Лог утилиты random's system information tool 1.08 (автор: random/random) Run by Fenix at 2011-05-17 07:12:41 Microsoft Windows XP Professional Service Pack 2 Системный раздел C: размер 9 GB (30%) Свободно 31 GB Total RAM: 1982 MB (47% free) HijackThis download failed ======Папка назначеных зданий====== C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\Dr.Web Daily scan.job C:\WINDOWS\tasks\Dr.Web Update.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job ======Снимок реестра====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60c4696a-e4eb-4d2d-9060-38928dd0b6a2}] digitalchocolate Toolbar - C:\Program Files\digitalchocolate\prxtbdigi.dll [2011-01-03 175400] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9BFBA68E-E21B-458E-AE12-FE85E903D2C1}] AlterGeoBHO Class - C:\Program Files\AlterGeo\AlterGeo Magic Scanner\2.8.8.615\AlterGeo.BrowserPlugin.dll [2010-08-31 257384] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}] QIPBHO Class - C:\Documents and Settings\Fenix\Application Data\Microsoft\Internet Explorer\qipsearchbar.dll [2009-10-05 150768] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTo1.dll [2011-01-13 3911776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-09 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-09 79648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-09-12 3863136] {60c4696a-e4eb-4d2d-9060-38928dd0b6a2} - digitalchocolate Toolbar - C:\Program Files\digitalchocolate\prxtbdigi.dll [2011-01-03 175400] {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files\uTorrentBar\tbuTo1.dll [2011-01-13 3911776] {23DD83B5-BDDC-49CE-B77B-514819C6D551} [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k [] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-08-16 7196672] "SpIDerMail"=C:\Program Files\DrWeb\spiderml.exe [2011-03-16 1572592] "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648] "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] ""=1 [] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-03-26 399736] "LHFDaphne"=C:\Program Files\Daphne\Daphne.exe [2010-08-28 813568] "MediaGet2"=C:\Documents and Settings\Fenix\Local Settings\Application Data\MediaGet2\mediaget.exe [2011-04-22 6053096] "QIP Internet Guardian"=C:\Documents and Settings\Fenix\Application Data\QipGuard\QipGuard.exe [2011-02-01 187776] "MAgent"=C:\Documents and Settings\Fenix\Application Data\Mail.Ru\Agent\magent.exe [2011-03-18 7975608] C:\Documents and Settings\All Users\Главное меню\Программы\Автозагрузка Dr.Web ®.lnk - C:\Program Files\DrWeb\spideragent.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="d3dx9_27.dll C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver\vksaver3.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon] C:\WINDOWS\system32\klogon.dll [2008-07-29 218376] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2003-08-18 239616] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= [] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "DisableStatusMessages"=0 "DisableTaskMgr"=0 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=149 "NoDriveAutoRun"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=60 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server" "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype" "C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Запуск библиотеки DLL как приложения" "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime" "C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser" "C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb" "C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray" "C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\124.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\124.exe:*:C:\WINDOWS\jjdrive32.exe" "C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\227.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\227.exe:*:C:\WINDOWS\jjdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\665.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\665.exe:*:C:\WINDOWS\jjdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\358.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\358.exe:*:C:\WINDOWS\jjdrive32.exe" "C:\WINDOWS\System32\11.scr"="C:\WINDOWS\System32\11.scr:*:C:\WINDOWS\livemessn.exe" "C:\WINDOWS\System32\68.scr"="C:\WINDOWS\System32\68.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\37.scr"="C:\WINDOWS\System32\37.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\20.scr"="C:\WINDOWS\System32\20.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\41.scr"="C:\WINDOWS\System32\41.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\60.scr"="C:\WINDOWS\System32\60.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\16.scr"="C:\WINDOWS\System32\16.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\56.scr"="C:\WINDOWS\System32\56.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\46.scr"="C:\WINDOWS\System32\46.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\07.scr"="C:\WINDOWS\System32\07.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\76.scr"="C:\WINDOWS\System32\76.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\15.scr"="C:\WINDOWS\System32\15.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\70.scr"="C:\WINDOWS\System32\70.scr:*:C:\WINDOWS\updatd7.exe" "C:\WINDOWS\System32\45.scr"="C:\WINDOWS\System32\45.scr:*:C:\WINDOWS\updatd7.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\837.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\837.exe:*:C:\WINDOWS\ccdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\193.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\193.exe:*:C:\WINDOWS\ccdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\922.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\922.exe:*:C:\WINDOWS\ccdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\582.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\582.exe:*:C:\WINDOWS\ccdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\286.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\286.exe:*:C:\WINDOWS\ccdrive32.exe" "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe:*:Enabled:BlueSoleil" "C:\Program Files\Mozilla Firefox 3.5.5 Pre Mod by SK\App\Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox 3.5.5 Pre Mod by SK\App\Firefox\firefox.exe:*:Enabled:Firefox" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\241.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\241.exe:*:C:\WINDOWS\cndrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\2248.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\2248.exe:*:C:\WINDOWS\cndrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\546780.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\546780.exe:*:C:\WINDOWS\cndrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\278016.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\278016.exe:*:C:\WINDOWS\cndrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\8158597.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\8158597.exe:*:C:\WINDOWS\cndrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\3313048.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\3313048.exe:*:C:\WINDOWS\cndrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\025.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\025.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\29787.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\29787.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\6865539.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\6865539.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\103.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\103.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\6255.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\6255.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\29604.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\29604.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\62829.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\62829.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\9863.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\9863.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\851.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\851.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\260132.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\260132.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\831532.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\831532.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\455.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\455.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\81443.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\81443.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\679.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\679.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\WINDOWS\System32\64.scr"="C:\WINDOWS\System32\64.scr:*:C:\WINDOWS\system32\Zsorm.exe" "C:\WINDOWS\System32\58.scr"="C:\WINDOWS\System32\58.scr:*:C:\WINDOWS\system32\Zsorm.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\4416.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\4416.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\8207.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\8207.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\3511750.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\3511750.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\WINDOWS\System32\71.scr"="C:\WINDOWS\System32\71.scr:*:C:\WINDOWS\system32\Zsorm.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\9952831.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\9952831.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\WINDOWS\System32\06.scr"="C:\WINDOWS\System32\06.scr:*:C:\WINDOWS\system32\Zsorm.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\14213.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\14213.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\238.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\238.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\01715.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\01715.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\3783.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\3783.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\5957.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\5957.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\5104921.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\5104921.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\531188.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\531188.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\6802.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\6802.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\72111.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\72111.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\521.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\521.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\0639.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\0639.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\94382.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\94382.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\0623246.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\0623246.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\3870.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\3870.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\0967116.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\0967116.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\623818.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\623818.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\4416494.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\4416494.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\950060.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\950060.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\975382.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\975382.exe:*:C:\WINDOWS\cfdrive32.exe" "C:\DOCUME~1\Fenix\LOCALS~1\Temp\51039.exe"="C:\DOCUME~1\Fenix\LOCALS~1\Temp\51039.exe:*:C:\WINDOWS\cfdrive32.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\Mozilla Firefox 3.5.5 Pre Mod by SK\App\Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox 3.5.5 Pre Mod by SK\App\Firefox\firefox.exe:*:Enabled:Firefox" ======Список файлов и папок, созданных за последние 3 месяца====== 2011-05-15 13:49:01 ----D---- C:\rsit 2011-05-15 13:49:01 ----D---- C:\Program Files\trend micro 2011-05-13 16:05:59 ----D---- C:\Program Files\QuickTime 2011-05-13 15:40:42 ----D---- C:\Documents and Settings\Fenix\Application Data\Apple Computer 2011-05-13 15:22:14 ----D---- C:\Program Files\Safari 2011-05-13 15:22:14 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer 2011-05-13 15:21:35 ----D---- C:\Program Files\Bonjour 2011-05-13 15:20:44 ----D---- C:\Program Files\Common Files\Apple 2011-05-13 15:20:01 ----D---- C:\Program Files\Apple Software Update 2011-05-13 15:20:00 ----D---- C:\Documents and Settings\All Users\Application Data\Apple 2011-05-09 23:49:31 ----D---- C:\WINDOWS\wb 2011-05-08 14:00:45 ----A---- C:\WINDOWS\system32\drivers\DrWebPF.sys 2011-05-08 14:00:42 ----A---- C:\WINDOWS\system32\drivers\drwebaf.sys 2011-05-01 13:51:24 ----A---- C:\Program Files\downloader_turbobit_3270850e972be1d312b9270bfada2d7d.exe 2011-04-30 14:21:38 ----D---- C:\Documents and Settings\Fenix\Application Data\EurekaLog 2011-04-29 22:24:36 ----A---- C:\WINDOWS\system32\drivers\dwprot.sys 2011-04-29 22:09:36 ----A---- C:\WINDOWS\system32\drivers\spiderg3.sys 2011-04-29 22:08:30 ----D---- C:\Documents and Settings\All Users\Application Data\Doctor Web 2011-04-29 22:08:28 ----D---- C:\Program Files\DrWeb 2011-04-29 22:08:28 ----D---- C:\Program Files\Common Files\Doctor Web 2011-04-12 20:24:02 ----D---- C:\Program Files\VKMusic 4 2011-04-12 20:23:12 ----A---- C:\Program Files\VKMusic_4.exe 2011-04-12 08:53:12 ----D---- C:\Documents and Settings\All Users\Application Data\VKSaver 2011-04-04 09:47:13 ----D---- C:\Program Files\Common Files\DirectX 2011-03-28 19:53:53 ----D---- C:\Program Files\Video 2011-03-27 20:18:34 ----D---- C:\Documents and Settings\Fenix\Application Data\Unity 2011-03-18 04:20:33 ----D---- C:\Documents and Settings\Fenix\Application Data\Mra 2011-03-05 00:47:16 ----D---- C:\Documents and Settings\Fenix\Application Data\rubar 2011-03-04 16:23:07 ----A---- C:\WINDOWS\uninst.exe 2011-03-04 16:19:52 ----A---- C:\WINDOWS\ScUnin.pif 2011-03-04 16:19:52 ----A---- C:\WINDOWS\ScUnin.exe 2011-03-04 01:20:35 ----D---- C:\Documents and Settings\All Users\Application Data\nView_Profiles ======Список файлов и папок, измененных за последние 3 месяца====== 2011-05-17 07:12:21 ----D---- C:\Documents and Settings\Fenix\Application Data\uTorrent 2011-05-17 03:23:18 ----D---- C:\WINDOWS\Prefetch 2011-05-17 01:39:13 ----A---- C:\WINDOWS\SchedLgU.Txt 2011-05-16 17:41:11 ----D---- C:\WINDOWS\Temp 2011-05-16 17:41:01 ----D---- C:\WINDOWS\system32\CatRoot2 2011-05-16 17:39:07 ----HD---- C:\WINDOWS 2011-05-16 01:03:17 ----D---- C:\WINDOWS\Minidump 2011-05-15 22:01:25 ----D---- C:\Documents and Settings\Fenix\Application Data\Skype 2011-05-15 21:12:00 ----D---- C:\Documents and Settings\Fenix\Application Data\skypePM 2011-05-15 21:10:32 ----SHD---- C:\WINDOWS\Installer 2011-05-15 21:00:31 ----A---- C:\ashampoo-acdw-log.txt 2011-05-15 20:52:36 ----D---- C:\Documents and Settings\Fenix\Application Data\PriceGong 2011-05-15 20:52:00 ----D---- C:\WINDOWS\system32\drivers 2011-05-15 13:49:01 ----RD---- C:\Program Files 2011-05-15 13:22:14 ----D---- C:\WINDOWS\system32\drivers\etc 2011-05-15 05:08:35 ----A---- C:\WINDOWS\NeroDigital.ini 2011-05-13 16:08:06 ----D---- C:\Program Files\Internet Explorer 2011-05-13 16:06:00 ----D---- C:\WINDOWS\system32 2011-05-13 15:20:44 ----D---- C:\Program Files\Common Files 2011-05-13 15:20:21 ----SD---- C:\WINDOWS\Tasks 2011-05-11 19:53:58 ----D---- C:\Documents and Settings\All Users\Application Data\Norton 2011-05-11 19:53:54 ----SHD---- C:\System Volume Information 2011-05-11 06:48:43 ----DC---- C:\WINDOWS\system32\DRVSTORE 2011-05-11 06:48:16 ----D---- C:\Program Files\Symantec 2011-05-10 17:44:26 ----D---- C:\Program Files\Revo Uninstaller Pro 2011-05-09 23:49:31 ----D---- C:\WINDOWS\system 2011-05-09 14:58:30 ----D---- C:\Program Files\Yandex 2011-05-08 16:32:29 ----D---- C:\Downloads 2011-05-08 14:02:53 ----D---- C:\Program Files\Mozilla Firefox 2011-05-08 14:01:03 ----HD---- C:\WINDOWS\inf 2011-05-08 14:00:26 ----SD---- C:\Documents and Settings\Fenix\Application Data\Microsoft 2011-04-29 22:17:22 ----D---- C:\WINDOWS\system32\config 2011-04-25 21:31:23 ----D---- C:\Documents and Settings\Fenix\Application Data\Media Get LLC 2011-04-25 21:31:23 ----D---- C:\Documents and Settings\All Users\Application Data\Media Get LLC 2011-04-24 00:28:41 ----D---- C:\Program Files\User 2011-04-14 17:13:48 ----D---- C:\Program Files\Opera 2011-04-05 01:46:45 ----D---- C:\Program Files\QIP 2010 2011-04-04 20:12:13 ----D---- C:\WINDOWS\WinSxS 2011-03-27 17:48:15 ----D---- C:\Program Files\Daphne 2011-03-27 08:55:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2011-03-26 22:47:35 ----D---- C:\Program Files\uTorrent 2011-03-20 19:41:56 ----D---- C:\Program Files\mediabar Toolbar 2011-03-18 04:20:33 ----D---- C:\Documents and Settings\Fenix\Application Data\Mail.Ru 2011-03-09 09:48:42 ----RSHDC---- C:\WINDOWS\system32\dllcache 2011-03-05 00:44:43 ----D---- C:\Program Files\Solo9RusEngNum 2011-02-23 14:40:55 ----A---- C:\WINDOWS\DUMPc488.tmp ======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)====== R0 DwProt;DrWeb Protection; C:\WINDOWS\system32\drivers\dwprot.sys [2011-02-03 139768] R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-03-31 44944] R0 SpiderG3;DrWeb file system scanner; C:\WINDOWS\system32\drivers\spiderg3.sys [2011-01-31 93944] R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-02-26 691696] R1 DRWEBAF;DrWEB Firewall Application Filter; \??\C:\WINDOWS\system32\drivers\drwebaf.sys [] R1 oreans32;oreans32; \??\C:\WINDOWS\system32\drivers\oreans32.sys [] R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228] R1 uze5nte2;AVZ-RK Kernel Driver; \??\C:\WINDOWS\system32\Drivers\uze5nte2.sys [] R1 WS2IFSL;Среда Windows Socket 2.0 поддержки поставщиков не-IFS служб; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-08-18 12032] R2 irda;ИК-протокол IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424] R2 rspndr;Ответчик обнаружения топологии уровня связи; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2006-12-04 62336] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-06-20 2324480] R3 DrWebPF;DrWeb Packet Filter Driver; C:\WINDOWS\system32\DRIVERS\DrWebPF.sys [2011-05-08 72568] R3 irsir;Драйвер для инфракрасного последовательного порта Microsoft; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-18 18688] R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-08-16 3502176] R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048] R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928] R3 Rasirda;Минипорт WAN (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-18 19584] R3 SymantecAntiBotDriver;SymantecAntiBotDriver; \??\C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotDriver.sys [] R3 SymantecAntiBotFilter;SymantecAntiBotFilter; \??\C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotFilter.sys [] R3 SymantecAntiBotShim;SymantecAntiBotShim; \??\C:\Program Files\Symantec\Norton AntiBot\agent\driver\AntiBotShim.sys [] R3 usbaudio;Аудио драйвер USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264] R3 usbccgp;Драйвер универсального родительского устройства USB (Microsoft); C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616] R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2005-07-30 121856] S0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [] S0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [] S1 kbdhid;Драйвер клавиатуры HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848] S1 SASDIFSV;SASDIFSV; C:\WINDOWS\system32\drivers\SASDIFSV.sys [] S1 SASKUTIL;SASKUTIL; C:\WINDOWS\system32\drivers\SASKUTIL.sys [] S2 TCPZ;TCP Half Open Limited Patcher ( TCP-Z); C:\WINDOWS\system32\drivers\TCPZ.sys [] S3 ar3b662e;ar3b662e; C:\WINDOWS\system32\drivers\ar3b662e.sys [] S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [] S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [] S3 bnzbicpmb;bnzbicpmb; \??\C:\WINDOWS\system32\01.tmp [] S3 bphbrzl;bphbrzl; \??\C:\WINDOWS\system32\01.tmp [] S3 brrvacope;brrvacope; \??\C:\WINDOWS\system32\01.tmp [] S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [] S3 btaudio;Аудиоустройство Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [] S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [] S3 BTDriver;Драйвер виртуальной связи Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [] S3 BthEnum;Драйвер блока запроса Bluetooth; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-04 17024] S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992] S3 BTHPORT;Драйвер порта Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-17 274688] S3 BTHUSB;Драйвер порта USB радиомодуля Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-04 18944] S3 BTWDNDIS;Сервер доступа к локальной сети Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [] S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [] S3 cbxqvurds;cbxqvurds; \??\C:\WINDOWS\system32\01.tmp [] S3 CCDECODE;Closed Caption декодер; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024] S3 deltzis;deltzis; \??\C:\WINDOWS\system32\01.tmp [] S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [] S3 fgzsztsi;fgzsztsi; \??\C:\WINDOWS\system32\01.tmp [] S3 FXDRV;FXDRV; \??\E:\Fxdrv.sys [] S3 gbqgets;gbqgets; \??\C:\WINDOWS\system32\0D.tmp [] S3 gdmcixu;gdmcixu; \??\C:\WINDOWS\system32\01.tmp [] S3 gtblqtiqb;gtblqtiqb; \??\C:\WINDOWS\system32\01.tmp [] S3 HidUsb;Драйвер класса HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600] S3 hsujxp;hsujxp; \??\C:\WINDOWS\system32\01.tmp [] S3 jgutjtz;jgutjtz; \??\C:\WINDOWS\system32\01.tmp [] S3 jlpvsuq;jlpvsuq; \??\C:\WINDOWS\system32\01.tmp [] S3 jqrrtqlie;jqrrtqlie; \??\C:\WINDOWS\system32\087.tmp [] S3 kfhlkwo;kfhlkwo; \??\C:\WINDOWS\system32\01.tmp [] S3 kgdmxoynh;kgdmxoynh; \??\C:\WINDOWS\system32\01.tmp [] S3 lfjooha;lfjooha; \??\C:\WINDOWS\system32\01.tmp [] S3 mouhid;Драйвер мыши HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-19 12160] S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504] S3 NABTSFEC;NABTS/FEC VBI кодек; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376] S3 NdisIP;Microsoft видео или ТВ подключение; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880] S3 nubpz;nubpz; \??\C:\WINDOWS\system32\01.tmp [] S3 rbfunzf;rbfunzf; \??\C:\WINDOWS\system32\01.tmp [] S3 Revoflt;Revoflt; C:\WINDOWS\system32\DRIVERS\revoflt.sys [2009-12-30 27064] S3 RFCOMM;Устройство Bluetooth (протокол RFCOMM TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-04 59648] S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2003-08-18 5888] S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\WINDOWS\system32\DRIVERS\s116bus.sys [2007-04-03 83336] S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [2007-04-03 15112] S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [2007-04-03 108680] S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s116mgmt.sys [2007-04-03 100488] S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:\WINDOWS\system32\DRIVERS\s116nd5.sys [2007-04-03 23176] S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s116obex.sys [2007-04-03 98696] S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:\WINDOWS\system32\DRIVERS\s116unic.sys [2007-04-03 99080] S3 SASENUM;SASENUM; C:\WINDOWS\system32\drivers\SASENUM.sys [] S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136] S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360] S3 USBSTOR;Драйвер запоминающих устройств для USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [] S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [] S3 VHidMinidrv;Bluetooth HID Device Service; C:\WINDOWS\system32\drivers\VHIDMini.sys [] S3 voomjgl;voomjgl; \??\C:\WINDOWS\system32\01.tmp [] S3 WSTCODEC;World Standard Teletext кодек; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328] S3 XDva349;XDva349; \??\C:\WINDOWS\system32\XDva349.sys [] S3 XDva366;XDva366; \??\C:\WINDOWS\system32\XDva366.sys [] S3 XDva370;XDva370; \??\C:\WINDOWS\system32\XDva370.sys [] S3 ximiu;ximiu; \??\C:\WINDOWS\system32\01.tmp [] S3 ycfxiougt;ycfxiougt; \??\C:\WINDOWS\system32\01.tmp [] S3 ziuvsf;ziuvsf; \??\C:\WINDOWS\system32\01.tmp [] ======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)====== R2 Bonjour Service;Служба Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2010-10-07 345376] R2 CSHelper;CopySafe Helper Service; C:\WINDOWS\system32\CSHelper.exe [2010-12-06 266240] R2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine); C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [2011-03-01 1667416] R2 DrWebFwSvc;Dr.Web Firewall Service; C:\Program Files\DrWeb\frwl_svc.exe [2011-04-20 2267120] R2 Irmon;Монитор инфракрасной связи; C:\WINDOWS\system32\svchost.exe [2003-08-18 14336] R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-09 153376] R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-08-16 131138] R2 SymantecAntiBotAgent;SymantecAntiBotAgent; C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABAgent.exe [2007-11-12 4909592] R2 SymantecAntiBotWatcher;SymantecAntiBotWatcher; C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABWatcher.exe [2007-11-12 539160] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\w [2010-01-19 74] S2 QipGuard;QipGuard; C:\Program Files\QipGuard\QipGuard.exe [] S2 Rubar Update Service;Rubar Update Service; C:\Program Files\mediabar Toolbar\RubarUpdateService.exe [] S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-12-04 72704] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2010-02-25 3432444] S4 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2003-08-18 14336] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF-----------------