• Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы

SPYWARE-RU.COM

Меню
  • Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы
В начало › Re: Re: последствия порно банера
Adguard
 

Re: Re: последствия порно банера

Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › последствия порно банера › Re: Re: последствия порно банера

4 ноября, 2009 в 7:53 дп #26547
Ihor
Participant
  • Темы:1
  • Сообщений:4
  • ☆

Доброго времени суток.

ComboFix 09-11-03.03 — Admin 04.11.2009 9:26.1.1 — NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.511.195 [GMT 2:00]
Running from: c:combofixComboFix.exe
Command switches used :: ComboFix
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:documents and settingsAdminApplication DataAdSubscribe
c:documents and settingsAdminApplication DataAdSubscribeAdSubscribe.dat
c:documents and settingsAdminApplication DataAdSubscribeFeed.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed1.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed2.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed3.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed4.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed5.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed6.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed7.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed8.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed9.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeedfeed.xml
c:documents and settingsAdminApplication Dataakokynokeh.ban
c:documents and settingsAdminApplication DataAldea
c:documents and settingsAdminApplication Datacafex.com
c:documents and settingsAdminApplication Datacida.exe
c:documents and settingsAdminApplication Datadehegim.pif
c:documents and settingsAdminApplication Dataefogiwa.com
c:documents and settingsAdminApplication Dataheripozuku.lib
c:documents and settingsAdminApplication Datamuqy.dll
c:documents and settingsAdminApplication Dataosigenowus._sy
c:documents and settingsAdminApplication Dataqozivazi.ban
c:documents and settingsAdminApplication Dataratofo.bat
c:documents and settingsAdminApplication Datasefok.scr
c:documents and settingsAdminApplication Datawunero.dl
c:documents and settingsAdminLocal SettingsApplication Databixybi.inf
c:documents and settingsAdminLocal SettingsApplication Databovegohofe.bat
c:documents and settingsAdminLocal SettingsApplication Datadedekyhoq.bin
c:documents and settingsAdminLocal SettingsApplication Datadorejaq.exe
c:documents and settingsAdminLocal SettingsApplication Datairakypig.dll
c:documents and settingsAdminLocal SettingsApplication Datalosuhineki.ban
c:documents and settingsAdminLocal SettingsApplication Dataqajuwi._sy
c:documents and settingsAdminLocal SettingsApplication Dataxogidoput.sys
c:documents and settingsAdminLocal SettingsApplication Dataycoripa.bat
c:documents and settingsAdminLocal SettingsApplication Dataytuvabuja.dll
c:documents and settingsAdminLocal SettingsTemporary Internet Filesbefeguve.inf
c:documents and settingsAdminLocal SettingsTemporary Internet Filesemajasuxi.inf
c:documents and settingsAdminLocal SettingsTemporary Internet Filesizyd.dat
c:documents and settingsAdminLocal SettingsTemporary Internet Filesjunic.reg
c:documents and settingsAdminLocal SettingsTemporary Internet Filessigijir.dat
c:documents and settingsAdminoashdihasidhasuidhiasdhiashdiuasdhasd
c:documents and settingsAll UsersДокументыarabisapy.dll
c:documents and settingsAll UsersДокументыasoqycyw._dl
c:documents and settingsAll UsersДокументыefomonuwu.dl
c:documents and settingsAll UsersДокументыeticipatu.bin
c:documents and settingsAll UsersДокументыixysyzaju.bin
c:documents and settingsAll UsersДокументыoful.scr
c:documents and settingsAll UsersДокументыsaquj.exe
c:documents and settingsAll UsersApplication Datacufupeti.lib
c:documents and settingsAll UsersApplication Datadojetirico._sy
c:documents and settingsAll UsersApplication Dataedepehona.scr
c:documents and settingsAll UsersApplication Datagemi.bat
c:documents and settingsAll UsersApplication Datahofagamu.bin
c:documents and settingsAll UsersApplication Dataibela.dll
c:documents and settingsAll UsersApplication Dataimibadode.sys
c:documents and settingsAll UsersApplication Datajyjorecyri.sys
c:documents and settingsAll UsersApplication Datajyleh.com
c:documents and settingsAll UsersApplication Datanukog.dll
c:documents and settingsAll UsersApplication Dataoquj.reg
c:documents and settingsAll UsersApplication Dataorygykov.ban
c:documents and settingsAll UsersApplication Datasehytacely.com
c:documents and settingsAll UsersApplication Dataupibiba.bin
c:documents and settingsAll UsersApplication Datawyfymymuqo.sys
c:documents and settingsAll UsersApplication Dataywugacaro.bin
c:documents and settingsAll Users„®Єг¬Ґ­влkebowasuqy.bat
c:documents and settingsAll Users„®Єг¬Ґ­влocyko.vbs
c:documents and settingsAll Users„®Єг¬Ґ­влuhecu.reg
c:documents and settingsAll Users„®Єг¬Ґ­влujuzale.inf
c:documents and settingsAll Users„®Єг¬Ґ­влuqohupocuz.bat
c:program filesCommon Filescyqadifuc.exe
c:program filesCommon Filesdasivy.scr
c:program filesCommon Filesdepa.ban
c:program filesCommon Filesdonijepu.bin
c:program filesCommon Filesenetimamo.bin
c:program filesCommon Filesjowewaxolo.ban
c:program filesCommon Filesjowym.dl
c:program filesCommon Filesjusisujar.exe
c:program filesCommon Filespigoxa.reg
c:program filesCommon Filespomesabyc.dll
c:program filesCommon Filessupyse.scr
c:windowsadoru.reg
c:windowsaxucolyca.reg
c:windowsbazaci.dll
c:windowsboxov._dl
c:windowsbysydyhy.exe
c:windowscemihepote.vbs
c:windowscosugak.sys
c:windowsDelete.bat
c:windowsdyjonojupe._sy
c:windowsehycamin._dl
c:windowsekonu.exe
c:windowselikut._dl
c:windowsfiwonuwe.sys
c:windowshofa.sys
c:windowshokacel.vbs
c:windowsicugiqiqe.reg
c:windowsiryvysy.exe
c:windowskyfufiguni.sys
c:windowsowatomavi.sys
c:windowspidif.sys
c:windowsramuguhyc.vbs
c:windowssystem32cocury._dl
c:windowssystem32defig._dl
c:windowssystem32gapolozyky.ban
c:windowssystem32jehi.dll
c:windowssystem32ovyrem.pif
c:windowssystem32puriced.sys
c:windowssystem32ulelib.dl
c:windowssystem32waxoq.bat
c:windowssystem32xoqimeselu.pif
c:windowssystem32ytotu.vbs
c:windowstineloxizu.vbs
c:windowsvanupetydy._sy
c:windowsvidev.sys
c:windowsvifotanyqa.inf
c:windowswupokasos.ban
c:windowsxulyhed._dl
c:windowsyqita.vbs

.
((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
.

2009-10-25 07:48 . 2009-10-25 07:48


d


w- c:documents and settingsAdminDoctorWeb
2009-10-25 07:20 . 2009-10-25 07:20 56 —ha-w- c:windowssystem32ezsidmv.dat
2009-10-25 07:18 . 2009-10-25 07:18


d


w- c:program filesCommon FilesSkype
2009-10-25 07:18 . 2009-10-25 07:18


d


r- c:program filesSkype
2009-10-25 05:23 . 2009-10-25 05:23 18257 —-a-w- c:windowssystem32hiwade.dat
2009-10-24 21:36 . 2009-11-03 23:13


d


w- c:program filestrend micro
2009-10-24 21:36 . 2009-10-24 21:37


d


w- C:rsit
2009-10-24 18:19 . 2009-10-24 18:19 10241 —-a-w- c:windowssystem32vulyk.com
2009-10-24 18:19 . 2009-10-24 18:19 14966 —-a-w- c:windowssystem32pehe.com
2009-10-24 14:31 . 2009-10-24 14:31 15240 —-a-w- c:windowssystem32ygeroraji.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 07:35 . 2009-05-03 13:23


d


w- c:documents and settingsAdminApplication DataSkype
2009-11-04 06:42 . 2009-01-26 14:16


d


w- c:documents and settingsAdminApplication DataTransLite
2009-11-03 22:08 . 2009-05-03 13:26


d


w- c:documents and settingsAdminApplication DataskypePM
2009-11-03 22:05 . 2008-12-07 11:31


d


w- c:documents and settingsAdminApplication DataThe Bat!
2009-10-25 15:36 . 2008-11-30 13:43


d


w- c:program filesESET
2009-10-25 07:18 . 2009-05-03 13:23


d


w- c:documents and settingsAll UsersApplication DataSkype
2009-10-25 06:25 . 2009-05-03 14:03 774 —-a-w- c:documents and settingsAdminApplication Dataaldea.dat
2009-10-25 05:24 . 2008-04-15 12:00 77534 —-a-w- c:windowssystem32perfc019.dat
2009-10-25 05:24 . 2008-04-15 12:00 451468 —-a-w- c:windowssystem32perfh019.dat
2009-10-24 21:22 . 2008-11-30 16:11


d


w- c:documents and settingsAdminApplication DataHPAppData
2009-10-24 19:22 . 2009-10-24 19:22 10504 —-a-w- c:program filesCommon Filessugyty.db
2009-10-24 18:19 . 2009-10-24 18:19 15737 —-a-w- c:documents and settingsAll UsersApplication Dataxini.dat
2009-09-11 05:59 . 2009-09-11 05:59


d


w- c:documents and settingsAdminApplication DataU3
2009-08-26 11:15 . 2009-08-26 06:37 19539 —-a-w- c:windowshpqins13.dat
2009-08-20 10:03 . 2009-08-20 10:03 17 —-a-w- c:documents and settingsAdminApplication Datagrf.dat
2003-06-20 22:26 . 2009-01-10 06:58 64591 —-a-r- c:program filesWMV9VCM.chm
2003-06-20 22:26 . 2009-01-10 06:58 12347 —-a-r- c:program filesWMV9VCM_readme.htm
2003-06-10 22:28 . 2009-01-10 06:58 666 —-a-r- c:program filesqPAL-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 661 —-a-r- c:program filesqNTSC-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesPAL-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesNTSC-vbr.wv9
2003-06-09 10:21 . 2009-01-10 06:58 21158 —-a-r- c:program fileslicense.txt
2003-04-07 12:06 . 2009-01-10 06:58 665 —-a-r- c:program filesFilm-320×240-vbr.wv9
2003-04-07 12:06 . 2009-01-10 06:58 659 —-a-r- c:program filesFilm-640×480-vbr.wv9
2003-04-07 12:06 . 2009-01-10 06:58 377 —-a-r- c:program filesFilm-1280×720-vbr.wv9
.


Sigcheck



[-] 2008-10-24 . 6A104BA98D99D53AB0C91825CE659FC6 . 361600 . . [5.1.2600.5625] . . c:windowssystem32driverstcpip.sys

[-] 2008-10-24 . 13548C87ADEFC5980AC4F0F50AC78396 . 80584 . . [7.2.6001.784] . . c:windowssystem32wuauclt.exe

[-] 2008-10-24 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:windowssystem32user32.dll

[-] 2008-10-24 . 8054F449106C9DA48AEDC82B05BA2B8E . 952832 . . [7.00.6000.20900] . . c:windowssystem32wininet.dll

[-] 2008-10-24 . 89F87645A856F6712E6225079B7931F4 . 1721344 . . [6.00.2900.5512] . . c:windowsexplorer.exe

[-] 2008-10-24 . E52BB415E3A7106E0308A6EE75219F30 . 1571840 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll

[-] 2008-10-24 . 08DD489E663B992B188166951AD131E0 . 30208 . . [5.1.2600.5512] . . c:windowssystem32ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
«Download Master»=»c:program filesDownload Masterdmaster.exe» [2009-02-06 3769856]
«Skype»=»c:program filesSkypePhoneSkype.exe» [2009-10-09 25623336]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
«NvCplDaemon»=»c:windowssystem32NvCpl.dll» [2006-08-11 7630848]
«RemoteControl8″=»c:program filesCyberLinkPowerDVD8PDVD8Serv.exe» [2008-03-20 83240]
«PDVD8LanguageShortcut»=»c:program filesCyberLinkPowerDVD8LanguageLanguage.exe» [2007-12-14 50472]
«BDRegion»=»c:program filesCyberlinkShared Filesbrs.exe» [2008-05-19 91432]
«egui»=»c:program filesESETESET NOD32 Antivirusegui.exe» [2008-08-18 1447168]
«HP Software Update»=»c:program filesHPHP Software UpdateHPWuSchd2.exe» [2007-10-14 49152]
«QuickTime Task»=»c:program filesQuickTimeqttask.exe» [2007-10-19 286720]
«iTunesHelper»=»c:program filesiTunesiTunesHelper.exe» [2007-11-02 267048]
«hpqSRMon»=»c:program filesHPDigital ImagingbinhpqSRMon.exe» [2008-08-20 150016]
«SoundMan»=»SOUNDMAN.EXE» — c:windowsSOUNDMAN.EXE [2007-04-16 577536]
«nwiz»=»nwiz.exe» — c:windowssystem32nwiz.exe [2006-08-11 1519616]
«NvMediaCenter»=»NvMCTray.dll» — c:windowssystem32nvmctray.dll [2006-08-11 86016]

[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=»c:windowssystem32CTFMON.EXE» [2008-10-24 30208]

[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
«IE7_011″=»shell32» [X]
«ZZZZ2_FirstLogonSetting»=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]
«IE7_012″=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]

c:documents and settingsAll Usersѓ« ў­®Ґ ¬Ґ­оЏа®Ја ¬¬лЂўв®§ Јаг§Є 
BlueSoleil.lnk — c:program filesIVT CorporationBlueSoleilgprs.exe [2007-12-27 43608]
HP Digital Imaging Monitor.lnk — c:program filesHPDigital Imagingbinhpqtra08.exe [2007-10-14 214360]
‘«®ў ам TransLite.lnk — c:program filesTransLitetranslite.exe [2009-1-22 761856]
“᪮७­л© § ЇгбЄ Adobe Reader.lnk — c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2004-12-14 29696]

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)

[HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)

[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
«FirewallOverride»=dword:00000001
«UpdatesOverride»=dword:00000001
«AntiVirusOverride»=dword:00000001

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
«EnableFirewall»= 0 (0x0)

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
«%windir%\Network Diagnostic\xpnetdiag.exe»=
«%windir%\system32\sessmgr.exe»=

R1 epfwtdir;epfwtdir;c:windowssystem32driversepfwtdir.sys [01.07.2008 8:04 34312]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:program filesCyberLinkPowerDVD800.fcl [15.05.2008 11:07 61424]
R2 ekrn;Eset Service;c:program filesESETESET NOD32 Antivirusekrn.exe [18.08.2008 12:25 468224]
R2 SandraAgentSrv;SiSoftware Deployment Agent Service;c:program filesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe [30.11.2008 16:58 98488]
R2 Start BT in service;Start BT in service;c:program filesIVT CorporationBlueSoleilStartSkysolSvc.exe [27.12.2007 14:39 51816]
S3 cel90xbe;cel90xbe;??d:tmpcel90xbe.sys —> d:tmpcel90xbe.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* — MBR
*NewlyCreated* — PROCEXP113
*NewlyCreated* — SRSERVICE
*Deregistered* — mbr
*Deregistered* — PROCEXP113

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the ‘Scheduled Tasks’ folder

2009-10-26 c:windowsTasksAppleSoftwareUpdate.job
— c:program filesApple Software UpdateSoftwareUpdate.exe [2007-08-29 12:57]
.
.


Supplementary Scan


.
uStart Page = hxxp://www.yandex.ru/
IE: &Экспорт в Microsoft Excel — c:progra~1MICROS~1OFFICE11EXCEL.EXE/3000
IE: Закачать ВСЕ при помощи Download Master — c:program filesDownload Masterdmieall.htm
IE: Закачать при помощи Download Master — c:program filesDownload Masterdmie.htm
IE: {{8DAE90AD-4583-4977-9DD4-4360F7A45C74} — c:program filesDownload Masterdmaster.exe
FF — ProfilePath — c:documents and settingsAdminApplication DataMozillaFirefoxProfilesaxxzg6s7.default
FF — prefs.js: network.proxy.type — 2
FF — plugin: c:program filesOperaprogrampluginsnpdm.dll

—- FIREFOX POLICIES —-
FF — user.js: capability.policy.policynames — localfilelinks
FF — user.js: capability.policy.localfilelinks.sites — hxxp://speed.travian.ae http://speed2.travian.ae http://s1.travian.ae http://s2.travian.ae http://s3.travian.ae http://s4.travian.ae http://s5.travian.ae http://s6.travian.ae http://s7.travian.ae http://s8.travian.ae http://s9.travian.ae http://s10.travian.ae http://s11.travian.ae http://s12.travian.ae http://s13.travian.ae http://s14.travian.ae http://s15.travian.ae http://s16.travian.ae http://s17.travian.ae http://s18.travian.ae http://s19.travian.ae http://s20.travian.ae http://s21.travian.ae http://s22.travian.ae http://s23.travian.ae http://s24.travian.ae http://s25.travian.ae http://s26.travian.ae http://s27.travian.ae http://s28.travian.ae http://s29.travian.ae http://s30.travian.ae http://s31.travian.ae http://s32.travian.ae http://s33.travian.ae http://s34.travian.ae http://s35.travian.ae http://speed.travian.asia http://speed2.travian.asia http://s1.travian.asia http://s2.travian.asia http://s3.travian.asia http://s4.travian.asia http://s5.travian.asia http://s6.travian.asia http://s7.travian.asia http://s8.travian.asia http://s9.travian.asia http://s10.travian.asia http://speed.travian.ba http://speed2.travian.ba http://s1.travian.ba http://s2.travian.ba http://s3.travian.ba http://s4.travian.ba http://s5.travian.ba http://s6.travian.ba http://s7.travian.ba http://s8.travian.ba http://s9.travian.ba http://s10.travian.ba http://speed.travian.bg http://speed2.travian.bg http://s1.travian.bg http://s2.travian.bg http://s3.travian.bg http://s4.travian.bg http://s5.travian.bg http://s6.travian.bg http://s7.travian.bg http://s8.travian.bg http://s9.travian.bg http://s10.travian.bg http://speed.travian.cl http://speed2.travian.cl http://s1.travian.cl http://s2.travian.cl http://s3.travian.cl http://s4.travian.cl http://s5.travian.cl http://s6.travian.cl http://s7.travian.cl http://s8.travian.cl http://s9.travian.cl http://s10.travian.cl http://speed.travian.cn http://speed2.travian.cn http://s1.travian.cn http://s2.travian.cn http://s3.travian.cn http://s4.travian.cn http://s5.travian.cn http://s6.travian.cn http://s7.travian.cn http://s8.travian.cn http://s9.travian.cn http://s10.travian.cn http://s11.travian.cn http://s12.travian.cn http://s13.travian.cn http://s14.travian.cn http://s15.travian.cn http://s16.travian.cn http://s17.travian.cn http://s18.travian.cn http://s19.travian.cn http://s20.travian.cn http://speed.travian.co.ee http://speed2.travian.co.ee http://s1.travian.co.ee http://s2.travian.co.ee http://s3.travian.co.ee http://s4.travian.co.ee http://s5.travian.co.ee http://s6.travian.co.ee http://s7.travian.co.ee http://s8.travian.co.ee http://s9.travian.co.ee http://s10.travian.co.ee http://s11.travian.co.ee http://s12.travian.co.ee http://s13.travian.co.ee http://s14.travian.co.ee http://s15.travian.co.ee http://s16.travian.co.ee http://s17.travian.co.ee http://s18.travian.co.ee http://s19.travian.co.ee http://s20.travian.co.ee http://speed.travian.co.id http://speed2.travian.co.id http://s1.travian.co.id http://s2.travian.co.id http://s3.travian.co.id http://s4.travian.co.id http://s5.travian.co.id http://s6.travian.co.id http://s7.travian.co.id http://s8.travian.co.id http://s9.travian.co.id http://s10.travian.co.id http://speed.travian.co.il http://speed2.travian.co.il http://s1.travian.co.il http://s2.travian.co.il http://s3.travian.co.il http://s4.travian.co.il http://s5.travian.co.il http://s6.travian.co.il http://s7.travian.co.il http://s8.travian.co.il http://s9.travian.co.il http://s10.travian.co.il http://speed.travian.co.kr http://speed2.travian.co.kr http://s1.travian.co.kr http://s2.travian.co.kr http://s3.travian.co.kr http://s4.travian.co.kr http://s5.travian.co.kr http://s6.travian.co.kr http://s7.travian.co.kr http://s8.travian.co.kr http://s9.travian.co.kr http://s10.travian.co.kr http://speed.travian.co.nz http://speed2.travian.co.nz http://s1.travian.co.nz http://s2.travian.co.nz http://s3.travian.co.nz http://s4.travian.co.nz http://s5.travian.co.nz http://s6.travian.co.nz http://s7.travian.co.nz http://s8.travian.co.nz http://s9.travian.co.nz http://s10.travian.co.nz http://speed.travian.co.uk http://speed2.travian.co.uk http://s1.travian.co.uk http://s2.travian.co.uk http://s3.travian.co.uk http://s4.travian.co.uk http://s5.travian.co.uk http://s6.travian.co.uk http://s7.travian.co.uk http://s8.travian.co.uk http://s9.travian.co.uk http://s10.travian.co.uk http://speed.travian.co.za http://speed2.travian.co.za http://s1.travian.co.za http://s2.travian.co.za http://s3.travian.co.za http://s4.travian.co.za http://s5.travian.co.za http://s6.travian.co.za http://s7.travian.co.za http://s8.travian.co.za http://s9.travian.co.za http://s10.travian.co.za http://speed.travian.com http://speed2.travian.com http://s1.travian.com http://s2.travian.com http://s3.travian.com http://s4.travian.com http://s5.travian.com http://s6.travian.com http://s7.travian.com http://s8.travian.com http://s9.travian.com http://s10.travian.com http://s11.travian.com http://s12.travian.com http://s13.travian.com http://s14.travian.com http://s15.travian.com http://s16.travian.com http://s17.travian.com http://s18.travian.com http://s19.travian.com http://s20.travian.com http://speed.travian.com.ar http://speed2.travian.com.ar http://s1.travian.com.ar http://s2.travian.com.ar http://s3.travian.com.ar http://s4.travian.com.ar http://s5.travian.com.ar http://s6.travian.com.ar http://s7.travian.com.ar http://s8.travian.com.ar http://s9.travian.com.ar http://s10.travian.com.ar http://speed.travian.com.au http://speed2.travian.com.au http://s1.travian.com.au http://s2.travian.com.au http://s3.travian.com.au http://s4.travian.com.au http://s5.travian.com.au http://s6.travian.com.au http://s7.travian.com.au http://s8.travian.com.au http://s9.travian.com.au http://s10.travian.com.au http://speed.travian.com.br http://speed2.travian.com.br http://s1.travian.com.br http://s2.travian.com.br http://s3.travian.com.br http://s4.travian.com.br http://s5.travian.com.br http://s6.travian.com.br http://s7.travian.com.br http://s8.travian.com.br http://s9.travian.com.br http://s10.travian.com.br http://s11.travian.com.br http://s12.travian.com.br http://s13.travian.com.br http://s14.travian.com.br http://s15.travian.com.br http://s16.travian.com.br http://s17.travian.com.br http://s18.travian.com.br http://s19.travian.com.br http://s20.travian.com.br http://speed.travian.com.hr http://speed2.travian.com.hr http://s1.travian.com.hr http://s2.travian.com.hr http://s3.travian.com.hr http://s4.travian.com.hr http://s5.travian.com.hr http://s6.travian.com.hr http://s7.travian.com.hr http://s8.travian.com.hr http://s9.travian.com.hr http://s10.travian.com.hr http://speed.travian.com.mx http://speed2.travian.com.mx http://s1.travian.com.mx http://s2.travian.com.mx http://s3.travian.com.mx http://s4.travian.com.mx http://s5.travian.com.mx http://s6.travian.com.mx http://s7.travian.com.mx http://s8.travian.com.mx http://s9.travian.com.mx http://s10.travian.com.mx http://speed.travian.com.my http://speed2.travian.com.my http://s1.travian.com.my http://s2.travian.com.my http://s3.travian.com.my http://s4.travian.com.my http://s5.travian.com.my http://s6.travian.com.my http://s7.travian.com.my http://s8.travian.com.my http://s9.travian.com.my http://s10.travian.com.my http://speed.travian.com.tr http://speed2.travian.com.tr http://s1.travian.com.tr http://s2.travian.com.tr http://s3.travian.com.tr http://s4.travian.com.tr http://s5.travian.com.tr http://s6.travian.com.tr http://s7.travian.com.tr http://s8.travian.com.tr http://s9.travian.com.tr http://s10.travian.com.tr http://s11.travian.com.tr http://s12.travian.com.tr http://s13.travian.com.tr http://s14.travian.com.tr http://s15.travian.com.tr http://s16.travian.com.tr http://s17.travian.com.tr http://s18.travian.com.tr http://s19.travian.com.tr http://s20.travian.com.tr http://s21.travian.com.tr http://s22.travian.com.tr http://s23.travian.com.tr http://s24.travian.com.tr http://s25.travian.com.tr http://s26.travian.com.tr http://s27.travian.com.tr http://s28.travian.com.tr http://s29.travian.com.tr http://s30.travian.com.tr http://speed.travian.com.ua http://speed2.travian.com.ua http://s1.travian.com.ua http://s2.travian.com.ua http://s3.travian.com.ua http://s4.travian.com.ua http://s5.travian.com.ua http://s6.travian.com.ua http://s7.travian.com.ua http://s8.travian.com.ua http://s9.travian.com.ua http://s10.travian.com.ua http://speed.travian.com.vn http://speed2.travian.com.vn http://s1.travian.com.vn http://s2.travian.com.vn http://s3.travian.com.vn http://s4.travian.com.vn http://s5.travian.com.vn http://s6.travian.com.vn http://s7.travian.com.vn http://s8.travian.com.vn http://s9.travian.com.vn http://s10.travian.com.vn http://speed.travian.cz http://speed2.travian.cz http://s1.travian.cz http://s2.travian.cz http://s3.travian.cz http://s4.travian.cz http://s5.travian.cz http://s6.travian.cz http://s7.travian.cz http://s8.travian.cz http://s9.travian.cz http://s10.travian.cz http://s11.travian.cz http://s12.travian.cz http://s13.travian.cz http://s14.travian.cz http://s15.travian.cz http://s16.travian.cz http://s17.travian.cz http://s18.travian.cz http://s19.travian.cz http://s20.travian.cz http://speed.travian.dk http://speed2.travian.dk http://s1.travian.dk http://s2.travian.dk http://s3.travian.dk http://s4.travian.dk http://s5.travian.dk http://s6.travian.dk http://s7.travian.dk http://s8.travian.dk http://s9.travian.dk http://s10.travian.dk http://speed.travian.fi http://speed2.travian.fi http://s1.travian.fi http://s2.travian.fi http://s3.travian.fi http://s4.travian.fi http://s5.travian.fi http://s6.travian.fi http://s7.travian.fi http://s8.travian.fi http://s9.travian.fi http://s10.travian.fi http://speed.travian.fr http://speed2.travian.fr http://s1.travian.fr http://s2.travian.fr http://s3.travian.fr http://s4.travian.fr http://s5.travian.fr http://s6.travian.fr http://s7.travian.fr http://s8.travian.fr http://s9.travian.fr http://s10.travian.fr http://s11.travian.fr http://s12.travian.fr http://s13.travian.fr http://s14.travian.fr http://s15.travian.fr http://s16.travian.fr http://s17.travian.fr http://s18.travian.fr http://s19.travian.fr http://s20.travian.fr http://speed.travian.gr http://speed2.travian.gr http://s1.travian.gr http://s2.travian.gr http://s3.travian.gr http://s4.travian.gr http://s5.travian.gr http://s6.travian.gr http://s7.travian.gr http://s8.travian.gr http://s9.travian.gr http://s10.travian.gr http://speed.travian.hk http://speed2.travian.hk http://s1.travian.hk http://s2.travian.hk http://s3.travian.hk http://s4.travian.hk http://s5.travian.hk http://s6.travian.hk http://s7.travian.hk http://s8.travian.hk http://s9.travian.hk http://s10.travian.hk http://speed.travian.hu http://speed2.travian.hu http://s1.travian.hu http://s2.travian.hu http://s3.travian.hu http://s4.travian.hu http://s5.travian.hu http://s6.travian.hu http://s7.travian.hu http://s8.travian.hu http://s9.travian.hu http://s10.travian.hu http://speed.travian.in http://speed2.travian.in http://s1.travian.in http://s2.travian.in http://s3.travian.in http://s4.travian.in http://s5.travian.in http://s6.travian.in http://s7.travian.in http://s8.travian.in http://s9.travian.in http://s10.travian.in http://speed.travian.ir http://speed2.travian.ir http://s1.travian.ir http://s2.travian.ir http://s3.travian.ir http://s4.travian.ir http://s5.travian.ir http://s6.travian.ir http://s7.travian.ir http://s8.travian.ir http://s9.travian.ir http://s10.travian.ir http://speed.travian.it http://speed2.travian.it http://s1.travian.it http://s2.travian.it http://s3.travian.it http://s4.travian.it http://s5.travian.it http://s6.travian.it http://s7.travian.it http://s8.travian.it http://s9.travian.it http://s10.travian.it http://s11.travian.it http://s12.travian.it http://s13.travian.it http://s14.travian.it http://s15.travian.it http://s16.travian.it http://s17.travian.it http://s18.travian.it http://s19.travian.it http://s20.travian.it http://speed.travian.jp http://speed2.travian.jp http://s1.travian.jp http://s2.travian.jp http://s3.travian.jp http://s4.travian.jp http://s5.travian.jp http://s6.travian.jp http://s7.travian.jp http://s8.travian.jp http://s9.travian.jp http://s10.travian.jp http://speed.travian.lt http://speed2.travian.lt http://s1.travian.lt http://s2.travian.lt http://s3.travian.lt http://s4.travian.lt http://s5.travian.lt http://s6.travian.lt http://s7.travian.lt http://s8.travian.lt http://s9.travian.lt http://s10.travian.lt http://speed.travian.lv http://speed2.travian.lv http://s1.travian.lv http://s2.travian.lv http://s3.travian.lv http://s4.travian.lv http://s5.travian.lv http://s6.travian.lv http://s7.travian.lv http://s8.travian.lv http://s9.travian.lv http://s10.travian.lv http://speed.travian.net http://speed2.travian.net http://s1.travian.net http://s2.travian.net http://s3.travian.net http://s4.travian.net http://s5.travian.net http://s6.travian.net http://s7.travian.net http://s8.travian.net http://s9.travian.net http://s10.travian.net http://speed.travian.nl http://speed2.travian.nl http://s1.travian.nl http://s2.travian.nl http://s3.travian.nl http://s4.travian.nl http://s5.travian.nl http://s6.travian.nl http://s7.travian.nl http://s8.travian.nl http://s9.travian.nl http://s10.travian.nl http://speed.travian.no http://speed2.travian.no http://s1.travian.no http://s2.travian.no http://s3.travian.no http://s4.travian.no http://s5.travian.no http://s6.travian.no http://s7.travian.no http://s8.travian.no http://s9.travian.no http://s10.travian.no http://speed.travian.ph http://speed2.travian.ph http://s1.travian.ph http://s2.travian.ph http://s3.travian.ph http://s4.travian.ph http://s5.travian.ph http://s6.travian.ph http://s7.travian.ph http://s8.travian.ph http://s9.travian.ph http://s10.travian.ph http://speed.travian.pk http://speed2.travian.pk http://s1.travian.pk http://s2.travian.pk http://s3.travian.pk http://s4.travian.pk http://s5.travian.pk http://s6.travian.pk http://s7.travian.pk http://s8.travian.pk http://s9.travian.pk http://s10.travian.pk http://speed.travian.pl http://speed2.travian.pl http://s1.travian.pl http://s2.travian.pl http://s3.travian.pl http://s4.travian.pl http://s5.travian.pl http://s6.travian.pl http://s7.travian.pl http://s8.travian.pl http://s9.travian.pl http://s10.travian.pl http://s11.travian.pl http://s12.travian.pl http://s13.travian.pl http://s14.travian.pl http://s15.travian.pl http://s16.travian.pl http://s17.travian.pl http://s18.travian.pl http://s19.travian.pl http://s20.travian.pl http://speed.travian.pt http://speed2.travian.pt http://s1.travian.pt http://s2.travian.pt http://s3.travian.pt http://s4.travian.pt http://s5.travian.pt http://s6.travian.pt http://s7.travian.pt http://s8.travian.pt http://s9.travian.pt http://s10.travian.pt http://s11.travian.pt http://s12.travian.pt http://s13.travian.pt http://s14.travian.pt http://s15.travian.pt http://s16.travian.pt http://s17.travian.pt http://s18.travian.pt http://s19.travian.pt http://s20.travian.pt http://speed.travian.ro http://speed2.travian.ro http://s1.travian.ro http://s2.travian.ro http://s3.travian.ro http://s4.travian.ro http://s5.travian.ro http://s6.travian.ro http://s7.travian.ro http://s8.travian.ro http://s9.travian.ro http://s10.travian.ro http://speed.travian.rs http://speed2.travian.rs http://s1.travian.rs http://s2.travian.rs http://s3.travian.rs http://s4.travian.rs http://s5.travian.rs http://s6.travian.rs http://s7.travian.rs http://s8.travian.rs http://s9.travian.rs http://s10.travian.rs http://speed.travian.ru http://speed2.travian.ru http://s1.travian.ru http://s2.travian.ru http://s3.travian.ru http://s4.travian.ru http://s5.travian.ru http://s6.travian.ru http://s7.travian.ru http://s8.travian.ru http://s9.travian.ru http://s10.travian.ru http://s11.travian.ru http://s12.travian.ru http://s13.travian.ru http://s14.travian.ru http://s15.travian.ru http://s16.travian.ru http://s17.travian.ru http://s18.travian.ru http://s19.travian.ru http://s20.travian.ru http://speed.travian.se http://speed2.travian.se http://s1.travian.se http://s2.travian.se http://s3.travian.se http://s4.travian.se http://s5.travian.se http://s6.travian.se http://s7.travian.se http://s8.travian.se http://s9.travian.se http://s10.travian.se http://speed.travian.si http://speed2.travian.si http://s1.travian.si http://s2.travian.si http://s3.travian.si http://s4.travian.si http://s5.travian.si http://s6.travian.si http://s7.travian.si http://s8.travian.si http://s9.travian.si http://s10.travian.si http://speed.travian.sk http://speed2.travian.sk http://s1.travian.sk http://s2.travian.sk http://s3.travian.sk http://s4.travian.sk http://s5.travian.sk http://s6.travian.sk http://s7.travian.sk http://s8.travian.sk http://s9.travian.sk http://s10.travian.sk http://speed.travian.us http://speed2.travian.us http://s1.travian.us http://s2.travian.us http://s3.travian.us http://s4.travian.us http://s5.travian.us http://s6.travian.us http://s7.travian.us http://s8.travian.us http://s9.travian.us http://s10.travian.us http://s11.travian.us http://s12.travian.us http://s13.travian.us http://s14.travian.us http://s15.travian.us http://s16.travian.us http://s17.travian.us http://s18.travian.us http://s19.travian.us http://s20.travian.us http://www.travian.at http://speed.travian.at http://speed2.travian.at http://www.travian.de http://speed.travian.de http://speed2.travian.de http://welt1.travian.de http://welt2.travian.de http://welt3.travian.de http://welt4.travian.de http://welt5.travian.de http://welt6.travian.de http://welt7.travian.de http://welt8.travian.de http://welt9.travian.de http://welt10.travian.de http://www.travian.org http://speed.travian.org http://speed2.travian.org
FF — user.js: capability.policy.localfilelinks.checkloaduri.enabled — allAccessc:program filesMozilla Firefoxgreprefssecurity-prefs.js — pref(«security.ssl3.rsa_seed_sha», true);
.
— — — — ORPHANS REMOVED — — — —

HKLM-Run-WinampAgent — c:program filesWinampwinampa.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) — c:program filesMalwarebytes’ Anti-Malwarembam.exe
AddRemove-SimCity 4 Rush Hour — e:_dcdf7~1GamesA417~1SIMCIT~1UNWISE.EXE
AddRemove-{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1 — d:tmpRar$EX01.547NOD32-PATCHObsoleteunins000.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista — rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-04 09:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sprs.sys >>UNKNOWN [0x82391938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

atapi.sys @ 0x0 0x0 bytes

Driveratapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_POWER ] 0xA73C != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF8369B40 atapi.sys
Driveratapi IRP hooks detected !

**************************************************************************

[HKEY_LOCAL_MACHINESystemControlSet001Services{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
«ImagePath»=»??c:program filesCyberLinkPowerDVD800.fcl»
.


DLLs Loaded Under Running Processes



— — — — — — — > ‘winlogon.exe'(732)
c:windowssystem32SETUPAPI.dll
c:windowssystem32cscui.dll

— — — — — — — > ‘lsass.exe'(788)
c:windowssystem32SETUPAPI.dll
.
Completion time: 2009-11-04 9:41
ComboFix-quarantined-files.txt 2009-11-04 07:41

Pre-Run: 4 126 130 176 байт свободно
Post-Run: 4 105 576 448 байт свободно

Добро пожаловать

На нашем сайте размещены инструкции и программы, которые помогут вам абсолютно бесплатно и самостоятельно удалить навязчивую рекламу, вирусы и трояны.

Поиск

Важные инструкции

Как запустить компьютер в безопасном режиме (Safe Mode)
Убрать рекламу в браузере (Chrome, Firefox, Opera, Yandex)
Сброс настроек Firefox
Как сбросить настройки Firefox (Инструкция)
Какой лучший антивирус ? Как выбрать антивирус ?
Установлено в соответствии с корпоративным правилом (Удалить из Хрома)

СПАЙВАРЕ РУ

  • О Спайваре Ру
  • Контакты
  • Реклама на сайте
  • Политика конфиденциальности
  • Правила использования

Нужна помощь?

Задайте свой вопрос прямо сейчас кликнув по следующей ссылке Задать вопрос.

Или обратитесь на наш форум, где команда Spyware-ru поможет вам. Узнайте, как попросить о помощи здесь.

Ссылки

  • Инструкции
  • Скачать программы
  • Помощь в удалении вирусов
  • Как вылечить компьютер
Copyright © 2008 - 2024 Spyware-RU.com (en)