Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › СПАМ со страницы ВКонтакте › Re: Re: СПАМ со страницы ВКонтакте
info.txt logfile of random’s system information tool 1.06 2009-06-08 15:42:07
======Uninstall list======
—>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:WINDOWSINFPCHealth.inf
ABBYY Lingvo 12 English Edition—>MsiExec.exe /I{A1200000-0001-0000-0000-074957833700}
Adobe Acrobat 8.1.5 Professional—>msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Anchor Service CS3—>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3—>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3—>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting—>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0—>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps—>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color — Photoshop Specific—>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings—>C:Program FilesCommon FilesAdobeInstallers6c8e2cb4fd241c55406016127a6ab2eSetup.exe
Adobe Color Common Settings—>MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Recommended Settings—>MsiExec.exe /I{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}
Adobe Color JA Extra Settings—>MsiExec.exe /I{D92B72E2-C854-4738-8ED6-4C3661CC17AE}
Adobe Color NA Extra Settings—>MsiExec.exe /I{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}
Adobe Default Language CS3—>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3—>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2—>C:Program FilesCommon FilesAdobeInstallers3e054d2218e7aa282c2369d939e58ffSetup.exe
Adobe ExtendScript Toolkit 2—>MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Flash Player 10 ActiveX—>C:WINDOWSsystem32MacromedFlashuninstall_activeX.exe
Adobe Fonts All—>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3—>MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3—>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files—>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3—>C:Program FilesCommon FilesAdobeInstallers8c1493d5f7a42ca50dc0bfa020c595aSetup.exe
Adobe Photoshop CS3—>MsiExec.exe /I{D7C6EE24-3B88-472B-A26A-2B15565D7B3B}
Adobe Setup—>MsiExec.exe /I{3AF8C5EB-70CD-4E3E-9ED4-48B24D40AD7A}
Adobe Setup—>MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup—>MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Stock Photos CS3—>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support—>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3—>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client—>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin—>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3—>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Apple Software Update—>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Avant Browser (remove only)—>»C:Program FilesAvant Browseruninst.exe»
DAEMON Tools—>MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
High Definition Audio Driver Package — KB888111—>»C:WINDOWS$NtUninstallKB888111WXPSP2$spuninstspuninst.exe»
HijackThis 2.0.2—>»C:Program Filestrend microHijackThis.exe» /uninstall
Intel(R) Graphics Media Accelerator Driver—>RUNDLL32.EXE C:WINDOWSsystem32ialmrem.dll,UninstallW2KIGfx2ID PCIVEN_8086&DEV_2776 PCIVEN_8086&DEV_2772
jv16 PowerTools 2007—>»C:Program Filesjv16 PowerTools 2007unins000.exe»
Mail.Ru Агент 5.4 (сборка 2647, для всех пользователей)—>C:Program FilesMail.RuAgentmagentsetup.exe -uninstalllm
Maple 11—>»C:Program FilesMaple 11Uninstall_Maple 11Uninstall Maple 11.exe»
McAfee VirusScan Enterprise—>MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
Microsoft Office — профессиональный выпуск версии 2003—>MsiExec.exe /I{90110419-6000-11D3-8CFE-0150048383C9}
OriginPro 8—>C:Program FilesInstallShield Installation Information{A912021A-FEDD-4DA3-8DB4-245EBDA84778}setup.exe -runfromtemp -l0x0009 -removeonly
PDF Settings—>MsiExec.exe /I{293D5729-7C01-4FA4-A4DE-BB6A1587BBB9}
QIP Infium 2.0.9020 RC3—>»C:Program FilesQIP Infiumunins000.exe»
QuickTime—>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
REALTEK GbE & FE Ethernet PCI-E NIC Driver—>C:Program FilesInstallShield Installation Information{C9BED750-1211-4480-B1A5-718A3BE15525}SETUP.EXE -runfromtemp -l0x0019 -removeonly
Realtek High Definition Audio Driver—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime1150Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}SETUP.EXE» -l0x19 -removeonly
SweetIM for Messenger 2.6—>MsiExec.exe /X{21D74CEE-EEFC-4D72-9691-2F2BE1DF9FB2}
SweetIM Toolbar for Internet Explorer 3.3—>MsiExec.exe /X{266C7330-C0F4-49E5-8F20-A56F9F822875}
WebMoney Advisor—>regsvr32 /u /s «C:Program FilesWebMoney Advisorwmadvisor.dll»
WebMoney Agent—>C:Program FilesWebMoney Agentuninst_wmagent.exe
WebMoney Keeper Classic 3.7.0.1—>»C:Program FilesWebMoneyUninstall.exe» «C:Program FilesWebMoneyinstall.log» -u
Windows XP Service Pack 3—>»C:WINDOWS$NtServicePackUninstall$spuninstspuninst.exe»
WinRAR archiver—>C:Program FilesWinRARuninstall.exe
Данные ДубльГИС г.Екатеринбург 01.03.2009—>MsiExec.exe /X{903F8DAC-631A-4EA1-B7AC-D0D0BD1B4979}
ДубльГИС 3.0.4.2—>MsiExec.exe /X{EBF56A8E-3483-4704-98B8-7685891F8EA7}
======Security center information======
AV: McAfee VirusScan Enterprise
======System event log======
Computer Name: ANALIT309-3
Event Code: 7036
Message: Служба «Рабочая станция» перешла в состояние Работает.
Record Number: 5221
Source Name: Service Control Manager
Time Written: 20090411125235.000000+360
Event Type: информация
User:
Computer Name: ANALIT309-3
Event Code: 7035
Message: Служба «Рабочая станция» успешно отправила управляющий элемент «запустить».
Record Number: 5220
Source Name: Service Control Manager
Time Written: 20090411125235.000000+360
Event Type: информация
User: USUmorozova
Computer Name: ANALIT309-3
Event Code: 7036
Message: Служба «Сервер» перешла в состояние Работает.
Record Number: 5219
Source Name: Service Control Manager
Time Written: 20090411125230.000000+360
Event Type: информация
User:
Computer Name: ANALIT309-3
Event Code: 7035
Message: Служба «Сервер» успешно отправила управляющий элемент «запустить».
Record Number: 5218
Source Name: Service Control Manager
Time Written: 20090411125230.000000+360
Event Type: информация
User: USUmorozova
Computer Name: ANALIT309-3
Event Code: 59
Message: Generate Activation Context завершилась не удачно для C:WINDOWSWinSxSx86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_39049d00MFC80U.DLL.
Соответствующее сообщение об ошибке: Операция успешно завершена.
.
Record Number: 5217
Source Name: SideBySide
Time Written: 20090411125156.000000+360
Event Type: ошибка
User:
=====Application event log=====
Computer Name: ANALIT309-3
Event Code: 257
Message: The Scan was unable to scan password protected file C:Documents and SettingsmorozovaLocal SettingsTemporary Internet FilesContent.IE54P23KPEByandsearch[1]yandsearch[1]. Scan engine version used is 5301.4018 DAT version 5632.0000.
Record Number: 5585
Source Name: McLogEvent
Time Written: 20090601145127.000000+360
Event Type: информация
User: NT AUTHORITYSYSTEM
Computer Name: ANALIT309-3
Event Code: 257
Message: The Scan was unable to scan password protected file C:Documents and SettingsmorozovaLocal SettingsTemporary Internet FilesContent.IE5NEWVJLKHyandsearch[1]yandsearch[1]. Scan engine version used is 5301.4018 DAT version 5632.0000.
Record Number: 5584
Source Name: McLogEvent
Time Written: 20090601145121.000000+360
Event Type: информация
User: NT AUTHORITYSYSTEM
Computer Name: ANALIT309-3
Event Code: 257
Message: The Scan was unable to scan password protected file C:Documents and SettingsmorozovaLocal SettingsTemporary Internet FilesContent.IE564ZT7EMN27600[1].htm27600[1]. Scan engine version used is 5301.4018 DAT version 5632.0000.
Record Number: 5583
Source Name: McLogEvent
Time Written: 20090601144552.000000+360
Event Type: информация
User: NT AUTHORITYSYSTEM
Computer Name: ANALIT309-3
Event Code: 257
Message: The Scan was unable to scan password protected file C:Documents and SettingsmorozovaLocal SettingsTemporary Internet FilesContent.IE5JGGEHC3N3_19[1].htm3_19[1]. Scan engine version used is 5301.4018 DAT version 5632.0000.
Record Number: 5582
Source Name: McLogEvent
Time Written: 20090601144425.000000+360
Event Type: информация
User: NT AUTHORITYSYSTEM
Computer Name: ANALIT309-3
Event Code: 257
Message: The Scan was unable to scan password protected file C:Documents and SettingsmorozovaLocal SettingsTemporary Internet FilesContent.IE5UPHG4O3J2626618[1]2626618[1]. Scan engine version used is 5301.4018 DAT version 5632.0000.
Record Number: 5581
Source Name: McLogEvent
Time Written: 20090601143652.000000+360
Event Type: информация
User: NT AUTHORITYSYSTEM
======Environment variables======
«ComSpec»=%SystemRoot%system32cmd.exe
«Path»=C:watcom-1.3binnt;C:watcom-1.3binw;%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem;C:Program FilesQuickTimeQTSystem
«windir»=%SystemRoot%
«FP_NO_HOST_CHECK»=NO
«OS»=Windows_NT
«PROCESSOR_ARCHITECTURE»=x86
«PROCESSOR_LEVEL»=6
«PROCESSOR_IDENTIFIER»=x86 Family 6 Model 15 Stepping 13, GenuineIntel
«PROCESSOR_REVISION»=0f0d
«NUMBER_OF_PROCESSORS»=2
«PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
«TEMP»=%SystemRoot%TEMP
«TMP»=%SystemRoot%TEMP
«KMP_DUPLICATE_LIB_OK»=TRUE
«WATCOM»=C:watcom-1.3
«CLASSPATH»=.;C:Program FilesQuickTimeQTSystemQTJava.zip
«QTJAVA»=C:Program FilesQuickTimeQTSystemQTJava.zip
«VSEDEFLOGDIR»=C:Documents and SettingsAll UsersApplication DataMcAfeeDesktopProtection
«DEFLOGDIR»=C:Documents and SettingsAll UsersApplication DataMcAfeeDesktopProtection
EOF

