Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › пмогите пожалуйста!!
- This topic has 0 ответов, 1 участник, and was last updated 13 years, 11 months назад by 6767.
-
АвторСообщения
-
17 декабря, 2010 в 8:56 дп #18889
типичная ситуация_ заблокирована страница в контакте, активация — 100р. просмотрела форум скачала программу, вот:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:41:01, on 17.12.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: NormalRunning processes:
C:Program Files (x86)ASUSSmartLogonsensorsrv.exe
C:Program Files (x86)ASUSNet4SwitchNet4Switch.exe
C:Program Files (x86)ASUSWireless Console 3wcourier.exe
C:Program Files (x86)ASUSASUS Live UpdateALU.exe
C:Program Files (x86)ASUSControlDeckControlDeckStartUp.exe
C:Program Files (x86)Microsoft OfficeOffice12ONENOTEM.EXE
C:Program Files (x86)ASUSTekASUSDVD 8PDVD8Serv.exe
C:Program Files (x86)ASUSATK HotkeyHControlUser.exe
C:Program Files (x86)ASUSATKOSD2ATKOSD2.exe
C:Program Files (x86)ASUSATK MediaDMedia.exe
C:Program Files (x86)BoingoBoingo Wi-FiBoingo Wi-Fi.exe
C:Program Files (x86)Hewlett-PackardHP Share-to-Webhpgs2wnd.exe
C:Program Files (x86)CyberlinkPowerDVDPDVDServ.exe
C:Program Files (x86)Mail.RuAgentmagent.exe
C:Program Files (x86)Mail.RuGuardGuardMailRu.exe
C:Program Files (x86)Hewlett-PackardHP Share-to-Webhpgs2wnf.exe
C:WindowsAsScrPro.exe
C:Program Files (x86)Windows Media Playerwmplayer.exe
C:Program Files (x86)MegaFon InternetMegaFon Internet.exe
C:Program Files (x86)ICQ7.2ICQ.exe
C:Program Files (x86)Internet Exploreriexplore.exe
C:Program Files (x86)Internet Exploreriexplore.exe
C:Program Files (x86)Windows LiveToolbarwltuser.exe
C:Program Files (x86)Mail.RuSputnikSputnikHelper.exe
C:Program Files (x86)Mail.RuSputnikSputnikFlashPlayer.exe
C:Program Files (x86)Internet Exploreriexplore.exe
C:Program Files (x86)Malwarebytes’ Anti-Malwarembam.exe
C:UsersAsusDownloadsHijackThis.exeR1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://asus.msn.com
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://google.icq.com/search/search_frame.php
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://google.icq.com
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.mail.ru/cnt/7227
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 — URLSearchHook: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program Files (x86)Mail.RuSputnikMailRuSputnik.dll
F2 — REG:system.ini: UserInit=userinit.exe,
O1 — Hosts: 194.28.113.41 google.ru
O1 — Hosts: 194.28.113.41 http://www.odnoklassniki.ru
O1 — Hosts: 194.28.113.41 odnoklassniki.ru
O1 — Hosts: 194.28.113.41 http://www.vkontakte.ru
O1 — Hosts: 194.28.113.41 vkontakte.ru
O1 — Hosts: 194.28.113.41 google.com
O1 — Hosts: 194.28.113.41 http://www.m.vkontakte.ru
O1 — Hosts: 194.28.113.41 m.vkontakte.ru
O1 — Hosts: 194.28.113.41 http://www.webmoney.ru
O1 — Hosts: 194.28.113.41 webmoney.ru
O1 — Hosts: 194.28.113.41 http://www.vkontakte.com
O1 — Hosts: 194.28.113.41 vkontakte.com
O1 — Hosts: 194.28.113.41 http://www.durov.ru
O1 — Hosts: 194.28.113.41 durov.ru
O1 — Hosts: 194.28.113.41 http://www.weblongney.ru
O1 — Hosts: 194.28.113.41 weblongney.ru
O1 — Hosts: 194.28.113.41 http://www.odnoklassniki.ua
O1 — Hosts: 194.28.113.41 odnoklassniki.ua
O1 — Hosts: 194.28.113.41 http://www.odnoklasniki.ru
O1 — Hosts: 194.28.113.41 odnoklasniki.ru
O1 — Hosts: 194.28.113.41 http://www.odnoklasniki.ua
O1 — Hosts: 194.28.113.41 odnoklasniki.ua
O1 — Hosts: 194.28.113.41 http://www.wap.odnoklassniki.ru
O1 — Hosts: 194.28.113.41 wap.odnoklassniki.ru
O1 — Hosts: 194.28.113.41 http://www.loveplanet.ru
O1 — Hosts: 194.28.113.41 loveplanet.ru
O1 — Hosts: 194.28.113.41 http://www.mamba.ru
O1 — Hosts: 194.28.113.41 mamba.ru
O1 — Hosts: 194.28.113.41 http://www.google.ua
O1 — Hosts: 194.28.113.41 google.ua
O1 — Hosts: 194.28.113.41 http://www.google.kz
O1 — Hosts: 194.28.113.41 google.kz
O1 — Hosts: 194.28.113.41 http://www.bing.com
O1 — Hosts: 194.28.113.41 bing.com
O1 — Hosts: 194.28.113.41 http://www.yandex.com
O1 — Hosts: 194.28.113.41 yandex.com
O1 — Hosts: 194.28.113.41 http://www.qiwi.ru
O1 — Hosts: 194.28.113.41 qiwi.ru
O1 — Hosts: 194.28.113.41 http://www.rambler.ru
O1 — Hosts: 194.28.113.41 rambler.ru
O1 — Hosts: 194.28.113.41 http://www.vk.com
O1 — Hosts: 194.28.113.41 vk.com
O1 — Hosts: 194.28.113.41 http://www.gmail.ru
O1 — Hosts: 194.28.113.41 gmail.ru
O1 — Hosts: 194.28.113.41 http://www.aport.ru
O1 — Hosts: 194.28.113.41 aport.ru
O1 — Hosts: 194.28.113.41 msn.com
O2 — BHO: AcroIEHelperStub — {18DF081C-E8AD-4283-A596-FA578C2EBDC3} — C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 — BHO: Search Helper — {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} — C:Program Files (x86)MicrosoftSearch Enhancement PackSearch HelperSearchHelper.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:Program Files (x86)Microsoft OfficeOffice12GrooveShellExtensions.dll
O2 — BHO: Спутник@Mail.Ru — {8984B388-A5BB-4DF7-B274-77B879E179DB} — C:Program Files (x86)Mail.RuSputnikMailRuSputnik.dll
O2 — BHO: Помощник по входу с помощью идентификатора Windows Live ID — {9030D464-4C02-4ABF-8ECC-5164760863C6} — C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 — BHO: AlterGeo Magic Scanner — {9BFBA68E-E21B-458E-AE12-FE85E903D2C1} — C:Program Files (x86)AlterGeoAlterGeo Magic Scanner2.8.8.615AlterGeo.BrowserPlugin.dll
O2 — BHO: Windows Live Toolbar Helper — {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} — C:Program Files (x86)Windows LiveToolbarwltcore.dll
O3 — Toolbar: &Windows Live Toolbar — {21FA44EF-376D-4D53-9B0F-8A89D3229068} — C:Program Files (x86)Windows LiveToolbarwltcore.dll
O3 — Toolbar: ICQToolBar — {855F3B16-6D32-4fe6-8A56-BBB695989046} — C:Program Files (x86)ICQ6Toolbar1008181227ICQToolBar.dll
O3 — Toolbar: Спутник@Mail.Ru — {09900DE8-1DCA-443F-9243-26FF581438AF} — C:Program Files (x86)Mail.RuSputnikMailRuSputnik.dll
O4 — HKLM..Run: [RemoteControl8] «C:Program Files (x86)ASUSTekASUSDVD 8PDVD8Serv.exe»
O4 — HKLM..Run: [PDVD8LanguageShortcut] «C:Program Files (x86)ASUSTekASUSDVD 8LanguageLanguage.exe»
O4 — HKLM..Run: [UpdateLBPShortCut] «C:Program Files (x86)CyberLinkLabelPrintMUITransferMUIStartMenu.exe» «C:Program Files (x86)CyberLinkLabelPrint» UpdateWithCreateOnce «SoftwareCyberLinkLabelPrint2.5»
O4 — HKLM..Run: [StartCCC] «C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe» MSRun
O4 — HKLM..Run: [HDAudDeck] C:Program Files (x86)VIAVIAudioiVDeckVDeck.exe -r
O4 — HKLM..Run: [HControlUser] C:Program Files (x86)ASUSATK HotkeyHControlUser.exe
O4 — HKLM..Run: [ATKOSD2] C:Program Files (x86)ASUSATKOSD2ATKOSD2.exe
O4 — HKLM..Run: [ATKMEDIA] C:Program Files (x86)ASUSATK MediaDMedia.exe
O4 — HKLM..Run: [Setwallpaper] c:programdataSetWallpaper.cmd
O4 — HKLM..Run: [Boingo Wi-Fi] «C:Program Files (x86)BoingoBoingo Wi-FiBoingo.lnk»
O4 — HKLM..Run: [zzzHPSETUP] E:Setup.exe
O4 — HKLM..Run: [Share-to-Web Namespace Daemon] C:Program Files (x86)Hewlett-PackardHP Share-to-Webhpgs2wnd.exe
O4 — HKLM..Run: [RemoteControl] «C:Program Files (x86)CyberLinkPowerDVDPDVDServ.exe»
O4 — HKLM..Run: [LanguageShortcut] «C:Program Files (x86)CyberLinkPowerDVDLanguageLanguage.exe»
O4 — HKLM..Run: [UpdatePPShortCut] «C:Program Files (x86)CyberLinkPowerProducerMUITransferMUIStartMenu.exe» «C:Program Files (x86)CyberLinkPowerProducer» update «SoftwareCyberLinkPowerProducer4.0»
O4 — HKLM..Run: [GrooveMonitor] «C:Program Files (x86)Microsoft OfficeOffice12GrooveMonitor.exe»
O4 — HKLM..Run: [actx.exe] «C:Program Files (x86)MegaFonMultiFonactx.exe» /autostart
O4 — HKLM..Run: [Adobe ARM] «C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe»
O4 — HKLM..Run: [Adobe Reader Speed Launcher] «C:Program Files (x86)AdobeReader 9.0ReaderReader_sl.exe»
O4 — HKLM..Run: [MAgent] C:Program Files (x86)Mail.RuAgentMAgent.exe -LM
O4 — HKLM..Run: [Guard.Mail.ru.gui] «C:Program Files (x86)Mail.RuGuardGuardMailRu.exe» /gui
O4 — HKCU..Run: [msnmsgr] «C:Program Files (x86)Windows LiveMessengermsnmsgr.exe» /background
O4 — HKCU..RunOnce: [FlashPlayerUpdate] C:WindowsSysWOW64MacromedFlashFlashUtil10k_ActiveX.exe -update activex
O4 — HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User ‘NETWORK SERVICE’)
O4 — Startup: Вырезка экрана и программа запуска для OneNote 2007.lnk = C:Program Files (x86)Microsoft OfficeOffice12ONENOTEM.EXE
O4 — Global Startup: FancyStart daemon.lnk = ?
O4 — Global Startup: SRS Premium Sound.lnk = ?
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~2MICROS~1Office12EXCEL.EXE/3000
O9 — Extra button: Отправка в блог — {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} — C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll
O9 — Extra ‘Tools’ menuitem: &Отправка в блог Windows Live Writer — {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} — C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~2MICROS~1Office12ONBttnIE.dll
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~2MICROS~1Office12ONBttnIE.dll
O9 — Extra button: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program Files (x86)Mail.RuAgentmagent.exe
O9 — Extra ‘Tools’ menuitem: Mail.Ru Агент — {7558B7E5-7B26-4201-BEDB-00D5FF534523} — C:Program Files (x86)Mail.RuAgentmagent.exe
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~2MICROS~1Office12REFIEBAR.DLL
O9 — Extra button: ICQ Lite — {E59EB121-F339-4851-A3BA-FE49C35617C2} — ICQ.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ Lite — {E59EB121-F339-4851-A3BA-FE49C35617C2} — ICQ.exe (file missing)
O10 — Unknown file in Winsock LSP: c:program files (x86)common filesmicrosoft sharedwindows livewlidnsp.dll
O10 — Unknown file in Winsock LSP: c:program files (x86)common filesmicrosoft sharedwindows livewlidnsp.dll
O16 — DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) — http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 — HKLMSystemCCSServicesTcpip..{D4AA7BAA-F6AA-4191-8907-BA14D5F38D7E}: NameServer = 10.52.129.36 10.52.129.37
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:Program Files (x86)Microsoft OfficeOffice12GrooveSystemServices.dll
O23 — Service: AFBAgent — Unknown owner — C:Windowssystem32FBAgent.exe (file missing)
O23 — Service: @%SystemRoot%system32Alg.exe,-112 (ALG) — Unknown owner — C:WindowsSystem32alg.exe (file missing)
O23 — Service: AMD External Events Utility — Unknown owner — C:Windowssystem32atiesrxx.exe (file missing)
O23 — Service: ASLDR Service (ASLDRService) — ASUS — C:Program Files (x86)ASUSATK HotkeyASLDRSrv.exe
O23 — Service: ATKGFNEX Service (ATKGFNEXSrv) — Unknown owner — C:Program FilesATKGFNEXGFNEXSrv.exe
O23 — Service: @%SystemRoot%system32efssvc.dll,-100 (EFS) — Unknown owner — C:WindowsSystem32lsass.exe (file missing)
O23 — Service: @%systemroot%system32fxsresm.dll,-118 (Fax) — Unknown owner — C:Windowssystem32fxssvc.exe (file missing)
O23 — Service: Guard.Mail.ru — Unknown owner — C:Program Files (x86)Mail.RuGuardGuardMailRu.exe
O23 — Service: ICQ Service — Unknown owner — C:Program Files (x86)ICQ6ToolbarICQ Service.exe
O23 — Service: PIXMA Extended Survey Program (IJPLMSVC) — Unknown owner — C:Program Files (x86)CanonIJPLMIJPLMSVC.EXE
O23 — Service: @keyiso.dll,-100 (KeyIso) — Unknown owner — C:Windowssystem32lsass.exe (file missing)
O23 — Service: @comres.dll,-2797 (MSDTC) — Unknown owner — C:WindowsSystem32msdtc.exe (file missing)
O23 — Service: @%SystemRoot%System32netlogon.dll,-102 (Netlogon) — Unknown owner — C:Windowssystem32lsass.exe (file missing)
O23 — Service: Oberon Media Game Console service (OberonGameConsoleService) — Unknown owner — C:Program Files (x86)AsusGame ParkGameConsoleOberonGameConsoleService.exe
O23 — Service: @%systemroot%system32psbase.dll,-300 (ProtectedStorage) — Unknown owner — C:Windowssystem32lsass.exe (file missing)
O23 — Service: Cyberlink RichVideo Service(CRVS) (RichVideo) — Unknown owner — C:Program Files (x86)CyberlinkShared filesRichVideo.exe
O23 — Service: @%systemroot%system32Locator.exe,-2 (RpcLocator) — Unknown owner — C:Windowssystem32locator.exe (file missing)
O23 — Service: @%SystemRoot%system32samsrv.dll,-1 (SamSs) — Unknown owner — C:Windowssystem32lsass.exe (file missing)
O23 — Service: @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) — Unknown owner — C:WindowsSystem32snmptrap.exe (file missing)
O23 — Service: spmgr — Unknown owner — C:Program FilesASUSNB ProbeSPMspmgr.exe
O23 — Service: @%systemroot%system32spoolsv.exe,-1 (Spooler) — Unknown owner — C:WindowsSystem32spoolsv.exe (file missing)
O23 — Service: @%SystemRoot%system32sppsvc.exe,-101 (sppsvc) — Unknown owner — C:Windowssystem32sppsvc.exe (file missing)
O23 — Service: @%SystemRoot%system32ui0detect.exe,-101 (UI0Detect) — Unknown owner — C:Windowssystem32UI0Detect.exe (file missing)
O23 — Service: @%SystemRoot%system32vaultsvc.dll,-1003 (VaultSvc) — Unknown owner — C:Windowssystem32lsass.exe (file missing)
O23 — Service: @%SystemRoot%system32vds.exe,-100 (vds) — Unknown owner — C:WindowsSystem32vds.exe (file missing)
O23 — Service: @%systemroot%system32vssvc.exe,-102 (VSS) — Unknown owner — C:Windowssystem32vssvc.exe (file missing)
O23 — Service: @%systemroot%system32wbengine.exe,-104 (wbengine) — Unknown owner — C:Windowssystem32wbengine.exe (file missing)
O23 — Service: @%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) — Unknown owner — C:Windowssystem32wbemWmiApSrv.exe (file missing)
O23 — Service: @%PROGRAMFILES%Windows Media Playerwmpnetwk.exe,-101 (WMPNetworkSvc) — Unknown owner — C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)—
End of file — 15121 bytes -
АвторСообщения
- Тема ‘пмогите пожалуйста!!’ закрыта для новых сообщений.