Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Подскажите как убрать заставку?
- This topic has 1 ответ, 2 участника, and was last updated 15 years, 11 months назад by
Admin.
-
АвторСообщения
-
28 ноября, 2009 в 8:06 пп #17514
Logfile of random’s system information tool 1.06 (written by random/random)
Run by Администратор at 2009-11-28 21:59:38
Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (34%) free of 27 GB
Total RAM: 2047 MB (60% free)HijackThis download failed
======Scheduled tasks folder======
C:WINDOWStasksUser_Feed_Synchronization-{B0E47A9A-859F-489B-833A-37BC5F662161}.job
C:WINDOWStasksScheduled Update for Ask Toolbar.job
C:WINDOWStasksSystemCheck.job======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll [2009-08-04 1586472][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class — C:Program FilesJavajre1.6.0_07binssv.dll [2008-06-10 509328][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper — C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll [2009-09-12 256112][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO — C:Program FilesGoogleGoogleToolbarNotifier5.4.4525.1752swg.dll [2009-11-18 764912][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch — C:Program FilesGoogleGoogle ToolbarComponentfastsearch_B7C5AC242193BB3E.dll [2009-09-12 458736][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar — C:Program FilesAsk.comGenericAskToolbar.dll [2009-09-30 1182088][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} — Google Toolbar — C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll [2009-09-12 256112]{91397D20-1446-11D4-8AF4-0040CA1127B6} — Яндекс.Бар — C:Program FilesYandexYandexBarIEyndbar.dll [2009-07-24 5586208]
{855F3B16-6D32-4fe6-8A56-BBB695989046} — ICQToolBar — C:Program FilesICQ6ToolbarICQToolBar.dll [2008-06-12 958712]
{17679b4f-3bcc-644b-8f28-a47597fbb905} — Яндекс.Бар (для НевоСофт) — C:Program FilesYandexYandexBarIEbarsbarienevosoftyndbar.dll [2009-10-26 5611272]
{D4027C7F-154A-4066-A1AD-4243D8127440} — Ask Toolbar — C:Program FilesAsk.comGenericAskToolbar.dll [2009-09-30 1182088][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«RTHDCPL»=C:WINDOWSRTHDCPL.EXE [2008-04-10 16861184]
«Alcmtr»=C:WINDOWSALCMTR.EXE [2005-05-03 69632]
«WinampAgent»=C:Program FilesWinampwinampa.exe [2009-07-01 37888]
«RemoteControl»=C:Program FilesCyberLinkPowerDVDPDVDServ.exe [2007-02-07 71216]
«LanguageShortcut»=C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe [2007-02-07 54832]
«HPDJ Taskbar Utility»=C:WINDOWSsystem32spooldriversw32x863hpztsb04.exe [2001-11-19 196608]
«avast!»=C:PROGRA~1ALWILS~1Avast4ashDisp.exe [2009-11-25 81000]
«amd_dc_opt»=C:Program FilesAMDDual-Core Optimizeramd_dc_opt.exe [2008-07-22 77824]
«NeroFilterCheck»=C:WINDOWSsystem32NeroCheck.exe [2001-07-09 155648]
«NevoDRM»=C:ИгрыNevoDRMNevoDRM.exe [2008-12-11 41984][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce]
«IERESETATTRIB»=C:WINDOWSsystem32cmd.exe [2008-07-16 400384][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2008-07-16 17408]
«VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2008-03-23 132096]
«uTorrent»=C:Program FilesuTorrentuTorrent.exe [2009-11-28 314160]
«Skype»=C:Program FilesSkypePhoneSkype.exe [2009-10-09 25623336]
«swg»=C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe [2009-09-12 39408]
«Download Master»=D:ELENAпрограммыDownload Masterdmaster.exe -autorun []
«ICQ»=C:PROGRA~1ICQ6.5ICQ.exe [2009-03-01 172792]C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
McAfee Security Scan.lnk — C:Program FilesMcAfee Security Scan1.0.150SSScheduler.exeC:Documents and SettingsАдминистраторГлавное менюПрограммыАвтозагрузка
Bible Verse.lnk — C:Program FilesBible Verseverse.exe[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAtiExtEvent]
C:WINDOWSsystem32Ati2evxx.dll [2008-02-26 126976][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2007-06-18 133632][HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetwork{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=145
«NoThumbnailCache»=1
«NoSMConfigurePrograms»=1[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«HonorAutoRunSetting»=[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«D:ИгрыPro Evolution Soccer 2009pes2009.exe»=»D:ИгрыPro Evolution Soccer 2009pes2009.exe:*:Enabled:Pro Evolution Soccer 2009»
«C:Program FilesuTorrentuTorrent.exe»=»C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent»
«C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE»=»C:Program FilesMicrosoft OfficeOffice12OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook»
«C:Program FilesICQ6.5ICQ.exe»=»C:Program FilesICQ6.5ICQ.exe:*:Enabled:ICQ6»
«C:Program FilesSkypePlugin ManagerskypePM.exe»=»C:Program FilesSkypePlugin ManagerskypePM.exe:*:Enabled:Skype Extras Manager»
«D:ИгрыPro.Evolution.Soccer.2010-RELOADEDCrackpes2010.exe»=»D:ИгрыPro.Evolution.Soccer.2010-RELOADEDCrackpes2010.exe:*:Enabled:Pro Evolution Soccer 2010»
«C:Documents and SettingsАдминистраторРабочий столpes2010.exe»=»C:Documents and SettingsАдминистраторРабочий столpes2010.exe:*:Enabled:Pro Evolution Soccer 2010»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{f8e56271-b74b-11de-b207-00221521c448}]
shellAutoRuncommand — F:setup.exe======List of files/folders created in the last 1 months======
2009-11-28 21:59:39 —-D—- C:Program Filestrend micro
2009-11-28 21:59:38 —-D—- C:rsit
2009-11-28 20:52:26 —-D—- C:WINDOWSLastGood
2009-11-28 19:15:14 —-SHD—- C:FOUND.007
2009-11-28 19:13:01 —-HD—- C:WINDOWS$NtUninstallKB976098-v2$
2009-11-28 19:12:56 —-HD—- C:WINDOWS$NtUninstallKB973687$
2009-11-21 08:48:40 —-D—- C:Documents and SettingsAll UsersApplication DataMcAfee
2009-11-19 08:48:38 —-D—- C:Program FilesMcAfee Security Scan
2009-11-19 08:48:38 —-D—- C:Documents and SettingsAll UsersApplication DataMcAfee Security Scan
2009-11-19 08:46:42 —-D—- C:Documents and SettingsAll UsersApplication DataNOS
2009-11-17 03:04:31 —-HD—- C:WINDOWS$NtUninstallKB969947$
2009-11-13 15:54:08 —-D—- C:Documents and SettingsАдминистраторApplication DataAskToolbar
2009-11-13 13:24:42 —-D—- C:Documents and SettingsАдминистраторApplication DataNero
2009-11-13 11:50:06 —-D—- C:Documents and SettingsAll UsersApplication DataNero
2009-11-13 11:50:05 —-D—- C:Program FilesCommon FilesNero
2009-11-13 11:45:03 —-D—- C:Program FilesAsk.com
2009-11-12 18:13:52 —-A—- C:WINDOWSNeroDigital.ini
2009-11-12 18:08:28 —-A—- C:WINDOWSsystem32TwnLib20.dll
2009-11-12 18:08:27 —-A—- C:WINDOWSsystem32NeroCheck.exe
2009-11-12 18:08:23 —-D—- C:Program FilesAhead
2009-11-07 13:26:07 —-D—- C:Documents and SettingsAll UsersApplication DataDVD X Studios
2009-11-06 22:48:52 —-D—- C:Documents and SettingsAll UsersApplication DataGameXzone
2009-11-06 22:44:07 —-D—- C:Игры
2009-11-05 20:21:26 —-D—- C:Program FilesAMD
2009-11-05 18:19:01 —-D—- C:Documents and SettingsАдминистраторApplication DataMedia Player Classic
2009-11-05 18:18:15 —-A—- C:WINDOWSsystem32rmoc3260.dll
2009-11-05 18:18:15 —-A—- C:WINDOWSsystem32pndx5032.dll
2009-11-05 18:18:15 —-A—- C:WINDOWSsystem32pndx5016.dll
2009-11-05 18:18:15 —-A—- C:WINDOWSsystem32pncrt.dll
2009-11-05 18:18:14 —-A—- C:WINDOWSsystem32unrar.dll
2009-11-05 18:18:14 —-A—- C:WINDOWSavisplitter.ini
2009-11-05 18:18:13 —-A—- C:WINDOWSsystem32yv12vfw.dll
2009-11-05 18:18:13 —-A—- C:WINDOWSsystem32xvidvfw.dll
2009-11-05 18:18:13 —-A—- C:WINDOWSsystem32xvidcore.dll
2009-11-05 18:18:13 —-A—- C:WINDOWSsystem32qt-dx331.dll
2009-11-05 18:18:13 —-A—- C:WINDOWSsystem32dpl100.dll
2009-11-05 18:18:12 —-A—- C:WINDOWSsystem32divx.dll
2009-11-05 18:18:11 —-A—- C:WINDOWSsystem32ff_vfw.dll.manifest
2009-11-05 18:18:11 —-A—- C:WINDOWSsystem32ff_vfw.dll
2009-11-05 18:18:10 —-D—- C:Program FilesK-Lite Codec Pack
2009-11-02 08:49:00 —-SHD—- C:FOUND.006
2009-11-02 00:02:39 —-HD—- C:WINDOWS$NtUninstallKB961118$
2009-10-30 13:15:06 —-A—- C:WINDOWSsystem32vp6vfw.dll
2009-10-30 12:48:40 —-D—- C:WINDOWSsystem32xlive
2009-10-30 12:48:40 —-D—- C:Program FilesMicrosoft Games for Windows — LIVE
2009-10-30 12:46:16 —-D—- C:Program FilesMSBuild
2009-10-30 12:44:06 —-D—- C:WINDOWSsystem32XPSViewer
2009-10-30 12:44:05 —-D—- C:WINDOWSsystem32en-us
2009-10-30 12:43:50 —-D—- C:Program FilesReference Assemblies
2009-10-30 12:43:08 —-N—- C:WINDOWSsystem32spmsg2.dll
2009-10-30 07:54:59 —-D—- C:Documents and SettingsAll UsersApplication DataKONAMI
2009-10-29 21:46:05 —-A—- C:WINDOWSsystem32aswBoot.exe
2009-10-29 20:38:14 —-SHD—- C:FOUND.005
2009-10-29 19:42:54 —-D—- C:Documents and SettingsАдминистраторApplication DataskypePM
2009-10-29 18:29:38 —-SHD—- C:FOUND.004
2009-10-29 17:28:54 —-D—- C:Program FilesBible Verse======List of files/folders modified in the last 1 months======
2009-11-28 20:47:54 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
2009-11-28 20:42:42 —-A—- C:WINDOWSSchedLgU.Txt
2009-11-17 03:04:44 —-A—- C:WINDOWSimsins.BAK
2009-11-05 20:36:22 —-A—- C:WINDOWSsystem32MRT.exe
2009-11-05 20:21:32 —-RSH—- C:boot.ini======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:WINDOWSsystem32driversAavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:WINDOWSsystem32driversaswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:WINDOWSsystem32driversaswTdi.sys [2009-11-25 48560]
R1 WmiAcpi;Интерфейс управления для ACPI Microsoft Windows; C:WINDOWSsystem32DRIVERSwmiacpi.sys [2008-07-16 8832]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B}; ??C:Program FilesCyberLinkPowerDVD 00.fcl []
R2 aswFsBlk;aswFsBlk; C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:WINDOWSsystem32driversaswMon2.sys [2009-09-15 94160]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:WINDOWSsystem32DRIVERSrspndr.sys [2008-07-08 62848]
R3 AmdLLD;AMD Low Level Device Driver; C:WINDOWSsystem32DRIVERSAmdLLD.sys [2007-06-29 34304]
R3 aswRdr;aswRdr; C:WINDOWSsystem32driversaswRdr.sys [2009-11-25 23120]
R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2008-02-26 2863616]
R3 HDAudBus;Драйвер шины Microsoft UAA для High Definition Audio; C:WINDOWSsystem32DRIVERSHDAudBus.sys [2008-04-15 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:WINDOWSsystem32driversRtkHDAud.sys [2008-04-17 4707328]
R3 MTsensor;ATK0110 ACPI UTILITY; C:WINDOWSsystem32DRIVERSASACPI.sys [2006-02-26 5810]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:WINDOWSsystem32DRIVERSNVENETFD.sys [2007-03-06 58752]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:WINDOWSsystem32DRIVERSnvnetbus.sys [2007-03-06 19968]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-07-16 30336]
R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-15 59520]
R3 usbohci;Драйвер минипорта Microsoft USB открытого хост-контроллера; C:WINDOWSsystem32DRIVERSusbohci.sys [2008-07-16 17152]
S3 usbprint;Класс принтеров Microsoft USB; C:WINDOWSsystem32DRIVERSusbprint.sys [2008-07-16 25856]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-07-16 26368]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2007-06-18 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2007-06-18 82944]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe [2009-11-25 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:WINDOWSsystem32Ati2evxx.exe [2008-02-26 520192]
R2 avast! Antivirus;avast! Antivirus; C:Program FilesAlwil SoftwareAvast4ashServ.exe [2009-11-25 138680]
R2 ICQ Service;ICQ Service; C:Program FilesICQ6ToolbarICQ Service.exe [2008-06-10 222456]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:Program FilesCommon FilesNeroNero BackItUp 4NBService.exe [2009-09-23 935208]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:Program FilesCyberLinkShared filesRichVideo.exe [2007-02-07 173616]
R3 avast! Mail Scanner;avast! Mail Scanner; C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:Program FilesAlwil SoftwareAvast4ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:WINDOWSMicrosoft.NETFrameworkv3.0WPFPresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe [2009-09-12 182768]
S3 idsvc;Windows CardSpace; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication Foundationinfocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication FoundationSMSvcHost.exe [2008-07-29 132096]
EOF
29 ноября, 2009 в 3:33 дп #27219Здравствуйте, добро пожаловать на Spyware-ru форум.
Необходима дополнительная проверка.
Скачайте программу Combofix. Закройте все открытые окна и запустите эту программу.
После выполнения будет создан лог файл, пожалуйста вставьте его в ваш ответ.Примечание: перед использованием Combofix обязательно установите Recovery console. Как это сделать будет описано на странице, ссылку на которую я привёл выше.
-
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.
