Copyright © 2009 Yahoo! Inc. All rights reserved.



1

======Security center information======

AV: avast! Antivirus

======System event log======

Computer Name: MICROSOF-99BC43
Event Code: 7036
Message: Служба «Совместимость быстрого переключения пользователей» перешла в состояние Работает.

Record Number: 3915
Source Name: Service Control Manager
Time Written: 20100507104520.000000+240
Event Type: информация
User:

Computer Name: MICROSOF-99BC43
Event Code: 7035
Message: Служба «Совместимость быстрого переключения пользователей» успешно отправила управляющий элемент «запустить».

Record Number: 3914
Source Name: Service Control Manager
Time Written: 20100507104520.000000+240
Event Type: информация
User: NT AUTHORITYSYSTEM

Computer Name: MICROSOF-99BC43
Event Code: 7036
Message: Служба «Службы терминалов» перешла в состояние Работает.

Record Number: 3913
Source Name: Service Control Manager
Time Written: 20100507104520.000000+240
Event Type: информация
User:

Computer Name: MICROSOF-99BC43
Event Code: 26
Message: Всплывающее окно приложения: : Machine Check: Regs

Record Number: 3912
Source Name: Application Popup
Time Written: 20100507104410.000000+240
Event Type: информация
User:

Computer Name: MICROSOF-99BC43
Event Code: 26
Message: Всплывающее окно приложения: : Machine Check:

Record Number: 3911
Source Name: Application Popup
Time Written: 20100507104410.000000+240
Event Type: информация
User:

=====Application event log=====

Computer Name: MICROSOF-99BC43
Event Code: 1040
Message: Начата транзакция установщика Windows: C:MSOCacheAll Users90000419-6000-11D3-8CFE-0150048383C9PRO11.MSI. ИД клиентского процесса: 3196.

Record Number: 164
Source Name: MsiInstaller
Time Written: 20100314161616.000000+180
Event Type: информация
User: MICROSOF-99BC43Admin

Computer Name: MICROSOF-99BC43
Event Code: 1033
Message: Установщик Windows выполнил установку продукта. Продукт: PROMT Expert 8 Giant. Версия: 8.0.297. Язык: 1049. Установка завершена с состоянием: 0.

Record Number: 163
Source Name: MsiInstaller
Time Written: 20100314161356.000000+180
Event Type: информация
User: MICROSOF-99BC43Admin

Computer Name: MICROSOF-99BC43
Event Code: 11707
Message: Продукт: PROMT Expert 8 Giant — Операция установки успешно завершена.

Record Number: 162
Source Name: MsiInstaller
Time Written: 20100314161356.000000+180
Event Type: информация
User: MICROSOF-99BC43Admin

Computer Name: MICROSOF-99BC43
Event Code: 1042
Message: Завершение транзакции установщика Windows: D:PROMTE~1.GIAPROMT Expert 8 Giant.msi. ИД клиентского процесса: 3636.

Record Number: 161
Source Name: MsiInstaller
Time Written: 20100314161350.000000+180
Event Type: информация
User: NT AUTHORITYSYSTEM

Computer Name: MICROSOF-99BC43
Event Code: 4097
Message: Приложение C:DOCUME~1AdminLOCALS~1Temp3582-490lhttsfrf.exe вызвало ошибку
Ошибка в 14/03/2010 @ 16:13:48.562
Вызвано исключение c0000005 по адресу 01002749 (lhttsfrf)

Record Number: 160
Source Name: DrWatson
Time Written: 20100314161348.000000+180
Event Type: информация
User:

======Environment variables======

«ComSpec»=%SystemRoot%system32cmd.exe
«Path»=%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem
«windir»=%SystemRoot%
«FP_NO_HOST_CHECK»=NO
«OS»=Windows_NT
«PROCESSOR_ARCHITECTURE»=x86
«PROCESSOR_LEVEL»=6
«PROCESSOR_IDENTIFIER»=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
«PROCESSOR_REVISION»=0801
«NUMBER_OF_PROCESSORS»=1
«PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
«TEMP»=%SystemRoot%TEMP
«TMP»=%SystemRoot%TEMP


EOF


Logfile of random’s system information tool 1.07 (written by random/random)
Run by Admin at 2010-06-04 18:45:22
Microsoft Windows XP Professional Service Pack 3
System drive C: has 18 GB (47%) free of 38 GB
Total RAM: 1023 MB (59% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2010-03-14 41760]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2010-03-14 73728]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{892E81F6-EC63-4d13-8422-835A7A05D6EB} — PROMT — C:Program FilesPRMT8PRMTIEprmtie.dll [2007-10-15 806912]

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«Share-to-Web Namespace Daemon»=c:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe [2002-04-17 69632]
«AutoRun»=F:AUTORUNAutoRun.exe /21 []
«SoundMan»=C:WINDOWSSOUNDMAN.EXE [2004-07-01 67584]
«avast5″=C:PROGRA~1ALWILS~1Avast5avastUI.exe [2010-05-07 2815192]

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2009-01-11 132096]
«Tok-Cirrhatus»= []

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCAP3ON]
C:WINDOWSsystem32spooldriversw32x863CAP3ONN.EXE [2002-08-22 22528]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
C:WINDOWSsystem32ctfmon.exe [2009-12-21 37376]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Canon LASER SHOT LBP-1120 Є¬єAµшµЎ.LNK]
C:WINDOWSsystem32spooldriversw32x863CAP3LAK.EXE [2002-08-22 30720]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyWgaLogon]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2007-06-18 133632]

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«DisableRegistryTools»=1
«DisableCMD»=0

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoFolderOptions»=1

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«HonorAutoRunSetting»=

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2G]
shellAutoRuncommand — G:LaunchU3.exe -a

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{76a2873c-6cda-11df-b6a0-101111111111}]
shellAutoRuncommand — G:LaunchU3.exe -a

======List of files/folders created in the last 1 months======

2010-06-04 18:45:23 —-D—- C:Program Filestrend micro
2010-06-04 18:45:22 —-D—- C:rsit
2010-06-04 12:00:54 —-D—- C:WINDOWSpss
2010-06-03 15:33:37 —-D—- C:Program FilesMSECache
2010-06-01 11:58:46 —-D—- C:Program FilesuTorrent
2010-06-01 11:57:50 —-D—- C:Documents and SettingsAdminApplication DatauTorrent
2010-06-01 00:28:05 —-A—- C:WINDOWSsystem32aswBoot.exe
2010-06-01 00:27:58 —-D—- C:Documents and SettingsAll UsersApplication DataAlwil Software
2010-06-01 00:16:33 —-D—- C:Documents and SettingsAdminApplication DataYandex
2010-06-01 00:15:57 —-D—- C:Documents and SettingsAdminApplication DataMozilla
2010-06-01 00:15:48 —-D—- C:Program FilesMozilla Firefox
2010-05-31 21:32:26 —-D—- C:Documents and SettingsAdminApplication DataU3
2010-05-25 00:14:05 —-A—- C:WINDOWSsystem32ptpusb.dll
2010-05-25 00:14:04 —-A—- C:WINDOWSsystem32ptpusd.dll
2010-05-12 18:02:03 —-D—- C:Program FilesTeachShop

======List of files/folders modified in the last 1 months======

2010-06-04 18:45:23 —-RD—- C:Program Files
2010-06-04 18:45:09 —-D—- C:WINDOWSTemp
2010-06-04 17:42:51 —-A—- C:WINDOWSSchedLgU.Txt
2010-06-04 12:14:05 —-RAH—- C:WINDOWSsystem32cdplayer.exe.manifest
2010-06-04 12:11:31 —-D—- C:WINDOWSPrefetch
2010-06-04 12:01:56 —-SH—- C:boot.ini
2010-06-04 12:01:56 —-A—- C:WINDOWSwin.ini
2010-06-04 12:01:56 —-A—- C:WINDOWSsystem.ini
2010-06-04 12:00:54 —-D—- C:WINDOWS
2010-06-03 16:31:53 —-D—- C:WINDOWSsystem32CatRoot2
2010-06-03 15:54:16 —-SHD—- C:WINDOWSInstaller
2010-06-03 15:54:15 —-D—- C:Program FilesCommon FilesMicrosoft Shared
2010-06-03 15:19:58 —-D—- C:WINDOWSsystem32
2010-06-03 06:44:56 —-ASH—- C:WINDOWSsystem32og.dll
2010-06-03 06:27:24 —-ASH—- C:WINDOWSsystem32ul.dll
2010-06-03 00:30:01 —-SD—- C:Documents and SettingsAdminApplication DataMicrosoft
2010-06-01 12:31:26 —-D—- C:Program FilesThe KMPlayer
2010-06-01 01:20:17 —-D—- C:WINDOWSSHELLNEW
2010-06-01 01:20:11 —-SD—- C:WINDOWSTasks
2010-06-01 01:20:11 —-D—- C:col4309
2010-06-01 00:28:17 —-D—- C:WINDOWSsystem32drivers
2010-06-01 00:28:12 —-D—- C:WINDOWSWinSxS
2010-06-01 00:27:58 —-D—- C:Program FilesAlwil Software
2010-05-31 23:03:08 —-SH—- C:AUTOEXEC.BAT
2010-05-24 11:13:39 —-A—- C:WINDOWSNeroDigital.ini
2010-05-09 21:29:02 —-D—- C:Program FilesAIMP2
2010-05-05 10:53:54 —-D—- C:WINDOWSNetwork Diagnostic

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:WINDOWSsystem32driversAavmker4.sys [2010-05-07 28880]
R1 AFS2K;AFS2k; C:WINDOWSsystem32driversAFS2K.sys [2010-03-14 82380]
R1 AmdK7;Драйвер AMD K7 процессора; C:WINDOWSsystem32DRIVERSamdk7.sys [2009-12-21 41984]
R1 aswSP;aswSP; C:WINDOWSsystem32driversaswSP.sys [2010-05-07 164048]
R1 aswTdi;avast! Network Shield Support; C:WINDOWSsystem32driversaswTdi.sys [2010-05-07 46672]
R2 aswFsBlk;aswFsBlk; C:WINDOWSsystem32driversaswFsBlk.sys [2010-05-07 19024]
R2 aswMon2;aswMon2; C:WINDOWSsystem32driversaswMon2.sys [2010-05-07 100432]
R2 exFat;exFat; C:WINDOWSsystem32driversexFat.sys [2009-01-28 133632]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:WINDOWSsystem32DRIVERSrspndr.sys [2008-10-11 62848]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:WINDOWSsystem32driversALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2004-07-01 626977]
R3 Arp1394;Протокол клиента 1394 ARP; C:WINDOWSsystem32DRIVERSarp1394.sys [2009-12-21 60800]
R3 aswRdr;aswRdr; C:WINDOWSsystem32driversaswRdr.sys [2010-05-07 23376]
R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2008-04-15 701440]
R3 BlueletAudio;Bluetooth Audio Service; C:WINDOWSsystem32DRIVERSblueletaudio.sys [2005-05-31 20480]
R3 BT;Bluetooth PAN Network Adapter; C:WINDOWSsystem32DRIVERSbtnetdrv.sys [2005-04-30 10804]
R3 BTHidEnum;Bluetooth HID Enumerator; C:WINDOWSsystem32DRIVERSvbtenum.sys [2005-04-30 11860]
R3 NIC1394;Сетевой драйвер 1394; C:WINDOWSsystem32DRIVERSnic1394.sys [2009-12-21 61824]
R3 NVENET;NVIDIA nForce MCP Networking Controller Driver; C:WINDOWSsystem32DRIVERSNVENET.sys [2003-08-15 72771]
R3 nvmpu401;Service for NVIDIA(R) nForce(TM) MIDI UART; C:WINDOWSsystem32driversnvmpu401.sys [2006-02-26 10240]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-04-15 30208]
R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-15 59520]
R3 usbohci;Драйвер минипорта Microsoft USB открытого хост-контроллера; C:WINDOWSsystem32DRIVERSusbohci.sys [2008-04-15 17152]
R3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-04-14 15104]
R3 VComm;Virtual Serial port driver; C:WINDOWSsystem32DRIVERSVComm.sys [2004-10-19 61312]
R3 VcommMgr;Bluetooth VComm Manager Service; C:WINDOWSSystem32DriversVcommMgr.sys [2005-03-25 82148]
S3 AutorunDirectIO;AutorunDirectIO; ??F:AUTORUNDIODrvr.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:WINDOWSSystem32Driversbtcusb.sys [2005-05-31 23000]
S3 CCDECODE;Closed Caption декодер; C:WINDOWSsystem32DRIVERSCCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:WINDOWSsystem32driversMSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI кодек; C:WINDOWSsystem32DRIVERSNABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft видео или ТВ подключение; C:WINDOWSsystem32DRIVERSNdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:WINDOWSsystem32DRIVERSSLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:WINDOWSsystem32DRIVERSStreamIP.sys [2008-04-14 15232]
S3 usbprint;Класс принтеров Microsoft USB; C:WINDOWSsystem32DRIVERSusbprint.sys [2008-04-14 25856]
S3 usbstor;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-15 26368]
S3 WSTCODEC;World Standard Teletext кодек; C:WINDOWSsystem32DRIVERSWSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2007-06-18 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2007-06-18 82944]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service; C:Program FilesABBYY FineReader 9.0NetworkLicenseServer.exe [2007-11-02 566560]
R2 avast! Antivirus;avast! Antivirus; C:Program FilesAlwil SoftwareAvast5AvastSvc.exe [2010-05-07 40384]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; D:BTNtService.exe [2005-04-06 110592]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:Program FilesCommon FilesNeroNero BackItUp 4NBService.exe [2008-09-24 935208]
R3 avast! Mail Scanner;avast! Mail Scanner; C:Program FilesAlwil SoftwareAvast5AvastSvc.exe [2010-05-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:Program FilesAlwil SoftwareAvast5AvastSvc.exe [2010-05-07 40384]
S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:WINDOWSMicrosoft.NetFrameworkv3.0WPFPresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication Foundationinfocard.exe [2006-10-30 741376]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
S4 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2010-03-14 153376]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication FoundationSMSvcHost.exe [2006-10-30 122880]


EOF


#29556
Admin
Keymaster
  • Темы:40
  • Сообщений:5676
  • ☆☆☆☆☆

Здравствуйте, добро пожаловать на Spyware-ru форум.

Скачайте OTM by OldTimer кликнув по этой ссылке.
Запустите OTM и в большое поле ввода (заголовок этого поля выделен желтым цветом) скопируйте следующий текст.

:services
AutorunDirectIO

:reg
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
"AutoRun"=-

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
"Tok-Cirrhatus"=-

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
"DisableRegistryTools"=-
"DisableCMD"=-

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
"NoFolderOptions"=0

:Commands
[emptytemp]
[Reboot]

Проверьте вставленный скрипт, если слева перед директивами появились пробелы, то удалите их, скрипт должен выглядеть так же как в сообщении. Кликните по кнопке MoveIt!. В процессе работы возможна перезагрузка компьютера.
По-завершении работы программы должен будет показан лог. Если лог не будет показан, то его можно найти в папке C:_OTMMovedFiles.

Вставьте в ваше ответное сообщение содержимое этого лога. И приложите свежий RSIT лог.

#29557
_2234
Participant
  • Темы:1
  • Сообщений:3

All processes killed
========== SERVICES/DRIVERS ==========
Error: No service named AutorunDirectIO was found to stop!
No service named AutorunDirectIO was found to delete!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun\AutoRun deleted successfully.
Registry value HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun\Tok-Cirrhatus deleted successfully.
Registry value HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem\DisableRegistryTools deleted successfully.
Registry value HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem\DisableCMD deleted successfully.
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer\»NoFolderOptions»|0 /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 1957956643 bytes
->Temporary Internet Files folder emptied: 12570183 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 83998354 bytes
->Opera cache emptied: 296671 bytes
->Flash cache emptied: 14580 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2340499 bytes
%systemroot%System32 .tmp files removed: 1241917 bytes
%systemroot%System32dllcache .tmp files removed: 0 bytes
%systemroot%System32drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 35374200 bytes
%systemroot%system32configsystemprofileLocal SettingsTemp folder emptied: 0 bytes
%systemroot%system32configsystemprofileLocal SettingsTemporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 2282945644 bytes

Total Files Cleaned = 4 174,00 mb

OTM by OldTimer — Version 3.1.12.2 log created on 06092010_010107

Files moved on Reboot…
C:WINDOWStemp_avast4_Webshlock.txt moved successfully.
C:WINDOWStempPerflib_Perfdata_734.dat moved successfully.

Registry entries deleted on Reboot…
Logfile of random’s system information tool 1.07 (written by random/random)
Run by Admin at 2010-06-09 01:15:24
Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (57%) free of 38 GB
Total RAM: 1023 MB (61% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2010-03-14 41760]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2010-03-14 73728]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{892E81F6-EC63-4d13-8422-835A7A05D6EB} — PROMT — C:Program FilesPRMT8PRMTIEprmtie.dll [2007-10-15 806912]

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«Share-to-Web Namespace Daemon»=c:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe [2002-04-17 69632]
«SoundMan»=C:WINDOWSSOUNDMAN.EXE [2004-07-01 67584]
«avast!»=C:PROGRA~1ALWILS~1Avast4ashDisp.exe [2009-11-25 81000]

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2009-01-11 132096]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCAP3ON]
C:WINDOWSsystem32spooldriversw32x863CAP3ONN.EXE [2002-08-22 22528]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
C:WINDOWSsystem32ctfmon.exe [2009-12-21 37376]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Главное меню^Программы^Автозагрузка^Canon LASER SHOT LBP-1120 Є¬єAµшµЎ.LNK]
C:WINDOWSsystem32spooldriversw32x863CAP3LAK.EXE [2002-08-22 30720]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyWgaLogon]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2007-06-18 133632]

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoFolderOptions»=0

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«HonorAutoRunSetting»=

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{76a2873c-6cda-11df-b6a0-101111111111}]
shellAutoRuncommand — G:LaunchU3.exe -a

======List of files/folders created in the last 1 months======

2010-06-09 01:15:25 —-D—- C:Program Filestrend micro
2010-06-09 01:15:24 —-D—- C:rsit
2010-06-09 01:01:07 —-D—- C:_OTM
2010-06-05 20:55:15 —-A—- C:WINDOWSsystem32aswBoot.exe
2010-06-05 09:22:44 —-D—- C:SDFix
2010-06-05 09:16:05 —-D—- C:Avenger
2010-06-05 09:16:05 —-A—- C:avenger.txt
2010-06-04 12:00:54 —-D—- C:WINDOWSpss
2010-06-03 15:33:37 —-D—- C:Program FilesMSECache
2010-06-01 11:58:46 —-D—- C:Program FilesuTorrent
2010-06-01 11:57:50 —-D—- C:Documents and SettingsAdminApplication DatauTorrent
2010-06-01 00:27:58 —-D—- C:Documents and SettingsAll UsersApplication DataAlwil Software
2010-06-01 00:16:33 —-D—- C:Documents and SettingsAdminApplication DataYandex
2010-06-01 00:15:57 —-D—- C:Documents and SettingsAdminApplication DataMozilla
2010-06-01 00:15:48 —-D—- C:Program FilesMozilla Firefox
2010-05-31 21:32:26 —-D—- C:Documents and SettingsAdminApplication DataU3
2010-05-25 00:14:05 —-A—- C:WINDOWSsystem32ptpusb.dll
2010-05-25 00:14:04 —-A—- C:WINDOWSsystem32ptpusd.dll
2010-05-12 18:02:03 —-D—- C:Program FilesTeachShop

======List of files/folders modified in the last 1 months======

2010-06-09 01:15:31 —-D—- C:WINDOWSPrefetch
2010-06-09 01:15:25 —-RD—- C:Program Files
2010-06-09 01:07:54 —-D—- C:WINDOWSTemp
2010-06-09 01:01:23 —-D—- C:WINDOWSsystem32
2010-06-09 01:01:23 —-D—- C:WINDOWS
2010-06-08 22:49:55 —-A—- C:WINDOWSSchedLgU.Txt
2010-06-07 22:31:24 —-A—- C:WINDOWSNeroDigital.ini
2010-06-07 08:55:40 —-SHD—- C:WINDOWSInstaller
2010-06-06 23:59:07 —-D—- C:WINDOWSsystem32CatRoot2
2010-06-06 23:17:51 —-D—- C:Program FilesThe KMPlayer
2010-06-05 20:55:29 —-D—- C:WINDOWSsystem32drivers
2010-06-05 20:27:40 —-D—- C:WINDOWSsystem32CPLDAPU
2010-06-04 12:14:05 —-RAH—- C:WINDOWSsystem32cdplayer.exe.manifest
2010-06-04 12:01:56 —-SH—- C:boot.ini
2010-06-04 12:01:56 —-A—- C:WINDOWSwin.ini
2010-06-04 12:01:56 —-A—- C:WINDOWSsystem.ini
2010-06-03 15:54:15 —-D—- C:Program FilesCommon FilesMicrosoft Shared
2010-06-03 06:44:56 —-ASH—- C:WINDOWSsystem32og.dll
2010-06-03 06:27:24 —-ASH—- C:WINDOWSsystem32ul.dll
2010-06-03 00:30:01 —-SD—- C:Documents and SettingsAdminApplication DataMicrosoft
2010-06-01 01:20:17 —-D—- C:WINDOWSSHELLNEW
2010-06-01 01:20:11 —-SD—- C:WINDOWSTasks
2010-06-01 01:20:11 —-D—- C:col4309
2010-06-01 00:28:12 —-D—- C:WINDOWSWinSxS
2010-06-01 00:27:58 —-D—- C:Program FilesAlwil Software
2010-05-31 23:03:08 —-SH—- C:AUTOEXEC.BAT

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:WINDOWSsystem32driversAavmker4.sys [2009-11-25 27408]
R1 AFS2K;AFS2k; C:WINDOWSsystem32driversAFS2K.sys [2010-03-14 82380]
R1 AmdK7;Драйвер AMD K7 процессора; C:WINDOWSsystem32DRIVERSamdk7.sys [2009-12-21 41984]
R1 aswSP;avast! Self Protection; C:WINDOWSsystem32driversaswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:WINDOWSsystem32driversaswTdi.sys [2009-11-25 48560]
R2 aswFsBlk;aswFsBlk; C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:WINDOWSsystem32driversaswMon2.sys [2009-11-25 94160]
R2 exFat;exFat; C:WINDOWSsystem32driversexFat.sys [2009-01-28 133632]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:WINDOWSsystem32DRIVERSrspndr.sys [2008-10-11 62848]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:WINDOWSsystem32driversALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2004-07-01 626977]
R3 Arp1394;Протокол клиента 1394 ARP; C:WINDOWSsystem32DRIVERSarp1394.sys [2009-12-21 60800]
R3 aswRdr;aswRdr; C:WINDOWSsystem32driversaswRdr.sys [2009-11-25 23120]
R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2008-04-15 701440]
R3 BlueletAudio;Bluetooth Audio Service; C:WINDOWSsystem32DRIVERSblueletaudio.sys [2005-05-31 20480]
R3 BT;Bluetooth PAN Network Adapter; C:WINDOWSsystem32DRIVERSbtnetdrv.sys [2005-04-30 10804]
R3 BTHidEnum;Bluetooth HID Enumerator; C:WINDOWSsystem32DRIVERSvbtenum.sys [2005-04-30 11860]
R3 NIC1394;Сетевой драйвер 1394; C:WINDOWSsystem32DRIVERSnic1394.sys [2009-12-21 61824]
R3 NVENET;NVIDIA nForce MCP Networking Controller Driver; C:WINDOWSsystem32DRIVERSNVENET.sys [2003-08-15 72771]
R3 nvmpu401;Service for NVIDIA(R) nForce(TM) MIDI UART; C:WINDOWSsystem32driversnvmpu401.sys [2006-02-26 10240]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-04-15 30208]
R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-15 59520]
R3 usbohci;Драйвер минипорта Microsoft USB открытого хост-контроллера; C:WINDOWSsystem32DRIVERSusbohci.sys [2008-04-15 17152]
R3 usbscan;Драйвер USB-сканера; C:WINDOWSsystem32DRIVERSusbscan.sys [2008-04-14 15104]
R3 VComm;Virtual Serial port driver; C:WINDOWSsystem32DRIVERSVComm.sys [2004-10-19 61312]
R3 VcommMgr;Bluetooth VComm Manager Service; C:WINDOWSSystem32DriversVcommMgr.sys [2005-03-25 82148]
S3 AutorunDirectIO;AutorunDirectIO; ??F:AUTORUNDIODrvr.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:WINDOWSSystem32Driversbtcusb.sys [2005-05-31 23000]
S3 CCDECODE;Closed Caption декодер; C:WINDOWSsystem32DRIVERSCCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:WINDOWSsystem32driversMSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI кодек; C:WINDOWSsystem32DRIVERSNABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft видео или ТВ подключение; C:WINDOWSsystem32DRIVERSNdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:WINDOWSsystem32DRIVERSSLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:WINDOWSsystem32DRIVERSStreamIP.sys [2008-04-14 15232]
S3 usbprint;Класс принтеров Microsoft USB; C:WINDOWSsystem32DRIVERSusbprint.sys [2008-04-14 25856]
S3 usbstor;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-15 26368]
S3 WSTCODEC;World Standard Teletext кодек; C:WINDOWSsystem32DRIVERSWSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2007-06-18 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2007-06-18 82944]
S4 IntelIde;IntelIde; C:WINDOWSsystem32driversIntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service; C:Program FilesABBYY FineReader 9.0NetworkLicenseServer.exe [2007-11-02 566560]
R2 aswUpdSv;avast! iAVS4 Control Service; C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:Program FilesAlwil SoftwareAvast4ashServ.exe [2009-11-25 138680]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; D:BTNtService.exe [2005-04-06 110592]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:Program FilesCommon FilesNeroNero BackItUp 4NBService.exe [2008-09-24 935208]
R3 avast! Mail Scanner;avast! Mail Scanner; C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:Program FilesAlwil SoftwareAvast4ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;ASP.NET State Service; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:WINDOWSMicrosoft.NetFrameworkv3.0WPFPresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication Foundationinfocard.exe [2006-10-30 741376]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
S4 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2010-03-14 153376]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:WINDOWSMicrosoft.NETFrameworkv3.0Windows Communication FoundationSMSvcHost.exe [2006-10-30 122880]


EOF


#29558
Admin
Keymaster
  • Темы:40
  • Сообщений:5676
  • ☆☆☆☆☆

Лог выглядит нормально. Какова сейчас ситуация со скрытыми файлами ?

#29559
_2234
Participant
  • Темы:1
  • Сообщений:3

В настройках так и не появилось меню просмотра скрытых файлов. я изменила антивирусник, предыдущий помещал файлы в карантин и они после этого становились скрытыми, и комп их не видел вообще. сейчас мне сложно судить видны ли эти файлы или комп их по прежнему не видит. Проблему с файлами на телефоне я устранила на другом компьютере(изменила в свойствах).

Просмотр 5 сообщений - с 1 по 5 (из 5 всего)
Войти