ALCWZRD.EXE
«NvMediaCenter»=RUNDLL32.EXE c:windowssystem32NvMcTray.dll,NvTaskbarInit
«OODefragTray»=c:program filesOO SoftwareDefragoodtray.exe
«GrooveMonitor»=»c:program filesMicrosoft OfficeOffice12GrooveMonitor.exe»
«MAgent»=c:program filesMail.RuAgentMAgent.exe -LM
«QuickTime Task»=»c:program filesQuickTimeQTTask.exe» -atboottime
«KernelFaultCheck»=%systemroot%system32dumprep 0 -k
«Acrobat Assistant 8.0″=»c:program filesAdobeAcrobat 9.0AcrobatAcrotray.exe»
«AdobeCS5ServiceManager»=»c:program filesCommon FilesAdobeCS5ServiceManagerCS5ServiceManager.exe» -launchedbylogin
«Adobe ARM»=»c:program filesCommon FilesAdobeARM1.0AdobeARM.exe»
«AdobeAAMUpdater-1.0″=»c:program filesCommon FilesAdobeOOBEPDAppUWAUpdaterStartupUtility.exe»
«SwitchBoard»=c:program filesCommon FilesAdobeSwitchBoardSwitchBoard.exe
«Adobe Reader Speed Launcher»=»c:program filesAdobeReader 9.0ReaderReader_sl.exe»
«Adobe Acrobat Speed Launcher»=»c:program filesAdobeAcrobat 9.0AcrobatAcrobat_sl.exe»
«SunJavaUpdateSched»=»c:program filesCommon FilesJavaJava Updatejusched.exe»
«ISUSPM Startup»=c:progra~1COMMON~1INSTAL~1UPDATE~1ISUSPM.exe -startup
«ISUSScheduler»=»c:program filesCommon FilesInstallShieldUpdateServiceissch.exe» -start
«2Gis Update Notifier»=»c:program files2gis3.02GISTrayNotifier.exe» -delayed_start[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
«%windir%\Network Diagnostic\xpnetdiag.exe»=
«%windir%\system32\sessmgr.exe»=
«c:\Program Files\uTorrent\uTorrent.exe»=
«c:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE»=
«c:\Program Files\Microsoft Office\Office12\GROOVE.EXE»=
«c:\Program Files\Microsoft Office\Office12\ONENOTE.EXE»=
«c:\Program Files\Mail.Ru\Agent\magent.exe»=
«c:\Program Files\Ubisoft\Related Designs\ANNO 1404\tools\Anno4Web.exe»=
«c:\Program Files\Ubisoft\Related Designs\ANNO 1404\tools\AddonWeb.exe»=
«c:\Program Files\Skype\Plugin Manager\skypePM.exe»=
«c:\Program Files\Autodesk\Backburner\monitor.exe»=
«c:\Program Files\Autodesk\Backburner\manager.exe»=
«c:\Program Files\Autodesk\Backburner\server.exe»=
«c:\Program Files\Autodesk\3ds Max 2009\3dsmax.exe»=
«c:\Program Files\Skype\Phone\Skype.exe»=R0 iteraid;ITERAID_Service_Install;c:windowssystem32driversiteraid.sys [14.05.2010 17:36 26112]
R1 ehdrv;ehdrv;c:windowssystem32driversehdrv.sys [07.04.2010 21:07 114984]
R1 epfwtdir;epfwtdir;c:windowssystem32driversepfwtdir.sys [07.04.2010 21:08 95872]
R2 ekrn;ESET Service;c:program filesESETESET NOD32 Antivirusekrn.exe [07.04.2010 21:07 810120]
R2 GatewayAgentService;O&O Gateway Agent Service;c:program filesOO SoftwareSharedGatewayAgentooemcgats.exe [28.08.2009 11:31 315392]
R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:program filesAutodesk3ds Max 2009mentalraysatelliteraysat_3dsMax2009_32server.exe [10.03.2008 0:04 65536]
R3 Ca2001v;CA2001 WebCam Driver;c:windowssystem32driversCa2001v.sys [19.02.2008 11:48 2333568]
S3 2GISUpdateService;2GIS UpdateService;c:program files2gis3.02GISUpdateService.exe [29.09.2010 12:50 837464]
S3 GoogleDesktopManager-051210-111108;Диспетчер Google Desktop 5.9.1005.12335;c:program filesGoogleGoogle Desktop SearchGoogleDesktop.exe [14.05.2010 21:13 30192]
S3 SwitchBoard;SwitchBoard;c:program filesCommon FilesAdobeSwitchBoardSwitchBoard.exe [19.02.2010 13:37 517096]
S3 vaxscsi;vaxscsi;c:windowssystem32driversvaxscsi.sys [14.05.2010 22:25 223128]
S4 sptd;sptd;c:windowssystem32driverssptd.sys [14.05.2010 22:21 642560]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost — NetSvcs
UxTuneUp
.
Contents of the ‘Scheduled Tasks’ folder2010-10-09 c:windowsTasksAdobeAAMUpdater-1.0-2-80C435F26AB94-User.job
— c:program filesCommon FilesAdobeOOBEPDAppUWAupdaterstartuputility.exe [2010-08-11 23:44]2010-07-26 c:windowsTasksAppleSoftwareUpdate.job
— c:program filesApple Software UpdateSoftwareUpdate.exe [2008-07-30 08:34]
.
.
Supplementary Scan
.
uStart Page = http://www.APEHA.ru
mStart Page = hxxp://www.apeha.ru
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Экспорт в Microsoft Excel — c:progra~1MICROS~2Office12EXCEL.EXE/3000
IE: Online-словари — c:program filesPRMT8PRMTIEoda.htm
IE: Автоматически определить шаблон тематики — c:program filesPRMT8PRMTIEaot.htm
IE: Добавить к существующему PDF — c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppend.html
IE: Добавить содержимое по ссылке в существующий файл PDF — c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Настроить параметры перевода — c:program filesPRMT8PRMTIEoptions.htm
IE: Незнакомые слова — c:program filesPRMT8PRMTIEinfopanel.htm
IE: Открыть словарную статью — c:program filesPRMT8PRMTIEaddentry.htm
IE: Перевести — c:program filesPRMT8PRMTIEtranslat.htm
IE: Перевести страницу — c:program filesPRMT8PRMTIEpage.htm
IE: Поиск в Интернете — c:program filesPRMT8PRMTIEsearch.htm
IE: Поиск@Mail.Ru — c:program filesMail.RuSputnikMailRuSputnik.dll/282
IE: Преобразовать в Adobe PDF — c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECapture.html
IE: Преобразовать содержимое по ссылке в PDF — c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Словари@Mail.Ru — c:program filesMail.RuSputnikMailRuSputnik.dll/283
IE: {{4034D172-4C52-49de-A6A1-E75F8F591FEC} — c:program filesPRMT8PRMTIEoptions.htm
IE: {{7558B7E5-7B26-4201-BEDB-00D5FF534523} — c:program filesMail.RuAgentmagent.exe
IE: {{A2DA13D5-AC77-43b7-963B-40445EBCB8E0} — c:program filesPRMT8PRMTIEprmtie5.htm
FF — ProfilePath — c:documents and settingsUserApplication DataMozillaFirefoxProfiles631ds4jz.default
FF — prefs.js: browser.search.selectedEngine — Google
FF — prefs.js: browser.startup.homepage — hxxp://www.mail.ru
FF — component: c:program filesMozilla Firefoxextensions{AB2CE124-6272-4b12-94A9-7303C7397BD1}componentsSkypeFfComponent.dll
FF — plugin: c:program filesJavajre6binnew_pluginnpdeployJava1.dll
FF — plugin: c:program filesK-Lite Codec PackRealbrowserpluginsnppl3260.dll
FF — plugin: c:program filesK-Lite Codec PackRealbrowserpluginsnprpjplug.dll—- FIREFOX POLICIES —-
c:program filesMozilla Firefoxgreprefsall.js — pref(«network.IDN.whitelist.xn--mgbaam7a8h», true);
c:program filesMozilla Firefoxgreprefsall.js — pref(«network.IDN.whitelist.xn--mgberp4a5d4ar», true);
c:program filesMozilla Firefoxdefaultspreffirefox.js — pref(«dom.ipc.plugins.enabled», false);
.
.
File Associations
.
.scr=AutoCADScriptFile
.
— — — — ORPHANS REMOVED — — — —AddRemove-_{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91} — c:program filesCorelCorelDRAW Graphics Suite 13ProgramsMSILauncher {7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}
.
DLLs Loaded Under Running Processes
— — — — — — — > ‘explorer.exe'(3780)
c:windowssystem32WPDShServiceObj.dll
c:windowssystem32PortableDeviceTypes.dll
c:windowssystem32PortableDeviceApi.dll
.
Other Running Processes
.
c:windowssystem32nvsvc32.exe
c:program filesCommon FilesAutodesk SharedServiceAdskScSrv.exe
c:program filesJavajre6binjqs.exe
c:program filesOO SoftwareDefragoodag.exe
c:program filesAlcohol SoftAlcohol 120StarWindStarWindService.exe
c:windowsSystem32TUProgSt.exe
c:windowssystem32wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-10-19 21:13:23 — machine was rebooted
ComboFix-quarantined-files.txt 2010-10-19 17:13Pre-Run: 12 282 417 152 begin_of_the_skype_highlighting 12 282 417 152 end_of_the_skype_highlighting байт свободно
Post-Run: 12 489 850 880 байт свободноWindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)WINDOWS
[operating systems]
c:cmdconsBOOTSECT.DAT=»Microsoft Windows Recovery Console» /cmdcons
UnsupportedDebug=»do not select this» /debug
multi(0)disk(0)rdisk(0)partition(1)WINDOWS=»Microsoft Windows XP Professional RU» /noexecute=optin /fastdetect— — End Of File — — 39BA60F3CA661DDBEA1A026A201C0521
Logfile of random’s system information tool 1.08 (written by random/random)
Run by User at 2010-10-13 18:17:35
Microsoft Windows XP Professional Service Pack 3
System drive C: has 8 GB (16%) free of 50 GB
Total RAM: 2047 MB (68% free)Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:17:49, on 13.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesESETESET NOD32 Antivirusegui.exe
C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
C:Program FilesAntirunantirun.exe
C:Program Files2gis3.02GISTrayNotifier.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesuTorrentuTorrent.exe
C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
C:Program FilesESETESET NOD32 Antivirusekrn.exe
C:Program FilesOO SoftwareSharedGatewayAgentooemcgats.exe
C:Program FilesJavajre6binjqs.exe
C:Program FilesAutodesk3ds Max 2009mentalraysatelliteraysat_3dsMax2009_32server.exe
C:Program FilesOO SoftwareDefragoodag.exe
C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32TUProgSt.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:Documents and SettingsUserРабочий столRSIT.exe
C:Program Filestrend microUser.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.APEHA.ru
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.apeha.ru
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
R3 — URLSearchHook: (no name) — {83821C2B-32A8-4DD7-B6D4-44309A78E668} — C:Program FilesMail.RuAgentMradllnewmrasearch.dll
O2 — BHO: AcroIEHelperStub — {18DF081C-E8AD-4283-A596-FA578C2EBDC3} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O2 — BHO: Adobe PDF Conversion Toolbar Helper — {AE7CD045-E861-484f-8273-0445EE161910} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll
O2 — BHO: SkypeIEPluginBHO — {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} — C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O2 — BHO: URLToolBHO — {B2150688-1AA5-4698-90BE-C3CBECBB5786} — (no file)
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: JQSIEStartDetectorImpl — {E7E6F031-17CE-4C07-BC86-EABFE594F69C} — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O2 — BHO: SmartSelect — {F4971EE7-DAA0-4053-9964-665D8EE6A077} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O3 — Toolbar: PROMT — {892E81F6-EC63-4d13-8422-835A7A05D6EB} — C:Program FilesPRMT8PRMTIEprmtie.dll
O3 — Toolbar: Adobe PDF — {47833539-D0C5-4125-9FA8-0819E2EAAC93} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll
O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
O4 — HKLM..Run: [Google Desktop Search] «C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe» /startup
O4 — HKLM..Run: [Antirun] C:Program FilesAntirunantirun.exe
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [Alcmtr] ALCMTR.EXE
O4 — HKLM..Run: [2Gis Update Notifier] «C:Program Files2gis3.02GISTrayNotifier.exe» -delayed_start
O4 — HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 — HKCU..Run: [uTorrent] «C:Program FilesuTorrentuTorrent.exe»
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O8 — Extra context menu item: Online-словари — C:Program FilesPRMT8PRMTIEoda.htm
O8 — Extra context menu item: Автоматически определить шаблон тематики — C:Program FilesPRMT8PRMTIEaot.htm
O8 — Extra context menu item: Добавить к существующему PDF — res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppend.html
O8 — Extra context menu item: Добавить содержимое по ссылке в существующий файл PDF — res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 — Extra context menu item: Настроить параметры перевода — C:Program FilesPRMT8PRMTIEoptions.htm
O8 — Extra context menu item: Незнакомые слова — C:Program FilesPRMT8PRMTIEinfopanel.htm
O8 — Extra context menu item: Открыть словарную статью — C:Program FilesPRMT8PRMTIEaddentry.htm
O8 — Extra context menu item: Перевести — C:Program FilesPRMT8PRMTIEtranslat.htm
O8 — Extra context menu item: Перевести страницу — C:Program FilesPRMT8PRMTIEpage.htm
O8 — Extra context menu item: Поиск в Интернете — C:Program FilesPRMT8PRMTIEsearch.htm
O8 — Extra context menu item: Поиск@Mail.Ru — res://C:Program FilesMail.RuSputnikMailRuSputnik.dll/282
O8 — Extra context menu item: Преобразовать в Adobe PDF — res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECapture.html
O8 — Extra context menu item: Преобразовать содержимое по ссылке в PDF — res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 — Extra context menu item: Словари@Mail.Ru — res://C:Program FilesMail.RuSputnikMailRuSputnik.dll/283
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 — Extra button: (no name) — {4034D172-4C52-49de-A6A1-E75F8F591FEC} — C:Program FilesPRMT8PRMTIEoptions.htm
O9 — Extra ‘Tools’ menuitem: Настроить параметры перевода — {4034D172-4C52-49de-A6A1-E75F8F591FEC} — C:Program FilesPRMT8PRMTIEoptions.htm
O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra button: Skype add-on for Internet Explorer — {898EA8C8-E7FF-479B-8935-AEC46303B9E5} — C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O9 — Extra ‘Tools’ menuitem: Skype add-on for Internet Explorer — {898EA8C8-E7FF-479B-8935-AEC46303B9E5} — C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 — Extra button: (no name) — {A2DA13D5-AC77-43b7-963B-40445EBCB8E0} — C:Program FilesPRMT8PRMTIEprmtie5.htm
O9 — Extra ‘Tools’ menuitem: Перевести — {A2DA13D5-AC77-43b7-963B-40445EBCB8E0} — C:Program FilesPRMT8PRMTIEprmtie5.htm
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra button: Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O9 — Extra ‘Tools’ menuitem: Windows Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O17 — HKLMSystemCCSServicesTcpip..{E474A615-AC6F-4964-A16C-0C793343DBC3}: NameServer = 85.113.62.227 85.113.63.252
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:PROGRA~1MICROS~2Office12GR99D3~1.DLL
O18 — Protocol: skype-ie-addon-data — {91774881-D725-4E58-B298-07617B9B86A8} — C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O20 — AppInit_DLLs: C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL
O22 — SharedTaskScheduler: Предзагрузчик Browseui — {438755C2-A8BA-11D1-B96B-00A0C90312E1} — C:WINDOWSsystem32browseui.dll
O22 — SharedTaskScheduler: Демон кэша категорий компонентов — {8C7461EF-2B13-11d2-BE35-3078302C2030} — C:WINDOWSsystem32browseui.dll
O23 — Service: 2GIS UpdateService (2GISUpdateService) — ООО ДубльГИС — C:Program Files2gis3.02GISUpdateService.exe
O23 — Service: Autodesk Licensing Service — Autodesk — C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
O23 — Service: ESET HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
O23 — Service: ESET Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: FLEXnet Licensing Service — Acresso Software Inc. — C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 — Service: O&O Gateway Agent Service (GatewayAgentService) — O&O Software GmbH — C:Program FilesOO SoftwareSharedGatewayAgentooemcgats.exe
O23 — Service: Диспетчер Google Desktop 5.9.1005.12335 (GoogleDesktopManager-051210-111108) — Google — C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Macrovision Corporation — C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Java Quick Starter (JavaQuickStarterService) — Sun Microsystems, Inc. — C:Program FilesJavajre6binjqs.exe
O23 — Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) — Unknown owner — C:Program FilesAutodesk3ds Max 2009mentalraysatelliteraysat_3dsMax2009_32server.exe
O23 — Service: NetMeeting Remote Desktop Sharing (mnmsrvc) — Корпорация Майкрософт — C:WINDOWSsystem32mnmsrvc.exe
O23 — Service: NVIDIA Display Driver Service (nvsvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
O23 — Service: O&O Defrag — O&O Software GmbH — C:Program FilesOO SoftwareDefragoodag.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: StarWind iSCSI Service (StarWindService) — Rocket Division Software — C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe
O23 — Service: SwitchBoard — Adobe Systems Incorporated — C:Program FilesCommon FilesAdobeSwitchBoardSwitchBoard.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: TuneUp Drive Defrag Service (TuneUp.Defrag) — TuneUp Software — C:WINDOWSSystem32TuneUpDefragService.exe
O23 — Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) — TuneUp Software — C:WINDOWSSystem32TUProgSt.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe—
End of file — 12345 bytes======Scheduled tasks folder======
C:WINDOWStasksAdobeAAMUpdater-1.0-2-80C435F26AB94-User.job
C:WINDOWStasksAppleSoftwareUpdate.job======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll [2010-04-03 75200][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-27 2210608][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2010-05-14 676704][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll [2010-04-03 349640][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer — C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll [2010-02-08 804136][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{B2150688-1AA5-4698-90BE-C3CBECBB5786}]
URLToolBHO[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2010-07-17 41760][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2010-07-17 79648][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll [2010-04-03 349640][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{09900DE8-1DCA-443F-9243-26FF581438AF} — Спутник@Mail.Ru — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2010-05-14 676704]
{892E81F6-EC63-4d13-8422-835A7A05D6EB} — PROMT — C:Program FilesPRMT8PRMTIEprmtie.dll [2007-03-21 749568]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} — Adobe PDF — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll [2010-04-03 349640][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«egui»=C:Program FilesESETESET NOD32 Antivirusegui.exe [2010-04-07 2145000]
«Google Desktop Search»=C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe [2010-08-01 30192]
«Antirun»=C:Program FilesAntirunantirun.exe [2010-05-29 574976]
«»= []
«NvCplDaemon»=C:WINDOWSsystem32NvCpl.dll [2010-04-03 13670504]
«Alcmtr»=C:WINDOWSALCMTR.EXE [2008-06-19 57344]
«2Gis Update Notifier»=C:Program Files2gis3.02GISTrayNotifier.exe [2010-09-29 4411736][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2008-04-14 15360]
«uTorrent»=C:Program FilesuTorrentuTorrent.exe [2010-09-26 328056][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMAgent]
C:Program FilesMail.RuAgentMAgent.exe [2010-05-14 5598392][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMan]
C:WINDOWSSOUNDMAN.EXE [2008-08-19 77824][HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupreguTorrent]
C:Program FilesuTorrentuTorrent.exe [2010-09-26 328056][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows]
«AppInit_DLLs»=»C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL»[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32WPDShServiceObj.dll [2006-08-24 133120][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL [2006-10-27 2210608][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=145[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=255[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«C:Program FilesuTorrentuTorrent.exe»=»C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent»
«C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE»=»C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook»
«C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE»=»C:Program FilesMicrosoft OfficeOffice12GROOVE.EXE:*:Enabled:Microsoft Office Groove»
«C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE»=»C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE:*:Enabled:Microsoft Office OneNote»
«C:Program FilesMail.RuAgentmagent.exe»=»C:Program FilesMail.RuAgentmagent.exe:*:Enabled:Mail.Ru Агент»
«C:Program FilesUbisoftRelated DesignsANNO 1404toolsAnno4Web.exe»=»C:Program FilesUbisoftRelated DesignsANNO 1404toolsAnno4Web.exe:*:Disabled:Anno4Web»
«C:Program FilesUbisoftRelated DesignsANNO 1404toolsAddonWeb.exe»=»C:Program FilesUbisoftRelated DesignsANNO 1404toolsAddonWeb.exe:*:Enabled:AddonWeb»
«E:ИГРЫCS 1.6 — Condition ZeroCounter-Strike 1.6 Condition Zero (by Veter)hl.exe»=»E:ИГРЫCS 1.6 — Condition ZeroCounter-Strike 1.6 Condition Zero (by Veter)hl.exe:*:Disabled:Half-Life Launcher»
«D:GAMESНовая папкаCounter-Strike 1.6 Condition Zero (by Veter)hl.exe»=»D:GAMESНовая папкаCounter-Strike 1.6 Condition Zero (by Veter)hl.exe:*:Disabled:Half-Life Launcher»
«M:skypeskype.exe»=»M:skypeskype.exe:*:Enabled:skype»
«C:Program FilesSkypePlugin ManagerskypePM.exe»=»C:Program FilesSkypePlugin ManagerskypePM.exe:*:Enabled:Skype Extras Manager»
«C:Program FilesAutodeskBackburnermonitor.exe»=»C:Program FilesAutodeskBackburnermonitor.exe:*:Enabled:backburner 2.3 monitor»
«C:Program FilesAutodeskBackburnermanager.exe»=»C:Program FilesAutodeskBackburnermanager.exe:*:Enabled:backburner 2.3 manager»
«C:Program FilesAutodeskBackburnerserver.exe»=»C:Program FilesAutodeskBackburnerserver.exe:*:Enabled:backburner 2.3 server»
«C:Program FilesAutodesk3ds Max 20093dsmax.exe»=»C:Program FilesAutodesk3ds Max 20093dsmax.exe:*:Enabled:Autodesk 3ds Max 2009 32-bit»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»
«M:SKYPE_PORTABLEskypeskype.exe»=»M:SKYPE_PORTABLEskypeskype.exe:*:Enabled:Skype «[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»======File associations======
.scr — open — C:WINDOWSsystem32notepad.exe «%1»
.scr — install —
.scr — config —======List of files/folders created in the last 1 months======
2010-10-13 18:17:35 —-D—- C:rsit
2010-10-08 16:09:21 —-D—- C:Documents and SettingsAll UsersApplication DataPrettyMay
2010-10-08 16:09:21 —-A—- C:WINDOWSstruct~.ini
2010-10-06 15:59:35 —-D—- C:Program FilesIllustrate
2010-10-04 21:36:56 —-D—- C:Documents and SettingsAll UsersApplication DataInstallShield
2010-10-04 21:35:08 —-D—- C:Program FilesCorel
2010-10-04 21:35:08 —-D—- C:Program FilesCommon FilesCorel
2010-10-04 21:07:08 —-D—- C:Documents and SettingsAll UsersApplication DataProtexis
2010-10-04 19:25:02 —-D—- C:Program FilesMicrosoft SDKs
2010-10-04 19:25:00 —-D—- C:Program FilesMicrosoft Visual Studio 9.0
2010-10-04 19:04:21 —-D—- C:Program FilesExlevel
2010-10-04 18:08:08 —-D—- C:Program FilesMAXON
2010-10-04 18:03:14 —-D—- C:Program FilesAutodesk
2010-09-30 21:52:26 —-D—- C:Program FilesSystemRequirementsLab
2010-09-30 21:52:21 —-D—- C:Documents and SettingsUserApplication DataSystemRequirementsLab
2010-09-30 21:31:02 —-HD—- C:WINDOWSPIF
2010-09-30 21:30:15 —-D—- C:Program FilesEverest
2010-09-30 17:54:00 —-D—- C:Program Filestrend micro
2010-09-25 23:35:19 —-D—- C:Program FilesCommon FilesBorland
2010-09-25 23:34:28 —-D—- C:Documents and SettingsUserApplication DataMozilla
2010-09-25 23:34:20 —-D—- C:Documents and SettingsAll UsersApplication DataNOS
2010-09-25 23:34:18 —-D—- C:Documents and SettingsAll UsersApplication DataNOS(2)
2010-09-24 22:35:12 —-D—- C:Documents and SettingsUserApplication DataMozilla(2)
2010-09-16 14:31:56 —-D—- C:WINDOWSsystem32driversumdf
2010-09-16 14:31:47 —-HDC—- C:WINDOWS$NtUninstallWMFDist11$
2010-09-15 17:15:52 —-D—- C:Documents and SettingsUserApplication DatadBpoweramp
2010-09-15 11:52:46 —-A—- C:WINDOWSsystem32apache.dll======List of files/folders modified in the last 1 months======
2010-10-13 18:17:42 —-D—- C:WINDOWSPrefetch
2010-10-13 18:17:36 —-D—- C:WINDOWSTemp
2010-10-13 18:10:06 —-D—- C:Documents and SettingsUserApplication DatauTorrent
2010-10-13 10:39:28 —-A—- C:WINDOWSSchedLgU.Txt
2010-10-09 17:32:04 —-RSD—- C:WINDOWSFonts
2010-10-09 14:42:53 —-D—- C:WINDOWSsystem32oodag
2010-10-08 17:08:09 —-D—- C:Config.Msi
2010-10-08 16:09:42 —-D—- C:Documents and SettingsUserApplication DataSkype
2010-10-08 16:09:21 —-D—- C:WINDOWS
2010-10-08 16:03:49 —-D—- C:Documents and SettingsUserApplication DataskypePM
2010-10-08 13:55:37 —-SHD—- C:WINDOWSInstaller
2010-10-07 21:26:28 —-D—- C:WINDOWSsystem32CatRoot2
2010-10-06 16:07:01 —-D—- C:WINDOWSsystem32
2010-10-06 16:07:00 —-RD—- C:Program Files
2010-10-05 11:37:01 —-D—- C:Documents and SettingsUserApplication DataCorel
2010-10-04 21:36:54 —-SD—- C:WINDOWSDownloaded Program Files
2010-10-04 21:36:54 —-D—- C:Program FilesCommon FilesInstallShield
2010-10-04 21:36:07 —-D—- C:WINDOWSWinSxS
2010-10-04 21:35:08 —-D—- C:Program FilesCommon Files
2010-10-04 21:25:51 —-D—- C:Documents and SettingsAll UsersApplication DataCorel
2010-10-04 21:23:07 —-RSD—- C:WINDOWSassembly
2010-10-04 19:30:24 —-D—- C:WINDOWSMicrosoft.NET
2010-10-04 19:28:36 —-D—- C:Documents and SettingsAll UsersApplication DataMicrosoft Help
2010-10-04 19:27:46 —-SD—- C:Documents and SettingsUserApplication DataMicrosoft
2010-10-04 19:27:46 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
2010-10-04 19:25:25 —-D—- C:Program FilesCommon FilesMicrosoft Shared
2010-10-04 18:04:38 —-D—- C:Program FilesCommon FilesAutodesk Shared
2010-10-04 18:03:38 —-D—- C:Documents and SettingsAll UsersApplication DataAutodesk
2010-10-04 18:03:08 —-HD—- C:WINDOWSinf
2010-10-04 18:03:08 —-D—- C:WINDOWSsystem32DirectX
2010-10-04 15:00:52 —-D—- C:Documents and SettingsUserApplication DataAutodesk
2010-10-04 13:29:51 —-D—- C:WINDOWSLhsp
2010-10-02 20:32:17 —-D—- C:Documents and SettingsUserApplication DataAdobe
2010-09-30 17:17:45 —-D—- C:Documents and SettingsUserApplication DataGraphisoft
2010-09-30 17:17:20 —-D—- C:WINDOWSsystem32drivers
2010-09-26 01:04:06 —-D—- C:Program FilesMozilla Firefox
2010-09-26 00:32:58 —-A—- C:WINDOWSIE4 Error Log.txt
2010-09-25 23:40:25 —-D—- C:WINDOWSsystem32config
2010-09-25 23:40:13 —-D—- C:WINDOWSsystem32wbem
2010-09-25 23:40:12 —-D—- C:WINDOWSRegistration
2010-09-25 23:36:19 —-HD—- C:Program FilesInstallShield Installation Information
2010-09-25 23:35:40 —-D—- C:WINDOWSsystem32ReinstallBackups
2010-09-25 23:35:39 —-RSHDC—- C:WINDOWSsystem32dllcache
2010-09-24 17:43:09 —-SD—- C:WINDOWSTasks
2010-09-16 14:31:56 —-D—- C:Program FilesWindows Media Player
2010-09-15 16:46:13 —-A—- C:WINDOWSsystem32SpoonUninstall.exe======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iteraid;ITERAID_Service_Install; C:WINDOWSsystem32DRIVERSiteraid.sys [2005-08-04 26112]
R0 ohci1394;VIA OHCI-совместимый IEEE 1394 хост-контроллер; C:WINDOWSsystem32DRIVERSohci1394.sys [2008-04-14 61696]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:WINDOWSSystem32driverssfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:WINDOWSSystem32driverssfhlp02.sys [2005-05-16 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:WINDOWSSystem32driverssfsync02.sys [2006-02-21 19968]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:WINDOWSSystem32driverssfvfs02.sys [2005-11-03 63488]
R0 sptd;sptd; C:WINDOWSSystem32Driverssptd.sys [2010-05-14 642560]
R1 ehdrv;ehdrv; C:WINDOWSsystem32DRIVERSehdrv.sys [2010-04-07 114984]
R1 epfwtdir;epfwtdir; C:WINDOWSsystem32DRIVERSepfwtdir.sys [2010-04-07 95872]
R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-14 40704]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; ??C:Program FilesUltraISOdriversISODrive.sys []
R2 eamon;eamon; C:WINDOWSsystem32DRIVERSeamon.sys [2010-04-07 139192]
R2 irda;ИК-протокол IrDA; C:WINDOWSsystem32DRIVERSirda.sys [2008-04-14 88192]
R3 Arp1394;Протокол клиента 1394 ARP; C:WINDOWSsystem32DRIVERSarp1394.sys [2008-04-14 60800]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:WINDOWSsystem32DRIVERSb57xp32.sys [2006-03-09 152064]
R3 Ca2001v;CA2001 WebCam Driver; C:WINDOWSSystem32DriversCa2001v.sys [2008-02-19 2333568]
R3 HDAudBus;Драйвер шины Microsoft UAA для High Definition Audio; C:WINDOWSsystem32DRIVERSHDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Драйвер класса HID Microsoft; C:WINDOWSsystem32DRIVERShidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:WINDOWSsystem32driversRtkHDAud.sys [2009-02-13 5029376]
R3 irsir;Драйвер для инфракрасного последовательного порта Microsoft; C:WINDOWSsystem32DRIVERSirsir.sys [2001-08-18 18688]
R3 mouhid;Драйвер мыши HID; C:WINDOWSsystem32DRIVERSmouhid.sys [2001-10-19 12160]
R3 NIC1394;Сетевой драйвер 1394; C:WINDOWSsystem32DRIVERSnic1394.sys [2008-04-14 61824]
R3 nv;nv; C:WINDOWSsystem32DRIVERSnv4_mini.sys [2010-04-04 10232128]
R3 Rasirda;Минипорт WAN (IrDA); C:WINDOWSsystem32DRIVERSrasirda.sys [2001-08-18 19584]
R3 usbaudio;Аудио драйвер USB (WDM); C:WINDOWSsystem32driversusbaudio.sys [2008-04-14 60032]
R3 usbccgp;Драйвер универсального родительского устройства USB (Microsoft); C:WINDOWSsystem32DRIVERSusbccgp.sys [2008-04-14 32128]
R3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-04-14 20608]
R3 vaxscsi;vaxscsi; C:WINDOWSSystem32Driversvaxscsi.sys [2010-05-15 223128]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:WINDOWSsystem32driversWmBEnum.sys [2004-04-14 10144]
R3 WmFilter;Logitech WingMan HID Filter Driver; C:WINDOWSsystem32driversWmFilter.sys [2004-04-14 21280]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:WINDOWSsystem32driversWmXlCore.sys [2004-04-14 44064]
S1 kbdhid;Драйвер клавиатуры HID; C:WINDOWSsystem32DRIVERSkbdhid.sys [2008-04-14 14720]
S3 CCDECODE;Closed Caption декодер; C:WINDOWSsystem32DRIVERSCCDECODE.sys [2004-07-09 16384]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:WINDOWSsystem32driversMSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:WINDOWSsystem32DRIVERSNABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:WINDOWSsystem32DRIVERSNdisIP.sys [2004-07-09 10112]
S3 SLIP;BDA Slip De-Framer; C:WINDOWSsystem32DRIVERSSLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; C:WINDOWSsystem32DRIVERSStreamIP.sys [2004-07-09 14976]
S3 usbvideo;USB-видеоустройство (WDM); C:WINDOWSSystem32Driversusbvideo.sys [2008-04-14 121984]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:WINDOWSsystem32driversWmVirHid.sys [2004-04-14 5600]
S3 WSTCODEC;World Standard Teletext Codec; C:WINDOWSsystem32DRIVERSWSTCODEC.SYS [2004-07-09 18688]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe [2010-05-15 85096]
R2 ekrn;ESET Service; C:Program FilesESETESET NOD32 Antivirusekrn.exe [2010-04-07 810120]
R2 GatewayAgentService;O&O Gateway Agent Service; C:Program FilesOO SoftwareSharedGatewayAgentooemcgats.exe [2009-08-28 315392]
R2 Irmon;Монитор инфракрасной связи; C:WINDOWSsystem32svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2010-07-17 153376]
R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit; C:Program FilesAutodesk3ds Max 2009mentalraysatelliteraysat_3dsMax2009_32server.exe [2008-03-10 65536]
R2 nvsvc;NVIDIA Display Driver Service; C:WINDOWSsystem32nvsvc32.exe [2010-04-03 154216]
R2 O&O Defrag;O&O Defrag; C:Program FilesOO SoftwareDefragoodag.exe [2009-09-12 1488128]
R2 StarWindService;StarWind iSCSI Service; C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe [2005-04-01 217600]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:WINDOWSSystem32TUProgSt.exe [2010-05-14 604416]
R2 UxTuneUp;TuneUp Theme Extension; C:WINDOWSSystem32svchost.exe [2008-04-14 14336]
S3 2GISUpdateService;2GIS UpdateService; C:Program Files2gis3.02GISUpdateService.exe [2010-09-29 837464]
S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe [2010-04-07 33560]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe [2010-06-22 1045256]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:WINDOWSMicrosoft.NETFrameworkv3.0WPFPresentationFontCache.exe [2008-07-29 46104]
S3 GoogleDesktopManager-051210-111108;Диспетчер Google Desktop 5.9.1005.12335; C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe [2010-08-01 30192]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication Foundationinfocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 SwitchBoard;SwitchBoard; C:Program FilesCommon FilesAdobeSwitchBoardSwitchBoard.exe [2010-02-19 517096]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:WINDOWSSystem32TuneUpDefragService.exe [2010-05-14 361216]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication FoundationSMSvcHost.exe [2008-07-29 132096]
EOF
info.txt logfile of random’s system information tool 1.08 2010-10-13 18:17:51
======Uninstall list======
«Oblivion ЗОЛОТОЕ ИЗДАНИЕ» версии 1.2.0416—>»D:GAMESOblivionunins000.exe»
—>MsiExec /X{DEA314C4-0929-4250-BC92-98E4C105F28D}
—>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:WINDOWSINFPCHealth.inf
µTorrent—>»C:Program FilesuTorrentuTorrent.exe» /UNINSTALL
ACDSee Photo Manager 2009—>MsiExec.exe /I{300578F9-9EFF-4B93-9AB1-C0E5707EF463}
Adobe Acrobat 9 Pro — English, Russian—>msiexec /I {AC76BA86-1048-8780-7760-000000000004}
Adobe Acrobat 9 Pro — English, Russian—>msiexec /I {AC76BA86-1048-8780-7760-000000000004}
Adobe AIR—>C:Program FilesCommon FilesAdobe AIRVersions1.0ResourcesAdobe AIR Updater.exe -arp:uninstall
Adobe AIR—>MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Community Help—>msiexec /qb /x {0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Community Help—>MsiExec.exe /I{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}
Adobe Flash Player 10 ActiveX—>C:WINDOWSsystem32MacromedFlashFlashUtil10i_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin—>C:WINDOWSsystem32MacromedFlashFlashUtil10i_Plugin.exe -maintain plugin
Adobe Media Player—>msiexec /qb /x {DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Media Player—>MsiExec.exe /I{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}
Adobe Photoshop CS5—>C:Program FilesCommon FilesAdobeOOBEPDAppcorePDApp.exe —appletID=»DWA_UI» —appletVersion=»1.0″ —mode=»Uninstall» —mediaSignature=»{15FEDA5F-141C-4127-8D7E-B962D1742728}»
Adobe Reader 9.3.3—>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A93000000001}
Adobe Setup—>MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
AIMP2: Audio Tools—>C:Program FilesAIMP2 ToolsatUninstall.exe
AIMP2—>C:Program FilesAIMP2Uninstall.exe
ANNO 1404 — Венеция—>»C:Program FilesInstallShield Installation Information{A07B2C21-863B-47AB-AE7E-20BB00BD7D33}Setup.exe» -runfromtemp -l0x0019 -removeonly
ANNO 1404—>»C:Program FilesInstallShield Installation Information{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}setup.exe» -runfromtemp -l0x0019 -removeonly
Antirun 1.0 build 6—>C:Program FilesAntirununinst.exe
Any DVD Converter Professional 4.0.4—>»C:Program FilesAnvSoftAny DVD Converter Professionalunins000.exe»
Any Video Converter Professional 3.0.4—>»C:Program FilesAnvSoftAny Video Converter Professionalunins000.exe»
Apple Application Support—>MsiExec.exe /I{553255F3-78FD-40F1-A6F8-6882140265FE}
Apple Software Update—>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Applian Director—>»C:WINDOWSApplian Directoruninstall.exe» «/U:C:Program FilesApplian DirectorUninstalluninstall_director.xml»
AutoCAD 2009 — Русский—>C:Program FilesAutoCAD 2009SetupSetup.exe /P {5783F2D7-7001-0419-0002-0060B0CE6BBA} /M ACAD
Autodesk 3ds Max 2009 32-bit—>MsiExec.exe /I{FDD8070F-E3B9-0409-822C-CCFE5E82C14D}
Autodesk Backburner 2008.1—>MsiExec.exe /I{3D347E6D-5A03-4342-B5BA-6A771885F379}
BDE Version 5.2.0.2—>»C:Program FilesCommon FilesBorlandBDEunins000.exe»
CorelDRAW Graphics Suite X3—>C:Program FilesCorelCorelDRAW Graphics Suite 13ProgramsMSILauncher {7C5123A9-30A8-4C44-89CA-A8C87A1FCC91} C:DOCUME~1UserLOCALS~1TempCGSX3.log
CorelDRAW Graphics Suite X3—>MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}
dBpoweramp [Calculate Audio CRC] Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp [Calculate Audio CRC] Codec.dat
dBpoweramp Batch Ripper—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Batch Ripper.dat
dBpoweramp CD Writer—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp CD Writer.dat
dBpoweramp Dalet Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Dalet Codec.dat
dBpoweramp DSP Effects—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp DSP Effects.dat
dBpoweramp FLAC Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp FLAC Codec.dat
dBpoweramp Monkeys Audio Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
dBpoweramp Mp2 and BwfMp2 codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Mp2 and BwfMp2 codec.dat
dBpoweramp mp3 (Fraunhofer IIS) Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp mp3 (Fraunhofer IIS) Codec.dat
dBpoweramp Music Converter—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Music Converter.dat
dBpoweramp Ogg Vorbis Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
dBpoweramp Real Audio (Helix) Encoder—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
dBPoweramp tooLame MP2 codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBPoweramp tooLame MP2 codec.dat
dBpoweramp Wave64 Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp Wave64 Codec.dat
dBpoweramp WavPack Codec—>»C:WINDOWSsystem32SpoonUninstall.exe» C:WINDOWSsystem32SpoonUninstall-dBpoweramp WavPack Codec.dat
DjVu Solo 3.1—>C:WINDOWSIsUninst.exe -f»C:Program FilesLizardTechDjVu Solo 3.1Uninst.isu»
Everest Professional ver.2.00.152—>C:Program FilesEverestuninst.exe
FBX Plugin 2009.0 for Max 2009—>C:Program FilesAutodeskFBXFbxPlugins2009.0Max2009Uninstall.exe
FontNav—>MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}
GoldWave v5.55—>»C:Program FilesGoldWaveunstall.exe» «GoldWave v5.55» «C:Program FilesGoldWaveunstall.log»
Google Desktop—>C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopSetup.exe -uninstall
Google SketchUp Pro 7—>MsiExec.exe /I{E1C256F5-58C6-44E9-939A-E1189C8126E2}
Govorilka—>C:Program FilesГоворилкаUninstall.exe
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)—>C:WINDOWSsystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=»»
Hotfix for Microsoft Visual Studio 2007 Tools for Applications — ENU (KB946040)—>C:WINDOWSsystem32msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=»»
Hotfix for Microsoft Visual Studio 2007 Tools for Applications — ENU (KB946308)—>C:WINDOWSsystem32msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=»»
Hotfix for Microsoft Visual Studio 2007 Tools for Applications — ENU (KB946344)—>C:WINDOWSsystem32msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=»»
Hotfix for Microsoft Visual Studio 2007 Tools for Applications — ENU (KB947540)—>C:WINDOWSsystem32msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=»»
Hotfix for Microsoft Visual Studio 2007 Tools for Applications — ENU (KB947789)—>C:WINDOWSsystem32msiexec.exe /package {AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB} /uninstall /qb+ REBOOTPROMPT=»»
ICE Book Reader Professional v9.0.0 Russian—>»C:Program FilesICE Book Reader Professional Russianunins000.exe»
Java(TM) 6 Update 21—>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}
Java(TM) 6 Update 3—>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
K-Lite Mega Codec Pack 5.8.3—>»C:Program FilesK-Lite Codec Packunins000.exe»
L&H TTS3000 Deutsch—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWSINFLHTTSGED.inf, Uninstall
L&H TTS3000 Espaсol—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWSINFLHTTSSPE.inf, Uninstall
L&H TTS3000 Franзais—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWSINFLHTTSFRF.inf, Uninstall
L&H TTS3000 Italiano—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWSINFLHTTSITI.inf, Uninstall
L&H TTS3000 Russian—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWSINFLHTTSRUR.inf, Uninstall
Lernout & Hauspie TruVoice American English TTS Engine—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWSINFtv_enua.inf, Uninstall
Logitech Gaming Software—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime701Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{B9242864-2841-4ADE-86E0-8F90F91B04DD}setup.exe» -l0x9
Mail.Ru Агент 5.3 (сборка 2552, для всех пользователей)—>C:Program FilesMail.RuAgentmagentsetup.exe -uninstalllm
Mail.Ru Спутник 2.0.1.54—>C:Program FilesMail.RuSputnikSputnikInstaller.exe -uninstall
MapInfo Professional 10.0—>MsiExec.exe /I{2ACF3993-A0E7-4374-B926-68EA1FAE8A88}
MAXON CINEMA 4D Studio Bundle v11.008—>»C:Program FilesMAXONunins000.exe»
Microsoft .NET Framework 2.0 Service Pack 2—>MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2—>MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1—>C:WINDOWSMicrosoft.NETFrameworkv3.5Microsoft .NET Framework 3.5 SP1setup.exe
Microsoft .NET Framework 3.5 SP1—>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft National Language Support Downlevel APIs—>»C:WINDOWS$NtServicePackUninstallNLSDownlevelMapping$spuninstspuninst.exe»
Microsoft Office Access MUI (Russian) 2007—>MsiExec.exe /X{90120000-0015-0419-0000-0000000FF1CE}
Microsoft Office Enterprise 2007—>»C:Program FilesCommon FilesMicrosoft SharedOFFICE12Office Setup Controllersetup.exe» /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007—>MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Russian) 2007—>MsiExec.exe /X{90120000-0016-0419-0000-0000000FF1CE}
Microsoft Office Groove MUI (Russian) 2007—>MsiExec.exe /X{90120000-00BA-0419-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Russian) 2007—>MsiExec.exe /X{90120000-0044-0419-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Russian) 2007—>MsiExec.exe /X{90120000-00A1-0419-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Russian) 2007—>MsiExec.exe /X{90120000-001A-0419-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Russian) 2007—>MsiExec.exe /X{90120000-0018-0419-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007—>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007—>MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Russian) 2007—>MsiExec.exe /X{90120000-001F-0419-0000-0000000FF1CE}
Microsoft Office Proof (Ukrainian) 2007—>MsiExec.exe /X{90120000-001F-0422-0000-0000000FF1CE}
Microsoft Office Proofing (Russian) 2007—>MsiExec.exe /X{90120000-002C-0419-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Russian) 2007—>MsiExec.exe /X{90120000-0019-0419-0000-0000000FF1CE}
Microsoft Office Shared MUI (Russian) 2007—>MsiExec.exe /X{90120000-006E-0419-0000-0000000FF1CE}
Microsoft Office Word MUI (Russian) 2007—>MsiExec.exe /X{90120000-001B-0419-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable — x86 9.0.30729.17—>MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual Studio 2005 Tools for Office Runtime—>MsiExec.exe /X{388E4B09-3E71-4649-8921-F44A3A2954A7}
Microsoft Visual Studio Tools for Applications 2.0 — ENU—>MsiExec.exe /X{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}
Microsoft Visual Studio Tools for Applications 2.0 Runtime—>MsiExec.exe /X{299C0434-4F4E-341F-A916-4E07AEB35E79}
Microsoft_VC80_ATL_x86—>MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86—>MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86—>MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86—>MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86—>MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86—>MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86—>MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Mozilla Firefox (3.6.10)—>C:Program FilesMozilla Firefoxuninstallhelper.exe
MSXML 6.0 Parser—>MsiExec.exe /I{AEB9948B-4FF2-47C9-990E-47014492A0FE}
MyLib 0.93—>C:Program FilesMyLibuninst.exe
Nero Lite 9.4.26.2 XCV Edition—>C:Program FilesNeroNero9uninst.exe
NVIDIA Display Control Panel—>C:Program FilesNVIDIA CorporationUninstallnvuninst.exe DisplayControlPanel
NVIDIA Drivers—>C:Program FilesNVIDIA CorporationUninstallnvuninst.exe UninstallGUI
NVIDIA nView Desktop Manager—>C:Program FilesNVIDIA CorporationnViewnViewSetup.exe -uninstall
NVIDIA PhysX—>MsiExec.exe /X{DEA314C4-0929-4250-BC92-98E4C105F28D}
O&O Defrag Workstation—>MsiExec.exe /I{2630D275-B4E1-4200-8497-2D4CDC61AD6E}
OpenAL—>»C:Program FilesOpenALoalinst.exe» /U
PDF Settings CS5—>MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
PDFCreator—>C:Program FilesPDFCreatorunins000.exe
PROMT 4U Giant Try-Buy—>MsiExec.exe /I{5AFD8203-C0A3-4006-AAAF-462996E428C1}
PROMT Expert 8 Giant Try-Buy—>MsiExec.exe /I{A4F761F7-FBC8-49BF-BC37-15550C3EAA85}
Psychonauts—>»D:GAMESPsychonautsPsychonautsunins000.exe»
QuickTime—>MsiExec.exe /I{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}
REALTEK GbE & FE Ethernet PCI-E NIC Driver—>C:Program FilesInstallShield Installation Information{C9BED750-1211-4480-B1A5-718A3BE15525}setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1150Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}Setup.exe» -l0x19 -removeonly
Replay Video Capture—>»C:WINDOWSReplay Video Captureuninstall.exe» «/U:C:Program FilesReplay Video CaptureUninstalluninstall.xml»
RU—>MsiExec.exe /I{01AE68B4-C785-4865-BC7E-78456372BB75}
Skype Toolbars—>MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2—>MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
SWAT 4: Синдикат Стечкина—>C:PROGRA~1COMMON~1INSTAL~1Driver1150INTEL3~1IDriver.exe /M{97E12F84-C033-4DA2-97D2-F540C3E292EA} uninstall
SWAT 4—>C:PROGRA~1COMMON~1INSTAL~1Driver10INTEL3~1IDriver.exe /M{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8} uninstall
System Requirements Lab for Intel—>MsiExec.exe /I{ADD72094-D289-4714-A62E-70574478A2BC}
TuneUp Utilities 2009—>MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
UltraISO Premium V9.35—>»C:Program FilesUltraISOunins000.exe»
Update Manager—>MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}
URLToolBHO—>»C:Program FilesURLToolBHOunins000.exe»
USB Video Camera—>»C:Program FilesInstallShield Installation Information{F11D6791-FBE8-4817-B5D4-D3191DDDCDC8}setup.exe» -runfromtemp -l0x0409 -removeonly
USB Video Camera—>MsiExec.exe /X{F11D6791-FBE8-4817-B5D4-D3191DDDCDC8}
VBA—>MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}
V-Ray for SketchUp 7—>»C:Program FilesInstallShield Installation Information{E31ABA95-B5A8-4373-AABF-BAC8CD34E217}setup.exe» -runfromtemp -l0x0009 -removeonly
Windows Media Format 11 runtime—>»C:Program FilesWindows Media Playerwmsetsdk.exe» /UninstallAll
Windows Media Format 11 runtime—>»C:WINDOWS$NtUninstallWMFDist11$spuninstspuninst.exe»
ZBrush3—>MsiExec.exe /I{6084D038-3401-4C9D-A216-86E6EEA25AFB}
Архиватор WinRAR—>C:Program FilesWinRARuninstall.exe
Данные ДубльГИС г.Краснодар 01.10.2010—>MsiExec.exe /X{DBAFC69A-5447-4031-8CAB-CD4F242DE238}
Данные ДубльГИС г.Самара 01.10.2010—>MsiExec.exe /X{01001477-A2A5-474F-B4A5-29FD52EF4FCC}
Данные ДубльГИС г.Сочи 01.10.2010—>MsiExec.exe /X{F7812E95-E958-4748-A732-4BD574C100A2}
ДубльГИС 3.0.8.2—>MsiExec.exe /X{6778170B-1E50-42E5-9810-25F33C7C2E42}
еда выполнения Visual Studio 2005 Tools for Office, второй выпуск—>C:Program FilesCommon FilesMicrosoft SharedVSTO8.0Microsoft Visual Studio 2005 Tools for Office Runtimeinstall.exe======Hosts File======
127.0.0.1 serial.alcohol-soft.com
======Security center information======
AV: ESET NOD32 Antivirus 4.2
======System event log======
Computer Name: 2-80C435F26AB94
Event Code: 6006
Message: Служба журнала событий остановлена.Record Number: 16469
Source Name: EventLog
Time Written: 20100925172237.000000+240
Event Type: информация
User:Computer Name: 2-80C435F26AB94
Event Code: 20159
Message: Подключение пользователя «v41030272» к «dom.ru», выполненное с помощью устройства «PPPoE6-0», было прервано.Record Number: 16468
Source Name: RemoteAccess
Time Written: 20100925172219.000000+240
Event Type: информация
User:Computer Name: 2-80C435F26AB94
Event Code: 4226
Message: Достигнут предел безопасности для TCP/IP, налагаемый на количество попыток одновременных TCP-подключений.Record Number: 16467
Source Name: Tcpip
Time Written: 20100925133358.000000+240
Event Type: предупреждение
User:Computer Name: 2-80C435F26AB94
Event Code: 4226
Message: Достигнут предел безопасности для TCP/IP, налагаемый на количество попыток одновременных TCP-подключений.Record Number: 16466
Source Name: Tcpip
Time Written: 20100925130716.000000+240
Event Type: предупреждение
User:Computer Name: 2-80C435F26AB94
Event Code: 20158
Message: Успешно выполнено подключение пользователя «v41030272″к «dom.ru», с помощью устройства «PPPoE6-0».Record Number: 16465
Source Name: RemoteAccess
Time Written: 20100925124425.000000+240
Event Type: информация
User:=====Application event log=====
Computer Name: 2-80C435F26AB94
Event Code: 3
Message:
Record Number: 2607
Source Name: RaySat_3dsmax2010_32 Server
Time Written: 20100806225203.000000+240
Event Type: информация
User:Computer Name: 2-80C435F26AB94
Event Code: 3
Message:
Record Number: 2606
Source Name: RaySat_3dsmax2010_32 Server
Time Written: 20100806225203.000000+240
Event Type: информация
User:Computer Name: 2-80C435F26AB94
Event Code: 3
Message:
Record Number: 2605
Source Name: RaySat_3dsmax2009_32 Server
Time Written: 20100806225200.000000+240
Event Type: информация
User:Computer Name: 2-80C435F26AB94
Event Code: 3
Message:
Record Number: 2604
Source Name: RaySat_3dsmax2009_32 Server
Time Written: 20100806225200.000000+240
Event Type: информация
User:Computer Name: 2-80C435F26AB94
Event Code: 0
Message: Service started successfully.Record Number: 2603
Source Name: O&O GatewayAgentService
Time Written: 20100806225159.000000+240
Event Type: информация
User:======Environment variables======
«ComSpec»=%SystemRoot%system32cmd.exe
«Path»=c:Program FilesNVIDIA CorporationPhysXCommon;%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem;C:Program FilesCommon FilesAutodesk Shared;C:Program FilesQuickTimeQTSystem;C:Program FilesAutodeskBackburner
«windir»=%SystemRoot%
«FP_NO_HOST_CHECK»=NO
«OS»=Windows_NT
«PROCESSOR_ARCHITECTURE»=x86
«PROCESSOR_LEVEL»=15
«PROCESSOR_IDENTIFIER»=x86 Family 15 Model 3 Stepping 4, GenuineIntel
«PROCESSOR_REVISION»=0304
«NUMBER_OF_PROCESSORS»=2
«PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
«TEMP»=%SystemRoot%TEMP
«TMP»=%SystemRoot%TEMP
«CLASSPATH»=.;C:Program FilesJavajre6libextQTJava.zip
«QTJAVA»=C:Program FilesJavajre6libextQTJava.zip
«PROG8D757106053″=1
EOF
-
АвторСообщения