Созданные ответы форума
-
АвторСообщения
-
Здравствуйте!Спасибо за помощь!Сделала все как вы сказали,правда вся запуталась вначале))
Вот лог:
ComboFix 09-11-04.05 — Admin 07.11.2009 18:26.6.1 — NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.511.77 [GMT 3:00]
Running from: c:documents and settingsAdminРабочий столComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.((((((((((((((((((((((((( Files Created from 2009-10-07 to 2009-11-07 )))))))))))))))))))))))))))))))
.2009-10-31 09:53 . 2009-10-31 09:55
d
w- c:program filestrend micro
2009-10-31 09:53 . 2009-10-31 09:55
d
w- C:rsit
2009-10-30 16:25 . 2009-10-30 16:25 932368 —-a-w- c:documents and settingsAll UsersApplication DataKaspersky LabAVP9DataKasFltPluginsprofiles-1-6.dll
2009-10-30 16:25 . 2009-10-30 16:25 678416 —-a-w- c:documents and settingsAll UsersApplication DataKaspersky LabAVP9DataKasFltPluginscontent_interpreter-1-1.dll
2009-10-30 16:25 . 2009-10-30 16:25 604688 —-a-w- c:documents and settingsAll UsersApplication DataKaspersky LabAVP9DataKasFltPluginsgsg-3-9.dll
2009-10-30 16:25 . 2009-10-30 16:25 1096208 —-a-w- c:documents and settingsAll UsersApplication DataKaspersky LabAVP9DataKasFltPluginsfiltration-4-6.dll
2009-10-30 16:25 . 2009-10-30 16:25 522768 —-a-w- c:documents and settingsAll UsersApplication DataKaspersky LabAVP9DataKasFltPluginsdatabase-1-5.dll
2009-10-30 15:35 . 2009-10-30 15:35 95259 —-a-w- c:windowssystem32driversklick.dat
2009-10-30 15:35 . 2009-10-30 15:35 108059 —-a-w- c:windowssystem32driversklin.dat
2009-10-30 15:34 . 2009-11-07 16:46
d
w- c:documents and settingsAll UsersApplication DataKaspersky Lab
2009-10-30 15:34 . 2009-10-30 15:34
d
w- c:program filesKaspersky Lab
2009-10-30 15:27 . 2009-10-30 15:27
d
w- c:documents and settingsAll UsersApplication DataKaspersky Lab Setup Files
2009-10-29 21:28 . 2009-10-30 20:31
d
w- c:documents and settingsAdminApplication DataCMedia
2009-10-29 21:28 . 2009-10-29 21:28 750592 —-a-w- c:documents and settingsAdminApplication DataCMediaCMedia.dll
2009-10-20 17:34 . 2009-10-20 17:34 219664 —-a-w- c:windowssystem32klogon.dll
2009-10-20 16:46 . 2009-10-20 16:46 59992 —-a-w- c:documents and settingsAll UsersApplication DataKaspersky Lab Setup FilesKaspersky Internet Security 2010 9.0.0.736Russiansetup.exe
2009-10-17 16:37 . 2009-10-17 16:37
d
w- c:documents and settingsAdminLocal SettingsApplication DataMozilla
2009-10-16 18:37 . 2009-10-16 18:37
d-sh—w- c:documents and settingsAdminPrivacIE
2009-10-16 18:33 . 2009-10-16 18:33
d-sh—w- c:documents and settingsAdminIETldCache
2009-10-16 18:05 . 2009-10-16 18:28
dc-h—w- c:windowsie8
2009-10-16 18:04 . 2009-10-16 18:30
d—h—w- c:windowsmsdownld.tmp
2009-10-14 18:18 . 2009-10-14 18:18 36880 —-a-w- c:windowssystem32driversklbg.sys.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 10:14 . 2009-10-04 18:08
d
w- c:documents and settingsAdminApplication DatauTorrent
2009-11-05 13:57 . 2009-01-21 15:12
d
w- c:program filesPunto Switcher
2009-11-01 10:50 . 2009-09-19 16:13
d
w- c:program filesTM FilePacker
2009-10-30 18:47 . 2009-10-29 21:28 87374 —-a-w- c:documents and settingsAdminApplication Datafieryads.dat
2009-10-30 18:13 . 2009-01-21 15:16
d
w- c:program filesAIMP2
2009-10-25 08:19 . 2008-04-15 12:00 84660 —-a-w- c:windowssystem32perfc019.dat
2009-10-25 08:19 . 2008-04-15 12:00 485242 —-a-w- c:windowssystem32perfh019.dat
2009-10-16 18:33 . 2009-09-18 20:42
d
w- c:program filesRambler Assistant
2009-10-13 18:51 . 2009-01-21 15:36
d
w- c:program filesCommon FilesAdobe
2009-10-07 13:51 . 2009-10-04 17:50
d
w- c:program filesuTorrent
2009-10-04 18:14 . 2009-10-04 17:28
d—h—w- c:program filesRS
2009-10-02 16:39 . 2009-10-02 16:39 19472 —-a-w- c:windowssystem32driversklmouflt.sys
2009-09-30 17:34 . 2009-09-26 17:04
d
w- c:program filesDownload Master
2009-09-29 12:35 . 2009-09-29 12:34
d
w- c:documents and settingsAdminApplication DataMra
2009-09-29 12:34 . 2009-09-29 12:34
d
w- c:program filesMail.Ru
2009-09-27 13:47 . 2009-09-05 21:44
d
w- c:documents and settingsAdminApplication DataDownload Master
2009-09-25 07:27 . 2009-09-25 07:27
d
w- c:program filesBeeline
2009-09-25 06:29 . 2009-01-21 15:12
d—h—w- c:program filesInstallShield Installation Information
2009-09-24 06:02 . 2009-01-21 16:20
d
w- c:documents and settingsAdminApplication DataCanon
2009-09-21 08:12 . 2009-09-21 08:12
d
w- c:documents and settingsAdminApplication DataRegensoft
2009-09-21 08:08 . 2009-09-21 08:08
d
w- c:program filesRegensoft
2009-09-21 08:07 . 2009-09-21 08:07
d
w- c:program filesAviSynth 2.5
2009-09-19 16:14 . 2009-09-19 16:14
d
w- c:documents and settingsAdminApplication DataTMAgency
2009-09-19 16:13 . 2009-09-19 16:13
d
w- c:program filesCommon FilesTM FilePacker
2009-09-19 14:23 . 2009-09-18 20:36
d
w- c:documents and settingsAdminApplication DataICQ
2009-09-18 20:42 . 2009-09-18 20:42
d
w- c:documents and settingsAdminApplication Datarambler.ru
2009-09-14 11:42 . 2009-09-14 11:42 32272 —-a-w- c:windowssystem32driversklim5.sys
2009-09-13 08:10 . 2009-09-13 08:10 1961720 —-a-w- c:documents and settingsAdminApplication DataMacromediaFlash Playerwww.macromedia.combinfpupdateaxfpupdateax.exe
2009-09-12 14:49 . 2009-09-12 14:49
d
w- c:documents and settingsAdminApplication DataMegaFon
2009-09-12 14:45 . 2009-09-12 14:43
d
w- c:program filesMegaFon Internet
2009-09-09 16:01 . 2009-09-09 16:01 27675 —-a-w- c:windowssystem32driversklopp.dat
2009-09-01 12:29 . 2009-09-01 12:29 128016 —-a-w- c:windowssystem32driverskl1.sys
2009-08-21 10:51 . 2009-01-21 14:59 86327 —-a-w- c:windowspchealthhelpctrOfflineCacheindex.dat
.
Sigcheck
[-] 2008-05-20 . 030DC4D48CC2B894FEE2F390D8E66AD5 . 361344 . . [5.1.2600.5512] . . c:windowssystem32driverstcpip.sys[-] 2008-05-20 . 5F38B1B965527C6F5C30DEDAB0AB0550 . 80216 . . [7.0.6000.381] . . c:windowssystem32wuauclt.exe
[-] 2008-05-20 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:windowssystem32user32.dll
[-] 2008-05-20 . DC5D73A9809B66026231A9D49DE6987F . 1721344 . . [6.00.2900.5512] . . c:windowsexplorer.exe
[-] 2008-05-20 . 46D60730EE2DF438750B38370425BC74 . 1571840 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll
[-] 2008-05-20 . AE0DB25EE10900C73D923AD5880564CF . 30208 . . [5.1.2600.5512] . . c:windowssystem32ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiersCMedia]
@=»{6B830884-20E3-4AB6-B672-2629F0F72071}»
[HKEY_CLASSES_ROOTCLSID{6B830884-20E3-4AB6-B672-2629F0F72071}]
2009-10-29 21:28 750592 —-a-w- c:docume~1AdminAPPLIC~1CMediaCMedia.dll[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
«VistaIcon»=»c:program filesVistaDriveIconVistaDrv.exe» [2008-01-02 132096]
«Punto Switcher»=»c:program filesPunto Switcherps.exe» [2007-11-14 201728]
«AlcoholAutomount»=»c:program filesAlcohol SoftAlcohol 120axcmd.exe» [2007-08-01 222592]
«PcSync»=»c:program filesNokiaNokia PC Suite 6PcSync2.exe» [2006-06-27 1449984]
«Download Master»=»d:program filesDownload Masterdmaster.exe» [2009-10-02 3779072]
«Beeline GPRS Explorer»=»c:program filesBeelineGPRS Explorergprsexpl.exe» [2007-01-12 834632][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
«SoundMAXPnP»=»c:program filesAnalog DevicesCoresmax4pnp.exe» [2007-03-16 868352]
«AmlMaple»=»c:program filesAmlMapleAmlMaple.exe» [2008-04-24 91648]
«TrueImageMonitor.exe»=»c:program filesAcronisTrueImageHomeTrueImageMonitor.exe» [2007-11-20 2615896]
«AcronisTimounterMonitor»=»c:program filesAcronisTrueImageHomeTimounterMonitor.exe» [2007-11-20 910864]
«Acronis Scheduler2 Service»=»c:program filesCommon FilesAcronisSchedule2schedhlp.exe» [2007-11-20 140568]
«MediaLingua AlphaLex 5.0 English»=»c:program filesMediaLinguaAlphaLex 5.0 Englishmultilex.exe» [2005-08-14 1277952]
«MAgent»=»c:program filesMail.RuAgentMAgent.exe» [2009-09-29 7975608]
«Adobe Reader Speed Launcher»=»c:program filesAdobeReader 8.0ReaderReader_sl.exe» [2008-10-14 39792]
«AVP»=»c:program filesKaspersky LabKaspersky Internet Security 2010avp.exe» [2009-10-20 340456]
«BluetoothAuthenticationAgent»=»bthprops.cpl» — c:windowssystem32bthprops.cpl [2008-04-15 110592][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=»c:windowssystem32CTFMON.EXE» [2008-05-20 30208]
«VistaIcon»=»c:program filesVistaDriveIconVistaDrv.exe» [2008-01-02 132096][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
«IE7_011″=»shell32» [X]
«ZZZZ2_FirstLogonSetting»=»advpack.dll» — c:windowssystem32advpack.dll [2009-03-08 128512]
«IE7_012″=»advpack.dll» — c:windowssystem32advpack.dll [2009-03-08 128512]c:documents and settingsAll Usersѓ« ў®Ґ ¬ҐоЏа®Ја ¬¬лЂўв®§ Јаг§Є
BlueSoleil.lnk — d:bluetoothBlueSoleil.exe [2006-4-28 872526][HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)[HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)[HKLM~startupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Adobe Gamma Loader.lnk]
path=c:documents and settingsAll UsersГлавное менюПрограммыАвтозагрузкаAdobe Gamma Loader.lnk
backup=c:windowspssAdobe Gamma Loader.lnkCommon Startup[HKLM~startupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Adobe Reader Speed Launch.lnk]
path=c:documents and settingsAll UsersГлавное менюПрограммыАвтозагрузкаAdobe Reader Speed Launch.lnk
backup=c:windowspssAdobe Reader Speed Launch.lnkCommon Startup[HKLM~startupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Adobe Reader Synchronizer.lnk]
path=c:documents and settingsAll UsersГлавное менюПрограммыАвтозагрузкаAdobe Reader Synchronizer.lnk
backup=c:windowspssAdobe Reader Synchronizer.lnkCommon Startup[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
«FirewallOverride»=dword:00000001
«UpdatesOverride»=dword:00000001
«AntiVirusOverride»=dword:00000001[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringKasperskyAntiVirus]
«DisableMonitoring»=dword:00000001[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
«EnableFirewall»= 0 (0x0)[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
«%windir%\Network Diagnostic\xpnetdiag.exe»=
«%windir%\system32\sessmgr.exe»=
«d:\Bluetooth\BlueSoleil.000″=
«d:\Program Files\ICQ6.5\ICQ.exe»=
«c:\Program Files\uTorrent\uTorrent.exe»=
«d:\Мои документы\программы\Kyodai Mahjongg\kyodai.exe»=
«d:\Мои документы\программы\торрент\utorrent.exe»=R0 klbg;Kaspersky Lab Boot Guard Driver;c:windowssystem32driversklbg.sys [14.10.2009 21:18 36880]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:windowssystem32driversklim5.sys [14.09.2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:windowssystem32driversklmouflt.sys [02.10.2009 19:39 19472]
S3 hwusbfake;Huawei DataCard USB Fake;c:windowssystem32driversewusbfake.sys [12.09.2009 17:43 102656]— Other Services/Drivers In Memory —
*NewlyCreated* — MBR
*NewlyCreated* — WUAUSERV
*Deregistered* — mbr[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled componentsWindows Sidebar]
c:windowssystem32hidec /W c:program filesWindows SidebarVAIOToolsREGTLIB.EXE «c:program filesWindows Sidebarsidebar.exe»[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{34A19196-274E-4D75-9D30-D7A45A0A4178}]
«c:program filesWindows Sidebar.regsvr32.exe» /s wlsrvc.dll[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{6B9228DA-9C15-419e-856C-19E768A13BDC}]
«c:program filesWindows Sidebar.regsvr32.exe» /s sbdrop.dll[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{BADA65A0-86B7-462B-B720-CE66655C73F5}]
regsvr32 /s c:program filesWindows SidebarVAIO.vshellext.dll
.
Contents of the ‘Scheduled Tasks’ folder2009-11-07 c:windowsTasksUser_Feed_Synchronization-{E8BE6AD1-5010-4F78-9FFB-17C2F8484266}.job
— c:windowssystem32msfeedssync.exe [2009-01-21 00:31]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.rambler.ru/ie8
uInternet Settings,ProxyOverride =
IE: &Экспорт в Microsoft Excel — c:progra~1MICROS~2OFFICE11EXCEL.EXE/3000
IE: Добавить в Rambler-Закладки — c:program filesRambler AssistantramblertoolbarU5950.dll/zakladki.htm
IE: Добавить в Анти-Баннер — c:program filesKaspersky LabKaspersky Internet Security 2010ie_banner_deny.htm
IE: Закачать ВСЕ при помощи Download Master — d:program filesDownload Masterdmieall.htm
IE: Закачать при помощи Download Master — d:program filesDownload Masterdmie.htm
IE: Найти с помощью Рамблера — c:program filesRambler AssistantramblertoolbarU5950.dll/search.htm
IE: Перевести с помощью словарей Рамблера — c:program filesRambler AssistantramblertoolbarU5950.dll/dic.htm
IE: Передать на удаленную закачку DM — d:program filesDownload Masterremdown.htm
IE: Поиск@Mail.Ru — c:program filesmail.rusputnikMailRuSputnik.dll/282
IE: Словари@Mail.Ru — c:program filesmail.rusputnikMailRuSputnik.dll/283
IE: {{7558B7E5-7B26-4201-BEDB-00D5FF534523} — c:program filesMail.RuAgentmagent.exe
IE: {{8DAE90AD-4583-4977-9DD4-4360F7A45C74} — d:program filesDownload Masterdmaster.exe
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
.
— — — — ORPHANS REMOVED — — — —URLSearchHooks-{83821C2B-32A8-4DD7-B6D4-44309A78E668} — c:program filesMail.RuAgentMradllnewmrasearch.dll
Toolbar-Locked — (no file)
HKLM-Run-NevoDRM — c:игрыNevoDRMNevoDRM.exe
AddRemove-CMedia — c:documents and settingsAdminApplication DataCMediaUninstall.exe
AddRemove-Exile — Spirits of the Underworld — c:program filesBethesda SoftworksMorrowindData FilesUninstal.exe
AddRemove-Forgotten Realms Mod v.1.73 — New World Order beta 0.23 — c:program filesBethesda SoftworksMorrowindData FilesUninstal.exe
AddRemove-Wilderness Mod v. 1.1 — c:program filesBethesda SoftworksMorrowindData FilesUninstal Wilderness Mod v1.1.exe**************************************************************************
catchme 0.3.1398 W2K/XP/Vista — rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-07 19:45
Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys sfsync02.sys hal.dll atapi.sys spec.sys >>UNKNOWN [0x8238F938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.netatapi.sys @ 0x0 0x0 bytes
Driveratapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF836AB40 atapi.sys
Driveratapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF836AB40 atapi.sys
Driveratapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF836AB40 atapi.sys
Driveratapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF85678B4 sfsync02.sys
Driveratapi [ IRP_MJ_POWER ] 0xA73C != 0xF836AB40 atapi.sys
Driveratapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF836AB40 atapi.sys
Driveratapi IRP hooks detected !**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001Services{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
«ImagePath»=»??c:program filesCyberLinkPowerDVD00.fcl»
.
LOCKED REGISTRY KEYS
[HKEY_USERSS-1-5-21-776561741-926492609-1177238915-500SoftwareMicrosoftInternet ExplorerUser Preferences]
@Denied: (2) (Administrator)
«88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977″=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e2,55,48,c7,c9,48,bb,4c,9d,75,74,
«2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81″=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e2,55,48,c7,c9,48,bb,4c,9d,75,74,
«6256FFB019F8FDFBD36745B06F4540E9AEAF222A25″=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e2,55,48,c7,c9,48,bb,4c,9d,75,74,
.
DLLs Loaded Under Running Processes
— — — — — — — > ‘winlogon.exe'(1200)
c:windowssystem32SETUPAPI.dll
c:windowssystem32Ati2evxx.dll
c:windowssystem32cscui.dll
c:windowssystem32COMRes.dll— — — — — — — > ‘lsass.exe'(1256)
c:windowssystem32relog_ap.dll
c:windowssystem32SETUPAPI.dll— — — — — — — > ‘explorer.exe'(6436)
c:program filesAmlMapleAmlMaple.dll
c:windowssystem32COMRes.dll
c:docume~1AdminAPPLIC~1CMediaCMedia.dll
c:program filesPunto Switchercorrect.dll
c:windowsSystem32cscui.dll
c:program filesMediaLinguaAlphaLex 5.0 Englishmlhook.dll
c:windowssystem32msi.dll
c:windowssystem32SETUPAPI.dll
c:windowssystem32ieframe.dll
c:windowssystem32NETSHELL.dll
c:windowssystem32wpdshserviceobj.dll
c:windowssystem32webcheck.dll
c:program filesNokiaNokia PC Suite 6PhoneBrowser.dll
c:program filesNokiaNokia PC Suite 6PCSCM.dll
c:windowssystem32ConnAPI.DLL
c:program filesNokiaNokia PC Suite 6LangPhoneBrowser_rus.nlr
c:program filesNokiaNokia PC Suite 6ResourcePhoneBrowser_Nokia.ngr
c:windowssystem32portabledevicetypes.dll
c:windowssystem32portabledeviceapi.dll
.
Other Running Processes
.
c:windowssystem32Ati2evxx.exe
c:windowssystem32Ati2evxx.exe
c:program filesCommon FilesAcronisSchedule2schedul2.exe
d:bluetoothBTNtService.exe
c:program filesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
c:program filesCyberLinkShared filesRichVideo.exe
c:program filesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe
c:program filesCommon FilesAcronisFomatikTrueImageTryStartService.exe
c:windowssystem32wscntfy.exe
c:windowssystem32rundll32.exe
c:windowssystem32rundll32.exe
c:progra~1NokiaNOKIAP~1LAUNCH~1.EXE
c:program filesCommon FilesPCSuiteServicesServiceLayer.exe
d:bluetoothBlueSoleil.000
c:progra~1COMMON~1NokiaMPAPIMPAPI3s.exe
.
**************************************************************************
.
Completion time: 2009-11-07 19:50 — machine was rebooted
ComboFix-quarantined-files.txt 2009-11-07 16:50Pre-Run: 4 634 836 992 байт свободно
Post-Run: 4 888 014 848 байт свободноВы не поверите, я просмотрела её уже 50 раз.Ёще немного и ваша помощь не понодобится!!
Болше не могу!! 😯 Вот она опять появилась,даже Вам сообщение не даёт написать((
А Вы ,наверное, по выходным не помогаете.Аххх…Так жаль 🙄 -
АвторСообщения

