Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Заразен компютър?! [РЕШЕН]

Featured Replies

Здравейте, приятели! Имам следния проблем: Не мога да отворя "Task Manager", "Regеdit" и не мога да подкарам антивирусна - въобще не се отваря :ohmy: . Дава ми също и някакъв Error от рода на Microsoft Runtime Error C:/Program Files/.... floating-point support not loaded The necessary floating-point library was not linked. dds.txt . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.2180 Run by 001 at 0:50:31 on 2011-09-29 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.511.81 [GMT 3:00] . FW: ActiveArmor Firewall *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Skype\Phone\Skype.exe C:\DOCUME~1\001\LOCALS~1\Temp\windwwk.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100467&mntrId=e065d61f000000000000001966009202 mWinlogon: UIHost=c:\documents and settings\all users\application data\tuneup software\tuneup utilities\winstyler\tu_logonui.exe BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.4.31.2\bh\BabylonToolbar.dll TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.4.31.2\BabylonToolbarTlbr.dll uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Google Update] "c:\documents and settings\001\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [king_mg] c:\windows\system32\mgking.exe uRun: [King_ar] c:\windows\system32\arking.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet mRun: [HLwin] c:\program files\hlwin\hlwin.exe uPolicies-system: DisableRegistryTools = 1 (0x1) uPolicies-system: DisableTaskMgr = 1 (0x1) mPolicies-system: EnableLUA = 0 (0x0) IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll TCP: Interfaces\{5DEAB2E2-595C-471E-9176-EEE05D975081} : NameServer = 195.24.89.9 195.24.90.1 TCP: Interfaces\{793409B4-D031-4C9A-A7E0-523F53B6EEA1} : NameServer = 195.24.90.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\001\application data\mozilla\firefox\profiles\105j8owt.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/ FF - plugin: c:\documents and settings\001\local settings\application data\google\update\1.3.21.68\npGoogleUpdate3.dll FF - plugin: c:\program files\inhatchteam\inhatch\npinhatch.dll . ============= SERVICES / DRIVERS =============== . R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-8-20 13496] R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\iupghg.sys --> c:\windows\system32\drivers\iupghg.sys [?] S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-8-20 328536] S2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2011-8-20 820568] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-24 2255464] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-8-20 1691480] . =============== Created Last 30 ================ . 2011-09-28 19:16:41 -------- d-----w- c:\documents and settings\001\application data\DriverCure 2011-09-28 19:16:40 -------- d-----w- c:\documents and settings\001\application data\ParetoLogic 2011-09-28 19:16:30 -------- d-----w- c:\program files\common files\ParetoLogic 2011-09-28 19:16:29 -------- d-----w- c:\program files\ParetoLogic 2011-09-28 19:16:29 -------- d-----w- c:\documents and settings\all users\application data\ParetoLogic 2011-09-28 19:10:50 -------- d--h--w- c:\windows\system32\GroupPolicy 2011-09-28 15:06:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-28 01:48:15 -------- d-----w- c:\documents and settings\001\application data\BabylonToolbar 2011-09-27 22:18:59 245248 --sh--r- c:\windows\system32\arking.exe 2011-09-27 22:18:59 114176 --sh--r- c:\windows\system32\arking0.dll 2011-09-27 22:18:43 255488 --sh--r- C:\w9.exe 2011-09-27 22:18:16 255488 --sh--r- c:\windows\system32\mgking.exe 2011-09-27 22:18:16 116736 --sh--r- c:\windows\system32\mgking0.dll . ==================== Find3M ==================== . 2011-08-26 03:31:13 286720 ------w- c:\windows\Setup1.exe 2011-08-26 03:31:11 73216 ----a-w- c:\windows\ST6UNST.EXE 2011-08-25 12:00:44 281408 ----a-w- c:\windows\system32\nvdrsdb1.bin 2011-08-25 12:00:44 1 ----a-w- c:\windows\system32\nvdrssel.bin 2011-08-25 11:55:14 281408 ----a-w- c:\windows\system32\nvdrsdb0.bin 2011-08-21 16:36:11 2321024 ----a-w- c:\windows\system32\TUKernel.exe 2011-08-21 16:22:31 306432 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2011-08-16 15:46:02 6427240 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys 2011-08-15 13:47:14 60008 ----a-w- c:\windows\system32\RtkCoInstXP.dll 2011-08-09 13:14:46 20055144 ----a-w- c:\windows\RTHDCPL.EXE 2011-08-08 08:00:00 74752 ----a-w- c:\windows\system32\ff_vfw.dll 2011-08-04 13:59:00 1493608 ----a-w- c:\windows\RtlUpd.exe 2011-07-16 14:17:06 151552 ----a-w- c:\windows\system32\ac3acm.acm 2011-07-11 11:17:00 1698408 ----a-w- c:\windows\RtlExUpd.dll 2010-11-27 10:51:06 255488 --sh--r- c:\windows\system32\mgking.exe . ============= FINISH: 0:50:52,95 =============== attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 20.8.2011 г. 14:11:12 System Uptime: 27.9.2011 г. 16:08:26 (32 hours ago) . Motherboard: | | K8NF6G-VSTA Processor: AMD Sempron Processor 2800+ | CPUSocket | 1607/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 29 GiB total, 21,505 GiB free. D: is FIXED (NTFS) - 47 GiB total, 38,64 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1: 21.8.2011 г. 20:23:37 - System Checkpoint RP2: 23.8.2011 г. 00:28:41 - System Checkpoint RP3: 24.8.2011 г. 13:06:21 - System Checkpoint RP4: 25.8.2011 г. 15:49:48 - System Checkpoint RP5: 25.8.2011 г. 18:09:37 - Installed Counter-Strike 1.6 RP6: 27.9.2011 г. 08:17:40 - System Checkpoint RP7: 28.9.2011 г. 09:13:47 - System Checkpoint . ==== Installed Programs ====================== . Adobe Flash Player 10 Plugin Advanced SystemCare 4 Babylon toolbar on IE Bulgarian Keyboards XP by G. Atanasov Counter-Strike Counter-Strike 1.6 Favorite-Games 5.19 Game Booster Google Chrome High Definition Audio Driver Package - KB888111 HLTooLz HLwin (remove only) Hotfix for Windows XP (KB935448) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB981793) Inhatch web plugins IObit Malware Fighter K-Lite Codec Pack 7.6.0 (Full) Microsoft Base Smart Card Cryptographic Service Provider Package Mozilla Firefox 6.0 (x86 en-US) NVIDIA Control Panel 280.26 NVIDIA Drivers NVIDIA ForceWare Network Access Manager NVIDIA Graphics Driver 280.26 NVIDIA Install Application NVIDIA nView 135.94 NVIDIA nView Desktop Manager NVIDIA Update 1.4.28 NVIDIA Update Components ParetoLogic PC Health Advisor Realtek High Definition Audio Driver Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981350) Security Update for Windows XP (KB982381) Skype Launcher Skype™ 3.8 Smart Defrag 2 Steam The KMPlayer (remove only) TuneUp Utilities 2008 Update for Windows XP (KB898461) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Winamp (remove only) Windows Media Format Runtime Windows Media Format SDK Hotfix - KB891122 ррхёІ°тѕр WinRAR µTorrent . ==== Event Viewer Messages From Past Week ======== . 28.9.2011 і. 22:13:44, error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:13:15, error: Service Control Manager [7034] - The NVIDIA Driver Helper Service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:13:12, error: Service Control Manager [7034] - The Advanced SystemCare Service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:12:49, error: Service Control Manager [7034] - The ForceWare IP service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:12:45, error: Service Control Manager [7034] - The IMF Service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:12:33, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). 27.9.2011 і. 16:09:03, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. . ==== End Of File ===========================

Здравейте,

Възможно е да става въпрос за полиморфен вирус като Sality или Virut.

Няма да се учудя изобщо, защото вие използвате Windows XP SP2, който отдавна е спрян от поддръжка.

Все пак да проверим това:

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива. За целта може да прегледате информацията от този линк: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

Забележка: При проблеми с ComboFix копирайте с (Copy) и поставете с (Paste) съдържанието на C:\BUG.txt в следващия си коментар.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

Забележка...ако се появи следния прозорец ми кажете:

Публикувано изображение

  • Автор

ComboFix 11-08-28.01 - 001 09.2011 г. 3:46.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.511.274 [GMT 3:00] Running from: c:\documents and settings\001\Desktop\ComboFix.exe FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\autorun.inf c:\documents and settings\001\Local Settings\Application Data\.# c:\documents and settings\001\Local Settings\Application Data\.#\MBX@CCC@90B31B0.### c:\documents and settings\001\Local Settings\Application Data\.#\MBX@CCC@90B31D0.### c:\documents and settings\001\Local Settings\Application Data\.#\MBX@CCC@90B31E0.### c:\windows\system32\arking.exe c:\windows\system32\arking0.dll c:\windows\system32\comct332.ocx c:\windows\system32\kbdBF.dll c:\windows\system32\mgking.exe c:\windows\system32\mgking0.dll D:\autorun.inf . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_ABP470N5 -------\Service_abp470n5 . . ((((((((((((((((((((((((( Files Created from 2011-08-28 to 2011-09-29 ))))))))))))))))))))))))))))))) . . 2011-09-29 00:43 . 2011-09-29 00:43 -------- d-----w- c:\documents and settings\UpdatusUser 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\001\Application Data\DriverCure 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\001\Application Data\ParetoLogic 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\program files\Common Files\ParetoLogic 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\program files\ParetoLogic 2011-09-28 19:10 . 2011-09-28 19:10 -------- d--h--w- c:\windows\system32\GroupPolicy 2011-09-28 15:06 . 2011-09-28 15:06 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-28 01:56 . 2011-09-28 01:56 -------- d-----w- c:\documents and settings\001\Local Settings\Application Data\Mozilla 2011-09-28 01:48 . 2011-09-28 01:48 -------- d-----w- c:\documents and settings\001\Application Data\BabylonToolbar 2011-09-27 22:18 . 2010-11-27 10:51 255488 --sh--r- C:\w9.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-26 03:31 . 2011-08-26 03:31 286720 ------w- c:\windows\Setup1.exe 2011-08-26 03:31 . 2011-08-26 03:31 73216 ----a-w- c:\windows\ST6UNST.EXE 2011-08-21 16:36 . 2011-08-21 16:36 2321024 ----a-w- c:\windows\system32\TUKernel.exe 2011-08-21 16:22 . 2011-08-21 16:22 306432 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2011-08-20 07:48 . 2011-08-20 11:27 105871872 ----a-w- C:\AllIn1_MCE_XP_2K(1107_ASR3)(1).zip 2011-08-16 15:46 . 2011-08-20 12:10 6427240 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys 2011-08-15 13:47 . 2011-08-20 12:10 60008 ----a-w- c:\windows\system32\RtkCoInstXP.dll 2011-08-09 13:14 . 2011-08-20 12:10 20055144 ----a-w- c:\windows\RTHDCPL.EXE 2011-08-08 08:00 . 2011-08-21 16:03 74752 ----a-w- c:\windows\system32\ff_vfw.dll 2011-08-04 13:59 . 2011-08-20 12:10 1493608 ----a-w- c:\windows\RtlUpd.exe 2011-08-03 11:49 . 2011-08-24 14:20 335872 ----a-w- c:\windows\system32\nvrsar.dll 2011-08-03 11:49 . 2011-08-24 14:20 331776 ----a-w- c:\windows\system32\nvrshe.dll 2011-08-03 11:49 . 2011-08-24 14:20 286720 ----a-w- c:\windows\system32\nvrsfr.dll 2011-08-03 11:49 . 2011-08-24 14:20 282624 ----a-w- c:\windows\system32\nvrsit.dll 2011-08-03 11:49 . 2011-08-24 14:20 282624 ----a-w- c:\windows\system32\nvrses.dll 2011-08-03 11:49 . 2011-08-24 14:20 282624 ----a-w- c:\windows\system32\nvrsel.dll 2011-08-03 11:49 . 2011-08-24 14:20 278528 ----a-w- c:\windows\system32\nvrsde.dll 2011-08-03 11:49 . 2011-08-24 14:20 274432 ----a-w- c:\windows\system32\nvrspt.dll 2011-08-03 11:49 . 2011-08-24 14:20 274432 ----a-w- c:\windows\system32\nvrsnl.dll 2011-08-03 11:49 . 2011-08-24 14:20 274432 ----a-w- c:\windows\system32\nvrsesm.dll 2011-08-03 11:49 . 2011-08-24 14:20 270336 ----a-w- c:\windows\system32\nvrsru.dll 2011-08-03 11:49 . 2011-08-24 14:20 270336 ----a-w- c:\windows\system32\nvrsptb.dll 2011-08-03 11:49 . 2011-08-24 14:20 270336 ----a-w- c:\windows\system32\nvrsja.dll 2011-08-03 11:49 . 2011-08-24 14:20 266240 ----a-w- c:\windows\system32\nvrsko.dll 2011-08-03 11:49 . 2011-08-24 14:20 262144 ----a-w- c:\windows\system32\nvrshu.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrstr.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrssl.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrssk.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrspl.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrsth.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrssv.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrsno.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrsda.dll 2011-08-03 11:49 . 2011-08-24 14:20 249856 ----a-w- c:\windows\system32\nvrsfi.dll 2011-08-03 11:49 . 2011-08-24 14:20 249856 ----a-w- c:\windows\system32\nvrseng.dll 2011-08-03 11:49 . 2011-08-24 14:20 249856 ----a-w- c:\windows\system32\nvrscs.dll 2011-08-03 11:49 . 2011-08-24 14:20 229376 ----a-w- c:\windows\system32\nvrszhc.dll 2011-08-03 11:49 . 2011-08-24 14:20 146024 ----a-w- c:\windows\system32\nvsvc32.exe 2011-08-03 11:49 . 2011-08-24 14:20 145000 ----a-w- c:\windows\system32\nvcolor.exe 2011-08-03 11:49 . 2011-08-24 14:20 126976 ----a-w- c:\windows\system32\nvrszht.dll 2011-08-03 11:49 . 2011-08-24 14:20 13892200 ----a-w- c:\windows\system32\nvcpl.dll 2011-08-03 11:49 . 2011-08-24 14:20 111208 ----a-w- c:\windows\system32\nvmctray.dll 2011-08-03 11:49 . 2011-08-24 14:20 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll 2011-08-03 11:49 . 2011-08-24 14:20 54272 ----a-w- c:\windows\system32\nvwddi.dll 2011-08-03 11:49 . 2011-08-24 14:19 914024 ----a-w- c:\windows\system32\nvdispco32.dll 2011-08-03 11:49 . 2011-08-24 14:19 875112 ----a-w- c:\windows\system32\nvgenco32.dll 2011-08-03 11:49 . 2011-08-24 14:19 61440 ----a-w- c:\windows\system32\OpenCL.dll 2011-08-03 11:49 . 2011-08-24 14:19 16191488 ----a-w- c:\windows\system32\nvoglnt.dll 2011-08-03 11:49 . 2011-08-24 14:19 2387560 ----a-w- c:\windows\system32\nvcuvid.dll 2011-08-03 11:49 . 2011-08-24 14:19 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll 2011-08-03 11:49 . 2011-08-24 14:19 5427200 ----a-w- c:\windows\system32\nvcuda.dll 2011-08-03 11:49 . 2011-08-24 14:19 2404864 ----a-w- c:\windows\system32\nvapi.dll 2011-08-03 11:49 . 2011-08-24 14:19 17186816 ----a-w- c:\windows\system32\nvcompiler.dll 2011-08-03 11:49 . 2011-08-20 11:27 4210816 ----a-w- c:\windows\system32\nv4_disp.dll 2011-08-03 11:49 . 2011-08-20 11:27 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys 2011-07-16 14:17 . 2011-08-21 16:03 151552 ----a-w- c:\windows\system32\ac3acm.acm 2011-07-11 11:17 . 2011-08-20 12:10 1698408 ----a-w- c:\windows\RtlExUpd.dll 2011-08-12 05:57 . 2011-09-28 01:56 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-04-23 22058792] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2011-08-09 20055144] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200] "NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1714280] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"= 1 (0x1) "DisableRegistryTools"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice] @="Service" . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Steam"="d:\steam\steam.exe" -silent "Google Update"="c:\documents and settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c "Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "nwiz"=nwiz.exe /install . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 "AntiVirusDisableNotify"=dword:00000001 "FirewallDisableNotify"=dword:00000001 "FirewallOverride"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 "UacDisableNotify"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"= "d:\\Valve\\hl.exe"= "c:\\Program Files\\Steam\\steamapps\\[email protected]\\counter-strike\\hl.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"= "c:\\Program Files\\NVIDIA Corporation\\nView\\nwiz.exe"= "c:\\WINDOWS\\system32\\netsh.exe"= "c:\\Program Files\\NVIDIA Corporation\\Installer2\\NVIDIA.Update.0\\ComUpdatus.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\ParetoLogic\\PCHA\\PCHA.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10950:TCP"= 10950:TCP:Inhatch P2P Streaming "10951:TCP"= 10951:TCP:Inhatch P2P Streaming "10952:TCP"= 10952:TCP:Inhatch P2P Streaming "10953:TCP"= 10953:TCP:Inhatch P2P Streaming "49780:UDP"= 49780:UDP:Inhatch P2P Streaming . R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [20.8.2011 і. 15:20 13496] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [20.8.2011 і. 15:18 328536] R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [20.8.2011 і. 15:20 820568] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [24.8.2011 і. 17:20 2255464] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.8.2011 і. 15:10 1691480] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ABP470N5 . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder . 2011-08-26 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 10:31] . 2011-09-29 c:\windows\Tasks\ASC4_PerformanceMonitor.job - c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-08-20 13:40] . 2011-09-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1604221776-682003330-1003Core.job - c:\documents and settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-20 11:54] . 2011-09-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1604221776-682003330-1003UA.job - c:\documents and settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-20 11:54] . 2011-09-28 c:\windows\Tasks\ParetoLogic Registration3.job - c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2011-08-04 22:06] . 2011-09-28 c:\windows\Tasks\ParetoLogic Update Version3.job - c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-08-04 22:06] . 2011-09-28 c:\windows\Tasks\PC Health Advisor Defrag.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-08-04 22:06] . 2011-09-29 c:\windows\Tasks\PC Health Advisor Startup.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-08-04 22:06] . 2011-09-28 c:\windows\Tasks\PC Health Advisor.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-08-04 22:06] . . ------- Supplementary Scan ------- . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100467&mntrId=e065d61f000000000000001966009202 TCP: Interfaces\{5DEAB2E2-595C-471E-9176-EEE05D975081}: NameServer = 195.24.89.9 195.24.90.1 TCP: Interfaces\{793409B4-D031-4C9A-A7E0-523F53B6EEA1}: NameServer = 195.24.90.1 FF - ProfilePath - c:\documents and settings\001\Application Data\Mozilla\Firefox\Profiles\105j8owt.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.kaldata.com/forums/index.php?showtopic=183166 . - - - - ORPHANS REMOVED - - - - . AddRemove-Favorite-Games_is1 - d:\favorite-games\unins000.exe AddRemove-Steam App 10 - d:\steam\steam.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-09-29 03:57 Windows 5.1.2600 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(3796) c:\program files\NVIDIA Corporation\nView\nview.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\RTHDCPL.EXE c:\windows\system32\RunDLL32.exe c:\windows\system32\rundll32.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe c:\windows\system32\nvsvc32.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe c:\windows\system32\wdfmgr.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe c:\windows\system32\wscntfy.exe c:\program files\Skype\Plugin Manager\skypePM.exe c:\program files\NVIDIA Corporation\Installer2\NVIDIA.Update.0\ComUpdatus.exe . ************************************************************************** . Completion time: 2011-09-29 04:01:51 - machine was rebooted ComboFix-quarantined-files.txt 2011-09-29 01:01 . Pre-Run: 22 843 592 704 bytes free Post-Run: 22 710 657 024 bytes free . - - End Of File - - 021E107B8027EA103221D05931E33742

За съжаление се оказах прав. Имате си Sality.

Това е вирус, който заразява всички exe файлове на всички дялове.

По-принцип борбата с тях е загубена кауза.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - ABP470N5

За да преценим има ли смисъл да се борим, да видим какви са щетите нанесени от вируса.

Направете една проверка с Kaspersky Virus Removal Tool 2011

След като стартирате инструмента, отидете до Settings (Иконата, която прилича на звездичка) сложете отметка пред My Computer.

Публикувано изображение

От опциите за почистване изберете Disinfect => но не избирайте delete if disinfection fails.

Публикувано изображение

Върнете се до Automatic Scan и натиснете Start Scanning.

Публикувано изображение

Ако по време на сканирането ви попита за дадено действие изберете skip.

След като приключи проверката изберете Report (Иконата която прилича на листче) => Detected Threats изберете SAVE и запазете документа на десктопа.

Публикувано изображение

Kопирайте съдържанието му в следващия си пост.

Затворете инструмента - това ще до деинсталира автоматично.

  • Автор

Човек аз ти казах, че не мога да инсталирам антивирусна, даже не ми дава да отворя този сайт на антивируса, който си ми дал

Това не е антивирусна, а самостоятелен инструмент за почистване.

Но да, сега видях че съм дал стар адрес към него за което се извинявам.

Мога да ви дам актуален адрес, но е по-добре да кача инструмента на някой външен хост сървър за по-сигурно.

Ето, пробвайте оттук

  • Автор

Status: Disinfected (events: 10) 29.9.2011 г. 12:08:54 Disinfected virus Virus.Win32.Sality.aa C:\Program Files\Mozilla Firefox\firefox.exe High 29.9.2011 г. 12:10:38 Disinfected virus Virus.Win32.Sality.aa c:\Program Files\NVIDIA Corporation\nView\nwiz.exe High 29.9.2011 г. 12:11:20 Disinfected virus Virus.Win32.Sality.aa c:\Documents and Settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe High 29.9.2011 г. 12:12:16 Disinfected virus Virus.Win32.Sality.aa c:\Program Files\Common Files\Steam\SteamService.exe High 29.9.2011 г. 12:13:24 Disinfected virus Virus.Win32.Sality.aa c:\Documents and Settings\001\Local Settings\Application Data\Google\Chrome\Application\chrome.exe High 29.9.2011 г. 12:14:02 Disinfected virus Virus.Win32.Sality.aa c:\Documents and Settings\001\Desktop\ComboFix.exe High 29.9.2011 г. 12:17:08 Disinfected virus Virus.Win32.Sality.aa d:\Valve\hl.exe High 29.9.2011 г. 12:17:44 Disinfected virus Virus.Win32.Sality.aa c:\Program Files\Steam\steamapps\[email protected]\counter-strike\hl.exe High 29.9.2011 г. 12:18:54 Disinfected virus Virus.Win32.Sality.aa c:\Program Files\ParetoLogic\PCHA\PCHA.exe High 29.9.2011 г. 12:19:36 Disinfected virus Virus.Win32.Sality.aa c:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe High Status: Detected (events: 7) 29.9.2011 г. 12:09:03 Detected Trojan program Backdoor.Win32.Mazben.gf c:\documents and settings\001\local settings\temp\rppqon.exe High 29.9.2011 г. 12:14:51 Detected Trojan program Packed.Win32.Katusha.o c:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe High 29.9.2011 г. 12:15:24 Detected Trojan program Packed.Win32.Katusha.o c:\Program Files\Messenger\msmsgs.exe High 29.9.2011 г. 12:16:00 Detected Trojan program Packed.Win32.Katusha.o c:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe High 29.9.2011 г. 12:16:33 Detected Trojan program Packed.Win32.Katusha.o c:\Program Files\uTorrent\uTorrent.exe High 29.9.2011 г. 12:18:16 Detected Trojan program Packed.Win32.Katusha.o c:\Program Files\NVIDIA Corporation\Installer2\NVIDIA.Update.0\ComUpdatus.exe High 29.9.2011 г. 12:18:55 Detected Trojan program Backdoor.Win32.Mazben.gf c:\Documents and Settings\001\Local Settings\temp\rppqon.exe High

Ако това са единствените намерени файлове при сканиране на целия компютър положението, не е чак толкова зле мисля.

Изтеглете прикачения файл и го тазархивирайте на десктопа.

Стартирайте файла с името del.bat.

Натиснете Enter на появилия се диалогов прозорец.

1. Спрете Autorun функцията.

Изтеглете и стартирайте следния файл Публикувано изображение

Стартирайте го и се съгласете с лицензионното споразумение.

Натиснете Next и изчакайте да си свърпи работата.

2. Спрете System Restore функцията.

Щракнете с десен бутон върху My Computer, после следвайте следните стъпки: Properties -> System restore и сложете отметката пред Turn System Restore on all drives. Натиснете Apply.

3. Изтеглете всички инструменти и ги запазете на десктопа.

Изключете интернет достъпа и след това сканирайте с всички тях един по един по реда както е описано:

Изтеглете SalityKiller и го разархивирайте на десктопа.

Стартирайте файла SalityKiller.exe и изчакайте проверката да завърши.

След това изтеглете rmslt.exe и го стартирайте

За финал направете една проверка с PCMAV for Sality.

Изтеглете и разархивирайте архива.

Стартирайте инструмента и направете проверката.

4. Включете интернет достъпа, изтрийте вашата версия на Combofix и изтеглете свежо копие на Combofix от линка по-нагоре.

Направете проверка и публикувайте лог файла.

del.zip

  • Автор

ComboFix 11-08-29.01 - 001 09.2011 г. 16:25:49.3.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.511.134 [GMT 3:00] Running from: c:\documents and settings\001\Desktop\ComboFix.exe FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_ABP470N5 . . ((((((((((((((((((((((((( Files Created from 2011-08-28 to 2011-09-29 ))))))))))))))))))))))))))))))) . . 2011-09-29 00:43 . 2011-09-29 00:43 -------- d-----w- c:\documents and settings\UpdatusUser 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\001\Application Data\DriverCure 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\001\Application Data\ParetoLogic 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\program files\Common Files\ParetoLogic 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic 2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\program files\ParetoLogic 2011-09-28 19:10 . 2011-09-28 19:10 -------- d--h--w- c:\windows\system32\GroupPolicy 2011-09-28 15:06 . 2011-09-28 15:06 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-28 01:56 . 2011-09-28 01:56 -------- d-----w- c:\documents and settings\001\Local Settings\Application Data\Mozilla 2011-09-28 01:48 . 2011-09-28 01:48 -------- d-----w- c:\documents and settings\001\Application Data\BabylonToolbar 2011-09-27 22:18 . 2010-11-27 10:51 181760 --sh--r- C:\w9.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-26 03:31 . 2011-08-26 03:31 286720 ------w- c:\windows\Setup1.exe 2011-08-26 03:31 . 2011-08-26 03:31 73216 ----a-w- c:\windows\ST6UNST.EXE 2011-08-21 16:36 . 2011-08-21 16:36 2321024 ----a-w- c:\windows\system32\TUKernel.exe 2011-08-21 16:22 . 2011-08-21 16:22 306432 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2011-08-20 07:48 . 2011-08-20 11:27 105871872 ----a-w- C:\AllIn1_MCE_XP_2K(1107_ASR3)(1).zip 2011-08-16 15:46 . 2011-08-20 12:10 6427240 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys 2011-08-15 13:47 . 2011-08-20 12:10 60008 ----a-w- c:\windows\system32\RtkCoInstXP.dll 2011-08-09 13:14 . 2011-08-20 12:10 20055144 ----a-w- c:\windows\RTHDCPL.EXE 2011-08-08 08:00 . 2011-08-21 16:03 74752 ----a-w- c:\windows\system32\ff_vfw.dll 2011-08-04 13:59 . 2011-08-20 12:10 1493608 ----a-w- c:\windows\RtlUpd.exe 2011-08-03 11:49 . 2011-08-24 14:20 335872 ----a-w- c:\windows\system32\nvrsar.dll 2011-08-03 11:49 . 2011-08-24 14:20 331776 ----a-w- c:\windows\system32\nvrshe.dll 2011-08-03 11:49 . 2011-08-24 14:20 286720 ----a-w- c:\windows\system32\nvrsfr.dll 2011-08-03 11:49 . 2011-08-24 14:20 282624 ----a-w- c:\windows\system32\nvrsit.dll 2011-08-03 11:49 . 2011-08-24 14:20 282624 ----a-w- c:\windows\system32\nvrses.dll 2011-08-03 11:49 . 2011-08-24 14:20 282624 ----a-w- c:\windows\system32\nvrsel.dll 2011-08-03 11:49 . 2011-08-24 14:20 278528 ----a-w- c:\windows\system32\nvrsde.dll 2011-08-03 11:49 . 2011-08-24 14:20 274432 ----a-w- c:\windows\system32\nvrspt.dll 2011-08-03 11:49 . 2011-08-24 14:20 274432 ----a-w- c:\windows\system32\nvrsnl.dll 2011-08-03 11:49 . 2011-08-24 14:20 274432 ----a-w- c:\windows\system32\nvrsesm.dll 2011-08-03 11:49 . 2011-08-24 14:20 270336 ----a-w- c:\windows\system32\nvrsru.dll 2011-08-03 11:49 . 2011-08-24 14:20 270336 ----a-w- c:\windows\system32\nvrsptb.dll 2011-08-03 11:49 . 2011-08-24 14:20 270336 ----a-w- c:\windows\system32\nvrsja.dll 2011-08-03 11:49 . 2011-08-24 14:20 266240 ----a-w- c:\windows\system32\nvrsko.dll 2011-08-03 11:49 . 2011-08-24 14:20 262144 ----a-w- c:\windows\system32\nvrshu.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrstr.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrssl.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrssk.dll 2011-08-03 11:49 . 2011-08-24 14:20 258048 ----a-w- c:\windows\system32\nvrspl.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrsth.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrssv.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrsno.dll 2011-08-03 11:49 . 2011-08-24 14:20 253952 ----a-w- c:\windows\system32\nvrsda.dll 2011-08-03 11:49 . 2011-08-24 14:20 249856 ----a-w- c:\windows\system32\nvrsfi.dll 2011-08-03 11:49 . 2011-08-24 14:20 249856 ----a-w- c:\windows\system32\nvrseng.dll 2011-08-03 11:49 . 2011-08-24 14:20 249856 ----a-w- c:\windows\system32\nvrscs.dll 2011-08-03 11:49 . 2011-08-24 14:20 229376 ----a-w- c:\windows\system32\nvrszhc.dll 2011-08-03 11:49 . 2011-08-24 14:20 146024 ----a-w- c:\windows\system32\nvsvc32.exe 2011-08-03 11:49 . 2011-08-24 14:20 145000 ----a-w- c:\windows\system32\nvcolor.exe 2011-08-03 11:49 . 2011-08-24 14:20 126976 ----a-w- c:\windows\system32\nvrszht.dll 2011-08-03 11:49 . 2011-08-24 14:20 13892200 ----a-w- c:\windows\system32\nvcpl.dll 2011-08-03 11:49 . 2011-08-24 14:20 111208 ----a-w- c:\windows\system32\nvmctray.dll 2011-08-03 11:49 . 2011-08-24 14:20 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll 2011-08-03 11:49 . 2011-08-24 14:20 54272 ----a-w- c:\windows\system32\nvwddi.dll 2011-08-03 11:49 . 2011-08-24 14:19 914024 ----a-w- c:\windows\system32\nvdispco32.dll 2011-08-03 11:49 . 2011-08-24 14:19 875112 ----a-w- c:\windows\system32\nvgenco32.dll 2011-08-03 11:49 . 2011-08-24 14:19 61440 ----a-w- c:\windows\system32\OpenCL.dll 2011-08-03 11:49 . 2011-08-24 14:19 16191488 ----a-w- c:\windows\system32\nvoglnt.dll 2011-08-03 11:49 . 2011-08-24 14:19 2387560 ----a-w- c:\windows\system32\nvcuvid.dll 2011-08-03 11:49 . 2011-08-24 14:19 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll 2011-08-03 11:49 . 2011-08-24 14:19 5427200 ----a-w- c:\windows\system32\nvcuda.dll 2011-08-03 11:49 . 2011-08-24 14:19 2404864 ----a-w- c:\windows\system32\nvapi.dll 2011-08-03 11:49 . 2011-08-24 14:19 17186816 ----a-w- c:\windows\system32\nvcompiler.dll 2011-08-03 11:49 . 2011-08-20 11:27 4210816 ----a-w- c:\windows\system32\nv4_disp.dll 2011-08-03 11:49 . 2011-08-20 11:27 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys 2011-07-16 14:17 . 2011-08-21 16:03 151552 ----a-w- c:\windows\system32\ac3acm.acm 2011-07-11 11:17 . 2011-08-20 12:10 1698408 ----a-w- c:\windows\RtlExUpd.dll 2011-08-12 05:57 . 2011-09-28 01:56 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-09-29_00.57.17 ))))))))))))))))))))))))))))))))))))))))) . + 2011-09-29 13:30 . 2011-09-29 13:30 16384 c:\windows\temp\Perflib_Perfdata_950.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-04-23 22058792] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2011-08-09 20055144] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200] "NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-09-29 1625600] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe" . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Steam"="d:\steam\steam.exe" -silent "Google Update"="c:\documents and settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c "Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "nwiz"=nwiz.exe /install . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"= "d:\\Valve\\hl.exe"= "c:\\Program Files\\Steam\\steamapps\\[email protected]\\counter-strike\\hl.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"= "c:\\Program Files\\NVIDIA Corporation\\nView\\nwiz.exe"= "c:\\WINDOWS\\system32\\netsh.exe"= "c:\\Program Files\\NVIDIA Corporation\\Installer2\\NVIDIA.Update.0\\ComUpdatus.exe"= "c:\\Program Files\\ParetoLogic\\PCHA\\PCHA.exe"= "c:\\WINDOWS\\RTHDCPL.EXE"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10950:TCP"= 10950:TCP:Inhatch P2P Streaming "10951:TCP"= 10951:TCP:Inhatch P2P Streaming "10952:TCP"= 10952:TCP:Inhatch P2P Streaming "10953:TCP"= 10953:TCP:Inhatch P2P Streaming "49780:UDP"= 49780:UDP:Inhatch P2P Streaming . R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [20.8.2011 і. 15:20 13496] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [20.8.2011 і. 15:18 328536] R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [20.8.2011 і. 15:20 820568] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [24.8.2011 і. 17:20 2255464] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.8.2011 і. 15:10 1691480] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder . 2011-08-26 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 10:31] . 2011-09-29 c:\windows\Tasks\ASC4_PerformanceMonitor.job - c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-08-20 13:40] . 2011-09-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1604221776-682003330-1003Core.job - c:\documents and settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-20 09:21] . 2011-09-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1604221776-682003330-1003UA.job - c:\documents and settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-20 09:21] . 2011-09-28 c:\windows\Tasks\ParetoLogic Registration3.job - c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2011-08-04 22:06] . 2011-09-28 c:\windows\Tasks\ParetoLogic Update Version3.job - c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-08-04 09:21] . 2011-09-28 c:\windows\Tasks\PC Health Advisor Defrag.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-08-04 09:21] . 2011-09-29 c:\windows\Tasks\PC Health Advisor Startup.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-08-04 09:21] . 2011-09-28 c:\windows\Tasks\PC Health Advisor.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-08-04 09:21] . . ------- Supplementary Scan ------- . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100467&mntrId=e065d61f000000000000001966009202 TCP: Interfaces\{5DEAB2E2-595C-471E-9176-EEE05D975081}: NameServer = 195.24.89.9 195.24.90.1 TCP: Interfaces\{793409B4-D031-4C9A-A7E0-523F53B6EEA1}: NameServer = 195.24.90.1 FF - ProfilePath - c:\documents and settings\001\Application Data\Mozilla\Firefox\Profiles\105j8owt.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.kaldata.com/forums/index.php?showtopic=183166 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-09-29 16:30 Windows 5.1.2600 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(3796) c:\program files\NVIDIA Corporation\nView\nview.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe c:\windows\RTHDCPL.EXE c:\windows\system32\RunDLL32.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe c:\windows\system32\wdfmgr.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe c:\windows\system32\wscntfy.exe c:\program files\Skype\Plugin Manager\skypePM.exe c:\program files\NVIDIA Corporation\Installer2\NVIDIA.Update.0\ComUpdatus.exe . ************************************************************************** . Completion time: 2011-09-29 16:33:32 - machine was rebooted ComboFix-quarantined-files.txt 2011-09-29 13:33 ComboFix2.txt 2011-09-29 01:01 . Pre-Run: 25 128 525 824 bytes free Post-Run: 25 116 876 800 bytes free . - - End Of File - - 16A74FF04647B8C9A88BAACE628DCA67 все още ми дава тези 2 грешки: post-307487-0-81898700-1314625004_thumb. post-307487-0-77206500-1314625022_thumb. ;)

Добра работа. Иначе ще дава грешки, защото тези файлове са били заразени и почистени, но вируса е с бъгав код и това пречи на нормалното функциониране на почистените файлове. Трябва да ги изтеглите наново и да ги преинсталирате. Изтрийте следните файлове и изтеглете чисти инсталационни версии на следните програми и драйвъри: C:\Program Files\Mozilla Firefox\firefox.exe c:\Program Files\NVIDIA Corporation\nView\nwiz.exe c:\Documents and Settings\001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe c:\Program Files\Common Files\Steam\SteamService.exe c:\Documents and Settings\001\Local Settings\Application Data\Google\Chrome\Application\chrome.exe c:\Program Files\Steam\steamapps\[email protected]\counter-strike\hl.exe c:\Program Files\ParetoLogic\PCHA\PCHA.exe c:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe c:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe c:\Program Files\Messenger\msmsgs.exe c:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe c:\Program Files\uTorrent\uTorrent.exe c:\Program Files\NVIDIA Corporation\Installer2\NVIDIA.Update.0\ComUpdatus.exe d:\Valve\hl.exe

Не сме приключили...нека да направим 3 финални проверки, защото Sality е коварна твар и по-принцип избягвам да си правя експерименти да го почиствам, но просто при вас ми се стори, че има светлина в тунела.

1. Повторете проверката с Kaspersky Virus Removal Tool и публикувайте лог файла.

2. Направете една проверка със следния инструмент:

Изтеглете програмата => Dr.Web CureIt и я стартирайте.

Направете следните настройки -> клавиш F9:

-В категория проверка се придвижете до списък с изключени файлове.

-Маркирайте всичките и изберете Изтрий. Потвърдете с Apply.

Публикувано изображение

-Придвижете се до категория действия.

Приложете настройките от снимката и натиснете Apply.

Публикувано изображение

Направете пълна проверка на системата и публикувайте съдържанието на лог файла (DrWeb.csv) в следващия си коментар. Можете да го качите на rapidshare.com и след това да дадете линк за файла

3. Изтеглете свежо копие на Combofix и направете една финална проверка. Искам да проверя дали рууткит услугата се е завърнала. Ако не се е...имаме да почистим едни поражения със скрипт за Combofix и чак тогава сме готови.

А да препоръчате някоя антивирусна програма с която няма да се стига до тук ? ;)

А да препоръчате някоя антивирусна програма с която няма да се стига до тук ? ;)

Няма точна рецепта, но за превенция ще си говорим след като приключим.

Следете темата...

  • Автор

Kaspersky removal tool log:

Status: Quarantined   (events: 4)   

29.9.2011 г. 21:31:18    Quarantined    virus HEUR:Trojan.Win32.Generic    C:\avast! Professional Edition 4.8.1282\Keygen.exe    High   

29.9.2011 г. 21:31:18    Quarantined    virus HEUR:Trojan.Win32.Generic    C:\avast! Professional Edition 4.8.1282\Keygen.exe//ASPack    High   

29.9.2011 г. 21:51:26    Quarantined    virus HEUR:Trojan.Win32.Generic    C:\System Volume Information\_restore{0198C883-8D77-47CB-92C6-6898F4D01A0E}\RP9\A0001834.exe    High   

29.9.2011 г. 21:51:26    Quarantined    virus HEUR:Trojan.Win32.Generic    C:\System Volume Information\_restore{0198C883-8D77-47CB-92C6-6898F4D01A0E}\RP9\A0001834.exe//ASPack    High   

Status: Detected   (events: 8)   

29.9.2011 г. 21:46:16    Detected    Trojan program Trojan.Win32.AutoRun.bmj    C:\Qoobox\Quarantine\C\autorun.inf.vir    High   

29.9.2011 г. 21:46:16    Detected    Trojan program Trojan.Win32.AutoRun.bmj    C:\Qoobox\Quarantine\D\av1.zip/Qoobox/Quarantine/D/autorun.inf.vir    High   

29.9.2011 г. 21:46:16    Detected    Trojan program Packed.Win32.Klone.bq    C:\Qoobox\Quarantine\C\WINDOWS\system32\mgking0.dll.vir    High   

29.9.2011 г. 21:46:16    Detected    Trojan program Trojan.Win32.AutoRun.bmj    C:\Qoobox\Quarantine\D\autorun.inf.vir    High   

29.9.2011 г. 21:46:16    Detected    Trojan program Trojan.WinREG.Agent.v    C:\Qoobox\Quarantine\Registry_backups\Service_abp470n5.reg.dat    High   

29.9.2011 г. 21:46:16    Detected    Trojan program Packed.Win32.Klone.bq    C:\Qoobox\Quarantine\C\WINDOWS\system32\mgking.exe.vir    High   

29.9.2011 г. 21:50:00    Detected    Trojan program Packed.Win32.Klone.bq    C:\System Volume Information\_restore{0198C883-8D77-47CB-92C6-6898F4D01A0E}\RP4\A0001687.exe    High   

29.9.2011 г. 22:02:34    Detected    Trojan program Packed.Win32.Klone.bq    D:\w9.exe    High   

Combofix log:

ComboFix 11-08-29.03 - 001 09.2011 г.   0:03.4.1 - x86

Microsoft Windows XP Professional  5.1.2600.2.1251.359.1033.18.511.301 [GMT 3:00]

Running from: c:\documents and settings\001\Desktop\ComboFix.exe

AV: avast! antivirus 4.8.1282 [VPS 110829-0] *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}

.

.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\system32\kbdBF.dll

.

.

(((((((((((((((((((((((((   Files Created from 2011-08-28 to 2011-09-29  )))))))))))))))))))))))))))))))

.

.

2011-09-29 19:09 . 2011-09-29 19:09    --------    d-----w-    c:\documents and settings\001\DoctorWeb

2011-09-29 18:25 . 2011-08-29 06:35    133208    ----a-w-    c:\windows\system32\drivers\06215855.sys

2011-09-29 18:15 . 2009-08-25 09:47    352256    ----a-w-    c:\windows\system32\SET6A.tmp

2011-09-29 18:15 . 2009-10-21 06:00    75776    ----a-w-    c:\windows\system32\SET59.tmp

2011-09-29 18:15 . 2009-10-21 06:00    25088    ----a-w-    c:\windows\system32\SET5A.tmp

2011-09-29 18:15 . 2009-10-20 14:58    263552    -c----w-    c:\windows\system32\dllcache\http.sys

2011-09-29 18:15 . 2009-10-20 14:58    263552    ----a-w-    c:\windows\system32\drivers\SET5B.tmp

2011-09-29 18:14 . 2009-09-11 14:33    133632    ----a-w-    c:\windows\system32\SET52.tmp

2011-09-29 17:41 . 2011-09-29 18:25    --------    d-----w-    c:\windows\LastGood

2011-09-29 16:38 . 2008-11-12 15:52    50656    ----a-w-    c:\windows\system32\drivers\aswTdi.sys

2011-09-29 16:38 . 2008-11-12 15:52    23152    ----a-w-    c:\windows\system32\drivers\aswRdr.sys

2011-09-29 16:38 . 2008-11-12 15:51    26944    ----a-w-    c:\windows\system32\drivers\aavmker4.sys

2011-09-29 16:38 . 2008-11-12 15:51    97480    ----a-w-    c:\windows\system32\AvastSS.scr

2011-09-29 16:38 . 2008-11-12 15:54    93296    ----a-w-    c:\windows\system32\drivers\aswmon.sys

2011-09-29 16:38 . 2008-11-12 15:54    94032    ----a-w-    c:\windows\system32\drivers\aswmon2.sys

2011-09-29 16:38 . 2008-11-12 15:53    110160    ----a-w-    c:\windows\system32\drivers\aswSP.sys

2011-09-29 16:38 . 2008-11-12 15:53    20560    ----a-w-    c:\windows\system32\drivers\aswFsBlk.sys

2011-09-29 16:38 . 2008-11-12 15:57    1235696    ----a-w-    c:\windows\system32\aswBoot.exe

2011-09-29 16:38 . 2004-01-09 08:13    380928    ----a-w-    c:\windows\system32\actskin4.ocx

2011-09-29 16:36 . 2011-09-29 18:31    --------    d-----w-    C:\avast! Professional Edition 4.8.1282

2011-09-29 16:35 . 2011-09-29 16:35    --------    d-s---w-    c:\documents and settings\001\UserData

2011-09-29 16:35 . 2011-09-29 16:35    --------    d-----w-    c:\program files\Conduit

2011-09-29 16:35 . 2011-09-29 16:35    --------    d-----w-    c:\documents and settings\001\Local Settings\Application Data\Conduit

2011-09-29 16:35 . 2011-09-29 16:35    --------    d-----w-    c:\documents and settings\001\Local Settings\Application Data\temp

2011-09-29 16:35 . 2011-09-29 16:35    --------    d-----w-    c:\program files\uTorrent

2011-09-29 16:34 . 2011-09-29 17:27    --------    d-----w-    c:\documents and settings\001\Application Data\uTorrent

2011-09-29 16:34 . 2011-09-29 16:34    --------    d-----w-    c:\documents and settings\001\Local Settings\Application Data\uTorrent

2011-09-29 16:14 . 2011-08-03 11:49    61440    ----a-w-    c:\windows\system32\OpenCL.dll

2011-09-29 16:14 . 2011-08-03 11:49    914024    ----a-w-    c:\windows\system32\nvdispco32.dll

2011-09-29 16:14 . 2011-08-03 11:49    875112    ----a-w-    c:\windows\system32\nvgenco32.dll

2011-09-29 16:14 . 2011-08-03 11:49    2387560    ----a-w-    c:\windows\system32\nvcuvid.dll

2011-09-29 16:14 . 2011-08-03 11:49    2090088    ----a-w-    c:\windows\system32\nvcuvenc.dll

2011-09-29 16:14 . 2011-08-03 11:49    16191488    ----a-w-    c:\windows\system32\nvoglnt.dll

2011-09-29 16:14 . 2011-08-03 11:49    5427200    ----a-w-    c:\windows\system32\nvcuda.dll

2011-09-29 16:14 . 2011-08-03 11:49    2404864    ----a-w-    c:\windows\system32\nvapi.dll

2011-09-29 16:14 . 2011-08-03 11:49    17186816    ----a-w-    c:\windows\system32\nvcompiler.dll

2011-09-28 19:16 . 2011-09-28 19:16    --------    d-----w-    c:\documents and settings\001\Application Data\DriverCure

2011-09-28 19:16 . 2011-09-28 19:16    --------    d-----w-    c:\documents and settings\001\Application Data\ParetoLogic

2011-09-28 19:16 . 2011-09-28 19:16    --------    d-----w-    c:\program files\Common Files\ParetoLogic

2011-09-28 19:16 . 2011-09-29 15:38    --------    d-----w-    c:\program files\ParetoLogic

2011-09-28 19:16 . 2011-09-28 19:16    --------    d-----w-    c:\documents and settings\All Users\Application Data\ParetoLogic

2011-09-28 19:10 . 2011-09-28 19:10    --------    d--h--w-    c:\windows\system32\GroupPolicy

2011-09-28 15:06 . 2011-09-28 15:06    404640    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl

2011-09-28 01:56 . 2011-09-28 01:56    --------    d-----w-    c:\documents and settings\001\Local Settings\Application Data\Mozilla

2011-09-28 01:48 . 2011-09-28 01:48    --------    d-----w-    c:\documents and settings\001\Application Data\BabylonToolbar

.

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-08-26 03:31 . 2011-08-26 03:31    286720    ------w-    c:\windows\Setup1.exe

2011-08-26 03:31 . 2011-08-26 03:31    73216    ----a-w-    c:\windows\ST6UNST.EXE

2011-08-21 16:36 . 2011-08-21 16:36    2321024    ----a-w-    c:\windows\system32\TUKernel.exe

2011-08-20 07:48 . 2011-08-20 11:27    105871872    ----a-w-    C:\AllIn1_MCE_XP_2K(1107_ASR3)(1).zip

2011-08-16 15:46 . 2011-08-20 12:10    6427240    ----a-w-    c:\windows\system32\drivers\RtkHDAud.sys

2011-08-15 13:47 . 2011-08-20 12:10    60008    ----a-w-    c:\windows\system32\RtkCoInstXP.dll

2011-08-09 13:14 . 2011-08-20 12:10    20055144    ----a-w-    c:\windows\RTHDCPL.EXE

2011-08-04 13:59 . 2011-08-20 12:10    1493608    ----a-w-    c:\windows\RtlUpd.exe

2011-08-03 11:49 . 2011-08-20 11:27    4210816    ----a-w-    c:\windows\system32\nv4_disp.dll

2011-08-03 11:49 . 2011-08-20 11:27    12542592    ----a-w-    c:\windows\system32\drivers\nv4_mini.sys

2011-07-11 11:17 . 2011-08-20 12:10    1698408    ----a-w-    c:\windows\RtlExUpd.dll

2011-08-12 05:57 . 2011-09-29 15:43    134104    ----a-w-    c:\program files\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{b54561db-0bbb-41b4-a814-df8301fe0a8e}"= "c:\program files\uTorrentBar2\prxtbuTor.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{b54561db-0bbb-41b4-a814-df8301fe0a8e}]

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b54561db-0bbb-41b4-a814-df8301fe0a8e}]

2011-05-09 09:49    176936    ----a-w-    c:\program files\uTorrentBar2\prxtbuTor.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{b54561db-0bbb-41b4-a814-df8301fe0a8e}"= "c:\program files\uTorrentBar2\prxtbuTor.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{b54561db-0bbb-41b4-a814-df8301fe0a8e}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-04-23 22058792]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2011-08-09 20055144]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-08-03 111208]

"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-12 81000]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]

"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"nwiz"=nwiz.exe /install

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=

"c:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"=

"c:\\Program Files\\NVIDIA Corporation\\nView\\nwiz.exe"=

"c:\\WINDOWS\\system32\\netsh.exe"=

"c:\\WINDOWS\\RTHDCPL.EXE"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"10950:TCP"= 10950:TCP:Inhatch P2P Streaming

"10951:TCP"= 10951:TCP:Inhatch P2P Streaming

"10952:TCP"= 10952:TCP:Inhatch P2P Streaming

"10953:TCP"= 10953:TCP:Inhatch P2P Streaming

"49780:UDP"= 49780:UDP:Inhatch P2P Streaming

.

R0 06215855;06215855;c:\windows\system32\drivers\06215855.sys [29.9.2011 і. 21:25 133208]

R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [20.8.2011 і. 15:20 13496]

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29.9.2011 і. 19:38 110160]

R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [20.8.2011 і. 15:18 328536]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29.9.2011 і. 19:38 20560]

R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [20.8.2011 і. 15:20 820568]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.8.2011 і. 15:10 1691480]

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - 06215855

*NewlyCreated* - ASWUPDSV

*NewlyCreated* - AVAST!_MAIL_SCANNER

*NewlyCreated* - AVAST!_WEB_SCANNER

*Deregistered* - Dwsh00004563

.

Contents of the 'Scheduled Tasks' folder

.

2011-09-29 c:\windows\Tasks\ASC4_PerformanceMonitor.job

- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-08-20 13:40]

.

2011-09-29 c:\windows\Tasks\ParetoLogic Registration3.job

- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2011-08-04 22:06]

.

2011-09-28 c:\windows\Tasks\ParetoLogic Update Version3.job

- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-08-04 09:21]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100467&mntrId=e065d61f000000000000001966009202

TCP: Interfaces\{5DEAB2E2-595C-471E-9176-EEE05D975081}: NameServer = 195.24.89.9 195.24.90.1

TCP: Interfaces\{793409B4-D031-4C9A-A7E0-523F53B6EEA1}: NameServer = 195.24.90.1

FF - ProfilePath - c:\documents and settings\001\Application Data\Mozilla\Firefox\Profiles\105j8owt.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.kaldata.com/forums/index.php?showtopic=183166

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-09-30 00:08

Windows 5.1.2600 Service Pack 2 NTFS

.

scanning hidden processes ...  

.

scanning hidden autostart entries ...

.

scanning hidden files ...  

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

Completion time: 2011-09-30  00:09:56

ComboFix-quarantined-files.txt  2011-09-29 21:09

ComboFix2.txt  2011-09-29 13:33

ComboFix3.txt  2011-09-29 01:01

.

Pre-Run: 25 557 958 656 bytes free

Post-Run: 25 553 461 248 bytes free

.

- - End Of File - - FA6FF68285D3D95B8994DAEF9141F653

Dr.Web cureit ми сканираше 1 час,и намери 2 инфектирани файла,а във следващите 3 часа беше заредил, по-малко от половината и не мърдаше и излязох от програмата,защото имам работа по компютъра и ми трябват повече ресурси.. ;)

Редактирано от iwailo (преглед на промените)

Силно препоръчвам да деинсталирате следните програми от Add/Remove Programs от Control Panel-a:

ParetoLogic DriverCure

ParetoLogic PC Health Advisor

TuneUp Utilities

Advanced SystemCare

IObit Malware Fighter

В момента сте инсталирали => avast! Professional Edition 4.8.1282 => обновете я версията до avast! Free Antivirus 6.0.1273 Beta

System Restore опцията отново е стартирана. Спрете опцията, както е описано по-нагоре.

Също така от Start => run => напишете cleanmgr.exe => натиснете Enter => изберете дял C:\ => натиснете ОК => Отидете до More Options и под System Restore изберете Clean up.

Натиснете OK и затворете приложението.

Кои бяха намерените бацили от Dr.Web ?

Добре е също така да оставите този скенер да приключи с цялостната проверка на системата (ако трябва оставете го през нощта).

*.Изтеглете прикачения файл и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

Публикувано изображение

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Когато Combofix приключи ще създаде лог файла. Моля, публикувайте този файл в следващия си пост.

CFScript.txt

  • Автор

Dr.Web:

cnet_SkypeLauncher-setup_exe.exe;C:\Documents and Settings\001\My Documents;Adware.Zugo.38;;

mgking.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Win32.HLLW.Autoruner.36438;Неизлечим.;

mgking0.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.PWS.Wsgame.24181;Изтрит.;

A0001687.exe;C:\System Volume Information\_restore{0198C883-8D77-47CB-92C6-6898F4D01A0E}\RP4;Win32.HLLW.Autoruner.36438;Неизлечим.;

w9.exe;D:\;Win32.HLLW.Autoruner.36438;Неизлечим.;

Combofix:

ComboFix 11-08-30.01 - 001 09.2011 г. 16:22:39.5.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.511.277 [GMT 3:00]

Running from: c:\documents and settings\001\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\001\Desktop\CFScript.txt

AV: avast! antivirus 4.8.1282 [VPS 110830-1] *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}

.

FILE ::

"C:\w9.exe"

"c:\windows\system32\drivers\06215855.sys"

"c:\windows\system32\drivers\SET5B.tmp"

"c:\windows\system32\SET52.tmp"

"c:\windows\system32\SET59.tmp"

"c:\windows\system32\SET5A.tmp"

"c:\windows\system32\SET6A.tmp"

"D:\w9.exe"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\docume~1\001\LOCALS~1\Temp\EF9B7C39-F8FD2432-75986FF9-2E4791F7\56ba3_xp.exe

c:\docume~1\001\LOCALS~1\Temp\EF9B7C39-F8FD2432-75986FF9-2E4791F7\715abd.exe

c:\docume~1\001\LOCALS~1\Temp\EF9B7C39-F8FD2432-75986FF9-2E4791F7\setup.dll

c:\documents and settings\001\DoctorWeb

c:\documents and settings\001\DoctorWeb\CureIt.log

c:\documents and settings\001\Local Settings\Application Data\Conduit

c:\documents and settings\001\Local Settings\Temp\EF9B7C39-F8FD2432-75986FF9-2E4791F7\56ba3_xp.exe

c:\documents and settings\001\Local Settings\Temp\EF9B7C39-F8FD2432-75986FF9-2E4791F7\715abd.exe

c:\documents and settings\001\Local Settings\Temp\EF9B7C39-F8FD2432-75986FF9-2E4791F7\setup.dll

c:\program files\Conduit

c:\program files\Conduit\Community Alerts\Alert.dll

c:\windows\system32\drivers\06215855.sys

c:\windows\system32\drivers\SET5B.tmp

c:\windows\system32\SET52.tmp

c:\windows\system32\SET59.tmp

c:\windows\system32\SET5A.tmp

c:\windows\system32\SET6A.tmp

D:\w9.exe

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_06215855

-------\Service_06215855

.

.

((((((((((((((((((((((((( Files Created from 2011-08-28 to 2011-09-30 )))))))))))))))))))))))))))))))

.

.

2011-09-29 18:15 . 2009-10-20 14:58 263552 -c----w- c:\windows\system32\dllcache\http.sys

2011-09-29 17:41 . 2011-09-29 18:25 -------- d-----w- c:\windows\LastGood.Tmp

2011-09-29 16:38 . 2008-11-12 15:52 50656 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-09-29 16:38 . 2008-11-12 15:52 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-09-29 16:38 . 2008-11-12 15:51 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2011-09-29 16:38 . 2008-11-12 15:51 97480 ----a-w- c:\windows\system32\AvastSS.scr

2011-09-29 16:38 . 2008-11-12 15:54 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys

2011-09-29 16:38 . 2008-11-12 15:54 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2011-09-29 16:38 . 2008-11-12 15:53 110160 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-09-29 16:38 . 2008-11-12 15:53 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-09-29 16:38 . 2008-11-12 15:57 1235696 ----a-w- c:\windows\system32\aswBoot.exe

2011-09-29 16:38 . 2004-01-09 08:13 380928 ----a-w- c:\windows\system32\actskin4.ocx

2011-09-29 16:36 . 2011-09-29 18:31 -------- d-----w- C:\avast! Professional Edition 4.8.1282

2011-09-29 16:35 . 2011-09-29 16:35 -------- d-s---w- c:\documents and settings\001\UserData

2011-09-29 16:35 . 2011-09-29 16:35 -------- d-----w- c:\documents and settings\001\Local Settings\Application Data\temp

2011-09-29 16:35 . 2011-09-29 16:35 -------- d-----w- c:\program files\uTorrent

2011-09-29 16:34 . 2011-09-30 01:42 -------- d-----w- c:\documents and settings\001\Application Data\uTorrent

2011-09-29 16:34 . 2011-09-29 16:34 -------- d-----w- c:\documents and settings\001\Local Settings\Application Data\uTorrent

2011-09-29 16:14 . 2011-08-03 11:49 61440 ----a-w- c:\windows\system32\OpenCL.dll

2011-09-29 16:14 . 2011-08-03 11:49 914024 ----a-w- c:\windows\system32\nvdispco32.dll

2011-09-29 16:14 . 2011-08-03 11:49 875112 ----a-w- c:\windows\system32\nvgenco32.dll

2011-09-29 16:14 . 2011-08-03 11:49 2387560 ----a-w- c:\windows\system32\nvcuvid.dll

2011-09-29 16:14 . 2011-08-03 11:49 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll

2011-09-29 16:14 . 2011-08-03 11:49 16191488 ----a-w- c:\windows\system32\nvoglnt.dll

2011-09-29 16:14 . 2011-08-03 11:49 5427200 ----a-w- c:\windows\system32\nvcuda.dll

2011-09-29 16:14 . 2011-08-03 11:49 2404864 ----a-w- c:\windows\system32\nvapi.dll

2011-09-29 16:14 . 2011-08-03 11:49 17186816 ----a-w- c:\windows\system32\nvcompiler.dll

2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\001\Application Data\DriverCure

2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\001\Application Data\ParetoLogic

2011-09-28 19:16 . 2011-09-28 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic

2011-09-28 19:10 . 2011-09-28 19:10 -------- d--h--w- c:\windows\system32\GroupPolicy

2011-09-28 15:06 . 2011-09-28 15:06 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-09-28 01:56 . 2011-09-28 01:56 -------- d-----w- c:\documents and settings\001\Local Settings\Application Data\Mozilla

2011-09-28 01:48 . 2011-09-28 01:48 -------- d-----w- c:\documents and settings\001\Application Data\BabylonToolbar

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-08-26 03:31 . 2011-08-26 03:31 286720 ------w- c:\windows\Setup1.exe

2011-08-26 03:31 . 2011-08-26 03:31 73216 ----a-w- c:\windows\ST6UNST.EXE

2011-08-21 16:36 . 2011-08-21 16:36 2321024 ----a-w- c:\windows\system32\TUKernel.exe

2011-08-20 07:48 . 2011-08-20 11:27 105871872 ----a-w- C:\AllIn1_MCE_XP_2K(1107_ASR3)(1).zip

2011-08-16 15:46 . 2011-08-20 12:10 6427240 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys

2011-08-15 13:47 . 2011-08-20 12:10 60008 ----a-w- c:\windows\system32\RtkCoInstXP.dll

2011-08-09 13:14 . 2011-08-20 12:10 20055144 ----a-w- c:\windows\RTHDCPL.EXE

2011-08-04 13:59 . 2011-08-20 12:10 1493608 ----a-w- c:\windows\RtlUpd.exe

2011-08-03 11:49 . 2011-08-20 11:27 4210816 ----a-w- c:\windows\system32\nv4_disp.dll

2011-08-03 11:49 . 2011-08-20 11:27 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys

2011-07-11 11:17 . 2011-08-20 12:10 1698408 ----a-w- c:\windows\RtlExUpd.dll

2011-08-12 05:57 . 2011-09-29 15:43 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((( SnapShot@2011-09-29_00.57.17 )))))))))))))))))))))))))))))))))))))))))

.

+ 2011-09-29 16:55 . 2011-09-29 16:55 16384 c:\windows\temp\Perflib_Perfdata_608.dat

+ 2011-09-30 13:30 . 2011-09-30 13:30 16384 c:\windows\temp\Perflib_Perfdata_5c0.dat

- 2011-08-20 12:45 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll

+ 2011-08-20 12:45 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 54272 c:\windows\system32\nvwddi.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 54272 c:\windows\system32\nvwddi.dll

+ 2004-08-03 22:56 . 2009-10-21 06:00 75776 c:\windows\system32\dllcache\strmfilt.dll

- 2004-08-03 22:56 . 2004-08-03 22:56 75776 c:\windows\system32\dllcache\strmfilt.dll

+ 2004-08-03 22:56 . 2009-10-21 06:00 25088 c:\windows\system32\dllcache\httpapi.dll

+ 2011-09-29 17:41 . 2002-09-04 22:10 6416 c:\windows\LastGood.Tmp\system32\kbdbd.dll

+ 2004-08-03 22:56 . 2007-10-27 14:40 227328 c:\windows\system32\wmasf.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 146024 c:\windows\system32\nvsvc32.exe

+ 2011-09-29 16:15 . 2011-08-03 11:49 146024 c:\windows\system32\nvsvc32.exe

+ 2011-09-29 16:15 . 2011-08-03 11:49 126976 c:\windows\system32\nvrszht.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 126976 c:\windows\system32\nvrszht.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 229376 c:\windows\system32\nvrszhc.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 229376 c:\windows\system32\nvrszhc.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 258048 c:\windows\system32\nvrstr.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 258048 c:\windows\system32\nvrstr.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 253952 c:\windows\system32\nvrsth.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 253952 c:\windows\system32\nvrsth.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 253952 c:\windows\system32\nvrssv.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 253952 c:\windows\system32\nvrssv.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 258048 c:\windows\system32\nvrssl.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 258048 c:\windows\system32\nvrssl.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 258048 c:\windows\system32\nvrssk.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 258048 c:\windows\system32\nvrssk.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 270336 c:\windows\system32\nvrsru.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 270336 c:\windows\system32\nvrsru.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 270336 c:\windows\system32\nvrsptb.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 270336 c:\windows\system32\nvrsptb.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 274432 c:\windows\system32\nvrspt.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 274432 c:\windows\system32\nvrspt.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 258048 c:\windows\system32\nvrspl.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 258048 c:\windows\system32\nvrspl.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 253952 c:\windows\system32\nvrsno.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 253952 c:\windows\system32\nvrsno.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 274432 c:\windows\system32\nvrsnl.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 274432 c:\windows\system32\nvrsnl.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 266240 c:\windows\system32\nvrsko.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 266240 c:\windows\system32\nvrsko.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 270336 c:\windows\system32\nvrsja.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 270336 c:\windows\system32\nvrsja.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 282624 c:\windows\system32\nvrsit.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 282624 c:\windows\system32\nvrsit.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 262144 c:\windows\system32\nvrshu.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 262144 c:\windows\system32\nvrshu.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 331776 c:\windows\system32\nvrshe.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 331776 c:\windows\system32\nvrshe.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 286720 c:\windows\system32\nvrsfr.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 286720 c:\windows\system32\nvrsfr.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 249856 c:\windows\system32\nvrsfi.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 249856 c:\windows\system32\nvrsfi.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 274432 c:\windows\system32\nvrsesm.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 274432 c:\windows\system32\nvrsesm.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 282624 c:\windows\system32\nvrses.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 282624 c:\windows\system32\nvrses.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 249856 c:\windows\system32\nvrseng.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 249856 c:\windows\system32\nvrseng.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 282624 c:\windows\system32\nvrsel.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 282624 c:\windows\system32\nvrsel.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 278528 c:\windows\system32\nvrsde.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 278528 c:\windows\system32\nvrsde.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 253952 c:\windows\system32\nvrsda.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 253952 c:\windows\system32\nvrsda.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 249856 c:\windows\system32\nvrscs.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 249856 c:\windows\system32\nvrscs.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 335872 c:\windows\system32\nvrsar.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 335872 c:\windows\system32\nvrsar.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 111208 c:\windows\system32\nvmctray.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 111208 c:\windows\system32\nvmctray.dll

+ 2011-09-29 16:15 . 2011-09-30 02:12 280276 c:\windows\system32\nvdrsdb1.bin

+ 2011-09-29 16:15 . 2011-09-30 02:07 280276 c:\windows\system32\nvdrsdb0.bin

- 2011-08-24 14:20 . 2011-08-03 11:49 145000 c:\windows\system32\nvcolor.exe

+ 2011-09-29 16:15 . 2011-08-03 11:49 145000 c:\windows\system32\nvcolor.exe

+ 2004-08-03 22:57 . 2005-06-26 10:13 366832 c:\windows\system32\msscp.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 600680 c:\windows\system32\easyupdatusapiu.dll

- 2011-08-24 14:20 . 2011-08-03 11:49 600680 c:\windows\system32\easyupdatusapiu.dll

+ 2004-08-03 22:56 . 2007-10-27 14:40 227328 c:\windows\system32\dllcache\wmasf.dll

+ 2004-08-03 22:56 . 2009-08-25 09:47 352256 c:\windows\system32\dllcache\winhttp.dll

+ 2004-08-03 22:56 . 2009-09-11 14:33 133632 c:\windows\system32\dllcache\msv1_0.dll

- 2004-08-03 22:56 . 2009-06-25 08:44 133632 c:\windows\system32\dllcache\msv1_0.dll

+ 2004-08-03 22:57 . 2005-06-26 10:13 366832 c:\windows\system32\dllcache\msscp.dll

+ 2011-09-29 18:25 . 2011-08-29 06:35 475736 c:\windows\LastGood.Tmp\system32\DRIVERS\4103496drv.sys

+ 2011-09-29 18:15 . 2009-10-20 14:58 263552 c:\windows\Driver Cache\i386\http.sys

- 2011-08-24 14:20 . 2011-08-03 11:49 13892200 c:\windows\system32\nvcpl.dll

+ 2011-09-29 16:15 . 2011-08-03 11:49 13892200 c:\windows\system32\nvcpl.dll

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-12 81000]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]

"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

2011-08-03 11:49 13892200 ----a-w- c:\windows\system32\nvcpl.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

2011-08-03 11:49 111208 ----a-w- c:\windows\system32\nvmctray.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2011-07-05 07:08 1632360 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2011-08-09 13:14 20055144 ----a-w- c:\windows\RTHDCPL.EXE

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

2008-04-23 14:45 22058792 ----a-r- c:\program files\Skype\Phone\Skype.exe

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe"

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"nwiz"=nwiz.exe /install

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=

"c:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"=

"c:\\Program Files\\NVIDIA Corporation\\nView\\nwiz.exe"=

"c:\\WINDOWS\\system32\\netsh.exe"=

"c:\\WINDOWS\\RTHDCPL.EXE"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"10950:TCP"= 10950:TCP:Inhatch P2P Streaming

"10951:TCP"= 10951:TCP:Inhatch P2P Streaming

"10952:TCP"= 10952:TCP:Inhatch P2P Streaming

"10953:TCP"= 10953:TCP:Inhatch P2P Streaming

"49780:UDP"= 49780:UDP:Inhatch P2P Streaming

.

R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [20.8.2011 і. 15:20 13496]

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29.9.2011 і. 19:38 110160]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29.9.2011 і. 19:38 20560]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.8.2011 і. 15:10 1691480]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100467&mntrId=e065d61f000000000000001966009202

TCP: Interfaces\{793409B4-D031-4C9A-A7E0-523F53B6EEA1}: NameServer = 195.24.90.1

FF - ProfilePath - c:\documents and settings\001\Application Data\Mozilla\Firefox\Profiles\105j8owt.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.kaldata.com/forums/index.php?showtopic=183166

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-09-30 16:30

Windows 5.1.2600 Service Pack 2 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Alwil Software\Avast4\aswUpdSv.exe

c:\program files\Alwil Software\Avast4\ashServ.exe

c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\wdfmgr.exe

c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

c:\program files\Alwil Software\Avast4\ashMaiSv.exe

c:\windows\system32\wscntfy.exe

c:\program files\Alwil Software\Avast4\ashWebSv.exe

.

**************************************************************************

.

Completion time: 2011-09-30 16:32:08 - machine was rebooted

ComboFix-quarantined-files.txt 2011-09-30 13:32

ComboFix2.txt 2011-09-29 21:09

ComboFix3.txt 2011-09-29 13:33

ComboFix4.txt 2011-09-29 01:01

.

Pre-Run: 25 504 485 376 bytes free

Post-Run: 25 483 718 656 bytes free

.

- - End Of File - - 93A6BC819F3A978FB2046F79A0AD9EFF

деинсталирах програмите:

ParetoLogic DriverCure

ParetoLogic PC Health Advisor

TuneUp Utilities

Advanced SystemCare

IObit Malware Fighter

и обнових Avast Публикувано изображение

Ok...деинсталирайте сега Combofix.

Start => Run => напишете Combofix /Uninstall (има разстояние между Combofix и /Uninstall) => натиснете Enter.

Направете две финални проверки - едната с обновения avast! (изтрийте намерените неща), а другата с Kaspersky Removal Tool (изтрийте намерените неща)...може да публикувате и резултатите.

Някой път направете и ПЪЛНА проверка с Dr.Web както е описано по-нагоре.

Какво е състоянието на системата в момента на системата ?

  • Автор

Status: Detected (events: 7) 31.8.2011 г. 06:36:15 Detected Trojan program Trojan.Win32.AutoRun.bmj C:\Qoobox\Quarantine\C\autorun.inf.vir High 31.8.2011 г. 06:36:15 Detected Trojan program Trojan.Win32.AutoRun.bmj C:\Qoobox\Quarantine\D\av1.zip/Qoobox/Quarantine/D/autorun.inf.vir High 31.8.2011 г. 06:36:15 Detected Trojan program Trojan.Win32.AutoRun.bmj C:\Qoobox\Quarantine\D\autorun.inf.vir High 31.8.2011 г. 06:36:16 Detected Trojan program Packed.Win32.Klone.bq C:\Qoobox\Quarantine\C\WINDOWS\system32\mgking.exe.vir High 31.8.2011 г. 06:36:16 Detected Trojan program Trojan.WinREG.Agent.v C:\Qoobox\Quarantine\Registry_backups\Service_abp470n5.reg.dat High 31.8.2011 г. 06:36:17 Detected Trojan program Packed.Win32.Klone.bq C:\Qoobox\Quarantine\D\av4.zip/Qoobox/Quarantine/D/w9.exe.vir High 31.8.2011 г. 06:36:17 Detected Trojan program Packed.Win32.Klone.bq C:\Qoobox\Quarantine\D\w9.exe.vir High Avast ги изчисти. А да те питам какво имаше предвид под "Какво е състоянието на системата в момента на системата ?"

Това от Kaspersky нали ?

Тези файлове са в карантинната папка на Combofix и тя трябваше да се е самоизтрила след деинсталацията на Combofix.

Нали деинсталирахте Combofix ?

avast! намери ли и тя нещо - може ли снимка на нещата в карантината ?

Avast ги изчисти. А да те питам какво имаше предвид под "Какво е състоянието на системата в момента на системата ?"

Имах предвид имате ли повече проблеми, защото системата трябва да е вече чиста.

Може да публикувате един финален лог от DDS да видим дали всичко е ок за един последен път...

След това ще ви дам съвети за превенция...

  • Автор

dds . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.2180 Run by 001 at 22:08:22 on 2011-08-31 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.511.272 [GMT 3:00] . AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: ActiveArmor Firewall *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVAST Software\Avast\avastUI.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100467&mntrId=e065d61f000000000000001966009202 mWinlogon: UIHost=c:\windows\system32\logonui.exe BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - Babylon toolbar helper TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll TCP: Interfaces\{5DEAB2E2-595C-471E-9176-EEE05D975081} : NameServer = 195.24.89.9 195.24.90.1 TCP: Interfaces\{793409B4-D031-4C9A-A7E0-523F53B6EEA1} : NameServer = 195.24.90.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\001\application data\mozilla\firefox\profiles\105j8owt.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.kaldata.com/forums/index.php?showtopic=183166 FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll . ============= SERVICES / DRIVERS =============== . R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-8-20 13496] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-30 442200] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-30 320472] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-30 20568] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-9-30 44768] S2 gupdate;Ус»уі° Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-30 136176] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-8-20 1691480] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-30 136176] . =============== Created Last 30 ================ . 2011-09-30 14:01:35 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-09-30 14:01:06 41184 ----a-w- c:\windows\avastSS.scr 2011-09-30 14:00:07 -------- d-----w- c:\program files\AVAST Software 2011-09-30 13:52:27 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software 2011-09-30 03:35:36 -------- d-----w- c:\windows\pss 2011-09-29 18:15:04 263552 -c----w- c:\windows\system32\dllcache\http.sys 2011-09-29 16:35:48 -------- d-s---w- c:\documents and settings\001\UserData 2011-09-29 16:35:12 -------- d-----w- c:\documents and settings\001\local settings\application data\temp 2011-09-29 16:35:06 -------- d-----w- c:\program files\uTorrent 2011-09-29 16:34:22 -------- d-----w- c:\documents and settings\001\local settings\application data\uTorrent 2011-09-29 16:34:22 -------- d-----w- c:\documents and settings\001\application data\uTorrent 2011-09-29 16:14:29 61440 ----a-w- c:\windows\system32\OpenCL.dll 2011-09-29 16:14:28 914024 ----a-w- c:\windows\system32\nvdispco32.dll 2011-09-29 16:14:28 875112 ----a-w- c:\windows\system32\nvgenco32.dll 2011-09-29 16:14:28 2387560 ----a-w- c:\windows\system32\nvcuvid.dll 2011-09-29 16:14:28 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll 2011-09-29 16:14:28 16191488 ----a-w- c:\windows\system32\nvoglnt.dll 2011-09-29 16:14:27 5427200 ----a-w- c:\windows\system32\nvcuda.dll 2011-09-29 16:14:27 2404864 ----a-w- c:\windows\system32\nvapi.dll 2011-09-29 16:14:27 17186816 ----a-w- c:\windows\system32\nvcompiler.dll 2011-09-29 15:27:51 -------- d-----w- c:\windows\system32\appmgmt 2011-09-29 00:40:32 -------- d-sha-r- C:\cmdcons 2011-09-29 00:39:24 98816 ----a-w- c:\windows\sed.exe 2011-09-29 00:39:24 518144 ----a-w- c:\windows\SWREG.exe 2011-09-29 00:39:24 256000 ----a-w- c:\windows\PEV.exe 2011-09-29 00:39:24 208896 ----a-w- c:\windows\MBR.exe 2011-09-28 19:16:41 -------- d-----w- c:\documents and settings\001\application data\DriverCure 2011-09-28 19:16:40 -------- d-----w- c:\documents and settings\001\application data\ParetoLogic 2011-09-28 19:16:29 -------- d-----w- c:\documents and settings\all users\application data\ParetoLogic 2011-09-28 19:10:50 -------- d--h--w- c:\windows\system32\GroupPolicy 2011-09-28 15:06:16 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-28 01:56:53 -------- d-----w- c:\documents and settings\001\local settings\application data\Mozilla 2011-09-28 01:48:15 -------- d-----w- c:\documents and settings\001\application data\BabylonToolbar 2011-08-31 18:14:48 -------- d--h--w- c:\windows\PIF 2011-08-31 18:01:41 28416 ----a-w- c:\windows\system32\uxtuneup.dll 2011-08-31 18:01:40 307968 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2011-08-31 18:00:57 -------- d-----w- c:\program files\TuneUp Utilities 2008 2011-08-31 18:00:30 -------- d-----w- c:\program files\common files\Wise Installation Wizard 2011-08-31 16:27:53 -------- d-----w- C:\SteamApps 2011-08-26 03:31:13 286720 ------w- c:\windows\Setup1.exe 2011-08-26 03:31:11 73216 ----a-w- c:\windows\ST6UNST.EXE 2011-08-24 18:50:35 -------- d-----w- c:\documents and settings\001\application data\goalbit 2011-08-24 16:45:40 -------- d-----w- c:\documents and settings\001\application data\NVIDIA 2011-08-24 16:39:52 -------- d-----w- c:\program files\SkypeLauncher 2011-08-24 16:39:21 -------- d-----w- c:\documents and settings\001\local settings\application data\Babylon 2011-08-24 16:39:20 -------- d-----w- c:\documents and settings\all users\application data\Babylon 2011-08-24 16:39:20 -------- d-----w- c:\documents and settings\001\application data\Babylon 2011-08-24 03:50:19 -------- d-----w- C:\NVIDIA 2011-08-21 16:36:11 2321024 ----a-w- c:\windows\system32\TUKernel.exe 2011-08-21 16:22:35 -------- d-----w- c:\documents and settings\001\application data\TuneUp Software 2011-08-21 16:22:24 -------- d-----w- c:\documents and settings\all users\application data\TuneUp Software 2011-08-21 16:03:23 175616 ----a-w- c:\windows\system32\unrar.dll 2011-08-21 16:00:25 -------- d-----w- c:\program files\The KMPlayer 2011-08-20 15:52:23 6416 ----a-w- c:\windows\system32\kbdbd.dll 2011-08-20 15:03:19 5120 ----a-w- c:\windows\system32\vga856.fon 2011-08-20 15:03:15 28672 ----a-w- c:\windows\system32\newdll.dll 2011-08-20 15:03:14 -------- d-----w- c:\windows\Datecs 2011-08-20 14:00:44 3072 ----a-w- c:\windows\system32\drivers\audstub.sys 2011-08-20 14:00:33 21504 ----a-w- c:\windows\system32\hidserv.dll 2011-08-20 14:00:14 57472 ----a-w- c:\windows\system32\drivers\redbook.sys 2011-08-20 14:00:01 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys . ==================== Find3M ==================== . 2011-08-31 16:56:32 280484 ----a-w- c:\windows\system32\nvdrsdb0.bin 2011-08-31 16:56:32 1 ----a-w- c:\windows\system32\nvdrssel.bin 2011-08-31 16:56:31 280484 ----a-w- c:\windows\system32\nvdrsdb1.bin 2011-08-16 15:46:02 6427240 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys 2011-08-15 13:47:14 60008 ----a-w- c:\windows\system32\RtkCoInstXP.dll 2011-08-09 13:14:46 20055144 ----a-w- c:\windows\RTHDCPL.EXE 2011-08-04 13:59:00 1493608 ----a-w- c:\windows\RtlUpd.exe 2011-07-11 11:17:00 1698408 ----a-w- c:\windows\RtlExUpd.dll 2011-06-30 13:15:00 891496 ----a-w- c:\windows\system32\RTSndMgr.CPL . ============= FINISH: 22:09:09,89 =============== attach . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 20.8.2011 г. 14:11:12 System Uptime: 31.8.2011 г. 21:49:03 (1 hours ago) . Motherboard: | | K8NF6G-VSTA Processor: AMD Sempron™ Processor 2800+ | CPUSocket | 1607/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 29 GiB total, 23,319 GiB free. D: is FIXED (NTFS) - 47 GiB total, 37,666 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP3: 31.8.2011 г. 21:35:32 - System Checkpoint . ==== Installed Programs ====================== . Adobe Flash Player 10 Plugin avast! Free Antivirus Babylon toolbar on IE Bulgarian Keyboards XP by G. Atanasov Game Booster Google Chrome Google Update Helper High Definition Audio Driver Package - KB888111 HLTooLz HLwin (remove only) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB935448) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB981793) Inhatch web plugins Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox 6.0 (x86 en-US) NVIDIA Control Panel 280.26 NVIDIA Drivers NVIDIA ForceWare Network Access Manager NVIDIA Graphics Driver 280.26 NVIDIA Install Application NVIDIA nView 135.94 NVIDIA nView Desktop Manager ParetoLogic PC Health Advisor Realtek High Definition Audio Driver Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981350) Security Update for Windows XP (KB982381) Skype Launcher Skype™ 3.8 Smart Defrag 2 The KMPlayer (remove only) TuneUp Utilities 2008 Update for Windows XP (KB898461) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Winamp (remove only) Windows Media Format Runtime Windows Media Format SDK Hotfix - KB891122 съ»і°рсєё ёЅтµрфµ№с ·° TuneUp Utilities 2008 ррхёІ°тѕр WinRAR µTorrent . ==== Event Viewer Messages From Past Week ======== . 31.8.2011 і. 22:04:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 22:04:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 22:04:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 22:04:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 22:04:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 22:04:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 22:04:12, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 31.8.2011 і. 21:34:41, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). 31.8.2011 і. 21:34:35, error: Service Control Manager [7034] - The ForceWare IP service service terminated unexpectedly. It has done this 1 time(s). 31.8.2011 і. 21:07:36, error: Service Control Manager [7000] - The TuneUp Theme Extension service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service. 31.8.2011 і. 21:06:57, error: Service Control Manager [7000] - The TuneUp Theme Extension service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service. 31.8.2011 і. 21:01:42, error: Service Control Manager [7000] - The TuneUp Theme Extension service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service. 31.8.2011 і. 11:56:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:56:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:56:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:56:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:56:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:56:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:56:23, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 31.8.2011 і. 11:13:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:13:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:13:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:13:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:13:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:13:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:13:09, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 31.8.2011 і. 11:11:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:11:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:11:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:11:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:11:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:11:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 31.8.2011 і. 11:11:39, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 30.9.2011 і. 19:16:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 19:16:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 19:16:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 19:16:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 19:16:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 19:16:09, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 19:16:09, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 30.9.2011 і. 16:58:59, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:58:59, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:58:59, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:58:59, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:58:59, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:58:59, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:58:59, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 30.9.2011 і. 16:57:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:57:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:57:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:57:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:57:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:57:12, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:57:12, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 30.9.2011 і. 16:51:24, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:51:24, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 30.9.2011 і. 16:51:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:51:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:51:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:51:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:51:23, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 30.9.2011 і. 16:29:34, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 30.9.2011 і. 16:28:12, error: PlugPlayManager [11] - The device Root\LEGACY_06215855\0000 disappeared from the system without first being prepared for removal. 30.9.2011 і. 16:22:36, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). 30.9.2011 і. 16:22:36, error: Service Control Manager [7034] - The NVIDIA Driver Helper Service service terminated unexpectedly. It has done this 1 time(s). 30.9.2011 і. 16:22:36, error: Service Control Manager [7034] - The Forceware Web Interface service terminated unexpectedly. It has done this 1 time(s). 30.9.2011 і. 16:22:36, error: Service Control Manager [7034] - The ForceWare user log service service terminated unexpectedly. It has done this 1 time(s). 30.9.2011 і. 16:22:36, error: Service Control Manager [7034] - The ForceWare IP service service terminated unexpectedly. It has done this 1 time(s). 30.9.2011 і. 04:15:02, error: Service Control Manager [7034] - The Advanced SystemCare Service service terminated unexpectedly. It has done this 1 time(s). 29.9.2011 і. 19:56:10, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 19:55:48, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:55:48, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:55:48, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:55:48, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:55:48, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:55:48, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:55:48, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 19:17:48, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 19:17:46, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:17:46, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:17:46, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:17:46, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:17:46, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:17:46, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 19:17:46, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 18:48:16, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 18:48:16, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 18:48:16, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 18:48:16, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 18:48:16, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 18:48:16, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 18:48:16, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 18:48:10, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 16:30:34, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 16:30:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 16:30:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 16:30:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 16:30:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 16:30:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 16:30:34, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 16:30:34, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 16:29:33, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 29.9.2011 і. 16:29:33, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 29.9.2011 і. 16:29:19, error: PlugPlayManager [11] - The device Root\LEGACY_ABP470N5\0000 disappeared from the system without first being prepared for removal. 29.9.2011 і. 15:10:23, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 15:10:19, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 12:22:19, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 29.9.2011 і. 12:22:19, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 29.9.2011 і. 12:22:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 12:22:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 12:22:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 12:22:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 12:22:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 12:22:19, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 12:22:19, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 12:22:01, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 03:57:02, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:56:55, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 29.9.2011 і. 03:51:26, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 29.9.2011 і. 03:51:12, error: PlugPlayManager [11] - The device Root\LEGACY_ABP470N5\0000 disappeared from the system without first being prepared for removal. 29.9.2011 і. 03:43:45, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 29.9.2011 і. 03:43:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:43:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:43:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:43:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:43:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:43:39, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 29.9.2011 і. 03:43:39, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 28.9.2011 і. 22:13:44, error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:13:15, error: Service Control Manager [7034] - The NVIDIA Driver Helper Service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:13:12, error: Service Control Manager [7034] - The Advanced SystemCare Service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:12:49, error: Service Control Manager [7034] - The ForceWare IP service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:12:45, error: Service Control Manager [7034] - The IMF Service service terminated unexpectedly. It has done this 1 time(s). 28.9.2011 і. 22:12:33, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). 27.9.2011 і. 16:09:03, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 27.9.2011 і. 16:09:00, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 25.8.2011 і. 13:22:25, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 25.8.2011 і. 13:22:06, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:22:27, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 24.8.2011 і. 17:22:08, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 24.8.2011 і. 17:17:36, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 17:17:33, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 24.8.2011 і. 15:29:53, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 24.8.2011 і. 15:29:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 15:29:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 15:29:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 15:29:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 15:29:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 15:29:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 15:29:49, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 24.8.2011 і. 15:15:31, error: Service Control Manager [7034] - The Advanced SystemCare Service service terminated unexpectedly. It has done this 1 time(s). 24.8.2011 і. 15:15:25, error: Service Control Manager [7034] - The IMF Service service terminated unexpectedly. It has done this 1 time(s). 24.8.2011 і. 12:19:53, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 12:19:49, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 24.8.2011 і. 06:53:05, error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 24.8.2011 і. 06:53:04, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. . ==== End Of File =========================== Ако може, да ми кажете как да проверя нещата в карантината че не съм много запознат с програмата, иначе няма проблеми вече не дава ерорр-и :D между другото,имам 2 непознати процеса в task manager-a: wscntfy.exe wdfmgr.exe

Редактирано от iwailo (преглед на промените)

Направете снимка на Virus Chest:

Публикувано изображение

Не сте деинсталирали следните програми:

ParetoLogic PC Health Advisor

TuneUp Utilities 2008

Ползвайте си ги на ваша отговорност...

между другото,имам 2 непознати процеса в task manager-a:

wscntfy.exe

wdfmgr.exe

Това са легитимни процеси...

Първия е от Security Center-a

Втория е от Windows Media Player 10

Добре е да инсталирате следните кръпки:

Windows XP Service Pack 3 RTM Build 5512

Mozilla Firefox 6.0.1 Final за Windows на английски

За почистването на използваните от нас инструменти направете следното:

Изтеглете TFC, стартирайте TFC.exe и изчакайте програмата да си свърши работата. Ако е необходимо да се рестартира компютъра, съгласете се.

Изтеглете OTCleanIt, стартирайте OTC.exe и натиснете Clean Up.

Ако има неизтрити от нас инструменти и логове ги изтрийте ръчно.

  • Автор

Нямам никакви вируси в клетката , сигурно защото дадох направо изтрии..

ParetoLogic PC Health Advisor - не съществува в компютъра ми о.О

TuneUp Utilities 2008 - инсталирана днес..

Исках също да попитам , на какво може да се дължи падането на фпс в играта Counter-Strike 1.6 ?

Преди нямах такъв проблем , само при smokegren..А сега като ми излезнат 4-5 човека от 100 пада на 50-60

Редактирано от iwailo (преглед на промените)

Отчета на avast! тогава може да се види от секцията Scan Logs.

Отворете реда в който пише Virus Found:

Публикувано изображение

Колкото до играта...пробвайте да я преинсталирате, защото все пак част от нея бе заразена и почистена.

Преинсталирайте и драйвърите на nVIDIA за видеокартата (защото и те бяха заразени и почистени).

Друго обяснение не намирам.

  • Автор
post-307487-0-09138100-1314887135_thumb. post-307487-0-00394800-1314887145_thumb. Заповядай. Не мисля че е от цс-а..Tака е от 2 седмици,а компютъра съм го преинсталирал 3-4 пъти от тогава..

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.