OTListIt 2\2
Код:
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = res://shdoclc.dll/hardAdmin.htm
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htm
HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = res://shdoclc.dll/hardAdmin.htm
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htm
HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\S-1-5-21-2339980570-2700689384-1226640419-1349\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\S-1-5-21-2339980570-2700689384-1226640419-1349\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
O1 HOSTS File: (769 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O3 - HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O3 - HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O4 - HKLM..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe" (Kaspersky Lab)
O4 - HKLM..\Run: [CPQTEAM] cpqteam.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [Punto Switcher] C:\Program Files\Punto Switcher\ps.exe (Punto.Ru)
O4 - HKU\S-1-5-21-2339980570-2700689384-1226640419-1349..\Run: [Punto Switcher] C:\Program Files\Punto Switcher\ps.exe (Punto.Ru)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ShowSuperHidden = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKU\S-1-5-21-2339980570-2700689384-1226640419-1349\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1231915325148 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149659546578 (MUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 172.16.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 127.0.0.1
O18 - Protocol\Handler: - hpapp - C:\Program Files\Compaq\Cpqacuxe\Bin\hpapp.dll (Hewlett-Packard Company)
O18 - Protocol\Handler: - hpapp\Apps - Reg Error: Key does not exist or could not be opened. File not found
O18 - Protocol\Handler: - ms-help - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O22 - SharedTaskScheduler: (Предзагрузчик Browseui) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
O22 - SharedTaskScheduler: (Демон кэша категорий компонентов) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Корпорация Майкрософт)
========== AppInit_DLLs ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls" = ice_time.dll
>[2009.01.15 17:04:43 | 00,069,632 | ---- | M] () -- C:\WINDOWS\system32\ice_time.dll
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
klogon: "DllName" = C:\WINDOWS\system32\klogon.dll -- C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
========== HKLM *SecurityProviders* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, pwdssp.dll
>[2003.05.12 14:00:00 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\pwdssp.dll
========== Safeboot Options ==========
"AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 0
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2006.06.05 16:51:52 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bb3ca006-cffe-11dd-83f6-0015605625df}\Shell\AutoRun\command]
"" = RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\dark.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bb3ca006-cffe-11dd-83f6-0015605625df}\Shell\open\command]
"" = RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\dark.exe
========== Files/Folders - Created Within 60 Days ==========
[4 C:\WINDOWS\*.tmp files]
[2009.01.16 08:31:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\sysadmin\Рабочий стол\SCAN
[2009.01.15 17:04:43 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\ice_time.dll
[2009.01.15 16:56:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2009.01.15 16:56:24 | 24,593,440 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009.01.15 16:56:24 | 02,529,568 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2009.01.15 16:56:24 | 00,006,320 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009.01.15 16:56:24 | 00,001,364 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2009.01.15 08:20:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\sysadmin\Application Data\Malwarebytes
[2009.01.15 08:20:39 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009.01.15 08:20:39 | 00,000,703 | ---- | C] () -- C:\Documents and Settings\All Users\Рабочий стол\Malwarebytes' Anti-Malware.lnk
[2009.01.15 08:20:37 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009.01.15 08:20:36 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009.01.15 08:20:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009.01.14 10:12:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009.01.14 08:53:39 | 03,593,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009.01.14 08:53:22 | 00,477,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtmled.dll
[2009.01.14 08:53:22 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2009.01.14 08:53:21 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2009.01.14 08:53:20 | 00,383,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieapfltr.dll
[2009.01.14 08:53:20 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtmsft.dll
[2009.01.14 08:53:20 | 00,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iertutil.dll
[2009.01.14 08:53:20 | 00,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\webcheck.dll
[2009.01.14 08:53:19 | 00,826,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet.dll
[2009.01.14 08:53:19 | 00,459,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2009.01.14 08:53:19 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\advpack.dll
[2009.01.14 08:53:18 | 01,160,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\urlmon.dll
[2009.01.14 08:53:18 | 00,214,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtrans.dll
[2009.01.14 08:53:18 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icardie.dll
[2009.01.14 08:53:17 | 06,066,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieframe.dll
[2009.01.14 08:52:14 | 00,438,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2009.01.14 08:48:55 | 00,384,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip.sys
[2009.01.14 08:48:55 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dnsperf.dll
[2009.01.14 08:48:54 | 00,450,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dns.exe
[2009.01.14 08:48:54 | 00,450,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dns.exe
[2009.01.14 08:48:54 | 00,234,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcpip6.sys
[2009.01.14 08:48:54 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\afd.sys
[2009.01.14 08:48:41 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rmcast.sys
[2009.01.14 08:48:14 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asp.dll
[2009.01.14 08:47:59 | 00,228,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmasf.dll
[2009.01.14 08:46:45 | 01,121,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml3.dll
[2009.01.14 08:46:41 | 00,247,326 | ---- | C] (Корпорация Майкрософт (Microsoft Corp.)) -- C:\WINDOWS\System32\dllcache\strmdll.dll
[2009.01.14 08:44:28 | 00,357,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2009.01.14 08:42:44 | 00,027,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2009.01.14 08:11:49 | 00,396,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.execf
[2009.01.14 08:10:49 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2009.01.13 10:15:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\sysadmin\Application Data\Lavasoft
[2009.01.13 09:43:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\sysadmin\Application Data\NAU
[2009.01.06 10:49:04 | 00,001,582 | ---- | C] () -- C:\Documents and Settings\sysadmin\Рабочий стол\Службы компонентов.lnk
[2009.01.06 10:48:03 | 00,001,652 | ---- | C] () -- C:\Documents and Settings\sysadmin\Рабочий стол\Управление данным сервером.lnk
[2009.01.06 10:47:06 | 00,000,727 | ---- | C] () -- C:\Documents and Settings\sysadmin\Рабочий стол\Active Directory - сайты и службы.lnk
[2009.01.06 10:47:06 | 00,000,727 | ---- | C] () -- C:\Documents and Settings\sysadmin\Рабочий стол\Active Directory - домены и доверие.lnk
[2008.12.23 16:18:22 | 00,000,211 | RH-- | C] () -- C:\BOOT.PCR
[2008.12.22 15:18:24 | 00,000,823 | ---- | C] () -- C:\Documents and Settings\All Users\Рабочий стол\Golden Gate 2002.lnk
[2008.12.22 15:16:33 | 00,000,012 | ---- | C] () -- C:\WINDOWS\System32\haspaddr.dat
[2008.12.22 15:16:23 | 03,149,312 | ---- | C] (Aladdin Knowledge Systems.) -- C:\WINDOWS\System32\hinstd.dll
[2008.12.22 15:16:20 | 00,225,280 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\nhsrvice.exe
[2008.12.22 15:16:20 | 00,164,864 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
[2008.12.22 15:16:20 | 00,051,111 | ---- | C] () -- C:\WINDOWS\System32\nhsrvw32.hlp
[2008.12.22 15:16:20 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\hsduinst.exe
[2008.12.22 15:16:20 | 00,000,000 | ---D | C] -- C:\Program Files\Aladdin
[2008.12.22 15:15:11 | 00,033,340 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbmsqlgc.dll
[2008.12.22 15:15:11 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbmsgnet.dll
[2008.12.22 15:15:11 | 00,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\Service Manager.lnk
[2008.12.22 15:15:10 | 00,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2008.12.22 15:14:17 | 00,676,864 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\hardlock.sys
[2008.12.22 15:14:17 | 00,328,448 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\akshasp.sys
[2008.12.22 15:14:17 | 00,099,968 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\aksusb.sys
[2008.12.22 15:14:17 | 00,007,168 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\akscoinst.dll
[2008.12.22 15:14:16 | 00,104,448 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\aksclass.sys
[2008.12.22 15:14:12 | 00,047,616 | ---- | C] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\Haspnt.sys
[2008.12.22 15:14:12 | 00,006,656 | ---- | C] (Aladdin Knowledge Systems.) -- C:\WINDOWS\System32\haspvdd.dll
[2008.12.22 15:14:12 | 00,005,752 | ---- | C] () -- C:\WINDOWS\System32\config.hsp
[2008.12.22 15:14:12 | 00,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2008.12.22 15:14:07 | 00,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc70.dll
[2008.12.22 15:14:07 | 00,853,504 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\xmlrtl70.bpl
[2008.12.22 15:14:07 | 00,257,024 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\dbrtl70.bpl
[2008.12.22 15:14:07 | 00,148,992 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\adortl70.bpl
[2008.12.22 15:14:07 | 00,143,360 | ---- | C] (ITV) -- C:\WINDOWS\System32\LCTW32.dll
[2008.12.22 15:14:07 | 00,097,792 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\vcljpg70.bpl
[2008.12.22 15:14:06 | 01,381,376 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\vcl70.bpl
[2008.12.22 15:14:06 | 00,778,240 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\rtl70.bpl
[2008.12.22 15:14:06 | 00,487,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp70.dll
[2008.12.22 15:14:06 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr70.dll
[2008.12.22 15:14:06 | 00,276,480 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\vclactnband70.bpl
[2008.12.22 15:14:06 | 00,215,040 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\vclx70.bpl
[2008.12.22 15:14:06 | 00,064,512 | ---- | C] (Borland Software Corporation) -- C:\WINDOWS\System32\vclsmp70.bpl
[2008.12.22 15:14:01 | 00,000,000 | ---D | C] -- C:\Program Files\ITV
[2008.12.22 15:14:01 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ITV Shared
[2008.12.22 10:58:05 | 00,000,210 | ---- | C] () -- C:\WINDOWS\tasks\НАУ Обновление.job
[2008.12.22 10:34:46 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBSTOR.SYS
[2008.12.22 10:34:46 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbstor.sys
[2008.12.22 08:07:40 | 01,716,580 | -H-- | C] () -- C:\Documents and Settings\sysadmin\Local Settings\Application Data\IconCache.db
[2008.11.21 15:49:55 | 00,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2008.11.21 15:49:16 | 00,000,000 | ---D | C] -- C:\kav
========== Files - Modified Within 60 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009.01.16 08:32:57 | 24,595,232 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009.01.16 08:31:31 | 02,529,568 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2009.01.16 08:25:44 | 01,716,580 | -H-- | M] () -- C:\Documents and Settings\sysadmin\Local Settings\Application Data\IconCache.db
[2009.01.16 08:01:30 | 00,001,196 | -H-- | M] () -- C:\Documents and Settings\sysadmin\Мои документы\Default.rdp
[2009.01.16 07:00:04 | 00,000,482 | ---- | M] () -- C:\WINDOWS\tasks\ShadowCopyVolume{e5234c5c-6976-4728-811c-4d0fedbd1850}.job
[2009.01.16 07:00:02 | 00,000,476 | ---- | M] () -- C:\WINDOWS\tasks\ShadowCopyVolume{c6350dca-f4b9-11da-a0a6-806e6f6e6963}.job
[2009.01.16 06:00:20 | 00,000,210 | ---- | M] () -- C:\WINDOWS\tasks\НАУ Обновление.job
[2009.01.16 04:11:54 | 00,000,828 | ---- | M] () -- C:\WINDOWS\tasks\Ultriumus.job
[2009.01.16 00:44:09 | 00,000,266 | ---- | M] () -- C:\WINDOWS\tasks\Copy To BackUpSrv.job
[2009.01.16 00:43:24 | 00,000,254 | ---- | M] () -- C:\WINDOWS\tasks\Backup Day.job
[2009.01.16 00:22:31 | 00,000,274 | ---- | M] () -- C:\WINDOWS\tasks\MySql Flush Logs.job
[2009.01.15 21:04:16 | 00,000,256 | ---- | M] () -- C:\WINDOWS\tasks\MySql Dump Day.job
[2009.01.15 20:44:01 | 00,065,536 | ---- | M] () -- C:\WINDOWS\NETLOGON.CHG
[2009.01.15 17:19:37 | 01,582,312 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009.01.15 17:19:37 | 00,661,400 | ---- | M] () -- C:\WINDOWS\System32\perfh019.dat
[2009.01.15 17:19:37 | 00,610,244 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009.01.15 17:19:37 | 00,158,324 | ---- | M] () -- C:\WINDOWS\System32\perfc019.dat
[2009.01.15 17:19:37 | 00,129,046 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009.01.15 17:15:27 | 00,000,012 | ---- | M] () -- C:\WINDOWS\System32\haspaddr.dat
[2009.01.15 17:15:00 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009.01.15 17:14:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009.01.15 17:13:19 | 00,006,320 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009.01.15 17:13:19 | 00,001,364 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2009.01.15 17:07:15 | 00,194,320 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2009.01.15 17:04:43 | 00,069,632 | ---- | M] () -- C:\WINDOWS\System32\ice_time.dll
[2009.01.15 08:20:39 | 00,000,703 | ---- | M] () -- C:\Documents and Settings\All Users\Рабочий стол\Malwarebytes' Anti-Malware.lnk
[2009.01.14 16:11:32 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009.01.14 16:11:28 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009.01.14 10:50:12 | 00,003,423 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009.01.14 10:48:55 | 00,396,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.execf
[2009.01.14 10:18:10 | 00,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009.01.14 10:12:12 | 00,096,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009.01.14 10:12:11 | 16,106,12736 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009.01.12 07:59:28 | 00,000,272 | ---- | M] () -- C:\WINDOWS\tasks\MySql DataBase Optimize.job
[2009.01.12 07:34:39 | 00,000,266 | ---- | M] () -- C:\WINDOWS\tasks\Backup & Clear Multimedia.job
[2009.01.09 17:35:30 | 20,853,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009.01.09 17:04:09 | 00,000,264 | ---- | M] () -- C:\WINDOWS\tasks\MySql Dump Week.job
[2009.01.09 09:51:53 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\Backup & Clear Tranzit.job
[2009.01.01 00:22:37 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\Backup Month.job
[2008.12.22 15:18:24 | 00,000,823 | ---- | M] () -- C:\Documents and Settings\All Users\Рабочий стол\Golden Gate 2002.lnk
[2008.12.22 15:15:11 | 00,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка\Service Manager.lnk
[2008.12.22 15:14:12 | 00,047,616 | ---- | M] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\Haspnt.sys
[2008.12.22 15:14:12 | 00,006,656 | ---- | M] (Aladdin Knowledge Systems.) -- C:\WINDOWS\System32\haspvdd.dll
[2008.12.22 15:14:12 | 00,005,795 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2008.12.22 15:14:12 | 00,000,383 | ---- | M] () -- C:\WINDOWS\System32\haspdos.sys
[2008.12.13 09:27:24 | 03,593,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2008.12.13 09:27:24 | 03,593,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2008.12.11 13:39:10 | 00,357,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\srv.sys
[2008.12.11 13:39:10 | 00,357,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srv.sys
[2008.12.11 10:31:39 | 00,000,449 | ---- | M] () -- C:\Documents and Settings\sysadmin\Рабочий стол\LIGA Server.lnk
[2008.11.24 09:40:58 | 00,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
< End of report >
Код:
Malwarebytes' Anti-Malware 1.33
Версия базы данных: 1656
Windows 5.2.3790 Service Pack 2
16.01.2009 8:39:07
mbam-log-2009-01-16 (08-39-07).txt
Тип проверки: Быстрая
Проверено объектов: 57012
Прошло времени: 2 minute(s), 8 second(s)
Заражено процессов в памяти: 0
Заражено модулей в памяти: 0
Заражено ключей реестра: 0
Заражено значений реестра: 0
Заражено параметров реестра: 0
Заражено папок: 0
Заражено файлов: 0
Заражено процессов в памяти:
(Вредоносные программы не обнаружены)
Заражено модулей в памяти:
(Вредоносные программы не обнаружены)
Заражено ключей реестра:
(Вредоносные программы не обнаружены)
Заражено значений реестра:
(Вредоносные программы не обнаружены)
Заражено параметров реестра:
(Вредоносные программы не обнаружены)
Заражено папок:
(Вредоносные программы не обнаружены)
Заражено файлов:
(Вредоносные программы не обнаружены)
|