Лог утилиты random's system information tool 1.09 (автор: random/random) Run by аа at 2013-01-14 20:30:56 Microsoft Windows 7 Домашняя расширенная Системный раздел C: размер 107 GB (89%) Свободно 120 GB Total RAM: 3069 MB (74% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:31:01, on 14.01.2013 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v9.00 (9.00.8112.16457) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Users\аа\AppData\Local\Yandex\Updater\praetorian.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\аа\Desktop\RSIT.exe C:\Program Files\trend micro\аа.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yandex.ru/?clid=1932033 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=1932033 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer предоставлен: Яндекс R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: Визуальные закладки - {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} - C:\Program Files\Yandex\FastDial\fastdial.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files\Yandex\Elements\yndbar.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [Praetorian] C:\Users\аа\AppData\Local\Yandex\Updater\praetorian.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- End of file - 3073 bytes ======Папка назначеных зданий====== C:\Windows\tasks\Adobe Flash Player Updater.job ======Снимок реестра====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-14 461216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}] Визуальные закладки - C:\Program Files\Yandex\FastDial\fastdial.dll [2012-07-30 2948448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-14 170912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {91397D20-1446-11D4-8AF4-0040CA1127B6} - Элементы Яндекса - C:\Program Files\Yandex\Elements\yndbar.dll [2012-08-07 6674784] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Praetorian"=C:\Users\аа\AppData\Local\Yandex\Updater\praetorian.exe [2012-08-07 1582976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "VIDC.UYVY"=msyuv.dll "VIDC.YUY2"=msyuv.dll "VIDC.YVYU"=msyuv.dll "VIDC.IYUV"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "VIDC.YVU9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv "MSVideo8"=VfWWDM32.dll ======Ассоциации файлов====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======Список файлов и папок, созданных за последние 3 месяца====== 2013-01-14 20:30:56 ----D---- C:\rsit 2013-01-14 20:30:56 ----D---- C:\Program Files\trend micro 2013-01-14 19:17:04 ----D---- C:\Windows\pss 2013-01-14 18:53:30 ----D---- C:\ProgramData\Yandex 2013-01-14 18:53:29 ----D---- C:\Users\аа\AppData\Roaming\Yandex 2013-01-14 18:53:29 ----D---- C:\Program Files\Yandex 2013-01-14 18:53:28 ----D---- C:\Users\аа\AppData\Roaming\Opera 2013-01-14 18:53:21 ----D---- C:\Users\аа\AppData\Roaming\Mozilla 2013-01-14 18:53:20 ----HD---- C:\Windows\msdownld.tmp 2013-01-14 18:52:46 ----A---- C:\Windows\system32\wininet.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\wextract.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\webcheck.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\vbscript.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\urlmon.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\url.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\SetIEInstalledDate.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\pngfilt.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\occache.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\msrating.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\msls31.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\mshtmler.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\mshtmled.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\mshtml.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\mshta.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\msfeedssync.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\msfeedsbs.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\msfeeds.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\licmgr10.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\jsproxy.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\jscript9.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\jscript.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\inseng.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\imgutil.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iexpress.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieUnatt.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieui.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iesysprep.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iesetup.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iertutil.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iernonce.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iepeers.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieframe.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\iedkcs32.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieapfltr.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieapfltr.dat 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieakui.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieaksie.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ieakeng.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\IEAdvpack.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\ie4uinit.exe 2013-01-14 18:52:46 ----A---- C:\Windows\system32\icardie.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\dxtrans.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\dxtmsft.dll 2013-01-14 18:52:46 ----A---- C:\Windows\system32\admparse.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\XpsRasterService.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\XpsPrint.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\XpsGdiConverter.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\WMVDECOD.DLL 2013-01-14 18:51:51 ----A---- C:\Windows\system32\mfreadwrite.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\mf.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\FntCache.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\ExplorerFrame.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\DWrite.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\drivers\dxgmms1.sys 2013-01-14 18:51:51 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys 2013-01-14 18:51:51 ----A---- C:\Windows\system32\d3d10warp.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\d3d10_1core.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\d3d10_1.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\d2d1.dll 2013-01-14 18:51:51 ----A---- C:\Windows\system32\cdd.dll 2013-01-14 18:36:12 ----D---- C:\ProgramData\Sun 2013-01-14 18:36:11 ----D---- C:\Program Files\Common Files\Java 2013-01-14 18:36:01 ----A---- C:\Windows\system32\npDeployJava1.dll 2013-01-14 18:36:01 ----A---- C:\Windows\system32\javaws.exe 2013-01-14 18:36:01 ----A---- C:\Windows\system32\deployJava1.dll 2013-01-14 18:35:56 ----A---- C:\Windows\system32\WindowsAccessBridge.dll 2013-01-14 18:35:56 ----A---- C:\Windows\system32\javaw.exe 2013-01-14 18:35:56 ----A---- C:\Windows\system32\java.exe 2013-01-14 18:35:50 ----D---- C:\Program Files\Java 2013-01-14 18:35:30 ----SHD---- C:\Windows\Installer 2013-01-14 18:16:39 ----D---- C:\Users\аа\AppData\Roaming\Macromedia 2013-01-14 18:16:38 ----D---- C:\Users\аа\AppData\Roaming\Adobe 2013-01-14 18:16:13 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2013-01-14 18:16:12 ----D---- C:\Windows\system32\Macromed 2013-01-14 18:15:49 ----D---- C:\ProgramData\Adobe 2013-01-14 17:07:25 ----N---- C:\Windows\system32\MpSigStub.exe 2013-01-14 17:00:53 ----A---- C:\Windows\system32\wups2.dll 2013-01-14 17:00:53 ----A---- C:\Windows\system32\wucltux.dll 2013-01-14 17:00:53 ----A---- C:\Windows\system32\wuaueng.dll 2013-01-14 17:00:53 ----A---- C:\Windows\system32\wuauclt.exe 2013-01-14 17:00:46 ----A---- C:\Windows\system32\wups.dll 2013-01-14 17:00:46 ----A---- C:\Windows\system32\wudriver.dll 2013-01-14 17:00:46 ----A---- C:\Windows\system32\wuapi.dll 2013-01-14 17:00:34 ----A---- C:\Windows\system32\wuwebv.dll 2013-01-14 17:00:34 ----A---- C:\Windows\system32\wuapp.exe 2013-01-14 17:00:09 ----D---- C:\Users\аа\AppData\Roaming\Identities 2013-01-14 17:00:01 ----SD---- C:\Users\аа\AppData\Roaming\Microsoft 2013-01-14 17:00:01 ----D---- C:\Users\аа\AppData\Roaming\Media Center Programs 2013-01-14 16:59:46 ----SHD---- C:\Recovery 2013-01-14 16:59:46 ----SHD---- C:\ProgramData\Шаблоны 2013-01-14 16:59:46 ----SHD---- C:\ProgramData\Рабочий стол 2013-01-14 16:59:46 ----SHD---- C:\ProgramData\Избранное 2013-01-14 16:59:46 ----SHD---- C:\ProgramData\Документы 2013-01-14 16:59:46 ----SHD---- C:\ProgramData\Главное меню 2013-01-14 16:54:55 ----A---- C:\Windows\system32\PerfStringBackup.INI 2013-01-14 16:47:50 ----D---- C:\Windows\SoftwareDistribution 2013-01-14 16:45:14 ----D---- C:\Windows\Prefetch 2013-01-14 16:44:54 ----ASH---- C:\pagefile.sys 2013-01-14 16:44:54 ----ASH---- C:\hiberfil.sys 2013-01-14 16:44:53 ----SHD---- C:\System Volume Information 2013-01-14 16:44:14 ----D---- C:\Windows\Panther 2013-01-14 16:44:02 ----RASH---- C:\BOOTSECT.BAK 2013-01-14 16:44:00 ----SHD---- C:\Boot ======Список файлов и папок, измененных за последние 3 месяца====== 2013-01-14 20:30:57 ----D---- C:\Windows\Temp 2013-01-14 20:30:56 ----RD---- C:\Program Files 2013-01-14 20:26:23 ----D---- C:\Windows 2013-01-14 20:22:10 ----D---- C:\Windows\system32\config 2013-01-14 20:20:04 ----D---- C:\Windows\Logs 2013-01-14 19:27:32 ----D---- C:\Windows\System32 2013-01-14 19:27:32 ----D---- C:\Windows\inf 2013-01-14 19:24:59 ----D---- C:\Windows\system32\wdi 2013-01-14 19:06:48 ----D---- C:\Windows\Tasks 2013-01-14 19:06:48 ----D---- C:\Windows\system32\Tasks 2013-01-14 18:55:54 ----D---- C:\Windows\winsxs 2013-01-14 18:54:06 ----D---- C:\Windows\system32\ru-RU 2013-01-14 18:54:05 ----D---- C:\Program Files\Internet Explorer 2013-01-14 18:54:04 ----D---- C:\Windows\system32\migration 2013-01-14 18:54:04 ----D---- C:\Windows\PolicyDefinitions 2013-01-14 18:54:03 ----D---- C:\Windows\system32\en-US 2013-01-14 18:53:59 ----D---- C:\Windows\system32\drivers 2013-01-14 18:53:30 ----HD---- C:\ProgramData 2013-01-14 18:53:12 ----D---- C:\Windows\system32\catroot 2013-01-14 18:53:11 ----D---- C:\Windows\system32\catroot2 2013-01-14 18:36:11 ----D---- C:\Program Files\Common Files 2013-01-14 17:00:14 ----D---- C:\Windows\system32\restore 2013-01-14 17:00:07 ----SHD---- C:\$Recycle.Bin 2013-01-14 16:59:58 ----RD---- C:\Users 2013-01-14 16:59:46 ----D---- C:\Windows\system32\Recovery 2013-01-14 16:59:46 ----D---- C:\Program Files\Windows NT 2013-01-14 16:59:44 ----SD---- C:\ProgramData\Microsoft 2013-01-14 16:59:23 ----D---- C:\Windows\system32\CodeIntegrity 2013-01-14 16:54:41 ----D---- C:\Windows\system32\wbem 2013-01-14 16:53:12 ----D---- C:\Windows\Microsoft.NET 2013-01-14 16:53:07 ----RSD---- C:\Windows\assembly 2013-01-14 16:51:02 ----D---- C:\Windows\rescache 2013-01-14 16:50:35 ----D---- C:\Windows\debug 2013-01-14 16:48:16 ----D---- C:\Windows\system32\sysprep ======Список драйверов (тип запуска: R=Запущен, S=остановлен, 0=Загрузочный, 1=Системный, 2=Автоматически, 3=Вручную, 4=Отключено)====== R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648] R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-14 1035776] R3 BthEnum;Служба перечислителя Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816] R3 BthPan;Устройства Bluetooth (личной сети); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696] R3 BTHUSB;Драйвер порта USB радиомодуля Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880] R3 netw5v32;Драйвер адаптера беспроводной связи серии Intel(R) Wireless WiFi Link 5000 для 32-разрядной версии Windows Vista; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168] R3 RFCOMM;Устройство Bluetooth (протокол RFCOMM TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536] R3 RTL8167;Драйвер Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776] R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992] S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704] S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888] S3 BTHPORT;Драйвер порта Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704] S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736] ======Список служб (тип запуска: R=Запущена, S=остановлена, 0=Загрузочная, 1=Системная, 2=Автоматически, 3=Вручную, 4=Отключено)====== S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-14 251400] -----------------EOF-----------------