Hi! In past couple of weeks a huge amount of flash games were installed to my PC, and the problem I'm having now is every time I swich on/reboot the computer Internet explorer automatically opens on pages madLen.uCoz.coM and gamezona.org. Could you help to get rid of this? I'm also getting a bit paranoid about catching some other malware that I'm not able to see - could you please check if there is anything else that needs fixing? thanks a lot!
DDS logs:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 13:43:28 on 2012-06-11
Microsoft Windows 7 Домашняя базовая 6.1.7601.1.1251.7.1049.18.4007.2132 [GMT 4:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Персональный файервол ESET *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
C:\Windows\system32\CxAudMsg64.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\SysWOW64\SAsrv.exe
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Windows\Explorer.EXE
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\System Update\SUService.exe
C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Александра\Downloads\dds.scr
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain ... &bmod=LENP
uStart Page = gamezona.org
mDefault_Page_URL = hxxp://xn--80afat5b.xn--p1ai
uURLSearchHooks: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
mURLSearchHooks: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - C:\ProgramData\Partner\Partner.dll
BHO: {8984B388-A5BB-4DF7-B274-77B879E179DB} - No File
BHO: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
BHO: Помощник по входу с помощью идентификатора Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Symantec VIP Access Add-On: {c63cd127-a1cb-4d49-a4f7-d6f88a917be6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [b762d2b7609ec7ffb7cb9ad15a8a15dd] iexplore.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
mRun: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
mRun: [start] C:\WINDOWS\TASKMAN.bat
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\ThinkPad\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Отправить изображение на &устройство Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Отправить страницу на &устройство Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: Interfaces\{F32F2F52-F05E-4E51-9FB1-4C45EBC4F1AF} : NameServer = 83.243.64.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
BHO-X64: {8984B388-A5BB-4DF7-B274-77B879E179DB} - No File
{8dec4b69-27c4-405d-a37d-8d45c83f66ab}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{8dec4b69-27c4-405d-a37d-8d45c83f66ab}
mRun-x64: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
mRun-x64: [start] C:\WINDOWS\TASKMAN.bat
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
.
============= SERVICES / DRIVERS ===============
.
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM64.sys --> C:\Windows\system32\DRIVERS\ApsHM64.sys [?]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys --> C:\Windows\system32\DRIVERS\smiifx64.sys [?]
R1 PHCORE;PHCORE;C:\Program Files\Lenovo\RapidBoot\PHCORE64.sys [2011-7-8 32104]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 CxAudMsg;Conexant Audio Message Service;C:\Windows\system32\CxAudMsg64.exe --> C:\Windows\system32\CxAudMsg64.exe [?]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-1-14 810144]
R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute;C:\Program Files\Lenovo\Communications Utility\CamMute.exe [2011-9-28 40808]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2011-5-26 45496]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-9-28 59240]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2011-5-26 93032]
R2 PwmEWSvc;Cisco EnergyWise Enabler;C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe [2011-9-28 148840]
R2 risdxc;risdxc;C:\Windows\system32\DRIVERS\risdxc64.sys --> C:\Windows\system32\DRIVERS\risdxc64.sys [?]
R2 SAService;Conexant SmartAudio service;C:\Windows\System32\SASrv.exe [2011-9-28 446592]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-3-13 13840]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2011-5-26 144232]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2011-5-26 64952]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-9-28 2656280]
R2 VIPAppService;VIPAppService;C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [2011-4-13 84088]
R3 5U877;USB Video Device;C:\Windows\system32\DRIVERS\5U877.sys --> C:\Windows\system32\DRIVERS\5U877.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 IntcDAud;Аудио Intel(R) для дисплеев;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 intelkmd;intelkmd;C:\Windows\system32\DRIVERS\igdpmd64.sys --> C:\Windows\system32\DRIVERS\igdpmd64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Драйвер адаптера Intel(R) Wireless WiFi Link серии 5000 для Windows 7 64 Bit ;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 PCDSRVC{127174DC-C366ED8B-06020200}_0;PCDSRVC{127174DC-C366ED8B-06020200}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\PC-Doctor\pcdsrvc_x64.pkms [2011-4-1 25584]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 gupdate;Служба Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-28 136176]
S2 HyperW7Svc;HyperW7 Service;C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2011-7-8 144232]
S3 BTWAMPFL;BTWAMPFL;C:\Windows\system32\DRIVERS\btwampfl.sys --> C:\Windows\system32\DRIVERS\btwampfl.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 gupdatem;Служба Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-28 136176]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2011-9-28 332272]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2011-9-28 83304]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-06-11 09:41:09 -------- d-----w- C:\Users\?ыхъёрэфЁр\AppData\Local\Microsoft
2012-06-10 17:53:33 -------- d-----w- C:\Users\Александра\AppData\Roaming\dvdcss
2012-06-09 17:38:45 -------- d-----w- C:\Users\Александра\AppData\Roaming\Funlinker
2012-06-08 09:46:19 8955792 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BF26C08B-DA6A-4F42-B4E0-FF5556F01FB2}\mpengine.dll
2012-06-08 06:45:06 -------- d-----w- C:\Users\Александра\AppData\Roaming\Stand O'Food 3
2012-06-07 11:11:56 -------- d-----w- C:\ProgramData\Farm Fishes
2012-06-07 11:07:31 -------- d-----w- C:\Program Files (x86)\madLen.uCoz.coM
2012-06-07 11:07:31 -------- d-----w- C:\Program Files (x86)\Conduit
2012-06-07 11:06:50 -------- d-----w- C:\Users\Александра\AppData\Roaming\Mozilla
2012-06-06 16:30:27 -------- d-----w- C:\Users\Александра\AppData\Roaming\WeatherLord
2012-06-06 16:30:27 -------- d-----w- C:\ProgramData\WeatherLord
2012-06-06 11:21:23 -------- d-----w- C:\Users\Александра\AppData\Roaming\FamilyVacationCalifornia
2012-06-06 10:46:15 -------- d-----w- C:\Users\Александра\AppData\Roaming\Elephant Games
2012-06-06 10:46:15 -------- d-----w- C:\ProgramData\Elephant Games
2012-06-05 16:11:16 -------- d-----w- C:\Users\Александра\AppData\Roaming\Blue Tea Games
2012-06-05 14:23:38 -------- d-----w- C:\Users\Александра\AppData\Roaming\Aidem Media
2012-06-05 13:40:16 -------- d-----w- C:\Users\Александра\AppData\Roaming\V5 Play
2012-06-04 18:31:18 -------- d-----w- C:\Users\Александра\AppData\Roaming\JoyBits
2012-06-03 19:36:39 -------- d-----w- C:\ProgramData\Intenium
2012-06-03 18:46:55 -------- d-----w- C:\Users\Александра\AppData\Roaming\CoronationStreetPC
2012-06-03 15:35:05 -------- d-----w- C:\Users\Александра\AppData\Roaming\Artifex Mundi
2012-06-03 15:10:40 -------- d-----w- C:\Users\Александра\AppData\Roaming\SulusGames
2012-06-02 16:06:09 -------- d-----w- C:\ProgramData\Venus DS
2012-06-02 12:06:30 -------- d-----w- C:\Users\Александра\AppData\Roaming\Skunk Studios
2012-06-02 10:33:23 -------- d-----w- C:\Users\Александра\AppData\Roaming\Alawar
2012-06-02 10:33:23 -------- d-----w- C:\ProgramData\Alawar
2012-06-02 10:28:27 -------- d-----w- C:\ProgramData\PopCap Games
2012-06-01 19:23:49 -------- d-----w- C:\ProgramData\VirtualizedApplications
2012-06-01 19:23:01 -------- d-----w- C:\Users\Александра\AppData\Roaming\SpinTop Games
2012-06-01 17:58:56 -------- d-----w- C:\Users\Александра\AppData\Roaming\PoBros
2012-06-01 17:58:56 -------- d-----w- C:\ProgramData\PoBros
2012-06-01 17:13:35 -------- d-----w- C:\Users\Александра\AppData\Roaming\SoftGrid Client
2012-06-01 17:12:54 -------- d-----w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-06-01 17:12:34 -------- d-----w- C:\Users\Александра\AppData\Roaming\TP
2012-06-01 10:37:37 -------- d-----w- C:\ProgramData\Alawar Stargaze
2012-06-01 10:37:36 -------- d-----w- C:\ProgramData\AlawarWrapper
2012-06-01 10:10:42 -------- d-----w- C:\Users\Александра\AppData\Roaming\Alawar Stargaze
2012-05-31 17:23:52 -------- d-----w- C:\Users\Александра\AppData\Roaming\Brabl
2012-05-31 17:23:52 -------- d-----w- C:\Users\Александра\.gstreamer-0.10
2012-05-31 17:23:52 -------- d-----w- C:\Users\Александра\.gnome2
2012-05-30 18:23:15 -------- d-----w- C:\ProgramData\GameHouse
2012-05-30 18:20:32 -------- d-----w- C:\Users\Александра\AppData\Roaming\Zylom
2012-05-30 18:15:04 -------- d-----w- C:\ProgramData\Slapdash Games
2012-05-30 17:45:46 -------- d-----w- C:\Users\Александра\AppData\Roaming\My Games
2012-05-30 10:46:57 -------- d-----w- C:\Users\Александра\AppData\Roaming\PassionFruit Games
2012-05-29 14:26:07 -------- d-----w- C:\Users\Александра\AppData\Roaming\PathToSuccess_RU
2012-05-29 08:56:34 -------- d-----w- C:\Users\Александра\AppData\Roaming\Freeze Tag
2012-05-28 17:04:35 -------- d-----r- C:\Program Files (x86)\Skype
2012-05-28 17:04:34 -------- d-----w- C:\Users\Александра\AppData\Roaming\Skype
2012-05-28 15:03:52 -------- d-----w- C:\Users\Александра\AppData\Roaming\8floor
2012-05-28 15:03:52 -------- d-----w- C:\ProgramData\8floor
2012-05-27 15:33:20 -------- d-----w- C:\ProgramData\SpookyMall
2012-05-27 09:33:37 -------- d-----w- C:\Users\Александра\AppData\Roaming\vlc
2012-05-27 09:32:45 -------- d-----w- C:\Program Files (x86)\VideoLAN
2012-05-27 09:26:49 -------- d-----w- C:\Users\Александра\AppData\Roaming\Google
2012-05-27 09:10:24 -------- d-----w- C:\Program Files (x86)\Mail.Ru
2012-05-27 09:09:34 -------- d-----w- C:\Program Files (x86)\Toolbar
2012-05-27 09:09:29 -------- d-----w- C:\Users\Александра\AppData\Roaming\Opera
2012-05-27 08:59:03 -------- d-----w- C:\Users\Александра\AppData\Roaming\WinRAR
2012-05-27 08:59:02 -------- d-----w- C:\Users\Александра\AppData\Roaming\Thinstall
2012-05-27 08:57:39 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-05-27 08:56:47 -------- d-----w- C:\Users\Александра\AppData\Roaming\uTorrent
2012-05-27 07:38:50 80384 ----a-w- C:\Windows\System32\drivers\BTHUSB.SYS
2012-05-27 07:38:50 552960 ----a-w- C:\Windows\System32\drivers\bthport.sys
2012-05-27 07:25:44 -------- d-----w- C:\Users\Александра\AppData\Roaming\PCDr
2012-05-26 16:37:57 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-05-26 16:26:06 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-05-26 16:26:06 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-05-26 16:26:06 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-05-26 16:26:06 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-05-26 16:26:06 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-05-26 16:26:06 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-05-26 16:26:06 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-05-26 16:26:05 8955792 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-05-26 16:21:15 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2012-05-26 16:21:15 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2012-05-26 16:21:14 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2012-05-26 16:21:14 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2012-05-26 16:18:54 77312 ----a-w- C:\Windows\System32\packager.dll
2012-05-26 16:18:54 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-05-26 16:17:47 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-05-26 16:17:46 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-05-26 16:17:46 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-05-26 16:17:46 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-05-26 16:08:19 -------- d-----w- C:\Users\Александра\AppData\Roaming\ESET
2012-05-26 16:07:51 -------- d-----w- C:\Program Files\ESET
2012-05-26 16:01:37 -------- d-----w- C:\Users\Александра\AppData\Roaming\Macromedia
2012-05-26 16:01:36 -------- d-----w- C:\Users\Александра\AppData\Roaming\Adobe
2012-05-26 15:51:00 -------- d-----w- C:\Users\Александра\AppData\Roaming\PwrMgr
2012-05-26 15:48:44 -------- d-----w- C:\Users\Александра\AppData\Roaming\Leadertech
2012-05-26 15:48:43 -------- d-----w- C:\Users\Александра\AppData\Roaming\ATI
2012-05-26 15:47:04 -------- d-----r- C:\Users\Александра\Searches
2012-05-26 15:46:53 -------- d-----w- C:\Users\Александра\AppData\Roaming\Identities
2012-05-26 15:46:49 -------- d-----r- C:\Users\Александра\Contacts
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Шаблоны
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Рабочий стол
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Главное меню
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Избранное
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Документы
.
==================== Find3M ====================
.
2012-05-02 13:22:54 25088 ----a-w- C:\Program Files (x86)\getfile.exe
2012-03-31 06:05:57 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2011-06-09 16:39:58 224256 ----a-w- C:\Program Files (x86)\wget.exe
.
============= FINISH: 13:43:43,66 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Домашняя базовая
Boot Device: \Device\HarddiskVolume1
Install Date: 26.05.2012 19:42:57
System Uptime: 11.06.2012 12:00:23 (1 hours ago)
.
Motherboard: LENOVO | | 1143CZG
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz | CPU | 2401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 453 GiB total, 413,207 GiB free.
D: is CDROM (CDFS)
E: is FIXED (FAT32) - 233 GiB total, 1,141 GiB free.
Q: is FIXED (NTFS) - 12 GiB total, 2,097 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP9: 01.06.2012 23:22:15 - Installed Vacation Quest 2 - Australia
RP10: 02.06.2012 13:02:06 - Центр обновления Windows
RP11: 02.06.2012 15:40:00 - Removed Vacation Quest 2 - Australia
RP12: 03.06.2012 3:00:11 - Центр обновления Windows
RP13: 04.06.2012 14:04:21 - Центр обновления Windows
RP14: 04.06.2012 14:06:56 - Центр обновления Windows
RP15: 05.06.2012 19:26:55 - Installed Macabre Mysteries - Curse of the Nightengale Collectors Edition
RP16: 06.06.2012 11:11:24 - Removed Macabre Mysteries - Curse of the Nightengale Collectors Edition
RP17: 08.06.2012 13:45:51 - Центр обновления Windows
.
==== Installed Programs ======================
.
Агентство моделей Full
Фотоальбом Windows Live
µTorrent
Почта Windows Live
Основные компоненты Windows Live
Элемент управления Windows Live Mesh ActiveX для удаленных подключений
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.0 - Russian
Burn.Now 4.5
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Corel Burn.Now Lenovo Edition
Corel DVD MovieFactory 7
Corel DVD MovieFactory Lenovo Edition
Corel WinDVD
Create Recovery Media
D3DX10
Direct DiscRecorder
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Integrated Camera Driver Installer Package Ver.1.1.0.1147
Integrated Camera TWAIN
Intel(R) Display Audio Driver
Intel(R) Identity Protection Technology 1.1.2.0
Intel(R) Management Engine Components
Intel(R) Wireless Display
Junk Mail filter update
Lenovo Registration
Lenovo User Guide
Lenovo Warranty Information
Lenovo Welcome
madLen.uCoz.coM Toolbar
Mesh Runtime
Message Center Plus
Microsoft Office 2010
Microsoft Office Starter 2010 - русский
Microsoft Office нажми и работай 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PowerXpressHybrid
PX Profile Update
Realtek Ethernet Controller Driver
RICOH_Media_Driver_v2.13.18.02
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Skype™ 5.0
System Update
ThinkPad Power Manager
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VIPAccess
VLC media player 2.0.1
Windows Live Communications Platform
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== End Of File ===========================
DDS logs:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 13:43:28 on 2012-06-11
Microsoft Windows 7 Домашняя базовая 6.1.7601.1.1251.7.1049.18.4007.2132 [GMT 4:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Персональный файервол ESET *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
C:\Windows\system32\CxAudMsg64.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\SysWOW64\SAsrv.exe
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Windows\Explorer.EXE
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Lenovo\System Update\SUService.exe
C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Александра\Downloads\dds.scr
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain ... &bmod=LENP
uStart Page = gamezona.org
mDefault_Page_URL = hxxp://xn--80afat5b.xn--p1ai
uURLSearchHooks: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
mURLSearchHooks: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - C:\ProgramData\Partner\Partner.dll
BHO: {8984B388-A5BB-4DF7-B274-77B879E179DB} - No File
BHO: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
BHO: Помощник по входу с помощью идентификатора Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Symantec VIP Access Add-On: {c63cd127-a1cb-4d49-a4f7-d6f88a917be6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: madLen.uCoz.coM Toolbar: {8dec4b69-27c4-405d-a37d-8d45c83f66ab} - C:\Program Files (x86)\madLen.uCoz.coM\tbmadL.dll
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
uRun: [b762d2b7609ec7ffb7cb9ad15a8a15dd] iexplore.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
mRun: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
mRun: [start] C:\WINDOWS\TASKMAN.bat
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\ThinkPad\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Отправить изображение на &устройство Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Отправить страницу на &устройство Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: Interfaces\{F32F2F52-F05E-4E51-9FB1-4C45EBC4F1AF} : NameServer = 83.243.64.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
BHO-X64: {8984B388-A5BB-4DF7-B274-77B879E179DB} - No File
{8dec4b69-27c4-405d-a37d-8d45c83f66ab}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
{8dec4b69-27c4-405d-a37d-8d45c83f66ab}
mRun-x64: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Lenovo Registration] C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe /boot
mRun-x64: [start] C:\WINDOWS\TASKMAN.bat
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
.
============= SERVICES / DRIVERS ===============
.
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM64.sys --> C:\Windows\system32\DRIVERS\ApsHM64.sys [?]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys --> C:\Windows\system32\DRIVERS\smiifx64.sys [?]
R1 PHCORE;PHCORE;C:\Program Files\Lenovo\RapidBoot\PHCORE64.sys [2011-7-8 32104]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 CxAudMsg;Conexant Audio Message Service;C:\Windows\system32\CxAudMsg64.exe --> C:\Windows\system32\CxAudMsg64.exe [?]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-1-14 810144]
R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute;C:\Program Files\Lenovo\Communications Utility\CamMute.exe [2011-9-28 40808]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2011-5-26 45496]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-9-28 59240]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2011-5-26 93032]
R2 PwmEWSvc;Cisco EnergyWise Enabler;C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe [2011-9-28 148840]
R2 risdxc;risdxc;C:\Windows\system32\DRIVERS\risdxc64.sys --> C:\Windows\system32\DRIVERS\risdxc64.sys [?]
R2 SAService;Conexant SmartAudio service;C:\Windows\System32\SASrv.exe [2011-9-28 446592]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-3-13 13840]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2011-5-26 144232]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2011-5-26 64952]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-9-28 2656280]
R2 VIPAppService;VIPAppService;C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [2011-4-13 84088]
R3 5U877;USB Video Device;C:\Windows\system32\DRIVERS\5U877.sys --> C:\Windows\system32\DRIVERS\5U877.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 IntcDAud;Аудио Intel(R) для дисплеев;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 intelkmd;intelkmd;C:\Windows\system32\DRIVERS\igdpmd64.sys --> C:\Windows\system32\DRIVERS\igdpmd64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Драйвер адаптера Intel(R) Wireless WiFi Link серии 5000 для Windows 7 64 Bit ;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 PCDSRVC{127174DC-C366ED8B-06020200}_0;PCDSRVC{127174DC-C366ED8B-06020200}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\PC-Doctor\pcdsrvc_x64.pkms [2011-4-1 25584]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 gupdate;Служба Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-28 136176]
S2 HyperW7Svc;HyperW7 Service;C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2011-7-8 144232]
S3 BTWAMPFL;BTWAMPFL;C:\Windows\system32\DRIVERS\btwampfl.sys --> C:\Windows\system32\DRIVERS\btwampfl.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 gupdatem;Служба Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-28 136176]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2011-9-28 332272]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2011-9-28 83304]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-06-11 09:41:09 -------- d-----w- C:\Users\?ыхъёрэфЁр\AppData\Local\Microsoft
2012-06-10 17:53:33 -------- d-----w- C:\Users\Александра\AppData\Roaming\dvdcss
2012-06-09 17:38:45 -------- d-----w- C:\Users\Александра\AppData\Roaming\Funlinker
2012-06-08 09:46:19 8955792 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BF26C08B-DA6A-4F42-B4E0-FF5556F01FB2}\mpengine.dll
2012-06-08 06:45:06 -------- d-----w- C:\Users\Александра\AppData\Roaming\Stand O'Food 3
2012-06-07 11:11:56 -------- d-----w- C:\ProgramData\Farm Fishes
2012-06-07 11:07:31 -------- d-----w- C:\Program Files (x86)\madLen.uCoz.coM
2012-06-07 11:07:31 -------- d-----w- C:\Program Files (x86)\Conduit
2012-06-07 11:06:50 -------- d-----w- C:\Users\Александра\AppData\Roaming\Mozilla
2012-06-06 16:30:27 -------- d-----w- C:\Users\Александра\AppData\Roaming\WeatherLord
2012-06-06 16:30:27 -------- d-----w- C:\ProgramData\WeatherLord
2012-06-06 11:21:23 -------- d-----w- C:\Users\Александра\AppData\Roaming\FamilyVacationCalifornia
2012-06-06 10:46:15 -------- d-----w- C:\Users\Александра\AppData\Roaming\Elephant Games
2012-06-06 10:46:15 -------- d-----w- C:\ProgramData\Elephant Games
2012-06-05 16:11:16 -------- d-----w- C:\Users\Александра\AppData\Roaming\Blue Tea Games
2012-06-05 14:23:38 -------- d-----w- C:\Users\Александра\AppData\Roaming\Aidem Media
2012-06-05 13:40:16 -------- d-----w- C:\Users\Александра\AppData\Roaming\V5 Play
2012-06-04 18:31:18 -------- d-----w- C:\Users\Александра\AppData\Roaming\JoyBits
2012-06-03 19:36:39 -------- d-----w- C:\ProgramData\Intenium
2012-06-03 18:46:55 -------- d-----w- C:\Users\Александра\AppData\Roaming\CoronationStreetPC
2012-06-03 15:35:05 -------- d-----w- C:\Users\Александра\AppData\Roaming\Artifex Mundi
2012-06-03 15:10:40 -------- d-----w- C:\Users\Александра\AppData\Roaming\SulusGames
2012-06-02 16:06:09 -------- d-----w- C:\ProgramData\Venus DS
2012-06-02 12:06:30 -------- d-----w- C:\Users\Александра\AppData\Roaming\Skunk Studios
2012-06-02 10:33:23 -------- d-----w- C:\Users\Александра\AppData\Roaming\Alawar
2012-06-02 10:33:23 -------- d-----w- C:\ProgramData\Alawar
2012-06-02 10:28:27 -------- d-----w- C:\ProgramData\PopCap Games
2012-06-01 19:23:49 -------- d-----w- C:\ProgramData\VirtualizedApplications
2012-06-01 19:23:01 -------- d-----w- C:\Users\Александра\AppData\Roaming\SpinTop Games
2012-06-01 17:58:56 -------- d-----w- C:\Users\Александра\AppData\Roaming\PoBros
2012-06-01 17:58:56 -------- d-----w- C:\ProgramData\PoBros
2012-06-01 17:13:35 -------- d-----w- C:\Users\Александра\AppData\Roaming\SoftGrid Client
2012-06-01 17:12:54 -------- d-----w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-06-01 17:12:34 -------- d-----w- C:\Users\Александра\AppData\Roaming\TP
2012-06-01 10:37:37 -------- d-----w- C:\ProgramData\Alawar Stargaze
2012-06-01 10:37:36 -------- d-----w- C:\ProgramData\AlawarWrapper
2012-06-01 10:10:42 -------- d-----w- C:\Users\Александра\AppData\Roaming\Alawar Stargaze
2012-05-31 17:23:52 -------- d-----w- C:\Users\Александра\AppData\Roaming\Brabl
2012-05-31 17:23:52 -------- d-----w- C:\Users\Александра\.gstreamer-0.10
2012-05-31 17:23:52 -------- d-----w- C:\Users\Александра\.gnome2
2012-05-30 18:23:15 -------- d-----w- C:\ProgramData\GameHouse
2012-05-30 18:20:32 -------- d-----w- C:\Users\Александра\AppData\Roaming\Zylom
2012-05-30 18:15:04 -------- d-----w- C:\ProgramData\Slapdash Games
2012-05-30 17:45:46 -------- d-----w- C:\Users\Александра\AppData\Roaming\My Games
2012-05-30 10:46:57 -------- d-----w- C:\Users\Александра\AppData\Roaming\PassionFruit Games
2012-05-29 14:26:07 -------- d-----w- C:\Users\Александра\AppData\Roaming\PathToSuccess_RU
2012-05-29 08:56:34 -------- d-----w- C:\Users\Александра\AppData\Roaming\Freeze Tag
2012-05-28 17:04:35 -------- d-----r- C:\Program Files (x86)\Skype
2012-05-28 17:04:34 -------- d-----w- C:\Users\Александра\AppData\Roaming\Skype
2012-05-28 15:03:52 -------- d-----w- C:\Users\Александра\AppData\Roaming\8floor
2012-05-28 15:03:52 -------- d-----w- C:\ProgramData\8floor
2012-05-27 15:33:20 -------- d-----w- C:\ProgramData\SpookyMall
2012-05-27 09:33:37 -------- d-----w- C:\Users\Александра\AppData\Roaming\vlc
2012-05-27 09:32:45 -------- d-----w- C:\Program Files (x86)\VideoLAN
2012-05-27 09:26:49 -------- d-----w- C:\Users\Александра\AppData\Roaming\Google
2012-05-27 09:10:24 -------- d-----w- C:\Program Files (x86)\Mail.Ru
2012-05-27 09:09:34 -------- d-----w- C:\Program Files (x86)\Toolbar
2012-05-27 09:09:29 -------- d-----w- C:\Users\Александра\AppData\Roaming\Opera
2012-05-27 08:59:03 -------- d-----w- C:\Users\Александра\AppData\Roaming\WinRAR
2012-05-27 08:59:02 -------- d-----w- C:\Users\Александра\AppData\Roaming\Thinstall
2012-05-27 08:57:39 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-05-27 08:56:47 -------- d-----w- C:\Users\Александра\AppData\Roaming\uTorrent
2012-05-27 07:38:50 80384 ----a-w- C:\Windows\System32\drivers\BTHUSB.SYS
2012-05-27 07:38:50 552960 ----a-w- C:\Windows\System32\drivers\bthport.sys
2012-05-27 07:25:44 -------- d-----w- C:\Users\Александра\AppData\Roaming\PCDr
2012-05-26 16:37:57 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-05-26 16:26:06 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-05-26 16:26:06 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-05-26 16:26:06 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-05-26 16:26:06 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-05-26 16:26:06 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-05-26 16:26:06 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-05-26 16:26:06 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-05-26 16:26:05 8955792 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-05-26 16:21:15 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2012-05-26 16:21:15 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2012-05-26 16:21:14 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2012-05-26 16:21:14 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2012-05-26 16:18:54 77312 ----a-w- C:\Windows\System32\packager.dll
2012-05-26 16:18:54 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-05-26 16:17:47 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-05-26 16:17:46 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-05-26 16:17:46 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-05-26 16:17:46 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-05-26 16:08:19 -------- d-----w- C:\Users\Александра\AppData\Roaming\ESET
2012-05-26 16:07:51 -------- d-----w- C:\Program Files\ESET
2012-05-26 16:01:37 -------- d-----w- C:\Users\Александра\AppData\Roaming\Macromedia
2012-05-26 16:01:36 -------- d-----w- C:\Users\Александра\AppData\Roaming\Adobe
2012-05-26 15:51:00 -------- d-----w- C:\Users\Александра\AppData\Roaming\PwrMgr
2012-05-26 15:48:44 -------- d-----w- C:\Users\Александра\AppData\Roaming\Leadertech
2012-05-26 15:48:43 -------- d-----w- C:\Users\Александра\AppData\Roaming\ATI
2012-05-26 15:47:04 -------- d-----r- C:\Users\Александра\Searches
2012-05-26 15:46:53 -------- d-----w- C:\Users\Александра\AppData\Roaming\Identities
2012-05-26 15:46:49 -------- d-----r- C:\Users\Александра\Contacts
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Шаблоны
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Рабочий стол
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Главное меню
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Избранное
2012-05-26 15:42:55 -------- d-sh--we C:\ProgramData\Документы
.
==================== Find3M ====================
.
2012-05-02 13:22:54 25088 ----a-w- C:\Program Files (x86)\getfile.exe
2012-03-31 06:05:57 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2011-06-09 16:39:58 224256 ----a-w- C:\Program Files (x86)\wget.exe
.
============= FINISH: 13:43:43,66 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Домашняя базовая
Boot Device: \Device\HarddiskVolume1
Install Date: 26.05.2012 19:42:57
System Uptime: 11.06.2012 12:00:23 (1 hours ago)
.
Motherboard: LENOVO | | 1143CZG
Processor: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz | CPU | 2401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 453 GiB total, 413,207 GiB free.
D: is CDROM (CDFS)
E: is FIXED (FAT32) - 233 GiB total, 1,141 GiB free.
Q: is FIXED (NTFS) - 12 GiB total, 2,097 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP9: 01.06.2012 23:22:15 - Installed Vacation Quest 2 - Australia
RP10: 02.06.2012 13:02:06 - Центр обновления Windows
RP11: 02.06.2012 15:40:00 - Removed Vacation Quest 2 - Australia
RP12: 03.06.2012 3:00:11 - Центр обновления Windows
RP13: 04.06.2012 14:04:21 - Центр обновления Windows
RP14: 04.06.2012 14:06:56 - Центр обновления Windows
RP15: 05.06.2012 19:26:55 - Installed Macabre Mysteries - Curse of the Nightengale Collectors Edition
RP16: 06.06.2012 11:11:24 - Removed Macabre Mysteries - Curse of the Nightengale Collectors Edition
RP17: 08.06.2012 13:45:51 - Центр обновления Windows
.
==== Installed Programs ======================
.
Агентство моделей Full
Фотоальбом Windows Live
µTorrent
Почта Windows Live
Основные компоненты Windows Live
Элемент управления Windows Live Mesh ActiveX для удаленных подключений
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.0 - Russian
Burn.Now 4.5
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Corel Burn.Now Lenovo Edition
Corel DVD MovieFactory 7
Corel DVD MovieFactory Lenovo Edition
Corel WinDVD
Create Recovery Media
D3DX10
Direct DiscRecorder
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Integrated Camera Driver Installer Package Ver.1.1.0.1147
Integrated Camera TWAIN
Intel(R) Display Audio Driver
Intel(R) Identity Protection Technology 1.1.2.0
Intel(R) Management Engine Components
Intel(R) Wireless Display
Junk Mail filter update
Lenovo Registration
Lenovo User Guide
Lenovo Warranty Information
Lenovo Welcome
madLen.uCoz.coM Toolbar
Mesh Runtime
Message Center Plus
Microsoft Office 2010
Microsoft Office Starter 2010 - русский
Microsoft Office нажми и работай 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PowerXpressHybrid
PX Profile Update
Realtek Ethernet Controller Driver
RICOH_Media_Driver_v2.13.18.02
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Skype™ 5.0
System Update
ThinkPad Power Manager
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
VIPAccess
VLC media player 2.0.1
Windows Live Communications Platform
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== End Of File ===========================
textbox. Do not include the word Code
.