• Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы

SPYWARE-RU.COM

Меню
  • Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы
В начало › Неполадки. Торможение, рестарты.
Adguard
 

Неполадки. Торможение, рестарты.

Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Неполадки. Торможение, рестарты.

  • This topic has 0 ответов, 1 участник, and was last updated 15 years, 8 months назад by Dic.
Просмотр 1 сообщения - с 1 по 1 (всего 1)
  • Автор
    Сообщения
  • 28 ноября, 2009 в 5:42 пп #17487
    Dic
    Participant
    • Темы:2
    • Сообщений:17
    • ☆

    Добрый вечер!

    С компьютером стали происходить неполадки. Начал работать медленнее, сам делать рестарт — без каких-либо предупреждений, в браузере место открытия вкладки, открываются окна, экран смерти.

    Так-же пропадает CD/DVDRom. Вернее компьютер его не видит.

    Надеюсь на помощь, и решение проблемы.

    С Уважнием,
    Артём.


    Info:

    info.txt logfile of random’s system information tool 1.06 2009-11-28 19:13:19

    ======Uninstall list======

    —>MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
    —>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:WINDOWSINFPCHealth.inf
    Adobe Flash Player 10 ActiveX—>C:WINDOWSsystem32MacromedFlashuninstall_activeX.exe
    Adobe Flash Player 10 Plugin—>C:WINDOWSsystem32MacromedFlashuninstall_plugin.exe
    Adobe Shockwave Player 11—>C:WINDOWSsystem32adobeSHOCKW~1UNWISE.EXE C:WINDOWSsystem32AdobeSHOCKW~1Install.log
    CCleaner—>»C:Program FilesCCleaneruninst.exe»
    HijackThis 2.0.2—>»C:Program Filestrend microHijackThis.exe» /uninstall
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)—>C:WINDOWSsystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=»»
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)—>C:WINDOWSsystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=»»
    Hotfix for Windows XP (KB976098-v2)—>»C:WINDOWS$NtUninstallKB976098-v2$spuninstspuninst.exe»
    Java(TM) 6 Update 7—>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    K-Lite Mega Codec Pack 3.7.5—>»C:Program FilesK-Lite Codec Packunins000.exe»
    LibertyKeeper—>»C:Program FilesLibertyKeeperuninstall.exe»
    Microsoft .NET Framework (English) v1.0.3705—>MsiExec.exe /X{B43357AA-3A6D-4D94-B56E-43C44D09E548}
    Microsoft .NET Framework 1.0 Hotfix (KB928367)—>»C:WINDOWSMicrosoft.NETFrameworkv1.0.3705Updateshotfix.exe» «C:WINDOWSMicrosoft.NETFrameworkv1.0.3705UpdatesM928367M928367Uninstall.msp»
    Microsoft .NET Framework 1.1 Security Update (KB953297)—>»C:WINDOWSMicrosoft.NETFrameworkv1.1.4322Updateshotfix.exe» «C:WINDOWSMicrosoft.NETFrameworkv1.1.4322UpdatesM953297M953297Uninstall.msp»
    Microsoft .NET Framework 1.1 SP1—>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1—>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0 Service Pack 2—>MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    Microsoft .NET Framework 3.0 Service Pack 2—>MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
    Microsoft .NET Framework 3.5 SP1—>C:WINDOWSMicrosoft.NETFrameworkv3.5Microsoft .NET Framework 3.5 SP1setup.exe
    Microsoft .NET Framework 3.5 SP1—>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
    Microsoft Office 2003 Proofing Tools—>MsiExec.exe /I{901F0409-6000-11D3-8CFE-0150048383C9}
    Microsoft Office 2003 Russian User Interface Pack—>MsiExec.exe /I{901E0419-6000-11D3-8CFE-0150048383C9}
    Microsoft Office Professional Edition 2003—>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Mozilla Firefox (3.5.5)—>C:Program FilesMozilla Firefoxuninstallhelper.exe
    Notepad++—>C:Program FilesNotepad++uninstall.exe
    NVIDIA Display Control Panel—>C:Program FilesNVIDIA CorporationUninstallnvuninst.exe DisplayControlPanel
    NVIDIA Drivers—>C:Program FilesNVIDIA CorporationUninstallnvuninst.exe UninstallGUI
    NVIDIA nView Desktop Manager—>C:Program FilesNVIDIA CorporationnViewnViewSetup.exe -uninstall
    NVIDIA PhysX—>MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
    Opera 10.10—>MsiExec.exe /X{FB8148DD-C575-4B0A-9F6C-0CFC46937930}
    Realtek High Definition Audio Driver—>RtlUpd.exe -r -m -nrg2709
    Security Update for Windows Internet Explorer 8 (KB969897)—>»C:WINDOWSie8updatesKB969897-IE8spuninstspuninst.exe»
    Security Update for Windows Internet Explorer 8 (KB971961)—>»C:WINDOWSie8updatesKB971961-IE8spuninstspuninst.exe»
    Security Update for Windows Internet Explorer 8 (KB974455)—>»C:WINDOWSie8updatesKB974455-IE8spuninstspuninst.exe»
    Security Update for Windows Media Player (KB954155)—>»C:WINDOWS$NtUninstallKB954155_WM9$spuninstspuninst.exe»
    Security Update for Windows Media Player (KB968816)—>»C:WINDOWS$NtUninstallKB968816_WM9$spuninstspuninst.exe»
    Security Update for Windows Media Player (KB973540)—>»C:WINDOWS$NtUninstallKB973540_WM9$spuninstspuninst.exe»
    Security Update for Windows XP (KB956744)—>»C:WINDOWS$NtUninstallKB956744$spuninstspuninst.exe»
    Security Update for Windows XP (KB956844)—>»C:WINDOWS$NtUninstallKB956844$spuninstspuninst.exe»
    Security Update for Windows XP (KB958869)—>»C:WINDOWS$NtUninstallKB958869$spuninstspuninst.exe»
    Security Update for Windows XP (KB960859)—>»C:WINDOWS$NtUninstallKB960859$spuninstspuninst.exe»
    Security Update for Windows XP (KB961371-v2)—>»C:WINDOWS$NtUninstallKB961371-v2$spuninstspuninst.exe»
    Security Update for Windows XP (KB969059)—>»C:WINDOWS$NtUninstallKB969059$spuninstspuninst.exe»
    Security Update for Windows XP (KB969947)—>»C:WINDOWS$NtUninstallKB969947$spuninstspuninst.exe»
    Security Update for Windows XP (KB971486)—>»C:WINDOWS$NtUninstallKB971486$spuninstspuninst.exe»
    Security Update for Windows XP (KB971557)—>»C:WINDOWS$NtUninstallKB971557$spuninstspuninst.exe»
    Security Update for Windows XP (KB971633)—>»C:WINDOWS$NtUninstallKB971633$spuninstspuninst.exe»
    Security Update for Windows XP (KB971657)—>»C:WINDOWS$NtUninstallKB971657$spuninstspuninst.exe»
    Security Update for Windows XP (KB973354)—>»C:WINDOWS$NtUninstallKB973354$spuninstspuninst.exe»
    Security Update for Windows XP (KB973507)—>»C:WINDOWS$NtUninstallKB973507$spuninstspuninst.exe»
    Security Update for Windows XP (KB973525)—>»C:WINDOWS$NtUninstallKB973525$spuninstspuninst.exe»
    Security Update for Windows XP (KB973869)—>»C:WINDOWS$NtUninstallKB973869$spuninstspuninst.exe»
    Security Update for Windows XP (KB974112)—>»C:WINDOWS$NtUninstallKB974112$spuninstspuninst.exe»
    Security Update for Windows XP (KB974571)—>»C:WINDOWS$NtUninstallKB974571$spuninstspuninst.exe»
    Security Update for Windows XP (KB975025)—>»C:WINDOWS$NtUninstallKB975025$spuninstspuninst.exe»
    Security Update for Windows XP (KB975467)—>»C:WINDOWS$NtUninstallKB975467$spuninstspuninst.exe»
    Skype™ 4.1—>MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
    System Requirements Lab—>C:Program FilesSystemRequirementsLabUninstall.exe
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)—>C:WINDOWSsystem32msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=»»
    Update for Windows Internet Explorer 8 (KB968220)—>»C:WINDOWSie8updatesKB968220-IE8spuninstspuninst.exe»
    Update for Windows Internet Explorer 8 (KB971930)—>»C:WINDOWSie8updatesKB971930-IE8spuninstspuninst.exe»
    Update for Windows Internet Explorer 8 (KB976749)—>»C:WINDOWSie8updatesKB976749-IE8spuninstspuninst.exe»
    Update for Windows XP (KB968389)—>»C:WINDOWS$NtUninstallKB968389$spuninstspuninst.exe»
    Update for Windows XP (KB973687)—>»C:WINDOWS$NtUninstallKB973687$spuninstspuninst.exe»
    Update for Windows XP (KB973815)—>»C:WINDOWS$NtUninstallKB973815$spuninstspuninst.exe»
    Winamp—>»C:Program FilesWinampUninstWA.exe»
    Windows Internet Explorer 8 Multilingual User Interface (MUI)—>»C:WINDOWSie8updatesIE8-MUIspuninstspuninst.exe»
    Windows Internet Explorer 8—>»C:WINDOWSie8spuninstspuninst.exe»
    Windows XP Media Center Edition 2005 KB973768—>»C:WINDOWS$NtUninstallKB973768$spuninstspuninst.exe»
    Архиватор WinRAR—>C:Program FilesWinRARuninstall.exe
    Пакет обеспечения совместимости для выпуска 2007 системы Microsoft Office—>MsiExec.exe /X{90120000-0020-0419-0000-0000000FF1CE}

    ======Security center information======

    AV: ESET NOD32 Antivirus 4.0

    ======System event log======

    Computer Name: CLONE
    Event Code: 19
    Message: Installation Successful: Windows successfully installed the following update: Security Update for Windows XP (KB963093)

    Record Number: 5
    Source Name: Windows Update Agent
    Time Written: 20091127155351.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 18
    Message: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on 27 ноября 2009 г. at 15:53:
    — Обновление для системы безопасности Windows XP (KB963093)
    — Накопительное обновление для системы безопасности Internet Explorer 8 в ОС Windows XP (KB969897)

    Record Number: 4
    Source Name: Windows Update Agent
    Time Written: 20091127155326.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 6005
    Message: Запущена служба журнала событий.

    Record Number: 3
    Source Name: EventLog
    Time Written: 20091127155234.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 6009
    Message: Microsoft (R) Windows 2000 (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

    Record Number: 2
    Source Name: EventLog
    Time Written: 20091127155234.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 6006
    Message: Служба журнала событий остановлена.

    Record Number: 1
    Source Name: EventLog
    Time Written: 20090709115659.000000+180
    Event Type: информация
    User:

    =====Application event log=====

    Computer Name: CLONE
    Event Code: 1001
    Message: Счетчики производительности для службы WmiApRpl (WmiApRpl) успешно удалены.
    Данные записи содержат новые значения разделов системного реестра Last Counter
    и Last Help.

    Record Number: 5
    Source Name: LoadPerf
    Time Written: 20091127155352.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 0
    Message:
    Record Number: 4
    Source Name: PDEngine
    Time Written: 20091127155300.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 0
    Message:
    Record Number: 3
    Source Name: PDAgent
    Time Written: 20091127155237.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 0
    Message:
    Record Number: 2
    Source Name: PDEngine
    Time Written: 20091127155237.000000+120
    Event Type: информация
    User:

    Computer Name: CLONE
    Event Code: 0
    Message:
    Record Number: 1
    Source Name: PDAgent
    Time Written: 20091127155235.000000+120
    Event Type: информация
    User:

    ======Environment variables======

    «ComSpec»=%SystemRoot%system32cmd.exe
    «devmgr_show_nonpresent_devices»=1
    «FP_NO_HOST_CHECK»=NO
    «NUMBER_OF_PROCESSORS»=2
    «OS»=Windows_NT
    «Path»=%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem
    «PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    «PROCESSOR_ARCHITECTURE»=x86
    «PROCESSOR_IDENTIFIER»=x86 Family 6 Model 15 Stepping 13, GenuineIntel
    «PROCESSOR_LEVEL»=6
    «PROCESSOR_REVISION»=0f0d
    «TEMP»=%SystemRoot%TEMP
    «TMP»=%SystemRoot%TEMP
    «windir»=%SystemRoot%


    EOF



    Log:

    Logfile of random’s system information tool 1.06 (written by random/random)
    Run by User at 2009-11-28 19:12:56
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 374 GB (98%) free of 382 GB
    Total RAM: 2046 MB (73% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:13:18, on 28.11.2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:WINDOWSSystem32smss.exe
    C:WINDOWSsystem32winlogon.exe
    C:WINDOWSsystem32services.exe
    C:WINDOWSsystem32lsass.exe
    C:WINDOWSsystem32nvsvc32.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:WINDOWSsystem32spoolsv.exe
    C:WINDOWSeHomeehRecvr.exe
    C:WINDOWSeHomeehSched.exe
    C:Program FilesESETESET NOD32 Antivirusekrn.exe
    C:WINDOWSExplorer.EXE
    C:Program FilesESETESET NOD32 Antivirusegui.exe
    C:Program FilesWinampwinampa.exe
    C:Documents and SettingsUserApplication DataMail.RuAgentMAgent.exe
    C:WINDOWSsystem32ctfmon.exe
    C:WINDOWSsystem32dllhost.exe
    C:Program FilesSkypePhoneSkype.exe
    C:Program FilesSkypePlugin ManagerskypePM.exe
    C:Program FilesMozilla Firefoxfirefox.exe
    C:WINDOWSsystem32wuauclt.exe
    C:Documents and SettingsUserMy DocumentsЗагрузкиRSIT.exe
    C:Program Filestrend microUser.exe

    R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.boldnet.lv/
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
    R3 — Default URLSearchHook is missing
    O2 — BHO: SSVHelper Class — {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} — C:Program FilesJavajre1.6.0_07binssv.dll
    O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
    O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
    O4 — HKLM..Run: [WinampAgent] «C:Program FilesWinampwinampa.exe»
    O4 — HKCU..Run: [MAgent] C:Documents and SettingsUserApplication DataMail.RuAgentMAgent.exe -CU
    O4 — HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
    O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
    O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
    O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
    O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
    O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
    O9 — Extra button: (no name) — {08B0E5C0-4FCB-11CF-AAA5-00401C608501} — C:Program FilesJavajre1.6.0_07binssv.dll
    O9 — Extra ‘Tools’ menuitem: Sun Java Console — {08B0E5C0-4FCB-11CF-AAA5-00401C608501} — C:Program FilesJavajre1.6.0_07binssv.dll
    O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
    O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Documents and SettingsUserApplication DataMail.RuAgentmagent.exe (HKCU)
    O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Documents and SettingsUserApplication DataMail.RuAgentmagent.exe (HKCU)
    O15 — Trusted Zone: http://www.boldnet.lv
    O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
    O20 — Winlogon Notify: Antiwpa — C:WINDOWS
    O23 — Service: ESET HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
    O23 — Service: ESET Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
    O23 — Service: NVIDIA Display Driver Service (nvsvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe

    —
    End of file — 4043 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class — C:Program FilesJavajre1.6.0_07binssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
    «egui»=C:Program FilesESETESET NOD32 Antivirusegui.exe [2009-03-19 2029640]
    «NvCplDaemon»=C:WINDOWSsystem32NvCpl.dll [2009-11-20 12669544]
    «WinampAgent»=C:Program FilesWinampwinampa.exe [2009-07-01 37888]

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
    «MAgent»=C:Documents and SettingsUserApplication DataMail.RuAgentMAgent.exe [2009-11-27 7975608]
    «ctfmon.exe»=C:WINDOWSsystem32ctfmon.exe [2008-04-15 15360]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregctfmon.exe]
    C:WINDOWSsystem32ctfmon.exe [2008-04-15 15360]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregDAEMON Tools Lite]
    C:Program FilesDAEMON Tools Litedaemon.exe [2009-04-23 691656]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregFlashPlayerUpdate]
    C:WINDOWSsystem32MacromedFlashNPSWF32_FlashUtil.exe [2009-07-18 257440]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvCplDaemon]
    C:WINDOWSsystem32NvCpl.dll [2009-11-20 12669544]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
    C:WINDOWSsystem32NvMcTray.dll [2009-11-20 110184]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregnwiz]
    nwiz.exe /installquiet []

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRTHDCPL]
    C:WINDOWSRTHDCPL.EXE [2009-06-12 17887232]

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSkype]
    C:Program FilesSkypePhoneSkype.exe [2009-06-26 25604904]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAntiwpa]

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
    «dontdisplaylastusername»=0
    «legalnoticecaption»=
    «legalnoticetext»=
    «shutdownwithoutlogon»=1
    «undockwithoutlogon»=1
    «InstallVisualStyle»=C:WINDOWSResourcesThemesRoyaleRoyale.msstyles
    «InstallTheme»=C:WINDOWSResourcesThemesRoyale.theme

    [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «NoDriveTypeAutoRun»=145

    [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
    «HonorAutoRunSetting»=

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «C:Program FilesVNCwinvnc.exe»=»C:Program FilesVNCwinvnc.exe:*:Enabled:VNC server for Win32»
    «C:WINDOWSsystem32sessmgr.exe»=»C:WINDOWSsystem32sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019»
    «C:Program FilesMessengermsmsgs.exe»=»C:Program FilesMessengermsmsgs.exe:*:Enabled:Windows Messenger»
    «C:Program FilesOperaopera.exe»=»C:Program FilesOperaopera.exe:*:Enabled:Opera Internet Browser»
    «C:Program FilesuTorrentuTorrent.exe»=»C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent»
    «C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»

    [HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
    «%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
    «%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

    [HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{a9ab488b-f5e4-11dd-b8b9-806d6172696f}]
    shellAutoRuncommand — D:setup.exe

    ======List of files/folders created in the last 1 months======

    2009-11-28 19:12:56 —-D—- C:rsit
    2009-11-28 19:12:56 —-D—- C:Program Filestrend micro
    2009-11-28 16:24:09 —-D—- C:Documents and SettingsUserApplication DataMikrotik
    2009-11-28 16:10:30 —-D—- C:Program FilesuTorrent
    2009-11-28 16:10:22 —-D—- C:Documents and SettingsUserApplication DatauTorrent
    2009-11-28 15:59:50 —-A—- C:WINDOWSsystem32NVUNINST.EXE
    2009-11-28 15:57:28 —-D—- C:Program FilesAdobe
    2009-11-28 15:10:15 —-D—- C:Documents and SettingsUserApplication DataThinstall
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32vxblock.dll
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxwave.dll
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxsfs.dll
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxmas.dll
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxinsa64.exe
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxhpinst.exe
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxdrv.dll
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxcpya64.exe
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32pxafs.dll
    2009-11-28 15:05:54 —-N—- C:WINDOWSsystem32px.dll
    2009-11-28 15:05:53 —-D—- C:Program FilesWinamp
    2009-11-28 15:05:53 —-D—- C:Documents and SettingsUserApplication DataWinamp
    2009-11-28 14:14:54 —-D—- C:Documents and SettingsAll UsersApplication DataFLEXnet
    2009-11-28 14:04:41 —-D—- C:Documents and SettingsAll UsersApplication DataAdobe
    2009-11-28 13:34:49 —-D—- C:Program FilesCommon FilesAdobe
    2009-11-28 13:22:56 —-D—- C:Program FilesNotepad++
    2009-11-28 13:22:56 —-D—- C:Documents and SettingsUserApplication DataNotepad++
    2009-11-28 12:39:10 —-D—- C:Program FilesCommon FilesAkamai
    2009-11-27 22:22:43 —-D—- C:Documents and SettingsAll UsersApplication DataNOS
    2009-11-27 20:54:04 —-D—- C:WINDOWSsystem32LogFiles
    2009-11-27 20:22:20 —-D—- C:Documents and SettingsUserApplication DataOpera
    2009-11-27 20:08:50 —-D—- C:Program FilesOpera
    2009-11-27 18:43:59 —-D—- C:WINDOWSsystem32AGEIA
    2009-11-27 18:43:58 —-D—- C:Program FilesAGEIA Technologies
    2009-11-27 18:43:44 —-D—- C:Program FilesCommon FilesWise Installation Wizard
    2009-11-27 18:43:43 —-D—- C:Documents and SettingsAll UsersApplication DataNVIDIA Corporation
    2009-11-27 18:43:39 —-D—- C:Program FilesNVIDIA Corporation
    2009-11-27 18:43:05 —-A—- C:WINDOWSsystem32OpenCL.dll
    2009-11-27 18:43:03 —-A—- C:WINDOWSsystem32nvcompiler.dll
    2009-11-27 18:43:01 —-D—- C:NVIDIA
    2009-11-27 18:29:30 —-D—- C:Program FilesSystemRequirementsLab
    2009-11-27 18:29:29 —-D—- C:Documents and SettingsUserApplication DataSystemRequirementsLab
    2009-11-27 18:29:25 —-D—- C:WINDOWSSun
    2009-11-27 18:29:25 —-D—- C:Documents and SettingsUserApplication DataSun
    2009-11-27 18:23:54 —-D—- C:Program FilesCCleaner
    2009-11-27 18:18:52 —-D—- C:Documents and SettingsUserApplication DataskypePM
    2009-11-27 18:17:00 —-D—- C:Documents and SettingsUserApplication DataMra
    2009-11-27 18:17:00 —-D—- C:Documents and SettingsUserApplication DataMail.Ru
    2009-11-27 18:16:51 —-D—- C:Program FilesMail.Ru
    2009-11-27 18:16:46 —-D—- C:Program FilesLibertyKeeper
    2009-11-27 18:11:24 —-SHD—- C:RECYCLER
    2009-11-27 18:10:13 —-D—- C:Documents and SettingsAll UsersApplication DataOffice Genuine Advantage
    2009-11-27 18:06:05 —-D—- C:Documents and SettingsUserApplication DataMozilla
    2009-11-27 18:06:02 —-D—- C:Program FilesMozilla Firefox
    2009-11-27 17:59:46 —-HDC—- C:WINDOWS$NtUninstallKB960859$
    2009-11-27 17:59:41 —-HDC—- C:WINDOWS$NtUninstallKB969059$
    2009-11-27 17:59:37 —-HDC—- C:WINDOWS$NtUninstallKB961371-v2$
    2009-11-27 17:59:33 —-HDC—- C:WINDOWS$NtUninstallKB971657$
    2009-11-27 17:59:28 —-HDC—- C:WINDOWS$NtUninstallKB971557$
    2009-11-27 17:59:24 —-HDC—- C:WINDOWS$NtUninstallKB974112$
    2009-11-27 17:59:20 —-HDC—- C:WINDOWS$NtUninstallKB975467$
    2009-11-27 17:58:59 —-HDC—- C:WINDOWS$NtUninstallKB968389$
    2009-11-27 17:51:30 —-A—- C:WINDOWSsystem32hidserv.dll
    2009-11-27 17:15:04 —-HDC—- C:WINDOWS$NtUninstallKB971633$
    2009-11-27 17:14:59 —-HDC—- C:WINDOWS$NtUninstallKB975025$
    2009-11-27 17:14:54 —-HDC—- C:WINDOWS$NtUninstallKB974571$
    2009-11-27 17:14:49 —-HDC—- C:WINDOWS$NtUninstallKB973507$
    2009-11-27 17:14:42 —-HDC—- C:WINDOWS$NtUninstallKB973815$
    2009-11-27 17:08:41 —-HDC—- C:WINDOWS$NtUninstallKB958869$
    2009-11-27 17:08:36 —-HDC—- C:WINDOWS$NtUninstallKB976098-v2$
    2009-11-27 17:08:31 —-HDC—- C:WINDOWS$NtUninstallKB968816_WM9$
    2009-11-27 17:08:27 —-HDC—- C:WINDOWS$NtUninstallKB954155_WM9$
    2009-11-27 17:07:48 —-HDC—- C:WINDOWS$NtUninstallKB956744$
    2009-11-27 17:07:42 —-HDC—- C:WINDOWS$NtUninstallKB956844$
    2009-11-27 17:07:36 —-HDC—- C:WINDOWS$NtUninstallKB973869$
    2009-11-27 17:07:29 —-HDC—- C:WINDOWS$NtUninstallKB973687$
    2009-11-27 17:07:23 —-HDC—- C:WINDOWS$NtUninstallKB973354$
    2009-11-27 17:07:16 —-HDC—- C:WINDOWS$NtUninstallKB973540_WM9$
    2009-11-27 17:06:51 —-HDC—- C:WINDOWS$NtUninstallKB973768$
    2009-11-27 17:06:24 —-HDC—- C:WINDOWS$NtUninstallKB971486$
    2009-11-27 17:06:13 —-HDC—- C:WINDOWS$NtUninstallKB973525$
    2009-11-27 17:05:55 —-HDC—- C:WINDOWS$NtUninstallKB969947$
    2009-11-27 17:04:04 —-HD—- C:WINDOWS$hf_mig$
    2009-11-27 17:03:14 —-D—- C:WINDOWSsystem32Lang
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nvcuvid.dll
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nvcuvenc.dll
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nvcuda.dll
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nvcodins.dll
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nvcod.dll
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nvapi.dll
    2009-11-27 16:59:19 —-A—- C:WINDOWSsystem32nv4_disp.dll
    2009-11-27 16:59:17 —-A—- C:WINDOWSsystem32nvoglnt.dll
    2009-11-27 16:59:17 —-A—- C:WINDOWSsystem32NvCplSetupInt.exe
    2009-11-27 16:58:18 —-D—- C:WINDOWSsystem32RTCOM
    2009-11-27 15:58:05 —-A—- C:WINDOWSvncutil.exe
    2009-11-27 15:58:04 —-A—- C:WINDOWSsystem32RtkCoInstXP.dll
    2009-11-27 15:58:04 —-A—- C:WINDOWSSkyTel.exe
    2009-11-27 15:58:04 —-A—- C:WINDOWSRtkAudioService.exe
    2009-11-27 15:58:00 —-A—- C:WINDOWSRtlUpd.exe
    2009-11-27 15:58:00 —-A—- C:WINDOWSMicCal.exe
    2009-11-27 15:58:00 —-A—- C:WINDOWSALCWZRD.EXE
    2009-11-27 15:57:59 —-A—- C:WINDOWSSOUNDMAN.EXE
    2009-11-27 15:57:59 —-A—- C:WINDOWSRTLCPL.EXE
    2009-11-27 15:57:59 —-A—- C:WINDOWSRTHDCPL.EXE
    2009-11-27 15:57:59 —-A—- C:WINDOWSALCMTR.EXE
    2009-11-27 15:57:41 —-A—- C:WINDOWSsystem32RtNicProp32.dll
    2009-11-27 15:56:05 —-DC—- C:WINDOWSsystem32DRVSTORE
    2009-11-20 20:32:14 —-A—- C:WINDOWSsystem32nvsvc32.exe
    2009-11-20 20:32:14 —-A—- C:WINDOWSsystem32nvmctray.dll
    2009-11-20 20:32:14 —-A—- C:WINDOWSsystem32nvmccs.dll
    2009-11-20 20:32:14 —-A—- C:WINDOWSsystem32nvcpl.dll
    2009-11-20 20:32:14 —-A—- C:WINDOWSsystem32nvcolor.exe
    2009-11-20 20:32:10 —-A—- C:WINDOWSsystem32nvwddi.dll

    ======List of files/folders modified in the last 1 months======

    2009-11-28 19:12:56 —-RD—- C:Program Files
    2009-11-28 19:10:02 —-D—- C:WINDOWSTemp
    2009-11-28 19:09:56 —-D—- C:Documents and SettingsUserApplication DataSkype
    2009-11-28 19:09:24 —-D—- C:WINDOWS
    2009-11-28 18:45:01 —-D—- C:WINDOWSRegistration
    2009-11-28 17:46:23 —-D—- C:WINDOWSPrefetch
    2009-11-28 16:37:39 —-SD—- C:Documents and SettingsUserApplication DataMicrosoft
    2009-11-28 15:59:58 —-D—- C:Program FilesCommon Files
    2009-11-28 15:59:50 —-D—- C:WINDOWSsystem32
    2009-11-28 15:56:25 —-D—- C:WINDOWSsystem32drivers
    2009-11-28 15:07:52 —-RSHDC—- C:WINDOWSsystem32dllcache
    2009-11-28 15:07:48 —-D—- C:WINDOWSsystem32CatRoot2
    2009-11-28 14:23:31 —-SHD—- C:WINDOWSInstaller
    2009-11-28 14:22:29 —-D—- C:Documents and SettingsUserApplication DataAdobe
    2009-11-28 14:16:54 —-SD—- C:Documents and SettingsAll UsersApplication DataMicrosoft
    2009-11-28 00:22:33 —-N—- C:WINDOWSSchedLgU.Txt
    2009-11-27 20:11:57 —-D—- C:Program FilesVNC
    2009-11-27 18:51:48 —-D—- C:WINDOWSMicrosoft.NET
    2009-11-27 18:51:40 —-RSD—- C:WINDOWSassembly
    2009-11-27 18:47:40 —-A—- C:WINDOWSsystem32storprop.dll
    2009-11-27 18:44:28 —-D—- C:WINDOWSHelp
    2009-11-27 18:43:30 —-HD—- C:WINDOWSinf
    2009-11-27 18:24:36 —-D—- C:WINDOWSDebug
    2009-11-27 18:05:32 —-D—- C:Downloads
    2009-11-27 18:05:29 —-D—- C:WINDOWSehome
    2009-11-27 18:04:37 —-D—- C:Program FilesCommon FilesNero
    2009-11-27 17:57:59 —-D—- C:Documents and SettingsUserApplication DataYandex
    2009-11-27 17:55:19 —-D—- C:Program FilesCommon FilesACD Systems
    2009-11-27 17:17:38 —-D—- C:Documents and Settings
    2009-11-27 17:09:54 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
    2009-11-27 17:09:45 —-D—- C:WINDOWSWinSxS
    2009-11-27 17:08:51 —-D—- C:Program FilesInternet Explorer
    2009-11-27 17:07:24 —-D—- C:Program FilesOutlook Express
    2009-11-27 15:53:20 —-D—- C:WINDOWSSoftwareDistribution
    2009-11-27 15:52:35 —-SHD—- C:System Volume Information
    2009-11-27 15:52:32 —-D—- C:WINDOWSsystem32config
    2009-11-05 09:36:22 —-A—- C:WINDOWSsystem32MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 BIOS;BIOS; ??C:WINDOWSsystem32driversBIOS.sys []
    R1 ehdrv;ehdrv; C:WINDOWSsystem32DRIVERSehdrv.sys [2009-03-19 107256]
    R1 epfwtdir;epfwtdir; C:WINDOWSsystem32DRIVERSepfwtdir.sys [2009-03-19 93848]
    R1 intelppm;Intel Processor Driver; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-15 36352]
    R2 eamon;eamon; C:WINDOWSsystem32DRIVERSeamon.sys [2009-03-19 113960]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:WINDOWSsystem32DRIVERSHDAudBus.sys [2008-04-15 144384]
    R3 HidUsb;Microsoft HID Class Driver; C:WINDOWSsystem32DRIVERShidusb.sys [2008-04-14 10368]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:WINDOWSsystem32driversRtkHDAud.sys [2009-06-16 5095936]
    R3 mouhid;Mouse HID Driver; C:WINDOWSsystem32DRIVERSmouhid.sys [2001-08-17 12160]
    R3 nv;nv; C:WINDOWSsystem32DRIVERSnv4_mini.sys [2009-11-21 10235968]
    R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:WINDOWSsystem32DRIVERSRtenicxp.sys [2008-10-31 117888]
    R3 usbaudio;USB Audio Driver (WDM); C:WINDOWSsystem32driversusbaudio.sys [2008-04-14 60032]
    R3 usbccgp;Microsoft USB Generic Parent Driver; C:WINDOWSsystem32DRIVERSusbccgp.sys [2008-04-14 32128]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-04-14 30208]
    R3 usbhub;USB2 Enabled Hub; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-14 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-04-14 20608]
    S3 aldikpez;aldikpez; C:WINDOWSsystem32driversaldikpez.sys []
    S3 Ambfilt;Ambfilt; C:WINDOWSsystem32driversAmbfilt.sys [2008-08-05 1684736]
    S3 CmBatt;Microsoft AC Adapter Driver; C:WINDOWSsystem32DRIVERSCmBatt.sys [2008-04-14 13952]
    S3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:WINDOWSsystem32driverses1371mp.sys [2001-08-17 40704]
    S3 Monfilt;Monfilt; C:WINDOWSsystem32driversMonfilt.sys [2006-01-04 1389056]
    S3 PCnet;AMD PCNET Compatable Adapter Driver; C:WINDOWSsystem32DRIVERSpcntpci5.sys [2001-08-17 35328]
    S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:WINDOWSsystem32DRIVERSRTL8139.SYS [2008-04-13 20992]
    S3 USBSTOR;USB Mass Storage Driver; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-13 26368]
    S4 sr;System Restore Filter Driver; C:WINDOWSsystem32DRIVERSsr.sys [2008-04-15 73472]
    S4 WS2IFSL;Среда Windows Socket 2.0 поддержки поставщиков не-IFS служб; C:WINDOWSSystem32driversws2ifsl.sys [2008-04-15 12032]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ehRecvr;Media Center Receiver Service; C:WINDOWSeHomeehRecvr.exe [2006-10-09 237568]
    R2 ehSched;Media Center Scheduler Service; C:WINDOWSeHomeehSched.exe [2005-08-05 102912]
    R2 ekrn;ESET Service; C:Program FilesESETESET NOD32 Antivirusekrn.exe [2009-03-19 731840]
    R2 nvsvc;NVIDIA Display Driver Service; C:WINDOWSsystem32nvsvc32.exe [2009-11-20 154216]
    S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2008-07-25 34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2008-07-25 69632]
    S3 EhttpSrv;ESET HTTP Server; C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe [2009-03-19 20680]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:WINDOWSMicrosoft.NETFrameworkv3.0WPFPresentationFontCache.exe [2008-07-29 46104]
    S3 idsvc;Windows CardSpace; c:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication Foundationinfocard.exe [2008-07-29 881664]
    S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
    S4 McrdSvc;Media Center Extender Service; C:WINDOWSehomemcrdsvc.exe [2005-08-05 99328]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication FoundationSMSvcHost.exe [2008-07-29 132096]
    S4 WSearch;Windows Search; C:WINDOWSsystem32SearchIndexer.exe [2008-05-26 439808]


    EOF


    —

  • Автор
    Сообщения
Просмотр 1 сообщения - с 1 по 1 (всего 1)
  • Для ответа в этой теме необходимо авторизоваться.
Войти

Добро пожаловать

На нашем сайте размещены инструкции и программы, которые помогут вам абсолютно бесплатно и самостоятельно удалить навязчивую рекламу, вирусы и трояны.

Поиск

Последние темы

  • Странность в Malwebytes опубликовано Artem225
    5 years, 9 months назад
  • SUSPICIOUS.FakedMBR.1 что делать, помогите!!! опубликовано White
    5 years, 9 months назад
  • Помогите пожалуйста вирус замучил. опубликовано dimazons1233211
    5 years, 11 months назад
  • Замучила реклама опубликовано Данила Беспятов
    6 years назад
  • Замучила реклама опубликовано Марк
    5 years, 10 months назад
  • Вирус S1.video.ru.net опубликовано ludovik
    6 years, 2 months назад
  • Чертов Safe Finder!!!! опубликовано kosta savo
    5 years, 11 months назад
  • ESET блокирует неизвестный сайт , вход на который не осуществлялся. опубликовано trollhamaren
    6 years, 4 months назад

СПАЙВАРЕ РУ

  • О Спайваре Ру
  • Контакты
  • Реклама на сайте
  • Политика конфиденциальности
  • Правила использования

Нужна помощь?

Задайте свой вопрос прямо сейчас кликнув по следующей ссылке Задать вопрос.

Или обратитесь на наш форум, где команда Spyware-ru поможет вам. Узнайте, как попросить о помощи здесь.

Ссылки

  • Инструкции
  • Скачать программы
  • Помощь в удалении вирусов
  • Как вылечить компьютер
Copyright © 2008 - 2024 Spyware-RU.com (en)