Созданные ответы форума
-
АвторСообщения
-
Доброго времени суток.
После перерегистрации почтового ящика, фоновая заставка оставшаяся после порно банера исчезла.
Огромная Вам благодарность и успехов.Logfile of random’s system information tool 1.06 (written by random/random)
Run by Admin at 2009-11-04 09:53:53
Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (39%) free of 10 GB
Total RAM: 511 MB (37% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:00, on 04.11.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
C:Program FilesESETESET NOD32 Antivirusekrn.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSOUNDMAN.EXE
C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe
C:Program FilesCyberlinkShared Filesbrs.exe
C:Program FilesESETESET NOD32 Antivirusegui.exe
C:Program FilesHPHP Software UpdateHPWuSchd2.exe
C:Program FilesiTunesiTunesHelper.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesDownload Masterdmaster.exe
C:Program FilesHPDigital Imagingbinhpqtra08.exe
C:Program FilesTransLitetranslite.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesSkypePlugin ManagerskypePM.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesHPDigital ImagingbinhpqSTE08.exe
C:Program FilesHPDigital Imagingbinhpqbam08.exe
C:Program FilesHPDigital Imagingbinhpqgpc01.exe
C:WINDOWSexplorer.exe
D:Мои документыЗагрузкиRSIT.exe
C:Program Filestrend microAdmin.exeR0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
O2 — BHO: HP Print Enhancer — {0347C33E-8762-4905-BF09-768834316C61} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
O2 — BHO: AcroIEHlprObj Class — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 — BHO: IE 4.x-6.x BHO for Download Master — {9961627E-4059-41B4-8E0E-A7D6B3854ADF} — C:PROGRA~1DOWNLO~1dmiehlp.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll (file missing)
O2 — BHO: HP Smart BHO Class — {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O3 — Toolbar: DM Bar — {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} — C:Program FilesDownload Masterdmbar.dll
O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [nwiz] nwiz.exe /install
O4 — HKLM..Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 — HKLM..Run: [RemoteControl8] «C:Program FilesCyberLinkPowerDVD8PDVD8Serv.exe»
O4 — HKLM..Run: [PDVD8LanguageShortcut] «C:Program FilesCyberLinkPowerDVD8LanguageLanguage.exe»
O4 — HKLM..Run: [BDRegion] C:Program FilesCyberlinkShared Filesbrs.exe
O4 — HKLM..Run: [egui] «C:Program FilesESETESET NOD32 Antivirusegui.exe» /hide /waitservice
O4 — HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeqttask.exe» -atboottime
O4 — HKLM..Run: [iTunesHelper] «C:Program FilesiTunesiTunesHelper.exe»
O4 — HKLM..Run: [hpqSRMon] C:Program FilesHPDigital ImagingbinhpqSRMon.exe
O4 — HKCU..Run: [Download Master] C:Program FilesDownload Masterdmaster.exe -autorun
O4 — HKCU..Run: [Skype] «C:Program FilesSkypePhoneSkype.exe» /nosplash /minimized
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [IE7_012] rundll32 advpack.dll,LaunchINFSectionEx IE7int.inf,AfterUserStart,,4,N (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
O4 — Global Startup: BlueSoleil.lnk = C:Program FilesIVT CorporationBlueSoleilgprs.exe
O4 — Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe
O4 — Global Startup: Словарь TransLite.lnk = C:Program FilesTransLitetranslite.exe
O4 — Global Startup: Ускоренный запуск Adobe Reader.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~1OFFICE11EXCEL.EXE/3000
O8 — Extra context menu item: Закачать ВСЕ при помощи Download Master — C:Program FilesDownload Masterdmieall.htm
O8 — Extra context menu item: Закачать при помощи Download Master — C:Program FilesDownload Masterdmie.htm
O9 — Extra button: Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra ‘Tools’ menuitem: &Download Master — {8DAE90AD-4583-4977-9DD4-4360F7A45C74} — C:Program FilesDownload Masterdmaster.exe
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~1OFFICE11REFIEBAR.DLL
O9 — Extra button: Расширенный выбор HP — {DDE87865-83C5-48c4-8357-2F5B1AA84522} — C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Apple Mobile Device — Apple, Inc. — C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 — Service: BlueSoleil Hid Service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilBTNtService.exe
O23 — Service: Eset HTTP Server (EhttpSrv) — ESET — C:Program FilesESETESET NOD32 AntivirusEHttpSrv.exe
O23 — Service: Eset Service (ekrn) — ESET — C:Program FilesESETESET NOD32 Antivirusekrn.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: Сервис iPod (iPod Service) — Apple Inc. — C:Program FilesiPodbiniPodService.exe
O23 — Service: NVIDIA Display Driver Service (NVSvc) — NVIDIA Corporation — C:WINDOWSsystem32nvsvc32.exe
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: SiSoftware Deployment Agent Service (SandraAgentSrv) — SiSoftware — C:Program FilesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: Start BT in service — Unknown owner — C:Program FilesIVT CorporationBlueSoleilStartSkysolSvc.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe—
End of file — 8621 bytesДоброго времени суток.
ComboFix 09-11-03.03 — Admin 04.11.2009 9:26.1.1 — NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.7.1049.18.511.195 [GMT 2:00]
Running from: c:combofixComboFix.exe
Command switches used :: ComboFix
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is activeWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.c:documents and settingsAdminApplication DataAdSubscribe
c:documents and settingsAdminApplication DataAdSubscribeAdSubscribe.dat
c:documents and settingsAdminApplication DataAdSubscribeFeed.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed1.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed2.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed3.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed4.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed5.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed6.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed7.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed8.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeed9.jpg
c:documents and settingsAdminApplication DataAdSubscribeFeedfeed.xml
c:documents and settingsAdminApplication Dataakokynokeh.ban
c:documents and settingsAdminApplication DataAldea
c:documents and settingsAdminApplication Datacafex.com
c:documents and settingsAdminApplication Datacida.exe
c:documents and settingsAdminApplication Datadehegim.pif
c:documents and settingsAdminApplication Dataefogiwa.com
c:documents and settingsAdminApplication Dataheripozuku.lib
c:documents and settingsAdminApplication Datamuqy.dll
c:documents and settingsAdminApplication Dataosigenowus._sy
c:documents and settingsAdminApplication Dataqozivazi.ban
c:documents and settingsAdminApplication Dataratofo.bat
c:documents and settingsAdminApplication Datasefok.scr
c:documents and settingsAdminApplication Datawunero.dl
c:documents and settingsAdminLocal SettingsApplication Databixybi.inf
c:documents and settingsAdminLocal SettingsApplication Databovegohofe.bat
c:documents and settingsAdminLocal SettingsApplication Datadedekyhoq.bin
c:documents and settingsAdminLocal SettingsApplication Datadorejaq.exe
c:documents and settingsAdminLocal SettingsApplication Datairakypig.dll
c:documents and settingsAdminLocal SettingsApplication Datalosuhineki.ban
c:documents and settingsAdminLocal SettingsApplication Dataqajuwi._sy
c:documents and settingsAdminLocal SettingsApplication Dataxogidoput.sys
c:documents and settingsAdminLocal SettingsApplication Dataycoripa.bat
c:documents and settingsAdminLocal SettingsApplication Dataytuvabuja.dll
c:documents and settingsAdminLocal SettingsTemporary Internet Filesbefeguve.inf
c:documents and settingsAdminLocal SettingsTemporary Internet Filesemajasuxi.inf
c:documents and settingsAdminLocal SettingsTemporary Internet Filesizyd.dat
c:documents and settingsAdminLocal SettingsTemporary Internet Filesjunic.reg
c:documents and settingsAdminLocal SettingsTemporary Internet Filessigijir.dat
c:documents and settingsAdminoashdihasidhasuidhiasdhiashdiuasdhasd
c:documents and settingsAll UsersДокументыarabisapy.dll
c:documents and settingsAll UsersДокументыasoqycyw._dl
c:documents and settingsAll UsersДокументыefomonuwu.dl
c:documents and settingsAll UsersДокументыeticipatu.bin
c:documents and settingsAll UsersДокументыixysyzaju.bin
c:documents and settingsAll UsersДокументыoful.scr
c:documents and settingsAll UsersДокументыsaquj.exe
c:documents and settingsAll UsersApplication Datacufupeti.lib
c:documents and settingsAll UsersApplication Datadojetirico._sy
c:documents and settingsAll UsersApplication Dataedepehona.scr
c:documents and settingsAll UsersApplication Datagemi.bat
c:documents and settingsAll UsersApplication Datahofagamu.bin
c:documents and settingsAll UsersApplication Dataibela.dll
c:documents and settingsAll UsersApplication Dataimibadode.sys
c:documents and settingsAll UsersApplication Datajyjorecyri.sys
c:documents and settingsAll UsersApplication Datajyleh.com
c:documents and settingsAll UsersApplication Datanukog.dll
c:documents and settingsAll UsersApplication Dataoquj.reg
c:documents and settingsAll UsersApplication Dataorygykov.ban
c:documents and settingsAll UsersApplication Datasehytacely.com
c:documents and settingsAll UsersApplication Dataupibiba.bin
c:documents and settingsAll UsersApplication Datawyfymymuqo.sys
c:documents and settingsAll UsersApplication Dataywugacaro.bin
c:documents and settingsAll Users„®Єг¬Ґвлkebowasuqy.bat
c:documents and settingsAll Users„®Єг¬Ґвлocyko.vbs
c:documents and settingsAll Users„®Єг¬Ґвлuhecu.reg
c:documents and settingsAll Users„®Єг¬Ґвлujuzale.inf
c:documents and settingsAll Users„®Єг¬Ґвлuqohupocuz.bat
c:program filesCommon Filescyqadifuc.exe
c:program filesCommon Filesdasivy.scr
c:program filesCommon Filesdepa.ban
c:program filesCommon Filesdonijepu.bin
c:program filesCommon Filesenetimamo.bin
c:program filesCommon Filesjowewaxolo.ban
c:program filesCommon Filesjowym.dl
c:program filesCommon Filesjusisujar.exe
c:program filesCommon Filespigoxa.reg
c:program filesCommon Filespomesabyc.dll
c:program filesCommon Filessupyse.scr
c:windowsadoru.reg
c:windowsaxucolyca.reg
c:windowsbazaci.dll
c:windowsboxov._dl
c:windowsbysydyhy.exe
c:windowscemihepote.vbs
c:windowscosugak.sys
c:windowsDelete.bat
c:windowsdyjonojupe._sy
c:windowsehycamin._dl
c:windowsekonu.exe
c:windowselikut._dl
c:windowsfiwonuwe.sys
c:windowshofa.sys
c:windowshokacel.vbs
c:windowsicugiqiqe.reg
c:windowsiryvysy.exe
c:windowskyfufiguni.sys
c:windowsowatomavi.sys
c:windowspidif.sys
c:windowsramuguhyc.vbs
c:windowssystem32cocury._dl
c:windowssystem32defig._dl
c:windowssystem32gapolozyky.ban
c:windowssystem32jehi.dll
c:windowssystem32ovyrem.pif
c:windowssystem32puriced.sys
c:windowssystem32ulelib.dl
c:windowssystem32waxoq.bat
c:windowssystem32xoqimeselu.pif
c:windowssystem32ytotu.vbs
c:windowstineloxizu.vbs
c:windowsvanupetydy._sy
c:windowsvidev.sys
c:windowsvifotanyqa.inf
c:windowswupokasos.ban
c:windowsxulyhed._dl
c:windowsyqita.vbs.
((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
.2009-10-25 07:48 . 2009-10-25 07:48
d
w- c:documents and settingsAdminDoctorWeb
2009-10-25 07:20 . 2009-10-25 07:20 56 —ha-w- c:windowssystem32ezsidmv.dat
2009-10-25 07:18 . 2009-10-25 07:18
d
w- c:program filesCommon FilesSkype
2009-10-25 07:18 . 2009-10-25 07:18
d
r- c:program filesSkype
2009-10-25 05:23 . 2009-10-25 05:23 18257 —-a-w- c:windowssystem32hiwade.dat
2009-10-24 21:36 . 2009-11-03 23:13
d
w- c:program filestrend micro
2009-10-24 21:36 . 2009-10-24 21:37
d
w- C:rsit
2009-10-24 18:19 . 2009-10-24 18:19 10241 —-a-w- c:windowssystem32vulyk.com
2009-10-24 18:19 . 2009-10-24 18:19 14966 —-a-w- c:windowssystem32pehe.com
2009-10-24 14:31 . 2009-10-24 14:31 15240 —-a-w- c:windowssystem32ygeroraji.dat.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 07:35 . 2009-05-03 13:23
d
w- c:documents and settingsAdminApplication DataSkype
2009-11-04 06:42 . 2009-01-26 14:16
d
w- c:documents and settingsAdminApplication DataTransLite
2009-11-03 22:08 . 2009-05-03 13:26
d
w- c:documents and settingsAdminApplication DataskypePM
2009-11-03 22:05 . 2008-12-07 11:31
d
w- c:documents and settingsAdminApplication DataThe Bat!
2009-10-25 15:36 . 2008-11-30 13:43
d
w- c:program filesESET
2009-10-25 07:18 . 2009-05-03 13:23
d
w- c:documents and settingsAll UsersApplication DataSkype
2009-10-25 06:25 . 2009-05-03 14:03 774 —-a-w- c:documents and settingsAdminApplication Dataaldea.dat
2009-10-25 05:24 . 2008-04-15 12:00 77534 —-a-w- c:windowssystem32perfc019.dat
2009-10-25 05:24 . 2008-04-15 12:00 451468 —-a-w- c:windowssystem32perfh019.dat
2009-10-24 21:22 . 2008-11-30 16:11
d
w- c:documents and settingsAdminApplication DataHPAppData
2009-10-24 19:22 . 2009-10-24 19:22 10504 —-a-w- c:program filesCommon Filessugyty.db
2009-10-24 18:19 . 2009-10-24 18:19 15737 —-a-w- c:documents and settingsAll UsersApplication Dataxini.dat
2009-09-11 05:59 . 2009-09-11 05:59
d
w- c:documents and settingsAdminApplication DataU3
2009-08-26 11:15 . 2009-08-26 06:37 19539 —-a-w- c:windowshpqins13.dat
2009-08-20 10:03 . 2009-08-20 10:03 17 —-a-w- c:documents and settingsAdminApplication Datagrf.dat
2003-06-20 22:26 . 2009-01-10 06:58 64591 —-a-r- c:program filesWMV9VCM.chm
2003-06-20 22:26 . 2009-01-10 06:58 12347 —-a-r- c:program filesWMV9VCM_readme.htm
2003-06-10 22:28 . 2009-01-10 06:58 666 —-a-r- c:program filesqPAL-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 661 —-a-r- c:program filesqNTSC-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesPAL-vbr.wv9
2003-06-10 22:28 . 2009-01-10 06:58 653 —-a-r- c:program filesNTSC-vbr.wv9
2003-06-09 10:21 . 2009-01-10 06:58 21158 —-a-r- c:program fileslicense.txt
2003-04-07 12:06 . 2009-01-10 06:58 665 —-a-r- c:program filesFilm-320×240-vbr.wv9
2003-04-07 12:06 . 2009-01-10 06:58 659 —-a-r- c:program filesFilm-640×480-vbr.wv9
2003-04-07 12:06 . 2009-01-10 06:58 377 —-a-r- c:program filesFilm-1280×720-vbr.wv9
.
Sigcheck
[-] 2008-10-24 . 6A104BA98D99D53AB0C91825CE659FC6 . 361600 . . [5.1.2600.5625] . . c:windowssystem32driverstcpip.sys[-] 2008-10-24 . 13548C87ADEFC5980AC4F0F50AC78396 . 80584 . . [7.2.6001.784] . . c:windowssystem32wuauclt.exe
[-] 2008-10-24 . 23B7D3F3F5EC8FEEA75EC381C71CBD5E . 579072 . . [5.1.2600.5512] . . c:windowssystem32user32.dll
[-] 2008-10-24 . 8054F449106C9DA48AEDC82B05BA2B8E . 952832 . . [7.00.6000.20900] . . c:windowssystem32wininet.dll
[-] 2008-10-24 . 89F87645A856F6712E6225079B7931F4 . 1721344 . . [6.00.2900.5512] . . c:windowsexplorer.exe
[-] 2008-10-24 . E52BB415E3A7106E0308A6EE75219F30 . 1571840 . . [5.1.2600.5512] . . c:windowssystem32sfcfiles.dll
[-] 2008-10-24 . 08DD489E663B992B188166951AD131E0 . 30208 . . [5.1.2600.5512] . . c:windowssystem32ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
«Download Master»=»c:program filesDownload Masterdmaster.exe» [2009-02-06 3769856]
«Skype»=»c:program filesSkypePhoneSkype.exe» [2009-10-09 25623336][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
«NvCplDaemon»=»c:windowssystem32NvCpl.dll» [2006-08-11 7630848]
«RemoteControl8″=»c:program filesCyberLinkPowerDVD8PDVD8Serv.exe» [2008-03-20 83240]
«PDVD8LanguageShortcut»=»c:program filesCyberLinkPowerDVD8LanguageLanguage.exe» [2007-12-14 50472]
«BDRegion»=»c:program filesCyberlinkShared Filesbrs.exe» [2008-05-19 91432]
«egui»=»c:program filesESETESET NOD32 Antivirusegui.exe» [2008-08-18 1447168]
«HP Software Update»=»c:program filesHPHP Software UpdateHPWuSchd2.exe» [2007-10-14 49152]
«QuickTime Task»=»c:program filesQuickTimeqttask.exe» [2007-10-19 286720]
«iTunesHelper»=»c:program filesiTunesiTunesHelper.exe» [2007-11-02 267048]
«hpqSRMon»=»c:program filesHPDigital ImagingbinhpqSRMon.exe» [2008-08-20 150016]
«SoundMan»=»SOUNDMAN.EXE» — c:windowsSOUNDMAN.EXE [2007-04-16 577536]
«nwiz»=»nwiz.exe» — c:windowssystem32nwiz.exe [2006-08-11 1519616]
«NvMediaCenter»=»NvMCTray.dll» — c:windowssystem32nvmctray.dll [2006-08-11 86016][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=»c:windowssystem32CTFMON.EXE» [2008-10-24 30208][HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
«IE7_011″=»shell32» [X]
«ZZZZ2_FirstLogonSetting»=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]
«IE7_012″=»advpack.dll» — c:windowssystem32advpack.dll [2008-10-24 124928]c:documents and settingsAll Usersѓ« ў®Ґ ¬ҐоЏа®Ја ¬¬лЂўв®§ Јаг§Є
BlueSoleil.lnk — c:program filesIVT CorporationBlueSoleilgprs.exe [2007-12-27 43608]
HP Digital Imaging Monitor.lnk — c:program filesHPDigital Imagingbinhpqtra08.exe [2007-10-14 214360]
‘«®ў ам TransLite.lnk — c:program filesTransLitetranslite.exe [2009-1-22 761856]
“бЄ®аҐл© § ЇгбЄ Adobe Reader.lnk — c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2004-12-14 29696][HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)[HKEY_USERS.defaultsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
«NoSMConfigurePrograms»= 1 (0x1)[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
«FirewallOverride»=dword:00000001
«UpdatesOverride»=dword:00000001
«AntiVirusOverride»=dword:00000001[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
«EnableFirewall»= 0 (0x0)[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
«%windir%\Network Diagnostic\xpnetdiag.exe»=
«%windir%\system32\sessmgr.exe»=R1 epfwtdir;epfwtdir;c:windowssystem32driversepfwtdir.sys [01.07.2008 8:04 34312]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:program filesCyberLinkPowerDVD800.fcl [15.05.2008 11:07 61424]
R2 ekrn;Eset Service;c:program filesESETESET NOD32 Antivirusekrn.exe [18.08.2008 12:25 468224]
R2 SandraAgentSrv;SiSoftware Deployment Agent Service;c:program filesSiSoftwareSiSoftware Sandra Engineer XII.SP2cRpcAgentSrv.exe [30.11.2008 16:58 98488]
R2 Start BT in service;Start BT in service;c:program filesIVT CorporationBlueSoleilStartSkysolSvc.exe [27.12.2007 14:39 51816]
S3 cel90xbe;cel90xbe;??d:tmpcel90xbe.sys —> d:tmpcel90xbe.sys [?]— Other Services/Drivers In Memory —
*NewlyCreated* — MBR
*NewlyCreated* — PROCEXP113
*NewlyCreated* — SRSERVICE
*Deregistered* — mbr
*Deregistered* — PROCEXP113[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the ‘Scheduled Tasks’ folder2009-10-26 c:windowsTasksAppleSoftwareUpdate.job
— c:program filesApple Software UpdateSoftwareUpdate.exe [2007-08-29 12:57]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.yandex.ru/
IE: &Экспорт в Microsoft Excel — c:progra~1MICROS~1OFFICE11EXCEL.EXE/3000
IE: Закачать ВСЕ при помощи Download Master — c:program filesDownload Masterdmieall.htm
IE: Закачать при помощи Download Master — c:program filesDownload Masterdmie.htm
IE: {{8DAE90AD-4583-4977-9DD4-4360F7A45C74} — c:program filesDownload Masterdmaster.exe
FF — ProfilePath — c:documents and settingsAdminApplication DataMozillaFirefoxProfilesaxxzg6s7.default
FF — prefs.js: network.proxy.type — 2
FF — plugin: c:program filesOperaprogrampluginsnpdm.dll—- FIREFOX POLICIES —-
FF — user.js: capability.policy.policynames — localfilelinks
FF — user.js: capability.policy.localfilelinks.sites — hxxp://speed.travian.ae http://speed2.travian.ae http://s1.travian.ae http://s2.travian.ae http://s3.travian.ae http://s4.travian.ae http://s5.travian.ae http://s6.travian.ae http://s7.travian.ae http://s8.travian.ae http://s9.travian.ae http://s10.travian.ae http://s11.travian.ae http://s12.travian.ae http://s13.travian.ae http://s14.travian.ae http://s15.travian.ae http://s16.travian.ae http://s17.travian.ae http://s18.travian.ae http://s19.travian.ae http://s20.travian.ae http://s21.travian.ae http://s22.travian.ae http://s23.travian.ae http://s24.travian.ae http://s25.travian.ae http://s26.travian.ae http://s27.travian.ae http://s28.travian.ae http://s29.travian.ae http://s30.travian.ae http://s31.travian.ae http://s32.travian.ae http://s33.travian.ae http://s34.travian.ae http://s35.travian.ae http://speed.travian.asia http://speed2.travian.asia http://s1.travian.asia http://s2.travian.asia http://s3.travian.asia http://s4.travian.asia http://s5.travian.asia http://s6.travian.asia http://s7.travian.asia http://s8.travian.asia http://s9.travian.asia http://s10.travian.asia http://speed.travian.ba http://speed2.travian.ba http://s1.travian.ba http://s2.travian.ba http://s3.travian.ba http://s4.travian.ba http://s5.travian.ba http://s6.travian.ba http://s7.travian.ba http://s8.travian.ba http://s9.travian.ba http://s10.travian.ba http://speed.travian.bg http://speed2.travian.bg http://s1.travian.bg http://s2.travian.bg http://s3.travian.bg http://s4.travian.bg http://s5.travian.bg http://s6.travian.bg http://s7.travian.bg http://s8.travian.bg http://s9.travian.bg http://s10.travian.bg http://speed.travian.cl http://speed2.travian.cl http://s1.travian.cl http://s2.travian.cl http://s3.travian.cl http://s4.travian.cl http://s5.travian.cl http://s6.travian.cl http://s7.travian.cl http://s8.travian.cl http://s9.travian.cl http://s10.travian.cl http://speed.travian.cn http://speed2.travian.cn http://s1.travian.cn http://s2.travian.cn http://s3.travian.cn http://s4.travian.cn http://s5.travian.cn http://s6.travian.cn http://s7.travian.cn http://s8.travian.cn http://s9.travian.cn http://s10.travian.cn http://s11.travian.cn http://s12.travian.cn http://s13.travian.cn http://s14.travian.cn http://s15.travian.cn http://s16.travian.cn http://s17.travian.cn http://s18.travian.cn http://s19.travian.cn http://s20.travian.cn http://speed.travian.co.ee http://speed2.travian.co.ee http://s1.travian.co.ee http://s2.travian.co.ee http://s3.travian.co.ee http://s4.travian.co.ee http://s5.travian.co.ee http://s6.travian.co.ee http://s7.travian.co.ee http://s8.travian.co.ee http://s9.travian.co.ee http://s10.travian.co.ee http://s11.travian.co.ee http://s12.travian.co.ee http://s13.travian.co.ee http://s14.travian.co.ee http://s15.travian.co.ee http://s16.travian.co.ee http://s17.travian.co.ee http://s18.travian.co.ee http://s19.travian.co.ee http://s20.travian.co.ee http://speed.travian.co.id http://speed2.travian.co.id http://s1.travian.co.id http://s2.travian.co.id http://s3.travian.co.id http://s4.travian.co.id http://s5.travian.co.id http://s6.travian.co.id http://s7.travian.co.id http://s8.travian.co.id http://s9.travian.co.id http://s10.travian.co.id http://speed.travian.co.il http://speed2.travian.co.il http://s1.travian.co.il http://s2.travian.co.il http://s3.travian.co.il http://s4.travian.co.il http://s5.travian.co.il http://s6.travian.co.il http://s7.travian.co.il http://s8.travian.co.il http://s9.travian.co.il http://s10.travian.co.il http://speed.travian.co.kr http://speed2.travian.co.kr http://s1.travian.co.kr http://s2.travian.co.kr http://s3.travian.co.kr http://s4.travian.co.kr http://s5.travian.co.kr http://s6.travian.co.kr http://s7.travian.co.kr http://s8.travian.co.kr http://s9.travian.co.kr http://s10.travian.co.kr http://speed.travian.co.nz http://speed2.travian.co.nz http://s1.travian.co.nz http://s2.travian.co.nz http://s3.travian.co.nz http://s4.travian.co.nz http://s5.travian.co.nz http://s6.travian.co.nz http://s7.travian.co.nz http://s8.travian.co.nz http://s9.travian.co.nz http://s10.travian.co.nz http://speed.travian.co.uk http://speed2.travian.co.uk http://s1.travian.co.uk http://s2.travian.co.uk http://s3.travian.co.uk http://s4.travian.co.uk http://s5.travian.co.uk http://s6.travian.co.uk http://s7.travian.co.uk http://s8.travian.co.uk http://s9.travian.co.uk http://s10.travian.co.uk http://speed.travian.co.za http://speed2.travian.co.za http://s1.travian.co.za http://s2.travian.co.za http://s3.travian.co.za http://s4.travian.co.za http://s5.travian.co.za http://s6.travian.co.za http://s7.travian.co.za http://s8.travian.co.za http://s9.travian.co.za http://s10.travian.co.za http://speed.travian.com http://speed2.travian.com http://s1.travian.com http://s2.travian.com http://s3.travian.com http://s4.travian.com http://s5.travian.com http://s6.travian.com http://s7.travian.com http://s8.travian.com http://s9.travian.com http://s10.travian.com http://s11.travian.com http://s12.travian.com http://s13.travian.com http://s14.travian.com http://s15.travian.com http://s16.travian.com http://s17.travian.com http://s18.travian.com http://s19.travian.com http://s20.travian.com http://speed.travian.com.ar http://speed2.travian.com.ar http://s1.travian.com.ar http://s2.travian.com.ar http://s3.travian.com.ar http://s4.travian.com.ar http://s5.travian.com.ar http://s6.travian.com.ar http://s7.travian.com.ar http://s8.travian.com.ar http://s9.travian.com.ar http://s10.travian.com.ar http://speed.travian.com.au http://speed2.travian.com.au http://s1.travian.com.au http://s2.travian.com.au http://s3.travian.com.au http://s4.travian.com.au http://s5.travian.com.au http://s6.travian.com.au http://s7.travian.com.au http://s8.travian.com.au http://s9.travian.com.au http://s10.travian.com.au http://speed.travian.com.br http://speed2.travian.com.br http://s1.travian.com.br http://s2.travian.com.br http://s3.travian.com.br http://s4.travian.com.br http://s5.travian.com.br http://s6.travian.com.br http://s7.travian.com.br http://s8.travian.com.br http://s9.travian.com.br http://s10.travian.com.br http://s11.travian.com.br http://s12.travian.com.br http://s13.travian.com.br http://s14.travian.com.br http://s15.travian.com.br http://s16.travian.com.br http://s17.travian.com.br http://s18.travian.com.br http://s19.travian.com.br http://s20.travian.com.br http://speed.travian.com.hr http://speed2.travian.com.hr http://s1.travian.com.hr http://s2.travian.com.hr http://s3.travian.com.hr http://s4.travian.com.hr http://s5.travian.com.hr http://s6.travian.com.hr http://s7.travian.com.hr http://s8.travian.com.hr http://s9.travian.com.hr http://s10.travian.com.hr http://speed.travian.com.mx http://speed2.travian.com.mx http://s1.travian.com.mx http://s2.travian.com.mx http://s3.travian.com.mx http://s4.travian.com.mx http://s5.travian.com.mx http://s6.travian.com.mx http://s7.travian.com.mx http://s8.travian.com.mx http://s9.travian.com.mx http://s10.travian.com.mx http://speed.travian.com.my http://speed2.travian.com.my http://s1.travian.com.my http://s2.travian.com.my http://s3.travian.com.my http://s4.travian.com.my http://s5.travian.com.my http://s6.travian.com.my http://s7.travian.com.my http://s8.travian.com.my http://s9.travian.com.my http://s10.travian.com.my http://speed.travian.com.tr http://speed2.travian.com.tr http://s1.travian.com.tr http://s2.travian.com.tr http://s3.travian.com.tr http://s4.travian.com.tr http://s5.travian.com.tr http://s6.travian.com.tr http://s7.travian.com.tr http://s8.travian.com.tr http://s9.travian.com.tr http://s10.travian.com.tr http://s11.travian.com.tr http://s12.travian.com.tr http://s13.travian.com.tr http://s14.travian.com.tr http://s15.travian.com.tr http://s16.travian.com.tr http://s17.travian.com.tr http://s18.travian.com.tr http://s19.travian.com.tr http://s20.travian.com.tr http://s21.travian.com.tr http://s22.travian.com.tr http://s23.travian.com.tr http://s24.travian.com.tr http://s25.travian.com.tr http://s26.travian.com.tr http://s27.travian.com.tr http://s28.travian.com.tr http://s29.travian.com.tr http://s30.travian.com.tr http://speed.travian.com.ua http://speed2.travian.com.ua http://s1.travian.com.ua http://s2.travian.com.ua http://s3.travian.com.ua http://s4.travian.com.ua http://s5.travian.com.ua http://s6.travian.com.ua http://s7.travian.com.ua http://s8.travian.com.ua http://s9.travian.com.ua http://s10.travian.com.ua http://speed.travian.com.vn http://speed2.travian.com.vn http://s1.travian.com.vn http://s2.travian.com.vn http://s3.travian.com.vn http://s4.travian.com.vn http://s5.travian.com.vn http://s6.travian.com.vn http://s7.travian.com.vn http://s8.travian.com.vn http://s9.travian.com.vn http://s10.travian.com.vn http://speed.travian.cz http://speed2.travian.cz http://s1.travian.cz http://s2.travian.cz http://s3.travian.cz http://s4.travian.cz http://s5.travian.cz http://s6.travian.cz http://s7.travian.cz http://s8.travian.cz http://s9.travian.cz http://s10.travian.cz http://s11.travian.cz http://s12.travian.cz http://s13.travian.cz http://s14.travian.cz http://s15.travian.cz http://s16.travian.cz http://s17.travian.cz http://s18.travian.cz http://s19.travian.cz http://s20.travian.cz http://speed.travian.dk http://speed2.travian.dk http://s1.travian.dk http://s2.travian.dk http://s3.travian.dk http://s4.travian.dk http://s5.travian.dk http://s6.travian.dk http://s7.travian.dk http://s8.travian.dk http://s9.travian.dk http://s10.travian.dk http://speed.travian.fi http://speed2.travian.fi http://s1.travian.fi http://s2.travian.fi http://s3.travian.fi http://s4.travian.fi http://s5.travian.fi http://s6.travian.fi http://s7.travian.fi http://s8.travian.fi http://s9.travian.fi http://s10.travian.fi http://speed.travian.fr http://speed2.travian.fr http://s1.travian.fr http://s2.travian.fr http://s3.travian.fr http://s4.travian.fr http://s5.travian.fr http://s6.travian.fr http://s7.travian.fr http://s8.travian.fr http://s9.travian.fr http://s10.travian.fr http://s11.travian.fr http://s12.travian.fr http://s13.travian.fr http://s14.travian.fr http://s15.travian.fr http://s16.travian.fr http://s17.travian.fr http://s18.travian.fr http://s19.travian.fr http://s20.travian.fr http://speed.travian.gr http://speed2.travian.gr http://s1.travian.gr http://s2.travian.gr http://s3.travian.gr http://s4.travian.gr http://s5.travian.gr http://s6.travian.gr http://s7.travian.gr http://s8.travian.gr http://s9.travian.gr http://s10.travian.gr http://speed.travian.hk http://speed2.travian.hk http://s1.travian.hk http://s2.travian.hk http://s3.travian.hk http://s4.travian.hk http://s5.travian.hk http://s6.travian.hk http://s7.travian.hk http://s8.travian.hk http://s9.travian.hk http://s10.travian.hk http://speed.travian.hu http://speed2.travian.hu http://s1.travian.hu http://s2.travian.hu http://s3.travian.hu http://s4.travian.hu http://s5.travian.hu http://s6.travian.hu http://s7.travian.hu http://s8.travian.hu http://s9.travian.hu http://s10.travian.hu http://speed.travian.in http://speed2.travian.in http://s1.travian.in http://s2.travian.in http://s3.travian.in http://s4.travian.in http://s5.travian.in http://s6.travian.in http://s7.travian.in http://s8.travian.in http://s9.travian.in http://s10.travian.in http://speed.travian.ir http://speed2.travian.ir http://s1.travian.ir http://s2.travian.ir http://s3.travian.ir http://s4.travian.ir http://s5.travian.ir http://s6.travian.ir http://s7.travian.ir http://s8.travian.ir http://s9.travian.ir http://s10.travian.ir http://speed.travian.it http://speed2.travian.it http://s1.travian.it http://s2.travian.it http://s3.travian.it http://s4.travian.it http://s5.travian.it http://s6.travian.it http://s7.travian.it http://s8.travian.it http://s9.travian.it http://s10.travian.it http://s11.travian.it http://s12.travian.it http://s13.travian.it http://s14.travian.it http://s15.travian.it http://s16.travian.it http://s17.travian.it http://s18.travian.it http://s19.travian.it http://s20.travian.it http://speed.travian.jp http://speed2.travian.jp http://s1.travian.jp http://s2.travian.jp http://s3.travian.jp http://s4.travian.jp http://s5.travian.jp http://s6.travian.jp http://s7.travian.jp http://s8.travian.jp http://s9.travian.jp http://s10.travian.jp http://speed.travian.lt http://speed2.travian.lt http://s1.travian.lt http://s2.travian.lt http://s3.travian.lt http://s4.travian.lt http://s5.travian.lt http://s6.travian.lt http://s7.travian.lt http://s8.travian.lt http://s9.travian.lt http://s10.travian.lt http://speed.travian.lv http://speed2.travian.lv http://s1.travian.lv http://s2.travian.lv http://s3.travian.lv http://s4.travian.lv http://s5.travian.lv http://s6.travian.lv http://s7.travian.lv http://s8.travian.lv http://s9.travian.lv http://s10.travian.lv http://speed.travian.net http://speed2.travian.net http://s1.travian.net http://s2.travian.net http://s3.travian.net http://s4.travian.net http://s5.travian.net http://s6.travian.net http://s7.travian.net http://s8.travian.net http://s9.travian.net http://s10.travian.net http://speed.travian.nl http://speed2.travian.nl http://s1.travian.nl http://s2.travian.nl http://s3.travian.nl http://s4.travian.nl http://s5.travian.nl http://s6.travian.nl http://s7.travian.nl http://s8.travian.nl http://s9.travian.nl http://s10.travian.nl http://speed.travian.no http://speed2.travian.no http://s1.travian.no http://s2.travian.no http://s3.travian.no http://s4.travian.no http://s5.travian.no http://s6.travian.no http://s7.travian.no http://s8.travian.no http://s9.travian.no http://s10.travian.no http://speed.travian.ph http://speed2.travian.ph http://s1.travian.ph http://s2.travian.ph http://s3.travian.ph http://s4.travian.ph http://s5.travian.ph http://s6.travian.ph http://s7.travian.ph http://s8.travian.ph http://s9.travian.ph http://s10.travian.ph http://speed.travian.pk http://speed2.travian.pk http://s1.travian.pk http://s2.travian.pk http://s3.travian.pk http://s4.travian.pk http://s5.travian.pk http://s6.travian.pk http://s7.travian.pk http://s8.travian.pk http://s9.travian.pk http://s10.travian.pk http://speed.travian.pl http://speed2.travian.pl http://s1.travian.pl http://s2.travian.pl http://s3.travian.pl http://s4.travian.pl http://s5.travian.pl http://s6.travian.pl http://s7.travian.pl http://s8.travian.pl http://s9.travian.pl http://s10.travian.pl http://s11.travian.pl http://s12.travian.pl http://s13.travian.pl http://s14.travian.pl http://s15.travian.pl http://s16.travian.pl http://s17.travian.pl http://s18.travian.pl http://s19.travian.pl http://s20.travian.pl http://speed.travian.pt http://speed2.travian.pt http://s1.travian.pt http://s2.travian.pt http://s3.travian.pt http://s4.travian.pt http://s5.travian.pt http://s6.travian.pt http://s7.travian.pt http://s8.travian.pt http://s9.travian.pt http://s10.travian.pt http://s11.travian.pt http://s12.travian.pt http://s13.travian.pt http://s14.travian.pt http://s15.travian.pt http://s16.travian.pt http://s17.travian.pt http://s18.travian.pt http://s19.travian.pt http://s20.travian.pt http://speed.travian.ro http://speed2.travian.ro http://s1.travian.ro http://s2.travian.ro http://s3.travian.ro http://s4.travian.ro http://s5.travian.ro http://s6.travian.ro http://s7.travian.ro http://s8.travian.ro http://s9.travian.ro http://s10.travian.ro http://speed.travian.rs http://speed2.travian.rs http://s1.travian.rs http://s2.travian.rs http://s3.travian.rs http://s4.travian.rs http://s5.travian.rs http://s6.travian.rs http://s7.travian.rs http://s8.travian.rs http://s9.travian.rs http://s10.travian.rs http://speed.travian.ru http://speed2.travian.ru http://s1.travian.ru http://s2.travian.ru http://s3.travian.ru http://s4.travian.ru http://s5.travian.ru http://s6.travian.ru http://s7.travian.ru http://s8.travian.ru http://s9.travian.ru http://s10.travian.ru http://s11.travian.ru http://s12.travian.ru http://s13.travian.ru http://s14.travian.ru http://s15.travian.ru http://s16.travian.ru http://s17.travian.ru http://s18.travian.ru http://s19.travian.ru http://s20.travian.ru http://speed.travian.se http://speed2.travian.se http://s1.travian.se http://s2.travian.se http://s3.travian.se http://s4.travian.se http://s5.travian.se http://s6.travian.se http://s7.travian.se http://s8.travian.se http://s9.travian.se http://s10.travian.se http://speed.travian.si http://speed2.travian.si http://s1.travian.si http://s2.travian.si http://s3.travian.si http://s4.travian.si http://s5.travian.si http://s6.travian.si http://s7.travian.si http://s8.travian.si http://s9.travian.si http://s10.travian.si http://speed.travian.sk http://speed2.travian.sk http://s1.travian.sk http://s2.travian.sk http://s3.travian.sk http://s4.travian.sk http://s5.travian.sk http://s6.travian.sk http://s7.travian.sk http://s8.travian.sk http://s9.travian.sk http://s10.travian.sk http://speed.travian.us http://speed2.travian.us http://s1.travian.us http://s2.travian.us http://s3.travian.us http://s4.travian.us http://s5.travian.us http://s6.travian.us http://s7.travian.us http://s8.travian.us http://s9.travian.us http://s10.travian.us http://s11.travian.us http://s12.travian.us http://s13.travian.us http://s14.travian.us http://s15.travian.us http://s16.travian.us http://s17.travian.us http://s18.travian.us http://s19.travian.us http://s20.travian.us http://www.travian.at http://speed.travian.at http://speed2.travian.at http://www.travian.de http://speed.travian.de http://speed2.travian.de http://welt1.travian.de http://welt2.travian.de http://welt3.travian.de http://welt4.travian.de http://welt5.travian.de http://welt6.travian.de http://welt7.travian.de http://welt8.travian.de http://welt9.travian.de http://welt10.travian.de http://www.travian.org http://speed.travian.org http://speed2.travian.org
FF — user.js: capability.policy.localfilelinks.checkloaduri.enabled — allAccessc:program filesMozilla Firefoxgreprefssecurity-prefs.js — pref(«security.ssl3.rsa_seed_sha», true);
.
— — — — ORPHANS REMOVED — — — —HKLM-Run-WinampAgent — c:program filesWinampwinampa.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) — c:program filesMalwarebytes’ Anti-Malwarembam.exe
AddRemove-SimCity 4 Rush Hour — e:_dcdf7~1GamesA417~1SIMCIT~1UNWISE.EXE
AddRemove-{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1 — d:tmpRar$EX01.547NOD32-PATCHObsoleteunins000.exe**************************************************************************
catchme 0.3.1398 W2K/XP/Vista — rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-04 09:37
Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sprs.sys >>UNKNOWN [0x82391938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.netatapi.sys @ 0x0 0x0 bytes
Driveratapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_POWER ] 0xA73C != 0xF8369B40 atapi.sys
Driveratapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF8369B40 atapi.sys
Driveratapi IRP hooks detected !**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001Services{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
«ImagePath»=»??c:program filesCyberLinkPowerDVD800.fcl»
.
DLLs Loaded Under Running Processes
— — — — — — — > ‘winlogon.exe'(732)
c:windowssystem32SETUPAPI.dll
c:windowssystem32cscui.dll— — — — — — — > ‘lsass.exe'(788)
c:windowssystem32SETUPAPI.dll
.
Completion time: 2009-11-04 9:41
ComboFix-quarantined-files.txt 2009-11-04 07:41Pre-Run: 4 126 130 176 байт свободно
Post-Run: 4 105 576 448 байт свободно -
АвторСообщения

