Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Не запускаеются антивирус, браузеры
- This topic has 2 ответа, 2 участника, and was last updated 14 years, 9 months назад by
Аноним.
-
АвторСообщения
-
9 ноября, 2010 в 1:00 пп #18816
Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Пожалуйста, подскажите, что делать: не могу установить антивирус и браузеры.
Logfile of random’s system information tool 1.08 (written by random/random)
Run by oksana at 2010-11-09 15:13:07
Microsoft Windows 7 Максимальная
System drive C: has 21 GB (64%) free of 33 GB
Total RAM: 1014 MB (49% free)Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:13:20, on 09.11.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: NormalRunning processes:
C:Windowssystem32taskhost.exe
C:Windowssystem32taskeng.exe
C:Program FilesUniblueRegistryBoosterrbmonitor.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesAdobeReader 9.0Readerreader_sl.exe
C:Program FilesTrojan RemoverTrjscan.exe
C:Program FilesMail.RuGuardGuardMailRu.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesAnVir Startup ManagerAnVir.exe
D:Статьи1RSIT.exe
C:Program Filestrend microoksana.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/cnt/7819
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O2 — BHO: SuggestMeYesBHO — {0FB6A909-6086-458F-BD92-1F8EE10042A0} — C:Program FilesAutocompleteProAutocompletePro.dll
O2 — BHO: AcroIEHelperStub — {18DF081C-E8AD-4283-A596-FA578C2EBDC3} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O4 — HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 — HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 — HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 — HKLM..Run: [Adobe Reader Speed Launcher] «C:Program FilesAdobeReader 9.0ReaderReader_sl.exe»
O4 — HKLM..Run: [TrojanScanner] C:Program FilesTrojan RemoverTrjscan.exe /boot
O4 — HKLM..Run: [Guard.Mail.ru.gui] «C:Program FilesMail.RuGuardGuardMailRu.exe» /gui
O4 — HKCU..Run: [RegistryBooster] «C:Program FilesUniblueRegistryBoosterlauncher.exe» delay 20000
O4 — HKCU..Run: [AnVir Startup Manager] «C:Program FilesAnVir Startup ManagerAnVir.exe» Minimized
O4 — HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User ‘NETWORK SERVICE’)
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O23 — Service: Guard.Mail.ru — Unknown owner — C:Program FilesMail.RuGuardGuardMailRu.exe
O23 — Service: Служба Google Update (gupdate) (gupdate) — Google Inc. — C:Program FilesGoogleUpdateGoogleUpdate.exe—
End of file — 3903 bytes======Scheduled tasks folder======
C:WindowstasksGoogleUpdateTaskMachineCore.job
C:WindowstasksGoogleUpdateTaskMachineUA.job
C:WindowstasksRegistryBooster.job======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
AC-Pro — C:Program FilesAutocompleteProAutocompletePro.dll [2010-07-14 97760][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll [2008-06-11 75128][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2010-11-09 1229496][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{09900DE8-1DCA-443F-9243-26FF581438AF} — Спутник@Mail.Ru — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2010-11-09 1229496][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«IgfxTray»=C:Windowssystem32igfxtray.exe [2009-09-23 141848]
«HotKeysCmds»=C:Windowssystem32hkcmd.exe [2009-09-23 173592]
«Persistence»=C:Windowssystem32igfxpers.exe [2009-09-23 150552]
«Adobe Reader Speed Launcher»=C:Program FilesAdobeReader 9.0ReaderReader_sl.exe [2008-06-12 34672]
«TrojanScanner»=C:Program FilesTrojan RemoverTrjscan.exe [2010-10-12 1167808]
«Guard.Mail.ru.gui»=C:Program FilesMail.RuGuardGuardMailRu.exe [2010-11-09 991936][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«RegistryBooster»=C:Program FilesUniblueRegistryBoosterlauncher.exe [2010-11-02 67448]
«AnVir Startup Manager»=C:Program FilesAnVir Startup ManagerAnVir.exe [2010-10-12 2381080][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyigfxcui]
C:Windowssystem32igfxdev.dll [2009-09-23 218112][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WebCheck — {E6FB5E20-DE35-11CF-9C87-00AA005127ED}[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrolsecurityproviders]
«SecurityProviders»=credssp.dll[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkAFD]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«ConsentPromptBehaviorAdmin»=5
«ConsentPromptBehaviorUser»=3
«EnableUIADesktopToggle»=0
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
======File associations======
.js — edit — C:WindowsSystem32Notepad.exe %1
.js — open — C:WindowsSystem32WScript.exe «%1» %*======List of files/folders created in the last 1 months======
2010-11-09 14:18:59 —-D—- C:Program FilesGoogle
2010-11-09 14:17:40 —-D—- C:UsersoksanaAppDataRoamingChemTable Software
2010-11-09 14:17:19 —-D—- C:Program FilesReg Organizer
2010-11-09 14:17:13 —-D—- C:Program FilesMail.Ru
2010-11-09 14:17:08 —-D—- C:Program FilesAnVir Startup Manager
2010-11-09 14:16:32 —-D—- C:ProgramDataAlwil Software
2010-11-09 12:19:21 —-D—- C:UsersoksanaAppDataRoamingUniblue
2010-11-09 12:19:18 —-HDC—- C:ProgramData{7BC48736-44DE-4E73-A789-B700D1778AE5}
2010-11-09 12:19:15 —-D—- C:Program FilesUniblue
2010-11-09 11:53:43 —-D—- C:Program Filestrend micro
2010-11-09 11:53:41 —-D—- C:rsit
2010-10-29 00:29:36 —-A—- C:Windowssystem32driversDiskdump.sys
2010-10-27 21:07:44 —-A—- C:Windowssystem32msdri.dll
2010-10-27 21:07:43 —-A—- C:Windowssystem32CPFilters.dll
2010-10-22 11:28:18 —-A—- C:Windowsntbtlog.txt
2010-10-20 10:11:28 —-D—- C:WindowsMinidump
2010-10-13 01:03:31 —-A—- C:Windowssystem32ole32.dll
2010-10-13 01:03:16 —-A—- C:Windowssystem32iertutil.dll
2010-10-13 01:03:15 —-A—- C:Windowssystem32mshtml.dll
2010-10-13 01:03:14 —-A—- C:Windowssystem32ieframe.dll
2010-10-13 01:03:13 —-A—- C:Windowssystem32msfeeds.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32wininet.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32urlmon.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32mstime.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32licmgr10.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32iedkcs32.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32mshtmled.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32msfeedssync.exe
2010-10-13 01:03:11 —-A—- C:Windowssystem32msfeedsbs.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32jsproxy.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32ieui.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32iepeers.dll
2010-10-13 01:02:33 —-A—- C:Windowssystem32t2embed.dll
2010-10-13 01:02:29 —-A—- C:Windowssystem32schannel.dll
2010-10-13 01:02:27 —-A—- C:Windowssystem32comctl32.dll
2010-10-13 01:02:24 —-A—- C:Windowssystem32mfc40u.dll
2010-10-13 01:02:24 —-A—- C:Windowssystem32mfc40.dll
2010-10-13 01:01:13 —-A—- C:Windowssystem32wmp.dll
2010-10-13 01:01:11 —-A—- C:Windowssystem32wmploc.DLL
2010-10-13 01:00:48 —-A—- C:Windowssystem32win32k.sys
2010-10-13 01:00:44 —-A—- C:Windowssystem32srvsvc.dll
2010-10-13 01:00:44 —-A—- C:Windowssystem32driverssrv2.sys
2010-10-13 01:00:44 —-A—- C:Windowssystem32driverssrv.sys
2010-10-13 01:00:43 —-A—- C:Windowssystem32driverssrvnet.sys
2010-10-13 00:53:43 —-A—- C:Windowssystem32wmpmde.dll
2010-10-13 00:49:16 —-A—- C:Windowssystem32StructuredQuery.dll
2010-10-12 13:34:12 —-A—- C:Windowssystem32ztvunrar36.dll
2010-10-12 13:34:12 —-A—- C:Windowssystem32ztvunace26.dll
2010-10-12 13:34:12 —-A—- C:Windowssystem32ztvcabinet.dll
2010-10-12 13:34:11 —-A—- C:Windowssystem32UNRAR3.dll
2010-10-12 13:34:11 —-A—- C:Windowssystem32unacev2.dll
2010-10-12 13:34:07 —-D—- C:UsersoksanaAppDataRoamingSimply Super Software
2010-10-12 13:34:07 —-D—- C:ProgramDataSimply Super Software
2010-10-12 13:34:07 —-D—- C:Program FilesTrojan Remover======List of files/folders modified in the last 1 months======
2010-11-09 15:13:20 —-D—- C:WindowsPrefetch
2010-11-09 15:12:08 —-D—- C:WindowsTemp
2010-11-09 15:11:20 —-D—- C:Program FilesAlwil Software
2010-11-09 15:10:01 —-D—- C:UsersoksanaAppDataRoaminguTorrent
2010-11-09 15:09:39 —-D—- C:Windows
2010-11-09 15:09:21 —-SHD—- C:System Volume Information
2010-11-09 14:28:53 —-D—- C:Windowssystem32config
2010-11-09 14:19:17 —-SHD—- C:WindowsInstaller
2010-11-09 14:19:14 —-D—- C:WindowsTasks
2010-11-09 14:19:14 —-D—- C:Windowssystem32Tasks
2010-11-09 14:18:59 —-RD—- C:Program Files
2010-11-09 14:18:42 —-D—- C:Windowswinsxs
2010-11-09 14:17:56 —-D—- C:Program FilesCommon Filesmicrosoft shared
2010-11-09 14:17:08 —-D—- C:WindowsSystem32
2010-11-09 14:16:32 —-HD—- C:ProgramData
2010-11-09 10:52:32 —-D—- C:Windowsinf
2010-11-09 10:52:32 —-A—- C:Windowssystem32PerfStringBackup.INI
2010-11-09 00:43:06 —-D—- C:UsersoksanaAppDataRoamingEurekaLog
2010-11-01 13:58:15 —-D—- C:Windowsrescache
2010-10-29 02:00:53 —-D—- C:WindowsAppPatch
2010-10-29 02:00:38 —-D—- C:Windowssystem32drivers
2010-10-28 02:05:49 —-RSD—- C:Windowsassembly
2010-10-28 02:04:53 —-D—- C:WindowsMicrosoft.NET
2010-10-28 02:01:52 —-D—- C:Windowsehome
2010-10-27 17:58:43 —-D—- C:Windowssystem32catroot
2010-10-27 17:58:36 —-D—- C:Windowssystem32catroot2
2010-10-25 07:15:47 —-SD—- C:UsersoksanaAppDataRoamingMicrosoft
2010-10-19 10:41:44 —-N—- C:Windowssystem32MpSigStub.exe
2010-10-13 02:18:30 —-D—- C:Windowssystem32migration
2010-10-13 02:18:30 —-D—- C:Program FilesInternet Explorer
2010-10-13 02:18:29 —-D—- C:Program FilesWindows Media Player
2010-10-13 02:00:58 —-A—- C:Windowssystem32MRT.exe
2010-10-12 15:43:54 —-D—- C:Windowssystem32wdi======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:WindowsSystem32driversrdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%system32cscsvc.dll,-202; C:Windowssystem32driverscsc.sys [2009-07-14 387584]
R1 vwififlt;Virtual WiFi Filter Driver; C:Windowssystem32DRIVERSvwififlt.sys [2009-07-14 48128]
R3 AgereSoftModem;Agere Systems Soft Modem; C:Windowssystem32DRIVERSAGRSM.sys [2009-07-14 1035776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:Windowssystem32DRIVERSathr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet — NDIS 6.0; C:Windowssystem32DRIVERSb57nd60x.sys [2009-07-14 229888]
R3 igfx;igfx; C:Windowssystem32DRIVERSigdkmd32.sys [2009-09-23 4808192]
S2 Parvdm;Parvdm; C:Windowssystem32DRIVERSparvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:Windowssystem32DRIVERSdjsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:Windowssystem32DRIVERSamdagp.sys [2009-07-14 53312]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:Windowssystem32DRIVERSewusbmdm.sys [2009-06-22 102912]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:Windowssystem32DRIVERSewusbdev.sys [2009-06-22 100736]
S3 pciide;pciide; C:Windowssystem32DRIVERSpciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:WindowsSystem32driversrdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:Windowssystem32DRIVERSvms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:Windowssystem32DRIVERSsisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:Windowssystem32DRIVERSstorvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:Windowssystem32DRIVERSviaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:Windowssystem32DRIVERSviac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%system32vmbusres.dll,-1000; C:Windowssystem32DRIVERSvmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:Windowssystem32DRIVERSVMBusHID.sys [2009-07-14 17920]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%system32cscsvc.dll,-200; C:WindowsSystem32svchost.exe [2009-07-14 20992]
R2 Guard.Mail.ru;Guard.Mail.ru; C:Program FilesMail.RuGuardGuardMailRu.exe [2010-11-09 991936]
S2 gupdate;Служба Google Update (gupdate); C:Program FilesGoogleUpdateGoogleUpdate.exe [2010-11-09 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:Windowssystem32svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%system32peerdistsvc.dll,-9000; C:WindowsSystem32svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%system32umrdp.dll,-1000; C:WindowsSystem32svchost.exe [2009-07-14 20992]
EOF
Logfile of random’s system information tool 1.08 (written by random/random)
Run by oksana at 2010-11-09 15:14:17
Microsoft Windows 7 Максимальная
System drive C: has 21 GB (64%) free of 33 GB
Total RAM: 1014 MB (47% free)Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:14:18, on 09.11.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: NormalRunning processes:
C:Windowssystem32taskhost.exe
C:Windowssystem32taskeng.exe
C:Program FilesUniblueRegistryBoosterrbmonitor.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesAdobeReader 9.0Readerreader_sl.exe
C:Program FilesMail.RuGuardGuardMailRu.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesAnVir Startup ManagerAnVir.exe
C:Windowssystem32NOTEPAD.EXE
D:Статьи1RSIT.exe
C:Program Filestrend microoksana.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/cnt/7819
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O2 — BHO: SuggestMeYesBHO — {0FB6A909-6086-458F-BD92-1F8EE10042A0} — C:Program FilesAutocompleteProAutocompletePro.dll
O2 — BHO: AcroIEHelperStub — {18DF081C-E8AD-4283-A596-FA578C2EBDC3} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O4 — HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 — HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 — HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 — HKLM..Run: [Adobe Reader Speed Launcher] «C:Program FilesAdobeReader 9.0ReaderReader_sl.exe»
O4 — HKLM..Run: [TrojanScanner] C:Program FilesTrojan RemoverTrjscan.exe /boot
O4 — HKLM..Run: [Guard.Mail.ru.gui] «C:Program FilesMail.RuGuardGuardMailRu.exe» /gui
O4 — HKCU..Run: [RegistryBooster] «C:Program FilesUniblueRegistryBoosterlauncher.exe» delay 20000
O4 — HKCU..Run: [AnVir Startup Manager] «C:Program FilesAnVir Startup ManagerAnVir.exe» Minimized
O4 — HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User ‘NETWORK SERVICE’)
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O23 — Service: Guard.Mail.ru — Unknown owner — C:Program FilesMail.RuGuardGuardMailRu.exe
O23 — Service: Служба Google Update (gupdate) (gupdate) — Google Inc. — C:Program FilesGoogleUpdateGoogleUpdate.exe—
End of file — 3891 bytes======Scheduled tasks folder======
C:WindowstasksGoogleUpdateTaskMachineCore.job
C:WindowstasksGoogleUpdateTaskMachineUA.job
C:WindowstasksRegistryBooster.job======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
AC-Pro — C:Program FilesAutocompleteProAutocompletePro.dll [2010-07-14 97760][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll [2008-06-11 75128][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2010-11-09 1229496][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{09900DE8-1DCA-443F-9243-26FF581438AF} — Спутник@Mail.Ru — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2010-11-09 1229496][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«IgfxTray»=C:Windowssystem32igfxtray.exe [2009-09-23 141848]
«HotKeysCmds»=C:Windowssystem32hkcmd.exe [2009-09-23 173592]
«Persistence»=C:Windowssystem32igfxpers.exe [2009-09-23 150552]
«Adobe Reader Speed Launcher»=C:Program FilesAdobeReader 9.0ReaderReader_sl.exe [2008-06-12 34672]
«TrojanScanner»=C:Program FilesTrojan RemoverTrjscan.exe [2010-10-12 1167808]
«Guard.Mail.ru.gui»=C:Program FilesMail.RuGuardGuardMailRu.exe [2010-11-09 991936][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«RegistryBooster»=C:Program FilesUniblueRegistryBoosterlauncher.exe [2010-11-02 67448]
«AnVir Startup Manager»=C:Program FilesAnVir Startup ManagerAnVir.exe [2010-10-12 2381080][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyigfxcui]
C:Windowssystem32igfxdev.dll [2009-09-23 218112][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WebCheck — {E6FB5E20-DE35-11CF-9C87-00AA005127ED}[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrolsecurityproviders]
«SecurityProviders»=credssp.dll[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkAFD]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«ConsentPromptBehaviorAdmin»=5
«ConsentPromptBehaviorUser»=3
«EnableUIADesktopToggle»=0
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
======File associations======
.js — edit — C:WindowsSystem32Notepad.exe %1
.js — open — C:WindowsSystem32WScript.exe «%1» %*======List of files/folders created in the last 1 months======
2010-11-09 14:18:59 —-D—- C:Program FilesGoogle
2010-11-09 14:17:40 —-D—- C:UsersoksanaAppDataRoamingChemTable Software
2010-11-09 14:17:19 —-D—- C:Program FilesReg Organizer
2010-11-09 14:17:13 —-D—- C:Program FilesMail.Ru
2010-11-09 14:17:08 —-D—- C:Program FilesAnVir Startup Manager
2010-11-09 14:16:32 —-D—- C:ProgramDataAlwil Software
2010-11-09 12:19:21 —-D—- C:UsersoksanaAppDataRoamingUniblue
2010-11-09 12:19:18 —-HDC—- C:ProgramData{7BC48736-44DE-4E73-A789-B700D1778AE5}
2010-11-09 12:19:15 —-D—- C:Program FilesUniblue
2010-11-09 11:53:43 —-D—- C:Program Filestrend micro
2010-11-09 11:53:41 —-D—- C:rsit
2010-10-29 00:29:36 —-A—- C:Windowssystem32driversDiskdump.sys
2010-10-27 21:07:44 —-A—- C:Windowssystem32msdri.dll
2010-10-27 21:07:43 —-A—- C:Windowssystem32CPFilters.dll
2010-10-22 11:28:18 —-A—- C:Windowsntbtlog.txt
2010-10-20 10:11:28 —-D—- C:WindowsMinidump
2010-10-13 01:03:31 —-A—- C:Windowssystem32ole32.dll
2010-10-13 01:03:16 —-A—- C:Windowssystem32iertutil.dll
2010-10-13 01:03:15 —-A—- C:Windowssystem32mshtml.dll
2010-10-13 01:03:14 —-A—- C:Windowssystem32ieframe.dll
2010-10-13 01:03:13 —-A—- C:Windowssystem32msfeeds.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32wininet.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32urlmon.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32mstime.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32licmgr10.dll
2010-10-13 01:03:12 —-A—- C:Windowssystem32iedkcs32.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32mshtmled.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32msfeedssync.exe
2010-10-13 01:03:11 —-A—- C:Windowssystem32msfeedsbs.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32jsproxy.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32ieui.dll
2010-10-13 01:03:11 —-A—- C:Windowssystem32iepeers.dll
2010-10-13 01:02:33 —-A—- C:Windowssystem32t2embed.dll
2010-10-13 01:02:29 —-A—- C:Windowssystem32schannel.dll
2010-10-13 01:02:27 —-A—- C:Windowssystem32comctl32.dll
2010-10-13 01:02:24 —-A—- C:Windowssystem32mfc40u.dll
2010-10-13 01:02:24 —-A—- C:Windowssystem32mfc40.dll
2010-10-13 01:01:13 —-A—- C:Windowssystem32wmp.dll
2010-10-13 01:01:11 —-A—- C:Windowssystem32wmploc.DLL
2010-10-13 01:00:48 —-A—- C:Windowssystem32win32k.sys
2010-10-13 01:00:44 —-A—- C:Windowssystem32srvsvc.dll
2010-10-13 01:00:44 —-A—- C:Windowssystem32driverssrv2.sys
2010-10-13 01:00:44 —-A—- C:Windowssystem32driverssrv.sys
2010-10-13 01:00:43 —-A—- C:Windowssystem32driverssrvnet.sys
2010-10-13 00:53:43 —-A—- C:Windowssystem32wmpmde.dll
2010-10-13 00:49:16 —-A—- C:Windowssystem32StructuredQuery.dll
2010-10-12 13:34:12 —-A—- C:Windowssystem32ztvunrar36.dll
2010-10-12 13:34:12 —-A—- C:Windowssystem32ztvunace26.dll
2010-10-12 13:34:12 —-A—- C:Windowssystem32ztvcabinet.dll
2010-10-12 13:34:11 —-A—- C:Windowssystem32UNRAR3.dll
2010-10-12 13:34:11 —-A—- C:Windowssystem32unacev2.dll
2010-10-12 13:34:07 —-D—- C:UsersoksanaAppDataRoamingSimply Super Software
2010-10-12 13:34:07 —-D—- C:ProgramDataSimply Super Software
2010-10-12 13:34:07 —-D—- C:Program FilesTrojan Remover======List of files/folders modified in the last 1 months======
2010-11-09 15:13:20 —-D—- C:WindowsPrefetch
2010-11-09 15:12:08 —-D—- C:WindowsTemp
2010-11-09 15:11:20 —-D—- C:Program FilesAlwil Software
2010-11-09 15:10:01 —-D—- C:UsersoksanaAppDataRoaminguTorrent
2010-11-09 15:09:39 —-D—- C:Windows
2010-11-09 15:09:21 —-SHD—- C:System Volume Information
2010-11-09 14:28:53 —-D—- C:Windowssystem32config
2010-11-09 14:19:17 —-SHD—- C:WindowsInstaller
2010-11-09 14:19:14 —-D—- C:WindowsTasks
2010-11-09 14:19:14 —-D—- C:Windowssystem32Tasks
2010-11-09 14:18:59 —-RD—- C:Program Files
2010-11-09 14:18:42 —-D—- C:Windowswinsxs
2010-11-09 14:17:56 —-D—- C:Program FilesCommon Filesmicrosoft shared
2010-11-09 14:17:08 —-D—- C:WindowsSystem32
2010-11-09 14:16:32 —-HD—- C:ProgramData
2010-11-09 10:52:32 —-D—- C:Windowsinf
2010-11-09 10:52:32 —-A—- C:Windowssystem32PerfStringBackup.INI
2010-11-09 00:43:06 —-D—- C:UsersoksanaAppDataRoamingEurekaLog
2010-11-01 13:58:15 —-D—- C:Windowsrescache
2010-10-29 02:00:53 —-D—- C:WindowsAppPatch
2010-10-29 02:00:38 —-D—- C:Windowssystem32drivers
2010-10-28 02:05:49 —-RSD—- C:Windowsassembly
2010-10-28 02:04:53 —-D—- C:WindowsMicrosoft.NET
2010-10-28 02:01:52 —-D—- C:Windowsehome
2010-10-27 17:58:43 —-D—- C:Windowssystem32catroot
2010-10-27 17:58:36 —-D—- C:Windowssystem32catroot2
2010-10-25 07:15:47 —-SD—- C:UsersoksanaAppDataRoamingMicrosoft
2010-10-19 10:41:44 —-N—- C:Windowssystem32MpSigStub.exe
2010-10-13 02:18:30 —-D—- C:Windowssystem32migration
2010-10-13 02:18:30 —-D—- C:Program FilesInternet Explorer
2010-10-13 02:18:29 —-D—- C:Program FilesWindows Media Player
2010-10-13 02:00:58 —-A—- C:Windowssystem32MRT.exe
2010-10-12 15:43:54 —-D—- C:Windowssystem32wdi======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:WindowsSystem32driversrdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%system32cscsvc.dll,-202; C:Windowssystem32driverscsc.sys [2009-07-14 387584]
R1 vwififlt;Virtual WiFi Filter Driver; C:Windowssystem32DRIVERSvwififlt.sys [2009-07-14 48128]
R3 AgereSoftModem;Agere Systems Soft Modem; C:Windowssystem32DRIVERSAGRSM.sys [2009-07-14 1035776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:Windowssystem32DRIVERSathr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet — NDIS 6.0; C:Windowssystem32DRIVERSb57nd60x.sys [2009-07-14 229888]
R3 igfx;igfx; C:Windowssystem32DRIVERSigdkmd32.sys [2009-09-23 4808192]
S2 Parvdm;Parvdm; C:Windowssystem32DRIVERSparvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:Windowssystem32DRIVERSdjsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:Windowssystem32DRIVERSamdagp.sys [2009-07-14 53312]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:Windowssystem32DRIVERSewusbmdm.sys [2009-06-22 102912]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:Windowssystem32DRIVERSewusbdev.sys [2009-06-22 100736]
S3 pciide;pciide; C:Windowssystem32DRIVERSpciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:WindowsSystem32driversrdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:Windowssystem32DRIVERSvms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:Windowssystem32DRIVERSsisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:Windowssystem32DRIVERSstorvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:Windowssystem32DRIVERSviaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:Windowssystem32DRIVERSviac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%system32vmbusres.dll,-1000; C:Windowssystem32DRIVERSvmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:Windowssystem32DRIVERSVMBusHID.sys [2009-07-14 17920]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%system32cscsvc.dll,-200; C:WindowsSystem32svchost.exe [2009-07-14 20992]
R2 Guard.Mail.ru;Guard.Mail.ru; C:Program FilesMail.RuGuardGuardMailRu.exe [2010-11-09 991936]
S2 gupdate;Служба Google Update (gupdate); C:Program FilesGoogleUpdateGoogleUpdate.exe [2010-11-09 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:Windowssystem32svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%system32peerdistsvc.dll,-9000; C:WindowsSystem32svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%system32umrdp.dll,-1000; C:WindowsSystem32svchost.exe [2009-07-14 20992]
EOF
12 ноября, 2010 в 6:16 пп #31774Здравствуйте, добро пожаловать на Spyware-ru форум.
не могу установить антивирус и браузеры.
При попытке запуска/установки этих программ что происходит ?
12 ноября, 2010 в 10:20 пп #31775Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Пишут, что «…не является приложением Win 32»
-
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.