• Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы

SPYWARE-RU.COM

Меню
  • Инструкции
    • Как использовать
      • Программы
    • Как удалить
      • Шпионское и рекламное ПО (adware и spyware)
      • Поддельное антиспайваре
      • Руткиты
      • Трояны
      • Кейлоггеры
  • Скачать программы
  • Вопросы и Ответы
  • Форумы
В начало
Adguard
 

Ihor

  • Профиль
  • Начатые темы
  • Созданные ответы
  • Engagements
  • Избранное

Созданные ответы форума

Просмотр 3 сообщений - с 1 по 3 (из 3 всего)
  • Автор
    Сообщения
  • 8 ноября, 2009 в 4:08 пп в ответ на: последствия порно банера #26550
    Ihor
    Participant
    • Темы:1
    • Сообщений:4
    • ☆

    Доброго времени суток.
    После перерегистрации почтового ящика, фоновая заставка оставшаяся после порно банера исчезла.
    Огромная Вам благодарность и успехов.

    4 ноября, 2009 в 7:56 дп в ответ на: последствия порно банера #26549
    Ihor
    Participant
    • Темы:1
    • Сообщений:4
    • ☆

    Logfile of random’s system information tool 1.06 (written by random/random)
    Run by Admin at 2009-11-04 09:53:53
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 4 GB (39%) free of 10 GB
    Total RAM: 511 MB (37% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:54:00, on 04.11.2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20900)
    Boot mode: Normal

    Running processes:
    C:WINDOWSSystem32smss.exe
    C:WINDOWSsystem32winlogon.exe
    C:WINDOWSsystem32services.exe
    C:WINDOWSsystem32lsass.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:WINDOWSsystem32spoolsv.exe
    C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
    C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
    C:Program FilesESETESET NOD32 Antivirusekrn.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSystem32svchost.exe
    C:WINDOWSsystem32nvsvc32.exe
    C:WINDOWSSystem32svchost.exe
    C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
    C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
    C:WINDOWSsystem32svchost.exe
    C:WINDOWSSOUNDMAN.EXE
    C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe
    C:Program FilesCyberlinkShared Filesbrs.exe
    C:Program FilesESETESET NOD32 Antivirusegui.exe
    C:Program FilesHPHP Software UpdateHPWuSchd2.exe
    C:Program FilesiTunesiTunesHelper.exe
    C:WINDOWSsystem32ctfmon.exe
    C:Program FilesDownload Masterdmaster.exe
    C:Program FilesHPDigital Imagingbinhpqtra08.exe
    C:Program FilesTransLitetranslite.exe
    C:Program FilesSkypePhoneSkype.exe
    C:Program FilesSkypePlugin ManagerskypePM.exe
    C:Program FilesiPodbiniPodService.exe
    C:Program FilesHPDigital ImagingbinhpqSTE08.exe
    C:Program FilesHPDigital Imagingbinhpqbam08.exe
    C:Program FilesHPDigital Imagingbinhpqgpc01.exe
    C:WINDOWSexplorer.exe
    D:Мои документыЗагрузкиRSIT.exe
    C:Program Filestrend microAdmin.exe

    R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
    O2 — BHO: HP Print Enhancer — {0347C33E-8762-4905-BF09-768834316C61} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
    O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
    O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
    O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll (file missing)
    O2 — BHO: HP Smart BHO Class — {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
    O3 — Toolbar: DM Bar — {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — C:Program FilesDownload Masterdmbar.dll
    O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
    O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
    O4 — HKLM..Run: [nwiz] nwiz.exe /install
    O4 — HKLM..Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 — HKLM..Run: [RemoteControl8] «C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe»
    O4 — HKLM..Run: [PDVD8LanguageShortcut] «C:Program FilesCyberLinkPowerDVD8LanguageLanguage.exe»
    O4 — HKLM..Run: [BDRegion] C:Program FilesCyberlinkShared Filesbrs.exe
    O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
    O4 — HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe
    O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeqttask.exe» -atboottime
    O4 — HKLM..Run: [iTunesHelper] «C:Program FilesiTunesiTunesHelper.exe»
    O4 — HKLM..Run: [hpqSRMon] C:Program FilesHPDigital ImagingbinhpqSRMon.exe
    O4 — HKCU..Run: [Download Master] C:Program FilesDownload Masterdmaster.exe -autorun
    O4 — HKCU..Run: [Skype] «C:Program FilesSkypePhoneSkype.exe» /nosplash /minimized
    O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
    O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
    O4 — HKUSS-1-5-18..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘SYSTEM’)
    O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
    O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
    O4 — Global Startup: BlueSoleil.lnk = C:Program FilesIVT CorporationBlueSoleilgprs.exe
    O4 — Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe
    O4 — Global Startup: Словарь TransLite.lnk = C:Program FilesTransLitetranslite.exe
    O4 — Global Startup: Ускоренный запуск Adobe Reader.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
    O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~1OFFICE11EXCEL.EXE/3000
    O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
    O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
    O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
    O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
    O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~1OFFICE11REFIEBAR.DLL
    O9 — Extra button: Расширенный выбор HP — {DDE87865-83C5-48c4-8357-2F5B1AA84522} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
    O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
    O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
    O23 — Service: Apple Mobile Device — Apple, Inc. — C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
    O23 — Service: BlueSoleil Hid Service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
    O23 — Service: Eset HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
    O23 — Service: Eset Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
    O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
    O23 — Service: Сервис iPod (iPod Service) — Apple Inc. — C:Program FilesiPodbiniPodService.exe
    O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
    O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
    O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
    O23 — Service: SiSoftware Deployment Agent Service (SandraAgentSrv) — SiSoftware — C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
    O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
    O23 — Service: Start BT in service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
    O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
    O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
    O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe

    —
    End of file — 8621 bytes

    4 ноября, 2009 в 7:53 дп в ответ на: последствия порно банера #26547
    Ihor
    Participant
    • Темы:1
    • Сообщений:4
    • ☆

    Доброго времени суток.

    ComboFix 09-11-03.03 — Admin 04.11.2009 9:26.1.1 — NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.511.195 [GMT 2:00]
    Running from: c:combofixComboFix.exe
    Command switches used :: ComboFix
    AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    * Resident AV is active

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:documents and settingsAdminApplication DataAdSubscribe
    c:documents and settingsAdminApplication DataAdSubscribeAdSubscribe.dat
    c:documents and settingsAdminApplication DataAdSubscribeFeed.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed1.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed2.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed3.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed4.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed5.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed6.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed7.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed8.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeed9.jpg
    c:documents and settingsAdminApplication DataAdSubscribeFeedfeed.xml
    c:documents and settingsAdminApplication Dataakokynokeh.ban
    c:documents and settingsAdminApplication DataAldea
    c:documents and settingsAdminApplication Datacafex.com
    c:documents and settingsAdminApplication Datacida.exe
    c:documents and settingsAdminApplication Datadehegim.pif
    c:documents and settingsAdminApplication Dataefogiwa.com
    c:documents and settingsAdminApplication Dataheripozuku.lib
    c:documents and settingsAdminApplication Datamuqy.dll
    c:documents and settingsAdminApplication Dataosigenowus._sy
    c:documents and settingsAdminApplication Dataqozivazi.ban
    c:documents and settingsAdminApplication Dataratofo.bat
    c:documents and settingsAdminApplication Datasefok.scr
    c:documents and settingsAdminApplication Datawunero.dl
    c:documents and settingsAdminLocal SettingsApplication Databixybi.inf
    c:documents and settingsAdminLocal SettingsApplication Databovegohofe.bat
    c:documents and settingsAdminLocal SettingsApplication Datadedekyhoq.bin
    c:documents and settingsAdminLocal SettingsApplication Datadorejaq.exe
    c:documents and settingsAdminLocal SettingsApplication Datairakypig.dll
    c:documents and settingsAdminLocal SettingsApplication Datalosuhineki.ban
    c:documents and settingsAdminLocal SettingsApplication Dataqajuwi._sy
    c:documents and settingsAdminLocal SettingsApplication Dataxogidoput.sys
    c:documents and settingsAdminLocal SettingsApplication Dataycoripa.bat
    c:documents and settingsAdminLocal SettingsApplication Dataytuvabuja.dll
    c:documents and settingsAdminLocal SettingsTemporary Internet Filesbefeguve.inf
    c:documents and settingsAdminLocal SettingsTemporary Internet Filesemajasuxi.inf
    c:documents and settingsAdminLocal SettingsTemporary Internet Filesizyd.dat
    c:documents and settingsAdminLocal SettingsTemporary Internet Filesjunic.reg
    c:documents and settingsAdminLocal SettingsTemporary Internet Filessigijir.dat
    c:documents and settingsAdminoashdihasidhasuidhiasdhiashdiuasdhasd
    c:documents and settingsAll UsersДокументыarabisapy.dll
    c:documents and settingsAll UsersДокументыasoqycyw._dl
    c:documents and settingsAll UsersДокументыefomonuwu.dl
    c:documents and settingsAll UsersДокументыeticipatu.bin
    c:documents and settingsAll UsersДокументыixysyzaju.bin
    c:documents and settingsAll UsersДокументыoful.scr
    c:documents and settingsAll UsersДокументыsaquj.exe
    c:documents and settingsAll UsersApplication Datacufupeti.lib
    c:documents and settingsAll UsersApplication Datadojetirico._sy
    c:documents and settingsAll UsersApplication Dataedepehona.scr
    c:documents and settingsAll UsersApplication Datagemi.bat
    c:documents and settingsAll UsersApplication Datahofagamu.bin
    c:documents and settingsAll UsersApplication Dataibela.dll
    c:documents and settingsAll UsersApplication Dataimibadode.sys
    c:documents and settingsAll UsersApplication Datajyjorecyri.sys
    c:documents and settingsAll UsersApplication Datajyleh.com
    c:documents and settingsAll UsersApplication Datanukog.dll
    c:documents and settingsAll UsersApplication Dataoquj.reg
    c:documents and settingsAll UsersApplication Dataorygykov.ban
    c:documents and settingsAll UsersApplication Datasehytacely.com
    c:documents and settingsAll UsersApplication Dataupibiba.bin
    c:documents and settingsAll UsersApplication Datawyfymymuqo.sys
    c:documents and settingsAll UsersApplication Dataywugacaro.bin
    c:documents and settingsAll Users„®Єг¬Ґ­влkebowasuqy.bat
    c:documents and settingsAll Users„®Єг¬Ґ­влocyko.vbs
    c:documents and settingsAll Users„®Єг¬Ґ­влuhecu.reg
    c:documents and settingsAll Users„®Єг¬Ґ­влujuzale.inf
    c:documents and settingsAll Users„®Єг¬Ґ­влuqohupocuz.bat
    c:program filesCommon Filescyqadifuc.exe
    c:program filesCommon Filesdasivy.scr
    c:program filesCommon Filesdepa.ban
    c:program filesCommon Filesdonijepu.bin
    c:program filesCommon Filesenetimamo.bin
    c:program filesCommon Filesjowewaxolo.ban
    c:program filesCommon Filesjowym.dl
    c:program filesCommon Filesjusisujar.exe
    c:program filesCommon Filespigoxa.reg
    c:program filesCommon Filespomesabyc.dll
    c:program filesCommon Filessupyse.scr
    c:windowsadoru.reg
    c:windowsaxucolyca.reg
    c:windowsbazaci.dll
    c:windowsboxov._dl
    c:windowsbysydyhy.exe
    c:windowscemihepote.vbs
    c:windowscosugak.sys
    c:windowsDelete.bat
    c:windowsdyjonojupe._sy
    c:windowsehycamin._dl
    c:windowsekonu.exe
    c:windowselikut._dl
    c:windowsfiwonuwe.sys
    c:windowshofa.sys
    c:windowshokacel.vbs
    c:windowsicugiqiqe.reg
    c:windowsiryvysy.exe
    c:windowskyfufiguni.sys
    c:windowsowatomavi.sys
    c:windowspidif.sys
    c:windowsramuguhyc.vbs
    c:windowssystem32cocury._dl
    c:windowssystem32defig._dl
    c:windowssystem32gapolozyky.ban
    c:windowssystem32jehi.dll
    c:windowssystem32ovyrem.pif
    c:windowssystem32puriced.sys
    c:windowssystem32ulelib.dl
    c:windowssystem32waxoq.bat
    c:windowssystem32xoqimeselu.pif
    c:windowssystem32ytotu.vbs
    c:windowstineloxizu.vbs
    c:windowsvanupetydy._sy
    c:windowsvidev.sys
    c:windowsvifotanyqa.inf
    c:windowswupokasos.ban
    c:windowsxulyhed._dl
    c:windowsyqita.vbs

    .
    ((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
    .

    2009-10-25 07:48 . 2009-10-25 07:48


    d


    w- c:documents and settingsAdminDoctorWeb
    2009-10-25 07:20 . 2009-10-25 07:20 56 —ha-w- c:windowssystem32ezsidmv.dat
    2009-10-25 07:18 . 2009-10-25 07:18


    d


    w- c:program filesCommon FilesSkype
    2009-10-25 07:18 . 2009-10-25 07:18


    d


    r- c:program filesSkype
    2009-10-25 05:23 . 2009-10-25 05:23 18257 —-a-w- c:windowssystem32hiwade.dat
    2009-10-24 21:36 . 2009-11-03 23:13


    d


    w- c:program filestrend micro
    2009-10-24 21:36 . 2009-10-24 21:37


    d


    w- C:rsit
    2009-10-24 18:19 . 2009-10-24 18:19 10241 —-a-w- c:windowssystem32vulyk.com
    2009-10-24 18:19 . 2009-10-24 18:19 14966 —-a-w- c:windowssystem32pehe.com
    2009-10-24 14:31 . 2009-10-24 14:31 15240 —-a-w- c:windowssystem32ygeroraji.dat

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-04 07:35 . 2009-05-03 13:23


    d


    w- c:documents and settingsAdminApplication DataSkype
    2009-11-04 06:42 . 2009-01-26 14:16


    d


    w- c:documents and settingsAdminApplication DataTransLite
    2009-11-03 22:08 . 2009-05-03 13:26


    d


    w- c:documents and settingsAdminApplication DataskypePM
    2009-11-03 22:05 . 2008-12-07 11:31


    d


    w- c:documents and settingsAdminApplication DataThe Bat!
    2009-10-25 15:36 . 2008-11-30 13:43


    d


    w- c:program filesESET
    2009-10-25 07:18 . 2009-05-03 13:23


    d


    w- c:documents and settingsAll UsersApplication DataSkype
    2009-10-25 06:25 . 2009-05-03 14:03 774 —-a-w- c:documents and settingsAdminApplication Dataaldea.dat
    2009-10-25 05:24 . 2008-04-15 12:00 77534 —-a-w- c:windowssystem32perfc019.dat
    2009-10-25 05:24 . 2008-04-15 12:00 451468 —-a-w- c:windowssystem32perfh019.dat
    2009-10-24 21:22 . 2008-11-30 16:11


    d


    w- c:documents and settingsAdminApplication DataHPAppData
    2009-10-24 19:22 . 2009-10-24 19:22 10504 —-a-w- c:program filesCommon Filessugyty.db
    2009-10-24 18:19 . 2009-10-24 18:19 15737 —-a-w- c:documents and settingsAll UsersApplication Dataxini.dat
    2009-09-11 05:59 . 2009-09-11 05:59


    d


    w- c:documents and settingsAdminApplication DataU3
    2009-08-26 11:15 . 2009-08-26 06:37 19539 —-a-w- c:windowshpqins13.dat
    2009-08-20 10:03 . 2009-08-20 10:03 17 —-a-w- c:documents and settingsAdminApplication Datagrf.dat
    2003-06-20 22:26 . 2009-01-10 06:58 64591 —-a-r- c:program filesWMV9VCM.chm
    2003-06-20 22:26 . 2009-01-10 06:58 12347 —-a-r- c:program filesWMV9VCM_readme.htm
    2003-06-10 22:28 . 2009-01-10 06:58 666 —-a-r- c:program filesqPAL-vbr.wv9
    2003-06-10 22:28 . 2009-01-10 06:58 661 —-a-r- c:program filesqNTSC-vbr.wv9
    2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesPAL-vbr.wv9
    2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesNTSC-vbr.wv9
    2003-06-09 10:21 . 2009-01-10 06:58 21158 —-a-r- c:program fileslicense.txt
    2003-04-07 12:06 . 2009-01-10 06:58 665 —-a-r- c:program filesFilm-320×240-vbr.wv9
    2003-04-07 12:06 . 2009-01-10 06:58 659 —-a-r- c:program filesFilm-640×480-vbr.wv9
    2003-04-07 12:06 . 2009-01-10 06:58 377 —-a-r- c:program filesFilm-1280×720-vbr.wv9
    .


    Sigcheck



    [-] 2008-10-24 . 6A104BA98D99D53AB0C91825CE659FC6 . 361600 . . [5.1.2600.5625] . . c:windowssystem32driverstcpip.sys

    [-] 2008-10-24 . 13548C87ADEFC5980AC4F0F50AC78396 . 80584 . . [7.2.6001.784] . . c:windowssystem32wuauclt.exe

    [-] 2008-10-24 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:windowssystem32user32.dll

    [-] 2008-10-24 . 8054F449106C9DA48AEDC82B05BA2B8E . 952832 . . [7.00.6000.20900] . . c:windowssystem32wininet.dll

    [-] 2008-10-24 . 89F87645A856F6712E6225079B7931F4 . 1721344 . . [6.00.2900.5512] . . c:windowsexplorer.exe

    [-] 2008-10-24 . E52BB415E3A7106E0308A6EE75219F30 . 1571840 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll

    [-] 2008-10-24 . 08DD489E663B992B188166951AD131E0 . 30208 . . [5.1.2600.5512] . . c:windowssystem32ctfmon.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
    «Download Master»=»c:program filesDownload Masterdmaster.exe» [2009-02-06 3769856]
    «Skype»=»c:program filesSkypePhoneSkype.exe» [2009-10-09 25623336]

    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
    «NvCplDaemon»=»c:windowssystem32NvCpl.dll» [2006-08-11 7630848]
    «RemoteControl8″=»c:program filesCyberLinkPowerDVD8PDVD8Serv.exe» [2008-03-20 83240]
    «PDVD8LanguageShortcut»=»c:program filesCyberLinkPowerDVD8LanguageLanguage.exe» [2007-12-14 50472]
    «BDRegion»=»c:program filesCyberlinkShared Filesbrs.exe» [2008-05-19 91432]
    «egui»=»c:program filesESETESET NOD32 Antivirusegui.exe» [2008-08-18 1447168]
    «HP Software Update»=»c:program filesHPHP Software UpdateHPWuSchd2.exe» [2007-10-14 49152]
    «QuickTime Task»=»c:program filesQuickTimeqttask.exe» [2007-10-19 286720]
    «iTunesHelper»=»c:program filesiTunesiTunesHelper.exe» [2007-11-02 267048]
    «hpqSRMon»=»c:program filesHPDigital ImagingbinhpqSRMon.exe» [2008-08-20 150016]
    «SoundMan»=»SOUNDMAN.EXE» — c:windowsSOUNDMAN.EXE [2007-04-16 577536]
    «nwiz»=»nwiz.exe» — c:windowssystem32nwiz.exe [2006-08-11 1519616]
    «NvMediaCenter»=»NvMCTray.dll» — c:windowssystem32nvmctray.dll [2006-08-11 86016]

    [HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
    «CTFMON.EXE»=»c:windowssystem32CTFMON.EXE» [2008-10-24 30208]

    [HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
    «IE7_011″=»shell32» [X]
    «ZZZZ2_FirstLogonSetting»=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]
    «IE7_012″=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]

    c:documents and settingsAll Usersѓ« ў­®Ґ ¬Ґ­оЏа®Ја ¬¬лЂўв®§ Јаг§Є 
    BlueSoleil.lnk — c:program filesIVT CorporationBlueSoleilgprs.exe [2007-12-27 43608]
    HP Digital Imaging Monitor.lnk — c:program filesHPDigital Imagingbinhpqtra08.exe [2007-10-14 214360]
    ‘«®ў ам TransLite.lnk — c:program filesTransLitetranslite.exe [2009-1-22 761856]
    “᪮७­л© § ЇгбЄ Adobe Reader.lnk — c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2004-12-14 29696]

    [HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
    «NoSMConfigurePrograms»= 1 (0x1)

    [HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
    «NoSMConfigurePrograms»= 1 (0x1)

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
    «FirewallOverride»=dword:00000001
    «UpdatesOverride»=dword:00000001
    «AntiVirusOverride»=dword:00000001

    [HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
    «EnableFirewall»= 0 (0x0)

    [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
    «%windir%\Network Diagnostic\xpnetdiag.exe»=
    «%windir%\system32\sessmgr.exe»=

    R1 epfwtdir;epfwtdir;c:windowssystem32driversepfwtdir.sys [01.07.2008 8:04 34312]
    R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:program filesCyberLinkPowerDVD800.fcl [15.05.2008 11:07 61424]
    R2 ekrn;Eset Service;c:program filesESETESET NOD32 Antivirusekrn.exe [18.08.2008 12:25 468224]
    R2 SandraAgentSrv;SiSoftware Deployment Agent Service;c:program filesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe [30.11.2008 16:58 98488]
    R2 Start BT in service;Start BT in service;c:program filesIVT CorporationBlueSoleilStartSkysolSvc.exe [27.12.2007 14:39 51816]
    S3 cel90xbe;cel90xbe;??d:tmpcel90xbe.sys —> d:tmpcel90xbe.sys [?]

    — Other Services/Drivers In Memory —

    *NewlyCreated* — MBR
    *NewlyCreated* — PROCEXP113
    *NewlyCreated* — SRSERVICE
    *Deregistered* — mbr
    *Deregistered* — PROCEXP113

    [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the ‘Scheduled Tasks’ folder

    2009-10-26 c:windowsTasksAppleSoftwareUpdate.job
    — c:program filesApple Software UpdateSoftwareUpdate.exe [2007-08-29 12:57]
    .
    .


    Supplementary Scan


    .
    uStart Page = hxxp://www.yandex.ru/
    IE: &Экспорт в Microsoft Excel — c:progra~1MICROS~1OFFICE11EXCEL.EXE/3000
    IE: Закачать ВСЕ при помощи Download Master — c:program filesDownload Masterdmieall.htm
    IE: Закачать при помощи Download Master — c:program filesDownload Masterdmie.htm
    IE: {{8DAE90AD-4583-4977-9DD4-4360F7A45C74} — c:program filesDownload Masterdmaster.exe
    FF — ProfilePath — c:documents and settingsAdminApplication DataMozillaFirefoxProfilesaxxzg6s7.default
    FF — prefs.js: network.proxy.type — 2
    FF — plugin: c:program filesOperaprogrampluginsnpdm.dll

    —- FIREFOX POLICIES —-
    FF — user.js: capability.policy.policynames — localfilelinks
    FF — user.js: capability.policy.localfilelinks.sites — hxxp://speed.travian.ae http://speed2.travian.ae http://s1.travian.ae http://s2.travian.ae http://s3.travian.ae http://s4.travian.ae http://s5.travian.ae http://s6.travian.ae http://s7.travian.ae http://s8.travian.ae http://s9.travian.ae http://s10.travian.ae http://s11.travian.ae http://s12.travian.ae http://s13.travian.ae http://s14.travian.ae http://s15.travian.ae http://s16.travian.ae http://s17.travian.ae http://s18.travian.ae http://s19.travian.ae http://s20.travian.ae http://s21.travian.ae http://s22.travian.ae http://s23.travian.ae http://s24.travian.ae http://s25.travian.ae http://s26.travian.ae http://s27.travian.ae http://s28.travian.ae http://s29.travian.ae http://s30.travian.ae http://s31.travian.ae http://s32.travian.ae http://s33.travian.ae http://s34.travian.ae http://s35.travian.ae http://speed.travian.asia http://speed2.travian.asia http://s1.travian.asia http://s2.travian.asia http://s3.travian.asia http://s4.travian.asia http://s5.travian.asia http://s6.travian.asia http://s7.travian.asia http://s8.travian.asia http://s9.travian.asia http://s10.travian.asia http://speed.travian.ba http://speed2.travian.ba http://s1.travian.ba http://s2.travian.ba http://s3.travian.ba http://s4.travian.ba http://s5.travian.ba http://s6.travian.ba http://s7.travian.ba http://s8.travian.ba http://s9.travian.ba http://s10.travian.ba http://speed.travian.bg http://speed2.travian.bg http://s1.travian.bg http://s2.travian.bg http://s3.travian.bg http://s4.travian.bg http://s5.travian.bg http://s6.travian.bg http://s7.travian.bg http://s8.travian.bg http://s9.travian.bg http://s10.travian.bg http://speed.travian.cl http://speed2.travian.cl http://s1.travian.cl http://s2.travian.cl http://s3.travian.cl http://s4.travian.cl http://s5.travian.cl http://s6.travian.cl http://s7.travian.cl http://s8.travian.cl http://s9.travian.cl http://s10.travian.cl http://speed.travian.cn http://speed2.travian.cn http://s1.travian.cn http://s2.travian.cn http://s3.travian.cn http://s4.travian.cn http://s5.travian.cn http://s6.travian.cn http://s7.travian.cn http://s8.travian.cn http://s9.travian.cn http://s10.travian.cn http://s11.travian.cn http://s12.travian.cn http://s13.travian.cn http://s14.travian.cn http://s15.travian.cn http://s16.travian.cn http://s17.travian.cn http://s18.travian.cn http://s19.travian.cn http://s20.travian.cn http://speed.travian.co.ee http://speed2.travian.co.ee http://s1.travian.co.ee http://s2.travian.co.ee http://s3.travian.co.ee http://s4.travian.co.ee http://s5.travian.co.ee http://s6.travian.co.ee http://s7.travian.co.ee http://s8.travian.co.ee http://s9.travian.co.ee http://s10.travian.co.ee http://s11.travian.co.ee http://s12.travian.co.ee http://s13.travian.co.ee http://s14.travian.co.ee http://s15.travian.co.ee http://s16.travian.co.ee http://s17.travian.co.ee http://s18.travian.co.ee http://s19.travian.co.ee http://s20.travian.co.ee http://speed.travian.co.id http://speed2.travian.co.id http://s1.travian.co.id http://s2.travian.co.id http://s3.travian.co.id http://s4.travian.co.id http://s5.travian.co.id http://s6.travian.co.id http://s7.travian.co.id http://s8.travian.co.id http://s9.travian.co.id http://s10.travian.co.id http://speed.travian.co.il http://speed2.travian.co.il http://s1.travian.co.il http://s2.travian.co.il http://s3.travian.co.il http://s4.travian.co.il http://s5.travian.co.il http://s6.travian.co.il http://s7.travian.co.il http://s8.travian.co.il http://s9.travian.co.il http://s10.travian.co.il http://speed.travian.co.kr http://speed2.travian.co.kr http://s1.travian.co.kr http://s2.travian.co.kr http://s3.travian.co.kr http://s4.travian.co.kr http://s5.travian.co.kr http://s6.travian.co.kr http://s7.travian.co.kr http://s8.travian.co.kr http://s9.travian.co.kr http://s10.travian.co.kr http://speed.travian.co.nz http://speed2.travian.co.nz http://s1.travian.co.nz http://s2.travian.co.nz http://s3.travian.co.nz http://s4.travian.co.nz http://s5.travian.co.nz http://s6.travian.co.nz http://s7.travian.co.nz http://s8.travian.co.nz http://s9.travian.co.nz http://s10.travian.co.nz http://speed.travian.co.uk http://speed2.travian.co.uk http://s1.travian.co.uk http://s2.travian.co.uk http://s3.travian.co.uk http://s4.travian.co.uk http://s5.travian.co.uk http://s6.travian.co.uk http://s7.travian.co.uk http://s8.travian.co.uk http://s9.travian.co.uk http://s10.travian.co.uk http://speed.travian.co.za http://speed2.travian.co.za http://s1.travian.co.za http://s2.travian.co.za http://s3.travian.co.za http://s4.travian.co.za http://s5.travian.co.za http://s6.travian.co.za http://s7.travian.co.za http://s8.travian.co.za http://s9.travian.co.za http://s10.travian.co.za http://speed.travian.com http://speed2.travian.com http://s1.travian.com http://s2.travian.com http://s3.travian.com http://s4.travian.com http://s5.travian.com http://s6.travian.com http://s7.travian.com http://s8.travian.com http://s9.travian.com http://s10.travian.com http://s11.travian.com http://s12.travian.com http://s13.travian.com http://s14.travian.com http://s15.travian.com http://s16.travian.com http://s17.travian.com http://s18.travian.com http://s19.travian.com http://s20.travian.com http://speed.travian.com.ar http://speed2.travian.com.ar http://s1.travian.com.ar http://s2.travian.com.ar http://s3.travian.com.ar http://s4.travian.com.ar http://s5.travian.com.ar http://s6.travian.com.ar http://s7.travian.com.ar http://s8.travian.com.ar http://s9.travian.com.ar http://s10.travian.com.ar http://speed.travian.com.au http://speed2.travian.com.au http://s1.travian.com.au http://s2.travian.com.au http://s3.travian.com.au http://s4.travian.com.au http://s5.travian.com.au http://s6.travian.com.au http://s7.travian.com.au http://s8.travian.com.au http://s9.travian.com.au http://s10.travian.com.au http://speed.travian.com.br http://speed2.travian.com.br http://s1.travian.com.br http://s2.travian.com.br http://s3.travian.com.br http://s4.travian.com.br http://s5.travian.com.br http://s6.travian.com.br http://s7.travian.com.br http://s8.travian.com.br http://s9.travian.com.br http://s10.travian.com.br http://s11.travian.com.br http://s12.travian.com.br http://s13.travian.com.br http://s14.travian.com.br http://s15.travian.com.br http://s16.travian.com.br http://s17.travian.com.br http://s18.travian.com.br http://s19.travian.com.br http://s20.travian.com.br http://speed.travian.com.hr http://speed2.travian.com.hr http://s1.travian.com.hr http://s2.travian.com.hr http://s3.travian.com.hr http://s4.travian.com.hr http://s5.travian.com.hr http://s6.travian.com.hr http://s7.travian.com.hr http://s8.travian.com.hr http://s9.travian.com.hr http://s10.travian.com.hr http://speed.travian.com.mx http://speed2.travian.com.mx http://s1.travian.com.mx http://s2.travian.com.mx http://s3.travian.com.mx http://s4.travian.com.mx http://s5.travian.com.mx http://s6.travian.com.mx http://s7.travian.com.mx http://s8.travian.com.mx http://s9.travian.com.mx http://s10.travian.com.mx http://speed.travian.com.my http://speed2.travian.com.my http://s1.travian.com.my http://s2.travian.com.my http://s3.travian.com.my http://s4.travian.com.my http://s5.travian.com.my http://s6.travian.com.my http://s7.travian.com.my http://s8.travian.com.my http://s9.travian.com.my http://s10.travian.com.my http://speed.travian.com.tr http://speed2.travian.com.tr http://s1.travian.com.tr http://s2.travian.com.tr http://s3.travian.com.tr http://s4.travian.com.tr http://s5.travian.com.tr http://s6.travian.com.tr http://s7.travian.com.tr http://s8.travian.com.tr http://s9.travian.com.tr http://s10.travian.com.tr http://s11.travian.com.tr http://s12.travian.com.tr http://s13.travian.com.tr http://s14.travian.com.tr http://s15.travian.com.tr http://s16.travian.com.tr http://s17.travian.com.tr http://s18.travian.com.tr http://s19.travian.com.tr http://s20.travian.com.tr http://s21.travian.com.tr http://s22.travian.com.tr http://s23.travian.com.tr http://s24.travian.com.tr http://s25.travian.com.tr http://s26.travian.com.tr http://s27.travian.com.tr http://s28.travian.com.tr http://s29.travian.com.tr http://s30.travian.com.tr http://speed.travian.com.ua http://speed2.travian.com.ua http://s1.travian.com.ua http://s2.travian.com.ua http://s3.travian.com.ua http://s4.travian.com.ua http://s5.travian.com.ua http://s6.travian.com.ua http://s7.travian.com.ua http://s8.travian.com.ua http://s9.travian.com.ua http://s10.travian.com.ua http://speed.travian.com.vn http://speed2.travian.com.vn http://s1.travian.com.vn http://s2.travian.com.vn http://s3.travian.com.vn http://s4.travian.com.vn http://s5.travian.com.vn http://s6.travian.com.vn http://s7.travian.com.vn http://s8.travian.com.vn http://s9.travian.com.vn http://s10.travian.com.vn http://speed.travian.cz http://speed2.travian.cz http://s1.travian.cz http://s2.travian.cz http://s3.travian.cz http://s4.travian.cz http://s5.travian.cz http://s6.travian.cz http://s7.travian.cz http://s8.travian.cz http://s9.travian.cz http://s10.travian.cz http://s11.travian.cz http://s12.travian.cz http://s13.travian.cz http://s14.travian.cz http://s15.travian.cz http://s16.travian.cz http://s17.travian.cz http://s18.travian.cz http://s19.travian.cz http://s20.travian.cz http://speed.travian.dk http://speed2.travian.dk http://s1.travian.dk http://s2.travian.dk http://s3.travian.dk http://s4.travian.dk http://s5.travian.dk http://s6.travian.dk http://s7.travian.dk http://s8.travian.dk http://s9.travian.dk http://s10.travian.dk http://speed.travian.fi http://speed2.travian.fi http://s1.travian.fi http://s2.travian.fi http://s3.travian.fi http://s4.travian.fi http://s5.travian.fi http://s6.travian.fi http://s7.travian.fi http://s8.travian.fi http://s9.travian.fi http://s10.travian.fi http://speed.travian.fr http://speed2.travian.fr http://s1.travian.fr http://s2.travian.fr http://s3.travian.fr http://s4.travian.fr http://s5.travian.fr http://s6.travian.fr http://s7.travian.fr http://s8.travian.fr http://s9.travian.fr http://s10.travian.fr http://s11.travian.fr http://s12.travian.fr http://s13.travian.fr http://s14.travian.fr http://s15.travian.fr http://s16.travian.fr http://s17.travian.fr http://s18.travian.fr http://s19.travian.fr http://s20.travian.fr http://speed.travian.gr http://speed2.travian.gr http://s1.travian.gr http://s2.travian.gr http://s3.travian.gr http://s4.travian.gr http://s5.travian.gr http://s6.travian.gr http://s7.travian.gr http://s8.travian.gr http://s9.travian.gr http://s10.travian.gr http://speed.travian.hk http://speed2.travian.hk http://s1.travian.hk http://s2.travian.hk http://s3.travian.hk http://s4.travian.hk http://s5.travian.hk http://s6.travian.hk http://s7.travian.hk http://s8.travian.hk http://s9.travian.hk http://s10.travian.hk http://speed.travian.hu http://speed2.travian.hu http://s1.travian.hu http://s2.travian.hu http://s3.travian.hu http://s4.travian.hu http://s5.travian.hu http://s6.travian.hu http://s7.travian.hu http://s8.travian.hu http://s9.travian.hu http://s10.travian.hu http://speed.travian.in http://speed2.travian.in http://s1.travian.in http://s2.travian.in http://s3.travian.in http://s4.travian.in http://s5.travian.in http://s6.travian.in http://s7.travian.in http://s8.travian.in http://s9.travian.in http://s10.travian.in http://speed.travian.ir http://speed2.travian.ir http://s1.travian.ir http://s2.travian.ir http://s3.travian.ir http://s4.travian.ir http://s5.travian.ir http://s6.travian.ir http://s7.travian.ir http://s8.travian.ir http://s9.travian.ir http://s10.travian.ir http://speed.travian.it http://speed2.travian.it http://s1.travian.it http://s2.travian.it http://s3.travian.it http://s4.travian.it http://s5.travian.it http://s6.travian.it http://s7.travian.it http://s8.travian.it http://s9.travian.it http://s10.travian.it http://s11.travian.it http://s12.travian.it http://s13.travian.it http://s14.travian.it http://s15.travian.it http://s16.travian.it http://s17.travian.it http://s18.travian.it http://s19.travian.it http://s20.travian.it http://speed.travian.jp http://speed2.travian.jp http://s1.travian.jp http://s2.travian.jp http://s3.travian.jp http://s4.travian.jp http://s5.travian.jp http://s6.travian.jp http://s7.travian.jp http://s8.travian.jp http://s9.travian.jp http://s10.travian.jp http://speed.travian.lt http://speed2.travian.lt http://s1.travian.lt http://s2.travian.lt http://s3.travian.lt http://s4.travian.lt http://s5.travian.lt http://s6.travian.lt http://s7.travian.lt http://s8.travian.lt http://s9.travian.lt http://s10.travian.lt http://speed.travian.lv http://speed2.travian.lv http://s1.travian.lv http://s2.travian.lv http://s3.travian.lv http://s4.travian.lv http://s5.travian.lv http://s6.travian.lv http://s7.travian.lv http://s8.travian.lv http://s9.travian.lv http://s10.travian.lv http://speed.travian.net http://speed2.travian.net http://s1.travian.net http://s2.travian.net http://s3.travian.net http://s4.travian.net http://s5.travian.net http://s6.travian.net http://s7.travian.net http://s8.travian.net http://s9.travian.net http://s10.travian.net http://speed.travian.nl http://speed2.travian.nl http://s1.travian.nl http://s2.travian.nl http://s3.travian.nl http://s4.travian.nl http://s5.travian.nl http://s6.travian.nl http://s7.travian.nl http://s8.travian.nl http://s9.travian.nl http://s10.travian.nl http://speed.travian.no http://speed2.travian.no http://s1.travian.no http://s2.travian.no http://s3.travian.no http://s4.travian.no http://s5.travian.no http://s6.travian.no http://s7.travian.no http://s8.travian.no http://s9.travian.no http://s10.travian.no http://speed.travian.ph http://speed2.travian.ph http://s1.travian.ph http://s2.travian.ph http://s3.travian.ph http://s4.travian.ph http://s5.travian.ph http://s6.travian.ph http://s7.travian.ph http://s8.travian.ph http://s9.travian.ph http://s10.travian.ph http://speed.travian.pk http://speed2.travian.pk http://s1.travian.pk http://s2.travian.pk http://s3.travian.pk http://s4.travian.pk http://s5.travian.pk http://s6.travian.pk http://s7.travian.pk http://s8.travian.pk http://s9.travian.pk http://s10.travian.pk http://speed.travian.pl http://speed2.travian.pl http://s1.travian.pl http://s2.travian.pl http://s3.travian.pl http://s4.travian.pl http://s5.travian.pl http://s6.travian.pl http://s7.travian.pl http://s8.travian.pl http://s9.travian.pl http://s10.travian.pl http://s11.travian.pl http://s12.travian.pl http://s13.travian.pl http://s14.travian.pl http://s15.travian.pl http://s16.travian.pl http://s17.travian.pl http://s18.travian.pl http://s19.travian.pl http://s20.travian.pl http://speed.travian.pt http://speed2.travian.pt http://s1.travian.pt http://s2.travian.pt http://s3.travian.pt http://s4.travian.pt http://s5.travian.pt http://s6.travian.pt http://s7.travian.pt http://s8.travian.pt http://s9.travian.pt http://s10.travian.pt http://s11.travian.pt http://s12.travian.pt http://s13.travian.pt http://s14.travian.pt http://s15.travian.pt http://s16.travian.pt http://s17.travian.pt http://s18.travian.pt http://s19.travian.pt http://s20.travian.pt http://speed.travian.ro http://speed2.travian.ro http://s1.travian.ro http://s2.travian.ro http://s3.travian.ro http://s4.travian.ro http://s5.travian.ro http://s6.travian.ro http://s7.travian.ro http://s8.travian.ro http://s9.travian.ro http://s10.travian.ro http://speed.travian.rs http://speed2.travian.rs http://s1.travian.rs http://s2.travian.rs http://s3.travian.rs http://s4.travian.rs http://s5.travian.rs http://s6.travian.rs http://s7.travian.rs http://s8.travian.rs http://s9.travian.rs http://s10.travian.rs http://speed.travian.ru http://speed2.travian.ru http://s1.travian.ru http://s2.travian.ru http://s3.travian.ru http://s4.travian.ru http://s5.travian.ru http://s6.travian.ru http://s7.travian.ru http://s8.travian.ru http://s9.travian.ru http://s10.travian.ru http://s11.travian.ru http://s12.travian.ru http://s13.travian.ru http://s14.travian.ru http://s15.travian.ru http://s16.travian.ru http://s17.travian.ru http://s18.travian.ru http://s19.travian.ru http://s20.travian.ru http://speed.travian.se http://speed2.travian.se http://s1.travian.se http://s2.travian.se http://s3.travian.se http://s4.travian.se http://s5.travian.se http://s6.travian.se http://s7.travian.se http://s8.travian.se http://s9.travian.se http://s10.travian.se http://speed.travian.si http://speed2.travian.si http://s1.travian.si http://s2.travian.si http://s3.travian.si http://s4.travian.si http://s5.travian.si http://s6.travian.si http://s7.travian.si http://s8.travian.si http://s9.travian.si http://s10.travian.si http://speed.travian.sk http://speed2.travian.sk http://s1.travian.sk http://s2.travian.sk http://s3.travian.sk http://s4.travian.sk http://s5.travian.sk http://s6.travian.sk http://s7.travian.sk http://s8.travian.sk http://s9.travian.sk http://s10.travian.sk http://speed.travian.us http://speed2.travian.us http://s1.travian.us http://s2.travian.us http://s3.travian.us http://s4.travian.us http://s5.travian.us http://s6.travian.us http://s7.travian.us http://s8.travian.us http://s9.travian.us http://s10.travian.us http://s11.travian.us http://s12.travian.us http://s13.travian.us http://s14.travian.us http://s15.travian.us http://s16.travian.us http://s17.travian.us http://s18.travian.us http://s19.travian.us http://s20.travian.us http://www.travian.at http://speed.travian.at http://speed2.travian.at http://www.travian.de http://speed.travian.de http://speed2.travian.de http://welt1.travian.de http://welt2.travian.de http://welt3.travian.de http://welt4.travian.de http://welt5.travian.de http://welt6.travian.de http://welt7.travian.de http://welt8.travian.de http://welt9.travian.de http://welt10.travian.de http://www.travian.org http://speed.travian.org http://speed2.travian.org
    FF — user.js: capability.policy.localfilelinks.checkloaduri.enabled — allAccessc:program filesMozilla Firefoxgreprefssecurity-prefs.js — pref(«security.ssl3.rsa_seed_sha», true);
    .
    — — — — ORPHANS REMOVED — — — —

    HKLM-Run-WinampAgent — c:program filesWinampwinampa.exe
    HKLM-Run-Malwarebytes Anti-Malware (reboot) — c:program filesMalwarebytes’ Anti-Malwarembam.exe
    AddRemove-SimCity 4 Rush Hour — e:_dcdf7~1GamesA417~1SIMCIT~1UNWISE.EXE
    AddRemove-{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1 — d:tmpRar$EX01.547NOD32-PATCHObsoleteunins000.exe

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista — rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-11-04 09:37
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes …

    scanning hidden autostart entries …

    scanning hidden files …

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sprs.sys >>UNKNOWN [0x82391938]<<
    kernel: MBR read successfully
    user & kernel MBR OK
    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    atapi.sys @ 0x0 0x0 bytes

    Driveratapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF8369B40 atapi.sys
    Driveratapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF8369B40 atapi.sys
    Driveratapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF8369B40 atapi.sys
    Driveratapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF8369B40 atapi.sys
    Driveratapi [ IRP_MJ_POWER ] 0xA73C != 0xF8369B40 atapi.sys
    Driveratapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF8369B40 atapi.sys
    Driveratapi IRP hooks detected !

    **************************************************************************

    [HKEY_LOCAL_MACHINESystemControlSet001Services{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
    «ImagePath»=»??c:program filesCyberLinkPowerDVD800.fcl»
    .


    DLLs Loaded Under Running Processes



    — — — — — — — > ‘winlogon.exe'(732)
    c:windowssystem32SETUPAPI.dll
    c:windowssystem32cscui.dll

    — — — — — — — > ‘lsass.exe'(788)
    c:windowssystem32SETUPAPI.dll
    .
    Completion time: 2009-11-04 9:41
    ComboFix-quarantined-files.txt 2009-11-04 07:41

    Pre-Run: 4 126 130 176 байт свободно
    Post-Run: 4 105 576 448 байт свободно

  • Автор
    Сообщения
Просмотр 3 сообщений - с 1 по 3 (из 3 всего)

Добро пожаловать

На нашем сайте размещены инструкции и программы, которые помогут вам абсолютно бесплатно и самостоятельно удалить навязчивую рекламу, вирусы и трояны.

Поиск

Важные инструкции

Как запустить компьютер в безопасном режиме (Safe Mode)
Проверка на вирусы Андроид телефона
Как удалить вирус с телефона Андроид (Инструкция)
Как восстановить зашифрованные файлы (Инструкция)
Этот параметр включен администратором
Убрать рекламу в браузере (Chrome, Firefox, Opera, Yandex)

СПАЙВАРЕ РУ

  • О Спайваре Ру
  • Контакты
  • Реклама на сайте
  • Политика конфиденциальности
  • Правила использования

Нужна помощь?

Задайте свой вопрос прямо сейчас кликнув по следующей ссылке Задать вопрос.

Или обратитесь на наш форум, где команда Spyware-ru поможет вам. Узнайте, как попросить о помощи здесь.

Ссылки

  • Инструкции
  • Скачать программы
  • Помощь в удалении вирусов
  • Как вылечить компьютер
Copyright © 2008 - 2024 Spyware-RU.com (en)