Ну вот что в блокноте вышло
ComboFix 09-11-14.03 - Администратор 14.11.2009 17:24..3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1251.7.1049.18.2046.1454 [GMT 5:00]
Running from: c:\documents and settings\Администратор\Рабочий стол\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Common Files\System\Uninstall
c:\program files\Common Files\System\Uninstall\Uninstall A360.lnk
c:\program files\Mail.Ru\Agent\Mra\dll\newmrasearch.dll
c:\windows\system32\ieuinit.inf
c:\windows\system32\msconfig.exe
c:\windows\system32\tmp78.tmp
c:\windows\system32\tmp79.tmp
c:\windows\zap.exe
----- BITS: Possible infected sites -----
hxxp://soft.export.yandex.ru
.
((((((((((((((((((((((((( Files Created from 2009-10-14 to 2009-11-14 )))))))))))))))))))))))))))))))
.
2009-11-14 12:27 . 2009-11-14 12:27 53248 ----a-w- c:\temp\catchme.dll
2009-11-13 13:26 . 2009-11-14 11:39 -------- d-----w- c:\temp\msohtml1
2009-11-13 13:26 . 2009-11-13 13:26 -------- d-----w- c:\temp\msohtml
2009-11-11 14:12 . 2009-11-11 14:12 -------- d-----w- c:\temp\6001wrd.~lk
2009-11-11 14:11 . 2009-11-11 14:11 -------- d-----w- c:\temp\4003wrd.~lk
2009-11-11 14:08 . 2009-11-11 14:08 -------- d-----w- c:\temp\8036wrd.~lk
2009-11-11 14:07 . 2009-11-14 12:26 -------- d-----w- c:\temp\2036wrd.~lk
2009-11-11 14:04 . 2009-11-11 14:04 -------- d-----w- c:\temp\1035wrd.~lk
2009-11-09 15:11 . 2009-11-09 15:23 -------- d-----w- c:\temp\{6740F9E3-1353-47DD-9765-BA49FC4C3479}
2009-11-09 15:10 . 2009-11-09 17:21 -------- d-----w- c:\documents and settings\Администратор\Application Data\uTorrent
2009-11-07 11:12 . 2009-11-07 11:12 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-11-07 08:57 . 2009-11-07 08:57 -------- d-----w- c:\temp\303Bwrd.~lk
2009-11-07 08:57 . 2009-11-07 08:57 -------- d-----w- c:\temp\2038wrd.~lk
2009-11-06 03:05 . 2009-11-14 02:46 -------- d-----w- c:\temp\_avast4_
2009-11-04 09:16 . 2009-11-14 12:26 -------- d-----w- c:\temp\300Cwrd.~lk
2009-11-04 09:16 . 2009-11-14 12:26 -------- d-----w- c:\temp\4033wrd.~lk
2009-11-04 07:19 . 2009-11-04 07:19 -------- d-----w- c:\program files\Common Files\EasyInfo
2009-11-03 19:10 . 2009-11-03 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-10-30 18:38 . 2009-10-30 19:02 -------- d-----w- c:\documents and settings\Администратор\Application Data\flightgear.org
2009-10-30 18:33 . 2009-11-09 16:45 -------- d-----w- c:\program files\FlightGear
2009-10-30 14:12 . 2009-10-30 14:12 -------- d-----w- c:\program files\MyPlayCity.ru
2009-10-29 15:37 . 2009-10-29 15:37 -------- d-----w- c:\documents and settings\Администратор\Local Settings\Application Data\WMTools Downloaded Files
2009-10-27 11:40 . 2009-11-04 10:38 -------- d-----w- c:\program files\The Sims 2
2009-10-25 11:06 . 2008-11-26 17:16 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-25 11:06 . 2008-11-26 17:16 50864 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-25 11:06 . 2008-11-26 17:15 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-25 11:06 . 2008-11-26 17:18 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-25 11:06 . 2008-11-26 17:18 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-25 11:06 . 2008-11-26 17:17 111184 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-25 11:06 . 2008-11-26 17:17 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-25 11:06 . 2008-11-26 17:15 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-25 11:05 . 2008-11-26 17:21 1236208 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-25 11:05 . 2009-10-25 11:05 -------- d-----w- c:\program files\Alwil Software
2009-10-20 12:08 . 2009-10-20 12:09 -------- d-----w- c:\documents and settings\Администратор\DoctorWeb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-09 16:45 . 2008-09-27 13:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-09 16:42 . 2001-10-20 12:00 50410 ----a-w- c:\windows\system32\perfc019.dat
2009-11-09 16:42 . 2001-10-20 12:00 349554 ----a-w- c:\windows\system32\perfh019.dat
2009-11-09 15:11 . 2009-02-26 18:16 -------- d-----w- c:\documents and settings\Администратор\Application Data\Yandex
2009-11-04 04:57 . 2008-09-27 09:16 60112 ----a-w- c:\documents and settings\Default User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-30 12:47 . 2009-04-08 06:19 -------- d-----w- c:\program files\Common Files\yuPlay
2009-10-30 12:47 . 2009-04-05 14:24 -------- d-----w- c:\program files\yuPlay
2009-10-20 15:18 . 2008-09-27 15:45 -------- d-----w- c:\program files\Gigabyte
2009-10-18 04:54 . 2008-09-30 09:43 -------- d-----w- c:\program files\DirectX
2009-09-20 11:44 . 2009-09-20 11:44 -------- d-----w- c:\program files\Yahoo!
2009-09-20 11:42 . 2009-09-20 11:42 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-09-20 11:42 . 2008-09-27 13:41 -------- d-----w- c:\program files\Common Files\InstallShield
2008-04-07 09:38 . 2009-03-14 15:59 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 09:38 . 2009-03-14 15:59 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 09:38 . 2009-03-14 15:59 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 09:38 . 2009-03-14 15:59 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 09:38 . 2009-03-14 15:59 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
[-] 2004-12-21 . 4092C56967175F009DC8458DC434358E . 359040 . . [5.1.2600.2505] . . c:\windows\system32\drivers\tcpip.sys
[-] 2004-10-31 11:59 . AB3D62010AF342203FFA60C2D94DBC68 . 8704 . . [1] . . c:\windows\system32\sfcfiles.dll
c:\windows\system32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91397D20-1446-11D4-8AF4-0040CA1127B6}"= "c:\program files\Yandex\YandexBarIE\yndbar.dll" [2009-07-24 5586208]
[HKEY_CLASSES_ROOT\clsid\{91397d20-1446-11d4-8af4-0040ca1127b6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91397D20-1446-11D4-8AF4-0040CA1127B6}"= "c:\program files\Yandex\YandexBarIE\yndbar.dll" [2009-07-24 5586208]
[HKEY_CLASSES_ROOT\clsid\{91397d20-1446-11d4-8af4-0040ca1127b6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"yuPlay.exe"="c:\program files\yuPlay\yuPlay.exe" [2009-09-11 1829888]
"Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2005-04-18 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ь" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"CNAP2 Launcher"="c:\windows\System32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2007-09-05 406944]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"2gis update client UI"="c:\program files\2gis\UpdateClientWin32\UpdateClientUI.exe" [2008-09-17 4055040]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-12-20 16860672]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [25.10.2009 16:06 111184]
R2 2GIS UpdateClientService;2GIS UpdateClientService;c:\program files\2gis\UpdateClientWin32\UpdateClientService.exe [17.09.2008 11:03 1134592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25.10.2009 16:06 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [09.12.2008 21:13 222456]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
*Deregistered* - spider
*Deregistered* - spidernt
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yandex.ru/?clid=47639
mStart Page = hxxp://www.yahoo.com
IE: &Экспорт в Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Поиск@Mail.Ru - c:\program files\mail.ru\sputnik\MailRuSputnik.dll/282
IE: Словари@Mail.Ru - c:\program files\mail.ru\sputnik\MailRuSputnik.dll/283
TCP: {92A657DB-F978-40E0-A779-AF2981A2E7F4} = 91.144.128.3 91.144.130.3
FF - ProfilePath - c:\documents and settings\Администратор\Application Data\Mozilla\Firefox\Profiles\9vf96daw.default\
FF - prefs.js: browser.search.selectedEngine - РџРѕРёСЃРє@mail.ru
FF - prefs.js: browser.startup.homepage - hxxp://www.mail.ru
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ISUSPM Startup - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
12
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
ссылка
Rootkit scan 2009-11-14 17:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-11-14 17:28
ComboFix-quarantined-files.txt 2009-11-14 12:28
Pre-Run: 219 659 902 976 байт свободно
Post-Run: 219 963 224 064 байт свободно
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional RU" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - 45B3CF2251632CE3DF0B09C660BDB968