ComboFix 13-01-08.01 - Павел 08.01.2013 19:47:48.2.2 - x64
Microsoft Windows 7 Профессиональная 6.1.7601.1.1251.7.1049.18.4061.2739 [GMT 4:00]
Running from: c:\users\¦ртхы\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-12-08 to 2013-01-08 )))))))))))))))))))))))))))))))
.
.
2013-01-08 15:51 . 2013-01-08 15:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-08 15:22 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{74B216DF-8F80-48BE-866A-D4CBB6CC9F63}\mpengine.dll
2013-01-08 15:07 . 2013-01-08 15:07 -------- d-----w- c:\program files (x86)\Trend Micro
2013-01-08 13:40 . 2013-01-08 14:45 13312 ----a-w- c:\windows\SysWow64\drivers\vdqxnjq3.sys
2013-01-08 08:33 . 2013-01-08 08:33 -------- d-----w- c:\users\Павел\AppData\Roaming\Malwarebytes
2013-01-08 08:32 . 2013-01-08 08:32 -------- d-----w- c:\programdata\Malwarebytes
2013-01-08 08:32 . 2013-01-08 08:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-01-08 08:32 . 2012-12-14 12:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-08 08:32 . 2013-01-08 08:32 -------- d-----w- c:\users\Павел\AppData\Local\Programs
2013-01-07 17:43 . 2013-01-08 07:48 -------- d-----w- c:\program files\Google
2013-01-07 17:43 . 2013-01-08 07:48 -------- d-----w- c:\program files (x86)\Google
2013-01-07 14:59 . 2013-01-07 14:59 -------- d-----w- c:\program files\CCleaner
2013-01-07 14:57 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-06 10:06 . 2013-01-06 10:17 -------- d-----w- c:\users\Павел\Doctor Web
2013-01-06 08:32 . 2013-01-07 14:45 -------- d-----w- c:\program files\Unlocker
2013-01-06 08:13 . 2013-01-07 14:45 -------- d-----w- c:\program files (x86)\BabylonToolbar
2013-01-04 11:10 . 2013-01-04 11:10 -------- d-----w- c:\users\Павел\AppData\Local\Apps
2013-01-04 11:10 . 2013-01-04 11:10 -------- d-----w- c:\users\Павел\AppData\Local\Deployment
2012-12-31 07:35 . 2012-12-31 07:35 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-12-28 16:14 . 2012-12-28 16:15 -------- d-----w- c:\users\Павел\AppData\Roaming\Photo! Web Album
2012-12-28 16:14 . 2012-12-28 16:14 -------- d-----w- c:\program files (x86)\Photo!
2012-12-21 18:41 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-21 18:41 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-21 18:41 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-21 18:41 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-13 17:21 . 2012-12-13 17:22 -------- d-----w- c:\users\Павел\AppData\Roaming\VKDJ
2012-12-13 17:21 . 2013-01-08 15:15 -------- d-----w- C:\VkontakteDJ
2012-12-12 15:42 . 2012-11-09 05:45 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-12 18:17 . 2012-08-27 09:43 67413224 ----a-w- c:\windows\system32\MRT.exe
2012-11-29 10:25 . 2012-11-29 10:25 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{634C36E9-B69A-425F-BD51-CA3AF4E60C2D}\gapaengine.dll
2012-11-19 16:26 . 2012-09-28 13:49 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-11-18 08:53 . 2012-10-08 14:56 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2012-10-29 14:56 . 2012-10-29 14:56 163056 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10142.bin
2012-10-16 08:38 . 2012-11-28 13:54 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 13:54 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 13:54 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 vdqxnjq3;AVZ-BC Kernel Driver;c:\windows\system32\Drivers\vdqxnjq3.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Служба технологий активации Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-08-27 1255736]
R4 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-08-28 1038088]
R4 ICQ Service;ICQ Service;c:\program files (x86)\ICQ6Toolbar\ICQ Service.exe [2011-07-20 247872]
R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-02 3064000]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-08-27 283200]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-30 128456]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
S3 NisSrv;Проверка сети (Майкрософт);c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-12 368896]
S3 RTL8167;Драйвер Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
.
.
.
--------- X64 Entries -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yandex.ru/?clid=40316
mLocal Page = c:\windows\SYSTEM32\blank.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-01-08 19:53:27
ComboFix-quarantined-files.txt 2013-01-08 15:53
ComboFix2.txt 2013-01-08 15:43
.
Pre-Run: 65*287*979*008 байт свободно
Post-Run: 65*230*131*200 байт свободно
.
- - End Of File - - 4BD920646A6534F26820F928BD02AEA1
Скрыть