Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Цялостно премахване на AVG [РЕШЕН]

Featured Replies

Здравейте,може ли някой да ми помогне да премахна изцяло антивирусната програма AVG?Деактивирах я и искам отново да я инсталирам ,но ми показва някаква грешка снимах за да видите съжелявам ако всичко това ви се струва тъпо..но не разбирам много от такива операций...просто от facebooka ми пратиха някакъв клип и като цъкнах на него компа му стана нещо изключи се, като зареди пак при вкючването от 4-те страни на монитора в черен екран се изписа safe mode и изобщо незнам кво стана направо незнам какво да правя и бързам да го оправя преди да дойдат шефките..като цъкнах след като се вкючи компа върху avg ми показва че няма такава програма и въобще незнам какво да правя затова търся помощ от вас

post-135988-0-68690800-1319792487_thumb.

  • Отговори 91
  • Прегледи 14,5k
  • Създадено
  • Последен отговор
  • Автор

Може ли да публикувате логовете от DDS ?

Системата ми е инфектирана - Какво да правя сега?

ще пробвам, за първи път го правя това

ще пробвам, за първи път го правя това

същелявам за невежеството от моя страна но не съм чак толкова запозната...тези неща къде да ги потърся?

Прекратете временно работата на всички скрипт блокиращи приложения, ако има такива или разрешете изпълнението на dds.scr.

  • Автор

Направо стартирайте DDS и публикувайте генерираните рапорти. Не е чак толкова трудно. :)

да като знаеш и си на ти не е толкова трудно...както и да е..и да знаете за фейса че има брутален вирус сега влезнах и е изпратил сумати съобщения на приятели да цакът на тоя клип баси тъпанарите дето правят тия вируси

ето..копирах от файла attach

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-08-26.01)

.

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 05.10.2009 г. 16:04:57

System Uptime: 28.10.2011 г. 12:21:08 (0 hours ago)

.

Motherboard: Hewlett-Packard | | 085Ch

Processor: Intel® Pentium® 4 CPU 2.60GHz | XU1 PROCESSOR | 2593/800mhz

.

==== Disk Partitions =========================

.

A: is Removable

C: is FIXED (NTFS) - 24 GiB total, 10,441 GiB free.

D: is FIXED (NTFS) - 13 GiB total, 8,7 GiB free.

E: is CDROM ()

.

==== Disabled Device Manager Items =============

.

Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}

Description: PS/2 Compatible Mouse

Device ID: ACPI\PNP0F13\4&369939D9&0

Manufacturer: Microsoft

Name: PS/2 Compatible Mouse

PNP Device ID: ACPI\PNP0F13\4&369939D9&0

Service: i8042prt

.

==== System Restore Points ===================

.

RP1138: 28.10.2011 г. 10:21:21 - System Checkpoint

RP1139: 28.10.2011 г. 10:27:37 - Restore Operation

.

==== Installed Programs ======================

.

%WS4_ARP_DISPLAY%

Декларация Обр.1 и 6

µTorrent

1.59.80

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Adobe Reader 9.4.6

Advanced SystemCare 4

AutocompletePro

Avanquest update

AVG 2012

Bulgarian (Phonetic) by Iliya Dankov

CSSI 4.51 REYCON - user edition

Driver Genius Professional Edition

DSTool v1.5.1 (remove only)

Foxit PDF Creator

Foxit Reader

Free PDF to Word Converter 1.5

Google Chrome

Google Talk Plugin

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

Hotfix for Windows XP (KB2158563)

Hotfix for Windows XP (KB2443685)

Hotfix for Windows XP (KB2570791)

Hotfix for Windows XP (KB954550-v5)

Hotfix for Windows XP (KB970653-v3)

Hotfix for Windows XP (KB976002-v5)

Hotfix for Windows XP (KB976098-v2)

Hotfix for Windows XP (KB979306)

Hotfix for Windows XP (KB981793)

ICQ7.1

Indigo testing

Intel® Extreme Graphics 2 Driver

IObit Malware Fighter

IrfanView (remove only)

Java 6 Update 13

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Security Update (KB2416447)

Microsoft .NET Framework 1.1 Security Update (KB979906)

Microsoft .NET Framework 1.1 Service Pack 1

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft Kernel-Mode Driver Framework Feature Pack 1.7

Microsoft Office 2007 Service Pack 2 (SP2)

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office File Validation Add-In

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Office XP Professional

Microsoft Silverlight

Microsoft Software Update for Web Folders (English) 12

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

MSXML 4.0 SP3 Parser

MSXML 4.0 SP3 Parser (KB973685)

MyPhoneExplorer

PDFill PDF Editor with FREE Writer and FREE Tools

Picasa 3

Platform

Protected Folder

RealNetworks - Microsoft Visual C++ 2008 Runtime

RealPlayer

RealUpgrade 1.1

Samsung Universal Scan Driver

Security Update for 2007 Microsoft Office System (KB2288621)

Security Update for 2007 Microsoft Office System (KB2288931)

Security Update for 2007 Microsoft Office System (KB2345043)

Security Update for 2007 Microsoft Office System (KB2553074)

Security Update for 2007 Microsoft Office System (KB2553089)

Security Update for 2007 Microsoft Office System (KB2553090)

Security Update for 2007 Microsoft Office System (KB2584063)

Security Update for 2007 Microsoft Office System (KB969559)

Security Update for 2007 Microsoft Office System (KB976321)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)

Security Update for Microsoft Office Access 2007 (KB979440)

Security Update for Microsoft Office Excel 2007 (KB2553073)

Security Update for Microsoft Office Groove 2007 (KB2552997)

Security Update for Microsoft Office InfoPath 2007 (KB2510061)

Security Update for Microsoft Office InfoPath 2007 (KB979441)

Security Update for Microsoft Office PowerPoint 2007 (KB2535818)

Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)

Security Update for Microsoft Office Publisher 2007 (KB2284697)

Security Update for Microsoft Office system 2007 (972581)

Security Update for Microsoft Office system 2007 (KB974234)

Security Update for Microsoft Office Visio Viewer 2007 (KB973709)

Security Update for Microsoft Office Word 2007 (KB2344993)

Security Update for Microsoft Windows (KB2564958)

Security Update for Windows Internet Explorer 8 (KB2183461)

Security Update for Windows Internet Explorer 8 (KB2360131)

Security Update for Windows Internet Explorer 8 (KB2416400)

Security Update for Windows Internet Explorer 8 (KB2482017)

Security Update for Windows Internet Explorer 8 (KB2497640)

Security Update for Windows Internet Explorer 8 (KB2510531)

Security Update for Windows Internet Explorer 8 (KB2530548)

Security Update for Windows Internet Explorer 8 (KB2544521)

Security Update for Windows Internet Explorer 8 (KB2559049)

Security Update for Windows Internet Explorer 8 (KB2586448)

Security Update for Windows Internet Explorer 8 (KB971961)

Security Update for Windows Internet Explorer 8 (KB972260)

Security Update for Windows Internet Explorer 8 (KB974455)

Security Update for Windows Internet Explorer 8 (KB976325)

Security Update for Windows Internet Explorer 8 (KB978207)

Security Update for Windows Internet Explorer 8 (KB981332)

Security Update for Windows Internet Explorer 8 (KB982381)

Security Update for Windows Media Player (KB2378111)

Security Update for Windows Media Player (KB954155)

Security Update for Windows Media Player (KB968816)

Security Update for Windows Media Player (KB973540)

Security Update for Windows Media Player (KB975558)

Security Update for Windows Media Player (KB978695)

Security Update for Windows Search 4 - KB963093

Security Update for Windows XP (KB2079403)

Security Update for Windows XP (KB2115168)

Security Update for Windows XP (KB2121546)

Security Update for Windows XP (KB2160329)

Security Update for Windows XP (KB2229593)

Security Update for Windows XP (KB2259922)

Security Update for Windows XP (KB2279986)

Security Update for Windows XP (KB2286198)

Security Update for Windows XP (KB2296011)

Security Update for Windows XP (KB2296199)

Security Update for Windows XP (KB2347290)

Security Update for Windows XP (KB2360937)

Security Update for Windows XP (KB2387149)

Security Update for Windows XP (KB2393802)

Security Update for Windows XP (KB2412687)

Security Update for Windows XP (KB2419632)

Security Update for Windows XP (KB2423089)

Security Update for Windows XP (KB2436673)

Security Update for Windows XP (KB2440591)

Security Update for Windows XP (KB2443105)

Security Update for Windows XP (KB2476490)

Security Update for Windows XP (KB2476687)

Security Update for Windows XP (KB2478960)

Security Update for Windows XP (KB2478971)

Security Update for Windows XP (KB2479628)

Security Update for Windows XP (KB2479943)

Security Update for Windows XP (KB2483185)

Security Update for Windows XP (KB2485376)

Security Update for Windows XP (KB2485663)

Security Update for Windows XP (KB2503658)

Security Update for Windows XP (KB2503665)

Security Update for Windows XP (KB2506212)

Security Update for Windows XP (KB2506223)

Security Update for Windows XP (KB2507618)

Security Update for Windows XP (KB2507938)

Security Update for Windows XP (KB2508272)

Security Update for Windows XP (KB2508429)

Security Update for Windows XP (KB2509553)

Security Update for Windows XP (KB2511455)

Security Update for Windows XP (KB2524375)

Security Update for Windows XP (KB2535512)

Security Update for Windows XP (KB2536276-v2)

Security Update for Windows XP (KB2536276)

Security Update for Windows XP (KB2544893)

Security Update for Windows XP (KB2555917)

Security Update for Windows XP (KB2562937)

Security Update for Windows XP (KB2566454)

Security Update for Windows XP (KB2567053)

Security Update for Windows XP (KB2567680)

Security Update for Windows XP (KB2570222)

Security Update for Windows XP (KB2570947)

Security Update for Windows XP (KB2592799)

Security Update for Windows XP (KB956744)

Security Update for Windows XP (KB956844)

Security Update for Windows XP (KB958869)

Security Update for Windows XP (KB960859)

Security Update for Windows XP (KB961371-v2)

Security Update for Windows XP (KB961501)

Security Update for Windows XP (KB968537)

Security Update for Windows XP (KB969059)

Security Update for Windows XP (KB969947)

Security Update for Windows XP (KB970238)

Security Update for Windows XP (KB970430)

Security Update for Windows XP (KB971468)

Security Update for Windows XP (KB971486)

Security Update for Windows XP (KB971557)

Security Update for Windows XP (KB971633)

Security Update for Windows XP (KB971657)

Security Update for Windows XP (KB972270)

Security Update for Windows XP (KB973346)

Security Update for Windows XP (KB973354)

Security Update for Windows XP (KB973507)

Security Update for Windows XP (KB973525)

Security Update for Windows XP (KB973869)

Security Update for Windows XP (KB973904)

Security Update for Windows XP (KB974112)

Security Update for Windows XP (KB974318)

Security Update for Windows XP (KB974392)

Security Update for Windows XP (KB974571)

Security Update for Windows XP (KB975025)

Security Update for Windows XP (KB975467)

Security Update for Windows XP (KB975560)

Security Update for Windows XP (KB975561)

Security Update for Windows XP (KB975562)

Security Update for Windows XP (KB975713)

Security Update for Windows XP (KB977165)

Security Update for Windows XP (KB977816)

Security Update for Windows XP (KB977914)

Security Update for Windows XP (KB978037)

Security Update for Windows XP (KB978251)

Security Update for Windows XP (KB978262)

Security Update for Windows XP (KB978338)

Security Update for Windows XP (KB978542)

Security Update for Windows XP (KB978601)

Security Update for Windows XP (KB978706)

Security Update for Windows XP (KB979309)

Security Update for Windows XP (KB979482)

Security Update for Windows XP (KB979559)

Security Update for Windows XP (KB979683)

Security Update for Windows XP (KB979687)

Security Update for Windows XP (KB980195)

Security Update for Windows XP (KB980218)

Security Update for Windows XP (KB980232)

Security Update for Windows XP (KB980436)

Security Update for Windows XP (KB981322)

Security Update for Windows XP (KB981852)

Security Update for Windows XP (KB981957)

Security Update for Windows XP (KB981997)

Security Update for Windows XP (KB982132)

Security Update for Windows XP (KB982214)

Security Update for Windows XP (KB982665)

Security Update for Windows XP (KB982802)

Skype™ 5.5

Sony Ericsson PC Companion 2.01.217

Sweet Home 3D version 3.3

Universal Viewer

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft Office 2007 System (KB2539530)

Update for Microsoft Office OneNote 2007 (KB980729)

Update for Microsoft Office Outlook 2007 (KB2583910)

Update for Outlook 2007 Junk Email Filter (KB2596560)

Update for Windows Internet Explorer 8 (KB976662)

Update for Windows Internet Explorer 8 (KB976749)

Update for Windows Internet Explorer 8 (KB980182)

Update for Windows XP (KB2141007)

Update for Windows XP (KB2345886)

Update for Windows XP (KB2467659)

Update for Windows XP (KB2541763)

Update for Windows XP (KB2607712)

Update for Windows XP (KB2616676)

Update for Windows XP (KB955759)

Update for Windows XP (KB968389)

Update for Windows XP (KB971029)

Update for Windows XP (KB971737)

Update for Windows XP (KB973687)

Update for Windows XP (KB973815)

VBA (2627.01)

VIA п»ї

VLC media player 1.1.7

WebFldrs XP

Winamp

Winamp Detector Plug-in

Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray

Windows Rights Management Client Backwards Compatibility SP2

Windows Rights Management Client with Service Pack 2

WinRAR archiver

.

==== Event Viewer Messages From Past Week ========

.

28.10.2011 г. 12:21:57, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AVGIDSEH

28.10.2011 г. 12:21:57, error: Service Control Manager [7000] - The vToolbarUpdater service failed to start due to the following error: The system cannot find the file specified.

28.10.2011 г. 12:21:57, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 12:20:12, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AVGIDSEH

28.10.2011 г. 12:20:12, error: Service Control Manager [7000] - The vToolbarUpdater service failed to start due to the following error: The system cannot find the file specified.

28.10.2011 г. 12:20:12, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 11:04:42, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AVGIDSEH

28.10.2011 г. 11:04:42, error: Service Control Manager [7000] - The vToolbarUpdater service failed to start due to the following error: The system cannot find the file specified.

28.10.2011 г. 11:04:42, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:47:13, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx86

28.10.2011 г. 10:47:13, error: Service Control Manager [7000] - The vToolbarUpdater service failed to start due to the following error: The system cannot find the file specified.

28.10.2011 г. 10:47:13, error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:47:13, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:29:50, error: Service Control Manager [7000] - The vToolbarUpdater service failed to start due to the following error: The system cannot find the file specified.

28.10.2011 г. 10:29:50, error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:29:50, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:15:53, error: Service Control Manager [7000] - The vToolbarUpdater service failed to start due to the following error: The system cannot find the file specified.

28.10.2011 г. 10:15:53, error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:15:53, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

28.10.2011 г. 10:14:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

28.10.2011 г. 10:14:40, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx86 Avgmfx86 Avgtdix Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

28.10.2011 г. 10:14:40, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.

28.10.2011 г. 10:14:40, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.

28.10.2011 г. 10:14:40, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

28.10.2011 г. 10:14:40, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

28.10.2011 г. 10:13:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

28.10.2011 г. 10:11:56, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

27.10.2011 г. 16:04:19, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

27.10.2011 г. 16:01:37, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

26.10.2011 г. 19:05:32, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

26.10.2011 г. 19:05:26, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

26.10.2011 г. 16:02:04, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

26.10.2011 г. 09:09:49, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

25.10.2011 г. 18:27:37, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

25.10.2011 г. 18:27:30, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

25.10.2011 г. 16:02:33, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

25.10.2011 г. 16:01:00, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

24.10.2011 г. 18:51:06, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

24.10.2011 г. 18:50:59, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

24.10.2011 г. 16:01:51, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

24.10.2011 г. 16:01:05, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

21.10.2011 г. 21:18:32, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

21.10.2011 г. 21:18:26, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

21.10.2011 г. 17:57:14, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

21.10.2011 г. 17:57:07, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

21.10.2011 г. 16:29:28, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).

21.10.2011 г. 16:27:49, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Office XP Web Components (KB947320).

.

==== End Of File ===========================

i ot dds

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702

Run by Administrator at 12:46:21 on 2011-10-28

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1015.137 [GMT 3:00]

.

AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe

C:\program files\real\realplayer\update\realsched.exe

C:\WINDOWS\system32\rundll32.exe

"C:\WINDOWS\update.tray-12-0\svchost.exe"

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\DOS2USB\DOS2USB.exe

C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe

C:\Program Files\charismathics\smart security interface 4.51\CSPregtool.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe

svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\update.2\svchost.exe srv

C:\WINDOWS\sysdriver32.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\update.1\svchost.exe srv

"C:\WINDOWS\update.2\svchost.exe" stand

"C:\WINDOWS\update.2\svchost.exe" spamer

"C:\WINDOWS\update.2\svchost.exe" spamer

"C:\WINDOWS\update.2\svchost.exe" spamer

"C:\WINDOWS\update.2\svchost.exe" spamer

C:\Program Files\Skype\Phone\Skype.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = about:blank

uInternet Connection Wizard,ShellNext = iexplore

uURLSearchHooks: H - No File

mURLSearchHooks: H - No File

mURLSearchHooks: H - No File

mURLSearchHooks: H - No File

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\8.0.0.34\AVG Secure Search_toolbar.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\8.0.0.34\AVG Secure Search_toolbar.dll

{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [DOS2USB] c:\program files\dos2usb\DOS2USB.exe

uRun: [sony Ericsson PC Companion] "c:\program files\sony ericsson\sony ericsson pc companion\PCCompanion.exe" /Background

uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe"

uRun: [Google Update] "c:\documents and settings\administrator\local settings\application data\google\update\GoogleUpdate.exe" /c

mRun: [igfxtray] c:\windows\system32\igfxtray.exe

mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe

mRun: [igfxpers] c:\windows\system32\igfxpers.exe

mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [AudioDeck] c:\program files\via\viaudioi\sbadeck\ADeck.exe 1

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"

mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot

mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

mRun: [Corel Graphics Suite 1117] c:\program files\corel\corel graphics 11\register\registration.exe /title="Corel Graphics Suite 11" /date=082611 serial=DR11CRD-0012082-DGW

mRun: [vProt] "c:\program files\avg secure search\vprot.exe"

mRun: [wxpdrv] c:\windows\services32.exe

mRun: [tray_ico]

mRun: [tray_ico0] c:\windows\update.tray-12-0\svchost.exe

mRun: [tray_ico1]

mRun: [tray_ico2]

mRun: [tray_ico3]

mRun: [tray_ico4]

mRun: [6163721.exe] "c:\docume~1\admini~1\locals~1\temp\6163721.exe"

mRun: [sysdriver32.exe] "c:\windows\sysdriver32.exe" rezerv

mRun: [sysdriver32_.exe] "c:\windows\sysdriver32_.exe" rezerv

mRun: [8637728.exe] "c:\windows\temp\8637728.exe"

mRun: [5011438.exe] "c:\windows\temp\5011438.exe"

mRun: [6869605.exe] "c:\windows\temp\6869605.exe"

StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\smarts~1.lnk - c:\program files\charismathics\smart security interface 4.51\CSPregtool.exe

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableSecureUIAPaths = 0 (0x0)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000

IE: {71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\icq7.1\ICQ.exe

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:\program files\plotsoft\pdfill\DownloadPDF.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL

DPF: {500A3316-5B0E-4253-BBE5-CE3F11A1AE71} - hxxps://inetdec.nra.bg/dds/InetVAT5Frm.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

DPF: {97EA2A5E-A821-48A1-B0F9-DEDB5E0E62A2} - hxxps://inetdec.nra.bg/cabs/SignCOM.cab

DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{A43573F3-E734-4BF8-A0EA-623CA13B79A3} : DhcpNameServer = 192.168.1.1

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -

Notify: igfxcui - igfxdev.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

.

============= SERVICES / DRIVERS ===============

.

R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-4-26 353168]

R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2011-6-16 821080]

R2 srviecheck;srviecheck;c:\windows\update.2\svchost.exe srv --> c:\windows\update.2\svchost.exe srv [?]

R2 srvsysdriver32;srvsysdriver32;c:\windows\sysdriver32.exe srv --> c:\windows\sysdriver32.exe srv [?]

R2 wxpdrivers;wxpdrivers;c:\windows\update.1\svchost.exe srv --> c:\windows\update.1\svchost.exe srv [?]

R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-10-13 27632]

S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\avgidseh.sys --> c:\windows\system32\drivers\AVGIDSEH.Sys [?]

S2 avgwd;AVG WatchDog;"c:\program files\avg\avg2012\avgwdsvc.exe" --> c:\program files\avg\avg2012\avgwdsvc.exe [?]

S2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\8.0.1\toolbarupdater.exe --> c:\program files\common files\avg secure search\vtoolbarupdater\8.0.1\ToolbarUpdater.exe [?]

S3 A38CCID;ACR38U-CCID Smart Card Reader;c:\windows\system32\drivers\a38ccid.sys [2010-8-27 36224]

S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriver.sys --> c:\windows\system32\drivers\AVGIDSDriver.Sys [?]

S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilter.sys --> c:\windows\system32\drivers\AVGIDSFilter.Sys [?]

S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshim.sys --> c:\windows\system32\drivers\AVGIDSShim.Sys [?]

S3 RegFilter;RegFilter;c:\program files\iobit\iobit malware fighter\drivers\wxp_x86\RegFilter.sys [2011-6-16 30368]

S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-10-13 89256]

S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2009-10-13 86824]

S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [2009-10-13 15016]

S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [2009-10-13 114600]

S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [2009-10-13 108328]

S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [2009-10-13 26024]

S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [2009-10-13 104616]

S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [2009-10-13 109736]

S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\sony ericsson\sony ericsson pc companion\PCCService.exe [2011-4-6 155344]

S3 UrlFilter;UrlFilter;c:\program files\iobit\iobit malware fighter\drivers\wxp_x86\UrlFilter.sys [2011-6-16 16080]

S4 FileMonitor;FileMonitor;c:\program files\iobit\iobit malware fighter\drivers\wxp_x86\FileMonitor.sys [2011-6-16 239472]

.

=============== Created Last 30 ================

.

2011-10-28 07:28:13 -------- d-----w- c:\windows\system32\wbem\repository\FS

2011-10-28 07:28:13 -------- d-----w- c:\windows\system32\wbem\Repository

2011-10-28 07:19:24 -------- d--h--w- c:\windows\update.2

2011-10-28 07:18:34 246272 ----a-w- c:\windows\unrar.exe

2011-10-28 07:16:35 258048 ----a-w- c:\windows\sysdriver32_.exe

2011-10-28 07:16:20 258048 ----a-w- c:\windows\sysdriver32.exe

2011-10-28 07:15:48 -------- d-----w- c:\windows\av_ico

2011-10-28 07:14:26 -------- d--h--w- c:\windows\update.1

2011-10-28 07:13:53 -------- d--h--w- c:\windows\update.tray-12-0-lnk

2011-10-28 07:13:53 -------- d--h--w- c:\windows\update.tray-12-0

2011-10-28 07:01:04 1198080 ----a-w- c:\windows\services32.exe

2011-10-24 14:33:33 5157 ----a-w- c:\windows\system32\bsvi.dll

2011-10-24 14:30:30 875520 ----a-w- c:\windows\system32\VFP6RENU.DLL

2011-10-24 14:30:30 3370768 ----a-w- c:\windows\system32\VFP6R.DLL

2011-10-24 14:30:30 24990 ----a-w- c:\windows\system32\VFP6RUN.EXE

2011-10-24 14:30:25 -------- d-----w- c:\program files\INDIGO

2011-10-14 15:05:50 -------- d-----w- c:\documents and settings\administrator\application data\AVG Secure Search

2011-10-14 15:02:47 -------- d-----w- c:\documents and settings\administrator\application data\AVG2012

.

==================== Find3M ====================

.

2011-10-18 12:19:06 0 ----a-w- c:\documents and settings\administrator\dos2usb.tmp

2011-09-26 08:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll

2011-09-26 08:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll

2011-09-26 08:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll

2011-09-09 09:11:14 599552 ----a-w- c:\windows\system32\crypt32.dll

2011-09-06 13:25:11 1867904 ----a-w- c:\windows\system32\win32k.sys

2011-08-30 14:37:53 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll

2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-08-22 23:48:54 1469440 ----a-w- c:\windows\system32\inetcpl.cpl

2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec

2011-08-17 13:41:46 138496 ----a-w- c:\windows\system32\drivers\afd.sys

2011-08-11 10:42:50 0 ----a-w- c:\windows\system32\ConduitEngine.tmp

2010-03-25 16:44:48 10534 ----a-w- c:\program files\common files\acpiec.sys

.

============= FINISH: 12:47:51,96 ===============

post-135988-0-19633100-1319794830_thumb.

Не исках да ви обиждам, но наистина стартирането на DDS е лесно - само стартиране на иконката и изчакване на проверката да завърши.

Така, имате стария вариант на вируса, който е малко по-упорит за премахване. Ще се наложи използването на по-сложен инструмент, но няма страшно.

Без да се паникьосвате прочетете внимателно следните инструкции и ще се справите:

Отворете Start Menu => Control Panel => Add or Remove Programs и деинсталирайте AVG.

След това изтеглете и стартирайте този инструмент => AVG Remover(32bit) 2012

Рестартирайте компютъра.

След това:

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

  • Автор

ок много ти благодаря а как да махна вируса от FACEBOOK изпраща си разни съобщения от мое име на приятели те ми

За какво му благодарите ? Още нищо не сме направили. Къде е лог файла от Combofix ? Как да изчистите вируса...не прочетохте ли предишния ми коментар...работим по въпроса. :)

  • Автор

благодаря понеже бяхте мнгоо изчерпателен в отговора и сигурно щяхте да ми помогните но извикаха техник и той се справи бързо с проблема..обаче има друг проблем на моя копм...от доста време клипчетата от youtubi не ми зареждат и в модзилата и в хромето също и

интернет експлорера ще пратя снимка на това което ми позва а и понякога като искам да заредя google горе в браузера ми дава пак същата грешка..а иначе директно от facebooka реша да пусна някой клипче от приятели и там го го зарежда...

post-135988-0-24722900-1319916482_thumb.

Аз продължавам да си чакам лог файла от Combofix.

Явно техника, който сте извикали не е решил напълно проблема с отстраняването на заразите.

Най-вероятно имате променен hosts файл...можем много бързо да поправим това, но искам да погледна и лог файла от Combofix.

  • Изтеглете Публикувано изображение и го запазете на вашия десктоп.
  • Стартирайте програмата и изберете 3. Натиснете Enter
  • Ще се появи лог файл с името RKreport[1].txt на вашия десктоп.
  • Копирайте съдържанието му в следващия си пост.
След това направете сканирането с Combofix, както е описано в предишния ми коментар.

Ако продължите да не следвате инструкциите ще затворя темата.

Благодаря за разбирането и лека вечер !

  • Автор

добре ей сега ще го направя ,но май не разбрахте че този проблем не е на служебния комп. а на моя във вкъщи:)сега ще изтегля това което казахте и ще постна RogueKiller V6.1.5 [10/29/2011] by Tigzy mail: tigzyRK<at>gmail<dot>com Feedback: hxxp://www.geekstogo.com/forum/files/file/413-roguekiller/ Blog: http://tigzyrk.blogspot.com Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User: PCV1 [Admin rights] Mode: HOSTSFix -- Date : 10/30/2011 10:10:51 Bad processes: 1 [sUSP PATH] gbm.exe -- c:\documents and settings\pcv1\local settings\application data\gbm.exe -> KILLED [TermProc] Driver: [LOADED] HOSTS File: 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 74.125.45.100 4-open-davinci.com 74.125.45.100 securitysoftwarepayments.com 74.125.45.100 privatesecuredpayments.com 74.125.45.100 secure.privatesecuredpayments.com 74.125.45.100 getantivirusplusnow.com 74.125.45.100 secure-plus-payments.com 74.125.45.100 www.getantivirusplusnow.com 74.125.45.100 www.secure-plus-payments.com 74.125.45.100 www.getavplusnow.com 74.125.45.100 safebrowsing-cache.google.com 74.125.45.100 urs.microsoft.com 74.125.45.100 www.securesoftwarebill.com 74.125.45.100 secure.paysecuresystem.com 74.125.45.100 paysoftbillsolution.com 74.125.45.100 protected.maxisoftwaremart.com 64.46.38.208 www.google.com 64.46.38.208 google.com 64.46.38.208 google.com.au [...] Resetted HOSTS: 127.0.0.1 localhost Finished : << RKreport[1].txt >> RKreport[1].txt ето

  • Автор

ComboFix 11-10-29.06 - PCV1 10.2011 г. 10:32:35.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1023.545 [GMT 2:00]

Running from: c:\documents and settings\PCV1\My Documents\Downloads\ComboFix.exe

AV: avast! antivirus 4.8.1368 [VPS 100515-1] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

AV: Norton 360 *Disabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}

FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

* Created a new restore point

.

ADS - WINDOWS: deleted 192 bytes in 2 streams.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\All Users\Application Data\5085da

c:\documents and settings\All Users\Application Data\5085da\5085dae149f3497d8b31fe752bb165d9.ocx

c:\documents and settings\All Users\Application Data\5085da\65.mof

c:\documents and settings\All Users\Application Data\5085da\BackUp\FlexType 2K.lnk

c:\documents and settings\All Users\Application Data\5085da\frgp45e7tm9q01u8hrfifsvz6ac45e7tmwk.dll

c:\documents and settings\All Users\Application Data\5085da\SME.ico

c:\documents and settings\All Users\Application Data\5085da\SMESys\VDAI.ntf

c:\documents and settings\PCV1\Application Data\addons.dat

c:\documents and settings\PCV1\Application Data\Skype\Phone\Skype.exe

c:\documents and settings\PCV1\Application Data\Smart Engine

c:\documents and settings\PCV1\Application Data\Smart Engine\Instructions.ini

c:\documents and settings\PCV1\Local Settings\Application Data\gbm.exe

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\background.html

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\cached_http_request.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\extension_info.json

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\icons\icon128.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\icons\icon19.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\icons\icon32.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\icons\icon48.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\includes\content.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\includes\content_kango.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\includes\content_messaging.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\includes\content_userscript.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango-ui\button.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango-ui\ui.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\browser.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\console.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\event_listener.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\initialize.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\io.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\jsonstorage.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\kango.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\lang.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\messaging.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\userscript_engine.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\kango\xhr.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\main.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\manifest.json

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\minibar\actions.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\minibar\cachedxhr.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\minibar\config.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\minibar\macros.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\minibar\minibar.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\popup.html

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\popup.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\tab.html

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome\tab.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\chrome_installer.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\common.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome.manifest

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\cached_http_request.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\content.xul

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\extension_info.json

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon128.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon19.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon32.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon48.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\button.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\popup.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\popup_window.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\popup_window.xul

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-left.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-middle.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-right.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\middle-left.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\middle-right.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\style.css

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-bottom.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-left.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-right.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-top.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-left.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-middle.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-right.png

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\ui.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\browser.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\console.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\event_listener.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\initialize.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\io.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\jsonstorage.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\kango.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\lang.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\messaging.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\storage.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\uninstall_observer.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\userscript_engine.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\xhr.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\main.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\actions.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\cachedxhr.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\config.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\config.json

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\homepage_helper.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\macros.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\minibar.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\search_helper.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\search_hook.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\tabpage_helper.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox\install.rdf

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\firefox_installer.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\ie_installer.js

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\install.json

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\minibar.crx

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\minibar.xpi

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\sqlite3.exe

c:\documents and settings\PCV1\Local Settings\Application Data\Minibar\Uninstall.exe

c:\program files\Minibar\FrOGgy.dll

c:\program files\Minibar\KaNGo.dll

c:\program files\Minibar\MiNIbarbutton.dll

c:\program files\SearchBar Inc

c:\program files\SearchBar Inc\SearchBar\BandObjectLib.DLL

c:\program files\SearchBar Inc\SearchBar\Interop.SHDocVw.DLL

c:\program files\SearchBar Inc\SearchBar\log4net.DLL

c:\program files\SearchBar Inc\SearchBar\SearchBar.dll

c:\program files\SearchBar Inc\SearchBar\SearchBar.dll.config

c:\program files\SearchBar Inc\SearchBar\SearchBar.InstallState

c:\windows\system32\d3d9caps.dat

c:\windows\system32\Thumbs.db

c:\windows\UA000059.DLL

c:\windows\XSxS

d:\pepyto\()B916~1\knigi\TOLE_n~1.exe

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_SSHNAS

.

.

((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-30 )))))))))))))))))))))))))))))))

.

.

2011-10-30 08:10 . 2011-10-30 08:11 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys

2011-10-24 21:02 . 2011-10-24 21:02 -------- d-----w- c:\documents and settings\PCV1\Application Data\NVIDIA

2011-10-24 15:56 . 2011-10-24 15:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-10-24 15:25 . 2011-10-24 15:25 -------- d-----w- c:\documents and settings\UpdatusUser

2011-10-24 15:25 . 2011-10-24 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA

2011-10-24 15:25 . 2011-10-24 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation

2011-10-24 15:25 . 2011-08-03 11:49 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll

2011-10-24 15:24 . 2011-10-24 15:24 280276 ----a-w- c:\windows\system32\nvdrsdb0.bin

2011-10-24 15:24 . 2011-10-24 15:24 1 ----a-w- c:\windows\system32\nvdrssel.bin

2011-10-24 15:24 . 2011-10-24 15:24 280276 ----a-w- c:\windows\system32\nvdrsdb1.bin

2011-10-24 15:23 . 2011-08-03 11:49 61440 ----a-w- c:\windows\system32\OpenCL.dll

2011-10-24 15:23 . 2011-08-03 11:49 914024 ----a-w- c:\windows\system32\nvdispco32.dll

2011-10-24 15:23 . 2011-08-03 11:49 875112 ----a-w- c:\windows\system32\nvgenco32.dll

2011-10-24 15:23 . 2011-08-03 11:49 17186816 ----a-w- c:\windows\system32\nvcompiler.dll

2011-10-24 15:23 . 2011-10-24 15:25 -------- d-----w- c:\program files\NVIDIA Corporation

2011-10-24 15:22 . 2011-10-24 15:22 -------- d-----w- C:\NVIDIA

2011-10-24 14:05 . 2011-10-24 14:05 -------- d-----w- c:\program files\Realtek

2011-10-24 14:04 . 2011-10-24 14:04 319488 ----a-w- c:\windows\HideWin.exe

2011-10-24 14:04 . 2011-08-31 16:12 1698408 ----a-w- c:\windows\RtlExUpd.dll

2011-10-24 14:04 . 2006-02-07 12:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll

2011-10-24 14:04 . 2006-02-07 12:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll

2011-10-24 14:04 . 2006-02-07 12:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll

2011-10-24 14:04 . 2006-02-07 12:39 32768 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\Objectps.dll

2011-10-24 14:04 . 2006-02-07 12:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll

2011-10-24 14:04 . 2005-11-13 20:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe

2011-10-24 14:04 . 2011-10-24 14:04 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll

2011-10-24 14:04 . 2011-10-24 14:04 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll

2011-10-23 14:41 . 2011-10-23 14:41 4096 ----a-w- c:\windows\system32\04.tmp

2011-10-21 21:58 . 2011-10-21 21:58 -------- d-----w- c:\program files\Intel

2011-10-21 21:58 . 2011-08-31 12:20 53248 ----a-w- c:\windows\system32\CSVer.dll

2011-10-21 21:57 . 2011-10-21 21:57 -------- d-----w- C:\Intel

2011-10-21 21:54 . 2011-10-21 21:54 -------- d-----w- c:\windows\VMUVC

2011-10-21 21:54 . 2008-04-03 11:35 250240 ----a-w- c:\windows\system32\drivers\VMUVC.sys

2011-10-21 21:54 . 2008-02-29 07:11 11776 ----a-w- c:\windows\system32\VMUVC.dll

2011-10-21 21:54 . 2007-11-14 15:08 476160 ----a-w- c:\windows\system32\drivers\vvftUVC.sys

2011-10-21 21:54 . 2007-10-11 10:51 188416 ----a-w- c:\windows\system32\vvftUVC.ax

2011-10-21 21:54 . 2007-09-05 14:00 516096 ----a-w- c:\windows\system32\VMUVC.ax

2011-10-21 21:54 . 2007-04-16 12:12 98304 ----a-w- c:\windows\system32\VMCtrl.ax

2011-10-21 21:54 . 2007-04-12 20:00 94208 ----a-w- c:\windows\system32\VvFtCtrl.dll

2011-10-21 21:54 . 2007-04-12 19:59 73728 ----a-w- c:\windows\system32\exvmuvc.ax

2011-10-21 21:54 . 2011-10-21 21:54 -------- d-----w- c:\program files\Vimicro Corporation

2011-10-21 21:53 . 2011-10-21 21:53 -------- d-----w- c:\documents and settings\PCV1\Application Data\InstallShield

2011-10-21 18:46 . 2011-10-21 18:46 -------- d-----w- c:\program files\Driver-Soft

2011-10-15 21:48 . 2011-10-15 21:48 -------- d-----w- c:\documents and settings\All Users\Uniblue

2011-10-15 21:47 . 2011-10-15 21:47 -------- d-----w- c:\program files\DAEMON Tools Lite

2011-10-14 23:45 . 2011-10-14 23:45 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software

2011-10-07 22:01 . 2011-10-07 22:01 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}

2011-10-07 20:48 . 2011-10-07 20:49 -------- d-----w- c:\program files\FormatFactory

2011-10-04 13:00 . 2011-10-04 13:00 19416 ----a-w- c:\program files\Mozilla Firefox\AccessibleMarshal.dll

2011-10-04 13:00 . 2011-10-04 13:00 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-10-15 21:47 . 2010-02-22 16:27 443448 ----a-w- c:\windows\system32\drivers\sptd.sys

2011-09-04 20:43 . 2011-09-04 20:43 180 ----a-w- C:\folderopenssearch.reg

2011-08-30 14:28 . 2010-02-20 14:19 6435432 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys

2011-08-29 13:20 . 2010-02-20 14:19 1493608 ----a-w- c:\windows\RtlUpd.exe

2011-08-27 11:46 . 2011-08-27 11:46 4452 ----a-w- c:\windows\system32\pictureandfaxrestore.reg

2011-08-23 09:06 . 2010-02-20 14:20 63592 ----a-w- c:\windows\system32\RtkCoInstXP.dll

2011-08-18 18:58 . 2011-08-18 18:59 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-08-18 18:58 . 2010-07-22 13:28 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-08-17 14:09 . 2010-02-20 14:19 20064872 ----a-w- c:\windows\RTHDCPL.EXE

2011-08-11 15:59 . 2011-08-11 15:56 592 ----a-w- c:\windows\chgkey.vbs

2011-08-03 11:49 . 2010-02-20 14:22 5427200 ----a-w- c:\windows\system32\nvcuda.dll

2011-08-03 11:49 . 2010-02-20 14:22 4210816 ----a-w- c:\windows\system32\nv4_disp.dll

2011-08-03 11:49 . 2010-02-20 14:22 2404864 ----a-w- c:\windows\system32\nvapi.dll

2011-08-03 11:49 . 2010-02-20 14:22 2387560 ----a-w- c:\windows\system32\nvcuvid.dll

2011-08-03 11:49 . 2010-02-20 14:22 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll

2011-08-03 11:49 . 2010-02-20 14:22 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys

2011-08-03 11:49 . 2010-02-20 14:22 16191488 ----a-w- c:\windows\system32\nvoglnt.dll

2011-08-03 11:49 . 2009-04-30 22:30 331776 ----a-w- c:\windows\system32\nvrshe.dll

2011-08-03 11:49 . 2009-04-30 22:30 282624 ----a-w- c:\windows\system32\nvrsit.dll

2011-08-03 11:49 . 2009-04-30 22:30 274432 ----a-w- c:\windows\system32\nvrspt.dll

2011-08-03 11:49 . 2009-04-30 22:30 274432 ----a-w- c:\windows\system32\nvrsnl.dll

2011-08-03 11:49 . 2009-04-30 22:30 270336 ----a-w- c:\windows\system32\nvrsru.dll

2011-08-03 11:49 . 2009-04-30 22:30 270336 ----a-w- c:\windows\system32\nvrsptb.dll

2011-08-03 11:49 . 2009-04-30 22:30 270336 ----a-w- c:\windows\system32\nvrsja.dll

2011-08-03 11:49 . 2009-04-30 22:30 266240 ----a-w- c:\windows\system32\nvrsko.dll

2011-08-03 11:49 . 2009-04-30 22:30 262144 ----a-w- c:\windows\system32\nvrshu.dll

2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrstr.dll

2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrssl.dll

2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrssk.dll

2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrspl.dll

2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrsth.dll

2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrssv.dll

2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrsno.dll

2011-08-03 11:49 . 2009-04-30 22:30 229376 ----a-w- c:\windows\system32\nvrszhc.dll

2011-08-03 11:49 . 2009-04-30 22:30 126976 ----a-w- c:\windows\system32\nvrszht.dll

2011-08-03 11:49 . 2009-04-30 22:30 54272 ----a-w- c:\windows\system32\nvwddi.dll

2011-08-03 11:49 . 2009-04-30 22:30 335872 ----a-w- c:\windows\system32\nvrsar.dll

2011-08-03 11:49 . 2009-04-30 22:30 286720 ----a-w- c:\windows\system32\nvrsfr.dll

2011-08-03 11:49 . 2009-04-30 22:30 282624 ----a-w- c:\windows\system32\nvrses.dll

2011-08-03 11:49 . 2009-04-30 22:30 282624 ----a-w- c:\windows\system32\nvrsel.dll

2011-08-03 11:49 . 2009-04-30 22:30 278528 ----a-w- c:\windows\system32\nvrsde.dll

2011-08-03 11:49 . 2009-04-30 22:30 274432 ----a-w- c:\windows\system32\nvrsesm.dll

2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrsda.dll

2011-08-03 11:49 . 2009-04-30 22:30 249856 ----a-w- c:\windows\system32\nvrsfi.dll

2011-08-03 11:49 . 2009-04-30 22:30 249856 ----a-w- c:\windows\system32\nvrseng.dll

2011-08-03 11:49 . 2009-04-30 22:30 249856 ----a-w- c:\windows\system32\nvrscs.dll

2011-08-03 11:49 . 2009-04-30 22:30 146024 ----a-w- c:\windows\system32\nvsvc32.exe

2011-08-03 11:49 . 2009-04-30 22:30 145000 ----a-w- c:\windows\system32\nvcolor.exe

2011-08-03 11:49 . 2009-04-30 22:30 13892200 ----a-w- c:\windows\system32\nvcpl.dll

2011-08-03 11:49 . 2009-04-30 22:30 111208 ----a-w- c:\windows\system32\nvmctray.dll

2011-07-19 10:57 . 2011-07-19 10:57 10534 ----a-w- c:\program files\Common Files\acpiec.sys

2011-10-04 13:00 . 2011-09-13 22:10 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{79754755-0120-4fb4-b3ec-84a8b8efa4b7}"= "c:\program files\Direct_2_Drive\prxtbDir0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}]

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}]

2011-05-09 09:49 176936 ----a-w- c:\program files\Direct_2_Drive\prxtbDir0.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{79754755-0120-4fb4-b3ec-84a8b8efa4b7}"= "c:\program files\Direct_2_Drive\prxtbDir0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{79754755-0120-4FB4-B3EC-84A8B8EFA4B7}"= "c:\program files\Direct_2_Drive\prxtbDir0.dll" [2011-05-09 176936]

.

[HKEY_CLASSES_ROOT\clsid\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-03-26 135168]

"RTHDCPL"="RTHDCPL.EXE" [2011-08-17 20064872]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]

"NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208]

"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2010-2-20 151552]

McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

@="Service"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2011-08-17 14:09 20064872 ----a-w- c:\windows\RTHDCPL.EXE

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"ose"=3 (0x3)

"wscsvc"=2 (0x2)

"WMPNetworkSvc"=3 (0x3)

"WmiApSrv"=3 (0x3)

"SSDPSRV"=3 (0x3)

"RemoteRegistry"=2 (0x2)

"Schedule"=2 (0x2)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun

"ctfmon.exe"=c:\windows\system32\ctfmon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

"nwiz"=nwiz.exe /install

"DWPersistentQueuedReporting"=c:\program files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE -a

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

"DisableNotifications"= 1 (0x1)

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\CSS\\hl2.exe"=

"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=

"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=

"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2996:TCP"= 2996:TCP:oouglt

"2706:TCP"= 2706:TCP:Inhatch P2P Streaming

"2707:TCP"= 2707:TCP:Inhatch P2P Streaming

"2708:TCP"= 2708:TCP:Inhatch P2P Streaming

"2709:TCP"= 2709:TCP:Inhatch P2P Streaming

"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443

"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443

"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674

"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674

"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675

.

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [07.1.2009 г. 22:39 20104]

R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\symds.sys [03.5.2011 г. 01:29 340088]

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\symefa.sys [03.5.2011 г. 01:29 744568]

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [20.2.2010 г. 15:47 114768]

R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110309.001\BHDrvx86.sys [10.3.2011 г. 23:38 800376]

R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\ironx86.sys [03.5.2011 г. 01:29 136312]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.2.2010 г. 15:47 20560]

R2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [14.1.2011 г. 12:35 196912]

R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [24.10.2011 г. 17:25 2255464]

R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [25.5.2011 г. 22:13 632792]

R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [23.8.2010 г. 16:17 2368]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [09.2.2011 г. 13:03 102448]

R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;c:\windows\system32\drivers\hcw88rc5.sys [20.2.2010 г. 16:21 11841]

R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [20.2.2010 г. 16:21 140865]

R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [20.2.2010 г. 16:21 613204]

R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [20.2.2010 г. 16:21 30528]

R3 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21.4.2007 г. 13:54 52080]

R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [21.10.2011 г. 23:54 250240]

R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [21.10.2011 г. 23:54 476160]

S2 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 13:16 130384]

S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [09.11.2010 г. 11:23 135664]

S2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccsvchst.exe [03.5.2011 г. 01:29 130008]

S2 pgxbnhnlt;Driver Shell;c:\windows\system32\svchost.exe -k netsvcs [14.4.2008 г. 14:00 14336]

S2 RoxLiveShare10;LiveShare P2P Server 10;"c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" --> c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [?]

S2 SessionLauncher;SessionLauncher;c:\docume~1\PCV1\LOCALS~1\Temp\DX9\SessionLauncher.exe --> c:\docume~1\PCV1\LOCALS~1\Temp\DX9\SessionLauncher.exe [?]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.2.2010 г. 16:20 1691480]

S3 aqyvqjsh;aqyvqjsh;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]

S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys --> c:\windows\system32\DRIVERS\btcomport.sys [?]

S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys --> c:\windows\system32\Drivers\btcombus.sys [?]

S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [07.12.2008 г. 11:44 25864]

S3 codzsabk;codzsabk;\??\c:\windows\system32\06.tmp --> c:\windows\system32\06.tmp [?]

S3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110408.001\IDSXpx86.sys [09.4.2011 г. 00:53 341944]

S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [02.7.2008 г. 13:58 23048]

S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 г. 14:49 227232]

S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [11.8.2011 г. 21:29 27064]

S3 sbnjqv;sbnjqv;\??\c:\windows\system32\03.tmp --> c:\windows\system32\03.tmp [?]

S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [30.10.2011 г. 10:10 111872]

S3 ubyyiadqq;ubyyiadqq;c:\windows\system32\04.tmp [23.10.2011 г. 16:41 4096]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 13:16 753504]

S3 xyybiqel;xyybiqel;\??\c:\windows\system32\03.tmp --> c:\windows\system32\03.tmp [?]

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WUAUSERV

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

fklzpetlk

pgxbnhnlt

.

Contents of the 'Scheduled Tasks' folder

.

2011-08-11 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]

.

2011-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc8df6cfe71180.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-09 09:23]

.

2011-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-09 09:23]

.

2010-04-27 c:\windows\Tasks\Install.job

- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2010-04-20 14:54]

.

2011-05-25 c:\windows\Tasks\RMSchedule.job

- c:\program files\Registry Mechanic\RegMech.exe [2011-05-25 07:02]

.

2011-05-25 c:\windows\Tasks\RMSmartUpdate.job

- c:\program files\Registry Mechanic\Update.exe [2011-05-25 10:23]

.

2011-09-26 c:\windows\Tasks\SLOW-PCfighter-PCV1-Startup.job

- c:\program files\Fighters\SLOW-PCfighter\SLOW-PCfighter.exe [2011-09-01 09:48]

.

2011-10-22 c:\windows\Tasks\User_Feed_Synchronization-{CC1C45FC-861B-4B2C-9242-BB7A7008C42F}.job

- c:\windows\system32\msfeedssync.exe [2008-04-14 03:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100474&mntrId=a41869f1000000000000101111111111

uDefault_Search_URL = hxxp://tudosearch.com/index.php?q=

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = *.local

uInternet Settings,ProxyServer = http=127.0.0.1:25536

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html

TCP: DhcpNameServer = 87.246.24.6

FF - ProfilePath - c:\documents and settings\PCV1\Application Data\Mozilla\Firefox\Profiles\379h1v5k.default\

.

- - - - ORPHANS REMOVED - - - -

.

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-TaskTray - (no file)

Notify-WgaLogon - (no file)

SafeBoot-WudfPf

SafeBoot-WudfRd

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-10-30 11:22

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]

"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aqyvqjsh]

"ImagePath"="\??\c:\windows\system32\02.tmp"

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\codzsabk]

"ImagePath"="\??\c:\windows\system32\06.tmp"

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sbnjqv]

"ImagePath"="\??\c:\windows\system32\03.tmp"

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ubyyiadqq]

"ImagePath"="\??\c:\windows\system32\04.tmp"

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xyybiqel]

"ImagePath"="\??\c:\windows\system32\03.tmp"

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pgxbnhnlt]

"ServiceDll"="c:\windows\system32\xbaoymi.dll"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(3536)

c:\windows\system32\newdll.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\OneX.DLL

c:\windows\system32\eappprxy.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll

c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL

c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr

c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\nvsvc32.exe

c:\program files\Alwil Software\Avast4\aswUpdSv.exe

c:\program files\Alwil Software\Avast4\ashServ.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\windows\system32\RunDLL32.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\PC Connectivity Solution\ServiceLayer.exe

c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe

c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe

c:\windows\system32\wscntfy.exe

c:\program files\Alwil Software\Avast4\ashMaiSv.exe

c:\program files\Alwil Software\Avast4\ashWebSv.exe

c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe

c:\windows\system32\dwwin.exe

.

**************************************************************************

.

Completion time: 2011-10-30 11:26:30 - machine was rebooted

ComboFix-quarantined-files.txt 2011-10-30 09:26

.

Pre-Run: 3 985 870 848 bytes free

Post-Run: 4 056 440 832 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - CB2673411A0F964D5C977D9C7892ED0B

post-135988-0-22110900-1319968864_thumb.

post-135988-0-43050900-1319968933_thumb.

Така...иамме доста работа още:

*. Изтрийте вашето копие на Combofix и изтеглете ново оттук

*. Отворете notepad.exe и с copy/paste въведете следната информация:

http://www.kaldata.com/forums/index.php?showtopic=185848

Driver::
pgxbnhnlt
aqyvqjsh
codzsabk
sbnjqv
ubyyiadqq
xyybiqel
Collect::
c:\windows\system32\02.tmp
c:\windows\system32\03.tmp
c:\windows\system32\04.tmp
c:\windows\system32\06.tmp
c:\windows\system32\xbaoymi.dll
Suspect::[4]
C:\Qoobox\Quarantine\C\Documents and Settings\PCV1\Application Data\Skype\Phone\Skype.exe.vir
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000001
"DisableNotifications"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2996:TCP"=-
NetSvc::
fklzpetlk
pgxbnhnlt
DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:25536

Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

Публикувано изображение

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. По време на тази операция Combofix ще отвори диалогов прозорец. Със скрипта който изпълнихте той ще архивира и ще изпрати няколко файлове за анализ. Необходимо е да се свързан към Интеренет преди да натиснете OK. Ще се появи син прозорец чрез който вие можете да проследите цялата операция. Накарая ще получите съобщението "Upload was Successful".

*. Ако по някаква причина Combofix не успее да изпрати файловете (вижте снимката отдолу):

Публикувано изображение

тогава просто кликнете върху файла C:\CF-Submit.htm и следвайте инструкциите за да го изпратите.

*. Когато Combofix приключи ще създаде лог файла. Моя, публикувайте този файл в следващия си пост.

Поздрави !

  • Автор

ок ще го направя но не ми дава да променя файла на нотепад ако натисна да промени ми излиза като файл който не съществува..дано да ме разбра какво точно казвам

Пробвайте да изтеглите файла от прикачения ми коментар и го пуснете в Combofix с drag&drop както е показано на картинката (с влачене).

CFScript.txt

  • Автор

ок като го влача направо ми дава run

ок като го влача направо ми дава run

Да разбирам, че проверката се е активирала ? Ако е така оставете да завърши и после публикувайте лог файла. :cool:

  • Автор

ок като го влача направо ми дава run

да натисна ли run
  • Автор

blagodarq ti 4e mi pimaga6..sajelqvam za latinicata no ne mi smenq na bg sigurno trqbva da go restartiram ve4e eto copy ot fajla ComboFix 11-10-30.02 - PCV1 10.2011 г. 14:24:10.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1023.469 [GMT 2:00] Running from: c:\documents and settings\PCV1\My Documents\Downloads\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 100515-1] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: Norton 360 *Disabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . . ((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-30 ))))))))))))))))))))))))))))))) . . 2011-10-30 08:10 . 2011-10-30 08:11 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2011-10-24 21:02 . 2011-10-24 21:02 -------- d-----w- c:\documents and settings\PCV1\Application Data\NVIDIA 2011-10-24 15:56 . 2011-10-24 15:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-24 15:25 . 2011-10-24 15:25 -------- d-----w- c:\documents and settings\UpdatusUser 2011-10-24 15:25 . 2011-10-24 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA 2011-10-24 15:25 . 2011-10-24 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation 2011-10-24 15:25 . 2011-08-03 11:49 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll 2011-10-24 15:24 . 2011-10-24 15:24 280276 ----a-w- c:\windows\system32\nvdrsdb0.bin 2011-10-24 15:24 . 2011-10-24 15:24 1 ----a-w- c:\windows\system32\nvdrssel.bin 2011-10-24 15:24 . 2011-10-24 15:24 280276 ----a-w- c:\windows\system32\nvdrsdb1.bin 2011-10-24 15:23 . 2011-08-03 11:49 61440 ----a-w- c:\windows\system32\OpenCL.dll 2011-10-24 15:23 . 2011-08-03 11:49 914024 ----a-w- c:\windows\system32\nvdispco32.dll 2011-10-24 15:23 . 2011-08-03 11:49 875112 ----a-w- c:\windows\system32\nvgenco32.dll 2011-10-24 15:23 . 2011-08-03 11:49 17186816 ----a-w- c:\windows\system32\nvcompiler.dll 2011-10-24 15:23 . 2011-10-24 15:25 -------- d-----w- c:\program files\NVIDIA Corporation 2011-10-24 15:22 . 2011-10-24 15:22 -------- d-----w- C:\NVIDIA 2011-10-24 14:05 . 2011-10-24 14:05 -------- d-----w- c:\program files\Realtek 2011-10-24 14:04 . 2011-10-24 14:04 319488 ----a-w- c:\windows\HideWin.exe 2011-10-24 14:04 . 2011-08-31 16:12 1698408 ----a-w- c:\windows\RtlExUpd.dll 2011-10-24 14:04 . 2006-02-07 12:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll 2011-10-24 14:04 . 2006-02-07 12:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll 2011-10-24 14:04 . 2006-02-07 12:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll 2011-10-24 14:04 . 2006-02-07 12:39 32768 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\Objectps.dll 2011-10-24 14:04 . 2006-02-07 12:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll 2011-10-24 14:04 . 2005-11-13 20:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe 2011-10-24 14:04 . 2011-10-24 14:04 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll 2011-10-24 14:04 . 2011-10-24 14:04 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll 2011-10-23 14:41 . 2011-10-23 14:41 4096 ----a-w- c:\windows\system32\04.tmp 2011-10-21 21:58 . 2011-10-21 21:58 -------- d-----w- c:\program files\Intel 2011-10-21 21:58 . 2011-08-31 12:20 53248 ----a-w- c:\windows\system32\CSVer.dll 2011-10-21 21:57 . 2011-10-21 21:57 -------- d-----w- C:\Intel 2011-10-21 21:54 . 2011-10-21 21:54 -------- d-----w- c:\windows\VMUVC 2011-10-21 21:54 . 2008-04-03 11:35 250240 ----a-w- c:\windows\system32\drivers\VMUVC.sys 2011-10-21 21:54 . 2008-02-29 07:11 11776 ----a-w- c:\windows\system32\VMUVC.dll 2011-10-21 21:54 . 2007-11-14 15:08 476160 ----a-w- c:\windows\system32\drivers\vvftUVC.sys 2011-10-21 21:54 . 2007-10-11 10:51 188416 ----a-w- c:\windows\system32\vvftUVC.ax 2011-10-21 21:54 . 2007-09-05 14:00 516096 ----a-w- c:\windows\system32\VMUVC.ax 2011-10-21 21:54 . 2007-04-16 12:12 98304 ----a-w- c:\windows\system32\VMCtrl.ax 2011-10-21 21:54 . 2007-04-12 20:00 94208 ----a-w- c:\windows\system32\VvFtCtrl.dll 2011-10-21 21:54 . 2007-04-12 19:59 73728 ----a-w- c:\windows\system32\exvmuvc.ax 2011-10-21 21:54 . 2011-10-21 21:54 -------- d-----w- c:\program files\Vimicro Corporation 2011-10-21 21:53 . 2011-10-21 21:53 -------- d-----w- c:\documents and settings\PCV1\Application Data\InstallShield 2011-10-21 18:46 . 2011-10-21 18:46 -------- d-----w- c:\program files\Driver-Soft 2011-10-15 21:48 . 2011-10-15 21:48 -------- d-----w- c:\documents and settings\All Users\Uniblue 2011-10-15 21:47 . 2011-10-15 21:47 -------- d-----w- c:\program files\DAEMON Tools Lite 2011-10-14 23:45 . 2011-10-14 23:45 -------- d-----w- c:\documents and settings\LocalService\Application Data\TuneUp Software 2011-10-07 22:01 . 2011-10-07 22:01 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} 2011-10-07 20:48 . 2011-10-07 20:49 -------- d-----w- c:\program files\FormatFactory 2011-10-04 13:00 . 2011-10-04 13:00 19416 ----a-w- c:\program files\Mozilla Firefox\AccessibleMarshal.dll 2011-10-04 13:00 . 2011-10-04 13:00 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-15 21:47 . 2010-02-22 16:27 443448 ----a-w- c:\windows\system32\drivers\sptd.sys 2011-09-04 20:43 . 2011-09-04 20:43 180 ----a-w- C:\folderopenssearch.reg 2011-08-30 14:28 . 2010-02-20 14:19 6435432 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys 2011-08-29 13:20 . 2010-02-20 14:19 1493608 ----a-w- c:\windows\RtlUpd.exe 2011-08-27 11:46 . 2011-08-27 11:46 4452 ----a-w- c:\windows\system32\pictureandfaxrestore.reg 2011-08-23 09:06 . 2010-02-20 14:20 63592 ----a-w- c:\windows\system32\RtkCoInstXP.dll 2011-08-18 18:58 . 2011-08-18 18:59 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-08-18 18:58 . 2010-07-22 13:28 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-08-17 14:09 . 2010-02-20 14:19 20064872 ----a-w- c:\windows\RTHDCPL.EXE 2011-08-11 15:59 . 2011-08-11 15:56 592 ----a-w- c:\windows\chgkey.vbs 2011-08-03 11:49 . 2010-02-20 14:22 5427200 ----a-w- c:\windows\system32\nvcuda.dll 2011-08-03 11:49 . 2010-02-20 14:22 4210816 ----a-w- c:\windows\system32\nv4_disp.dll 2011-08-03 11:49 . 2010-02-20 14:22 2404864 ----a-w- c:\windows\system32\nvapi.dll 2011-08-03 11:49 . 2010-02-20 14:22 2387560 ----a-w- c:\windows\system32\nvcuvid.dll 2011-08-03 11:49 . 2010-02-20 14:22 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll 2011-08-03 11:49 . 2010-02-20 14:22 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys 2011-08-03 11:49 . 2010-02-20 14:22 16191488 ----a-w- c:\windows\system32\nvoglnt.dll 2011-08-03 11:49 . 2009-04-30 22:30 331776 ----a-w- c:\windows\system32\nvrshe.dll 2011-08-03 11:49 . 2009-04-30 22:30 282624 ----a-w- c:\windows\system32\nvrsit.dll 2011-08-03 11:49 . 2009-04-30 22:30 274432 ----a-w- c:\windows\system32\nvrspt.dll 2011-08-03 11:49 . 2009-04-30 22:30 274432 ----a-w- c:\windows\system32\nvrsnl.dll 2011-08-03 11:49 . 2009-04-30 22:30 270336 ----a-w- c:\windows\system32\nvrsru.dll 2011-08-03 11:49 . 2009-04-30 22:30 270336 ----a-w- c:\windows\system32\nvrsptb.dll 2011-08-03 11:49 . 2009-04-30 22:30 270336 ----a-w- c:\windows\system32\nvrsja.dll 2011-08-03 11:49 . 2009-04-30 22:30 266240 ----a-w- c:\windows\system32\nvrsko.dll 2011-08-03 11:49 . 2009-04-30 22:30 262144 ----a-w- c:\windows\system32\nvrshu.dll 2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrstr.dll 2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrssl.dll 2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrssk.dll 2011-08-03 11:49 . 2009-04-30 22:30 258048 ----a-w- c:\windows\system32\nvrspl.dll 2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrsth.dll 2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrssv.dll 2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrsno.dll 2011-08-03 11:49 . 2009-04-30 22:30 229376 ----a-w- c:\windows\system32\nvrszhc.dll 2011-08-03 11:49 . 2009-04-30 22:30 126976 ----a-w- c:\windows\system32\nvrszht.dll 2011-08-03 11:49 . 2009-04-30 22:30 54272 ----a-w- c:\windows\system32\nvwddi.dll 2011-08-03 11:49 . 2009-04-30 22:30 335872 ----a-w- c:\windows\system32\nvrsar.dll 2011-08-03 11:49 . 2009-04-30 22:30 286720 ----a-w- c:\windows\system32\nvrsfr.dll 2011-08-03 11:49 . 2009-04-30 22:30 282624 ----a-w- c:\windows\system32\nvrses.dll 2011-08-03 11:49 . 2009-04-30 22:30 282624 ----a-w- c:\windows\system32\nvrsel.dll 2011-08-03 11:49 . 2009-04-30 22:30 278528 ----a-w- c:\windows\system32\nvrsde.dll 2011-08-03 11:49 . 2009-04-30 22:30 274432 ----a-w- c:\windows\system32\nvrsesm.dll 2011-08-03 11:49 . 2009-04-30 22:30 253952 ----a-w- c:\windows\system32\nvrsda.dll 2011-08-03 11:49 . 2009-04-30 22:30 249856 ----a-w- c:\windows\system32\nvrsfi.dll 2011-08-03 11:49 . 2009-04-30 22:30 249856 ----a-w- c:\windows\system32\nvrseng.dll 2011-08-03 11:49 . 2009-04-30 22:30 249856 ----a-w- c:\windows\system32\nvrscs.dll 2011-08-03 11:49 . 2009-04-30 22:30 146024 ----a-w- c:\windows\system32\nvsvc32.exe 2011-08-03 11:49 . 2009-04-30 22:30 145000 ----a-w- c:\windows\system32\nvcolor.exe 2011-08-03 11:49 . 2009-04-30 22:30 13892200 ----a-w- c:\windows\system32\nvcpl.dll 2011-08-03 11:49 . 2009-04-30 22:30 111208 ----a-w- c:\windows\system32\nvmctray.dll 2011-07-19 10:57 . 2011-07-19 10:57 10534 ----a-w- c:\program files\Common Files\acpiec.sys 2011-10-04 13:00 . 2011-09-13 22:10 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((( SnapShot@2011-10-30_09.21.35 ))))))))))))))))))))))))))))))))))))))))) . + 2011-10-30 11:43 . 2011-10-30 11:43 16384 c:\windows\Temp\Perflib_Perfdata_630.dat + 2011-10-30 11:43 . 2011-10-30 11:43 16384 c:\windows\Temp\Perflib_Perfdata_594.dat - 2008-04-14 12:00 . 2011-08-11 18:53 88326 c:\windows\system32\perfc009.dat + 2008-04-14 12:00 . 2011-10-30 09:24 88326 c:\windows\system32\perfc009.dat - 2010-02-20 13:29 . 2011-10-30 09:22 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2010-02-20 13:29 . 2011-10-30 11:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - 2010-02-20 13:29 . 2011-10-30 09:22 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2010-02-20 13:29 . 2011-10-30 11:44 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2010-02-20 13:29 . 2011-10-30 11:44 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat - 2010-02-20 13:29 . 2011-10-30 09:22 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat - 2008-04-14 12:00 . 2011-08-11 18:53 504862 c:\windows\system32\perfh009.dat + 2008-04-14 12:00 . 2011-10-30 09:24 504862 c:\windows\system32\perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{79754755-0120-4fb4-b3ec-84a8b8efa4b7}"= "c:\program files\Direct_2_Drive\prxtbDir0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}] 2011-05-09 09:49 176936 ----a-w- c:\program files\Direct_2_Drive\prxtbDir0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{79754755-0120-4fb4-b3ec-84a8b8efa4b7}"= "c:\program files\Direct_2_Drive\prxtbDir0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{79754755-0120-4FB4-B3EC-84A8B8EFA4B7}"= "c:\program files\Direct_2_Drive\prxtbDir0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{79754755-0120-4fb4-b3ec-84a8b8efa4b7}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-03-26 135168] "RTHDCPL"="RTHDCPL.EXE" [2011-08-17 20064872] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200] "NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2010-2-20 151552] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2011-08-17 14:09 20064872 ----a-w- c:\windows\RTHDCPL.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ose"=3 (0x3) "wscsvc"=2 (0x2) "WMPNetworkSvc"=3 (0x3) "WmiApSrv"=3 (0x3) "SSDPSRV"=3 (0x3) "RemoteRegistry"=2 (0x2) "Schedule"=2 (0x2) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun "ctfmon.exe"=c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" "NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup "NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit "nwiz"=nwiz.exe /install "DWPersistentQueuedReporting"=c:\program files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE -a . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "DisableNotifications"= 1 (0x1) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\CSS\\hl2.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2996:TCP"= 2996:TCP:oouglt "2706:TCP"= 2706:TCP:Inhatch P2P Streaming "2707:TCP"= 2707:TCP:Inhatch P2P Streaming "2708:TCP"= 2708:TCP:Inhatch P2P Streaming "2709:TCP"= 2709:TCP:Inhatch P2P Streaming "443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443 "443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443 "37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674 "37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674 "37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675 . R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [07.1.2009 г. 22:39 20104] R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?] R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\symds.sys [03.5.2011 г. 01:29 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\symefa.sys [03.5.2011 г. 01:29 744568] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [20.2.2010 г. 15:47 114768] R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20110309.001\BHDrvx86.sys [10.3.2011 г. 23:38 800376] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\ironx86.sys [03.5.2011 г. 01:29 136312] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.2.2010 г. 15:47 20560] R2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [14.1.2011 г. 12:35 196912] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [24.10.2011 г. 17:25 2255464] R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [25.5.2011 г. 22:13 632792] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [23.8.2010 г. 16:17 2368] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [09.2.2011 г. 13:03 102448] R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;c:\windows\system32\drivers\hcw88rc5.sys [20.2.2010 г. 16:21 11841] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [20.2.2010 г. 16:21 140865] R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [20.2.2010 г. 16:21 613204] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [20.2.2010 г. 16:21 30528] R3 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21.4.2007 г. 13:54 52080] R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [21.10.2011 г. 23:54 250240] R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [21.10.2011 г. 23:54 476160] S2 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 13:16 130384] S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [09.11.2010 г. 11:23 135664] S2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccsvchst.exe [03.5.2011 г. 01:29 130008] S2 pgxbnhnlt;Driver Shell;c:\windows\system32\svchost.exe -k netsvcs [14.4.2008 г. 14:00 14336] S2 RoxLiveShare10;LiveShare P2P Server 10;"c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" --> c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [?] S2 SessionLauncher;SessionLauncher;c:\docume~1\PCV1\LOCALS~1\Temp\DX9\SessionLauncher.exe --> c:\docume~1\PCV1\LOCALS~1\Temp\DX9\SessionLauncher.exe [?] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.2.2010 г. 16:20 1691480] S3 aqyvqjsh;aqyvqjsh;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?] S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys --> c:\windows\system32\DRIVERS\btcomport.sys [?] S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys --> c:\windows\system32\Drivers\btcombus.sys [?] S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [07.12.2008 г. 11:44 25864] S3 codzsabk;codzsabk;\??\c:\windows\system32\06.tmp --> c:\windows\system32\06.tmp [?] S3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20110408.001\IDSXpx86.sys [09.4.2011 г. 00:53 341944] S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [02.7.2008 г. 13:58 23048] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 г. 14:49 227232] S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [11.8.2011 г. 21:29 27064] S3 sbnjqv;sbnjqv;\??\c:\windows\system32\03.tmp --> c:\windows\system32\03.tmp [?] S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [30.10.2011 г. 10:10 111872] S3 ubyyiadqq;ubyyiadqq;c:\windows\system32\04.tmp [23.10.2011 г. 16:41 4096] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 13:16 753504] S3 xyybiqel;xyybiqel;\??\c:\windows\system32\03.tmp --> c:\windows\system32\03.tmp [?] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs fklzpetlk pgxbnhnlt . Contents of the 'Scheduled Tasks' folder . 2011-08-11 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50] . 2011-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc8df6cfe71180.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-09 09:23] . 2011-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-09 09:23] . 2010-04-27 c:\windows\Tasks\Install.job - c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2010-04-20 14:54] . 2011-05-25 c:\windows\Tasks\RMSchedule.job - c:\program files\Registry Mechanic\RegMech.exe [2011-05-25 07:02] . 2011-05-25 c:\windows\Tasks\RMSmartUpdate.job - c:\program files\Registry Mechanic\Update.exe [2011-05-25 10:23] . 2011-09-26 c:\windows\Tasks\SLOW-PCfighter-PCV1-Startup.job - c:\program files\Fighters\SLOW-PCfighter\SLOW-PCfighter.exe [2011-09-01 09:48] . 2011-10-22 c:\windows\Tasks\User_Feed_Synchronization-{CC1C45FC-861B-4B2C-9242-BB7A7008C42F}.job - c:\windows\system32\msfeedssync.exe [2008-04-14 03:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=100474&mntrId=a41869f1000000000000101111111111 uDefault_Search_URL = hxxp://tudosearch.com/index.php?q= uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uInternet Settings,ProxyServer = http=127.0.0.1:25536 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html TCP: DhcpNameServer = 87.246.24.6 FF - ProfilePath - c:\documents and settings\PCV1\Application Data\Mozilla\Firefox\Profiles\379h1v5k.default\ . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-10-30 14:35 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360] "ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aqyvqjsh] "ImagePath"="\??\c:\windows\system32\02.tmp" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\codzsabk] "ImagePath"="\??\c:\windows\system32\06.tmp" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sbnjqv] "ImagePath"="\??\c:\windows\system32\03.tmp" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ubyyiadqq] "ImagePath"="\??\c:\windows\system32\04.tmp" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xyybiqel] "ImagePath"="\??\c:\windows\system32\03.tmp" . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pgxbnhnlt] "ServiceDll"="c:\windows\system32\xbaoymi.dll" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(5588) c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2011-10-30 14:38:25 ComboFix-quarantined-files.txt 2011-10-30 12:38 ComboFix2.txt 2011-10-30 09:26 . Pre-Run: 3 823 431 680 bytes free Post-Run: 3 799 240 704 bytes free . - - End Of File - - 3ECE77849E4EE63391B1EE11EF7725E2 искам само да ти пратя какво ми изписа преди да тръне да търси програма... а това след като рестартирах тоя аванс защо постоянно си сега някъде..бях го деинсталирала но все като искам да си сложа нова антивирусна се влючва че пречи аванса..и заради нея нямам антивирусна от сумати време

post-135988-0-39003700-1319978463_thumb.

post-135988-0-12992000-1319978472_thumb.

post-135988-0-81564800-1319978591_thumb.

Ще премахнем avast! от списъка с инсталираните програми, но скрипта не се е задействал.

Running from: c:\documents and settings\PCV1\My Documents\Downloads\ComboFix.exe

Трябваше да изпише

Command switches used :: c:\documents and settings\PCV1\Desktop\CFScript.txt

Ок...преместете Combofix.exe и файла CFScript.txt на декстопа !

След това от Start Menu => отидете на Run => копирайте командата в полето:

"%userprofile%\desktop\combofix.exe" "%userprofile%\desktop\CFScript.txt"

Натиснете Enter.

Публикувайте лог файла след края на проверката.

  • Автор

направих го но ми изписва ето това

post-135988-0-38754000-1319980822_thumb.

Оххх на грешката се казва, че нямате файл Combofix.exe на десктопа.

Изтеглете нова версия оттук и запазете файла на ДЕСКТОПА!

Изтеглете и новия прикачен файл и го запезете на ДЕСКТОПА!CFScript.txt

След това от Start => Run копирайте командата:

"%userprofile%\desktop\combofix.exe" "%userprofile%\desktop\CFScript.txt"

Току що пробвах при мен и се получи. :rolleyes:

Снимка за ваше улеснение:

Публикувано изображение

  • Автор

добре ,но да изтрия ли първо тези от декстопа и от папката в който се изтеглиха?

Да, изтрийте стартите и изтеглете новите. Преди да копирате командата се уверете, че и двата файла се намират на десктопа. Поздрави ! :eek: И още нещо...сега видях една стара снимка от вашия десктоп....уверете се че оригиналните файлове са на декстопа а не тяхни икони/шорткъти/преки пътища... Надявам се ме разбрахте.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.