Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › Заражение компьютера
- This topic has 1 ответ, 2 участника, and was last updated 16 years, 2 months назад by
Admin.
-
АвторСообщения
-
12 марта, 2009 в 7:59 пп #16403
Аноним
Гость- Темы:532
- Сообщений:1553
- ☆☆☆☆☆
Доброго времени суток!
Уважаемая Администрация,прошу помочь мне с удалением вирусов и чистке компьютера. Итак,я уверен,что мой компьютер полон вирусов,так как он очень медленно работает и постоянно зависает,out post вообще не помогает,а только ёщё больше замедляет работу.Я сделал как написано в соседней теме.Надеюсь,я вас не очень затруднил,что просканировал за 3 месяца…Итак,содержимое log.txt.Также хочу дополнить,что info мне не высветилось.Logfile of random’s system information tool 1.05 (written by random/random)
Run by Олег at 2009-03-12 22:55:00
Microsoft Windows XP Professional Service Pack 2
System drive C: has 78 GB (33%) free of 238 GB
Total RAM: 1022 MB (41% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:55:02, on 12.03.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSehomeehtray.exe
C:Program FilesAnalog DevicesCoresmax4pnp.exe
C:Program FilesAnalog DevicesSoundMAXSmax4.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32cisvc.exe
C:WINDOWSeHomeehRecvr.exe
C:WINDOWSeHomeehSched.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32nvsvc32.exe
C:Program FilesAgnitumOutpost Security Suiteoutpost.exe
C:WINDOWSsystem32PnkBstrA.exe
C:WINDOWSsystem32PnkBstrB.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32dllhost.exe
C:WINDOWSeHomeehmsas.exe
C:WINDOWSsystem32wuauclt.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSTEMPBN5.tmp
C:WINDOWSTEMPanv2.tmp
C:WINDOWSIsUninstR.Exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Documents and SettingsОлегDesktopRSIT.exe
C:Program Filestrend microОлег.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://search.qip.ru
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://search.qip.ru
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.qip.ru/ie
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.qip.ru
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = start.qip.ru
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.qip.ru/ie
R1 — HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://search.qip.ru/search?query=%s&from=IE
R3 — URLSearchHook: (no name) — {95289393-33EA-4F8D-B952-483415B9C955} — (no file)
R3 — URLSearchHook: (no name) — — (no file)
O1 — Hosts: 78.107.238.86 status.wow-europe.com
O1 — Hosts: 78.107.238.86 launcher.worldofwarcraft.com
O2 — BHO: Google Toolbar Helper — {AA58ED58-01DD-4d91-8333-CF10577473F7} — c:program filesgooglegoogletoolbar1.dll
O2 — BHO: Google Toolbar Notifier BHO — {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} — C:Program FilesGoogleGoogleToolbarNotifier2.0.301.7164swg.dll
O4 — HKLM..Run: [ehTray] C:WINDOWSehomeehtray.exe
O4 — HKLM..Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [SoundMAXPnP] C:Program FilesAnalog DevicesCoresmax4pnp.exe
O4 — HKLM..Run: [SoundMAX] «C:Program FilesAnalog DevicesSoundMAXSmax4.exe» /tray
O4 — HKLM..Run: [ISUSPM Startup] C:PROGRA~1COMMON~1INSTAL~1UPDATE~1isuspm.exe -startup
O4 — HKLM..Run: [ISUSScheduler] «C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe» -start
O4 — HKLM..Run: [VVSN] C:Program FilesVVSNVVSN.exe
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [Outpost Security Suite] C:Program FilesAgnitumOutpost Security Suiteoutpost.exe /waitservice
O4 — HKLM..Run: [OutpostFeedBack] C:Program FilesAgnitumOutpost Security Suitefeedback.exe /dump:os_startup
O4 — HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 — HKCU..Run: [Steam] «c:program filesgamescsssteam.exe» -silent
O4 — HKCU..Run: [Rainlendar2] C:DOCUME~1 5AC~1LOCALS~1TempRar$EX00.000Rainlendar2.exe
O4 — HKCU..Run: [QIP.Online] C:Program FilesQIP.Onlineqiponline.exe auto_start
O4 — HKCU..Run: [Infium] «C:Program FilesQIP Infiuminfium.exe»
O4 — HKCU..Run: [Олег] C:Documents and SettingsОлегОлег.exe /i
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — Startup: NHL™ 09 — регистрация.lnk = C:Program FilesEA SPORTSNHL 09SupportEAregister.exe
O4 — Startup: Registration The Settlers — Наследие королей — Золотое издание.LNK = ?
O4 — Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 — Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~4OFFICE11EXCEL.EXE/3000
O8 — Extra context menu item: Найти с помощью Рамблера — res://C:Program FilesRambler AssistantramblertoolbarU0.dll/search.htm
O8 — Extra context menu item: Опубликовать в Дневнике — res://C:Program FilesRambler AssistantramblertoolbarU0.dll/planet.htm
O8 — Extra context menu item: Перевести с помощью словарей Рамблера — res://C:Program FilesRambler AssistantramblertoolbarU0.dll/dic.htm
O8 — Extra context menu item: Поиск@Mail.Ru — res://C:PROGRA~1Mail.RuSputnikMAILRU~1.DLL/SEARCH.HTM
O8 — Extra context menu item: Словари@Mail.Ru — res://C:PROGRA~1Mail.RuSputnikMAILRU~1.DLL/TRANSLATE.HTM
O9 — Extra button: Быстрая настройка Outpost Security Suite Pro — {44627E97-789B-40d4-B5C2-58BD171129A1} — C:Program FilesAgnitumOutpost Security SuitePluginsBrowserBarie_bar.dll
O9 — Extra button: (no name) — {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} — C:Program FilesPRMT6PRMTIEprmtie5.htm
O9 — Extra ‘Tools’ menuitem: Перевести — {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} — C:Program FilesPRMT6PRMTIEprmtie5.htm
O9 — Extra button: (no name) — {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} — C:Program FilesPRMT6PRMTIEoptions.htm
O9 — Extra ‘Tools’ menuitem: Настройка параметров перевода — {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} — C:Program FilesPRMT6PRMTIEoptions.htm
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~4OFFICE11REFIEBAR.DLL
O9 — Extra button: ICQ Lite — {B863453A-26C3-4e1f-A54D-A2CD196348E9} — C:Program FilesICQLiteICQLite.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ Lite — {B863453A-26C3-4e1f-A54D-A2CD196348E9} — C:Program FilesICQLiteICQLite.exe (file missing)
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra button: Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O9 — Extra ‘Tools’ menuitem: Windows Messenger — {FB5F1910-F110-11d2-BB9E-00C04F795683} — C:Program FilesMessengermsmsgs.exe
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O10 — Unknown file in Winsock LSP: c:program filesagnitumoutpost security suitelspfilt.dll
O14 — IERESET.INF: START_PAGE_URL=http://www.kraftway.ru
O17 — HKLMSystemCCSServicesTcpip..{AA1C9E3A-E65D-45F9-A694-C67199394E6A}: NameServer = 213.234.192.7 195.14.50.21
O20 — AppInit_DLLs: C:WINDOWSsystem32mmmjwyto.dll
O23 — Service: Adobe LM Service — Unknown owner — C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 — Service: Application Driver Auto Removal Service (01) (appdrvrem01) — Protection Technology — C:WINDOWSSystem32appdrvrem01.exe
O23 — Service: Google Updater Service (gusvc) — Google — C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 — Service: InstallDriver Table Manager (IDriverT) — Unknown owner — C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe (file missing)
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
O23 — Service: Outpost Security Suite Service (OutpostSecuritySuite) — Agnitum Ltd. — C:Program FilesAgnitumOutpost Security Suiteoutpost.exe
O23 — Service: PnkBstrA — Unknown owner — C:WINDOWSsystem32PnkBstrA.exe
O23 — Service: PnkBstrB — Unknown owner — C:WINDOWSsystem32PnkBstrB.exe
O23 — Service: FlatOut: Ultimate Carnage Drivers Auto Removal (pr2aslcb) (pr2aslcb) — Buka — C:WINDOWSsystem32pr2aslcb.exe
O23 — Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) — Protection Technology (StarForce) — C:WINDOWSsystem32sfrem01.exe—
End of file — 9868 bytes======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper — c:program filesgooglegoogletoolbar1.dll [2007-11-02 2427968][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO — C:Program FilesGoogleGoogleToolbarNotifier2.0.301.7164swg.dll [2007-11-14 325048][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«ehTray»=C:WINDOWSehomeehtray.exe [2005-08-05 64512]
«High Definition Audio Property Page Shortcut»=C:WINDOWSSYSTEM32HDAShCut.exe [2005-01-07 61952]
«NvCplDaemon»=C:WINDOWSsystem32NvCpl.dll [2008-10-07 13574144]
«nwiz»=nwiz.exe /install []
«SoundMAXPnP»=C:Program FilesAnalog DevicesCoresmax4pnp.exe [2005-05-20 925696]
«SoundMAX»=C:Program FilesAnalog DevicesSoundMAXSmax4.exe [2005-09-07 716800]
«ISUSPM Startup»=C:PROGRA~1COMMON~1INSTAL~1UPDATE~1isuspm.exe [2004-06-16 221184]
«ISUSScheduler»=C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe [2004-06-16 81920]
«VVSN»=C:Program FilesVVSNVVSN.exe []
«NvMediaCenter»=C:WINDOWSsystem32NvMcTray.dll [2008-10-07 86016]
«Outpost Security Suite»=C:Program FilesAgnitumOutpost Security Suiteoutpost.exe [2007-04-28 120832]
«OutpostFeedBack»=C:Program FilesAgnitumOutpost Security Suitefeedback.exe [2007-04-27 348160][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2006-05-05 15360]
«Steam»=c:program filesgamescsssteam.exe [2008-10-10 1410296]
«Rainlendar2″=C:DOCUME~1 5AC~1LOCALS~1TempRar$EX00.000Rainlendar2.exe []
«QIP.Online»=C:Program FilesQIP.Onlineqiponline.exe auto_start []
«Infium»=C:Program FilesQIP Infiuminfium.exe []
«Олег»=C:Documents and SettingsОлегОлег.exe /i []C:Documents and SettingsAll UsersStart MenuProgramsStartup
Adobe Gamma Loader.lnk — C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
Adobe Reader Speed Launch.lnk — C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exeC:Documents and SettingsОлегStart MenuProgramsStartup
NHL™ 09 — регистрация.lnk — C:Program FilesEA SPORTSNHL 09SupportEAregister.exe
Registration The Settlers — Наследие королей — Золотое издание.LNK — C:Program FilesUbisoftBlue ByteThe Settlers — Наследие королей — Золотое изданиеsupportRegisterRegistrationReminder.exe[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows]
«AppInit_DLLS»=»C:WINDOWSsystem32mmmjwyto.dll»[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
0aMCPClient — {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32WPDShServiceObj.dll [2006-10-18 133632][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1
«InstallVisualStyle»=C:WINDOWSResourcesThemesRoyaleRoyale.msstyles
«InstallTheme»=C:WINDOWSResourcesThemesRoyale.theme[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=145[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoSMBalloonTip»=
«HonorAutoRunSetting»=[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«C:Program FilesElectronic ArtsBattlefield 2142BF2142.exe»=»C:Program FilesElectronic ArtsBattlefield 2142BF2142.exe:*:Enabled:Battlefield 2»
«C:Program FilesICQLiteICQLite.exe»=»C:Program FilesICQLiteICQLite.exe:*:Enabled:ICQ Lite»
«C:Program FilesuTorrentuTorrent.exe»=»C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent»
«C:Program FilesSierraFEARFEAR.exe»=»C:Program FilesSierraFEARFEAR.exe:*:Enabled:FEAR»
«C:Program FilesGameSpy ArcadeAphex.exe»=»C:Program FilesGameSpy ArcadeAphex.exe:*:Enabled:GameSpy Arcade»
«C:Program FilesTHQGas Powered GamesGPGNetGPG.Multiplayer.Client.exe»=»C:Program FilesTHQGas Powered GamesGPGNetGPG.Multiplayer.Client.exe:*:Enabled:GPGNet — Supreme Commander»
«C:Program FilesSkypePhoneSkype.exe»=»C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype»
«C:Program FilesTHQFrontlines-Fuel of WarBinariesFFOW.exe»=»C:Program FilesTHQFrontlines-Fuel of WarBinariesFFOW.exe:*:Enabled:Frontlines Game»
«C:WINDOWSsystem32PnkBstrA.exe»=»C:WINDOWSsystem32PnkBstrA.exe:*:Enabled:PnkBstrA»
«C:WINDOWSsystem32PnkBstrB.exe»=»C:WINDOWSsystem32PnkBstrB.exe:*:Enabled:PnkBstrB»
«C:Program FilesUbisoftTHE SETTLERS — Расцвет империиbasebinSettlers6.exe»=»C:Program FilesUbisoftTHE SETTLERS — Расцвет империиbasebinSettlers6.exe:*:Enabled:THE SETTLERS — Расцвет империи»
«C:WINDOWSExplorer.EXE»=»C:WINDOWSExplorer.EXE:*:Enabled:ENABLE»
«C:WINDOWSsystem32userinit.exe»=»C:WINDOWSsystem32userinit.exe:*:Enabled:ENABLE»
«C:Program FilesGamesCSSSteamAppscommonleft 4 deadleft4dead.exe»=»C:Program FilesGamesCSSSteamAppscommonleft 4 deadleft4dead.exe:*:Enabled:Left 4 Dead»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2D]
shellAutoRuncommand — D:autorun.exe======List of files/folders created in the last 3 months======
2009-03-12 22:41:43 —-D—- C:Program Filestrend micro
2009-03-12 22:41:40 —-D—- C:rsit
2009-03-12 07:42:40 —-HDC—- C:WINDOWS$NtUninstallKB960225$
2009-03-12 07:42:35 —-HDC—- C:WINDOWS$NtUninstallKB958690$
2009-03-12 07:42:18 —-HDC—- C:WINDOWS$NtUninstallKB959772_WM11$
2009-02-27 22:54:32 —-HDC—- C:WINDOWS$NtUninstallKB967715$
2009-02-16 17:03:56 —-D—- C:Documents and SettingsОлегApplication DataMount&Blade
2009-02-12 05:58:30 —-HDC—- C:WINDOWS$NtUninstallKB960715$
2009-02-11 20:55:04 —-D—- C:Documents and SettingsAll UsersApplication DataTages
2009-02-08 20:03:44 —-RA—- C:WINDOWSsystem32tmp180.tmp
2009-02-08 20:03:44 —-RA—- C:WINDOWSsystem32tmp17F.tmp
2009-02-05 20:27:46 —-D—- C:Documents and SettingsОлегApplication DataQIP.Online
2009-01-31 11:52:55 —-D—- C:Program FilesMSXML 6.0
2009-01-31 11:52:32 —-HDC—- C:WINDOWS$NtUninstallKB925720$
2009-01-30 18:04:45 —-D—- C:Program FilesMSBuild
2009-01-30 18:02:25 —-D—- C:WINDOWSsystem32XPSViewer
2009-01-30 18:01:08 —-D—- C:Program FilesReference Assemblies
2009-01-30 18:00:32 —-N—- C:WINDOWSsystem32spmsg2.dll
2009-01-30 18:00:03 —-HDC—- C:WINDOWS$NtUninstallWIC$
2009-01-30 17:57:25 —-D—- C:Program FilesMicrosoft Games for Windows — LIVE
2009-01-28 22:13:15 —-A—- C:WINDOWSsystem32pbsvc.exe
2009-01-28 15:07:37 —-HDC—- C:WINDOWS$NtUninstallKB896256$
2009-01-25 17:13:08 —-D—- C:Documents and SettingsОлегApplication Datadvdcss
2009-01-25 17:12:23 —-D—- C:Program FilesVideoLAN
2009-01-23 11:09:45 —-D—- C:Program FilesUbisoft
2009-01-23 10:31:17 —-D—- C:Program FilesHalf Life 2
2009-01-15 07:41:33 —-HDC—- C:WINDOWS$NtUninstallKB958687$
2009-01-09 20:56:24 —-D—- C:Program FilesSnowball Interactive
2009-01-09 15:43:10 —-D—- C:Sierra
2008-12-29 14:11:08 —-A—- C:WINDOWSRomeTW.ini
2008-12-26 23:28:47 —-D—- C:Program FilesGSC Game World
2008-12-26 21:00:36 —-A—- C:WINDOWSWar3Unin.exe
2008-12-26 20:57:26 —-D—- C:Program FilesWarcraft III
2008-12-17 19:42:38 —-D—- C:Program FilesWorld of Warcraft
2008-12-17 06:51:56 —-D—- C:Documents and SettingsAll UsersApplication DataBlizzard
2008-12-16 21:23:35 —-D—- C:Logs
2008-12-16 20:49:17 —-SHD—- C:WINDOWSCSC
2008-12-16 18:03:38 —-A—- C:WINDOWSntbtlog.txt======List of files/folders modified in the last 3 months======
2009-03-12 22:48:38 —-D—- C:Program FilesMozilla Firefox
2009-03-12 22:47:58 —-D—- C:WINDOWS
2009-03-12 22:46:47 —-RD—- C:Program Files
2009-03-12 22:46:06 —-D—- C:Program FilesCommon FilesInstallShield
2009-03-12 22:46:03 —-A—- C:WINDOWSSIERRA.INI
2009-03-12 22:39:54 —-D—- C:WINDOWSTemp
2009-03-12 22:36:44 —-D—- C:WINDOWSRegistration
2009-03-12 22:35:36 —-A—- C:WINDOWSODBC.INI
2009-03-12 22:34:51 —-D—- C:WINDOWSsystem32drivers
2009-03-12 21:12:24 —-D—- C:WINDOWSPrefetch
2009-03-12 20:31:31 —-D—- C:WINDOWSsystem32CatRoot2
2009-03-12 17:01:02 —-D—- C:WINDOWSHelp
2009-03-12 16:28:41 —-D—- C:WINDOWSsystem32
2009-03-12 07:42:50 —-A—- C:WINDOWSSchedLgU.Txt
2009-03-12 07:42:43 —-HD—- C:WINDOWSinf
2009-03-12 07:42:42 —-RSHDC—- C:WINDOWSsystem32dllcache
2009-03-12 07:42:38 —-A—- C:WINDOWSimsins.BAK
2009-03-12 07:26:56 —-HD—- C:WINDOWS$hf_mig$
2009-03-12 07:25:34 —-D—- C:Program FilesMessenger
2009-02-28 08:24:55 —-D—- C:WINDOWS.2
2009-02-12 05:58:07 —-D—- C:Program FilesInternet Explorer
2009-02-08 20:03:48 —-A—- C:WINDOWSsystem32wrap_oal.dll
2009-02-08 20:03:48 —-A—- C:WINDOWSsystem32OpenAL32.dll
2009-02-04 02:21:12 —-A—- C:WINDOWSsystem32MRT.exe
2009-01-31 11:45:27 —-D—- C:WINDOWSMicrosoft.NET
2009-01-30 18:05:18 —-A—- C:WINDOWSsystem32PerfStringBackup.INI
2009-01-30 18:02:21 —-RSD—- C:WINDOWSFonts
2009-01-28 22:14:31 —-A—- C:WINDOWSsystem32PnkBstrB.exe
2009-01-28 15:09:32 —-D—- C:Program FilesAGEIA Technologies
2009-01-27 12:48:01 —-AT—- C:WINDOWSsystem32SIntfNT.dll
2009-01-27 12:48:01 —-AT—- C:WINDOWSsystem32SIntf32.dll
2009-01-27 12:48:01 —-AT—- C:WINDOWSsystem32SIntf16.dll
2009-01-17 17:53:33 —-D—- C:WINDOWSsystem32CatRoot_bak
2009-01-17 17:53:33 —-D—- C:WINDOWSsystem32CatRoot
2009-01-16 21:35:14 —-A—- C:WINDOWSsystem32mshtml.dll
2008-12-31 13:20:06 —-A—- C:WINDOWSsystem32CmdLineExt.dll
2008-12-28 21:39:03 —-D—- C:WINDOWSWinSxS
2008-12-28 21:31:06 —-D—- C:Program FilesMicrosoft Games
2008-12-26 23:44:56 —-D—- C:Documents and Settings
2008-12-21 02:15:41 —-A—- C:WINDOWSsystem32wininet.dll
2008-12-21 02:15:40 —-A—- C:WINDOWSsystem32webcheck.dll
2008-12-21 02:15:40 —-A—- C:WINDOWSsystem32urlmon.dll
2008-12-21 02:15:39 —-A—- C:WINDOWSsystem32url.dll
2008-12-21 02:15:38 —-N—- C:WINDOWSsystem32occache.dll
2008-12-21 02:15:38 —-A—- C:WINDOWSsystem32pngfilt.dll
2008-12-21 02:15:32 —-N—- C:WINDOWSsystem32mstime.dll
2008-12-21 02:15:31 —-N—- C:WINDOWSsystem32msrating.dll
2008-12-21 02:15:30 —-A—- C:WINDOWSsystem32mshtmled.dll
2008-12-21 02:15:24 —-A—- C:WINDOWSsystem32msfeedsbs.dll
2008-12-21 02:15:23 —-N—- C:WINDOWSsystem32jsproxy.dll
2008-12-21 02:15:23 —-A—- C:WINDOWSsystem32msfeeds.dll
2008-12-21 02:15:22 —-A—- C:WINDOWSsystem32iertutil.dll
2008-12-21 02:15:21 —-N—- C:WINDOWSsystem32iernonce.dll
2008-12-21 02:15:21 —-A—- C:WINDOWSsystem32ieframe.dll
2008-12-21 02:15:16 —-N—- C:WINDOWSsystem32iedkcs32.dll
2008-12-21 02:15:15 —-A—- C:WINDOWSsystem32ieapfltr.dll
2008-12-21 02:15:14 —-N—- C:WINDOWSsystem32ieaksie.dll
2008-12-21 02:15:14 —-N—- C:WINDOWSsystem32ieakeng.dll
2008-12-21 02:15:13 —-N—- C:WINDOWSsystem32extmgr.dll
2008-12-21 02:15:13 —-A—- C:WINDOWSsystem32icardie.dll
2008-12-21 02:15:13 —-A—- C:WINDOWSsystem32dxtrans.dll
2008-12-21 02:15:12 —-A—- C:WINDOWSsystem32dxtmsft.dll
2008-12-21 02:15:11 —-N—- C:WINDOWSsystem32advpack.dll
2008-12-19 12:10:15 —-N—- C:WINDOWSsystem32ie4uinit.exe
2008-12-19 12:10:15 —-A—- C:WINDOWSsystem32ieudinit.exe
2008-12-19 08:23:56 —-N—- C:WINDOWSsystem32ieakui.dll
2008-12-17 20:16:12 —-D—- C:Program FilesCommon FilesBlizzard Entertainment======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Amfilter;A4Tech Mouse Filter Driver; C:WINDOWSsystem32DRIVERSAmfilter.sys [2007-05-15 9216]
R1 appdrv01;Application Driver (01); C:WINDOWSSystem32Driversappdrv01.sys [2008-03-10 2915944]
R1 intelppm;Intel Processor Driver; C:WINDOWSsystem32DRIVERSintelppm.sys [2006-05-05 36096]
R1 kbdhid;Keyboard HID Driver; C:WINDOWSsystem32DRIVERSkbdhid.sys [2004-08-03 14848]
R1 nvport;NVIDIA PORT IO Control Driver; ??C:WINDOWSsystem32Driversnvport.sys []
R1 prodrv06;StarForce Protection Environment Driver v6; C:WINDOWSSystem32driversprodrv06.sys [2004-09-03 54368]
R1 SandBox;SandBox; C:WINDOWSsystem32DRIVERSSandBox.sys [2007-04-28 378440]
R1 VFILT;Outpost Security Suite Kernel Driver; ??C:Program FilesAgnitumOutpost Security SuitekernelFILTNT.SYS []
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:WINDOWSSystem32driversws2ifsl.sys [2006-05-05 12032]
R2 atksgt;atksgt; C:WINDOWSsystem32DRIVERSatksgt.sys [2009-02-11 278984]
R2 lirsgt;lirsgt; C:WINDOWSsystem32DRIVERSlirsgt.sys [2007-06-21 18048]
R3 ADBLOCK.DLL;Outpost Security Suite PlugIn (ADBLOCK.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelADBLOCK.DLL []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:WINDOWSsystem32driversADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:WINDOWSsystem32driversAEAudio.sys [2005-03-04 127872]
R3 ARP.DLL;Outpost Security Suite PlugIn (ARP.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelARP.DLL []
R3 ASWFilt;ASWFilt; C:WINDOWSsystem32FiltASWFilt.dll [2007-04-28 31112]
R3 CONTENT.DLL;Outpost Security Suite PlugIn (CONTENT.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelCONTENT.DLL []
R3 DNSCACHE.DLL;Outpost Security Suite PlugIn (DNSCACHE.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelDNSCACHE.DLL []
R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:WINDOWSsystem32DRIVERSfetnd5bv.sys [2005-10-18 42496]
R3 FTPFILT.DLL;Outpost Security Suite PlugIn (FTPFILT.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelFTPFILT.DLL []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:WINDOWSsystem32DRIVERSHDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:WINDOWSsystem32DRIVERShidusb.sys [2001-08-17 9600]
R3 HTMLFILT.DLL;Outpost Security Suite PlugIn (HTMLFILT.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelHTMLFILT.DLL []
R3 HTTPFILT.DLL;Outpost Security Suite PlugIn (HTTPFILT.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelHTTPFILT.DLL []
R3 MAILFILT.DLL;Outpost Security Suite PlugIn (MAILFILT.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelMAILFILT.DLL []
R3 mouhid;Mouse HID Driver; C:WINDOWSsystem32DRIVERSmouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:WINDOWSsystem32DRIVERSASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:WINDOWSsystem32DRIVERSnv4_mini.sys [2008-10-07 6133856]
R3 pfc;Padus ASPI Shell; C:WINDOWSsystem32driverspfc.sys [2005-06-13 9856]
R3 PROTECT.DLL;Outpost Security Suite PlugIn (PROTECT.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelPROTECT.DLL []
R3 SECRET.DLL;Outpost Security Suite PlugIn (SECRET.DLL); ??C:Program FilesAgnitumOutpost Security SuitekernelSECRET.DLL []
R3 SenFiltService;SenFilt Service; C:WINDOWSsystem32driversSenfilt.sys [2005-08-11 393088]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:WINDOWSsystem32DRIVERSusbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:WINDOWSsystem32DRIVERSusbehci.sys [2006-05-05 26624]
R3 usbhub;USB2 Enabled Hub; C:WINDOWSsystem32DRIVERSusbhub.sys [2006-05-05 57600]
R3 USBSTOR;USB Mass Storage Driver; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:WINDOWSsystem32DRIVERSusbuhci.sys [2006-05-05 20480]
R3 VBEngNT;VBEngNT; C:WINDOWSsystem32DRIVERSVBEngNT.sys [2006-12-05 798366]
R3 VBFilt;VBFilt; C:WINDOWSsystem32FiltVBFilt.dll [2007-04-28 156992]
S2 amd64si;amd64si; ??C:WINDOWSsystem32driversamd64si.sys []
S2 ati64si;ati64si; ??C:WINDOWSsystem32driversati64si.sys []
S2 fips32cup;fips32cup; ??C:WINDOWSsystem32driversfips32cup.sys []
S2 ksi32sk;ksi32sk; ??C:WINDOWSsystem32driversksi32sk.sys []
S2 nicsk32;nicsk32; ??C:WINDOWSsystem32driversnicsk32.sys []
S2 port135sik;port135sik; ??C:WINDOWSsystem32driversport135sik.sys []
S2 securentm;securentm; ??C:WINDOWSsystem32driverssecurentm.sys []
S2 ws2_32sik;ws2_32sik; ??C:WINDOWSsystem32driversws2_32sik.sys []
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:WINDOWSsystem32DRIVERSAmusbprt.sys [2007-05-15 14336]
S3 CCDECODE;Closed Caption Decoder; C:WINDOWSsystem32DRIVERSCCDECODE.sys [2004-08-03 17024]
S3 dtscsi;dtscsi; C:WINDOWSSystem32Driversdtscsi.sys [2008-10-05 223128]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:WINDOWSsystem32DRIVERSfetnd5.sys [2001-08-17 27165]
S3 hamachi;Hamachi Network Interface; C:WINDOWSsystem32DRIVERShamachi.sys [2008-10-26 25544]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:WINDOWSsystem32driversHdAudio.sys [2005-01-07 145920]
S3 MHNDRV;MHN driver; C:WINDOWSsystem32DRIVERSmhndrv.sys [2004-08-10 11008]
S3 MR97310_USB_DUAL_CAMERA;CIF Dual-Mode Camera; C:WINDOWSsystem32DRIVERSmr97310c.sys [2006-05-02 110720]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:WINDOWSsystem32driversMSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:WINDOWSsystem32DRIVERSNABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:WINDOWSsystem32DRIVERSNdisIP.sys [2004-08-03 10880]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM); C:WINDOWSsystem32DRIVERSsea1bus.sys [2007-01-04 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter; C:WINDOWSsystem32DRIVERSsea1mdfl.sys [2007-02-08 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver; C:WINDOWSsystem32DRIVERSsea1mdm.sys [2007-02-08 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM); C:WINDOWSsystem32DRIVERSsea1mgmt.sys [2007-02-08 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS); C:WINDOWSsystem32DRIVERSsea1nd5.sys [2007-02-08 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface; C:WINDOWSsystem32DRIVERSsea1obex.sys [2006-11-20 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM); C:WINDOWSsystem32DRIVERSsea1unic.sys [2007-02-08 90800]
S3 SLIP;BDA Slip De-Framer; C:WINDOWSsystem32DRIVERSSLIP.sys [2004-08-03 11136]
S3 StillCam;Still Serial Digital Camera Driver; C:WINDOWSsystem32DRIVERSserscan.sys [2001-08-17 6784]
S3 streamip;BDA IPSink; C:WINDOWSsystem32DRIVERSStreamIP.sys [2004-08-03 15360]
S3 usbprint;Microsoft USB PRINTER Class; C:WINDOWSsystem32DRIVERSusbprint.sys [2004-08-03 25856]
S3 WSTCODEC;World Standard Teletext Codec; C:WINDOWSsystem32DRIVERSWSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []
S4 sr;System Restore Filter Driver; C:WINDOWSsystem32DRIVERSsr.sys [2006-05-05 73472]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ehRecvr;Media Center Receiver Service; C:WINDOWSeHomeehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:WINDOWSeHomeehSched.exe [2005-08-05 102912]
R2 McrdSvc;Media Center Extender Service; C:WINDOWSehomemcrdsvc.exe [2005-08-05 99328]
R2 MDM;Machine Debug Manager; C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:WINDOWSsystem32nvsvc32.exe [2008-10-07 163908]
R2 OutpostSecuritySuite;Outpost Security Suite Service; C:Program FilesAgnitumOutpost Security Suiteoutpost.exe [2007-04-28 120832]
R2 PnkBstrA;PnkBstrA; C:WINDOWSsystem32PnkBstrA.exe [2007-11-18 66872]
R2 PnkBstrB;PnkBstrB; C:WINDOWSsystem32PnkBstrB.exe [2009-01-28 107832]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:WINDOWSSystem32appdrvrem01.exe [2008-03-10 304528]
S2 pr2aslcb;FlatOut: Ultimate Carnage Drivers Auto Removal (pr2aslcb); C:WINDOWSsystem32pr2aslcb.exe [2008-07-09 415120]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:WINDOWSsystem32sfrem01.exe [2006-07-05 358008]
S3 Adobe LM Service;Adobe LM Service; C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe [2008-09-23 68096]
S3 Adpsumsn;Adpsumsn; C:WINDOWSsystem32driversnwlnkflt.sys [2006-05-05 12416]
S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:WINDOWSMicrosoft.NetFrameworkv3.0WPFPresentationFontCache.exe [2006-10-20 36864]
S3 gusvc;Google Updater Service; C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe [2007-11-02 138168]
S3 IDriverT;InstallDriver Table Manager; C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe []
S3 idsvc;Windows CardSpace; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication Foundationinfocard.exe [2006-10-30 741376]
S3 MHN;MHN; C:WINDOWSSystem32svchost.exe [2006-05-05 14336]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Служба общих сетевых ресурсов проигрывателя Windows Media; C:Program FilesWindows Media PlayerWMPNetwk.exe [2006-11-02 914944]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2006-05-05 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication FoundationSMSvcHost.exe [2006-10-30 122880]
EOF
С уважением,Домин Олег
13 марта, 2009 в 5:53 пп #22590Здравствуйте Олег, добро пожаловать на Spyware-ru форум.
Прочитайте описание программы Malwarebytes Anti-malware (MBAM).
Скачайте и выполните сканирование вашего компьютера. Удалите всё что будет найдено. В конце работы будет показан лог.В ваш ответ вставьте MBAM лог и свежий RSIT лог.
-
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.