Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Реклама порносайта с просьбой отсыкли смс
- This topic has 2 ответа, 2 участника, and was last updated 15 years, 11 months назад by
Admin.
-
АвторСообщения
-
2 ноября, 2009 в 10:28 дп #17391
Logfile of random’s system information tool 1.06 (written by random/random)
Run by для варки at 2009-11-02 13:21:51
Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (14%) free of 238 GB
Total RAM: 1023 MB (53% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:22:17, on 02.11.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: NormalRunning processes:
C:WINDOWS.1System32smss.exe
C:WINDOWS.1system32winlogon.exe
C:WINDOWS.1system32services.exe
C:WINDOWS.1system32lsass.exe
C:WINDOWS.1system32svchost.exe
C:WINDOWS.1System32svchost.exe
C:WINDOWS.1system32svchost.exe
C:WINDOWS.1system32spoolsv.exe
C:WINDOWS.1Explorer.EXE
C:Program FilesESETESET NOD32 Antivirusekrn.exe
C:WINDOWS.1system32ctfmon.exe
C:WINDOWS.1system32nvsvc32.exe
C:WINDOWS.1system32svchost.exe
C:WINDOWS.1system32RUNDLL32.EXE
C:Program FilesA4TechMouseAmoumain.exe
C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe
C:WINDOWS.1system32RUNDLL32.EXE
C:Program FilesESETESET NOD32 Antivirusegui.exe
C:Program FilesVistaDriveIconVistaDrv.exe
C:Program FilesLClocklclock.exe
C:Program FilesNokiaNokia PC Suite 7PCSuite.exe
C:Program FilesDAEMON Tools Litedaemon.exe
C:Program FilesLouderItLouderIt.exe
C:Program FilesDownload Masterdmaster.exe
C:Documents and Settingsдля варкиApplication DataMail.RuAgentMAgent.exe
C:Program FilesSpybot — Search & DestroyTeaTimer.exe
C:Program FilesCommon FilesTeleca SharedCapabilityManager.exe
C:Program FilesCommon FilesTeleca SharedGeneric.exe
C:Program FilesSony EricssonMobile2Mobile Phone Monitorepmworker.exe
C:Program FilesPC Connectivity SolutionServiceLayer.exe
C:Program FilesPC Connectivity SolutionTransportsNclUSBSrv.exe
C:Program FilesSpybot — Search & DestroySpybotSD.exe
C:Program FilesOperaopera.exe
C:Documents and Settingsдля варкиLocal SettingsApplication DataOperaOperatemporary_downloadsRSIT.exe
C:Program Filestrend microдля варки.exeR1 — HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://yandex.ru/yandsearch?clid=123046&text=%s
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.yandex.ru/?clid=123048
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://search.qip.ru
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.qip.ru/ie
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://yandex.ru/yandsearch?clid=123044
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/?clid=123048
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.qip.ru/ie
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R1 — HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = Root: HKCU; Subkey: SoftwareMicrosoftInternet ExplorerSearchUrl; ValueType: string; ValueName: ‘; ValueData: ‘; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 — HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://ui.skype.com/ui/0/3.8.0.154/ru/go/rates
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: QIPBHO Class — {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} — C:Documents and Settingsдля варкиApplication DataMicrosoftInternet Explorerqipsearchbar.dll
R3 — URLSearchHook: (no name) — {83821C2B-32A8-4DD7-B6D4-44309A78E668} — C:Documents and Settingsдля варкиApplication DataMail.RuAgentMradllnewmrasearch.dll
R3 — URLSearchHook: (no name) — — (no file)
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 — BHO: Shareaza Web Download Hook — {0EEDB912-C5FA-486F-8334-57288578C627} — c:program filesshareazarazawebhook32.dll
O2 — BHO: flashget urlcatch — {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} — C:Program FilesFlashGetjccatch.dll
O2 — BHO: Доступ к платному контенту FieryAds v2.0.2 — {6D125299-C2A9-4DBC-BEC3-6F7124E39A41} — (no file)
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll
O2 — BHO: Java(tm) Plug-In SSV Helper — {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} — C:Program FilesJavajre6binssv.dll
O2 — BHO: Update Timer — {963B125B-8B21-49A2-A3A8-E37092276531} — C:Program FilesGet-Styles 2.0updatebho.dll (file missing)
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
O2 — BHO: script helper for ie — {9B5FB65F-631E-4564-ABF2-AD71845B28E0} — C:Program FilesGet-Styles 2.0iejsloader.dll
O2 — BHO: QIPBHO — {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} — C:Documents and Settingsдля варкиApplication DataMicrosoftInternet Explorerqipsearchbar.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: JQSIEStartDetectorImpl — {E7E6F031-17CE-4C07-BC86-EABFE594F69C} — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O2 — BHO: FlashGet GetFlash Class — {F156768E-81EF-470C-9057-481BA8380DBA} — C:Program FilesFlashGetgetflash.dll
O3 — Toolbar: PROMT — {FF284F5C-7CF9-4682-8701-D467C1DBB99F} — C:Program FilesPRMT6PRMTIEprmtie.dll
O3 — Toolbar: Get-Styles [темы для Контакта] — {5BCDC9E9-A980-4B53-B2E8-60CFF484DA61} — C:Program FilesGet-Styles 2.0ietoolbar.dll
O4 — HKLM..Run: [WheelMouse] C:Program FilesA4TechMouseAmoumain.exe
O4 — HKLM..Run: [Sony Ericsson PC Suite] «C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe» /startoptions
O4 — HKLM..Run: [ISUSPM Startup] «C:Program FilesCommon FilesInstallShieldUpdateServiceISUSPM.exe» -startup
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWS.1system32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWS.1system32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [NeroFilterCheck] C:WINDOWS.1system32NeroCheck.exe
O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
O4 — HKCU..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe
O4 — HKCU..Run: [LClock] C:Program FilesLClocklclock.exe
O4 — HKCU..Run: [ctfmon.exe] C:WINDOWS.1system32ctfmon.exe
O4 — HKCU..Run: [PC Suite Tray] «C:Program FilesNokiaNokia PC Suite 7PCSuite.exe» -onlytray
O4 — HKCU..Run: [DAEMON Tools Lite] «C:Program FilesDAEMON Tools Litedaemon.exe» -autorun
O4 — HKCU..Run: [louderit.exe] C:Program FilesLouderItLouderIt.exe
O4 — HKCU..Run: [Download Master] C:Program FilesDownload Masterdmaster.exe -autorun
O4 — HKCU..Run: [MAgent] C:Documents and Settingsдля варкиApplication DataMail.RuAgentMAgent.exe -CU
O4 — HKCU..Run: [Google Update] «C:Documents and Settingsдля варкиLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe» /c
O4 — HKCU..Run: [uTorrent] «C:Program FilesuTorrentuTorrent.exe»
O4 — HKCU..Run: [VKontakte] C:Program FilesAgent VkontakteAgentVkontakte.exe
O4 — HKCU..Run: [Shareaza] «C:Program FilesShareazaShareaza.exe» -tray
O4 — HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot — Search & DestroyTeaTimer.exe
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWS.1system32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWS.1INFcustom.inf,OnceFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWS.1system32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWS.1INFcustom.inf,OnceFirstLogonInstall,0 (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-21-1343024091-838170752-1229272821-1004..Run: [CTFMON.EXE] C:WINDOWS.1system32ctfmon.exe (User ‘мартышка’)
O4 — HKUSS-1-5-21-1343024091-838170752-1229272821-1005..Run: [CTFMON.EXE] C:WINDOWS.1system32ctfmon.exe (User ‘Ээээ»»»»»»)
O4 — HKUSS-1-5-21-1343024091-838170752-1229272821-500..Run: [CTFMON.EXE] C:WINDOWS.1system32ctfmon.exe (User ‘Admin’)
O4 — HKUSS-1-5-21-1343024091-838170752-1229272821-501..Run: [CTFMON.EXE] C:windowssystem32ctfmon.exe (User ‘Гость’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWS.1system32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWS.1INFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWS.1system32CTFMON.EXE (User ‘Default user’)
O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWS.1INFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 Startup: Alienware Dock.lnk = C:Program FilesAlienGUIseAlienwareDockObjectDock.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 Startup: BIRTHDAY! millennium.lnk = C:Program FilesBIRTHDAYbirthmil.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 Startup: Stardock ObjectDock.lnk = C:games123StardockObjectDockObjectDock.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 Startup: Yahoo! Widget Engine.lnk = C:Program Files123Yahoo!WidgetsYahooWidgetEngine.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 User Startup: Alienware Dock.lnk = C:Program FilesAlienGUIseAlienwareDockObjectDock.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 User Startup: BIRTHDAY! millennium.lnk = C:Program FilesBIRTHDAYbirthmil.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 User Startup: Stardock ObjectDock.lnk = C:games123StardockObjectDockObjectDock.exe (User ‘Ээээ»»»»»»)
O4 — S-1-5-21-1343024091-838170752-1229272821-1005 User Startup: Yahoo! Widget Engine.lnk = C:Program Files123Yahoo!WidgetsYahooWidgetEngine.exe (User ‘Ээээ»»»»»»)
O8 — Extra context menu item: &Закачать все при помощи FlashGet — C:Program FilesFlashGetjc_all.htm
O8 — Extra context menu item: &Закачать при помощи FlashGet — C:Program FilesFlashGetjc_link.htm
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O8 — Extra context menu item: Download with &Shareaza — res://c:program filesshareazarazawebhook32.dll/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
O8 — Extra context menu item: Передать на удаленную закачку DM — C:Program FilesDownload Masterremdown.htm
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 — Extra button: (no name) — {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} — C:Program FilesPRMT6PRMTIEprmtie5.htm
O9 — Extra ‘Tools’ menuitem: Перевести — {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} — C:Program FilesPRMT6PRMTIEprmtie5.htm
O9 — Extra button: (no name) — {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} — C:Program FilesPRMT6PRMTIEoptions.htm
O9 — Extra ‘Tools’ menuitem: Настройка параметров перевода — {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} — C:Program FilesPRMT6PRMTIEoptions.htm
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 — Extra button: FlashGet — {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} — C:Program FilesFlashGetFlashGet.exe
O9 — Extra ‘Tools’ menuitem: FlashGet — {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} — C:Program FilesFlashGetFlashGet.exe
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWS.1Network Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWS.1Network Diagnosticxpnetdiag.exe
O9 — Extra button: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — C:Program FilesICQ6ICQ.exe
O9 — Extra ‘Tools’ menuitem: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — C:Program FilesICQ6ICQ.exe
O9 — Extra button: QIP Infium — {1EF681F7-A04B-4D6D-9012-A307CCA55610} — C:Program FilesQIP Infiuminfium.exe (HKCU)
O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Documents and Settingsдля варкиApplication DataMail.RuAgentmagent.exe (HKCU)
O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Documents and Settingsдля варкиApplication DataMail.RuAgentmagent.exe (HKCU)
O12 — Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O17 — HKLMSystemCCSServicesTcpip..{8D77E9A3-89B1-4E3A-981A-B45B0E479222}: NameServer = 94.125.244.10 91.143.48.42
O18 — Protocol: base64 — {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} — C:Program FilesGet-Styles 2.0ietdataprotocol.dll
O18 — Protocol: chrome — {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} — C:Program FilesGet-Styles 2.0ietdataprotocol.dll
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:Program FilesMicrosoft OfficeOffice12GrooveSystemServices.dll
O18 — Protocol: prox — {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} — C:Program FilesGet-Styles 2.0ietdataprotocol.dll
O23 — Service: ESET HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
O23 — Service: ESET Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWS.1system32services.exe
O23 — Service: FLEXnet Licensing Service — Macrovision Europe Ltd. — C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWS.1system32imapi.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWS.1system32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWS.1system32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWS.1system32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWS.1System32SCardSvr.exe
O23 — Service: ServiceLayer — Nokia. — C:Program FilesPC Connectivity SolutionServiceLayer.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWS.1system32smlogsvc.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWS.1System32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWS.1system32wbemwmiapsrv.exe
O23 — Service: Marvell Yukon Service (yksvc) — Unknown owner — RUNDLL32.EXE (file missing)—
End of file — 16532 bytes======Scheduled tasks folder======
C:WINDOWS.1tasksGoogleUpdateTaskUserS-1-5-21-1343024091-838170752-1229272821-1006Core.job
C:WINDOWS.1tasksGoogleUpdateTaskUserS-1-5-21-1343024091-838170752-1229272821-1006UA.job
C:WINDOWS.1tasksSystem Check.job======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class — C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx [2001-03-02 37808][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{0EEDB912-C5FA-486F-8334-57288578C627}]
Shareaza Web Download Hook — c:program filesshareazarazawebhook32.dll [2009-10-31 86528][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl — C:Program FilesFlashGetjccatch.dll [2007-08-06 94308][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{6D125299-C2A9-4DBC-BEC3-6F7124E39A41}]
Доступ к платному контенту FieryAds v2.0.2[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll [2007-08-24 2212224][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper — C:Program FilesJavajre6binssv.dll [2009-02-07 320920][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{963B125B-8B21-49A2-A3A8-E37092276531}]
TimerBHO Class — C:Program FilesGet-Styles 2.0updatebho.dll [][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9961627E-4059-41B4-8E0E-A7D6B3854ADF}]
IE 4.x-6.x BHO for Download Master — C:PROGRA~1DOWNLO~1dmiehlp.dll [2009-04-16 158208][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9B5FB65F-631E-4564-ABF2-AD71845B28E0}]
WitBHO Class — C:Program FilesGet-Styles 2.0iejsloader.dll [2009-10-03 221408][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class — C:Documents and Settingsдля варкиApplication DataMicrosoftInternet Explorerqipsearchbar.dll [2009-10-05 150768][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2009-02-07 34816][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2009-02-07 73728][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class — C:Program FilesFlashGetgetflash.dll [2007-05-18 163840][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{FF284F5C-7CF9-4682-8701-D467C1DBB99F} — PROMT — C:Program FilesPRMT6PRMTIEprmtie.dll [2005-11-10 434176]
{5BCDC9E9-A980-4B53-B2E8-60CFF484DA61} — Get-Styles [темы для Контакта] — C:Program FilesGet-Styles 2.0ietoolbar.dll [2009-10-03 126176][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«WheelMouse»=C:Program FilesA4TechMouseAmoumain.exe [2007-05-15 204800]
«Sony Ericsson PC Suite»=C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe [2005-10-26 159744]
«ISUSPM Startup»=C:Program FilesCommon FilesInstallShieldUpdateServiceISUSPM.exe [2005-08-11 249856]
«NvCplDaemon»=C:WINDOWS.1system32NvCpl.dll [2007-12-04 8523776]
«nwiz»=nwiz.exe /install []
«NvMediaCenter»=C:WINDOWS.1system32NvMcTray.dll [2007-12-04 81920]
«NeroFilterCheck»=C:WINDOWS.1system32NeroCheck.exe [2006-01-12 155648]
«egui»=C:Program FilesESETESET NOD32 Antivirusegui.exe [2009-02-06 2021400][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2008-01-02 132096]
«LClock»=C:Program FilesLClocklclock.exe [2007-12-14 86016]
«ctfmon.exe»=C:WINDOWS.1system32ctfmon.exe [2008-10-24 30208]
«PC Suite Tray»=C:Program FilesNokiaNokia PC Suite 7PCSuite.exe [2008-08-11 1124352]
«DAEMON Tools Lite»=C:Program FilesDAEMON Tools Litedaemon.exe [2008-04-01 486856]
«louderit.exe»=C:Program FilesLouderItLouderIt.exe [2008-02-19 41472]
«Download Master»=C:Program FilesDownload Masterdmaster.exe [2009-10-02 3779072]
«MAgent»=C:Documents and Settingsдля варкиApplication DataMail.RuAgentMAgent.exe [2008-10-17 7975608]
«Google Update»=C:Documents and Settingsдля варкиLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2008-10-17 133104]
«uTorrent»=C:Program FilesuTorrentuTorrent.exe [2008-10-17 289072]
«VKontakte»=C:Program FilesAgent VkontakteAgentVkontakte.exe [2009-10-20 3085824]
«Shareaza»=C:Program FilesShareazaShareaza.exe [2009-10-31 5794816]
«SpybotSD TeaTimer»=C:Program FilesSpybot — Search & DestroyTeaTimer.exe [2009-01-26 2144088][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows]
«AppInit_DLLS»=»wbsys.dll»[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyWB]
C:Program FilesAlienGUIsefastload.dll [2001-12-20 24576][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
0aMCPClient — {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} — C:PROGRA~1COMMON~1StardockMCPCore.dll [2005-05-10 86016]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWS.1system32wpdshserviceobj.dll [2008-03-02 133632][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll [2007-08-24 2212224][HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkWdf01000.sys]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=145
«NoSharedDocuments»=1
«NoSMConfigurePrograms»=1[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{498fddd7-996d-11de-a630-001a92164a54}]
shellAutoRuncommand — H:DriverFilesDrago.exe
shellopencommand — H:DriverFilesDrago.exe[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{94e58b7a-36e8-11dc-a5ef-001a92164a54}]
shellAutoRuncommand — C:WINDOWS.1system32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .RECYCLERS-5-3-42-2819952290-8240758988-879315005-3665jwgkvsq.vmx,ahaezedrn======List of files/folders created in the last 1 months======
2009-11-02 13:21:54 —-D—- C:Program Filestrend micro
2009-11-02 13:21:51 —-D—- C:rsit
2009-11-02 12:59:15 —-D—- C:Program FilesSpybot — Search & Destroy
2009-11-02 12:59:15 —-D—- C:Documents and SettingsAll Users.WINDOWS.1Application DataSpybot — Search & Destroy
2009-11-02 11:23:36 —-A—- C:WINDOWS.1system32__c002CD6.exe
2009-11-02 11:21:06 —-A—- C:WINDOWS.1system32__c003D6C.exe
2009-11-02 11:18:51 —-A—- C:WINDOWS.1system32__c004AE1.exe
2009-11-02 11:16:21 —-A—- C:WINDOWS.1system32__c006784.exe
2009-11-02 11:14:06 —-A—- C:WINDOWS.1system32__c0018BE.exe
2009-11-02 11:11:36 —-A—- C:WINDOWS.1system32__c004823.exe
2009-11-02 11:07:09 —-A—- C:WINDOWS.1system32__c0029.exe
2009-11-02 10:40:20 —-D—- C:Program FilesTeraCopy
2009-11-02 10:21:12 —-A—- C:WINDOWS.1system32syschk32.exe
2009-11-02 10:21:12 —-A—- C:WINDOWS.1system32el32.dll
2009-11-02 10:04:50 —-D—- C:Documents and Settingsдля варкиApplication DataShareaza
2009-11-02 10:04:46 —-D—- C:Program FilesShareaza
2009-10-31 17:08:02 —-D—- C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2009-10-28 13:27:05 —-D—- C:Documents and Settingsдля варкиApplication DataYandex
2009-10-28 13:26:09 —-D—- C:Documents and Settingsдля варкиApplication DataMozilla
2009-10-28 13:25:47 —-D—- C:Program FilesMozilla Firefox
2009-10-27 20:09:34 —-D—- C:Documents and Settingsдля варкиApplication DataVKontakte
2009-10-27 20:09:24 —-D—- C:Program FilesAgent Vkontakte======List of files/folders modified in the last 1 months======
2009-11-02 13:21:56 —-D—- C:WINDOWS.1Temp
2009-11-02 13:21:54 —-D—- C:Program Files
2009-11-02 13:13:20 —-D—- C:WINDOWS.1system32CatRoot2
2009-11-02 13:13:06 —-D—- C:Documents and Settingsдля варкиApplication DatauTorrent
2009-11-02 13:08:43 —-A—- C:WINDOWS.1SchedLgU.Txt
2009-11-02 13:08:14 —-D—- C:Documents and Settingsдля варкиApplication DataAIMP
2009-11-02 11:27:48 —-D—- C:WINDOWS.1system32
2009-11-02 10:21:13 —-SD—- C:WINDOWS.1Tasks
2009-11-02 09:58:14 —-D—- C:Documents and Settingsдля варкиApplication DataTeraCopy
2009-11-01 19:15:54 —-D—- C:Program FilesGarena
2009-11-01 18:08:43 —-D—- C:Downloads
2009-10-31 21:26:34 —-A—- C:WINDOWS.1NeroDigital.ini
2009-10-31 17:19:48 —-D—- C:Program FilesGet-Styles 2.0
2009-10-30 22:38:20 —-D—- C:Documents and Settingsдля варкиApplication DataGet Styles for Opera
2009-10-28 13:43:44 —-SHD—- C:WINDOWS.1Installer
2009-10-28 13:43:44 —-SHD—- C:Config.Msi
2009-10-28 13:43:40 —-D—- C:Program FilesOpera
2009-10-28 13:26:27 —-D—- C:WINDOWS.1
2009-10-28 05:30:07 —-A—- C:WINDOWS.1system32PerfStringBackup.INI
2009-10-27 13:49:17 —-D—- C:WINDOWS
2009-10-26 18:54:08 —-D—- C:Program FilesFlashGet======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Amfilter;A4Tech Mouse Filter Driver; C:WINDOWS.1system32DRIVERSAmfilter.sys [2007-05-15 9216]
R1 ehdrv;ehdrv; C:WINDOWS.1system32DRIVERSehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir; C:WINDOWS.1system32DRIVERSepfwtdir.sys [2009-02-06 93336]
R1 intelppm;Драйвер Intel процессора; C:WINDOWS.1system32DRIVERSintelppm.sys [2008-04-15 40704]
R2 eamon;eamon; C:WINDOWS.1system32DRIVERSeamon.sys [2009-02-06 113448]
R2 PARLDR2K;ParLdr2k; ??C:WINDOWS.1system32driversparldr2k.sys []
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:WINDOWS.1system32DRIVERSrspndr.sys [2008-10-11 62848]
R3 aeaudio;aeaudio; C:WINDOWS.1system32driversaeaudio.sys [2005-03-05 127872]
R3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:WINDOWS.1system32DRIVERSAmusbprt.sys [2007-05-15 14336]
R3 hidusb;Драйвер класса HID Microsoft; C:WINDOWS.1system32DRIVERShidusb.sys [2008-04-15 10368]
R3 nv;nv; C:WINDOWS.1system32DRIVERSnv4_mini.sys [2007-12-04 7435392]
R3 senfilt;senfilt; C:WINDOWS.1system32driverssenfilt.sys [2005-03-01 392704]
R3 smwdm;smwdm; C:WINDOWS.1system32driverssmwdm.sys [2005-03-28 220992]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWS.1system32DRIVERSusbehci.sys [2008-04-15 30208]
R3 usbhub;USB2 концентратор; C:WINDOWS.1system32DRIVERSusbhub.sys [2008-04-14 59520]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWS.1system32DRIVERSusbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:WINDOWS.1system32DRIVERSyk51x86.sys [2008-08-18 290176]
S1 kbdhid;Драйвер клавиатуры HID; C:WINDOWS.1system32DRIVERSkbdhid.sys [2008-04-14 14720]
S3 a3s3wno8;a3s3wno8; C:WINDOWS.1system32driversa3s3wno8.sys []
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWS.1system32driversALCXWDM.SYS [2008-01-25 4127488]
S3 GarenaPEngine;GarenaPEngine; ??C:DOCUME~1 15E~1LOCALS~1TempAAK109B.tmp []
S3 mouhid;Драйвер мыши HID; C:WINDOWS.1system32DRIVERSmouhid.sys [2008-04-15 12160]
S3 nmwcd;Nokia USB Phone Parent; C:WINDOWS.1system32driversccdcmb.sys [2009-07-10 17664]
S3 nmwcdc;Nokia USB Generic; C:WINDOWS.1system32driversccdcmbo.sys [2009-07-10 22016]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:WINDOWS.1system32driversnmwcdnsu.sys [2009-07-10 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:WINDOWS.1system32driversnmwcdnsuc.sys [2009-07-10 8320]
S3 RivaTuner32;RivaTuner32; ??C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionRivaTuner32.sys []
S3 upperdev;upperdev; C:WINDOWS.1system32DRIVERSusbser_lowerflt.sys [2009-07-10 7808]
S3 usbccgp;Драйвер универсального родительского устройства USB (Microsoft); C:WINDOWS.1system32DRIVERSusbccgp.sys [2008-04-14 32128]
S3 usbscan;Драйвер USB-сканера; C:WINDOWS.1system32DRIVERSusbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:WINDOWS.1system32driversusbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:WINDOWS.1system32DRIVERSusbser_lowerfltj.sys [2009-07-10 7808]
S3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWS.1system32DRIVERSUSBSTOR.SYS [2008-04-14 26368]
S3 w810bus;Sony Ericsson W810 Driver driver (WDM); C:WINDOWS.1system32DRIVERSw810bus.sys [2006-02-20 58288]
S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; C:WINDOWS.1system32DRIVERSw810mdfl.sys [2006-02-20 8336]
S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; C:WINDOWS.1system32DRIVERSw810mdm.sys [2006-02-20 94064]
S3 w810mgmt;Sony Ericsson W810 USB WMC Device Management Drivers (WDM); C:WINDOWS.1system32DRIVERSw810mgmt.sys [2006-02-20 85408]
S3 w810obex;Sony Ericsson W810 USB WMC OBEX Interface; C:WINDOWS.1system32DRIVERSw810obex.sys [2006-02-20 83344]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:WINDOWS.1System32Driverswdf01000.sys [2008-03-27 503008]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWS.1system32DRIVERSwudfrd.sys [2006-09-15 82688]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:Program FilesESETESET NOD32 Antivirusekrn.exe [2009-02-06 727720]
R2 NVSvc;NVIDIA Display Driver Service; C:WINDOWS.1system32nvsvc32.exe [2007-12-04 155716]
R2 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWS.1system32svchost.exe [2008-04-15 14336]
R2 yksvc;Marvell Yukon Service; ykx32mpcoinst,serviceStartProc []
R3 ServiceLayer;ServiceLayer; C:Program FilesPC Connectivity SolutionServiceLayer.exe [2008-08-07 575488]
S3 aspnet_state;ASP.NET State Service; C:WINDOWS.1Microsoft.NETFrameworkv2.0.50727aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWS.1Microsoft.NETFrameworkv2.0.50727mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;ESET HTTP Server; C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe [2009-02-06 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe [2009-07-28 654848]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
S4 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2009-02-07 152984]
EOF
2 ноября, 2009 в 10:29 дп #26774info.txt logfile of random’s system information tool 1.06 2009-11-02 13:22:21
======Uninstall list======
«Русская рыбалка 1.5»—>C:Program FilesFish SoftwareRussian Fishing 1.5Uninstall.exe
—>MsiExec.exe /I{52D02A2B-03D2-4E34-A358-DC5D951FD296}
—>MsiExec.exe /I{8E719AE4-286B-4F01-8DA1-6270B0BF819D}
—>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:WINDOWS.1INFPCHealth.inf
µTorrent—>»C:Program FilesuTorrentuTorrent.exe» /UNINSTALL
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-0015-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-0016-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-0018-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-0019-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-001A-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-001B-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-001F-0419-0000-0000000FF1CE} /uninstall {D7CE14BC-96D9-41C5-822D-F5B1C2C35AA2}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-001F-0422-0000-0000000FF1CE} /uninstall {DC154E48-5278-423A-80A1-B93247E38A1A}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-0044-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-006E-0419-0000-0000000FF1CE} /uninstall {23653CA5-BFB5-4B52-B2DA-045D7ABEB874}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-00A1-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
2007 Microsoft Office Suite Service Pack 1 (SP1)—>msiexec /package {90120000-00BA-0419-0000-0000000FF1CE} /uninstall {1AD50F4A-04F7-4944-BD47-4421532548F5}
Adobe Acrobat 5.0—>C:WINDOWS.1ISUNINST.EXE -f»C:Program FilesCommon FilesAdobeAcrobat 5.0NTUninst.isu» -c»C:Program FilesCommon FilesAdobeAcrobat 5.0NTUninst.dll»
Adobe Anchor Service CS3—>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3—>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Camera Raw 4.0—>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps—>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color — Photoshop Specific—>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings—>MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings—>MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings—>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings—>MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3—>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Flash Player 10 ActiveX—>C:WINDOWS.1system32MacromedFlashuninstall_activeX.exe
Adobe Flash Player 10 Plugin—>C:WINDOWS.1system32MacromedFlashuninstall_plugin.exe
Adobe Flash Player 9 ActiveX—>C:WINDOWS.1system32MacromedFlashUninstFl.exe -q
Adobe Fonts All—>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Linguistics CS3—>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files—>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3—>C:Program FilesCommon FilesAdobeInstallers719d6f144d0c086a0dfa7ff76bb9ac1Setup.exe
Adobe Photoshop CS3—>MsiExec.exe /I{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}
Adobe Setup—>MsiExec.exe /I{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}
Adobe Type Support—>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3—>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client—>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin—>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3—>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AIMP2—>C:Program FilesAIMP2Uninstall.exe
AlienGUIse Theme Manager—>C:PROGRA~1ALIENG~1thememgr.exe /uninstallwise
All in one Cleaner ver.1.0—>»C:Program FilesAll in one Cleanerunins000.exe»
BootSkin—>C:gamesStardockWINCUS~1BootSkinUNWISE.EXE C:gamesStardockWINCUS~1BootSkinINSTALL.LOG
Convexsoft DJ Audio Mixer—>C:WINDOWS.1Convexsoft DJ Audio Mixer Uninstaller.exe
Cool PDF Reader 2.0—>»C:Program FilesCool PDF Readerunins000.exe»
Download Master version 5.5.14.1175—>»C:Program FilesDownload Masterunins000.exe»
FlashGet 1.9.6.1073—>C:Program FilesFlashGetuninst.exe
Garena—>C:Program FilesGarenauninst.exe
Get-Styles для ВКонтакте—>C:Program FilesGet-Styles 2.0uninstall.exe
HijackThis 2.0.2—>»C:Program Filestrend microHijackThis.exe» /uninstall
Hydrogen—>»C:Program FilesHydrogenuninstall.exe»
ICQ6—>»C:Program FilesInstallShield Installation Information{60DE4033-9503-48D1-A483-7846BD217CA9}setup.exe» -runfromtemp -l0x0009 -removeonly
Java(TM) 6 Update 10—>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
K-Lite Mega Codec Pack 3.9.5—>»C:Program FilesK-Lite Codec Packunins000.exe»
L&H TTS3000 Deutsch—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWS.1INFLHTTSGED.inf, Uninstall
L&H TTS3000 Espaсol—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWS.1INFLHTTSSPE.inf, Uninstall
L&H TTS3000 Franзais—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWS.1INFLHTTSFRF.inf, Uninstall
L&H TTS3000 Italiano—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWS.1INFLHTTSITI.inf, Uninstall
L&H TTS3000 Russian—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWS.1INFLHTTSRUR.inf, Uninstall
LClock—>C:Program FilesLClockUninstall.exe
Lernout & Hauspie TruVoice American English TTS Engine—>RunDll32 advpack.dll,LaunchINFSection C:WINDOWS.1INFtv_enua.inf, Uninstall
Microsoft .NET Framework 1.1 Russian Language Pack—>MsiExec.exe /X{2BB372D9-52B4-410A-BC1A-FEAB63181EEF}
Microsoft .NET Framework 1.1—>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1—>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1—>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5—>»C:WINDOWS.1$NtUninstallWdf01005$spuninstspuninst.exe»
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7—>»C:WINDOWS.1$NtUninstallWdf01007$spuninstspuninst.exe»
Microsoft Office Access MUI (Russian) 2007—>MsiExec.exe /X{90120000-0015-0419-0000-0000000FF1CE}
Microsoft Office Enterprise 2007—>»C:Program FilesCommon FilesMicrosoft SharedOFFICE12Office Setup Controllersetup.exe» /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007—>MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Russian) 2007—>MsiExec.exe /X{90120000-0016-0419-0000-0000000FF1CE}
Microsoft Office Groove MUI (Russian) 2007—>MsiExec.exe /X{90120000-00BA-0419-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Russian) 2007—>MsiExec.exe /X{90120000-0044-0419-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Russian) 2007—>MsiExec.exe /X{90120000-00A1-0419-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Russian) 2007—>MsiExec.exe /X{90120000-001A-0419-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Russian) 2007—>MsiExec.exe /X{90120000-0018-0419-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007—>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007—>MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Russian) 2007—>MsiExec.exe /X{90120000-001F-0419-0000-0000000FF1CE}
Microsoft Office Proof (Ukrainian) 2007—>MsiExec.exe /X{90120000-001F-0422-0000-0000000FF1CE}
Microsoft Office Proofing (Russian) 2007—>MsiExec.exe /X{90120000-002C-0419-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Russian) 2007—>MsiExec.exe /X{90120000-0019-0419-0000-0000000FF1CE}
Microsoft Office Shared MUI (Russian) 2007—>MsiExec.exe /X{90120000-006E-0419-0000-0000000FF1CE}
Microsoft Office Word MUI (Russian) 2007—>MsiExec.exe /X{90120000-001B-0419-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.5—>»C:WINDOWS.1$NtUninstallWudf01005$spuninstspuninst.exe»
Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.5.4)—>C:Program FilesMozilla Firefoxuninstallhelper.exe
MSI to redistribute Pyscollider—>MsiExec.exe /I{A2842623-F30E-443B-AF50-A462F70F0359}
MSVC80_x86—>MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 4.0 SP2 (KB941833)—>MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MTS PC Client—>MsiExec.exe /I{88012DE1-9E77-4D59-B66F-2C02381153C1}
Need for Speed Most Wanted — Black Edition—>»C:gamesNeed for Speed Most Wanted — Black Editionunins000.exe»
Nero 6—>C:Program FilesAheadnerouninstallUNNERO.exe /UNINSTALL
Nokia 6500s RM-240 FW-10.00 Light—>»C:Program FilesNokiaPhoenixproductsRM-240unins000.exe»
Nokia PC Suite—>MsiExec.exe /I{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}
NSIS Mixxx—>»C:Program FilesMixxxuninstall.exe»
NVIDIA Drivers—>C:WINDOWS.1system32nvuninst.exe UninstallGUI
OpenAL—>»C:Program FilesOpenALoalinst.exe» /U
Opera 10.01—>MsiExec.exe /X{6CDC748B-47B0-45EB-B740-681E8429F7F9}
Paint.NET v 3.36—>rundll32.exe advpack.dll,LaunchINFSection PaintDN.inf,Uninstall
Paper Folding 3D—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime100Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{3EFC6C19-B06F-41B7-9763-42538D5B5CB3}setup.exe» -l0x9 -removeonly
PC Connectivity Solution—>MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}
PDF Settings—>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Phoenix Internal Service Software—>MsiExec.exe /I{6E47361D-5035-49E6-8D02-DC4EF59586DF}
Punto Switcher—>C:Program FilesPunto SwitcherUninstall.exe
‘Rappelz’—>»C:Program FilesNikitaRappelzunins000.exe»
Recover My Files—>»C:Program FilesGetDataRecover My Filesunins000.exe»
RF Online 1.1.3—>»C:Games4GAMERFOnlineunins000.exe»
RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition—>»C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionuninstall.exe»
Shareaza 2.5.0.0—>»C:Program FilesShareazaUninstallunins000.exe»
Smart-X7 7.80—>C:Program FilesA4TechMouseUninst32.exe
Sony Ericsson PC Suite 1.10.176—>MsiExec.exe /I{968145DF-4F74-4A22-83CA-A66A4F7BC027}
Spybot — Search & Destroy—>»C:Program FilesSpybot — Search & Destroyunins000.exe»
Talk to Me—>C:Talk to Me NVUnInstal.exe «C:Talk to Me NV»
TeraCopy 2.01—>»C:Program FilesTeraCopyunins000.exe»
TmUnitedForever—>»C:Program FilesTmUnitedForeverunins000.exe»
Update Manager—>MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}
Vista Drive Icon—>rundll32.exe advpack.dll,LaunchINFSection C:WINDOWS.1INFVistaDrv.inf,Uninstall
Vista Games 1.3 XP—>C:Program FilesVista Gamesuninst.exe
WarRun 4.00 alpha—>»C:Program FilesWarRununins000.exe»
X-Translator Revolution Giant—>MsiExec.exe /I{F09BA1D1-7F52-4ECE-83D7-A7CDBCDDB6F1}
YoGen Vocal Remover 3.0.3—>MsiExec.exe /I{C6E9285D-C77D-4762-A31C-E5D08E955057}
Агент Вконтакте v1.28—>C:Program FilesAgent Vkontakteuninst.exe
Армада танков—>C:Program FilesAlawar.ruАрмада танковUninstall.exe
Бесплатный контент FieryAds—>C:Documents and Settingsдля варкиApplication DataFieryAdsFieryAdsUninstall.exe
Боковая панель Windows—>rundll32.exe advpack.dll,LaunchINFSection C:WINDOWS.1INFSidebar.inf,DefaultUnInstall
Данные ДубльГИС г.Нижневартовск 01.10.2009—>MsiExec.exe /X{DD97AA61-3C80-4D34-8125-F636549ED1EF}
Доступ к условно бесплатному контенту AdSubscribe—>C:Documents and Settingsдля варкиApplication DataAdSubscribeUninstall.exe
Доступ к условно бесплатному контенту CMedia—>C:Documents and Settingsдля варкиApplication DataCMediaUninstall.exe
ДубльГИС 3.0.5.4—>MsiExec.exe /X{67A1DF48-1CEA-468C-ADAA-74BA915437D8}
Пакет драйверов Windows — Nokia Modem (02/15/2007 3.1)—>C:PROGRA~1DIFX270581355A767BF1dpinst.exe /u C:WINDOWS.1system32DRVSTOREpccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293Bpccs_bluetooth.inf
Пакет драйверов Windows — Nokia Modem (02/15/2007 3.1)—>C:PROGRA~1DIFX270581355A767BF1dpinst.exe /u C:WINDOWS.1system32DRVSTOREpccs_bluet_F12A08B6F776984A95553486F64C541356F86E38pccs_bluetooth.inf
Пакет драйверов Windows — Nokia Modem (05/22/2008 3.8)—>C:PROGRA~1DIFX270581355A767BF1dpinst.exe /u C:WINDOWS.1system32DRVSTOREnokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181Enokia_bluetooth.inf
Пакет драйверов Windows — Nokia Modem (05/22/2008 7.00.0.1)—>C:PROGRA~1DIFX270581355A767BF1dpinst.exe /u C:WINDOWS.1system32DRVSTOREnokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9nokbtmdm.inf
Пакет драйверов Windows — Nokia pccsmcfd (10/12/2007 6.85.4.0)—>C:PROGRA~1DIFX270581355A767BF1dpinst.exe /u C:WINDOWS.1system32DRVSTOREpccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175pccsmcfd.inf
Русификатор v.1.1 для Adobe Photoshop CS3—>»C:Program FilesAdobeAdobe Photoshop CS3RequiredUninstall.exe»
Ускоритель интернета 1.5—>»C:Program FilesУскоритель интернетаunins000.exe»
Фраза—>C:DOCUME~115E~1LOCALS~1TempUninstall.exe======Security center information======
AV: ESET NOD32 Antivirus 4.0 (outdated)
======System event log======
Computer Name: MICROSOF-970644
Event Code: 7036
Message: Служба «Совместимость быстрого переключения пользователей» перешла в состояние Работает.Record Number: 7188
Source Name: Service Control Manager
Time Written: 20090810073641.000000+240
Event Type: информация
User:Computer Name: MICROSOF-970644
Event Code: 7035
Message: Служба «Совместимость быстрого переключения пользователей» успешно отправила управляющий элемент «запустить».Record Number: 7187
Source Name: Service Control Manager
Time Written: 20090810073641.000000+240
Event Type: информация
User: NT AUTHORITYSYSTEMComputer Name: MICROSOF-970644
Event Code: 7036
Message: Служба «Службы терминалов» перешла в состояние Работает.Record Number: 7186
Source Name: Service Control Manager
Time Written: 20090810073101.000000+240
Event Type: информация
User:Computer Name: MICROSOF-970644
Event Code: 7035
Message: Служба «Службы терминалов» успешно отправила управляющий элемент «запустить».Record Number: 7185
Source Name: Service Control Manager
Time Written: 20090810073101.000000+240
Event Type: информация
User: NT AUTHORITYSYSTEMComputer Name: MICROSOF-970644
Event Code: 7036
Message: Служба «Диспетчер подключений удаленного доступа» перешла в состояние Работает.Record Number: 7184
Source Name: Service Control Manager
Time Written: 20090810073101.000000+240
Event Type: информация
User:=====Application event log=====
Computer Name: MICROSOF-970644
Event Code: 0
Message:
Record Number: 391
Source Name: ServiceLayer
Time Written: 20090301190738.000000+180
Event Type: информация
User:Computer Name: MICROSOF-970644
Event Code: 0
Message:
Record Number: 390
Source Name: ServiceLayer
Time Written: 20090301120614.000000+180
Event Type: информация
User:Computer Name: MICROSOF-970644
Event Code: 0
Message:
Record Number: 389
Source Name: ServiceLayer
Time Written: 20090301075548.000000+180
Event Type: информация
User:Computer Name: MICROSOF-970644
Event Code: 0
Message:
Record Number: 388
Source Name: ServiceLayer
Time Written: 20090228185324.000000+180
Event Type: информация
User:Computer Name: MICROSOF-970644
Event Code: 0
Message:
Record Number: 387
Source Name: ServiceLayer
Time Written: 20090228075522.000000+180
Event Type: информация
User:======Environment variables======
«ComSpec»=%SystemRoot%system32cmd.exe
«Path»=C:Program FilesPC Connectivity Solution;%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem;C:Program FilesCommon FilesTeleca Shared
«windir»=%SystemRoot%
«FP_NO_HOST_CHECK»=NO
«OS»=Windows_NT
«PROCESSOR_ARCHITECTURE»=x86
«PROCESSOR_LEVEL»=15
«PROCESSOR_IDENTIFIER»=x86 Family 15 Model 6 Stepping 4, GenuineIntel
«PROCESSOR_REVISION»=0604
«NUMBER_OF_PROCESSORS»=2
«PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
«TEMP»=%SystemRoot%TEMP
«TMP»=%SystemRoot%TEMP
«DEFAULT_CA_NR»=CA6
EOF
7 ноября, 2009 в 5:25 пп #26775Здравствуйте, добро пожаловать на Spyware-ru форум.
Необходима дополнительная проверка.
Скачайте программу Combofix. Закройте все открытые окна и запустите эту программу.
После выполнения будет создан лог файл, пожалуйста вставьте его в ваш ответ.Примечание: перед использованием Combofix обязательно установите Recovery console. Как это сделать будет описано на странице, ссылку на которую я привёл выше.
-
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.
