[more] [more]
Цитата: смотреть лучше этим ProcessMonitor
Абсолютно все процессы под названием "explorer.exe"
И как это понимать и что с этой программой делать я не знаю)
Лог HijackThis
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:35:08, on 14.07.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\SOUNDMAN.EXE
C:\Users\Djedai\AppData\Local\MailRu\MailRuUpdater.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Djedai\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sweet-page.com/?type=hp&ts=1399987573&from=cor&uid=395049983_266162_C8B6110F R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://mail.ru/cnt/10445?gp=newcustom1 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sweet-page.com/?type=hp&ts=1399987573&from=cor&uid=395049983_266162_C8B6110F R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.sweet-page.com/web/?type=ds&ts=1399987573&from=cor&uid=395049983_266162_C8B6110F&q={searchTerms} R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.sweet-page.com/web/?type=ds&ts=1399987573&from=cor&uid=395049983_266162_C8B6110F&q={searchTerms} R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.sweet-page.com/?type=hp&ts=1399987573&from=cor&uid=395049983_266162_C8B6110F R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [VKSaver] C:\ProgramData\VKSaver\VKSaver.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [MailRuUpdater] C:\Users\Djedai\AppData\Local\MailRu\MailRuUpdater.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Djedai\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: C:\Program Files\SupTab\SearchProtect32.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - (no file)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Служба Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Служба Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Update webget - Unknown owner - C:\Program Files\webget\updatewebget.exe (file missing)
--
End of file - 4680 bytes
[/more] [/more]
Добавлено: [more] Лог UVS полностью состоит из этого
>4?8AL V 59AB28B5;L=0, ?>4?8A0=> M i c r o s o f t W i n d o w s " @838=0;L=>5 8<O C B V A . d l l . m u i 5@A8O D09;0 L 6 . 1 . 7 6 0 0 . 1 6 3 8 5 ( w i n 7 _ r t m . 0 9 0 7 1 3 - 1 2 5 5 ) ?8A0=85 h W i n d o w s M e d i a C e n t e r C o n t e n t A n a l y s i s F i l t e r M o d u l e @>872>48B5;L , M i c r o s o f t C o r p o r a t i o n >?. 8=D>@<0F8O 8 =0 <><5=B >1=>2;5=8O A?8A:0
S H A 1 R 8 9 7 0 D F F 9 7 7 1 2 6 5 6 B 2 D 3 4 B 9 1 2 8 A 0 3 6 8 E E 3 D E 2 B 3 E E M D 5 B 9 D 7 F B 5 0 9 F A 7 D B 3 8 E 1 9 7 4 9 2 F C 3 E 2 1 0 8 E 6 " !AK;:8 =0 >1J5:B !AK;:0 т H K L M \ S o f t w a r e \ C l a s s e s \ C L S I D \ { 0 8 3 8 6 3 F 1 - 7 0 D E - 1 1 d 0 - B D 4 0 - 0 0 A 0 C 9 1 1 C E 8 6 } \ I n s t a n c e \ { 3 1 C 8 8 F F 0 - 2 1 1 1 - 4 4 B D - A 1 2 1 - 6 1 D E 9 C D 0 4 1 2 D } \ C L S I D !AK;:0 ¦ H K L M \ S o f t w a r e \ C l a s s e s \ C L S I D \ { 3 1 C 8 8 F F 0 - 2 1 1 1 - 4 4 B D - A 1 2 1 - 6 1 D E 9 C D 0 4 1 2 D } \ I n p r o c S e r v e r 3 2 \ @Сшъ€Л‹яU‹мѓ}uиБ ]й‰эяяММММММhЄЯЅdя5 ‹D$‰l$Ќl$+аSVWЎ°1ї1E V B I C O D E C . A X ( C : \ W I N D O W S \ S Y S T E M 3 2 , M i c r o s o f t C o r p o r a t i o n H >;=>5 8<O @ C : \ W I N D O W S \ S Y S T E M 3 2 \ V B I C O D E C . A X <O D09;0 V B I C O D E C . A X !B0BCA J !"+ + 2 02B>70?CA:5 F i l e _ I d 4 C E 7 B A 1 C 2 9 0 0 0 L i n k e r 9 . 0 07<5@ 1 5 3 6 0 0 109B !>740= , 2 0 . 1 1 . 2 0 1 0 2 2 1 : 2 9 : 3 8 7<5=5= , 2 0 . 1 1 . 2 0 1 0 2 2 1 : 2 9 : 3 8 "8? D09;0 0 3 2 - E 18B=K9 !/+ &8D@. ?>4?8AL V 59AB28B5;L=0, ?>4?8A0=> M i c r o s o f t W i n d o w s " @838=0;L=>5 8<O V B I C o d e c . a x 5@A8O D09;0 R 6 . 6 . 7 6 0 1 . 1 7 5 1 4 ( w i n 7 s p 1 _ r t m . 1 0 1 1 1 9 - 1 8 5 0 ) ?8A0=85 ( M i c r o s o f t V B I C o d e c @>872>48B5;L , M i c r o s o f t C o r p o r a t i o n >?. 8=D>@<0F8O 8 =0 <><5=B >1=>2;5=8O A?8A:0
S H A 1 R C 4 1 B B F 0 2 C 7 4 C 8 F 3 9 A 8 3 2 4 0 E 3 E B 2 3 4 5 B 3 9 8 5 0 D 5 7 C M D 5 B 4 D 6 2 6 2 D 5 C F F A 7 D 9 3 2 1 2 6 D 2 B 8 5 C 3 7 3 F 8 7 " !AK;:8 =0 >1J5:B !AK;:0 т H K L M \ S o f t w a r e \ C l a s s e s \ C L S I D \ { 0 8 3 8 6 3 F 1 - 7 0 D E - 1 1 d 0 - B D 4 0 - 0 0 A 0 C 9 1 1 C E 8 6 } \ I n s t a n c e \ { 3 7 0 A 1 D 5 D - D D E B - 4 1 8 C - 8 1 C D - 1 8 9 E 0 D 4 F A 4 4 3 } \ C L S I D !AK;:0 ¦ H K L M \ S o f t w a r e \ C l a s s e s \ C L S I D \ { 3 7 0 A 1 D 5 D - D D E B - 4 1 8 C - 8 1 C D - 1 8 9 E 0 D 4 F A 4 4 3 } \ I n p r o c S e r v e r 3 2 \ @P|оъ€Л‹яU‹мѓ}uи ]й тяяђђђђђ‹яU‹мѓмЎ пѓeш ѓeь SWїNж@»» яя;З„ C C A . D L L ( C : \ W I N D O W S \ S Y S T E M 3 2 , M i c r o s o f t C o r p o r a t i o n ¬ >;=>5 8<O 8 C : \ W I N D O W S \ S Y S T E M 3 2 \ C C A . D L L <O D09;0 C C A . D L L !B0BCA J !"+ + 2 02B>70?CA:5 F i l e _ I d 4 C E 7 B 7 7 2 1 3 0 0 0 L i n k e r 9 . 0 07<5@ 6 6 5 6 0 109B !>740= , 2 0 . 1 1 . 2 0 1 0 2 2 1 : 2 9 : 3 8 7<5=5= , 2 0 . 1 1 . 2 0 1 0 2 2 1 : 2 9 : 3 8 "8? D09;0 0 3 2 - E 18B=K9 !/+ &8D@. ?>4?8AL V 59AB28B5;L=0, ?>4?8 [/more]