Новый участник
Сообщения: 4
Благодарности: 0
|
Профиль
|
Отправить PM
| Цитировать
здравствуйте вот лог из SDfix
читать дальше »
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http:/ /www.gmer.net Rootkit scan 2011-01-20 00:58:07 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC 1-08002BE10318}\Descriptions] "\34\48\4=\48\4?\4>\4@\4B\4 ??\4;\0040\4=\48\4@\4>\0042\4I\48\4:\0040\4 ??\0040\ 4:\0045\4B\4>\0042\4"=str(7):"1\0002\0003\0004\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?L?2?T?P?)?"=str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?P?P?T?P?)?"=str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?P?P?P?o?E?)?"=str(7):"1\0" "\37\4@\4O\4<\4>\49\4 ??\0040\4@\0040\4;\4;\0045\4;\4L\4=\4K\49\4 ??\4>\4@\4B\4" =str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?I?P?)?"=str(7):"1\0" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\grbim] "DisplayName"="Helper Manager" "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Description"="▲15A?5G8205B 70I8I5==>5 E@0=5=85 A5:@5B=KE 40==KE, B0:8E, :0: 70: @KBK5 :;NG8, 4;O ?@54>B2@0I5=8O =5A0=:F8>=8@>20==>3> 4>ABC?0 A;C61, ?@>F5AA>2 8; 8 ?>;L7>20B5;59." [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\grbim\Parameters] "ServiceDll"=str(2):"C:\WINDOWS.0\system32\ohrgpcx.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1 058D9A64CEC] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000001 "hdf12"=hex:ff,80,75,cd,14,9a,7e,34,df,b1,1d,22,3c,df,c8,2f,de,68,b6,2c,9c,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1 058D9A64CEC\00000001] "a0"=hex:20,01,00,00,5f,7f,30,66,62,d8,33,81,7b,ae,7f,76,e1,8d,05,da,81,.. "hdf12"=hex:9c,51,57,4b,60,19,1a,c3,d7,ac,e1,55,a0,78,ee,39,ae,17,24,85,53,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1 058D9A64CEC\00000001\gdq0] "hdf12"=hex:de,a4,2d,28,da,99,e2,80,d4,8d,82,52,9d,3e,ac,7e,db,ce,ff,88,a4,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4 BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000000 "khjeh"=hex:50,c6,f3,14,cb,b3,99,c3,b8,ec,6a,f9,b0,14,ee,1c,2b,68,a0,4a,20,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4 BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,92,3e,19,f7,6a,12,3a,dc,6e,e9,b1,b0,d2,7c,0f,6b,24,.. "khjeh"=hex:b0,2e,c7,fb,b2,5c,a9,25,86,18,1d,c1,13,ad,55,5b,e2,50,33,a5,97,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4 BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:7b,c5,0d,89,70,04,54,a7,d7,99,27,b1,40,04,be,8a,49,ff,bb,9b,d3,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE -BFC1-08002BE10318}\Descriptions] "\34\48\4=\48\4?\4>\4@\4B\4 ??\4;\0040\4=\48\4@\4>\0042\4I\48\4:\0040\4 ??\0040\ 4:\0045\4B\4>\0042\4"=str(7):"1\0002\0003\0004\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?L?2?T?P?)?"=str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?P?P?T?P?)?"=str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?P?P?P?o?E?)?"=str(7):"1\0" "\37\4@\4O\4<\4>\49\4 ??\0040\4@\0040\4;\4;\0045\4;\4L\4=\4K\49\4 ??\4>\4@\4B\4" =str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?I?P?)?"=str(7):"1\0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\grbim] "DisplayName"="Helper Manager" "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Description"="▲15A?5G8205B 70I8I5==>5 E@0=5=85 A5:@5B=KE 40==KE, B0:8E, :0: 70: @KBK5 :;NG8, 4;O ?@54>B2@0I5=8O =5A0=:F8>=8@>20==>3> 4>ABC?0 A;C61, ?@>F5AA>2 8; 8 ?>;L7>20B5;59." [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\grbim\Parameters] "ServiceDll"=str(2):"C:\WINDOWS.0\system32\ohrgpcx.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares] "vTask$"=str(7):"CSCFlags=0\0MaxUses=4294967295\0Path=C:\WINDOWS.0\TEMP\Task\0Pe rmissions=0\0Remark=\0Type=0\0" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:2df9c43f "s2"=dword:110480d0 "h0"=dword:00000002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA 3CF1058D9A64CEC] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000001 "hdf12"=hex:ff,80,75,cd,14,9a,7e,34,df,b1,1d,22,3c,df,c8,2f,de,68,b6,2c,9c,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA 3CF1058D9A64CEC\00000001] "a0"=hex:20,01,00,00,5f,7f,30,66,62,d8,33,81,7b,ae,7f,76,e1,8d,05,da,81,.. "hdf12"=hex:9c,51,57,4b,60,19,1a,c3,d7,ac,e1,55,a0,78,ee,39,ae,17,24,85,53,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA 3CF1058D9A64CEC\00000001\gdq0] "hdf12"=hex:24,a4,c5,47,98,a2,0b,76,8c,6a,bb,1c,aa,c9,45,af,05,65,4d,f9,5d,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E36468 2FA4BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000000 "khjeh"=hex:50,c6,f3,14,cb,b3,99,c3,b8,ec,6a,f9,b0,14,ee,1c,2b,68,a0,4a,20,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E36468 2FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,92,3e,19,f7,6a,12,3a,dc,6e,e9,b1,b0,d2,7c,0f,6b,24,.. "khjeh"=hex:b0,2e,c7,fb,b2,5c,a9,25,86,18,1d,c1,13,ad,55,5b,e2,50,33,a5,97,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E36468 2FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:7b,c5,0d,89,70,04,54,a7,d7,99,27,b1,40,04,be,8a,49,ff,bb,9b,d3,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC 1-08002BE10318}\Descriptions] "\34\48\4=\48\4?\4>\4@\4B\4 ??\4;\0040\4=\48\4@\4>\0042\4I\48\4:\0040\4 ??\0040\ 4:\0045\4B\4>\0042\4"=str(7):"1\0002\0003\0004\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?L?2?T?P?)?"=str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?P?P?T?P?)?"=str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?P?P?P?o?E?)?"=str(7):"1\0" "\37\4@\4O\4<\4>\49\4 ??\0040\4@\0040\4;\4;\0045\4;\4L\4=\4K\49\4 ??\4>\4@\4B\4" =str(7):"1\0" "\34\48\4=\48\4?\4>\4@\4B\4 ?W?A?N? ?(?I?P?)?"=str(7):"1\0" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\grbim] "DisplayName"="Helper Manager" "Type"=dword:00000020 "Start"=dword:00000002 "ErrorControl"=dword:00000000 "ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Description"="▲15A?5G8205B 70I8I5==>5 E@0=5=85 A5:@5B=KE 40==KE, B0:8E, :0: 70: @KBK5 :;NG8, 4;O ?@54>B2@0I5=8O =5A0=:F8>=8@>20==>3> 4>ABC?0 A;C61, ?@>F5AA>2 8; 8 ?>;L7>20B5;59." [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\grbim\Parameters] "ServiceDll"=str(2):"C:\WINDOWS.0\system32\ohrgpcx.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1 058D9A64CEC] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000001 "hdf12"=hex:ff,80,75,cd,14,9a,7e,34,df,b1,1d,22,3c,df,c8,2f,de,68,b6,2c,9c,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1 058D9A64CEC\00000001] "a0"=hex:20,01,00,00,5f,7f,30,66,62,d8,33,81,7b,ae,7f,76,e1,8d,05,da,81,.. "hdf12"=hex:9c,51,57,4b,60,19,1a,c3,d7,ac,e1,55,a0,78,ee,39,ae,17,24,85,53,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1 058D9A64CEC\00000001\gdq0] "hdf12"=hex:24,a4,c5,47,98,a2,0b,76,8c,6a,bb,1c,aa,c9,45,af,05,65,4d,f9,5d,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4 BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools Lite\" "h0"=dword:00000000 "khjeh"=hex:50,c6,f3,14,cb,b3,99,c3,b8,ec,6a,f9,b0,14,ee,1c,2b,68,a0,4a,20,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4 BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,92,3e,19,f7,6a,12,3a,dc,6e,e9,b1,b0,d2,7c,0f,6b,24,.. "khjeh"=hex:b0,2e,c7,fb,b2,5c,a9,25,86,18,1d,c1,13,ad,55,5b,e2,50,33,a5,97,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4 BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:7b,c5,0d,89,70,04,54,a7,d7,99,27,b1,40,04,be,8a,49,ff,bb,9b,d3,.. scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Curs ors\Schemes] "!\4B\0040\4=\0044\0040\4@\4B\4=\0040\4O\4 ?W?i?n?d?o?w?s?"="",,,,,,,,,,,,,"" "\37\4>\0044\0042\48\0046\4=\0040\4O\4 ?W?i?n?d?o?w?s?"=""C:\WINDOWS.0\Cursors\r ainbow.ani,,C:\WINDOWS.0\Cursors\appstart.ani,C:\WINDOWS.0\Cursors\hourglas.ani, C:\WINDOWS.0\Cursors\cross.cur,,,,C:\WINDOWS.0\Cursors\sizens.ani,C:\WINDOWS.0\C ursors\sizewe.ani,C:\WINDOWS.0\Cursors\sizenwse.ani,C:\WINDOWS.0\Cursors\sizenes w.ani,,"" "\36\0041\4J\0045\4<\4=\0040\4O\4 ?1\0045\4;\0040\4O\4"=""C:\WINDOWS.0\Cursors\3 dwarro.cur,,C:\WINDOWS.0\Cursors\appstar3.ani,C:\WINDOWS.0\Cursors\hourgla3.ani, C:\WINDOWS.0\Cursors\cross.cur,,,C:\WINDOWS.0\Cursors\3dwno.cur,C:\WINDOWS.0\Cur sors\3dwns.cur,C:\WINDOWS.0\Cursors\3dwwe.cur,C:\WINDOWS.0\Cursors\3dwnwse.cur,C :\WINDOWS.0\Cursors\3dwnesw.cur,C:\WINDOWS.0\Cursors\3dwmove.cur,"" " \4C\4:\48\4 ?1?"=""C:\WINDOWS.0\Cursors\harrow.cur,,C:\WINDOWS.0\Cursors\handa pst.ani,C:\WINDOWS.0\Cursors\hand.ani,C:\WINDOWS.0\Cursors\hcross.cur,C:\WINDOWS .0\Cursors\hibeam.cur,,C:\WINDOWS.0\Cursors\hnodrop.cur,C:\WINDOWS.0\Cursors\hns .cur,C:\WINDOWS.0\Cursors\hwe.cur,C:\WINDOWS.0\Cursors\hnwse.cur,C:\WINDOWS.0\Cu rsors\hnesw.cur,C:\WINDOWS.0\Cursors\hmove.cur,"" " \4C\4:\48\4 ?2?"=""C:\WINDOWS.0\Cursors\harrow.cur,,C:\WINDOWS.0\Cursors\handa pst.ani,C:\WINDOWS.0\Cursors\handwait.ani,C:\WINDOWS.0\Cursors\hcross.cur,C:\WIN DOWS.0\Cursors\hibeam.cur,,C:\WINDOWS.0\Cursors\handno.ani,C:\WINDOWS.0\Cursors\ handns.ani,C:\WINDOWS.0\Cursors\handwe.ani,C:\WINDOWS.0\Cursors\handnwse.ani,C:\ WINDOWS.0\Cursors\handnesw.ani,C:\WINDOWS.0\Cursors\hmove.cur,"" "\24\48\4=\4>\0047\0040\0042\4@\4"=""C:\WINDOWS.0\Cursors\3dgarro.cur,,C:\WINDOW S.0\Cursors\dinosaur.ani,C:\WINDOWS.0\Cursors\dinosau2.ani,C:\WINDOWS.0\Cursors\ cross.cur,,,C:\WINDOWS.0\Cursors\banana.ani,C:\WINDOWS.0\Cursors\3dsns.cur,C:\WI NDOWS.0\Cursors\3dgwe.cur,C:\WINDOWS.0\Cursors\3dsnwse.cur,C:\WINDOWS.0\Cursors\ 3dgnesw.cur,C:\WINDOWS.0\Cursors\3dsmove.cur,"" "\22\4 ?A\4B\0040\4@\4>\4<\4 ?A\4B\48\4;\0045\4"=""C:\WINDOWS.0\Cursors\harrow.c ur,,C:\WINDOWS.0\Cursors\horse.ani,C:\WINDOWS.0\Cursors\barber.ani,C:\WINDOWS.0\ Cursors\hcross.cur,C:\WINDOWS.0\Cursors\hibeam.cur,,C:\WINDOWS.0\Cursors\coin.an i,C:\WINDOWS.0\Cursors\3dgns.cur,C:\WINDOWS.0\Cursors\3dgwe.cur,C:\WINDOWS.0\Cur sors\3dgnwse.cur,C:\WINDOWS.0\Cursors\3dgnesw.cur,C:\WINDOWS.0\Cursors\3dgmove.c ur,"" "\24\48\4@\48\0046\0045\4@\4"=""C:\WINDOWS.0\Cursors\harrow.cur,,C:\WINDOWS.0\Cu rsors\drum.ani,C:\WINDOWS.0\Cursors\metronom.ani,C:\WINDOWS.0\Cursors\hcross.cur ,C:\WINDOWS.0\Cursors\hibeam.cur,,C:\WINDOWS.0\Cursors\piano.ani,C:\WINDOWS.0\Cu rsors\hns.cur,C:\WINDOWS.0\Cursors\hwe.cur,C:\WINDOWS.0\Cursors\hnwse.cur,C:\WIN DOWS.0\Cursors\hnesw.cur,C:\WINDOWS.0\Cursors\hmove.cur,"" "#\0042\0045\4;\48\4G\0045\4=\4=\0040\4O\4"=""C:\WINDOWS.0\Cursors\larrow.cur,,C :\WINDOWS.0\Cursors\lappstrt.cur,C:\WINDOWS.0\Cursors\lwait.cur,C:\WINDOWS.0\Cur sors\lcross.cur,C:\WINDOWS.0\Cursors\libeam.cur,,C:\WINDOWS.0\Cursors\lnodrop.cu r,C:\WINDOWS.0\Cursors\lns.cur,C:\WINDOWS.0\Cursors\lwe.cur,C:\WINDOWS.0\Cursors \lnwse.cur,C:\WINDOWS.0\Cursors\lnesw.cur,C:\WINDOWS.0\Cursors\lmove.cur,"" "\22\0040\4@\48\0040\4F\48\48\4"=""C:\WINDOWS.0\Cursors\fillitup.ani,,C:\WINDOWS .0\Cursors\raindrop.ani,C:\WINDOWS.0\Cursors\counter.ani,C:\WINDOWS.0\Cursors\cr oss.cur,,,C:\WINDOWS.0\Cursors\wagtail.ani,C:\WINDOWS.0\Cursors\sizens.ani,C:\WI NDOWS.0\Cursors\sizewe.ani,C:\WINDOWS.0\Cursors\sizenwse.ani,C:\WINDOWS.0\Cursor s\sizenesw.ani,"" "\36\0041\4J\0045\4<\4=\0040\4O\4 ?1\4@\4>\4=\0047\4>\0042\0040\4O\4"=""C:\WINDO WS.0\Cursors\3dgarro.cur,,C:\WINDOWS.0\Cursors\appstar2.ani,C:\WINDOWS.0\Cursors \hourgla2.ani,C:\WINDOWS.0\Cursors\cross.cur,,,C:\WINDOWS.0\Cursors\3dgno.cur,C: \WINDOWS.0\Cursors\3dgns.cur,C:\WINDOWS.0\Cursors\3dgwe.cur,C:\WINDOWS.0\Cursors \3dgnwse.cur,C:\WINDOWS.0\Cursors\3dgnesw.cur,C:\WINDOWS.0\Cursors\3dgmove.cur," " "'\0045\4@\4=\0040\4O\4 ?"="C:\WINDOWS.0\cursors\arrow_r.cur,C:\WINDOWS.0\cursor s\help_r.cur,C:\WINDOWS.0\cursors\wait_r.cur,C:\WINDOWS.0\cursors\busy_r.cur,C:\ WINDOWS.0\cursors\cross_r.cur,C:\WINDOWS.0\cursors\beam_r.cur,C:\WINDOWS.0\curso rs\pen_r.cur,C:\WINDOWS.0\cursors\no_r.cur,C:\WINDOWS.0\cursors\size4_r.cur,C:\W INDOWS.0\cursors\size3_r.cur,C:\WINDOWS.0\cursors\size2_r.cur,C:\WINDOWS.0\curso rs\size1_r.cur,C:\WINDOWS.0\cursors\move_r.cur,C:\WINDOWS.0\cursors\up_r.cur" "'\0045\4@\4=\0040\4O\4 ?(?:\4@\4C\4?\4=\0040\4O\4)?"="C:\WINDOWS.0\cursors\arro w_rm.cur,C:\WINDOWS.0\cursors\help_rm.cur,C:\WINDOWS.0\cursors\wait_rm.cur,C:\WI NDOWS.0\cursors\busy_rm.cur,C:\WINDOWS.0\cursors\cross_rm.cur,C:\WINDOWS.0\curso rs\beam_rm.cur,C:\WINDOWS.0\cursors\pen_rm.cur,C:\WINDOWS.0\cursors\no_rm.cur,C: \WINDOWS.0\cursors\size4_rm.cur,C:\WINDOWS.0\cursors\size3_rm.cur,C:\WINDOWS.0\c ursors\size2_rm.cur,C:\WINDOWS.0\cursors\size1_rm.cur,C:\WINDOWS.0\cursors\move_ rm.cur,C:\WINDOWS.0\cursors\up_rm.cur" "'\0045\4@\4=\0040\4O\4 ?(?>\0043\4@\4>\4<\4=\0040\4O\4)?"="C:\WINDOWS.0\cursors \arrow_rl.cur,C:\WINDOWS.0\cursors\help_rl.cur,C:\WINDOWS.0\cursors\wait_rl.cur, C:\WINDOWS.0\cursors\busy_rl.cur,C:\WINDOWS.0\cursors\cross_rl.cur,C:\WINDOWS.0\ cursors\beam_rl.cur,C:\WINDOWS.0\cursors\pen_rl.cur,C:\WINDOWS.0\cursors\no_rl.c ur,C:\WINDOWS.0\cursors\size4_rl.cur,C:\WINDOWS.0\cursors\size3_rl.cur,C:\WINDOW S.0\cursors\size2_rl.cur,C:\WINDOWS.0\cursors\size1_rl.cur,C:\WINDOWS.0\cursors\ move_rl.cur,C:\WINDOWS.0\cursors\up_rl.cur" "\30\4=\0042\0045\4@\4A\4=\0040\4O\4"="C:\WINDOWS.0\cursors\arrow_i.cur,C:\WINDO WS.0\cursors\help_i.cur,C:\WINDOWS.0\cursors\wait_i.cur,C:\WINDOWS.0\cursors\bus y_i.cur,C:\WINDOWS.0\cursors\cross_i.cur,C:\WINDOWS.0\cursors\beam_i.cur,C:\WIND OWS.0\cursors\pen_i.cur,C:\WINDOWS.0\cursors\no_i.cur,C:\WINDOWS.0\cursors\size4 _i.cur,C:\WINDOWS.0\cursors\size3_i.cur,C:\WINDOWS.0\cursors\size2_i.cur,C:\WIND OWS.0\cursors\size1_i.cur,C:\WINDOWS.0\cursors\move_i.cur,C:\WINDOWS.0\cursors\u p_i.cur" "\30\4=\0042\0045\4@\4A\4=\0040\4O\4 ?(?:\4@\4C\4?\4=\0040\4O\4)?"="C:\WINDOWS.0 \cursors\arrow_im.cur,C:\WINDOWS.0\cursors\help_im.cur,C:\WINDOWS.0\cursors\wait _im.cur,C:\WINDOWS.0\cursors\busy_im.cur,C:\WINDOWS.0\cursors\cross_im.cur,C:\WI NDOWS.0\cursors\beam_im.cur,C:\WINDOWS.0\cursors\pen_im.cur,C:\WINDOWS.0\cursors \no_im.cur,C:\WINDOWS.0\cursors\size4_im.cur,C:\WINDOWS.0\cursors\size3_im.cur,C :\WINDOWS.0\cursors\size2_im.cur,C:\WINDOWS.0\cursors\size1_im.cur,C:\WINDOWS.0\ cursors\move_im.cur,C:\WINDOWS.0\cursors\up_im.cur" "\30\4=\0042\0045\4@\4A\4=\0040\4O\4 ?(?>\0043\4@\4>\4<\4=\0040\4O\4)?"="C:\WIND OWS.0\cursors\arrow_il.cur,C:\WINDOWS.0\cursors\help_il.cur,C:\WINDOWS.0\cursors \wait_il.cur,C:\WINDOWS.0\cursors\busy_il.cur,C:\WINDOWS.0\cursors\cross_il.cur, C:\WINDOWS.0\cursors\beam_il.cur,C:\WINDOWS.0\cursors\pen_il.cur,C:\WINDOWS.0\cu rsors\no_il.cur,C:\WINDOWS.0\cursors\size4_il.cur,C:\WINDOWS.0\cursors\size3_il. cur,C:\WINDOWS.0\cursors\size2_il.cur,C:\WINDOWS.0\cursors\size1_il.cur,C:\WINDO WS.0\cursors\move_il.cur,C:\WINDOWS.0\cursors\up_il.cur" "!\4B\0040\4=\0044\0040\4@\4B\4=\0040\4O\4 ?(?:\4@\4C\4?\4=\0040\4O\4)?"="C:\WIN DOWS.0\cursors\arrow_m.cur,C:\WINDOWS.0\cursors\help_m.cur,C:\WINDOWS.0\cursors\ wait_m.cur,C:\WINDOWS.0\cursors\busy_m.cur,C:\WINDOWS.0\cursors\cross_m.cur,C:\W INDOWS.0\cursors\beam_m.cur,C:\WINDOWS.0\cursors\pen_m.cur,C:\WINDOWS.0\cursors\ no_m.cur,C:\WINDOWS.0\cursors\size4_m.cur,C:\WINDOWS.0\cursors\size3_m.cur,C:\WI NDOWS.0\cursors\size2_m.cur,C:\WINDOWS.0\cursors\size1_m.cur,C:\WINDOWS.0\cursor s\move_m.cur,C:\WINDOWS.0\cursors\up_m.cur" "!\4B\0040\4=\0044\0040\4@\4B\4=\0040\4O\4 ?(?>\0043\4@\4>\4<\4=\0040\4O\4)?"="C :\WINDOWS.0\cursors\arrow_l.cur,C:\WINDOWS.0\cursors\help_l.cur,C:\WINDOWS.0\cur sors\wait_l.cur,C:\WINDOWS.0\cursors\busy_l.cur,C:\WINDOWS.0\cursors\cross_l.cur ,C:\WINDOWS.0\cursors\beam_l.cur,C:\WINDOWS.0\cursors\pen_l.cur,C:\WINDOWS.0\cur sors\no_l.cur,C:\WINDOWS.0\cursors\size4_l.cur,C:\WINDOWS.0\cursors\size3_l.cur, C:\WINDOWS.0\cursors\size2_l.cur,C:\WINDOWS.0\cursors\size1_l.cur,C:\WINDOWS.0\c ursors\move_l.cur,C:\WINDOWS.0\cursors\up_l.cur" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Sidebar] "\30\0047\0044\0040\4B\0045\4;\4L\4"="→>@?>@0F8O ∟09:@>A>DB" source file error: C:\Documents and Settings\Admin\ntuser.dat scanning hidden files ... C:\Users\Admin\Local Settings\Application Data\Opera\Opera\cache\sesn\opr00A0F.t mp 169 bytes scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 1
вот hosts
читать дальше »
# (C) Корпорация Майкрософт (Microsoft Corp.), 1993-1999 # # Это образец файла HOSTS, используемый Microsoft TCP/IP для Windows. # # Этот файл содержит сопоставления IP-адресов именам узлов. # Каждый элемент должен располагаться в отдельной строке. IP-адрес должен # находиться в первом столбце, за ним должно следовать соответствующее имя. # IP-адрес и имя узла должны разделяться хотя бы одним пробелом. # # Кроме того, в некоторых строках могут быть вставлены комментарии # (такие, как эта строка), они должны следовать за именем узла и отделяться # от него символом '#'. # # Например: # # 102.54.94.97 rhino.acme.com # исходный сервер # 38.25.63.10 x.acme.com # узел клиента x 127.0.0.1 localhost
|