Созданные ответы форума
-
АвторСообщения
-
Logfile of random’s system information tool 1.07 (written by random/random)
Run by Admin at 2010-05-24 00:12:44
Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (8%) free of 76 GB
Total RAM: 511 MB (25% free)Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:13:38, on 24.05.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: NormalRunning processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe
C:WINDOWSExplorer.exe
C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAVerMediaServiceAVerRemote.exe
C:Program FilesCommon FilesAVerMediaServiceAVerScheduleService.exe
C:Program FilesICQ6ToolbarICQ Service.exe
C:Program FilesSymantecSymantec Endpoint ProtectionRtvscan.exe
C:Program FilesCommon FilesAVerMediaAVerQuickAVerHIDReceiver.exe
C:WINDOWSSOUNDMAN.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesWinampwinampa.exe
C:Program FilesCyberLinkPowerDVDPDVDServ.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesVistaDriveIconVistaDrv.exe
C:Program FilesCommon FilesAVerMediaAVerQuickAVerQuick.exe
C:Program FilesSymantecSymantec Endpoint ProtectionSmcGui.exe
C:Program FilesSharemanShareman.exe
D:Opera_10.01.1844_Final_ML_PortableAppOperaopera.exe
C:Documents and SettingsAdminLocal SettingsApplication DataOperaOperatemporary_downloadsRSIT.exe
C:Program Filestrend microAdmin.exeR1 — HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://yandex.ru/yandsearch?clid=123046&text=%s
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.yandex.ru/?clid=123048
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://yandex.ru/yandsearch?clid=123044
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/?clid=123048
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ссылки
R3 — URLSearchHook: (no name) — — (no file)
R3 — URLSearchHook: ICQToolBar — {855F3B16-6D32-4fe6-8A56-BBB695989046} — C:Program FilesICQ6ToolbarICQToolBar.dll
F2 — REG:system.ini: Shell=Explorer.exe C:DOCUME~1AdminLOCALS~1Tempstart.bat
O1 — Hosts: 188.40.163.73 http://www.vkontakte.ru
O1 — Hosts: 188.40.163.73 vkontakte.ru
O1 — Hosts: 188.40.163.73 http://www.vk.com
O1 — Hosts: 188.40.163.73 vk.com
O1 — Hosts: 188.40.163.73 http://www.kaspersky.ru
O1 — Hosts: 188.40.163.73 kaspersky.ru
O1 — Hosts: 188.40.163.73 http://www.viruslist.ru
O1 — Hosts: 188.40.163.73 viruslist.ru
O1 — Hosts: 188.40.163.73 http://www.odnoklassniki.ru
O1 — Hosts: 188.40.163.73 odnoklassniki.ru
O1 — Hosts: 188.40.163.73 http://www.odnoklasniki.ru
O1 — Hosts: 188.40.163.73 odnoklasniki.ru
O1 — Hosts: 188.40.163.73 google.com
O1 — Hosts: 188.40.163.73 google.ru
O1 — Hosts: 188.40.163.73 mail.ru
O1 — Hosts: 188.40.163.73 yandex.ru
O1 — Hosts: 188.40.163.73 ya.ru
O1 — Hosts: 188.40.163.73 rambler.ru
O1 — Hosts: 188.40.163.73 http://www.google.com
O1 — Hosts: 188.40.163.73 http://www.google.ru
O1 — Hosts: 188.40.163.73 http://www.mail.ru
O1 — Hosts: 188.40.163.73 http://www.yandex.ru
O1 — Hosts: 188.40.163.73 http://www.ya.ru
O1 — Hosts: 188.40.163.73 http://www.rambler.ru
O1 — Hosts: 188.40.163.73 dom2.ru
O1 — Hosts: 188.40.163.73 http://www.dom2.ru
O1 — Hosts: 188.40.163.73 http://www.avto.ru
O1 — Hosts: 188.40.163.73 avto.ru
O1 — Hosts: 188.40.163.73 durov.ru
O1 — Hosts: 188.40.163.73 http://www.durov.ru
O1 — Hosts: 188.40.163.73 http://www.virustotal.ru
O1 — Hosts: 188.40.163.73 virustotal.ru
O1 — Hosts: 188.40.163.73 sms001.ru
O1 — Hosts: 188.40.163.73 http://www.sms001.ru
O1 — Hosts: 188.40.163.73 steptocash.ru
O1 — Hosts: 188.40.163.73 http://www.steptocash.ru
O2 — BHO: Update Timer — {963B125B-8B21-49A2-A3A8-E37092276531} — C:Program FilesGet-Styles 2.0utilsupdatebho.dll
O2 — BHO: script helper for ie — {9B5FB65F-631E-4564-ABF2-AD71845B28E0} — C:Program FilesGet-Styles 2.0iejsloader.dll
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: JQSIEStartDetectorImpl — {E7E6F031-17CE-4C07-BC86-EABFE594F69C} — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O3 — Toolbar: ICQToolBar — {855F3B16-6D32-4fe6-8A56-BBB695989046} — C:Program FilesICQ6ToolbarICQToolBar.dll
O3 — Toolbar: Get-Styles toolbar v3 — {5BCDC9E9-A980-4B53-B2E8-60CFF484DA61} — C:Program FilesGet-Styles 2.0ietoolbar.dll
O4 — HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 — HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 — HKLM..Run: [ccApp] «C:Program FilesCommon FilesSymantec SharedccApp.exe»
O4 — HKLM..Run: [WinampAgent] «C:Program FilesWinampwinampa.exe»
O4 — HKLM..Run: [RemoteControl] «C:Program FilesCyberLinkPowerDVDPDVDServ.exe»
O4 — HKLM..Run: [LanguageShortcut] «C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe»
O4 — HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 — HKCU..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe
O4 — HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [VistaIcon] C:Program FilesVistaDriveIconVistaDrv.exe (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,OnceFirstLogonInstall,0 (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-20..RunOnce: [ZZZZ1_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,OnceFirstLogonInstall,0 (User ‘NETWORK SERVICE’)
O4 — HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘SYSTEM’)
O4 — HKUSS-1-5-18..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘SYSTEM’)
O4 — HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ‘Default user’)
O4 — HKUS.DEFAULT..RunOnce: [ZZZZ2_FirstLogonSetting] %SystemRoot%System32rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFcustom.inf,NewUserFirstLogonInstall,0 (User ‘Default user’)
O4 — Global Startup: AVer HID Receiver.lnk = C:Program FilesCommon FilesAVerMediaAVerQuickAVerHIDReceiver.exe
O4 — Global Startup: AVerQuick.lnk = C:Program FilesCommon FilesAVerMediaAVerQuickAVerQuick.exe
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~1OFFICE11EXCEL.EXE/3000
O9 — Extra button: Справочные материалы — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~1OFFICE11REFIEBAR.DLL
O9 — Extra button: (no name) — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 — {e2e2dd38-d088-4134-82b7-f2ba38496583} — C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 — Extra button: ICQ Lite — {E59EB121-F339-4851-A3BA-FE49C35617C2} — ICQ.exe (file missing)
O9 — Extra ‘Tools’ menuitem: ICQ Lite — {E59EB121-F339-4851-A3BA-FE49C35617C2} — ICQ.exe (file missing)
O17 — HKLMSystemCCSServicesTcpip..{48285233-E313-49A3-9B05-D28E32BA5728}: NameServer = 212.120.160.130 212.120.173.34
O18 — Protocol: base64 — {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} — C:Program FilesGet-Styles 2.0ietdataprotocol.dll
O18 — Protocol: chrome — {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} — C:Program FilesGet-Styles 2.0ietdataprotocol.dll
O18 — Protocol: prox — {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} — C:Program FilesGet-Styles 2.0ietdataprotocol.dll
O22 — SharedTaskScheduler: Предзагрузчик Browseui — {438755C2-A8BA-11D1-B96B-00A0C90312E1} — C:WINDOWSsystem32browseui.dll
O22 — SharedTaskScheduler: Демон кэша категорий компонентов — {8C7461EF-2B13-11d2-BE35-3078302C2030} — C:WINDOWSsystem32browseui.dll
O23 — Service: Ati HotKey Poller — ATI Technologies Inc. — C:WINDOWSsystem32Ati2evxx.exe
O23 — Service: AVerRemote — AVerMedia — C:Program FilesCommon FilesAVerMediaServiceAVerRemote.exe
O23 — Service: AVerScheduleService — Unknown owner — C:Program FilesCommon FilesAVerMediaServiceAVerScheduleService.exe
O23 — Service: Symantec Event Manager (ccEvtMgr) — Symantec Corporation — C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
O23 — Service: Symantec Settings Manager (ccSetMgr) — Symantec Corporation — C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
O23 — Service: Журнал событий (Eventlog) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: ICQ Service — Unknown owner — C:Program FilesICQ6ToolbarICQ Service.exe
O23 — Service: Служба COM записи компакт-дисков IMAPI (ImapiService) — Корпорация Майкрософт — C:WINDOWSsystem32imapi.exe
O23 — Service: LiveUpdate — Symantec Corporation — C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 — Service: Plug and Play (PlugPlay) — Корпорация Майкрософт — C:WINDOWSsystem32services.exe
O23 — Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) — Корпорация Майкрософт — C:WINDOWSsystem32sessmgr.exe
O23 — Service: Смарт-карты (SCardSvr) — Корпорация Майкрософт — C:WINDOWSSystem32SCardSvr.exe
O23 — Service: Symantec Management Client (SmcService) — Symantec Corporation — C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe
O23 — Service: Symantec Endpoint Protection (Symantec AntiVirus) — Symantec Corporation — C:Program FilesSymantecSymantec Endpoint ProtectionRtvscan.exe
O23 — Service: Журналы и оповещения производительности (SysmonLog) — Корпорация Майкрософт — C:WINDOWSsystem32smlogsvc.exe
O23 — Service: Теневое копирование тома (VSS) — Корпорация Майкрософт — C:WINDOWSSystem32vssvc.exe
O23 — Service: Адаптер производительности WMI (WmiApSrv) — Корпорация Майкрософт — C:WINDOWSsystem32wbemwmiapsrv.exe—
End of file — 10547 bytes======Scheduled tasks folder======
C:WINDOWStasksUser_Feed_Synchronization-{CE0E8A15-3CCC-4E80-9F17-F6F7B858C233}.job
======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{963B125B-8B21-49A2-A3A8-E37092276531}]
TimerBHO Class — C:Program FilesGet-Styles 2.0utilsupdatebho.dll [2009-12-01 125952][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{9B5FB65F-631E-4564-ABF2-AD71845B28E0}]
WitBHO Class — C:Program FilesGet-Styles 2.0iejsloader.dll [2009-12-16 226016][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2010-01-10 41760][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class — C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll [2010-01-10 73728][HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} — ICQToolBar — C:Program FilesICQ6ToolbarICQToolBar.dll [2008-06-12 958712]
{5BCDC9E9-A980-4B53-B2E8-60CFF484DA61} — Get-Styles toolbar v3 — C:Program FilesGet-Styles 2.0ietoolbar.dll [2009-12-16 128736][HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«NeroFilterCheck»=C:WINDOWSsystem32NeroCheck.exe [2006-01-12 155648]
«SoundMan»=C:WINDOWSSOUNDMAN.EXE [2007-04-16 577536]
«ccApp»=C:Program FilesCommon FilesSymantec SharedccApp.exe [2009-07-08 115560]
«WinampAgent»=C:Program FilesWinampwinampa.exe [2009-07-01 37888]
«RemoteControl»=C:Program FilesCyberLinkPowerDVDPDVDServ.exe [2005-12-08 30208]
«LanguageShortcut»=C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe [2006-04-13 49152][HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«CTFMON.EXE»=C:WINDOWSsystem32ctfmon.exe [2009-12-12 30208]
«VistaIcon»=C:Program FilesVistaDriveIconVistaDrv.exe [2008-01-02 132096]C:Documents and SettingsAll UsersГлавное менюПрограммыАвтозагрузка
AVer HID Receiver.lnk — C:Program FilesCommon FilesAVerMediaAVerQuickAVerHIDReceiver.exe
AVerQuick.lnk — C:Program FilesCommon FilesAVerMediaAVerQuickAVerQuick.exe[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyAtiExtEvent]
C:WINDOWSsystem32Ati2evxx.dll [2009-02-26 155648][HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyWgaLogon]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
WPDShServiceObj — {AAA288BA-9A4C-45B0-95D7-94D524869DB5} — C:WINDOWSsystem32wpdshserviceobj.dll [2008-05-18 133632][HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalccEvtMgr]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalccSetMgr]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalSymantec Antivirus]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalSymantec Antvirus]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkccEvtMgr]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkccSetMgr]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkSmcService]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkSymantec Antivirus]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootnetworkSymantec Antvirus]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1
«DisableStatusMessages»=0
«DisableTaskMgr»=0[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveTypeAutoRun»=149
«NoSharedDocuments»=1
«NoSMConfigurePrograms»=1
«NoDriveAutoRun»=0[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«HonorAutoRunSetting»=[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
«%windir%Network Diagnosticxpnetdiag.exe»=»%windir%Network Diagnosticxpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000»
«%windir%system32sessmgr.exe»=»%windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019»[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{149a5dfa-fdfe-11de-93d4-806d6172696f}]
shellAutoRuncommand — F:autorun.exe /R======List of files/folders created in the last 1 months======
2010-05-24 00:04:04 —-D—- C:Program Filestrend micro
2010-05-24 00:03:57 —-D—- C:rsit
2010-05-23 12:13:36 —-D—- C:Program FilesНовый Диск
2010-05-17 06:50:11 —-SHD—- C:found.000
2010-05-16 18:05:19 —-D—- C:WINDOWSWBEM
2010-05-16 18:04:39 —-N—- C:WINDOWSsystem32spmsg.dll
2010-05-16 18:04:31 —-A—- C:WINDOWSsystem32spupdsvc.exe
2010-04-30 22:30:18 —-A—- C:WINDOWSsystem32xmltok.dll
2010-04-30 22:30:18 —-A—- C:WINDOWSsystem32xmlparse.dll
2010-04-30 22:30:18 —-A—- C:WINDOWSsystem32xmlinst.exe
2010-04-30 22:30:18 —-A—- C:WINDOWSsystem32vp6vfw.dll
2010-04-30 22:30:18 —-A—- C:WINDOWSsystem32vp6install.exe
2010-04-30 22:30:16 —-A—- C:WINDOWSsystem32vcomp.dll
2010-04-30 22:30:09 —-A—- C:WINDOWSsystem32Vb5db.dll
2010-04-30 22:30:08 —-A—- C:WINDOWSsystem32OpenALwEAX.exe
2010-04-30 22:30:07 —-A—- C:WINDOWSsystem32msxml4a.dll
2010-04-30 22:30:05 —-A—- C:WINDOWSsystem32msvcr71d.dll
2010-04-30 22:30:04 —-A—- C:WINDOWSsystem32msvcr70d.dll
2010-04-30 22:30:02 —-A—- C:WINDOWSsystem32msvcp71d.dll
2010-04-30 22:30:02 —-A—- C:WINDOWSsystem32msvcp70d.dll
2010-04-30 22:30:01 —-A—- C:WINDOWSsystem32Msvcp60d.dll
2010-04-30 22:30:00 —-A—- C:WINDOWSsystem32msvci70d.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfcm80u.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfcm80.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80u.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80KOR.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80JPN.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80ITA.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80FRA.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80ESP.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80ENU.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80DEU.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80CHT.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80CHS.dll
2010-04-30 22:29:57 —-A—- C:WINDOWSsystem32mfc80.dll
2010-04-30 22:29:54 —-A—- C:WINDOWSsystem32eax.dll
2010-04-30 22:29:45 —-A—- C:WINDOWSsystem32Cc3250mt.dll
2010-04-30 22:29:44 —-A—- C:WINDOWSsystem32Borlndmm.dll
2010-04-30 22:29:44 —-A—- C:WINDOWSsystem32ATL80.dll======List of files/folders modified in the last 1 months======
2010-05-24 00:04:04 —-RD—- C:Program Files
2010-05-23 22:01:37 —-D—- C:WINDOWSTemp
2010-05-23 18:18:16 —-A—- C:WINDOWSSchedLgU.Txt
2010-05-23 12:14:04 —-HD—- C:Program FilesInstallShield Installation Information
2010-05-23 12:13:06 —-D—- C:Program FilesCommon FilesInstallShield
2010-05-23 11:42:23 —-D—- C:Program FilesShareman
2010-05-23 07:43:24 —-D—- C:WINDOWSsystem32CatRoot2
2010-05-22 15:00:05 —-D—- C:Documents and SettingsAdminApplication DataICQ
2010-05-21 00:32:11 —-D—- C:WINDOWSsystem32config
2010-05-21 00:31:59 —-D—- C:WINDOWSsystem32wbem
2010-05-21 00:31:57 —-D—- C:WINDOWSRegistration
2010-05-19 22:52:54 —-SHD—- C:WINDOWSInstaller
2010-05-17 22:36:00 —-RSHDC—- C:WINDOWSsystem32dllcache
2010-05-17 22:36:00 —-D—- C:WINDOWSsystem32ru-ru
2010-05-17 22:36:00 —-D—- C:WINDOWS
2010-05-17 22:35:59 —-AD—- C:WINDOWSsystem32
2010-05-17 22:35:58 —-HD—- C:WINDOWSinf
2010-05-17 22:35:58 —-D—- C:WINDOWSHelp
2010-05-17 22:35:58 —-D—- C:Program FilesInternet Explorer
2010-05-17 07:01:59 —-D—- C:WINDOWSsystem32CatRoot
2010-05-17 06:57:12 —-SD—- C:WINDOWSTasks
2010-05-16 18:05:45 —-A—- C:WINDOWSimsins.BAK
2010-05-16 18:05:02 —-D—- C:WINDOWSMedia
2010-05-14 21:55:18 —-D—- C:Program FilesOpera AC 3.7
2010-05-10 00:52:28 —-A—- C:WINDOWSNeroDigital.ini
2010-05-06 21:51:29 —-D—- C:Documents and SettingsAdminApplication DatauTorrent
2010-05-05 16:47:42 —-SD—- C:Documents and SettingsAdminApplication DataMicrosoft
2010-05-04 22:54:08 —-D—- C:Program FilesKMPlayer
2010-04-27 00:14:53 —-D—- C:Documents and SettingsAll UsersApplication DataAVerTV======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 eeCtrl;Symantec Eraser Control driver; ??C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys []
R1 intelppm;Драйвер Intel процессора; C:WINDOWSsystem32DRIVERSintelppm.sys [2008-04-15 40704]
R1 SPBBCDrv;SPBBCDrv; ??C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCDrv.sys []
R1 SRTSP;SRTSP; C:WINDOWSSystem32DriversSRTSP.SYS [2009-08-25 281648]
R1 SRTSPX;SRTSPX; C:WINDOWSSystem32DriversSRTSPX.SYS [2009-08-25 43696]
R1 SYMTDI;SYMTDI; C:WINDOWSSystem32DriversSYMTDI.SYS [2009-09-03 188080]
R1 WPS;WPS; ??C:WINDOWSsystem32driverswpsdrvnt.sys []
R2 exFat;exFat; C:WINDOWSsystem32driversexFat.sys [2009-01-28 133632]
R2 rspndr;Ответчик обнаружения топологии уровня связи; C:WINDOWSsystem32DRIVERSrspndr.sys [2008-10-11 62848]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:WINDOWSsystem32driversALCXWDM.SYS [2008-09-24 4122368]
R3 ati2mtag;ati2mtag; C:WINDOWSsystem32DRIVERSati2mtag.sys [2009-02-26 3565568]
R3 AVerA706;AVerMedia A706 BDA Service; C:WINDOWSsystem32DRIVERSAVerA706.sys [2009-06-10 1169920]
R3 DLKRTS;D-Link DFE-538TX 10/100 Adapter; C:WINDOWSsystem32DRIVERSDLKRTS.SYS [2002-06-24 45568]
R3 E100B;Intel(R) PRO Network Connection Driver; C:WINDOWSsystem32DRIVERSe100b325.sys [2007-11-16 165496]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; ??C:Program FilesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys []
R3 NAVENG;NAVENG; ??C:PROGRA~1COMMON~1SYMANT~1VIRUSD~120100523.004NAVENG.SYS []
R3 NAVEX15;NAVEX15; ??C:PROGRA~1COMMON~1SYMANT~1VIRUSD~120100523.004NAVEX15.SYS []
R3 SymEvent;SymEvent; ??C:WINDOWSsystem32DriversSYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:WINDOWSSystem32DriversSYMREDRV.SYS [2009-09-03 26416]
R3 Teefer2;Teefer2 Miniport; C:WINDOWSsystem32DRIVERSteefer2.sys [2009-05-27 50064]
R3 usbehci;Драйвер минипорта Microsoft USB 2.0 расширенного хост-контроллера; C:WINDOWSsystem32DRIVERSusbehci.sys [2008-04-15 30208]
R3 usbhub;USB2 концентратор; C:WINDOWSsystem32DRIVERSusbhub.sys [2008-04-14 59520]
R3 usbprint;Класс принтеров Microsoft USB; C:WINDOWSsystem32DRIVERSusbprint.sys [2008-04-14 25856]
R3 USBSTOR;Драйвер запоминающих устройств для USB; C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Драйвер минипорта Microsoft USB универсального хост-контроллера; C:WINDOWSsystem32DRIVERSusbuhci.sys [2008-04-14 20608]
R3 WpsHelper;WpsHelper; ??C:WINDOWSsystem32driversWpsHelper.sys []
S3 3xHybrid;3xHybrid service; C:WINDOWSsystem32DRIVERS3xHybrid.sys [2007-10-17 945920]
S3 CCDECODE;Closed Caption декодер; C:WINDOWSsystem32DRIVERSCCDECODE.sys [2008-04-14 17024]
S3 COH_Mon;COH_Mon; ??C:WINDOWSsystem32DriversCOH_Mon.sys []
S3 MPE;BDA MPE фильтр; C:WINDOWSsystem32DRIVERSMPE.sys [2008-04-14 15232]
S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:WINDOWSsystem32driversMSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI кодек; C:WINDOWSsystem32DRIVERSNABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft видео или ТВ подключение; C:WINDOWSsystem32DRIVERSNdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:WINDOWSsystem32DRIVERSSLIP.sys [2008-04-14 11136]
S3 SRTSPL;SRTSPL; C:WINDOWSSystem32DriversSRTSPL.SYS [2009-08-25 320560]
S3 streamip;BDA IPSink; C:WINDOWSsystem32DRIVERSStreamIP.sys [2008-04-14 15232]
S3 WSTCODEC;World Standard Teletext кодек; C:WINDOWSsystem32DRIVERSWSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation — User-mode Driver Framework Platform Driver; C:WINDOWSsystem32DRIVERSWudfPf.sys [2008-05-18 77568]
S3 WudfRd;Windows Driver Foundation — User-mode Driver Framework Reflector; C:WINDOWSsystem32DRIVERSwudfrd.sys [2008-05-18 82944]
S4 SysPlant;SysPlant for NT; C:WINDOWSSYSTEM32DriversSysPlant.sys [2009-09-17 92488]======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:WINDOWSsystem32Ati2evxx.exe [2009-02-26 602112]
R2 AVerRemote;AVerRemote; C:Program FilesCommon FilesAVerMediaServiceAVerRemote.exe [2009-04-08 344064]
R2 AVerScheduleService;AVerScheduleService; C:Program FilesCommon FilesAVerMediaServiceAVerScheduleService.exe [2008-12-10 405504]
R2 ccEvtMgr;Symantec Event Manager; C:Program FilesCommon FilesSymantec SharedccSvcHst.exe [2009-07-08 108392]
R2 ccSetMgr;Symantec Settings Manager; C:Program FilesCommon FilesSymantec SharedccSvcHst.exe [2009-07-08 108392]
R2 ICQ Service;ICQ Service; C:Program FilesICQ6ToolbarICQ Service.exe [2008-06-10 222456]
R2 SmcService;Symantec Management Client; C:Program FilesSymantecSymantec Endpoint ProtectionSmc.exe [2009-09-17 1864888]
R2 Symantec AntiVirus;Symantec Endpoint Protection; C:Program FilesSymantecSymantec Endpoint ProtectionRtvscan.exe [2009-09-17 2477304]
S3 LiveUpdate;LiveUpdate; C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE [2009-08-18 3093880]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Служба общих сетевых ресурсов проигрывателя Windows Media; C:Program FilesWindows Media Playerwmpnetwk.exe [2006-11-03 914944]
S3 WudfSvc;Windows Driver Foundation — User-mode Driver Framework; C:WINDOWSsystem32svchost.exe [2008-04-15 14336]
S4 JavaQuickStarterService;Java Quick Starter; C:Program FilesJavajre6binjqs.exe [2010-01-10 153376]
S4 SNAC;Symantec Network Access Control; C:Program FilesSymantecSymantec Endpoint ProtectionSNAC.EXE [2009-09-17 341320]
EOF
info.txt logfile of random’s system information tool 1.06 2010-05-24 00:06:03
======Uninstall list======
—>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:WINDOWSINFPCHealth.inf
Adobe Flash Player 10 ActiveX—>C:WINDOWSsystem32MacromedFlashuninstall_activeX.exe
Adobe Flash Player 10 Plugin—>C:WINDOWSsystem32MacromedFlashuninstall_plugin.exe
ArtMoney PRO v7.30.1—>»D:Opera_10.01.1844_Final_ML_PortableArtMoneyUninstallunins000.exe»
ATI Display Driver—>rundll32 C:WINDOWSsystem32atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVerMedia M16H PCI Analog 3.6.64.6—>C:Program FilesAVerMediaAVerMedia M16H PCI Analoguninst.exe
AVerMedia MCE Encoder x86 3.0.1.6—>C:Program FilesAVerMediaAVerMedia MCE Encoder x86uninst.exe
AVerTV—>C:Program FilesInstallShield Installation Information{5016185F-05AF-455F-AA70-6B6E5D6D4E70}setup.exe -runfromtemp -l0x0419
CCleaner—>»C:Program FilesCCleaneruninst.exe»
Cheat Engine 5.5—>»D:Opera_10.01.1844_Final_ML_PortableCheat Engineunins000.exe»
Command & Conquer 3—>D:GamesCNC3CDUNWISE.EXE D:GamesCNC3CDINSTALL.LOG
DSS DJ 5.6—>»D:музDSS DJunins000.exe»
FutureDecks Pro 2.0.0—>»D:Новая папка (2)futuredecks_pro_v2.0.0FutureDecksProunins000.exe»
Get Styles for Opera—>C:Program FilesGet-Styles 2.0opuninstall.exe
Get-Styles for Chrome—>C:Program FilesGet-Styles 2.0chuninstall.exe
Get-Styles for IE—>C:Program FilesGet-Styles 2.0ieuninstall.exe
Get-Styles для ВКонтакте—>C:Program FilesGet-Styles 2.0utilsuninstall.exe
ICQ Lite—>»C:Program FilesInstallShield Installation Information{6C13128C-1782-456F-84A4-017CECE259CA}setup.exe» -runfromtemp -l0x0009 -removeonly
ICQ Toolbar—>C:Program FilesICQ6ToolbarICQUnToolbar.exe
Java(TM) 6 Update 17—>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
K-Lite Mega Codec Pack 5.4.4—>»C:Program FilesK-Lite Codec Packunins000.exe»
KMPlayer 2.9.4.1436—>C:Program FilesKMPlayerUninstall.exe
KWorld TV713X BDA Driver—>C:WINDOWSp3xunist.exe
LEGO Star Wars—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1PROFES~1RunTime91Intel32Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{8A9F11D7-992E-431F-969A-875DC1BE96A6}setup.exe» -l0x19
LiveUpdate 3.3 (Symantec Corporation)—>»C:Program FilesSymantecLiveUpdateLSETUP.EXE» /U
Major 3.0.0—>»D:клабMajorunins000.exe»
Microsoft Office — профессиональный выпуск версии 2003—>MsiExec.exe /I{90110419-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable—>MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable — x86 9.0.30729.4148—>MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
MSXML 4.0 SP3 Parser (KB973685)—>MsiExec.exe /I{859DFA95-E4A6-48CD-B88E-A3E483E89B44}
My Translator 1.5—>»D:ререводчикMy Translator 1.5uninstall.exe»
Nero 6—>C:Program FilesAheadnerouninstallUNNERO.exe /UNINSTALL
Opera 10.53—>MsiExec.exe /X{1A0D2EFC-C4FC-446A-8BC3-57A54CE5EADD}
Phaser 3120—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{085895C1-D691-4AB9-B72F-D380623127AD}setup.exe»
PowerDVD—>RunDll32 C:PROGRA~1COMMON~1INSTAL~1engine6INTEL3~1Ctor.dll,LaunchSetup «C:Program FilesInstallShield Installation Information{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}Setup.exe» -uninstall
Realtek AC’97 Audio—>Alcrmv.exe -r -m
Splinter Cell — Pandora Tomorrow—>»C:Program FilesRussobit-MSplinter Cell — Pandora Tomorrowunins000.exe»
Symantec Endpoint Protection—>MsiExec.exe /I{2EFCC193-D915-4CCB-9201-31773A27BC06}
TEKKEN-3—>D:6F26~196A3~1TEKKEN-3UNWISE.EXE D:6F26~196A3~1TEKKEN-3INSTALL.LOG
Vista Drive Icon—>rundll32.exe advpack.dll,LaunchINFSection C:WINDOWSINFVistaDrv.inf,Uninstall
Архиватор WinRAR—>C:Program FilesWinRARuninstall.exe======Hosts File======
188.40.163.73 http://www.vkontakte.ru
188.40.163.73 vkontakte.ru
188.40.163.73 http://www.vk.com
188.40.163.73 vk.com
188.40.163.73 http://www.kaspersky.ru
188.40.163.73 kaspersky.ru
188.40.163.73 http://www.viruslist.ru
188.40.163.73 viruslist.ru
188.40.163.73 http://www.odnoklassniki.ru
188.40.163.73 odnoklassniki.ru======Security center information======
AV: Symantec Endpoint Protection
FW: Symantec Endpoint Protection======System event log======
Computer Name: MICROSOF-87A876
Event Code: 7036
Message: Служба «Службы терминалов» перешла в состояние Работает.Record Number: 5
Source Name: Service Control Manager
Time Written: 20100503174431.000000+360
Event Type: информация
User:Computer Name: MICROSOF-87A876
Event Code: 1007
Message: Компьютер автоматически настроил IP-адрес для сетевого адаптера
с адресом 00055D4D6947. Используется IP-адрес 169.254.50.140.Record Number: 4
Source Name: Dhcp
Time Written: 20100503174349.000000+360
Event Type: предупреждение
User:Computer Name: MICROSOF-87A876
Event Code: 2003
Message: Symantec Antivirus minifilter successfully loaded.Record Number: 3
Source Name: SRTSP
Time Written: 20100503174238.000000+360
Event Type: информация
User:Computer Name: MICROSOF-87A876
Event Code: 6005
Message: Запущена служба журнала событий.Record Number: 2
Source Name: EventLog
Time Written: 20100503174224.000000+360
Event Type: информация
User:Computer Name: MICROSOF-87A876
Event Code: 6009
Message: Microsoft (R) Windows 2000 (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.Record Number: 1
Source Name: EventLog
Time Written: 20100503174224.000000+360
Event Type: информация
User:=====Application event log=====
Computer Name: MICROSOF-87A876
Event Code: 7
Message:Загружен новый файл описания вирусов. Версия: 120311b.
Record Number: 971
Source Name: Symantec AntiVirus
Time Written: 20100311222253.000000+300
Event Type: информация
User:Computer Name: MICROSOF-87A876
Event Code: 13
Message:
LiveUpdate returned a non-critical error. Available content updates may have failed to install.Record Number: 970
Source Name: SescLU
Time Written: 20100311211659.000000+300
Event Type: ошибка
User:Computer Name: MICROSOF-87A876
Event Code: 1002
Message: Оболочка неожиданно завершила работу, и программа «Explorer.exe» была перезапущена.Record Number: 969
Source Name: Winlogon
Time Written: 20100311202257.000000+300
Event Type: информация
User:Computer Name: MICROSOF-87A876
Event Code: 13
Message:
LiveUpdate returned a non-critical error. Available content updates may have failed to install.Record Number: 968
Source Name: SescLU
Time Written: 20100311201621.000000+300
Event Type: ошибка
User:Computer Name: MICROSOF-87A876
Event Code: 1002
Message: Оболочка неожиданно завершила работу, и программа «Explorer.exe» была перезапущена.Record Number: 967
Source Name: Winlogon
Time Written: 20100311193942.000000+300
Event Type: информация
User:======Environment variables======
«ComSpec»=%SystemRoot%system32cmd.exe
«Path»=%SystemRoot%system32;%SystemRoot%;%SystemRoot%System32Wbem
«windir»=%SystemRoot%
«FP_NO_HOST_CHECK»=NO
«OS»=Windows_NT
«PROCESSOR_ARCHITECTURE»=x86
«PROCESSOR_LEVEL»=15
«PROCESSOR_IDENTIFIER»=x86 Family 15 Model 2 Stepping 9, GenuineIntel
«PROCESSOR_REVISION»=0209
«NUMBER_OF_PROCESSORS»=2
«PATHEXT»=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
«TEMP»=%SystemRoot%TEMP
«TMP»=%SystemRoot%TEMP
EOF
-
АвторСообщения