Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 18:18:17, on 09.05.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 SP3 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DrWeb\spideragent.exe
C:\Program Files\DrWeb\dwservice.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\DWA-125\RtWlan.exe
C:\WINDOWS\system32\KaraokeSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwarkdaemon.exe
C:\Program Files\DrWeb\dwnetfilter.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Рабочий стол\Новая папка\Опера\29.0.1795.47\opera.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Рабочий стол\Новая папка\Опера\29.0.1795.47\opera_crashreporter.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Рабочий стол\Новая папка\Опера\29.0.1795.47\opera.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Рабочий стол\Новая папка\Опера\29.0.1795.47\opera.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Рабочий стол\Новая папка\Опера\29.0.1795.47\opera.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Рабочий стол\Новая папка\Опера\29.0.1795.47\opera.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Documents and Settings\миша.EDDB870B92074D6\Мои документы\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SpIDerAgent] "C:\Program Files\DrWeb\spideragent.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: D-Link DWA-125 WPS Utility.lnk = C:\Program Files\D-Link\DWA-125\RtWlan.exe
O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Отправить в OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone:
http://*.a-k-d.ru
O15 - Trusted Zone:
http://torgi.admkrsk.ru
O15 - Trusted Zone:
http://*.ahml.ru
O15 - Trusted Zone:
http://*.akosta.info
O15 - Trusted Zone:
http://*.alfalot.ru
O15 - Trusted Zone:
http://etp.asgor.su
O15 - Trusted Zone:
http://*.atctrade.ru
O15 - Trusted Zone:
http://d.ati.su
O15 - Trusted Zone:
http://*.auction63.ru
O15 - Trusted Zone:
http://*.bashzakaz.ru
O15 - Trusted Zone:
http://*.bepspb.ru
O15 - Trusted Zone:
http://*.cdtrf.ru
O15 - Trusted Zone:
http://*.dfotender.ru
O15 - Trusted Zone:
http://torgi.donland.ru
O15 - Trusted Zone:
http://etp.dveuk.ru
O15 - Trusted Zone:
http://*.eksystems.ru
O15 - Trusted Zone:
http://*.el-torg.com
O15 - Trusted Zone:
http://*.electro-torgi.ru
O15 - Trusted Zone:
http://*.eltorg.org
O15 - Trusted Zone:
http://*.estp-sro.ru
O15 - Trusted Zone:
http://bankrupt.etp-agenda.ru
O15 - Trusted Zone:
http://*.etp-micex.ru
O15 - Trusted Zone:
http://*.etp-profit.ru
O15 - Trusted Zone:
http://*.etp33.ru
O15 - Trusted Zone:
http://*.etpu.ru
O15 - Trusted Zone:
http://*.etrade-capital.ru
O15 - Trusted Zone:
http://*.fabrikant.ru
O15 - Trusted Zone:
http://*.fciit.ru
O15 - Trusted Zone:
http://lk.fcsm.ru
O15 - Trusted Zone:
http://lks.fcsm.ru
O15 - Trusted Zone:
http://*.fedresurs.ru
O15 - Trusted Zone:
http://*.fips.ru
O15 - Trusted Zone:
http://*.gazneftetorg.ru
O15 - Trusted Zone:
http://zakupki.gov.ru
O15 - Trusted Zone:
http://*.kartoteka.ru
O15 - Trusted Zone:
http://*.kontur-ca.ru
O15 - Trusted Zone:
http://*.krista.ru
O15 - Trusted Zone:
http://*.lot-online.ru
O15 - Trusted Zone:
http://*.lotcenter.ru
O15 - Trusted Zone:
http://*.m-ets.ru
O15 - Trusted Zone:
http://*.meta-invest.ru
O15 - Trusted Zone:
http://fgis.minregion.ru
O15 - Trusted Zone:
http://market.zakupki.mos.ru
O15 - Trusted Zone:
http://etp.mse.ru
O15 - Trusted Zone:
http://*.nistp.ru
O15 - Trusted Zone:
http://*.nsso.ru
O15 - Trusted Zone:
http://*.oetprf.ru
O15 - Trusted Zone:
http://*.otc-tender.ru
O15 - Trusted Zone:
http://*.otc.ru
O15 - Trusted Zone:
http://*.pfotender.ru
O15 - Trusted Zone:
http://*.promkonsalt.ru
O15 - Trusted Zone:
http://etp.roseltorg.ru
O15 - Trusted Zone:
http://*.roseltorg.ru
O15 - Trusted Zone:
http://*.rts-tender.ru
O15 - Trusted Zone:
http://*.rus-on.ru
O15 - Trusted Zone:
http://etp.s-vfu.ru
O15 - Trusted Zone:
http://*.sberbank-ast.ru
O15 - Trusted Zone:
http://bankruptcy.selt-online.ru
O15 - Trusted Zone:
http://*.seltim.ru
O15 - Trusted Zone:
http://*.setonline.ru
O15 - Trusted Zone:
http://supply.severstal.com
O15 - Trusted Zone:
http://*.sibfotender.ru
O15 - Trusted Zone:
http://*.startrader.ru
O15 - Trusted Zone:
http://*.stroytorgi.ru
O15 - Trusted Zone:
http://*.tektorg.ru
O15 - Trusted Zone:
http://*.torg-fin.ru
O15 - Trusted Zone:
http://*.torgi223.ru
O15 - Trusted Zone:
http://*.torgibankrot.ru
O15 - Trusted Zone:
http://*.utender.ru
O15 - Trusted Zone:
http://*.vertrades.ru
O15 - Trusted Zone:
http://*.vestnik-gosreg.ru
O15 - Trusted Zone:
http://*.zakupki21.ru
O15 - Trusted Zone:
http://*.kontur-ca.ru (HKLM)
O15 - ESC Trusted Zone:
http://*.a-k-d.ru
O15 - ESC Trusted Zone:
http://torgi.admkrsk.ru
O15 - ESC Trusted Zone:
http://*.ahml.ru
O15 - ESC Trusted Zone:
http://*.akosta.info
O15 - ESC Trusted Zone:
http://*.alfalot.ru
O15 - ESC Trusted Zone:
http://etp.asgor.su
O15 - ESC Trusted Zone:
http://*.atctrade.ru
O15 - ESC Trusted Zone:
http://d.ati.su
O15 - ESC Trusted Zone:
http://*.auction63.ru
O15 - ESC Trusted Zone:
http://*.bashzakaz.ru
O15 - ESC Trusted Zone:
http://*.bepspb.ru
O15 - ESC Trusted Zone:
http://*.cdtrf.ru
O15 - ESC Trusted Zone:
http://*.dfotender.ru
O15 - ESC Trusted Zone:
http://torgi.donland.ru
O15 - ESC Trusted Zone:
http://etp.dveuk.ru
O15 - ESC Trusted Zone:
http://*.eksystems.ru
O15 - ESC Trusted Zone:
http://*.el-torg.com
O15 - ESC Trusted Zone:
http://*.electro-torgi.ru
O15 - ESC Trusted Zone:
http://*.eltorg.org
O15 - ESC Trusted Zone:
http://*.estp-sro.ru
O15 - ESC Trusted Zone:
http://bankrupt.etp-agenda.ru
O15 - ESC Trusted Zone:
http://*.etp-micex.ru
O15 - ESC Trusted Zone:
http://*.etp-profit.ru
O15 - ESC Trusted Zone:
http://*.etp33.ru
O15 - ESC Trusted Zone:
http://*.etpu.ru
O15 - ESC Trusted Zone:
http://*.etrade-capital.ru
O15 - ESC Trusted Zone:
http://*.fabrikant.ru
O15 - ESC Trusted Zone:
http://*.fciit.ru
O15 - ESC Trusted Zone:
http://lk.fcsm.ru
O15 - ESC Trusted Zone:
http://lks.fcsm.ru
O15 - ESC Trusted Zone:
http://*.fedresurs.ru
O15 - ESC Trusted Zone:
http://*.fips.ru
O15 - ESC Trusted Zone:
http://*.gazneftetorg.ru
O15 - ESC Trusted Zone:
http://zakupki.gov.ru
O15 - ESC Trusted Zone:
http://*.kartoteka.ru
O15 - ESC Trusted Zone:
http://*.kontur-ca.ru
O15 - ESC Trusted Zone:
http://*.krista.ru
O15 - ESC Trusted Zone:
http://*.lot-online.ru
O15 - ESC Trusted Zone:
http://*.lotcenter.ru
O15 - ESC Trusted Zone:
http://*.m-ets.ru
O15 - ESC Trusted Zone:
http://*.meta-invest.ru
O15 - ESC Trusted Zone:
http://fgis.minregion.ru
O15 - ESC Trusted Zone:
http://market.zakupki.mos.ru
O15 - ESC Trusted Zone:
http://etp.mse.ru
O15 - ESC Trusted Zone:
http://*.nistp.ru
O15 - ESC Trusted Zone:
http://*.nsso.ru
O15 - ESC Trusted Zone:
http://*.oetprf.ru
O15 - ESC Trusted Zone:
http://*.otc-tender.ru
O15 - ESC Trusted Zone:
http://*.otc.ru
O15 - ESC Trusted Zone:
http://*.pfotender.ru
O15 - ESC Trusted Zone:
http://*.promkonsalt.ru
O15 - ESC Trusted Zone:
http://etp.roseltorg.ru
O15 - ESC Trusted Zone:
http://*.roseltorg.ru
O15 - ESC Trusted Zone:
http://*.rts-tender.ru
O15 - ESC Trusted Zone:
http://*.rus-on.ru
O15 - ESC Trusted Zone:
http://etp.s-vfu.ru
O15 - ESC Trusted Zone:
http://*.sberbank-ast.ru
O15 - ESC Trusted Zone:
http://bankruptcy.selt-online.ru
O15 - ESC Trusted Zone:
http://*.seltim.ru
O15 - ESC Trusted Zone:
http://*.setonline.ru
O15 - ESC Trusted Zone:
http://supply.severstal.com
O15 - ESC Trusted Zone:
http://*.sibfotender.ru
O15 - ESC Trusted Zone:
http://*.startrader.ru
O15 - ESC Trusted Zone:
http://*.stroytorgi.ru
O15 - ESC Trusted Zone:
http://*.tektorg.ru
O15 - ESC Trusted Zone:
http://*.torg-fin.ru
O15 - ESC Trusted Zone:
http://*.torgi223.ru
O15 - ESC Trusted Zone:
http://*.torgibankrot.ru
O15 - ESC Trusted Zone:
http://*.utender.ru
O15 - ESC Trusted Zone:
http://*.vertrades.ru
O15 - ESC Trusted Zone:
http://*.vestnik-gosreg.ru
O15 - ESC Trusted Zone:
http://*.zakupki21.ru
O15 - ESC Trusted Zone:
http://*.kontur-ca.ru (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Предзагрузчик Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Демон кэша категорий компонентов - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Dr.Web Control Service (DrWebAVService) - Doctor Web, Ltd. - C:\Program Files\DrWeb\dwservice.exe
O23 - Service: Dr.Web Scanning Engine (DrWebEngine) (DrWebEngine) - Doctor Web, Ltd. - C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
O23 - Service: Dr.Web Net Filtering Service (DrWebNetFilter) - Doctor Web, Ltd. - C:\Program Files\DrWeb\dwnetfilter.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Служба Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: VIA Karaoke digital mixer Service (KaraokeService) - VIA Technologies, Inc. - C:\WINDOWS\system32\KaraokeSer.exe
O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Корпорация Майкрософт - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe
--
End of file - 14972 bytes
Скрыть