Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Имам вирус, вероятно от социална мрежа, но май не е сам...

Featured Replies

Здравейте, Изчетох почти всички теми свързани с тази и се надявам да помогнете и на мен, за което предварително Ви благодаря! Нямам инсталационен диск на Windows. McAffee ми дава предупреждение "ENHANCED PROTECTION MODE",а в Control Panel не го намирам за Uninstall. Системата ми казва, че PCто е защитено с AVG Antivirus Free, но и тази програма я няма в Контолпанела. Изтеглих си DDS, но сканира повече от 10 минути без резултат. Сега какво мога да направя?

Здравейте,

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива. За целта може да прегледате информацията от този линк: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

Забележка: При проблеми с ComboFix копирайте с (Copy) и поставете с (Paste) съдържанието на C:\BUG.txt в следващия си коментар.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

  • Автор

Изтеглих програмата ComboFix. Стартирах я. Искаше да инсталирам Windows Recovery Console, инсталира се без проблем. Стартирах сканиране, но PCто замря. На екрана пишеше че сканирането не трябва да отнеме повече от 10 минути, аз изчаках 25, но не ми даде *.txt файл.

В C:\ също няма файл с име BUG.txt.

Какво следва сега?

  • Изтеглете Публикувано изображение и го запазете на вашия десктоп.
  • Стартирайте програмата и изберете 2. Натиснете Enter
  • Ще се появи лог файл с името RKreport[1].txt на вашия десктоп.
  • Копирайте съдържанието му в следващия си пост.
  • Автор

Ето съдържанието на файла: RogueKiller V5.2.8 [07/23/2011] by Tigzy contact at http://www.sur-la-toile.com mail: tigzyRK<at>gmail<dot>com Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User: Laptop [Admin rights] Mode: Remove -- Date : 07/29/2011 19:09:07 Bad processes: 10 [sVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED [sUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED [sVCHOST] svchost.exe -- c:\windows\update.2\svchost.exe -> KILLED [sUSP PATH] systemup.exe -- c:\windows\systemup.exe -> KILLED [sVCHOST] svchost.exe -- c:\windows\update.tray-9-0\svchost.exe -> KILLED [sVCHOST] svchost.exe -- c:\windows\update.tray-12-0\svchost.exe -> KILLED [sUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED [sUSP PATH] stsystra.exe -- c:\windows\stsystra.exe -> KILLED [sUSP PATH] l1rezerv.exe -- c:\windows\l1rezerv.exe -> KILLED [RESIDUE] systemup.exe -- c:\windows\systemup.exe -> KILLED Registry Entries: 17 [sUSP PATH] HKLM\[...]\Run : wxpdrv (C:\WINDOWS\services32.exe) -> DELETED [sUSP PATH] HKLM\[...]\Run : systemup ("C:\WINDOWS\systemup.exe" stand) -> DELETED [sUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\WINDOWS\sysdriver32_.exe" rezerv) -> DELETED [sUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\WINDOWS\sysdriver32.exe" rezerv) -> DELETED [sUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("C:\WINDOWS\l1rezerv.exe") -> DELETED [sUSP PATH] HKLM\[...]\Run : 7216617.exe ("C:\WINDOWS\TEMP\7216617.exe") -> DELETED [sUSP PATH] HKLM\[...]\Run : 44961623-loader2.exe ("C:\WINDOWS\TEMP\44961623-loader2.exe") -> DELETED [sUSP PATH] HKLM\[...]\Run : 4246532.exe ("C:\WINDOWS\TEMP\4246532.exe") -> DELETED [sUSP PATH] HKLM\[...]\Run : 2282689.exe ("C:\DOCUME~1\Laptop\LOCALS~1\Temp\2282689.exe") -> DELETED [sUSP PATH] HKLM\[...]\Run : 1117208.exe ("C:\DOCUME~1\Laptop\LOCALS~1\Temp\1117208.exe") -> DELETED [sUSP PATH] HKLM\[...]\Run : 4984345.exe ("C:\WINDOWS\TEMP\4984345.exe") -> DELETED [] HKLM\[...]\Windows : () -> ACCESS DENIED [HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0) [HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0) [HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0) [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0) [] HKLM\[...]\Windows : () -> ACCESS DENIED HOSTS File: 127.0.0.1 localhost 127.0.0.1 vkontakte.ru 127.0.0.1 www.vkontakte.ru 127.0.0.1 login.vk.com 127.0.0.1 vk.com 127.0.0.1 www.vk.com 127.0.0.1 odnoklassniki.ru 127.0.0.1 www.odnoklassniki.ru 127.0.0.1 facebook.com 127.0.0.1 www.facebook.com 127.0.0.1 af-za.facebook.com 127.0.0.1 az-az.facebook.com 127.0.0.1 id-id.facebook.com 127.0.0.1 ms-my.facebook.com 127.0.0.1 bs-ba.facebook.com 127.0.0.1 ca-es.facebook.com 127.0.0.1 cs-cz.facebook.com 127.0.0.1 cy-gb.facebook.com 127.0.0.1 da-dk.facebook.com 127.0.0.1 de-de.facebook.com [...] Finished : << RKreport[1].txt >> RKreport[1].txt

Така...стартирайте програмата още веднъж, но този път изберете 3 и натиснете Enter.

Сега пробвайте да изтеглите и стартирате Combofix отново.

  • Автор

Ето файла след натискане на 3, сега схте пробвам Combofix отново.

RogueKiller V5.2.8 [07/23/2011] by Tigzy

contact at http://www.sur-la-toile.com

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Laptop [Admin rights]

Mode: HOSTSFix -- Date : 07/29/2011 20:13:51

Bad processes: 6

[sVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED

[sUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED

[sVCHOST] svchost.exe -- c:\windows\update.2\svchost.exe -> KILLED

[sVCHOST] svchost.exe -- c:\windows\update.tray-9-0\svchost.exe -> KILLED

[sVCHOST] svchost.exe -- c:\windows\update.tray-12-0\svchost.exe -> KILLED

[sUSP PATH] stsystra.exe -- c:\windows\stsystra.exe -> KILLED

HOSTS File:

127.0.0.1 localhost

127.0.0.1 vkontakte.ru

127.0.0.1 www.vkontakte.ru

127.0.0.1 login.vk.com

127.0.0.1 vk.com

127.0.0.1 www.vk.com

127.0.0.1 odnoklassniki.ru

127.0.0.1 www.odnoklassniki.ru

127.0.0.1 facebook.com

127.0.0.1 www.facebook.com

127.0.0.1 af-za.facebook.com

127.0.0.1 az-az.facebook.com

127.0.0.1 id-id.facebook.com

127.0.0.1 ms-my.facebook.com

127.0.0.1 bs-ba.facebook.com

127.0.0.1 ca-es.facebook.com

127.0.0.1 cs-cz.facebook.com

127.0.0.1 cy-gb.facebook.com

127.0.0.1 da-dk.facebook.com

127.0.0.1 de-de.facebook.com

[...]

Resetted HOSTS:

127.0.0.1 localhost

Finished : << RKreport[2].txt >>

RKreport[1].txt ; RKreport[2].txt

  • Автор

За съжаление Combofix не сработи...

Мод едит:

едитнат коментар от латиница на кирилица

Ок, ще опитаме с друг инструмент и моля пишете на КИРИЛИЦА !

  • Изтеглете OTL.exe и го запазете на десктопа.
  • Стартирайте файла Публикувано изображение с двукратен клик на мишката.
  • Сложете отметка пред Scan All Users Публикувано изображение
  • Под менюто File Age => изберете 90 days
  • Под менюто Standard Registry => променете на ALL
  • Сложете отметки пред LOP, Purity Check и Skip Microsoft Files
  • Под Публикувано изображение с Copy/ Paste въведете следната текстова информация:
netsvcs
msconfig
safebootminimal
safebootnetwork
%SYSTEMDRIVE%\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Application Data\*.*
%USERPROFILE%\Local Settings\Application Data\*.*
%AllUsersProfile%\*.*
%AllUsersProfile%\Application Data\*.*
%USERPROFILE%\My Documents\*.*
%CommonProgramFiles%\*.*
%PROGRAMFILES%\*.*
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
/md5start
hlp.dat
winlogon.exe
wininit.exe
userinit.exe
explorer.exe
volsnap.sys
/md5stop
  • Натиснете маркираният в синьо бутон: Публикувано изображение.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt.
  • Публикувайте съдържанието на лог файловете в следващия си коментар.
  • Автор

Извинявам се за латиницата преди малко... Няма да се повтори! Ето и данните от двата лог файла: OTL.Txt Extras.Txt Забелязах също така, че в Task Manager'а има ufa.exe което товари процесора почти на 100%, незнам дали е от значение, но реших да го споделя.

Извинявам се за забавянето, но имах гости:

Стартирайте отново OTL, копирайте (Copy) и поставете (Paste) скриптовия текст от текстовото поле по-долу под колонката Custom Scans/Fixes, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта.

:OTL
PRC - [2011.07.27 18:28:45 | 000,502,272 | ---- | M] () -- C:\WINDOWS\update.2\svchost.exe
PRC - [2011.07.27 18:28:45 | 000,502,272 | ---- | M] () -- C:\WINDOWS\update.2\svchost.exe
PRC - [2011.07.26 02:36:20 | 000,348,672 | ---- | M] () -- C:\WINDOWS\update.5.0\svchost.exe
PRC - [2011.07.26 02:36:20 | 000,348,672 | ---- | M] () -- C:\WINDOWS\update.5.0\svchost.exe
PRC - [2011.07.25 18:14:12 | 000,256,000 | ---- | M] () -- C:\WINDOWS\sysdriver32.exe
PRC - [2011.07.25 17:58:03 | 001,185,280 | -H-- | M] () -- C:\WINDOWS\update.tray-9-0\svchost.exe
PRC - [2011.07.25 17:58:03 | 001,185,280 | -H-- | M] () -- C:\WINDOWS\update.tray-12-0\svchost.exe
PRC - [2011.07.25 17:58:03 | 001,185,280 | -H-- | M] () -- C:\WINDOWS\update.1\svchost.exe
SRV - File not found [Auto | Stopped] --  -- (PEVSystemStart)
SRV - File not found [On_Demand | Stopped] --  -- (McComponentHostService)
SRV - File not found [Auto | Stopped] --  -- (avg8wd)
SRV - File not found [Auto | Stopped] --  -- (avg8emc)
SRV - File not found [On_Demand | Stopped] --  -- (AVG Security Toolbar Service)
SRV - [2011.07.27 18:28:45 | 000,502,272 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.2\svchost.exe -- (srviecheck)
SRV - [2011.07.26 02:36:20 | 000,348,672 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update.5.0\svchost.exe -- (srvbtcclient)
SRV - [2011.07.25 18:14:12 | 000,256,000 | ---- | M] () [Auto | Running] -- C:\WINDOWS\sysdriver32.exe -- (srvsysdriver32)
SRV - [2011.07.25 17:58:03 | 001,185,280 | -H-- | M] () [Auto | Running] -- C:\WINDOWS\update.1\svchost.exe -- (wxpdrivers)
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} -  File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} -  File not found
IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} -  File not found
IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: [email protected]:3.11.3.15590
[2011.04.30 10:05:28 | 000,002,394 | ---- | M] () -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Firefox\Profiles\95rtjjqc.default\searchplugins\askcom.xml
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  File not found
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} -  File not found
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  File not found
O3 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  File not found
O4 - HKLM..\Run: [Adobe Photo Downloader]  File not found
O4 - HKLM..\Run: [NSLauncher]  File not found
O4 - HKLM..\Run: [SearchSettings]  File not found
O4 - HKLM..\Run: [tray_ico]  File not found
O4 - HKLM..\Run: [tray_ico0] C:\WINDOWS\update.tray-12-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico1] C:\WINDOWS\update.tray-9-0\svchost.exe ()
O4 - HKLM..\Run: [tray_ico2]  File not found
O4 - HKLM..\Run: [tray_ico3]  File not found
O4 - HKLM..\Run: [tray_ico4]  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk =  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SetPoint.lnk =  File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -  File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  File not found
O31 - SafeBoot: AlternateShell - services32.exe
O33 - MountPoints2\{9da11733-75fa-11e0-8116-001422ae49d6}\Shell - "" = AutoRun
O33 - MountPoints2\{9da11733-75fa-11e0-8116-001422ae49d6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9da11733-75fa-11e0-8116-001422ae49d6}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL \RECYCLER\S-2-3-68-1452147148-2010354382-344148443-7787\nVmUqKNl.exe
O33 - MountPoints2\{9da11733-75fa-11e0-8116-001422ae49d6}\Shell\explore\command - "" = \RECYCLER\S-2-3-68-1452147148-2010354382-344148443-7787\nVmUqKNl.exe
O33 - MountPoints2\{9da11733-75fa-11e0-8116-001422ae49d6}\Shell\Open\command - "" = \RECYCLER\S-2-3-68-1452147148-2010354382-344148443-7787\nVmUqKNl.exe
O33 - MountPoints2\{9e9cefa4-7ab1-11e0-8119-001422ae49d6}\Shell - "" = AutoRun
O33 - MountPoints2\{9e9cefa4-7ab1-11e0-8119-001422ae49d6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9e9cefa4-7ab1-11e0-8119-001422ae49d6}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE  	.\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{a6c08f9d-87b3-11df-8087-001422ae49d6}\Shell\AutoRun\command - "" = G:\recycle.{645FF040-5081-101B-9F08-00AA002F954E}\Setup.exe
O33 - MountPoints2\{a6c08f9d-87b3-11df-8087-001422ae49d6}\Shell\explore\Command - "" = G:\recycle.{645FF040-5081-101B-9F08-00AA002F954E}\Setup.exe Show
O33 - MountPoints2\{a6c08f9d-87b3-11df-8087-001422ae49d6}\Shell\open\Command - "" = G:\recycle.{645FF040-5081-101B-9F08-00AA002F954E}\Setup.exe Show
O33 - MountPoints2\{ab19bfe6-a144-11df-8097-001422ae49d6}\Shell\AutoRun\command - "" = G:\wyskq6lt.exe
O33 - MountPoints2\{ab19bfe6-a144-11df-8097-001422ae49d6}\Shell\open\Command - "" = G:\wyskq6lt.exe
O33 - MountPoints2\{e0daef70-2afa-11e0-80ef-001422ae49d6}\Shell\AutoRun\command - "" = G:\fakerica//shmekerica.exe
O33 - MountPoints2\{e0daef70-2afa-11e0-80ef-001422ae49d6}\Shell\Explore\command - "" = G:\fakerica//shmekerica.exe
O33 - MountPoints2\{e0daef70-2afa-11e0-80ef-001422ae49d6}\Shell\Open\command - "" = G:\fakerica//shmekerica.exe
SafeBootMin: wxpdrivers - C:\WINDOWS\update.1\svchost.exe ()
SafeBootNet: wxpdrivers - C:\WINDOWS\update.1\svchost.exe ()
[2011.07.25 18:38:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\ufa
[2011.07.25 18:38:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\rpcminer
[2011.07.25 18:38:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\phoenix
[2011.07.25 18:28:51 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.5.0
[2011.07.25 18:21:09 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.2
[2011.07.25 18:13:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\av_ico
[2011.07.25 18:09:44 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.1
[2011.07.25 18:09:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-9-0-lnk
[2011.07.25 18:09:00 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-9-0
[2011.07.25 18:08:59 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-12-0-lnk
[2011.07.25 18:08:59 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-12-0
[2011.03.06 21:21:50 | 003,056,008 | ---- | C] (Ask) -- C:\Program Files\Common Files\AskToolbarInstaller.exe
[2011.07.27 19:24:42 | 000,000,179 | ---- | M] () -- C:\WINDOWS\info1
[2011.07.25 18:38:09 | 005,589,370 | ---- | M] () -- C:\WINDOWS\phoenix.rar
[2011.07.25 18:38:09 | 000,246,272 | ---- | M] () -- C:\WINDOWS\unrar.exe
[2011.07.25 18:38:09 | 000,182,617 | ---- | M] () -- C:\WINDOWS\ufa.rar
[2011.07.25 18:38:08 | 001,075,284 | ---- | M] () -- C:\WINDOWS\rpcminer.rar
[2011.07.25 18:34:22 | 000,114,176 | ---- | M] () -- C:\WINDOWS\systemup.exe
[2011.07.25 18:26:05 | 000,232,960 | ---- | M] () -- C:\WINDOWS\l1rezerv.exe
[2011.07.25 18:18:53 | 000,904,792 | ---- | M] () -- C:\WINDOWS\geoiplist.rar
[2011.07.25 18:15:11 | 000,000,000 | ---- | M] () -- C:\WINDOWS\loader2.exe_ok
[2011.07.25 18:14:12 | 000,256,000 | ---- | M] () -- C:\WINDOWS\sysdriver32_.exe
[2011.07.25 18:14:12 | 000,256,000 | ---- | M] () -- C:\WINDOWS\sysdriver32.exe
[2011.07.25 17:58:03 | 001,185,280 | ---- | M] () -- C:\WINDOWS\services32.exe
[2011.07.17 03:24:20 | 004,636,907 | ---- | M] () -- C:\WINDOWS\geoiplist
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FD000392
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A53F2207
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A58B27C9
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:98DFF516
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5345C8F6
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E91ADC66
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:78E0DF72
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40D8F125
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:69AF9D20
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4FE42FFC
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:28CDD861
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DE6EED8B
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E9B629B
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallOverride" = 0
"DisableThumbnailCache" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Laptop\My Documents\Downloads\Flash-Player.exe" =-
"C:\WINDOWS\update.1\svchost.exe" =-
"C:\WINDOWS\services32.exe" =-
"C:\WINDOWS\update.tray-12-0\svchost.exe" =-
"C:\WINDOWS\update.tray-9-0\svchost.exe" =-
"C:\WINDOWS\update.2\svchost.exe" =-
:commands
[resethosts]
[emptytemp]
След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix

Windows ще се рестартира и ще се създаде лог файл. Публикувайте съдържанието му с Copy/Paste в следващия си коментар.

  • Автор

Здравейте отново, Копирах скрипта, и Уилдоуса се рестартира, но след това не създаде лог файл, или поне аз незнам къде го е сложил...

  • Автор

Докъто чакам реших да опитам отново, съмнявах се, че не е копирано правилно всичко... Уиндоуса се рестартира, после екрана се включи отново, но беше абсолютно черен. Изчахак около 15 минути, и рестартирах, появи ми се следният лог файл: Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk not found! File\Folder C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SetPoint.lnk not found! Registry entries deleted on Reboot...

Здравейте отново,

Копирах скрипта, и Уилдоуса се рестартира, но след това не създаде лог файл, или поне аз незнам къде го е сложил...

Здравейте,

Проверете в папката C:\_OTL\MovedFiles за лог файла и го копирайте в следващия си пост.

Ако пак не се е получило ще пробваме с друг инструмент, че при вас нещо се закучиха нещата.

  • Автор

Само този файл е там. Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk not found! File\Folder C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SetPoint.lnk not found! Registry entries deleted on Reboot...

Спрете защитата на антивирусната си програма !

Изтеглете The Avenger (от Swandog46) и го запазете на вашия десктоп. Разархивирайте архива на вашия десктоп, отново.

Стартирайте avenger.exe, копирайте следния скрипт и го поставете в текстовото поле на програмата:

Begin copying here:
Drivers to disable:
srviecheck
srvbtcclient
srvsysdriver32
wxpdrivers
PEVSystemStart
McComponentHostService
avg8wd
avg8emc
AVG Security Toolbar Service
 
Drivers to delete:
srviecheck
srvbtcclient
srvsysdriver32
wxpdrivers
PEVSystemStart
McComponentHostService
avg8wd
avg8emc
AVG Security Toolbar Service
 
Files to delete:
C:\Program Files\Common Files\AskToolbarInstaller.exe
C:\WINDOWS\info1
C:\WINDOWS\phoenix.rar
C:\WINDOWS\unrar.exe
C:\WINDOWS\ufa.rar
C:\WINDOWS\rpcminer.rar
C:\WINDOWS\systemup.exe
C:\WINDOWS\l1rezerv.exe
C:\WINDOWS\geoiplist.rar
C:\WINDOWS\loader2.exe_ok
C:\WINDOWS\sysdriver32_.exe
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\services32.exe
C:\WINDOWS\geoiplist
C:\WINDOWS\update.1\svchost.exe
C:\WINDOWS\update.tray-9-0\svchost.exe
C:\WINDOWS\update.tray-12-0\svchost.exe
C:\WINDOWS\update.2\svchost.exe
C:\WINDOWS\update.2\svchost.exe
C:\WINDOWS\update.5.0\svchost.exe
C:\WINDOWS\update.5.0\svchost.exe
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\update.tray-9-0\svchost.exe
C:\WINDOWS\update.tray-12-0\svchost.exe
C:\WINDOWS\update.1\svchost.exe
 
Folders to delete:
C:\WINDOWS\ufa
C:\WINDOWS\rpcminer
C:\WINDOWS\phoenix
C:\WINDOWS\update.5.0
C:\WINDOWS\update.2
C:\WINDOWS\av_ico
C:\WINDOWS\update.1
C:\WINDOWS\update.tray-9-0-lnk
C:\WINDOWS\update.tray-9-0
C:\WINDOWS\update.tray-12-0-lnk
C:\WINDOWS\update.tray-12-0

Бележка: Този скрипт е създаден специално за този потребител. Ако Вие не сте този потребител, НЕ ползвайте този скрипт, защото ной може да повреди сериозно вашата система.

Уверете се, че Scan for rootkits и Automatically disable any rootkits found имат отметки.

Накрая, изберете Execute и при въпрос от страна на програмата, кликнете върху Yes, при което компютър ще се рестартира. След рестартирането, копирайте и поставете съдържанието на лог файла от програмата, намиращ се в C:\avenger.txt в следващия Ви коментар в тази тема.

  • Автор

Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Error: could not open driver "srviecheck" Disablement of driver "srviecheck" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "srvbtcclient" Disablement of driver "srvbtcclient" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "srvsysdriver32" Disablement of driver "srvsysdriver32" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "wxpdrivers" Disablement of driver "wxpdrivers" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "PEVSystemStart" Disablement of driver "PEVSystemStart" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "McComponentHostService" Disablement of driver "McComponentHostService" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "avg8wd" Disablement of driver "avg8wd" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "avg8emc" Disablement of driver "avg8emc" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open driver "AVG Security Toolbar Service" Disablement of driver "AVG Security Toolbar Service" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\srviecheck" not found! Deletion of driver "srviecheck" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\srvbtcclient" not found! Deletion of driver "srvbtcclient" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\srvsysdriver32" not found! Deletion of driver "srvsysdriver32" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\wxpdrivers" not found! Deletion of driver "wxpdrivers" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\PEVSystemStart" not found! Deletion of driver "PEVSystemStart" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\McComponentHostService" not found! Deletion of driver "McComponentHostService" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\avg8wd" not found! Deletion of driver "avg8wd" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\avg8emc" not found! Deletion of driver "avg8emc" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\AVG Security Toolbar Service" not found! Deletion of driver "AVG Security Toolbar Service" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\Program Files\Common Files\AskToolbarInstaller.exe" not found! Deletion of file "C:\Program Files\Common Files\AskToolbarInstaller.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\info1" not found! Deletion of file "C:\WINDOWS\info1" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\phoenix.rar" not found! Deletion of file "C:\WINDOWS\phoenix.rar" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\unrar.exe" not found! Deletion of file "C:\WINDOWS\unrar.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\ufa.rar" not found! Deletion of file "C:\WINDOWS\ufa.rar" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\rpcminer.rar" not found! Deletion of file "C:\WINDOWS\rpcminer.rar" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\systemup.exe" not found! Deletion of file "C:\WINDOWS\systemup.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\l1rezerv.exe" not found! Deletion of file "C:\WINDOWS\l1rezerv.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\geoiplist.rar" not found! Deletion of file "C:\WINDOWS\geoiplist.rar" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\loader2.exe_ok" not found! Deletion of file "C:\WINDOWS\loader2.exe_ok" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\sysdriver32_.exe" not found! Deletion of file "C:\WINDOWS\sysdriver32_.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\sysdriver32.exe" not found! Deletion of file "C:\WINDOWS\sysdriver32.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\services32.exe" not found! Deletion of file "C:\WINDOWS\services32.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\geoiplist" not found! Deletion of file "C:\WINDOWS\geoiplist" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open file "C:\WINDOWS\update.1\svchost.exe" Deletion of file "C:\WINDOWS\update.1\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.tray-9-0\svchost.exe" Deletion of file "C:\WINDOWS\update.tray-9-0\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.tray-12-0\svchost.exe" Deletion of file "C:\WINDOWS\update.tray-12-0\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.2\svchost.exe" Deletion of file "C:\WINDOWS\update.2\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.2\svchost.exe" Deletion of file "C:\WINDOWS\update.2\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.5.0\svchost.exe" Deletion of file "C:\WINDOWS\update.5.0\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.5.0\svchost.exe" Deletion of file "C:\WINDOWS\update.5.0\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: file "C:\WINDOWS\sysdriver32.exe" not found! Deletion of file "C:\WINDOWS\sysdriver32.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open file "C:\WINDOWS\update.tray-9-0\svchost.exe" Deletion of file "C:\WINDOWS\update.tray-9-0\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.tray-12-0\svchost.exe" Deletion of file "C:\WINDOWS\update.tray-12-0\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: could not open file "C:\WINDOWS\update.1\svchost.exe" Deletion of file "C:\WINDOWS\update.1\svchost.exe" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: folder "C:\WINDOWS\ufa" not found! Deletion of folder "C:\WINDOWS\ufa" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\rpcminer" not found! Deletion of folder "C:\WINDOWS\rpcminer" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\phoenix" not found! Deletion of folder "C:\WINDOWS\phoenix" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.5.0" not found! Deletion of folder "C:\WINDOWS\update.5.0" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.2" not found! Deletion of folder "C:\WINDOWS\update.2" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\av_ico" not found! Deletion of folder "C:\WINDOWS\av_ico" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.1" not found! Deletion of folder "C:\WINDOWS\update.1" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.tray-9-0-lnk" not found! Deletion of folder "C:\WINDOWS\update.tray-9-0-lnk" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.tray-9-0" not found! Deletion of folder "C:\WINDOWS\update.tray-9-0" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.tray-12-0-lnk" not found! Deletion of folder "C:\WINDOWS\update.tray-12-0-lnk" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: folder "C:\WINDOWS\update.tray-12-0" not found! Deletion of folder "C:\WINDOWS\update.tray-12-0" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate.

Явно все пак обектите са били изтрити още от OTL, макар да не е създал лог.

Моля, направете нова проверка с OTL както е описано тук и публикувайте лог файла.

  • Автор

Програмата създаде само един файл.

Това е съдържанието на OLT.exe файла:

OTL logfile created on: 01.08.2011 17:21:37 - Run 2

OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\Laptop\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.MM.yyyy

1014.37 Mb Total Physical Memory | 414.11 Mb Available Physical Memory | 40.82% Memory free

3.34 Gb Paging File | 2.89 Gb Available in Paging File | 86.46% Paging File free

Paging file location(s): C:\pagefile.sys 2500 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 24.90 Gb Total Space | 10.60 Gb Free Space | 42.58% Space Free | Partition Type: NTFS

Drive D: | 29.59 Gb Total Space | 5.05 Gb Free Space | 17.08% Space Free | Partition Type: NTFS

Drive F: | 999.63 Mb Total Space | 556.64 Mb Free Space | 55.68% Space Free | Partition Type: FAT

Computer Name: VELOX-LAPTOP | User Name: Laptop | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - [2011.07.29 21:10:03 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Laptop\Desktop\OTL.exe

PRC - [2011.06.22 08:27:15 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2010.09.17 12:14:50 | 000,098,304 | ---- | M] (Firebird Project) -- C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe

PRC - [2010.09.17 12:14:42 | 003,735,552 | ---- | M] (Firebird Project) -- C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe

PRC - [2008.04.14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007.10.08 14:15:50 | 000,356,352 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe

PRC - [2007.10.08 14:09:26 | 000,659,456 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe

PRC - [2006.06.21 20:14:50 | 000,035,328 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe

PRC - [2006.03.24 17:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe

========== Modules (SafeList) ==========

MOD - [2011.07.29 21:10:03 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Laptop\Desktop\OTL.exe

MOD - [2009.07.11 20:41:02 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll

MOD - [2008.07.25 12:17:20 | 000,635,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll

MOD - [2008.04.14 03:12:51 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

MOD - [2008.04.14 03:11:50 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (wuauserv)

SRV - File not found [Disabled | Stopped] -- -- (HidServ)

SRV - [2010.09.17 12:14:50 | 000,098,304 | ---- | M] (Firebird Project) [Auto | Running] -- C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance)

SRV - [2010.09.17 12:14:42 | 003,735,552 | ---- | M] (Firebird Project) [On_Demand | Running] -- C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe -- (FirebirdServerDefaultInstance)

SRV - [2010.01.27 05:09:02 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)

SRV - [2007.10.08 14:15:50 | 000,356,352 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER) Intel®

SRV - [2007.02.08 16:13:46 | 000,212,480 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

========== Driver Services (SafeList) ==========

DRV - [2010.01.27 05:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf)

DRV - [2009.11.17 10:44:54 | 000,105,344 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\jrdusbser.sys -- (jrdusbser)

DRV - [2009.08.20 09:45:25 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)

DRV - [2009.08.20 09:45:25 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)

DRV - [2009.07.27 23:10:06 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)

DRV - [2007.09.26 06:01:32 | 002,236,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel®

DRV - [2007.08.27 11:10:36 | 000,012,288 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)

DRV - [2007.01.17 12:25:12 | 000,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)

DRV - [2006.11.21 04:25:44 | 000,045,568 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)

DRV - [2006.11.15 00:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)

DRV - [2006.11.14 19:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)

DRV - [2006.11.14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)

DRV - [2006.03.24 17:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)

DRV - [2001.08.22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)

========== Standard Registry (All) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

IE - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""

FF - prefs.js..browser.search.defaultenginename: ""

FF - prefs.js..browser.search.order.1: ""

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811"

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://www.google.com.tr/"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.12.09 10:09:59 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009.11.22 03:04:37 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.07.02 14:11:24 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.24 19:20:20 | 000,000,000 | ---D | M]

[2009.09.28 09:06:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Extensions

[2009.09.28 09:06:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2011.08.01 15:12:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Firefox\Profiles\95rtjjqc.default\extensions

[2010.09.11 12:24:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Firefox\Profiles\95rtjjqc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011.07.11 14:32:29 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Firefox\Profiles\95rtjjqc.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}

[2011.03.06 20:10:33 | 000,002,125 | ---- | M] () -- C:\Documents and Settings\Laptop\Application Data\Mozilla\Firefox\Profiles\95rtjjqc.default\searchplugins\Searchster.xml

[2011.08.01 15:12:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011.06.22 08:27:20 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009.11.22 03:04:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

[2010.02.02 15:38:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

[2011.06.24 19:20:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

[2011.06.22 08:27:15 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2011.06.22 08:27:15 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2011.06.22 08:27:17 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll

[2011.03.12 12:28:40 | 000,103,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll

[2010.07.14 09:04:57 | 000,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml

[2010.07.14 09:04:57 | 000,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml

[2011.03.17 23:44:12 | 000,002,404 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml

[2010.07.14 09:04:57 | 000,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml

[2010.07.14 09:04:57 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml

[2010.07.14 09:04:57 | 000,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml

[2010.07.14 09:04:57 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

[2011.01.18 03:11:02 | 000,000,846 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2011.07.31 14:43:06 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: ::1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O3 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [sigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()

O4 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)

O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\Laptop\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)

O15 - HKU\S-1-5-21-220523388-1123561945-1801674531-1003\..Trusted Domains: ubb.bg ([ebb] https in Trusted sites)

O16 - DPF: {173D9E48-B527-4AA0-A929-30B446002AA8} http://192.168.2.3:7000/DVRemoteAx.cab (DVRemoteControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)

O16 - DPF: {9EF2BA47-C6A7-470D-9DD9-4323B0CB8353} http://94.155.50.76:7000/WebClient.cab (WebClient Control)

O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.101.1

O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)

O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)

O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)

O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)

O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)

O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)

O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)

O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)

O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)

O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)

O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)

O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Laptop\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Laptop\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)

O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)

O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)

O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009.07.27 21:34:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2011.07.31 13:22:41 | 000,000,000 | ---D | C] -- C:\_OTL

[2011.07.29 21:09:47 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Laptop\Desktop\OTL.exe

[2011.07.29 20:16:08 | 000,000,000 | --SD | C] -- C:\ComboFix

[2011.07.29 19:33:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\New Folder (5)

[2011.07.29 19:09:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\RK_Quarantine

[2011.07.28 22:56:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\bataryalar

[2011.07.28 14:14:46 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2011.07.28 13:43:11 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2011.07.28 13:43:11 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2011.07.28 13:43:11 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2011.07.28 13:43:11 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2011.07.28 13:43:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011.07.28 13:42:32 | 000,000,000 | ---D | C] -- C:\Qoobox

[2011.07.28 09:40:52 | 000,000,000 | ---D | C] -- C:\Avenger

[2011.07.25 18:18:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\WinRAR

[2011.07.22 14:50:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype

[2011.07.15 11:25:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\smyrna

[2011.06.24 19:20:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun

[2011.06.24 19:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java

[2011.06.24 19:20:20 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll

[2011.06.24 19:20:20 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe

[2011.06.24 19:20:20 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe

[2011.06.24 19:20:20 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe

[2011.06.18 04:12:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Collage Maker

[2011.06.18 04:12:56 | 000,000,000 | ---D | C] -- C:\Program Files\Collage Maker

[2011.06.18 04:08:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\Hamburger_menyu

[2011.06.10 12:57:36 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2011.06.02 10:23:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\ALAMANYA

[2011.06.01 14:55:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\New Folder (4)

[2011.06.01 14:48:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Start Menu\Programs\BetterJPEG Plug-ins

[2011.06.01 14:48:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\BetterJPEG

[2011.05.19 22:43:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Laptop\Desktop\New Folder (3)

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2011.08.01 17:00:31 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011.08.01 17:00:30 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-220523388-1123561945-1801674531-1003.job

[2011.08.01 17:00:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011.08.01 16:06:31 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2011.07.31 15:28:00 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-220523388-1123561945-1801674531-1003.job

[2011.07.31 14:43:06 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts

[2011.07.31 12:49:44 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hоsts

[2011.07.29 21:10:03 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Laptop\Desktop\OTL.exe

[2011.07.29 19:08:27 | 000,526,848 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\RogueKiller.exe

[2011.07.29 19:08:12 | 000,003,718 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\rendu2.png

[2011.07.28 22:57:07 | 000,043,836 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\activedoccia.jpg

[2011.07.28 15:26:24 | 000,002,767 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\loading.gif

[2011.07.28 14:48:46 | 000,000,561 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\Chalishma_saatleri.lnk

[2011.07.28 14:47:32 | 000,000,488 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\KAFE GELIR GIDERLERI.lnk

[2011.07.28 14:14:51 | 000,000,331 | RHS- | M] () -- C:\boot.ini

[2011.07.27 02:47:22 | 000,000,215 | ---- | M] () -- C:\Boot.bak

[2011.07.27 02:12:00 | 000,443,922 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011.07.27 02:12:00 | 000,072,180 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011.07.25 17:40:04 | 080,019,330 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm

[2011.07.13 13:44:59 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011.06.26 09:45:56 | 000,256,000 | ---- | M] () -- C:\WINDOWS\PEV.exe

[2011.06.24 19:00:53 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

[2011.06.21 03:32:42 | 000,304,182 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\1.2011.06.21.03.37.07.659.bmp

[2011.06.02 15:26:26 | 000,956,242 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\VELOX-CATALOG.pdf

[2011.06.01 14:56:57 | 003,534,910 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\New Folder (4).rar

[2011.05.30 19:10:29 | 000,054,877 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\denso2.JPG

[2011.05.30 19:09:10 | 000,055,604 | ---- | M] () -- C:\Documents and Settings\Laptop\Desktop\denso.JPG

[2011.05.04 04:52:34 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe

[2011.05.04 04:52:33 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe

[2011.05.04 04:52:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe

[2011.05.04 04:52:22 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll

[2011.05.04 02:25:49 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.07.29 19:08:10 | 000,526,848 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\RogueKiller.exe

[2011.07.29 19:07:52 | 000,003,718 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\rendu2.png

[2011.07.28 22:56:52 | 000,043,836 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\activedoccia.jpg

[2011.07.28 15:26:02 | 000,002,767 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\loading.gif

[2011.07.28 14:48:46 | 000,000,561 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\Chalishma_saatleri.lnk

[2011.07.28 14:47:32 | 000,000,488 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\KAFE GELIR GIDERLERI.lnk

[2011.07.28 14:14:51 | 000,000,215 | ---- | C] () -- C:\Boot.bak

[2011.07.28 14:14:48 | 000,260,272 | RHS- | C] () -- C:\cmldr

[2011.07.28 13:43:11 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2011.07.28 13:43:11 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2011.07.28 13:43:11 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2011.07.28 13:43:11 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2011.07.28 13:43:11 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2011.07.28 09:34:43 | 000,731,136 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\avenger.exe

[2011.07.27 02:47:21 | 000,000,947 | ---- | C] () -- C:\Documents and Settings\Laptop\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk

[2011.06.21 03:32:42 | 000,304,182 | ---- | C] () -- C:\Documents and Settings\Laptop\My Documents\1.2011.06.21.03.37.07.659.bmp

[2011.06.02 15:26:22 | 000,956,242 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\VELOX-CATALOG.pdf

[2011.06.01 14:56:55 | 003,534,910 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\New Folder (4).rar

[2011.05.30 19:10:29 | 000,054,877 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\denso2.JPG

[2011.05.30 19:09:10 | 000,055,604 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\denso.JPG

[2011.05.24 10:04:02 | 000,212,957 | ---- | C] () -- C:\Documents and Settings\Laptop\Desktop\VELOX-SYSTEMS.jpg

[2011.03.06 20:12:49 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2011.02.04 18:33:25 | 000,000,061 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2010.02.25 16:09:21 | 000,000,041 | ---- | C] () -- C:\WINDOWS\crw.ini

[2010.02.15 15:10:14 | 000,479,232 | ---- | C] () -- C:\WINDOWS\ssndii.exe

[2010.02.15 15:09:13 | 000,022,723 | ---- | C] () -- C:\WINDOWS\System32\cx21sl3.dll

[2010.02.15 15:06:17 | 000,110,592 | ---- | C] () -- C:\WINDOWS\WiaInst.exe

[2010.02.15 14:59:52 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\WIAIPH.dll

[2010.02.15 14:59:52 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\WIAEH.dll

[2010.02.15 14:59:52 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\WIASTIIO.dll

[2010.02.15 14:59:51 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\Sswiadrv.dll

[2010.02.15 14:59:51 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\Ssuiext.dll

[2010.01.27 05:09:02 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

[2009.10.26 09:39:43 | 000,052,224 | ---- | C] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.10.01 15:42:38 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\fusioncache.dat

[2009.10.01 15:18:54 | 000,684,032 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2009.10.01 15:18:53 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll

[2009.09.29 16:29:22 | 000,695,617 | ---- | C] () -- C:\WINDOWS\unins000.exe

[2009.09.29 16:29:22 | 000,025,052 | ---- | C] () -- C:\WINDOWS\unins000.dat

[2009.09.29 16:27:10 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll

[2009.09.28 09:05:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2009.09.24 14:54:59 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009.09.09 10:26:52 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys

[2009.09.09 10:26:52 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\F7852AD672.sys

[2009.08.17 13:28:11 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat

[2009.08.05 19:10:36 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat

[2009.07.31 12:44:31 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009.07.28 00:25:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2009.07.28 00:24:28 | 000,316,360 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009.07.27 22:02:57 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll

[2009.07.27 21:56:42 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4814.dll

[2009.07.27 21:55:16 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe

[2009.07.27 21:51:31 | 000,000,130 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009.07.27 21:38:01 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2009.07.27 21:31:41 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2004.08.04 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2004.08.04 15:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2004.08.04 15:00:00 | 000,443,922 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2004.08.04 15:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2004.08.04 15:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2004.08.04 15:00:00 | 000,072,180 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2004.08.04 15:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2004.08.04 15:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2004.08.04 15:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2004.08.04 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2004.08.04 15:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin

[2004.08.04 15:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011.01.19 12:21:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\firebird

[2009.09.20 17:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations

[2009.08.05 16:45:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo

[2009.09.19 09:16:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia

[2010.02.17 11:17:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite

[2009.10.01 15:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PixelPlanet

[2009.08.10 13:51:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst

[2010.02.18 12:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Readon

[2010.08.07 16:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2009.08.07 10:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\Aisle 5 Games, Inc

[2009.09.19 09:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\AutoDWG

[2009.09.29 16:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

[2011.01.21 18:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\DVRemote

[2009.08.07 11:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\Enlightenus

[2009.08.05 19:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\GameInvest

[2009.08.07 15:03:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\Games

[2010.03.23 16:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\Leadertech

[2009.09.19 09:27:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\Nokia

[2009.09.20 17:53:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\NSeries

[2009.09.19 09:08:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\PC Suite

[2009.08.10 13:51:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\PlayFirst

[2009.08.06 15:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\she_is_a_shadow

[2011.02.24 01:39:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\TeamViewer

[2009.08.06 14:58:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\V-Games

[2009.10.01 15:45:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Laptop\Application Data\ZiWu-Soft

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2009.07.27 21:34:58 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT

[2011.08.01 16:53:11 | 000,023,256 | ---- | M] () -- C:\avenger.txt

[2011.07.27 02:47:22 | 000,000,215 | ---- | M] () -- C:\Boot.bak

[2011.07.28 14:14:51 | 000,000,331 | RHS- | M] () -- C:\boot.ini

[2004.08.03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr

[2009.07.27 21:34:58 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2009.07.27 21:34:58 | 000,000,000 | RHS- | M] () -- C:\IO.SYS

[2009.07.27 21:34:58 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2004.08.04 15:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2009.08.06 21:27:20 | 000,250,048 | RHS- | M] () -- C:\ntldr

[2011.08.01 17:00:20 | 2621,440,000 | -HS- | M] () -- C:\pagefile.sys

[2010.02.27 15:16:31 | 000,013,030 | ---- | M] () -- C:\PDOXUSRS.NET

[2009.08.13 20:05:58 | 000,000,196 | ---- | M] () -- C:\WirelessDiagLog.csv

< %USERPROFILE%\*.* >

[2010.02.15 15:10:52 | 000,117,079 | ---- | M] () -- C:\Documents and Settings\Laptop\111

[2009.11.22 16:38:52 | 000,036,280 | ---- | M] () -- C:\Documents and Settings\Laptop\GamingC.mac

[2011.08.01 16:52:01 | 007,864,320 | -H-- | M] () -- C:\Documents and Settings\Laptop\NTUSER.DAT

[2011.08.01 17:20:47 | 000,001,024 | -H-- | M] () -- C:\Documents and Settings\Laptop\ntuser.dat.LOG

[2011.08.01 16:52:01 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Laptop\ntuser.ini

< %USERPROFILE%\Application Data\*.* >

[2009.07.28 00:25:16 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Laptop\Application Data\desktop.ini

< %USERPROFILE%\Local Settings\Application Data\*.* >

[2011.07.13 13:44:59 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009.10.01 15:42:38 | 000,000,129 | ---- | M] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\fusioncache.dat

[2011.01.20 13:41:04 | 000,092,976 | ---- | M] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2011.08.01 00:24:42 | 006,394,930 | -H-- | M] () -- C:\Documents and Settings\Laptop\Local Settings\Application Data\IconCache.db

< %AllUsersProfile%\*.* >

< %AllUsersProfile%\Application Data\*.* >

[2009.07.28 00:25:16 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

[2010.10.20 14:14:00 | 000,000,088 | RHS- | M] () -- C:\Documents and Settings\All Users\Application Data\F7852AD672.sys

[2010.10.20 14:14:01 | 000,002,828 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys

< %USERPROFILE%\My Documents\*.* >

[2011.06.21 03:32:42 | 000,304,182 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\1.2011.06.21.03.37.07.659.bmp

[2011.06.06 18:55:30 | 000,322,048 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\Alex_CV-BG.doc

[2011.05.27 19:06:45 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\alman_cevap.doc

[2011.07.01 14:53:26 | 000,114,176 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\chart_juli.doc

[2011.06.08 09:08:17 | 000,134,656 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\chart_juni.doc

[2009.08.05 12:32:32 | 000,000,077 | -HS- | M] () -- C:\Documents and Settings\Laptop\My Documents\desktop.ini

[2011.04.25 05:05:01 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\FACE_LIKE_BUTON_CODE.doc

[2009.09.09 16:00:35 | 000,024,871 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\Graphic1.cdr

[2011.01.13 04:05:55 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\menyu.doc

[2011.02.26 19:42:26 | 000,000,043 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\njoy_low.ogg.m3u

[2009.08.12 10:56:36 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\obyava.doc

[2011.06.21 03:32:49 | 000,014,336 | -HS- | M] () -- C:\Documents and Settings\Laptop\My Documents\Thumbs.db

[2009.09.10 16:29:53 | 000,053,498 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\velox111.cdr

[2011.03.01 23:57:24 | 000,000,113 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\YAMAHA_STIKER.txt

[2011.02.02 16:43:10 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Laptop\My Documents\yazilar.doc

< %CommonProgramFiles%\*.* >

< %PROGRAMFILES%\*.* >

< %systemroot%\system32\*.dll /lockedfiles >

[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

[2007.02.27 11:39:52 | 000,019,968 | ---- | M] (Windows ® 2000 DDK provider) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\cx21spc.dll

[2008.07.06 15:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

[2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Spool\prtprocs\w32x86\msonpppr.dll

< MD5 for: EXPLORER.EXE >

[2008.04.14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe

[2008.04.14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe

[2008.04.14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe

[2004.08.04 15:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: USERINIT.EXE >

[2004.08.04 15:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

[2008.04.14 03:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe

[2008.04.14 03:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\userinit.exe

[2008.04.14 03:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: VOLSNAP.SYS >

[2008.04.13 21:41:01 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\ServicePackFiles\i386\volsnap.sys

[2008.04.13 21:41:01 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\volsnap.sys

[2008.04.13 21:41:01 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=4C8FCB5CC53AAB716D810740FE59D025 -- C:\WINDOWS\system32\drivers\volsnap.sys

[2004.08.04 15:00:00 | 000,052,352 | ---- | M] (Microsoft Corporation) MD5=EE4660083DEBA849FF6C485D944B379B -- C:\WINDOWS\$NtServicePackUninstall$\volsnap.sys

< MD5 for: WINLOGON.EXE >

[2004.08.04 15:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe

[2008.04.14 03:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe

[2008.04.14 03:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe

[2008.04.14 03:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

< End of report >

Лог файла изглежда добре....

Точно това ми трябваше:

След това направете следните две проверки:

  • Изтеглете Malwarebytes' Anti-Malware оттук и я инсталирайте.
  • Стартирайте Malwarebytes' Anti-Malware и отидете на UPDATE и натиснете Check for updates.
  • След това се върнете на Scanner изберете Perform QUICK Scan, след това кликнете на Scan.
  • Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете Remove Selected.
  • Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C:\ както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.

После кажете как е състоянието на машината.

  • Автор

Eто данните след сканирането на програма Malwarebytes' Anti-Malware:

Malwarebytes' Anti-Malware 1.51.1.1800

www.malwarebytes.org

Database version: 7346

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

01.08.2011 19:18:12

mbam-log-2011-08-01 (19-18-12).txt

Scan type: Quick scan

Objects scanned: 162216

Time elapsed: 4 minute(s), 21 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 6

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 32

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2863E737-DD3F-4280-9AF8-E9E79C16F312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F334C7B0-8774-4D5B-BD7A-4F448D03A1AE} (Adware.SkyLab) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\Software\SkyMedia (Adware.SkyMedia) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\documents and settings\Laptop\my documents\downloads\flash-player.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\1723833.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\2189187.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\51842749.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\5697091.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\6131309.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\7216617.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\7571_myunrar2.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\2357204.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\2599286.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\315179.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\3550773.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\380398.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\4107938.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\4246532.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\44961623-loader2.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\4721291.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\4856965.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\1046319.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\1059775.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\1691366.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\3069149.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\4984345.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\5127710.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\6037286.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\6192171.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\6207255.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\6414980.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\7799390.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\8322635.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\8608317.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\Temp\328373656.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

Сега продължавам с другата програма, ще пратя резултатите веднага щом ги получа.

  • Автор

Ето и лог файла на aswMBR:

aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software

Run date: 2011-08-01 19:25:17

-----------------------------

19:25:17.125 OS Version: Windows 5.1.2600 Service Pack 3

19:25:17.125 Number of processors: 2 586 0xE08

19:25:17.125 ComputerName: VELOX-LAPTOP UserName: Laptop

19:25:17.484 Initialize success

19:44:17.187 AVAST engine defs: 11080100

19:46:04.453 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

19:46:04.453 Disk 0 Vendor: ST96812AS 8.03 Size: 55796MB BusType: 3

19:46:04.453 Disk 1 \Device\Harddisk1\DR3 -> \Device\00000078

19:46:04.453 Disk 1 Vendor: RICOH 01 Size: 999MB BusType: 0

19:46:06.468 Disk 0 MBR read successfully

19:46:06.484 Disk 0 MBR scan

19:46:06.703 Disk 0 Windows XP default MBR code

19:46:06.718 Disk 0 scanning sectors +114270345

19:46:07.203 Disk 0 scanning C:\WINDOWS\system32\drivers

19:46:18.890 Service scanning

19:46:20.062 Modules scanning

19:46:33.703 Disk 0 trace - called modules:

19:46:33.734 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS

19:46:34.093 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f07ab8]

19:46:34.109 3 CLASSPNP.SYS[f78bbfd7] -> nt!IofCallDriver -> \Device\00000070[0x86f76030]

19:46:34.109 5 ACPI.sys[f7802620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86f0a940]

19:46:34.406 AVAST engine scan C:\

19:50:13.031 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\1117208.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:13.171 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\2282689.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:13.359 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\4246532.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:13.484 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\44961623-loader2.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:13.718 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\4984345.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:13.843 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\7216617.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:13.984 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\l1rezerv.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:14.171 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\services32.exe.vir **INFECTED** Win32:Malware-gen

19:50:14.390 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\sysdriver32.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:14.515 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\sysdriver32_.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

19:50:14.609 File: C:\Documents and Settings\Laptop\Desktop\RK_Quarantine\systemup.exe.vir **INFECTED** Win32:Delf-QBF [Trj]

20:00:17.562 File: C:\System Volume Information\_restore{3893EC75-34F5-48D1-9477-21B5BEEAB4BA}\RP1\A0000012.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:04.515 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\l1rezerv.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:07.781 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\services32.exe **INFECTED** Win32:Malware-gen

20:43:08.031 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\sysdriver32.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:08.265 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\sysdriver32_.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:08.593 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\systemup.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:09.593 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.1\svchost.exe **INFECTED** Win32:Malware-gen

20:43:10.093 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.2\svchost.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:10.406 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.5.0\svchost.exe **INFECTED** Win32:Delf-QBF [Trj]

20:43:10.812 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.tray-12-0\svchost.exe **INFECTED** Win32:Malware-gen

20:43:11.234 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.tray-12-0-lnk\svchost.exe **INFECTED** Win32:Malware-gen

20:43:11.625 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.tray-9-0\svchost.exe **INFECTED** Win32:Malware-gen

20:43:12.093 File: C:\_OTL\MovedFiles\07312011_132241\C_WINDOWS\update.tray-9-0-lnk\svchost.exe **INFECTED** Win32:Malware-gen

20:43:12.718 Scan finished successfully

20:45:54.921 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Laptop\Desktop\MBR.dat"

20:45:54.921 The log file has been saved successfully to "C:\Documents and Settings\Laptop\Desktop\aswMBR.txt"

Колкото до това, как се държи машината, мога да кажа, че разликата е огромна, но все още има неща, които ме притесняват, като например това, че звука който издава Уиндоуса при стартиране при мен се чува доста късно, чак след като заредя настройките на вайрлеса, и влезна в форума :baby:

Здравейте,

Изтрийте папката RK_Quarantine от вашия десктоп (и от кошчето - Recycle Bin-a).

Стартирайте OTL още веднъж и натиснете бутона CleanUp.

Публикувано изображение

Ако бъдете подканени да рестартирате, се съгласете.

Временно спрете System Restore:

Десен бутон на My Computer => Properties => System Restore => Сложете отметка пред "Turn off system on all drives" => натиснете Apply

Публикувано изображение

После по-обратния път махнете отметката.

Следвайте следната инструкция за работа с GMER:

  • Изтеглете този файл и го разархивирайте на десктопа.
  • Временно спрете Интернет и всички работещи програми, както и антивирусната си програма (ако има такава).
  • Преименувайте GMER.exe на Tool.exe и го стартирайте.

    Забележки:

    1. Сканирането може да доведе до грешки, затова не предприемайте никакви действия върху редовете маркирани с "<--- ROOKIT" без да имате инструкция за това.

    2. Ако GMER не се стартира или не работи коректно, не предприемайте повторен опит за стартиране. Moже да пробвате и в Safe Mode, но само веднъж.

  • Ако бъде открит Rootkit, ще последва въпрос дали желаете пълно сканиране на системата. Изберете NO.
  • В десния панел на програмата ще видите какво е проверено, но не променяйте нищо. Убедете се, че на Show All няма отметка.
  • Маркирайте всички устройства: C:, D: и пр.
  • Натиснете бутона Scan и изчакайте програмата да завърши сканирането.
  • Когато завърши сканирането, натиснете бутона Save и запишете (save as) резултатите на десктопа с име: Results.log
  • Вече можете да включите Интернет.
  • Автор

Извинявам се за закъснелия резултат, просто извесно време ми беше спрян интернета... :whist: Ето и съдържанието на Results.log файла: GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2011-08-06 06:38:21 Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST96812AS rev.8.03 Running: Tool.exe; Driver: C:\DOCUME~1\Laptop\LOCALS~1\Temp\ugtdipow.sys ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3324] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 104089D7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3736] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) ---- Services - GMER 1.0.15 ---- Service C:\WINDOWS\System32\alg.exe? (*** hidden *** ) [MANUAL] ALG <-- ROOTKIT !!! Service C:\WINDOWS\system32\cisvc.exe? (*** hidden *** ) [MANUAL] CiSvc <-- ROOTKIT !!! Service C:\WINDOWS\system32\clipsrv.exe? (*** hidden *** ) [MANUAL] ClipSrv <-- ROOTKIT !!! Service C:\WINDOWS\system32\imapi.exe? (*** hidden *** ) [MANUAL] ImapiService <-- ROOTKIT !!! Service C:\WINDOWS\system32\lsass.exe? (*** hidden *** ) [AUTO] PolicyAgent <-- ROOTKIT !!! Service C:\WINDOWS\system32\lsass.exe? (*** hidden *** ) [AUTO] ProtectedStorage <-- ROOTKIT !!! Service C:\WINDOWS\system32\spoolsv.exe? (*** hidden *** ) [AUTO] Spooler <-- ROOTKIT !!! Service C:\WINDOWS\System32\ups.exe? (*** hidden *** ) [MANUAL] UPS <-- ROOTKIT !!! ---- Registry - GMER 1.0.15 ---- Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1 ---- EOF - GMER 1.0.15 ----

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.