Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › НЕ счастливый оладатель информера
- This topic has 3 ответа, 2 участника, and was last updated 16 years, 3 months назад by
Admin.
-
АвторСообщения
-
10 декабря, 2008 в 10:09 пп #16002
Доброго времени суток Вам! Сразу хочется выказать болшущюю благодарность, с наилучшими пожеланиями — за ту поддержку, кою Вы оказываете бедолагам вроде меня.
Собственно просьба: помогите удалить информер FREE PORNO VIDEO
Да, еще — на компютере установлены и ЛИСА и ОПЕРА, информер выскакивает только IE.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:19:17, on 11.12.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: NormalRunning processes:
C:Windowssystem32taskeng.exe
C:Windowssystem32Dwm.exe
C:Windowssystem32taskeng.exe
C:WindowsExplorer.EXE
C:Program FilesWinamp Remotebinorbtray.exe
C:Program FilesWindows DefenderMSASCui.exe
C:WindowsRtHDVCpl.exe
C:Program FilesMail.RuAgentmagent.exe
C:Program FilesSystem Control ManagerMGSysCtrl.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:Windowssystem32igfxsrvc.exe
C:Program FilesProtector Suite QLpsqltray.exe
C:WindowsBisonCamBisonHK.exe
C:WindowsBisonCamBsMnt.exe
D:1Sony Ericsson PC SuiteSEPCSuite.exe
C:Program FilesSkypePhoneSkype.exe
C:Windowsehomeehtray.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehmsas.exe
C:Program FilesWinamp RemotebinOrb.exe
C:Program FilesSkypePlugin ManagerskypePM.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtMng.exe
C:Program FilesToshibaBluetooth Toshiba StackTosA2dp.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtHid.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtHsp.exe
C:Program FilesInternet Explorerieuser.exe
C:Program FilesInternet Exploreriexplore.exe
D:Operaopera.exe
C:Windowssystem32MacromedFlashFlashUtil10a.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe
C:Windowssystem32SearchFilterHost.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 — URLSearchHook: (no name) — {83821C2B-32A8-4DD7-B6D4-44309A78E668} — C:Program FilesMail.RuAgentMradllnewmrasearch.dll
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O1 — Hosts: ::1 localhost
O2 — BHO: Adobe PDF Reader Link Helper — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 — BHO: fqclibP — {14A73946-6708-4E75-A6C9-5A4C3AE2382F} — C:Windowssystem32fqclib.dll
O2 — BHO: Skype add-on (mastermind) — {22BF413B-C6D2-4d91-82A9-A0F997BA588C} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 — BHO: edwlibP — {649E5EA7-32CE-483B-A457-9814D959ABDE} — C:Windowssystem32edwlib.dll
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O4 — HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 — HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 — HKLM..Run: [Skytel] Skytel.exe
O4 — HKLM..Run: [MAgent] C:Program FilesMail.RuAgentMAgent.exe -LM
O4 — HKLM..Run: [MGSysCtrl] C:Program FilesSystem Control ManagerMGSysCtrl.exe
O4 — HKLM..Run: [PSQLLauncher] «C:Program FilesProtector Suite QLlauncher.exe» /startup
O4 — HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 — HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 — HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 — HKLM..Run: [Adobe Reader Speed Launcher] «C:Program FilesAdobeReader 8.0ReaderReader_sl.exe»
O4 — HKLM..Run: [avgnt] «C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe» /min
O4 — HKLM..Run: [BisonHK] C:WindowsBisonCamBisonHK.exe
O4 — HKLM..Run: [BsMnt] C:WindowsBisonCamBsMnt.exe
O4 — HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 — HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 — HKCU..Run: [Sony Ericsson PC Suite] «D:1Sony Ericsson PC SuiteSEPCSuite.exe» /systray /nologon
O4 — HKCU..Run: [Skype] «C:Program FilesSkypePhoneSkype.exe» /nosplash /minimized
O4 — HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 — HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User ‘NETWORK SERVICE’)
O4 — Global Startup: Bluetooth Manager.lnk = ?
O4 — Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 — Extra context menu item: Найти в интернете — res://C:Program FilesMail.RuSputnikMailRuSputnik.dll/282
O8 — Extra context menu item: Найти в словарях — res://C:Program FilesMail.RuSputnikMailRuSputnik.dll/283
O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra button: Skype — {77BF5300-1474-4EC7-9980-D32B190E9B07} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O9 — Extra button: Real.com — {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} — C:Windowssystem32Shdocvw.dll
O13 — Gopher Prefix:
O16 — DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) — http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Agere Modem Call Progress Audio (AgereModemAudio) — Agere Systems — C:Windowssystem32agrsmsvc.exe
O23 — Service: Avira AntiVir Personal — Free Antivirus Scheduler (AntiVirScheduler) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 — Service: Avira AntiVir Personal — Free Antivirus Guard (AntiVirService) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 — Service: @dfsrres.dll,-101 (DFSR) — Корпорация Майкрософт — C:Windowssystem32DFSR.exe
O23 — Service: SCM Driver Daemon (NishService) — Unknown owner — C:Program FilesSystem Control Manageredd.exe
O23 — Service: TOSHIBA Bluetooth Service — TOSHIBA CORPORATION — C:Program FilesToshibaBluetooth Toshiba StackTosBtSrv.exe—
End of file — 7428 bytes11 декабря, 2008 в 5:42 дп #20281Здравствуйте, добро пожаловать на Spyware-ru форум.
Спасибо за пожелания 🙂
Приступим к лечению вашего компьютера.
Запустите HijackThis, кликните по кнопке Do a system scan only.
Далее отметьте галочкой (слева) следующие строки:O2 - BHO: fqclibP - {14A73946-6708-4E75-A6C9-5A4C3AE2382F} - C:Windowssystem32fqclib.dll
O2 - BHO: edwlibP - {649E5EA7-32CE-483B-A457-9814D959ABDE} - C:Windowssystem32edwlib.dllКликните по кнопке Fix checked и подтвердите свои действия выбрав YES.
Перезагрузите компьютер и проверьте наличие информера.Для дополнительной проверки скачайте сканер RSIT кликнув по этой ссылке.
Дважды кликните по скачанному файлу.
Кликните по кнопке Continue.
Когда программа закончит работу, будут показаны два лога (log.txt и info.txt).Вставьте оба RSIT лога в ваш ответ.
11 декабря, 2008 в 7:52 пп #20282…О! СЧАСТЬЕ НАМ, А ВАМ ОГРОМНОЕ СПАСИБО!
ПУСТЬ ГАДЫ КОРЧАТСЯ ВО ТЬМЕ!!!
НАД ВАМИ Ж СОЛНЦЕ И ГОЛУБОЕ НЕБО,
РЕСПЕКТ РЕБЯТА!, УДАЧИ В ЭТОЙ КУТЕРЬМЕ!!!…собственно, понятно, что гадость красная убита 😀
Вот что «сказал» RSIT :
Logfile of random’s system information tool 1.04 (written by random/random)
Run by ПАПА at 2008-12-11 22:30:41
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 7 GB (19%) free of 35 GB
Total RAM: 2039 MB (44% free)Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:30:43, on 11.12.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: NormalRunning processes:
C:Windowssystem32taskeng.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesWindows DefenderMSASCui.exe
C:WindowsRtHDVCpl.exe
C:Program FilesMail.RuAgentmagent.exe
C:Program FilesSystem Control ManagerMGSysCtrl.exe
C:WindowsSystem32igfxtray.exe
C:WindowsSystem32hkcmd.exe
C:Windowssystem32igfxsrvc.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:WindowsBisonCamBisonHK.exe
C:Program FilesProtector Suite QLpsqltray.exe
C:WindowsBisonCamBsMnt.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Windowsehomeehtray.exe
D:1Sony Ericsson PC SuiteSEPCSuite.exe
C:Windowsehomeehmsas.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtMng.exe
C:Program FilesToshibaBluetooth Toshiba StackTosA2dp.exe
C:Program FilesWindows Sidebarsidebar.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtHid.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtHsp.exe
C:Program FilesSkypePlugin ManagerskypePM.exe
C:Program FilesInternet Explorerieuser.exe
C:Program FilesInternet Exploreriexplore.exe
C:Windowssystem32MacromedFlashFlashUtil10a.exe
D:Operaopera.exe
D:RSIT.exe
C:Program FilesTrend MicroHijackThisПАПА.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 — URLSearchHook: (no name) — {83821C2B-32A8-4DD7-B6D4-44309A78E668} — C:Program FilesMail.RuAgentMradllnewmrasearch.dll
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O1 — Hosts: ::1 localhost
O2 — BHO: Adobe PDF Reader Link Helper — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 — BHO: Skype add-on (mastermind) — {22BF413B-C6D2-4d91-82A9-A0F997BA588C} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program FilesMail.RuSputnikMailRuSputnik.dll
O4 — HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 — HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 — HKLM..Run: [Skytel] Skytel.exe
O4 — HKLM..Run: [MAgent] C:Program FilesMail.RuAgentMAgent.exe -LM
O4 — HKLM..Run: [MGSysCtrl] C:Program FilesSystem Control ManagerMGSysCtrl.exe
O4 — HKLM..Run: [PSQLLauncher] «C:Program FilesProtector Suite QLlauncher.exe» /startup
O4 — HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 — HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 — HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 — HKLM..Run: [Adobe Reader Speed Launcher] «C:Program FilesAdobeReader 8.0ReaderReader_sl.exe»
O4 — HKLM..Run: [avgnt] «C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe» /min
O4 — HKLM..Run: [BisonHK] C:WindowsBisonCamBisonHK.exe
O4 — HKLM..Run: [BsMnt] C:WindowsBisonCamBsMnt.exe
O4 — HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 — HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 — HKCU..Run: [Sony Ericsson PC Suite] «D:1Sony Ericsson PC SuiteSEPCSuite.exe» /systray /nologon
O4 — HKCU..Run: [Skype] «C:Program FilesSkypePhoneSkype.exe» /nosplash /minimized
O4 — HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 — HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User ‘NETWORK SERVICE’)
O4 — Global Startup: Bluetooth Manager.lnk = ?
O4 — Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 — Extra context menu item: Найти в интернете — res://C:Program FilesMail.RuSputnikMailRuSputnik.dll/282
O8 — Extra context menu item: Найти в словарях — res://C:Program FilesMail.RuSputnikMailRuSputnik.dll/283
O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program FilesMail.RuAgentmagent.exe
O9 — Extra button: Skype — {77BF5300-1474-4EC7-9980-D32B190E9B07} — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O9 — Extra button: Real.com — {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} — C:Windowssystem32Shdocvw.dll
O13 — Gopher Prefix:
O16 — DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) — http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 — Service: Agere Modem Call Progress Audio (AgereModemAudio) — Agere Systems — C:Windowssystem32agrsmsvc.exe
O23 — Service: Avira AntiVir Personal — Free Antivirus Scheduler (AntiVirScheduler) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 — Service: Avira AntiVir Personal — Free Antivirus Guard (AntiVirService) — Avira GmbH — C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 — Service: @dfsrres.dll,-101 (DFSR) — Корпорация Майкрософт — C:Windowssystem32DFSR.exe
O23 — Service: SCM Driver Daemon (NishService) — Unknown owner — C:Program FilesSystem Control Manageredd.exe
O23 — Service: TOSHIBA Bluetooth Service — TOSHIBA CORPORATION — C:Program FilesToshibaBluetooth Toshiba StackTosBtSrv.exe—
End of file — 7083 bytes======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll [2006-10-22 62080][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) — C:Program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll [2008-09-23 1088296][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{8984B388-A5BB-4DF7-B274-77B879E179DB}]
MailRuBHO Class — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2008-10-04 665800][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{09900DE8-1DCA-443F-9243-26FF581438AF} — Спутник@Mail.Ru — C:Program FilesMail.RuSputnikMailRuSputnik.dll [2008-10-04 665800][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«Windows Defender»=C:Program FilesWindows DefenderMSASCui.exe [2008-01-19 1008184]
«RtHDVCpl»=C:WindowsRtHDVCpl.exe [2007-04-10 4431872]
«Skytel»=C:WindowsSkytel.exe [2007-04-04 1822720]
«MAgent»=C:Program FilesMail.RuAgentMAgent.exe [2008-10-04 4417016]
«MGSysCtrl»=C:Program FilesSystem Control ManagerMGSysCtrl.exe [2007-06-06 561152]
«PSQLLauncher»=C:Program FilesProtector Suite QLlauncher.exe [2007-03-28 49168]
«IgfxTray»=C:Windowssystem32igfxtray.exe [2008-04-18 150040]
«HotKeysCmds»=C:Windowssystem32hkcmd.exe [2008-04-18 170520]
«Persistence»=C:Windowssystem32igfxpers.exe [2008-04-18 141848]
«Adobe Reader Speed Launcher»=C:Program FilesAdobeReader 8.0ReaderReader_sl.exe [2008-10-15 39792]
«avgnt»=C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe [2008-06-12 266497]
«BisonHK»=C:WindowsBisonCamBisonHK.exe [2007-03-15 32768]
«BsMnt»=C:WindowsBisonCamBsMnt.exe [2007-03-15 172032][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«Sidebar»=C:Program FilesWindows Sidebarsidebar.exe [2008-01-19 1233920]
«ehTray.exe»=C:WindowsehomeehTray.exe [2008-01-19 125952]
«Sony Ericsson PC Suite»=D:1Sony Ericsson PC SuiteSEPCSuite.exe [2008-02-20 360448]
«Skype»=C:Program FilesSkypePhoneSkype.exe [2008-09-23 21755688]
«WMPNSCFG»=C:Program FilesWindows Media PlayerWMPNSCFG.exe [2008-01-19 202240]C:ProgramDataMicrosoftWindowsStart MenuProgramsStartup
Bluetooth Manager.lnk — C:Program FilesToshibaBluetooth Toshiba StackTosBtMng.exe
Microsoft Office.lnk — C:Program FilesMicrosoft OfficeOffice10OSA.EXE[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyigfxcui]
C:Windowssystem32igfxdev.dll [2008-04-18 208896][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifypsfus]
C:Windowssystem32psqlpwd.dll [2007-03-28 90112][HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa]
«notification packages»=scecli
psqlpwd[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«NoHotStart»=1[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1
«NoHotStart»=1
«DisableCAD»=1
«EnableUIADesktopToggle»=0[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{8594c463-40ff-11dd-89bb-a039ef443683}]
shellAutoRuncommand — E:
shellopencommand — rundll32.exe .\dpmodqmx.dll,InstallM======List of files/folders created in the last 1 months======
2008-12-11 22:30:41 —-D—- C:rsit
2008-12-11 00:18:43 —-D—- C:Program FilesTrend Micro
2008-12-10 08:56:54 —-A—- C:Windowssystem32tzres.dll
2008-12-10 01:26:35 —-A—- C:ProgramDataCameraRecorder.ini
2008-12-10 01:12:42 —-D—- C:Program FilesCamera Recorder
2008-12-10 00:56:29 —-D—- C:WindowsSnapshot
2008-12-10 00:54:35 —-D—- C:WindowsBisonCam
2008-12-09 21:55:48 —-A—- C:Windowssystem32gdi32.dll
2008-12-09 21:55:43 —-A—- C:Windowssystem32GameUXLegacyGDFs.dll
2008-12-09 21:55:43 —-A—- C:Windowssystem32Apphlpdm.dll
2008-12-09 21:55:37 —-A—- C:Windowssystem32shell32.dll
2008-12-09 21:55:26 —-A—- C:Windowsexplorer.exe
2008-12-09 21:55:21 —-A—- C:Windowssystem32mshtml.dll
2008-12-09 21:55:20 —-A—- C:Windowssystem32urlmon.dll
2008-12-09 21:55:20 —-A—- C:Windowssystem32ieframe.dll
2008-12-09 21:55:19 —-A—- C:Windowssystem32wininet.dll
2008-12-09 21:55:19 —-A—- C:Windowssystem32mstime.dll
2008-12-09 21:55:19 —-A—- C:Windowssystem32iertutil.dll
2008-12-09 21:55:18 —-A—- C:Windowssystem32jsproxy.dll
2008-12-09 21:55:15 —-A—- C:Windowssystem32WMVCORE.DLL
2008-12-09 21:55:15 —-A—- C:Windowssystem32mf.dll
2008-12-09 21:55:14 —-A—- C:Windowssystem32WMNetMgr.dll
2008-12-09 21:55:14 —-A—- C:Windowssystem32logagent.exe
2008-12-06 18:41:04 —-D—- C:ProgramDataAvira
2008-12-06 18:41:04 —-D—- C:Program FilesAvira
2008-12-06 11:52:34 —-D—- C:Program FilesCCleaner
2008-11-29 17:23:20 —-A—- C:Windowssystem32wups2.dll
2008-11-29 17:23:20 —-A—- C:Windowssystem32wucltux.dll
2008-11-29 17:23:20 —-A—- C:Windowssystem32wuaueng.dll
2008-11-29 17:23:20 —-A—- C:Windowssystem32wuauclt.exe
2008-11-29 17:22:55 —-A—- C:Windowssystem32wups.dll
2008-11-29 17:22:55 —-A—- C:Windowssystem32wudriver.dll
2008-11-29 17:22:55 —-A—- C:Windowssystem32wuapi.dll
2008-11-29 17:22:36 —-A—- C:Windowssystem32wuwebv.dll
2008-11-29 17:22:36 —-A—- C:Windowssystem32wuapp.exe
2008-11-28 12:41:13 —-D—- C:UsersПАПАAppDataRoamingMozilla
2008-11-28 12:41:03 —-D—- C:Program FilesMozilla Firefox
2008-11-28 01:36:12 —-D—- C:Program FilesMicrosoft Office
2008-11-27 23:56:09 —-A—- C:Windowssystem32PortableDeviceApi.dll
2008-11-27 23:56:02 —-A—- C:Windowssystem32WindowsCodecsExt.dll
2008-11-27 23:56:02 —-A—- C:Windowssystem32WindowsCodecs.dll
2008-11-27 23:56:02 —-A—- C:Windowssystem32PhotoMetadataHandler.dll
2008-11-27 23:55:48 —-A—- C:Windowssystem32connect.dll
2008-11-23 19:05:15 —-D—- C:UsersПАПАAppDataRoamingGoogle
2008-11-23 18:28:14 —-D—- C:Program FilesGoogle
2008-11-23 18:28:13 —-D—- C:ProgramDataGoogle
2008-11-17 23:07:54 —-D—- C:Program FilesAdobe
2008-11-15 13:34:48 —-A—- C:Windowssystem32msxml3.dll
2008-11-15 13:34:45 —-A—- C:Windowssystem32msxml6.dll======List of files/folders modified in the last 1 months======
2008-12-11 22:30:43 —-D—- C:WindowsTemp
2008-12-11 22:24:58 —-D—- C:WindowsSystem32
2008-12-11 22:24:58 —-D—- C:Windowsinf
2008-12-11 22:24:58 —-A—- C:Windowssystem32PerfStringBackup.INI
2008-12-11 22:24:06 —-D—- C:UsersПАПАAppDataRoamingSkype
2008-12-11 22:22:44 —-D—- C:UsersПАПАAppDataRoamingskypePM
2008-12-11 22:01:29 —-D—- C:UsersПАПАAppDataRoamingMra
2008-12-11 00:18:43 —-RD—- C:Program Files
2008-12-10 23:47:50 —-HD—- C:Program FilesInstallShield Installation Information
2008-12-10 09:23:11 —-D—- C:Windowsrescache
2008-12-10 09:16:59 —-D—- C:Windowswinsxs
2008-12-10 09:06:51 —-D—- C:Windowssystem32catroot
2008-12-10 09:04:20 —-D—- C:Program FilesWindows Mail
2008-12-10 09:04:19 —-D—- C:Windowssystem32ru-RU
2008-12-10 09:04:19 —-D—- C:WindowsAppPatch
2008-12-10 09:04:19 —-D—- C:Windows
2008-12-10 08:57:22 —-D—- C:Windowssystem32catroot2
2008-12-10 08:54:20 —-SHD—- C:System Volume Information
2008-12-10 01:26:35 —-HD—- C:ProgramData
2008-12-10 01:23:45 —-A—- C:Windowswin.ini
2008-12-10 01:23:44 —-RSD—- C:WindowsMedia
2008-12-10 01:23:44 —-D—- C:Windowstwain_32
2008-12-10 01:23:44 —-D—- C:WindowsOptions
2008-12-10 01:23:34 —-D—- C:WindowsPrefetch
2008-12-10 01:12:44 —-SHD—- C:WindowsInstaller
2008-12-09 23:00:11 —-D—- C:Windowssystem32Tasks
2008-12-06 18:41:04 —-D—- C:Windowssystem32drivers
2008-12-06 11:31:45 —-D—- C:Program FilesWinamp Remote
2008-12-03 00:26:30 —-A—- C:Windowssystem32mrt.exe
2008-11-28 11:37:25 —-D—- C:Program FilesInternet Explorer
2008-11-27 23:50:53 —-D—- C:Windowssystem32Msdtc
2008-11-27 23:50:50 —-D—- C:Windowssystem32wbem
2008-11-27 23:49:59 —-D—- C:Windowssystem32config
2008-11-27 23:49:44 —-D—- C:WindowsTasks
2008-11-27 23:49:44 —-D—- C:Windowssystem32spool
2008-11-27 23:49:44 —-D—- C:Windowssystem32Macromed
2008-11-27 23:49:44 —-D—- C:Windowssystem32CodeIntegrity
2008-11-27 23:49:38 —-D—- C:Windowsregistration
2008-11-18 21:47:52 —-SD—- C:WindowsDownloaded Program Files
2008-11-17 23:08:11 —-D—- C:Program FilesCommon FilesAdobe
2008-11-17 23:08:04 —-D—- C:ProgramDataAdobe======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgio.sys [2007-02-27 11840]
R1 avipbb;avipbb; C:Windowssystem32DRIVERSavipbb.sys [2008-12-06 75072]
R1 ssmdrv;ssmdrv; C:Windowssystem32DRIVERSssmdrv.sys [2007-03-01 28352]
R1 Tosrfcom;Bluetooth RFCOMM; C:WindowsSystem32Driverstosrfcom.sys [2005-08-01 64896]
R3 AgereSoftModem;Agere Systems Soft Modem; C:Windowssystem32DRIVERSAGRSM.sys [2006-11-28 1161888]
R3 avgntflt;avgntflt; ??C:Program FilesAviraAntiVir PersonalEdition Classicavgntflt.sys [2008-05-20 52032]
R3 BlueletAudio;Bluetooth Audio Service; C:Windowssystem32DRIVERSblueletaudio.sys [2007-03-05 34576]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:Windowssystem32DRIVERSBlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:Windowssystem32DRIVERSbtnetdrv.sys [2007-03-05 18320]
R3 CmBatt;Драйвер батареи с ACPI-управлением (Microsoft); C:Windowssystem32DRIVERSCmBatt.sys [2008-01-19 14208]
R3 EMSCR;EMSCR; C:Windowssystem32DRIVERSEMS7SK.sys [2006-10-25 62208]
R3 ESDCR;ESDCR; C:Windowssystem32DRIVERSESD7SK.sys [2006-10-25 42240]
R3 ESMCR;ESMCR; C:Windowssystem32DRIVERSESM7SK.sys [2006-10-25 76928]
R3 igfx;igfx; C:Windowssystem32DRIVERSigdkmd32.sys [2008-04-18 2354176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:Windowssystem32driversRTKVHDA.sys [2007-04-10 1764960]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:Windowssystem32driversIntcHdmi.sys [2008-04-10 113152]
R3 MGHwCtrl;MGHwCtrl; ??C:Windowssystem32driversMGHwCtrl.sys [2006-12-22 19456]
R3 NETw4v32;Драйвер адаптера Intel(R) Wireless WiFi Link для Windows Vista 32 Bit; C:Windowssystem32DRIVERSNETw4v32.sys [2007-04-30 2219520]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:WindowsSystem32DriversRootMdm.sys [2008-01-19 8192]
R3 RTL8169;Realtek 8169 NT Driver; C:Windowssystem32DRIVERSRtlh86.sys [2007-06-07 83456]
R3 sdbus;sdbus; C:Windowssystem32DRIVERSsdbus.sys [2008-01-19 88576]
R3 TcUsb;TC USB Kernel Driver; C:WindowsSystem32Driverstcusb.sys [2007-03-28 46992]
R3 tosporte;Bluetooth COM Port; C:Windowssystem32DRIVERStosporte.sys [2006-10-10 41600]
R3 VComm;Virtual Serial port driver; C:Windowssystem32DRIVERSVComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:WindowsSystem32DriversVcommMgr.sys [2007-03-05 44304]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:WindowsSystem32Driversbtcusb.sys [2007-03-05 39184]
S3 drmkaud;Звуковой дешифратор DRM ядра системы; C:Windowssystem32driversdrmkaud.sys [2008-01-19 5632]
S3 DVC;USB DVC Svc; C:WindowsSystem32DriversDVC.sys [2001-09-10 38401]
S3 HdAudAddService;Драйвер функции UAA для службы High Definition Audio (Microsoft), версия 1.1; C:Windowssystem32driversHdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Представитель служб потоков Microsoft; C:Windowssystem32driversMSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Посредник синхронизации потоков Microsoft; C:Windowssystem32driversMSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Представитель диспетчера качества потоков Microsoft; C:Windowssystem32driversMSPQM.sys [2008-01-19 5504]
S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:Windowssystem32driversMSTEE.sys [2008-01-19 6016]
S3 NETw3v32;Драйвер адаптера беспроводной сети Intel(R) PRO/Wireless 3945ABG для 32-разрядной Windows Vista; C:Windowssystem32DRIVERSNETw3v32.sys [2006-11-02 1781760]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:Windowssystem32DRIVERSs116bus.sys [2007-04-03 83336]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:Windowssystem32DRIVERSs116mdfl.sys [2007-04-03 15112]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:Windowssystem32DRIVERSs116mdm.sys [2007-04-03 108680]
S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM); C:Windowssystem32DRIVERSs116mgmt.sys [2007-04-03 100488]
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:Windowssystem32DRIVERSs116nd5.sys [2007-04-03 23176]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:Windowssystem32DRIVERSs116obex.sys [2007-04-03 98696]
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:Windowssystem32DRIVERSs116unic.sys [2007-04-03 99080]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM); C:Windowssystem32DRIVERSSE31bus.sys [2006-05-01 61600]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter; C:Windowssystem32DRIVERSSE31mdfl.sys [2006-05-01 9360]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver; C:Windowssystem32DRIVERSSE31mdm.sys [2006-05-01 97184]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM); C:Windowssystem32DRIVERSSE31mgmt.sys [2006-05-01 88688]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS); C:Windowssystem32DRIVERSse31nd5.sys [2006-05-01 18704]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface; C:Windowssystem32DRIVERSSE31obex.sys [2006-05-01 86560]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM); C:Windowssystem32DRIVERSse31unic.sys [2006-05-01 90800]
S3 tosrfbd;Bluetooth RFBUS; C:Windowssystem32DRIVERStosrfbd.sys [2006-11-30 113792]
S3 tosrfbnp;Bluetooth RFBNEP; C:WindowsSystem32Driverstosrfbnp.sys [2006-11-20 36480]
S3 Tosrfhid;Bluetooth RFHID; C:Windowssystem32DRIVERSTosrfhid.sys [2006-10-05 73600]
S3 tosrfnds;Bluetooth Personal Area Network; C:Windowssystem32DRIVERStosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio; C:Windowssystem32driverstosrfsnd.sys [2006-11-02 53504]
S3 Tosrfusb;Bluetooth USB Controller; C:Windowssystem32DRIVERStosrfusb.sys [2006-10-27 40960]
S3 usbvideo;USB-видеоустройство (WDM); C:WindowsSystem32Driversusbvideo.sys [2008-01-19 134016]
S3 WUDFRd;WUDFRd; C:Windowssystem32DRIVERSWUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:Windowssystem32driverswmiacpi.sys [2006-11-02 11264]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:Windowssystem32agrsmsvc.exe [2006-10-05 9216]
R2 AntiVirScheduler;Avira AntiVir Personal — Free Antivirus Scheduler; C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe [2008-12-06 68865]
R2 AntiVirService;Avira AntiVir Personal — Free Antivirus Guard; C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe [2008-12-06 151297]
R2 NishService;SCM Driver Daemon; C:Program FilesSystem Control Manageredd.exe [2006-03-22 40960]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:Program FilesToshibaBluetooth Toshiba StackTosBtSrv.exe [2006-10-31 77824]
S3 aspnet_state;Служба состояний ASP.NET; C:WindowsMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe [2008-01-05 33800]
EOF
12 декабря, 2008 в 10:15 дп #20283Лог выглядит нормально.
…О! СЧАСТЬЕ НАМ, А ВАМ ОГРОМНОЕ СПАСИБО!
ПУСТЬ ГАДЫ КОРЧАТСЯ ВО ТЬМЕ!!!
НАД ВАМИ Ж СОЛНЦЕ И ГОЛУБОЕ НЕБО,
РЕСПЕКТ РЕБЯТА!, УДАЧИ В ЭТОЙ КУТЕРЬМЕ!!!…собственно, понятно, что гадость красная убит
Проблема решена ?
-
АвторСообщения
- Для ответа в этой теме необходимо авторизоваться.