Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › последствия порно банера
- This topic has 5 ответов, 2 участника, and was last updated 15 years, 11 months назад by
Ihor.
-
АвторСообщения
-
26 октября, 2009 в 2:23 пп #17314
Доброго времени суток!
Проблема — на компьютере появился порнобаннер. Пользуюсь мозилой и в нижнем правом углу появлялся банер.
После некоторого времени пространство занимаемое банером отображает только ошибку 404 not found. В опере был тот же банер, но потом исчез. Помогите избавитьсяПозавчера выскочил Антивирус про 2010 — пробовал убрать по инструкции с Вашего сайта, не получалось — при перезагрузке он автоматически загружался.Получилось убрать Dr. Web cureit
Logfile of random’s system information tool 1.06 (written by random/random)
Run by Admin at 2009-10-26 16:07:41
Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (41%) free of 10 GB
Total RAM: 511 MB (28% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:07:55, on 26.10.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
C:Program FilesESETESET NOD32 Antivirusekrn.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32svchost.exe
C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSOUNDMAN.EXE
C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe
C:Program FilesCyberlinkShared Filesbrs.exe
C:Program FilesESETESET NOD32 Antivirusegui.exe
C:Program FilesHPHP Software UpdateHPWuSchd2.exe
C:Program FilesiTunesiTunesHelper.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesDownload Masterdmaster.exe
C:Program FilesHPDigital Imagingbinhpqtra08.exe
C:Program FilesTransLitetranslite.exe
C:Program FilesIVT CorporationBlueSoleilBlueSoleil.exe
C:Program FilesIVT CorporationBlueSoleilBlueSoleil VoIP Plugin.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesSkypePlugin ManagerskypePM.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesHPDigital ImagingbinhpqSTE08.exe
C:Program FilesHPDigital Imagingbinhpqbam08.exe
C:Program FilesHPDigital Imagingbinhpqgpc01.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesThe Bat!thebat.exe
D:Мои документыЗагрузкиRSIT.exe
C:Program Filestrend microAdmin.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: (no name) — — (no file)
O1 — Hosts: 79.174.64.209 vkontakte.ru
O1 — Hosts: 79.174.64.209 http://www.vkontakte.ru
O1 — Hosts: 79.174.64.209 win.mail.ru
O1 — Hosts: 79.174.64.209 http://www.win.mail.ru
O1 — Hosts: 79.174.64.209 odnoklassniki.ru
O1 — Hosts: 79.174.64.209 http://www.odnoklassniki.ru
O1 — Hosts: 79.174.64.209 passport.yandex.ru
O1 — Hosts: 79.174.64.209 http://www.passport.yandex.ru
O2 — BHO: HP Print Enhancer — {0347C33E-8762-4905-BF09-768834316C61} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll (file missing)
O2 — BHO: HP Smart BHO Class — {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O3 — Toolbar: DM Bar — {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — C:Program FilesDownload Masterdmbar.dll
O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 — HKLM..Run: [WinampAgent] «C:Program FilesWinampwinampa.exe»
O4 — HKLM..Run: [RemoteControl8] «C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe»
O4 — HKLM..Run: [PDVD8LanguageShortcut] «C:Program FilesCyberLinkPowerDVD8LanguageLanguage.exe»
O4 — HKLM..Run: [BDRegion] C:Program FilesCyberlinkShared Filesbrs.exe
O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
O4 — HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeqttask.exe» -atboottime
O4 — HKLM..Run: [iTunesHelper] «C:Program FilesiTunesiTunesHelper.exe»
O4 — HKLM..Run: [hpqSRMon] C:Program FilesHPDigital ImagingbinhpqSRMon.exe
O4 — HKLM..Run: [Malwarebytes Anti-Malware (reboot)] «C:Program FilesMalwarebytes’ Anti-Malwarembam.exe» /runcleanupscript
O4 — HKLM..Run: [sysgif32] C:WINDOWSTempwpv181255703227.exe
O4 — HKLM..Run: [Regedit32] C:WINDOWSsystem32regedit.exe
O4 — HKLM..Run: [Antivirus Pro 2010] «C:Program FilesAntivirusPro_2010AntivirusPro_2010.exe» /hide
O4 — HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 — HKCU..Run: [Download Master] C:Program FilesDownload Masterdmaster.exe -autorun
O4 — HKCU..Run: [Skype] «C:Program FilesSkype\PhoneSkype.exe» /nosplash /minimized
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,OnceFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,OnceFirstLogonInstall,0 (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
O4 — Global Startup: BlueSoleil.lnk = C:Program FilesIVT CorporationBlueSoleilgprs.exe
O4 — Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe
O4 — Global Startup: Словарь TransLite.lnk = C:Program FilesTransLitetranslite.exe
O4 — Global Startup: Ускоренный запуск Adobe Reader.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~1OFFICE11EXCEL.EXE/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~1OFFICE11REFIEBAR.DLL
O9 — Extra button: Расширенный выбор HP — {DDE87865-83C5-48c4-8357-2F5B1AA84522} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Apple Mobile Device — Apple, Inc. — C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 — Service: BlueSoleil Hid Service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
O23 — Service: Eset HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
O23 — Service: Eset Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Сервис iPod (iPod Service) — Apple Inc. — C:Program FilesiPodbiniPodService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: SiSoftware Deployment Agent Service (SandraAgentSrv) — SiSoftware — C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: Start BT in service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe—
End of file — 10760 bytes======Scheduled tasks folder======
C:WINDOWStasksAppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_printenhancer.dll [2007-11-06 322880][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll [2004-12-14 63136][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — C:PROGRA~1DOWNLO~1dmiehlp.dll [2008-10-24 157696][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll [2007-11-06 542016][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — DM Bar — C:Program FilesDownload Masterdmbar.dll [2007-11-26 180224][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«SoundMan»=C:WINDOWSSOUNDMAN.EXE [2007-04-16 577536]
«NvCplDaemon»=C:WINDOWSsystem32NvCpl.dll [2006-08-11 7630848]
«nwiz»=nwiz.exe /install []
«NvMediaCenter»=NvMCTray.dll,NvTaskbarInit []
«WinampAgent»=C:Program FilesWinampwinampa.exe []
«RemoteControl8″=C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe [2008-03-20 83240]
«PDVD8LanguageShortcut»=C:Program FilesCyberLinkPowerDVD8LanguageLanguage.exe [2007-12-14 50472]
«BDRegion»=C:Program FilesCyberlinkShared Filesbrs.exe [2008-05-19 91432]
«egui»=C:Program FilesESETESET NOD32 Antivirusegui.exe [2008-08-18 1447168]
«HP Software Update»=C:Program FilesHPHP Software UpdateHPWuSchd2.exe [2007-10-14 49152]
«QuickTime Task»=C:Program FilesQuickTimeqttask.exe [2007-10-19 286720]
«iTunesHelper»=C:Program FilesiTunesiTunesHelper.exe [2007-11-02 267048]
«hpqSRMon»=C:Program FilesHPDigital ImagingbinhpqSRMon.exe [2008-08-20 150016]
«Malwarebytes Anti-Malware (reboot)»=C:Program FilesMalwarebytes’ Anti-Malwarembam.exe /runcleanupscript []
«sysgif32″=C:WINDOWSTempwpv181255703227.exe []
«Regedit32″=C:WINDOWSsystem32regedit.exe []
«Antivirus Pro 2010″=C:Program FilesAntivirusPro_2010AntivirusPro_2010.exe /hide [][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«ctfmon.exe»=C:WINDOWSsystem32ctfmon.exe [2008-10-24 30208]
«Download Master»=C:Program FilesDownload Masterdmaster.exe [2009-02-06 3769856]
«Skype»=C:Program FilesSkype\PhoneSkype.exe [2009-10-09 25623336]C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
BlueSoleil.lnk — C:Program FilesIVT CorporationBlueSoleilgprs.exe
HP Digital Imaging Monitor.lnk — C:Program FilesHPDigital Imagingbinhpqtra08.exe
Словарь TransLite.lnk — C:Program FilesTransLitetranslite.exe
Ускоренный запуск Adobe Reader.lnk — C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2008-03-02 133632][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=145
«NoSharedDocuments»=1
«NoSMConfigurePrograms»=1
«ForceClassicControlPanel»=1[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{48c40d8d-bedb-11dd-8a3b-0005ca51501a}]
shellAutoRuncommand — H:Autorun.exe /run
shellShell00command — H:Autorun.exe /run
shellShell01command — H:Autorun.exe /action
shellShell02command — H:Autorun.exe /uninstall======List of files/folders created in the last 1 months======
2009-10-25 09:18:06 —-D—- C:Program FilesCommon FilesSkype
2009-10-25 09:18:02 —-RD—- C:Program FilesSkype
2009-10-25 07:23:50 —-A—- C:Program FilesCommon Filespomesabyc.dll
2009-10-25 07:23:48 —-A—- C:WINDOWStineloxizu.vbs
2009-10-24 23:36:53 —-D—- C:Program Filestrend micro
2009-10-24 23:36:50 —-D—- C:rsit
2009-10-24 22:07:03 —-A—- C:WINDOWSiryvysy.exe
2009-10-24 22:07:02 —-A—- C:WINDOWSsystem32waxoq.bat
2009-10-24 22:07:02 —-A—- C:WINDOWSekonu.exe
2009-10-24 22:07:01 —-A—- C:Program FilesCommon Filesjusisujar.exe
2009-10-24 21:22:27 —-A—- C:Documents and SettingsAll UsersApplication Datasehytacely.com
2009-10-24 21:22:27 —-A—- C:Documents and SettingsAll UsersApplication Dataibela.dll
2009-10-24 21:22:27 —-A—- C:Documents and SettingsAdminApplication Dataratofo.bat
2009-10-24 21:22:27 —-A—- C:Documents and SettingsAdminApplication Datacafex.com
2009-10-24 20:19:10 —-A—- C:WINDOWSsystem32vulyk.com
2009-10-24 20:19:10 —-A—- C:Documents and SettingsAll UsersApplication Datagemi.bat
2009-10-24 20:19:10 —-A—- C:Documents and SettingsAdminApplication Datacida.exe
2009-10-24 20:19:09 —-A—- C:WINDOWSsystem32pehe.com
2009-10-24 19:00:14 —-A—- C:WINDOWSsystem32jehi.dll
2009-10-24 19:00:14 —-A—- C:WINDOWShokacel.vbs
2009-10-24 19:00:14 —-A—- C:WINDOWScemihepote.vbs
2009-10-24 19:00:14 —-A—- C:Program FilesCommon Filescyqadifuc.exe
2009-10-24 18:01:01 —-D—- C:WINDOWSsystem32appmgmt
2009-10-24 16:31:17 —-A—- C:WINDOWSyqita.vbs
2009-10-24 16:31:17 —-A—- C:WINDOWSsystem32ytotu.vbs
2009-10-24 16:31:17 —-A—- C:WINDOWSramuguhyc.vbs
2009-10-24 16:31:17 —-A—- C:WINDOWSbysydyhy.exe
2009-10-24 16:31:17 —-A—- C:WINDOWSbazaci.dll
2009-10-24 16:31:17 —-A—- C:Documents and SettingsAll UsersApplication Datanukog.dll
2009-10-24 16:31:17 —-A—- C:Documents and SettingsAll UsersApplication Datajyleh.com
2009-10-24 16:31:17 —-A—- C:Documents and SettingsAdminApplication Datamuqy.dll
2009-10-24 16:31:17 —-A—- C:Documents and SettingsAdminApplication Dataefogiwa.com======List of files/folders modified in the last 1 months======
2009-10-26 16:07:47 —-D—- C:WINDOWSTemp
2009-10-26 15:33:32 —-D—- C:Documents and SettingsAdminApplication DataSkype
2009-10-26 15:04:57 —-D—- C:Documents and SettingsAdminApplication DataThe Bat!
2009-10-26 14:13:14 —-D—- C:Program FilesMozilla Firefox
2009-10-26 12:33:11 —-D—- C:Documents and SettingsAdminApplication DataTransLite
2009-10-26 11:07:10 —-A—- C:WINDOWSSchedLgU.Txt
2009-10-26 09:48:21 —-D—- C:Documents and SettingsAdminApplication DataskypePM
2009-10-25 17:36:10 —-D—- C:Program FilesESET
2009-10-25 13:37:32 —-AD—- C:Program Files
2009-10-25 12:08:54 —-AD—- C:WINDOWSsystem32
2009-10-25 10:03:01 —-D—- C:WINDOWSsystem32drivers
2009-10-25 09:55:17 —-D—- C:Documents and SettingsAdminApplication DataAldea
2009-10-25 09:55:09 —-D—- C:Documents and SettingsAdminApplication DataAdSubscribe
2009-10-25 09:18:12 —-SHD—- C:WINDOWSInstaller
2009-10-25 09:18:06 —-AD—- C:Program FilesCommon Files
2009-10-25 09:18:01 —-D—- C:Documents and SettingsAll UsersApplication DataSkype
2009-10-25 07:24:18 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
2009-10-25 07:23:49 —-D—- C:WINDOWS
2009-10-24 23:22:17 —-D—- C:Documents and SettingsAdminApplication DataHPAppData
2009-10-11 19:49:16 —-A—- C:WINDOWSIE4 Error Log.txt
2009-10-08 16:48:30 —-D—- C:Documents and SettingsAdminApplication DataMozilla
2009-10-03 16:00:10 —-D—- C:WINDOWSsystem32CatRoot2======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:WINDOWSsystem32DRIVERSeasdrv.sys [2008-08-18 53256]
R1 epfwtdir;epfwtdir; C:WINDOWSsystem32DRIVERSepfwtdir.sys [2008-08-18 34312]
R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-15 40704]
R1 StarOpen;StarOpen; C:WINDOWSsystem32driversStarOpen.sys [2009-04-11 5632]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; ??C:Program FilesCyberLinkPowerDVD8 00.fcl []
R2 eamon;EAMON; C:WINDOWSsystem32DRIVERSeamon.sys [2008-08-18 39944]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:WINDOWSsystem32DRIVERSrspndr.sys [2008-10-11 62848]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2008-01-24 4127488]
R3 BlueletAudio;Bluetooth Audio Service; C:WINDOWSsystem32DRIVERSblueletaudio.sys [2007-06-24 34312]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:WINDOWSsystem32DRIVERSBlueletSCOAudio.sys [2007-06-24 27656]
R3 BT;Bluetooth PAN Network Adapter; C:WINDOWSsystem32DRIVERSbtnetdrv.sys [2007-03-05 18320]
R3 GEARAspiWDM;GEARAspiWDM; C:WINDOWSSystem32DriversGEARAspiWDM.sys [2006-09-19 15664]
R3 nv;nv; C:WINDOWSsystem32DRIVERSnv4_mini.sys [2006-08-11 3958496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:WINDOWSSystem32DriversRootMdm.sys [2008-04-15 5888]
R3 USB_RNDIS;Broadband Cable Modem Remote NDIS Network Device Driver; C:WINDOWSsystem32DRIVERSusb8023.sys [2008-04-15 12800]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-04-15 30208]
R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-15 59520]
R3 usbohci;Драйвер минипорта Microsoft USB открытого хост-контроллера; C:WINDOWSsystem32DRIVERSusbohci.sys [2008-04-15 17152]
R3 VComm;Virtual Serial port driver; C:WINDOWSsystem32DRIVERSVComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:WINDOWSSystem32DriversVcommMgr.sys [2007-03-05 44304]
S1 kbdhid;Драйвер клавиатуры HID; C:WINDOWSsystem32DRIVERSkbdhid.sys [2008-04-14 14720]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:WINDOWSSystem32Driversbtcusb.sys [2007-06-24 38920]
S3 cel90xbe;cel90xbe; ??D:TMPcel90xbe.sys []
S3 HidUsb;Драйвер класса HID Microsoft; C:WINDOWSsystem32DRIVERShidusb.sys [2008-04-14 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:WINDOWSsystem32DRIVERSHPZid412.sys [2007-11-01 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:WINDOWSsystem32DRIVERSHPZipr12.sys [2007-11-01 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:WINDOWSsystem32DRIVERSHPZius12.sys [2007-11-01 21568]
S3 mouhid;Драйвер мыши HID; C:WINDOWSsystem32DRIVERSmouhid.sys [2001-10-19 12160]
S3 SANDRA;SANDRA; ??C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cWNt500x86Sandra.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:WINDOWSsystem32DRIVERSss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:WINDOWSsystem32DRIVERSss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:WINDOWSsystem32DRIVERSss_mdm.sys [2007-05-02 109704]
S3 USBAAPL;Apple Mobile USB Driver; C:WINDOWSSystem32Driversusbaapl.sys [2007-10-31 30464]
S3 usbccgp;Драйвер универсального родительского устройства USB (Microsoft); C:WINDOWSsystem32DRIVERSusbccgp.sys [2008-04-13 32128]
S3 usbprint;Класс принтеров Microsoft USB; C:WINDOWSsystem32DRIVERSusbprint.sys [2008-04-13 25856]
S3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-04-13 15104]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2008-03-02 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2008-03-02 82944]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe [2007-10-31 110592]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:Program FilesIVT CorporationBlueSoleilBTNtService.exe [2007-12-27 166520]
R2 ekrn;Eset Service; C:Program FilesESETESET NOD32 Antivirusekrn.exe [2008-08-18 468224]
R2 hpqddsvc;Служба HP CUE DeviceDiscovery; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
R2 MDM;Machine Debug Manager; C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE [2003-06-19 322120]
R2 Net Driver HPZ12;Net Driver HPZ12; C:WINDOWSSystem32svchost.exe [2008-04-15 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:WINDOWSsystem32nvsvc32.exe [2006-08-11 155715]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:WINDOWSSystem32svchost.exe [2008-04-15 14336]
R2 SandraAgentSrv;SiSoftware Deployment Agent Service; C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe [2008-04-23 98488]
R2 Start BT in service;Start BT in service; C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe [2007-12-27 51816]
R3 hpqcxs08;hpqcxs08; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
R3 iPod Service;Сервис iPod; C:Program FilesiPodbiniPodService.exe [2007-11-02 504104]
S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;Eset HTTP Server; C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe [2008-08-18 19200]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
EOF
1 ноября, 2009 в 5:23 пп #26546Здравствуйте, добро пожаловать на Spyware-ru форум.
Запустите HijackThis, для этого кликните Пуск, Выполнить, введите
C:Program Filestrend microAdmin.exeи нажмите Enter.
Кликните по кнопке Do a system scan only.
Далее отметьте галочкой (слева) следующие строки, если они присутствуют:R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: 79.174.64.209 vkontakte.ru
O1 - Hosts: 79.174.64.209 www.vkontakte.ru
O1 - Hosts: 79.174.64.209 win.mail.ru
O1 - Hosts: 79.174.64.209 www.win.mail.ru
O1 - Hosts: 79.174.64.209 odnoklassniki.ru
O1 - Hosts: 79.174.64.209 www.odnoklassniki.ru
O1 - Hosts: 79.174.64.209 passport.yandex.ru
O1 - Hosts: 79.174.64.209 www.passport.yandex.ru
O4 - HKLM..Run: [sysgif32] C:WINDOWSTempwpv181255703227.exe
O4 - HKLM..Run: [Regedit32] C:WINDOWSsystem32regedit.exe
O4 - HKLM..Run: [Antivirus Pro 2010] "C:Program FilesAntivirusPro_2010AntivirusPro_2010.exe" /hideЗакройте все запущенные программы (включая InternetExplorer) и окна Windows.
Кликните по кнопке Fix checked и подтвердите свои действия выбрав YES.
Перезагрузите компьютер.Скачайте программу Combofix. Закройте все открытые окна и запустите эту программу.
После выполнения будет создан лог файл, пожалуйста вставьте его в ваш ответ.Примечание: перед использованием Combofix обязательно установите Recovery console. Как это сделать будет описано на странице, ссылку на которую я привёл выше.
Так же в ваш ответ вставьте свежий RSIT лог (только log.txt).
4 ноября, 2009 в 7:53 дп #26547Доброго времени суток.
ComboFix 09-11-03.03 — Admin 04.11.2009 9:26.1.1 — NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.511.195 [GMT 2:00]
Running from: c:combofixComboFix.exe
Command switches used :: ComboFix
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is activeWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.c:documents and settingsAdminApplication DataAdSubscribe
c:documents and settingsAdminApplication DataAdSubscribeAdSubscribe.dat
c:documents and settingsAdminApplication DataAdSubscribeFeed.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed1.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed2.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed3.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed4.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed5.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed6.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed7.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed8.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed9.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeedfeed.xml
c:documents and settingsAdminApplication Dataakokynokeh.ban
c:documents and settingsAdminApplication DataAldea
c:documents and settingsAdminApplication Datacafex.com
c:documents and settingsAdminApplication Datacida.exe
c:documents and settingsAdminApplication Datadehegim.pif
c:documents and settingsAdminApplication Dataefogiwa.com
c:documents and settingsAdminApplication Dataheripozuku.lib
c:documents and settingsAdminApplication Datamuqy.dll
c:documents and settingsAdminApplication Dataosigenowus._sy
c:documents and settingsAdminApplication Dataqozivazi.ban
c:documents and settingsAdminApplication Dataratofo.bat
c:documents and settingsAdminApplication Datasefok.scr
c:documents and settingsAdminApplication Datawunero.dl
c:documents and settingsAdminLocal SettingsApplication Databixybi.inf
c:documents and settingsAdminLocal SettingsApplication Databovegohofe.bat
c:documents and settingsAdminLocal SettingsApplication Datadedekyhoq.bin
c:documents and settingsAdminLocal SettingsApplication Datadorejaq.exe
c:documents and settingsAdminLocal SettingsApplication Datairakypig.dll
c:documents and settingsAdminLocal SettingsApplication Datalosuhineki.ban
c:documents and settingsAdminLocal SettingsApplication Dataqajuwi._sy
c:documents and settingsAdminLocal SettingsApplication Dataxogidoput.sys
c:documents and settingsAdminLocal SettingsApplication Dataycoripa.bat
c:documents and settingsAdminLocal SettingsApplication Dataytuvabuja.dll
c:documents and settingsAdminLocal SettingsTemporary Internet Filesbefeguve.inf
c:documents and settingsAdminLocal SettingsTemporary Internet Filesemajasuxi.inf
c:documents and settingsAdminLocal SettingsTemporary Internet Filesizyd.dat
c:documents and settingsAdminLocal SettingsTemporary Internet Filesjunic.reg
c:documents and settingsAdminLocal SettingsTemporary Internet Filessigijir.dat
c:documents and settingsAdminoashdihasidhasuidhiasdhiashdiuasdhasd
c:documents and settingsAll UsersДокументыarabisapy.dll
c:documents and settingsAll UsersДокументыasoqycyw._dl
c:documents and settingsAll UsersДокументыefomonuwu.dl
c:documents and settingsAll UsersДокументыeticipatu.bin
c:documents and settingsAll UsersДокументыixysyzaju.bin
c:documents and settingsAll UsersДокументыoful.scr
c:documents and settingsAll UsersДокументыsaquj.exe
c:documents and settingsAll UsersApplication Datacufupeti.lib
c:documents and settingsAll UsersApplication Datadojetirico._sy
c:documents and settingsAll UsersApplication Dataedepehona.scr
c:documents and settingsAll UsersApplication Datagemi.bat
c:documents and settingsAll UsersApplication Datahofagamu.bin
c:documents and settingsAll UsersApplication Dataibela.dll
c:documents and settingsAll UsersApplication Dataimibadode.sys
c:documents and settingsAll UsersApplication Datajyjorecyri.sys
c:documents and settingsAll UsersApplication Datajyleh.com
c:documents and settingsAll UsersApplication Datanukog.dll
c:documents and settingsAll UsersApplication Dataoquj.reg
c:documents and settingsAll UsersApplication Dataorygykov.ban
c:documents and settingsAll UsersApplication Datasehytacely.com
c:documents and settingsAll UsersApplication Dataupibiba.bin
c:documents and settingsAll UsersApplication Datawyfymymuqo.sys
c:documents and settingsAll UsersApplication Dataywugacaro.bin
c:documents and settingsAll Users„®Єг¬Ґвлkebowasuqy.bat
c:documents and settingsAll Users„®Єг¬Ґвлocyko.vbs
c:documents and settingsAll Users„®Єг¬Ґвлuhecu.reg
c:documents and settingsAll Users„®Єг¬Ґвлujuzale.inf
c:documents and settingsAll Users„®Єг¬Ґвлuqohupocuz.bat
c:program filesCommon Filescyqadifuc.exe
c:program filesCommon Filesdasivy.scr
c:program filesCommon Filesdepa.ban
c:program filesCommon Filesdonijepu.bin
c:program filesCommon Filesenetimamo.bin
c:program filesCommon Filesjowewaxolo.ban
c:program filesCommon Filesjowym.dl
c:program filesCommon Filesjusisujar.exe
c:program filesCommon Filespigoxa.reg
c:program filesCommon Filespomesabyc.dll
c:program filesCommon Filessupyse.scr
c:windowsadoru.reg
c:windowsaxucolyca.reg
c:windowsbazaci.dll
c:windowsboxov._dl
c:windowsbysydyhy.exe
c:windowscemihepote.vbs
c:windowscosugak.sys
c:windowsDelete.bat
c:windowsdyjonojupe._sy
c:windowsehycamin._dl
c:windowsekonu.exe
c:windowselikut._dl
c:windowsfiwonuwe.sys
c:windowshofa.sys
c:windowshokacel.vbs
c:windowsicugiqiqe.reg
c:windowsiryvysy.exe
c:windowskyfufiguni.sys
c:windowsowatomavi.sys
c:windowspidif.sys
c:windowsramuguhyc.vbs
c:windowssystem32cocury._dl
c:windowssystem32defig._dl
c:windowssystem32gapolozyky.ban
c:windowssystem32jehi.dll
c:windowssystem32ovyrem.pif
c:windowssystem32puriced.sys
c:windowssystem32ulelib.dl
c:windowssystem32waxoq.bat
c:windowssystem32xoqimeselu.pif
c:windowssystem32ytotu.vbs
c:windowstineloxizu.vbs
c:windowsvanupetydy._sy
c:windowsvidev.sys
c:windowsvifotanyqa.inf
c:windowswupokasos.ban
c:windowsxulyhed._dl
c:windowsyqita.vbs.
((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
.2009-10-25 07:48 . 2009-10-25 07:48
d
w- c:documents and settingsAdminDoctorWeb
2009-10-25 07:20 . 2009-10-25 07:20 56 —ha-w- c:windowssystem32ezsidmv.dat
2009-10-25 07:18 . 2009-10-25 07:18
d
w- c:program filesCommon FilesSkype
2009-10-25 07:18 . 2009-10-25 07:18
d
r- c:program filesSkype
2009-10-25 05:23 . 2009-10-25 05:23 18257 —-a-w- c:windowssystem32hiwade.dat
2009-10-24 21:36 . 2009-11-03 23:13
d
w- c:program filestrend micro
2009-10-24 21:36 . 2009-10-24 21:37
d
w- C:rsit
2009-10-24 18:19 . 2009-10-24 18:19 10241 —-a-w- c:windowssystem32vulyk.com
2009-10-24 18:19 . 2009-10-24 18:19 14966 —-a-w- c:windowssystem32pehe.com
2009-10-24 14:31 . 2009-10-24 14:31 15240 —-a-w- c:windowssystem32ygeroraji.dat.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 07:35 . 2009-05-03 13:23
d
w- c:documents and settingsAdminApplication DataSkype
2009-11-04 06:42 . 2009-01-26 14:16
d
w- c:documents and settingsAdminApplication DataTransLite
2009-11-03 22:08 . 2009-05-03 13:26
d
w- c:documents and settingsAdminApplication DataskypePM
2009-11-03 22:05 . 2008-12-07 11:31
d
w- c:documents and settingsAdminApplication DataThe Bat!
2009-10-25 15:36 . 2008-11-30 13:43
d
w- c:program filesESET
2009-10-25 07:18 . 2009-05-03 13:23
d
w- c:documents and settingsAll UsersApplication DataSkype
2009-10-25 06:25 . 2009-05-03 14:03 774 —-a-w- c:documents and settingsAdminApplication Dataaldea.dat
2009-10-25 05:24 . 2008-04-15 12:00 77534 —-a-w- c:windowssystem32perfc019.dat
2009-10-25 05:24 . 2008-04-15 12:00 451468 —-a-w- c:windowssystem32perfh019.dat
2009-10-24 21:22 . 2008-11-30 16:11
d
w- c:documents and settingsAdminApplication DataHPAppData
2009-10-24 19:22 . 2009-10-24 19:22 10504 —-a-w- c:program filesCommon Filessugyty.db
2009-10-24 18:19 . 2009-10-24 18:19 15737 —-a-w- c:documents and settingsAll UsersApplication Dataxini.dat
2009-09-11 05:59 . 2009-09-11 05:59
d
w- c:documents and settingsAdminApplication DataU3
2009-08-26 11:15 . 2009-08-26 06:37 19539 —-a-w- c:windowshpqins13.dat
2009-08-20 10:03 . 2009-08-20 10:03 17 —-a-w- c:documents and settingsAdminApplication Datagrf.dat
2003-06-20 22:26 . 2009-01-10 06:58 64591 —-a-r- c:program filesWMV9VCM.chm
2003-06-20 22:26 . 2009-01-10 06:58 12347 —-a-r- c:program filesWMV9VCM_readme.htm
2003-06-10 22:28 . 2009-01-10 06:58 666 —-a-r- c:program filesqPAL-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 661 —-a-r- c:program filesqNTSC-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesPAL-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesNTSC-vbr.wv9
2003-06-09 10:21 . 2009-01-10 06:58 21158 —-a-r- c:program fileslicense.txt
2003-04-07 12:06 . 2009-01-10 06:58 665 —-a-r- c:program filesFilm-320×240-vbr.wv9
2003-04-07 12:06 . 2009-01-10 06:58 659 —-a-r- c:program filesFilm-640×480-vbr.wv9
2003-04-07 12:06 . 2009-01-10 06:58 377 —-a-r- c:program filesFilm-1280×720-vbr.wv9
.
Sigcheck
[-] 2008-10-24 . 6A104BA98D99D53AB0C91825CE659FC6 . 361600 . . [5.1.2600.5625] . . c:windowssystem32driverstcpip.sys[-] 2008-10-24 . 13548C87ADEFC5980AC4F0F50AC78396 . 80584 . . [7.2.6001.784] . . c:windowssystem32wuauclt.exe
[-] 2008-10-24 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:windowssystem32user32.dll
[-] 2008-10-24 . 8054F449106C9DA48AEDC82B05BA2B8E . 952832 . . [7.00.6000.20900] . . c:windowssystem32wininet.dll
[-] 2008-10-24 . 89F87645A856F6712E6225079B7931F4 . 1721344 . . [6.00.2900.5512] . . c:windowsexplorer.exe
[-] 2008-10-24 . E52BB415E3A7106E0308A6EE75219F30 . 1571840 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll
[-] 2008-10-24 . 08DD489E663B992B188166951AD131E0 . 30208 . . [5.1.2600.5512] . . c:windowssystem32ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
«Download Master»=»c:program filesDownload Masterdmaster.exe» [2009-02-06 3769856]
«Skype»=»c:program filesSkypePhoneSkype.exe» [2009-10-09 25623336][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
«NvCplDaemon»=»c:windowssystem32NvCpl.dll» [2006-08-11 7630848]
«RemoteControl8″=»c:program filesCyberLinkPowerDVD8PDVD8Serv.exe» [2008-03-20 83240]
«PDVD8LanguageShortcut»=»c:program filesCyberLinkPowerDVD8LanguageLanguage.exe» [2007-12-14 50472]
«BDRegion»=»c:program filesCyberlinkShared Filesbrs.exe» [2008-05-19 91432]
«egui»=»c:program filesESETESET NOD32 Antivirusegui.exe» [2008-08-18 1447168]
«HP Software Update»=»c:program filesHPHP Software UpdateHPWuSchd2.exe» [2007-10-14 49152]
«QuickTime Task»=»c:program filesQuickTimeqttask.exe» [2007-10-19 286720]
«iTunesHelper»=»c:program filesiTunesiTunesHelper.exe» [2007-11-02 267048]
«hpqSRMon»=»c:program filesHPDigital ImagingbinhpqSRMon.exe» [2008-08-20 150016]
«SoundMan»=»SOUNDMAN.EXE» — c:windowsSOUNDMAN.EXE [2007-04-16 577536]
«nwiz»=»nwiz.exe» — c:windowssystem32nwiz.exe [2006-08-11 1519616]
«NvMediaCenter»=»NvMCTray.dll» — c:windowssystem32nvmctray.dll [2006-08-11 86016][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=»c:windowssystem32CTFMON.EXE» [2008-10-24 30208][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
«IE7_011″=»shell32» [X]
«ZZZZ2_FirstLogonSetting»=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]
«IE7_012″=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]c:documents and settingsAll Usersѓ« ў®Ґ ¬ҐоЏа®Ја ¬¬лЂўв®§ Јаг§Є
BlueSoleil.lnk — c:program filesIVT CorporationBlueSoleilgprs.exe [2007-12-27 43608]
HP Digital Imaging Monitor.lnk — c:program filesHPDigital Imagingbinhpqtra08.exe [2007-10-14 214360]
‘«®ў ам TransLite.lnk — c:program filesTransLitetranslite.exe [2009-1-22 761856]
“бЄ®аҐл© § ЇгбЄ Adobe Reader.lnk — c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2004-12-14 29696][HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)[HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
«FirewallOverride»=dword:00000001
«UpdatesOverride»=dword:00000001
«AntiVirusOverride»=dword:00000001[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
«EnableFirewall»= 0 (0x0)[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
«%windir%\Network Diagnostic\xpnetdiag.exe»=
«%windir%\system32\sessmgr.exe»=R1 epfwtdir;epfwtdir;c:windowssystem32driversepfwtdir.sys [01.07.2008 8:04 34312]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:program filesCyberLinkPowerDVD800.fcl [15.05.2008 11:07 61424]
R2 ekrn;Eset Service;c:program filesESETESET NOD32 Antivirusekrn.exe [18.08.2008 12:25 468224]
R2 SandraAgentSrv;SiSoftware Deployment Agent Service;c:program filesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe [30.11.2008 16:58 98488]
R2 Start BT in service;Start BT in service;c:program filesIVT CorporationBlueSoleilStartSkysolSvc.exe [27.12.2007 14:39 51816]
S3 cel90xbe;cel90xbe;??d:tmpcel90xbe.sys —> d:tmpcel90xbe.sys [?]— Other Services/Drivers In Memory —
*NewlyCreated* — MBR
*NewlyCreated* — PROCEXP113
*NewlyCreated* — SRSERVICE
*Deregistered* — mbr
*Deregistered* — PROCEXP113[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the ‘Scheduled Tasks’ folder2009-10-26 c:windowsTasksAppleSoftwareUpdate.job
— c:program filesApple Software UpdateSoftwareUpdate.exe [2007-08-29 12:57]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.yandex.ru/
IE: &Экспорт в Microsoft Excel — c:progra~1MICROS~1OFFICE11EXCEL.EXE/3000
IE: Закачать ВСЕ при помощи Download Master — c:program filesDownload Masterdmieall.htm
IE: Закачать при помощи Download Master — c:program filesDownload Masterdmie.htm
IE: {{8DAE90AD-4583-4977-9DD4-4360F7A45C74} — c:program filesDownload Masterdmaster.exe
FF — ProfilePath — c:documents and settingsAdminApplication DataMozillaFirefoxProfilesaxxzg6s7.default
FF — prefs.js: network.proxy.type — 2
FF — plugin: c:program filesOperaprogrampluginsnpdm.dll—- FIREFOX POLICIES —-
FF — user.js: capability.policy.policynames — localfilelinks
FF — user.js: capability.policy.localfilelinks.sites — hxxp://speed.travian.ae http://speed2.travian.ae http://s1.travian.ae http://s2.travian.ae http://s3.travian.ae http://s4.travian.ae http://s5.travian.ae http://s6.travian.ae http://s7.travian.ae http://s8.travian.ae http://s9.travian.ae http://s10.travian.ae http://s11.travian.ae http://s12.travian.ae http://s13.travian.ae http://s14.travian.ae http://s15.travian.ae http://s16.travian.ae http://s17.travian.ae http://s18.travian.ae http://s19.travian.ae http://s20.travian.ae http://s21.travian.ae http://s22.travian.ae http://s23.travian.ae http://s24.travian.ae http://s25.travian.ae http://s26.travian.ae http://s27.travian.ae http://s28.travian.ae http://s29.travian.ae http://s30.travian.ae http://s31.travian.ae http://s32.travian.ae http://s33.travian.ae http://s34.travian.ae http://s35.travian.ae http://speed.travian.asia http://speed2.travian.asia http://s1.travian.asia http://s2.travian.asia http://s3.travian.asia http://s4.travian.asia http://s5.travian.asia http://s6.travian.asia http://s7.travian.asia http://s8.travian.asia http://s9.travian.asia http://s10.travian.asia http://speed.travian.ba http://speed2.travian.ba http://s1.travian.ba http://s2.travian.ba http://s3.travian.ba http://s4.travian.ba http://s5.travian.ba http://s6.travian.ba http://s7.travian.ba http://s8.travian.ba http://s9.travian.ba http://s10.travian.ba http://speed.travian.bg http://speed2.travian.bg http://s1.travian.bg http://s2.travian.bg http://s3.travian.bg http://s4.travian.bg http://s5.travian.bg http://s6.travian.bg http://s7.travian.bg http://s8.travian.bg http://s9.travian.bg http://s10.travian.bg http://speed.travian.cl http://speed2.travian.cl http://s1.travian.cl http://s2.travian.cl http://s3.travian.cl http://s4.travian.cl http://s5.travian.cl http://s6.travian.cl http://s7.travian.cl http://s8.travian.cl http://s9.travian.cl http://s10.travian.cl http://speed.travian.cn http://speed2.travian.cn http://s1.travian.cn http://s2.travian.cn http://s3.travian.cn http://s4.travian.cn http://s5.travian.cn http://s6.travian.cn http://s7.travian.cn http://s8.travian.cn http://s9.travian.cn http://s10.travian.cn http://s11.travian.cn http://s12.travian.cn http://s13.travian.cn http://s14.travian.cn http://s15.travian.cn http://s16.travian.cn http://s17.travian.cn http://s18.travian.cn http://s19.travian.cn http://s20.travian.cn http://speed.travian.co.ee http://speed2.travian.co.ee http://s1.travian.co.ee http://s2.travian.co.ee http://s3.travian.co.ee http://s4.travian.co.ee http://s5.travian.co.ee http://s6.travian.co.ee http://s7.travian.co.ee http://s8.travian.co.ee http://s9.travian.co.ee http://s10.travian.co.ee http://s11.travian.co.ee http://s12.travian.co.ee http://s13.travian.co.ee http://s14.travian.co.ee http://s15.travian.co.ee http://s16.travian.co.ee http://s17.travian.co.ee http://s18.travian.co.ee http://s19.travian.co.ee http://s20.travian.co.ee http://speed.travian.co.id http://speed2.travian.co.id http://s1.travian.co.id http://s2.travian.co.id http://s3.travian.co.id http://s4.travian.co.id http://s5.travian.co.id http://s6.travian.co.id http://s7.travian.co.id http://s8.travian.co.id http://s9.travian.co.id http://s10.travian.co.id http://speed.travian.co.il http://speed2.travian.co.il http://s1.travian.co.il http://s2.travian.co.il http://s3.travian.co.il http://s4.travian.co.il http://s5.travian.co.il http://s6.travian.co.il http://s7.travian.co.il http://s8.travian.co.il http://s9.travian.co.il http://s10.travian.co.il http://speed.travian.co.kr http://speed2.travian.co.kr http://s1.travian.co.kr http://s2.travian.co.kr http://s3.travian.co.kr http://s4.travian.co.kr http://s5.travian.co.kr http://s6.travian.co.kr http://s7.travian.co.kr http://s8.travian.co.kr http://s9.travian.co.kr http://s10.travian.co.kr http://speed.travian.co.nz http://speed2.travian.co.nz http://s1.travian.co.nz http://s2.travian.co.nz http://s3.travian.co.nz http://s4.travian.co.nz http://s5.travian.co.nz http://s6.travian.co.nz http://s7.travian.co.nz http://s8.travian.co.nz http://s9.travian.co.nz http://s10.travian.co.nz http://speed.travian.co.uk http://speed2.travian.co.uk http://s1.travian.co.uk http://s2.travian.co.uk http://s3.travian.co.uk http://s4.travian.co.uk http://s5.travian.co.uk http://s6.travian.co.uk http://s7.travian.co.uk http://s8.travian.co.uk http://s9.travian.co.uk http://s10.travian.co.uk http://speed.travian.co.za http://speed2.travian.co.za http://s1.travian.co.za http://s2.travian.co.za http://s3.travian.co.za http://s4.travian.co.za http://s5.travian.co.za http://s6.travian.co.za http://s7.travian.co.za http://s8.travian.co.za http://s9.travian.co.za http://s10.travian.co.za http://speed.travian.com http://speed2.travian.com http://s1.travian.com http://s2.travian.com http://s3.travian.com http://s4.travian.com http://s5.travian.com http://s6.travian.com http://s7.travian.com http://s8.travian.com http://s9.travian.com http://s10.travian.com http://s11.travian.com http://s12.travian.com http://s13.travian.com http://s14.travian.com http://s15.travian.com http://s16.travian.com http://s17.travian.com http://s18.travian.com http://s19.travian.com http://s20.travian.com http://speed.travian.com.ar http://speed2.travian.com.ar http://s1.travian.com.ar http://s2.travian.com.ar http://s3.travian.com.ar http://s4.travian.com.ar http://s5.travian.com.ar http://s6.travian.com.ar http://s7.travian.com.ar http://s8.travian.com.ar http://s9.travian.com.ar http://s10.travian.com.ar http://speed.travian.com.au http://speed2.travian.com.au http://s1.travian.com.au http://s2.travian.com.au http://s3.travian.com.au http://s4.travian.com.au http://s5.travian.com.au http://s6.travian.com.au http://s7.travian.com.au http://s8.travian.com.au http://s9.travian.com.au http://s10.travian.com.au http://speed.travian.com.br http://speed2.travian.com.br http://s1.travian.com.br http://s2.travian.com.br http://s3.travian.com.br http://s4.travian.com.br http://s5.travian.com.br http://s6.travian.com.br http://s7.travian.com.br http://s8.travian.com.br http://s9.travian.com.br http://s10.travian.com.br http://s11.travian.com.br http://s12.travian.com.br http://s13.travian.com.br http://s14.travian.com.br http://s15.travian.com.br http://s16.travian.com.br http://s17.travian.com.br http://s18.travian.com.br http://s19.travian.com.br http://s20.travian.com.br http://speed.travian.com.hr http://speed2.travian.com.hr http://s1.travian.com.hr http://s2.travian.com.hr http://s3.travian.com.hr http://s4.travian.com.hr http://s5.travian.com.hr http://s6.travian.com.hr http://s7.travian.com.hr http://s8.travian.com.hr http://s9.travian.com.hr http://s10.travian.com.hr http://speed.travian.com.mx http://speed2.travian.com.mx http://s1.travian.com.mx http://s2.travian.com.mx http://s3.travian.com.mx http://s4.travian.com.mx http://s5.travian.com.mx http://s6.travian.com.mx http://s7.travian.com.mx http://s8.travian.com.mx http://s9.travian.com.mx http://s10.travian.com.mx http://speed.travian.com.my http://speed2.travian.com.my http://s1.travian.com.my http://s2.travian.com.my http://s3.travian.com.my http://s4.travian.com.my http://s5.travian.com.my http://s6.travian.com.my http://s7.travian.com.my http://s8.travian.com.my http://s9.travian.com.my http://s10.travian.com.my http://speed.travian.com.tr http://speed2.travian.com.tr http://s1.travian.com.tr http://s2.travian.com.tr http://s3.travian.com.tr http://s4.travian.com.tr http://s5.travian.com.tr http://s6.travian.com.tr http://s7.travian.com.tr http://s8.travian.com.tr http://s9.travian.com.tr http://s10.travian.com.tr http://s11.travian.com.tr http://s12.travian.com.tr http://s13.travian.com.tr http://s14.travian.com.tr http://s15.travian.com.tr http://s16.travian.com.tr http://s17.travian.com.tr http://s18.travian.com.tr http://s19.travian.com.tr http://s20.travian.com.tr http://s21.travian.com.tr http://s22.travian.com.tr http://s23.travian.com.tr http://s24.travian.com.tr http://s25.travian.com.tr http://s26.travian.com.tr http://s27.travian.com.tr http://s28.travian.com.tr http://s29.travian.com.tr http://s30.travian.com.tr http://speed.travian.com.ua http://speed2.travian.com.ua http://s1.travian.com.ua http://s2.travian.com.ua http://s3.travian.com.ua http://s4.travian.com.ua http://s5.travian.com.ua http://s6.travian.com.ua http://s7.travian.com.ua http://s8.travian.com.ua http://s9.travian.com.ua http://s10.travian.com.ua http://speed.travian.com.vn http://speed2.travian.com.vn http://s1.travian.com.vn http://s2.travian.com.vn http://s3.travian.com.vn http://s4.travian.com.vn http://s5.travian.com.vn http://s6.travian.com.vn http://s7.travian.com.vn http://s8.travian.com.vn http://s9.travian.com.vn http://s10.travian.com.vn http://speed.travian.cz http://speed2.travian.cz http://s1.travian.cz http://s2.travian.cz http://s3.travian.cz http://s4.travian.cz http://s5.travian.cz http://s6.travian.cz http://s7.travian.cz http://s8.travian.cz http://s9.travian.cz http://s10.travian.cz http://s11.travian.cz http://s12.travian.cz http://s13.travian.cz http://s14.travian.cz http://s15.travian.cz http://s16.travian.cz http://s17.travian.cz http://s18.travian.cz http://s19.travian.cz http://s20.travian.cz http://speed.travian.dk http://speed2.travian.dk http://s1.travian.dk http://s2.travian.dk http://s3.travian.dk http://s4.travian.dk http://s5.travian.dk http://s6.travian.dk http://s7.travian.dk http://s8.travian.dk http://s9.travian.dk http://s10.travian.dk http://speed.travian.fi http://speed2.travian.fi http://s1.travian.fi http://s2.travian.fi http://s3.travian.fi http://s4.travian.fi http://s5.travian.fi http://s6.travian.fi http://s7.travian.fi http://s8.travian.fi http://s9.travian.fi http://s10.travian.fi http://speed.travian.fr http://speed2.travian.fr http://s1.travian.fr http://s2.travian.fr http://s3.travian.fr http://s4.travian.fr http://s5.travian.fr http://s6.travian.fr http://s7.travian.fr http://s8.travian.fr http://s9.travian.fr http://s10.travian.fr http://s11.travian.fr http://s12.travian.fr http://s13.travian.fr http://s14.travian.fr http://s15.travian.fr http://s16.travian.fr http://s17.travian.fr http://s18.travian.fr http://s19.travian.fr http://s20.travian.fr http://speed.travian.gr http://speed2.travian.gr http://s1.travian.gr http://s2.travian.gr http://s3.travian.gr http://s4.travian.gr http://s5.travian.gr http://s6.travian.gr http://s7.travian.gr http://s8.travian.gr http://s9.travian.gr http://s10.travian.gr http://speed.travian.hk http://speed2.travian.hk http://s1.travian.hk http://s2.travian.hk http://s3.travian.hk http://s4.travian.hk http://s5.travian.hk http://s6.travian.hk http://s7.travian.hk http://s8.travian.hk http://s9.travian.hk http://s10.travian.hk http://speed.travian.hu http://speed2.travian.hu http://s1.travian.hu http://s2.travian.hu http://s3.travian.hu http://s4.travian.hu http://s5.travian.hu http://s6.travian.hu http://s7.travian.hu http://s8.travian.hu http://s9.travian.hu http://s10.travian.hu http://speed.travian.in http://speed2.travian.in http://s1.travian.in http://s2.travian.in http://s3.travian.in http://s4.travian.in http://s5.travian.in http://s6.travian.in http://s7.travian.in http://s8.travian.in http://s9.travian.in http://s10.travian.in http://speed.travian.ir http://speed2.travian.ir http://s1.travian.ir http://s2.travian.ir http://s3.travian.ir http://s4.travian.ir http://s5.travian.ir http://s6.travian.ir http://s7.travian.ir http://s8.travian.ir http://s9.travian.ir http://s10.travian.ir http://speed.travian.it http://speed2.travian.it http://s1.travian.it http://s2.travian.it http://s3.travian.it http://s4.travian.it http://s5.travian.it http://s6.travian.it http://s7.travian.it http://s8.travian.it http://s9.travian.it http://s10.travian.it http://s11.travian.it http://s12.travian.it http://s13.travian.it http://s14.travian.it http://s15.travian.it http://s16.travian.it http://s17.travian.it http://s18.travian.it http://s19.travian.it http://s20.travian.it http://speed.travian.jp http://speed2.travian.jp http://s1.travian.jp http://s2.travian.jp http://s3.travian.jp http://s4.travian.jp http://s5.travian.jp http://s6.travian.jp http://s7.travian.jp http://s8.travian.jp http://s9.travian.jp http://s10.travian.jp http://speed.travian.lt http://speed2.travian.lt http://s1.travian.lt http://s2.travian.lt http://s3.travian.lt http://s4.travian.lt http://s5.travian.lt http://s6.travian.lt http://s7.travian.lt http://s8.travian.lt http://s9.travian.lt http://s10.travian.lt http://speed.travian.lv http://speed2.travian.lv http://s1.travian.lv http://s2.travian.lv http://s3.travian.lv http://s4.travian.lv http://s5.travian.lv http://s6.travian.lv http://s7.travian.lv http://s8.travian.lv http://s9.travian.lv http://s10.travian.lv http://speed.travian.net http://speed2.travian.net http://s1.travian.net http://s2.travian.net http://s3.travian.net http://s4.travian.net http://s5.travian.net http://s6.travian.net http://s7.travian.net http://s8.travian.net http://s9.travian.net http://s10.travian.net http://speed.travian.nl http://speed2.travian.nl http://s1.travian.nl http://s2.travian.nl http://s3.travian.nl http://s4.travian.nl http://s5.travian.nl http://s6.travian.nl http://s7.travian.nl http://s8.travian.nl http://s9.travian.nl http://s10.travian.nl http://speed.travian.no http://speed2.travian.no http://s1.travian.no http://s2.travian.no http://s3.travian.no http://s4.travian.no http://s5.travian.no http://s6.travian.no http://s7.travian.no http://s8.travian.no http://s9.travian.no http://s10.travian.no http://speed.travian.ph http://speed2.travian.ph http://s1.travian.ph http://s2.travian.ph http://s3.travian.ph http://s4.travian.ph http://s5.travian.ph http://s6.travian.ph http://s7.travian.ph http://s8.travian.ph http://s9.travian.ph http://s10.travian.ph http://speed.travian.pk http://speed2.travian.pk http://s1.travian.pk http://s2.travian.pk http://s3.travian.pk http://s4.travian.pk http://s5.travian.pk http://s6.travian.pk http://s7.travian.pk http://s8.travian.pk http://s9.travian.pk http://s10.travian.pk http://speed.travian.pl http://speed2.travian.pl http://s1.travian.pl http://s2.travian.pl http://s3.travian.pl http://s4.travian.pl http://s5.travian.pl http://s6.travian.pl http://s7.travian.pl http://s8.travian.pl http://s9.travian.pl http://s10.travian.pl http://s11.travian.pl http://s12.travian.pl http://s13.travian.pl http://s14.travian.pl http://s15.travian.pl http://s16.travian.pl http://s17.travian.pl http://s18.travian.pl http://s19.travian.pl http://s20.travian.pl http://speed.travian.pt http://speed2.travian.pt http://s1.travian.pt http://s2.travian.pt http://s3.travian.pt http://s4.travian.pt http://s5.travian.pt http://s6.travian.pt http://s7.travian.pt http://s8.travian.pt http://s9.travian.pt http://s10.travian.pt http://s11.travian.pt http://s12.travian.pt http://s13.travian.pt http://s14.travian.pt http://s15.travian.pt http://s16.travian.pt http://s17.travian.pt http://s18.travian.pt http://s19.travian.pt http://s20.travian.pt http://speed.travian.ro http://speed2.travian.ro http://s1.travian.ro http://s2.travian.ro http://s3.travian.ro http://s4.travian.ro http://s5.travian.ro http://s6.travian.ro http://s7.travian.ro http://s8.travian.ro http://s9.travian.ro http://s10.travian.ro http://speed.travian.rs http://speed2.travian.rs http://s1.travian.rs http://s2.travian.rs http://s3.travian.rs http://s4.travian.rs http://s5.travian.rs http://s6.travian.rs http://s7.travian.rs http://s8.travian.rs http://s9.travian.rs http://s10.travian.rs http://speed.travian.ru http://speed2.travian.ru http://s1.travian.ru http://s2.travian.ru http://s3.travian.ru http://s4.travian.ru http://s5.travian.ru http://s6.travian.ru http://s7.travian.ru http://s8.travian.ru http://s9.travian.ru http://s10.travian.ru http://s11.travian.ru http://s12.travian.ru http://s13.travian.ru http://s14.travian.ru http://s15.travian.ru http://s16.travian.ru http://s17.travian.ru http://s18.travian.ru http://s19.travian.ru http://s20.travian.ru http://speed.travian.se http://speed2.travian.se http://s1.travian.se http://s2.travian.se http://s3.travian.se http://s4.travian.se http://s5.travian.se http://s6.travian.se http://s7.travian.se http://s8.travian.se http://s9.travian.se http://s10.travian.se http://speed.travian.si http://speed2.travian.si http://s1.travian.si http://s2.travian.si http://s3.travian.si http://s4.travian.si http://s5.travian.si http://s6.travian.si http://s7.travian.si http://s8.travian.si http://s9.travian.si http://s10.travian.si http://speed.travian.sk http://speed2.travian.sk http://s1.travian.sk http://s2.travian.sk http://s3.travian.sk http://s4.travian.sk http://s5.travian.sk http://s6.travian.sk http://s7.travian.sk http://s8.travian.sk http://s9.travian.sk http://s10.travian.sk http://speed.travian.us http://speed2.travian.us http://s1.travian.us http://s2.travian.us http://s3.travian.us http://s4.travian.us http://s5.travian.us http://s6.travian.us http://s7.travian.us http://s8.travian.us http://s9.travian.us http://s10.travian.us http://s11.travian.us http://s12.travian.us http://s13.travian.us http://s14.travian.us http://s15.travian.us http://s16.travian.us http://s17.travian.us http://s18.travian.us http://s19.travian.us http://s20.travian.us http://www.travian.at http://speed.travian.at http://speed2.travian.at http://www.travian.de http://speed.travian.de http://speed2.travian.de http://welt1.travian.de http://welt2.travian.de http://welt3.travian.de http://welt4.travian.de http://welt5.travian.de http://welt6.travian.de http://welt7.travian.de http://welt8.travian.de http://welt9.travian.de http://welt10.travian.de http://www.travian.org http://speed.travian.org http://speed2.travian.org
FF — user.js: capability.policy.localfilelinks.checkloaduri.enabled — allAccessc:program filesMozilla Firefoxgreprefssecurity-prefs.js — pref(«security.ssl3.rsa_seed_sha», true);
.
— — — — ORPHANS REMOVED — — — —HKLM-Run-WinampAgent — c:program filesWinampwinampa.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) — c:program filesMalwarebytes’ Anti-Malwarembam.exe
AddRemove-SimCity 4 Rush Hour — e:_dcdf7~1GamesA417~1SIMCIT~1UNWISE.EXE
AddRemove-{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1 — d:tmpRar$EX01.547NOD32-PATCHObsoleteunins000.exe**************************************************************************
catchme 0.3.1398 W2K/XP/Vista — rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-04 09:37
Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sprs.sys >>UNKNOWN [0x82391938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.netatapi.sys @ 0x0 0x0 bytes
Driveratapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_POWER ] 0xA73C != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF8369B40 atapi.sys
Driveratapi IRP hooks detected !**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001Services{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
«ImagePath»=»??c:program filesCyberLinkPowerDVD800.fcl»
.
DLLs Loaded Under Running Processes
— — — — — — — > ‘winlogon.exe'(732)
c:windowssystem32SETUPAPI.dll
c:windowssystem32cscui.dll— — — — — — — > ‘lsass.exe'(788)
c:windowssystem32SETUPAPI.dll
.
Completion time: 2009-11-04 9:41
ComboFix-quarantined-files.txt 2009-11-04 07:41Pre-Run: 4 126 130 176 байт свободно
Post-Run: 4 105 576 448 байт свободно4 ноября, 2009 в 7:56 дп #26549Logfile of random’s system information tool 1.06 (written by random/random)
Run by Admin at 2009-11-04 09:53:53
Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (39%) free of 10 GB
Total RAM: 511 MB (37% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:00, on 04.11.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
C:Program FilesESETESET NOD32 Antivirusekrn.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSOUNDMAN.EXE
C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe
C:Program FilesCyberlinkShared Filesbrs.exe
C:Program FilesESETESET NOD32 Antivirusegui.exe
C:Program FilesHPHP Software UpdateHPWuSchd2.exe
C:Program FilesiTunesiTunesHelper.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesDownload Masterdmaster.exe
C:Program FilesHPDigital Imagingbinhpqtra08.exe
C:Program FilesTransLitetranslite.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesSkypePlugin ManagerskypePM.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesHPDigital ImagingbinhpqSTE08.exe
C:Program FilesHPDigital Imagingbinhpqbam08.exe
C:Program FilesHPDigital Imagingbinhpqgpc01.exe
C:WINDOWSexplorer.exe
D:Мои документыЗагрузкиRSIT.exe
C:Program Filestrend microAdmin.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
O2 — BHO: HP Print Enhancer — {0347C33E-8762-4905-BF09-768834316C61} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll (file missing)
O2 — BHO: HP Smart BHO Class — {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O3 — Toolbar: DM Bar — {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — C:Program FilesDownload Masterdmbar.dll
O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 — HKLM..Run: [RemoteControl8] «C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe»
O4 — HKLM..Run: [PDVD8LanguageShortcut] «C:Program FilesCyberLinkPowerDVD8LanguageLanguage.exe»
O4 — HKLM..Run: [BDRegion] C:Program FilesCyberlinkShared Filesbrs.exe
O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
O4 — HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeqttask.exe» -atboottime
O4 — HKLM..Run: [iTunesHelper] «C:Program FilesiTunesiTunesHelper.exe»
O4 — HKLM..Run: [hpqSRMon] C:Program FilesHPDigital ImagingbinhpqSRMon.exe
O4 — HKCU..Run: [Download Master] C:Program FilesDownload Masterdmaster.exe -autorun
O4 — HKCU..Run: [Skype] «C:Program FilesSkypePhoneSkype.exe» /nosplash /minimized
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
O4 — Global Startup: BlueSoleil.lnk = C:Program FilesIVT CorporationBlueSoleilgprs.exe
O4 — Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe
O4 — Global Startup: Словарь TransLite.lnk = C:Program FilesTransLitetranslite.exe
O4 — Global Startup: Ускоренный запуск Adobe Reader.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~1OFFICE11EXCEL.EXE/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~1OFFICE11REFIEBAR.DLL
O9 — Extra button: Расширенный выбор HP — {DDE87865-83C5-48c4-8357-2F5B1AA84522} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Apple Mobile Device — Apple, Inc. — C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 — Service: BlueSoleil Hid Service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
O23 — Service: Eset HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
O23 — Service: Eset Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Сервис iPod (iPod Service) — Apple Inc. — C:Program FilesiPodbiniPodService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: SiSoftware Deployment Agent Service (SandraAgentSrv) — SiSoftware — C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: Start BT in service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe—
End of file — 8621 bytes8 ноября, 2009 в 4:08 пп #26550Доброго времени суток.
После перерегистрации почтового ящика, фоновая заставка оставшаяся после порно банера исчезла.
Огромная Вам благодарность и успехов.8 ноября, 2009 в 4:13 пп #26548Нужно ещё немного подчистить компьютер.
Откройте блокнот (Кликните Пуск, Выполнить, в строке ввода введите notepad и нажмите Enter) и вставьте в него следующий текст:Driver::
cel90xbe
File::
c:windowssystem32ezsidmv.dat
c:windowssystem32hiwade.dat
c:windowssystem32vulyk.com
c:windowssystem32pehe.com
c:windowssystem32ygeroraji.datЗапишите получившийся файл на ваш рабочий стол под именем CFScript
Далее перетащите получившийся файл на иконку Combofix, как показано на картинке ниже.

Сombofix запуститься и выполнит процедуры описанные в созданном нами файле.
По результатам работы Combofix будет создан новый лог, его и вставьте в свой следующий ответ. -
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.
