Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Mediashifting.com + Rootkit ZeroAccess [РЕШЕН]

Featured Replies

Здравейте, Надявам се, това да е точното място за темата. Проблемите са описаните в заглавието, а най-вероятно и друго ще има. Около Коледа лаптопа започна да забива+замръзване+син екран за грешка и рестартиране. Тогава нямах много време, и едва днес започнах да се занимавам с проблемите (от тогава до днес е бил изключен). Притеснявам се, защото на този лаптоп има доста важна информация. Ето и логовете: DDS: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Run by Shushi at 16:37:23 on 2012-01-10 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1022.596 [GMT -8:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes =============== . C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Apoint\Apoint.exe C:\WINDOWS\stsystra.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\AVAST Software\Avast\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Apoint\HidFind.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Apoint\Apntex.exe C:\WINDOWS\STK02H\STK02HM.exe C:\WINDOWS\STK02N\STK02NM.exe C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe svchost.exe svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\AVAST Software\Avast\setup\avast.setup C:\WINDOWS\system32\wuauclt.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.google.bg/ uSearch Bar = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s uWinlogon: Shell=c:\documents and settings\shushi\local settings\application data\d5201a33\X BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [DAEMON Tools Lite] "d:\program files\daemon tools lite\DTLite.exe" -autorun uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [sigmatelSysTrayApp] stsystra.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\stk02h~1.lnk - c:\windows\stk02h\STK02HM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\stk02n~1.lnk - c:\windows\stk02n\STK02NM.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - d:\program files\winhttrack\WinHTTrackIEBar.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: mswsock.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259733507765 DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF} DPF: {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 84.54.128.6 192.168.4.1 TCP: Interfaces\{87004F63-7CB8-4F65-BD00-B77325A04D6C} : DhcpNameServer = 84.54.128.6 192.168.4.1 TCP: Interfaces\{D64404E0-9FD3-4385-8C73-D444068BFD69} : DhcpNameServer = 84.54.128.6 192.168.4.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\shushi\application data\mozilla\firefox\profiles\j1ok8789.default\ FF - prefs.js: browser.startup.homepage - google.bg FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=bg&q= FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPJinit13128.dll FF - plugin: c:\program files\mozilla firefox\plugins\npww.dll . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-6 371544] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-12-1 301528] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-12-1 19544] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-6 42184] S0 66825487;66825487;c:\windows\system32\drivers\83182158.sys --> c:\windows\system32\drivers\83182158.sys [?] S0 Si3124;Si3124; [x] S0 Si3531;Si3531; [x] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [2010-5-3 223232] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-01-10 14:35:51 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2012-01-10 12:45:44 -------- d-----w- c:\program files\CCleaner 2011-12-27 22:45:29 -------- d-----w- C:\TDSSKiller_Quarantine 2011-12-25 16:05:45 -------- d-sh--w- c:\documents and settings\shushi\local settings\application data\d5201a33 . ==================== Find3M ==================== . 2011-12-27 22:20:36 64512 ----a-w- c:\windows\system32\drivers\serial.sys 2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys 2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll 2011-10-31 23:43:21 832512 ----a-w- c:\windows\system32\wininet.dll 2011-10-31 23:43:21 78336 ----a-w- c:\windows\system32\ieencode.dll 2011-10-31 23:43:21 1830912 ----a-w- c:\windows\system32\inetcpl.cpl 2011-10-31 23:43:20 17408 ----a-w- c:\windows\system32\corpol.dll 2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 ----a-w- c:\windows\system32\encdec.dll . ============= FINISH: 16:44:47,87 =============== Attach: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 01.12.2009 г. 07:06:00 System Uptime: 10.1.2012 г. 16:34:17 (0 hours ago) . Motherboard: Dell Inc. | | 0JF242 Processor: Genuine Intel® CPU T2500 @ 2.00GHz | Microprocessor | 997/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 29 GiB total, 4,966 GiB free. D: is FIXED (NTFS) - 20 GiB total, 10,759 GiB free. E: is CDROM () F: is FIXED (NTFS) - 16 GiB total, 3,534 GiB free. G: is FIXED (NTFS) - 10 GiB total, 1,712 GiB free. H: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\D4A2450394FC000 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\D4A2450394FC000 Service: NIC1394 . Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318} Description: Communications Port Device ID: ACPI\PNP0501\4&25E2FF18&0 Manufacturer: (Standard port types) Name: Communications Port (COM1) PNP Device ID: ACPI\PNP0501\4&25E2FF18&0 Service: Serial . ==== System Restore Points =================== . RP631: 05.12.2011 г. 13:04:22 - System Checkpoint RP632: 06.12.2011 г. 21:31:01 - System Checkpoint RP633: 08.12.2011 г. 00:27:17 - System Checkpoint RP634: 10.12.2011 г. 03:02:16 - System Checkpoint RP635: 11.12.2011 г. 17:55:48 - System Checkpoint RP636: 12.12.2011 г. 18:56:04 - System Checkpoint RP637: 14.12.2011 г. 19:38:32 - System Checkpoint RP638: 15.12.2011 г. 19:47:00 - System Checkpoint RP639: 16.12.2011 г. 11:32:56 - Software Distribution Service 3.0 RP640: 17.12.2011 г. 19:33:23 - System Checkpoint RP641: 19.12.2011 г. 13:22:03 - System Checkpoint RP642: 21.12.2011 г. 15:25:16 - System Checkpoint RP643: 22.12.2011 г. 18:43:27 - System Checkpoint RP644: 26.12.2011 г. 15:22:32 - Restore Operation RP645: 26.12.2011 г. 15:23:44 - Restore Operation . ==== Installed Programs ====================== . Архиватор WinRAR µTorrent 3.4.0.9271.1 Adobe AIR Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps Adobe Default Language CS3 Adobe Device Central CS3 Adobe Dreamweaver CS3 Adobe ExtendScript Toolkit 2 Adobe Extension Manager CS3 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Help Viewer CS3 Adobe PDF Library Files Adobe Reader X (10.1.1) Adobe Setup Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client ALPS Touch Pad Driver Apple Application Support avast! Free Antivirus Broadcom TPM Driver Installer Bulgarian Keyboards XP by G. Atanasov BulgarianPhonetic XP by G. Atanasov CameraHelperMsi CCleaner Click to Call with Skype Compatibility Pack for the 2007 Office system Conexant HDA D110 MDC V.92 Modem Craft ROBO Controller Crystal Reports 2008 Runtime SP2 erLT FileZilla Client 3.3.1 Google Updater Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) J2SE Runtime Environment 5.0 Update 21 Java 6 Update 17 LightScribe 1.6.43.1 Logitech Webcam Software LWS Facebook LWS Gallery LWS Help_main LWS Launcher LWS Motion Detection LWS Pictures And Video LWS Twitter LWS Video Mask Maker LWS VideoEffects LWS Webcam Software LWS WLM Plugin LWS YouTube Plugin Microinvest Invoice Pro (remove only) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox 6.0 (x86 bg) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser Nero 7 Essentials NTRU Hybrid TSS v2.0.7 NVIDIA Drivers Oracle JInitiator 1.3.1.28 QuickTime ROBO Master for Silhouette Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2559049) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB2618444) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Skype™ 5.5 Sony USB Driver Sothink SWF Decompiler Sothink SWF Easy Sothink SWF Quicker STK02H 2.3 STK02N 2.4 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB898461) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Winamp Windows Driver Package - Intel (w29n51) net (09/12/2005 9.0.3.9) Windows Media Format Runtime WinHTTrack Website Copier 3.41-3 WinMerge 2.12.4 . ==== Event Viewer Messages From Past Week ======== . 10.1.2012 г. 16:36:17, error: Service Control Manager [7000] - The NTRU Hybrid TSS v2.0.7 TCS service failed to start due to the following error: The device is not ready. 10.1.2012 г. 16:36:17, error: Service Control Manager [7000] - The NICCONFIGSVC service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 16:36:17, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:34:04, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:34:04, error: DCOM [10005] - DCOM got error "%2" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 14:34:02, error: Service Control Manager [7000] - The Process Monitor service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:34:02, error: Service Control Manager [7000] - The NTRU Hybrid TSS v2.0.7 TCS service failed to start due to the following error: The device is not ready. 10.1.2012 г. 14:34:02, error: Service Control Manager [7000] - The NICCONFIGSVC service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:34:02, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:34:02, error: Service Control Manager [7000] - The Java Quick Starter service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:34:02, error: Service Control Manager [7000] - The ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 14:33:53, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.1.2012 г. 14:33:38, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.1.2012 г. 14:31:40, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 10.1.2012 г. 14:22:56, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 14:19:34, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 14:19:01, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 14:09:26, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 14:05:50, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 10.1.2012 г. 13:45:12, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 13:09:39, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 13:08:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 13:08:34, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 13:08:24, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:58:10, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:57:59, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:57:59, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:57:24, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:57:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:57:06, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:57:06, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:56:49, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:56:49, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:56:47, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:56:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:56:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:56:28, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:55:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:55:28, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:55:10, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:55:10, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:53:39, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:53:39, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:52:46, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:51:42, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:50, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:50, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:40, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:40, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:30, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:30, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:27, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:26, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:24, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:24, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:20, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:20, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:50:11, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:47:12, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:47:09, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:47:08, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:45:59, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:45:58, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:45:53, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:45:53, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:35:05, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 10.1.2012 г. 12:32:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 12:31:31, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:31:25, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:31:24, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:31:21, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:31:11, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:29:10, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:28:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:28:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:28:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:28:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:28:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:27:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:27:47, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:27:40, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:27:15, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:32, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:20, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:20, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:15, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:07, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:26:07, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:03, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:25:03, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:47, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:47, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:32, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:32, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:27, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:27, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:21, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:24:21, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:23:38, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 10.1.2012 г. 12:22:24, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:21:35, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:21:13, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:21:13, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:54, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:54, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:34, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:10, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:20:08, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:19:56, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:18:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:18:30, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:18:30, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:17:49, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:17:49, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:17:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:17:43, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:16:37, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 12:16:01, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:16:01, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:48, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:40, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:40, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:28, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:28, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:23, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:15:10, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:14:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:14:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:13:21, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:13:12, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:12:53, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:12:53, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:12:50, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:12:46, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:12:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 12:12:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 11:57:25, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 10.1.2012 г. 11:56:41, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 11:54:28, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:54:23, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 11:54:20, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 11:54:20, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 11:53:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:48:35, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 11:45:58, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:38:45, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:38:09, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:37:58, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:29:47, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10.1.2012 г. 11:28:58, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSnx aswSP aswTdi Fips intelppm 10.1.2012 г. 11:27:57, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 10.1.2012 г. 04:45:42, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 04:45:42, error: DCOM [10005] - DCOM got error "%2" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 10.1.2012 г. 04:45:28, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The system cannot find the file specified. 10.1.2012 г. 04:45:28, error: DCOM [10005] - DCOM got error "%2" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} 06.1.2012 г. 16:11:59, error: System Error [1003] - Error code 1000007e, parameter1 c0000005, parameter2 f3ad3258, parameter3 f6966a7c, parameter4 f6966778. 06.1.2012 г. 16:02:16, error: System Error [1003] - Error code 1000007e, parameter1 c0000005, parameter2 f3cf0258, parameter3 ba39fa7c, parameter4 ba39f778. . ==== End Of File =========================== Благодаря предварително, за отделеното време!

  • Отговори 75
  • Прегледи 7,5k
  • Създадено
  • Последен отговор

Здравейте,

Да видим какво е положението:

1. Изтеглете ComboFix от BleepingComputer

и го запазете (бутон Save -> Save as) ComboFix на вашия десктоп:

Публикувано изображение

След приключване на изтеглянето на ComboFix, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения, отворени прозорци и програми работещи във фонов режим. Спрете временно защитата в реално време на антивирусната програма и на другите програми за сигурност, ако има такива.

3. Стартирайте с двоен клик Combofix.exe. Изберете YES, за да се съгласите с условията за използване на програмата. Важно: По време на работата на ComboFix не бива да се движи мишката и да се натискат клавиши от клавиатурата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще провери дали Windows Recovery Console e инсталиранa.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

Публикувано изображение

Забележка: Необходимо е да сте свързани към Интернет за да може Windows Recovery Console да се изтегли.

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

Публикувано изображение

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката след приключване на работата на Combofix, моля да прочетете това: Manually restoring the Internet connection section.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad:

Публикувано изображение

Копирайте с (Copy) и поставете с (Paste) съдържанието на лога в следващия си коментар.

  • Автор

Здравейте,

Свалих и инсталирах програмата, всичко беше според инструкциите, но т.6 не се случи.

Докато сканираше (синия прозорец) извади съобщение, че има засечен Rootkit ZeroAccess в ттп/ип и може да отнеме време сканирането. После се появи съобщение,че заради този Rootkit трябва да ребуутне системата. Можех да дам само ОК и последва рестартиране. След него отново се появи синият прозорец, в които пишеше,че сканира и ще отнеме време. След 1 минута започна да излиза съобщение в прозореца (нещо като "PEV" is not ............................., както и Completed scan stage1,stage 2 и т.н.). Системата отново се рестартира, но нямаше син прозорец, а само се появи икона на IE на десктопа.

Няма лог файл. Надявам се, причината да не е в мен.

Много благодаря за отделеното време и ще помоля за още помощ!

Редакция: След рестарта, имаше съобщение от типа The system has recovered from a serious error.

Редактирано от Papadopoulos (преглед на промените)

Ако системата е буттнала нормално, отворете C:\ и вижте дали има лог - Combofix.txt (можете да проверите и в папката C:\Qoobox за такъв файл).

  • Автор

Здравейте, Има файл в C:\ComboFix, който се казва Combofix.txt Ето съдържанието: (Премахнато)

Редактирано от B-boy[StyLe]
премахната - важна информация (преглед на промените)

Благодаря, премахнах лог файла от съображения за сигурност. Докладвах за проблема. Пробвайте да изтеглите нова версия на Combofix и повторете проверката. Ако пак се получи същия резултат направете проверката в Safe Mode. Само че ако стартирате файла от Safe Mode и Combofix рестартира компютъра, после отново ще трябва да заредите в Safe Mode за да завърши проверката успешно. Накрая рестартирайте в Normal Mode и публикувайте лог файла.

  • Автор

Здравейте, Бихте ли ми казали откъде да изтегля по-нова версия. Сегашната е 12.1.10.2. Сега ще я деинсталирам.

  • Автор

Разбирам - няма да я деинсталирам. При свалянето иска да използвам ново име, тъй като файлът съществува. Какво име трябва да дам, или трябва да изтрия първо ComboFix от десктопа?

post-316482-0-55106200-1326297917_thumb.

Редактирано от Papadopoulos (преглед на промените)

Първо изтрийте вашата версия от десктопа. :) Бъдете сигурни, че сте спрели всички налични инсталирани защитни програми, които могат да попречат на сканирането да се извърши преди да стартирате файла.

  • Автор

Здравейте,

Докато чаках за отговор,направих проверката в Safe Mode. Рестартира се няколко пъти, като пак имаше съобщения за инфекция с Rootkit. Досега сканира и има лог :

ComboFix 12-01-10.02 - Shushi 01.2012 г. 8:38.2.2 - x86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1022.813 [GMT -8:00]

Running from: c:\documents and settings\Shushi\Desktop\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\00000001.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\000000c0.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\000000cb.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\000000cf.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\80000000.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\800000c0.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\800000cb.@

c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\U\800000cf.@

c:\windows\XSxS

c:\windows\$NtUninstallKB12524$\1670538081 . . . . Failed to delete

.

.

((((((((((((((((((((((((( Files Created from 2011-12-11 to 2012-01-11 )))))))))))))))))))))))))))))))

.

.

2012-01-11 13:39 . 2012-01-11 13:39 -------- d-----w- c:\windows\LastGood

2012-01-11 00:49 . 2012-01-11 16:18 -------- d-----w- c:\program files\sms

2012-01-10 14:35 . 2012-01-10 14:40 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys

2012-01-10 12:45 . 2012-01-10 12:45 -------- d-----w- c:\program files\CCleaner

2011-12-27 22:45 . 2012-01-10 19:31 -------- d-----w- C:\TDSSKiller_Quarantine

2011-12-25 16:05 . 2012-01-11 13:14 -------- d-sh--w- c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-27 22:20 . 2008-04-14 00:45 64512 ----a-w- c:\windows\system32\drivers\serial.sys

2011-11-23 13:25 . 2008-04-14 01:00 1859584 ----a-w- c:\windows\system32\win32k.sys

2011-11-01 16:07 . 2008-04-14 05:42 1288704 ----a-w- c:\windows\system32\ole32.dll

2011-10-31 23:43 . 2008-04-23 11:39 832512 ----a-w- c:\windows\system32\wininet.dll

2011-10-31 23:43 . 2008-04-23 11:39 1830912 ----a-w- c:\windows\system32\inetcpl.cpl

2011-10-31 23:43 . 2008-04-23 11:38 78336 ----a-w- c:\windows\system32\ieencode.dll

2011-10-31 23:43 . 2008-04-23 11:38 17408 ----a-w- c:\windows\system32\corpol.dll

2011-10-28 05:31 . 2008-04-14 05:41 33280 ----a-w- c:\windows\system32\csrsrv.dll

2011-10-25 13:37 . 2008-04-14 00:54 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe

2011-10-25 12:52 . 2008-04-13 21:01 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe

2011-10-18 11:13 . 2008-04-14 05:41 186880 ----a-w- c:\windows\system32\encdec.dll

2011-08-12 06:09 . 2011-08-18 12:33 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2008-04-23 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2011-02-23 14:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]

"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-18 39408]

"SMS by Jeko Ianev"="c:\program files\sms\sms.exe" [2011-12-19 13506048]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7401472]

"nwiz"="nwiz.exe" [2006-01-19 1519616]

"NVHotkey"="nvHotkey.dll" [2006-01-19 73728]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]

"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-22 149280]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]

"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-08 165208]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

STK02H 2.3 PNP Monitor.lnk - c:\windows\STK02H\STK02HM.exe [2010-5-30 163840]

STK02N 2.4 PNP Monitor.lnk - c:\windows\STK02N\STK02NM.exe [2010-5-30 163840]

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"d:\\Program Files\\WinHTTrack\\WinHTTrack.exe"=

"c:\\Documents and Settings\\Shushi\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"7001:TCP"= 7001:TCP:BitComet 7001 TCP

"7001:UDP"= 7001:UDP:BitComet 7001 UDP

.

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07.11.2010 г. 11:00 691696]

S0 66825487;66825487;c:\windows\system32\drivers\83182158.sys --> c:\windows\system32\drivers\83182158.sys [?]

S0 Si3124;Si3124; [x]

S0 Si3531;Si3531; [x]

S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [06.4.2011 г. 18:01 371544]

S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [01.12.2009 г. 21:16 301528]

S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [01.12.2009 г. 21:16 19544]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 12:16 130384]

S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [03.5.2010 г. 19:46 223232]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 12:16 753504]

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2007-04-19 21:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.bg/

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

TCP: DhcpNameServer = 84.54.128.6 192.168.4.1

DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF}

FF - ProfilePath - c:\documents and settings\Shushi\Application Data\Mozilla\Firefox\Profiles\j1ok8789.default\

FF - prefs.js: browser.startup.homepage - google.bg

FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=bg&q=

.

- - - - ORPHANS REMOVED - - - -

.

SafeBoot-66825487.sys

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-01-11 08:59

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial]

"ImagePath"="system32\drivers\tsk89.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command]

@="c:\\Program Files\\CCleaner\\ccleaner.exe"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(588)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

.

Completion time: 2012-01-11 09:08:36 - machine was rebooted

ComboFix-quarantined-files.txt 2012-01-11 17:08

.

Pre-Run: 6 508 273 664 bytes free

Post-Run: 6 723 506 176 bytes free

.

- - End Of File - - 7C6452875A954EB4527583A0DF6E1857

Проверката беше с първата свалена ComboFix. Сега нужно ли е да я изтривам,свалям наново и сканирам или този лог е достатъчен?

п.п.Извинявам се, за късния отговор, но от предпоследното ми мнение досега сканираше+рестартираше

Редактирано от Papadopoulos (преглед на промените)

Не, не изтривайте нищо. Тази информация е достатъчна. Ще пиша след малко, но ще имаме доста работа... Малко ще хапна и ще пиша към 20.30/21.00

  • Автор

Много благодаря! Оставам на линия и чакам инструкции. Много се надявам, да има шанс всичко да се оправи.

Здравейте,

Явно сте се самолекували...

Искам да видя лог файла от TDSSKiller:

2011-12-27 22:45 . 2012-01-10 19:31 -------- d-----w- C:TDSSKiller_Quarantine

След това:

*. Отворете notepad и с copy/paste въведете следната информация:

Driver::
66825487
File::
c:windowssystem32drivers83182158.sys
SRPeek::
c:windowssystem32driversserial.sys
Folder::
c:windows$NtUninstallKB12524$1670538081
c:documents and settingsShushiLocal SettingsApplication Datad5201a33

*.Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

Публикувано изображение

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Копирайте съдържанието на лог файла в следващия си пост.

След това:

Отворете notepad и с copy/paste въведете следната информация:

Windows Registry Editor Version 5.00

@echo off
reg query "HKEY_LOCAL_MACHINESystemcurrentcontrolsetServicesSerial" /v imagepath > result.txt
start result.txt
del %0

Запазете файла с името peek.bat.

Файла ше изглежда така - Публикувано изображение

Стартирайте файла.

Ще се появи текстов файл. Копирайте съдържанието на лог файла в следващия си пост.

  • Автор

Досега сканира. Не бях обаче в сейф моуд и отново има това съобщение. Ето лога: (премахнат лог) Да повторя ли операцията в сейф моуд? От TDSSKiller няма лог, мога да направя скрийншот какво има в папката. Иначе програмите,които използвах са TDSSKiller,RogueKiller (има 2 лог файла),salitykiller и CCleaner, за да се справя с mediashifting заразата. Някоя от програмите съобщи за Rootkit ZeroAccess и така попаднах във форума. Сега ще изпълня и вторите инструкции и ще редактирам поста. редакция: Ето от бат файла ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\System\currentcontrolset\Services\Serial imagepath REG_EXPAND_SZ system32\drivers\tsk89.tmp

Редактирано от B-boy[StyLe]
премахната важна информация (преглед на промените)

Не, проблема е в avast! Искам да деинсталирате временно avast! след това повторете проверката от Normal Mode. (изтеглете ново копие на Combofix, защото мисля, че avast е повредил текущото такова). Лог файла на TDSSKiller трябва да се намира в свободната на C:\TDSSKiller(дата).txt Така и така сте тръгнали публикувайте и лог файла от RogueKiller - трябва да е на десктопа - RKreport.txt

  • Автор

След близо 50 минутно сканиране (нормално ли е,да е толкова бавно?), ето резултата:

ComboFix 12-01-10.02 - Shushi 01.2012 г. 11:51:37.4.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1022.739 [GMT -8:00]

Running from: c:\documents and settings\Shushi\Desktop\ComboFix.exe

.

.

((((((((((((((((((((((((( Files Created from 2011-12-11 to 2012-01-11 )))))))))))))))))))))))))))))))

.

.

2012-01-11 00:49 . 2012-01-11 19:44 -------- d-----w- c:\program files\sms

2012-01-10 14:35 . 2012-01-10 14:40 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys

2012-01-10 12:45 . 2012-01-10 12:45 -------- d-----w- c:\program files\CCleaner

2011-12-27 22:45 . 2012-01-10 19:31 -------- d-----w- C:\TDSSKiller_Quarantine

2011-12-25 16:05 . 2012-01-11 13:14 -------- d-sh--w- c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-12-27 22:20 . 2008-04-14 00:45 64512 ----a-w- c:\windows\system32\drivers\serial.sys

2011-11-23 13:25 . 2008-04-14 01:00 1859584 ----a-w- c:\windows\system32\win32k.sys

2011-11-01 16:07 . 2008-04-14 05:42 1288704 ----a-w- c:\windows\system32\ole32.dll

2011-10-31 23:43 . 2008-04-23 11:39 832512 ----a-w- c:\windows\system32\wininet.dll

2011-10-31 23:43 . 2008-04-23 11:39 1830912 ----a-w- c:\windows\system32\inetcpl.cpl

2011-10-31 23:43 . 2008-04-23 11:38 78336 ----a-w- c:\windows\system32\ieencode.dll

2011-10-31 23:43 . 2008-04-23 11:38 17408 ----a-w- c:\windows\system32\corpol.dll

2011-10-28 05:31 . 2008-04-14 05:41 33280 ----a-w- c:\windows\system32\csrsrv.dll

2011-10-25 13:37 . 2008-04-14 00:54 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe

2011-10-25 12:52 . 2008-04-13 21:01 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe

2011-10-18 11:13 . 2008-04-14 05:41 186880 ----a-w- c:\windows\system32\encdec.dll

2011-08-12 06:09 . 2011-08-18 12:33 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

------- Sigcheck -------

Note: Unsigned files aren't necessarily malware.

.

[-] 2008-04-23 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]

"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-18 39408]

"SMS by Jeko Ianev"="c:\program files\sms\sms.exe" [2011-12-19 13506048]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7401472]

"nwiz"="nwiz.exe" [2006-01-19 1519616]

"NVHotkey"="nvHotkey.dll" [2006-01-19 73728]

"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]

"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-22 149280]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]

"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-08 165208]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

STK02H 2.3 PNP Monitor.lnk - c:\windows\STK02H\STK02HM.exe [2010-5-30 163840]

STK02N 2.4 PNP Monitor.lnk - c:\windows\STK02N\STK02NM.exe [2010-5-30 163840]

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"d:\\Program Files\\WinHTTrack\\WinHTTrack.exe"=

"c:\\Documents and Settings\\Shushi\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"7001:TCP"= 7001:TCP:BitComet 7001 TCP

"7001:UDP"= 7001:UDP:BitComet 7001 UDP

.

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07.11.2010 г. 11:00 691696]

S0 Si3124;Si3124; [x]

S0 Si3531;Si3531; [x]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 12:16 130384]

S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [03.5.2010 г. 19:46 223232]

S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 12:16 753504]

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2007-04-19 21:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.bg/

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

TCP: DhcpNameServer = 84.54.128.6 192.168.4.1

DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF}

FF - ProfilePath - c:\documents and settings\Shushi\Application Data\Mozilla\Firefox\Profiles\j1ok8789.default\

FF - prefs.js: browser.startup.homepage - google.bg

FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=bg&q=

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-01-11 12:18

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial]

"ImagePath"="system32\drivers\tsk89.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command]

@="c:\\Program Files\\CCleaner\\ccleaner.exe"

.

Completion time: 2012-01-11 12:21:56

ComboFix-quarantined-files.txt 2012-01-11 20:21

ComboFix2.txt 2012-01-11 17:08

.

Pre-Run: 5 533 368 320 bytes free

Post-Run: 5 524 611 072 bytes free

.

- - End Of File - - 5E839E31519A8B1537AFB587BD2D406C

Редакция:

TDSSKiller.2.6.25.0_27.12.2011_14.44.43_log

14:44:43.0250 1580 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16

14:44:43.0296 1580 ============================================================

14:44:43.0296 1580 Current date / time: 2011/12/27 14:44:43.0296

14:44:43.0296 1580 SystemInfo:

14:44:43.0296 1580

14:44:43.0296 1580 OS Version: 5.1.2600 ServicePack: 3.0

14:44:43.0296 1580 Product type: Workstation

14:44:43.0296 1580 ComputerName: Shushi

14:44:43.0296 1580 UserName: Shushi

14:44:43.0296 1580 Windows directory: C:\WINDOWS

14:44:43.0296 1580 System windows directory: C:\WINDOWS

14:44:43.0296 1580 Processor architecture: Intel x86

14:44:43.0296 1580 Number of processors: 2

14:44:43.0296 1580 Page size: 0x1000

14:44:43.0296 1580 Boot type: Safe boot with network

14:44:43.0296 1580 ============================================================

14:44:45.0828 1580 Initialize success

14:44:47.0734 1584 ============================================================

14:44:47.0734 1584 Scan started

14:44:47.0734 1584 Mode: Manual;

14:44:47.0734 1584 ============================================================

14:44:49.0765 1584 14209318 - ok

14:44:49.0843 1584 66825487 - ok

14:44:50.0000 1584 Aavmker4 (83631291adf2887cffc786d034d3fa15) C:\WINDOWS\system32\drivers\Aavmker4.sys

14:44:50.0000 1584 Aavmker4 - ok

14:44:50.0046 1584 Abiosdsk - ok

14:44:50.0109 1584 abp480n5 - ok

14:44:50.0187 1584 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys

14:44:50.0187 1584 ACPI - ok

14:44:50.0250 1584 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys

14:44:50.0250 1584 ACPIEC - ok

14:44:50.0343 1584 adpu160m - ok

14:44:50.0421 1584 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

14:44:50.0437 1584 aec - ok

14:44:50.0515 1584 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys

14:44:50.0515 1584 AFD - ok

14:44:50.0546 1584 Aha154x - ok

14:44:50.0609 1584 aic78u2 - ok

14:44:50.0671 1584 aic78xx - ok

14:44:50.0796 1584 AliIde - ok

14:44:50.0843 1584 amsint - ok

14:44:50.0921 1584 ApfiltrService (090880e9bf20f928bc341f96d27c019e) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys

14:44:50.0921 1584 ApfiltrService - ok

14:44:50.0968 1584 Appdrv - ok

14:44:51.0078 1584 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys

14:44:51.0078 1584 Arp1394 - ok

14:44:51.0140 1584 asc - ok

14:44:51.0203 1584 asc3350p - ok

14:44:51.0265 1584 asc3550 - ok

14:44:51.0453 1584 aswFsBlk (1c2e6bb4fe8621b1b863855b02bc33eb) C:\WINDOWS\system32\drivers\aswFsBlk.sys

14:44:51.0453 1584 aswFsBlk - ok

14:44:51.0515 1584 aswMon2 (452d0ecd14fa02f9b061f42c8a30dd49) C:\WINDOWS\system32\drivers\aswMon2.sys

14:44:51.0515 1584 aswMon2 - ok

14:44:51.0578 1584 aswRdr (b6a9373619d851be80fb5f1b5eed0d4e) C:\WINDOWS\system32\drivers\aswRdr.sys

14:44:51.0578 1584 aswRdr - ok

14:44:51.0671 1584 aswSnx (9be41c1ae8bc481eb662d85c98d979c2) C:\WINDOWS\system32\drivers\aswSnx.sys

14:44:51.0687 1584 aswSnx - ok

14:44:51.0765 1584 aswSP (4b1a54ba2bc5873a774df6b70ab8b0b3) C:\WINDOWS\system32\drivers\aswSP.sys

14:44:51.0765 1584 aswSP - ok

14:44:51.0828 1584 aswTdi (c7f1cea32766184911293f4e1ee653f5) C:\WINDOWS\system32\drivers\aswTdi.sys

14:44:51.0828 1584 aswTdi - ok

14:44:51.0890 1584 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

14:44:51.0921 1584 AsyncMac - ok

14:44:52.0046 1584 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

14:44:52.0046 1584 atapi - ok

14:44:52.0218 1584 Atdisk - ok

14:44:52.0328 1584 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

14:44:52.0343 1584 Atmarpc - ok

14:44:52.0421 1584 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

14:44:52.0421 1584 audstub - ok

14:44:52.0546 1584 b57w2k (c0acd392ece55784884cc208aafa06ce) C:\WINDOWS\system32\DRIVERS\b57xp32.sys

14:44:52.0546 1584 b57w2k - ok

14:44:52.0640 1584 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

14:44:52.0640 1584 Beep - ok

14:44:52.0781 1584 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys

14:44:52.0781 1584 BthEnum - ok

14:44:52.0875 1584 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys

14:44:52.0875 1584 BTHMODEM - ok

14:44:52.0953 1584 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys

14:44:52.0968 1584 BthPan - ok

14:44:53.0062 1584 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys

14:44:53.0062 1584 BTHPORT - ok

14:44:53.0140 1584 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys

14:44:53.0140 1584 BTHUSB - ok

14:44:53.0234 1584 camvid20 (5f68a3ab60262e3bf5b5c6c926e53525) C:\WINDOWS\system32\DRIVERS\camdrv21.sys

14:44:53.0234 1584 camvid20 - ok

14:44:53.0312 1584 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

14:44:53.0312 1584 cbidf2k - ok

14:44:53.0375 1584 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

14:44:53.0375 1584 CCDECODE - ok

14:44:53.0421 1584 cd20xrnt - ok

14:44:53.0500 1584 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

14:44:53.0500 1584 Cdaudio - ok

14:44:53.0562 1584 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

14:44:53.0562 1584 Cdfs - ok

14:44:53.0656 1584 cdrbsdrv (351735695e9ead93de6af85d8beb1ca8) C:\WINDOWS\system32\drivers\cdrbsdrv.sys

14:44:53.0656 1584 cdrbsdrv - ok

14:44:53.0718 1584 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

14:44:53.0718 1584 Cdrom - ok

14:44:53.0781 1584 Changer - ok

14:44:53.0968 1584 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys

14:44:53.0968 1584 CmBatt - ok

14:44:54.0031 1584 CmdIde - ok

14:44:54.0093 1584 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys

14:44:54.0093 1584 Compbatt - ok

14:44:54.0234 1584 Cpqarray - ok

14:44:54.0390 1584 dac2w2k - ok

14:44:54.0468 1584 dac960nt - ok

14:44:54.0687 1584 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

14:44:54.0687 1584 Disk - ok

14:44:54.0812 1584 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys

14:44:54.0843 1584 dmboot - ok

14:44:54.0875 1584 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys

14:44:54.0890 1584 dmio - ok

14:44:54.0953 1584 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

14:44:54.0953 1584 dmload - ok

14:44:55.0031 1584 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

14:44:55.0046 1584 DMusic - ok

14:44:55.0140 1584 dpti2o - ok

14:44:55.0218 1584 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

14:44:55.0218 1584 drmkaud - ok

14:44:55.0437 1584 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

14:44:55.0453 1584 Fastfat - ok

14:44:55.0531 1584 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys

14:44:55.0531 1584 Fdc - ok

14:44:55.0578 1584 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys

14:44:55.0593 1584 Fips - ok

14:44:55.0671 1584 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys

14:44:55.0671 1584 Flpydisk - ok

14:44:55.0750 1584 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

14:44:55.0765 1584 FltMgr - ok

14:44:55.0828 1584 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

14:44:55.0843 1584 Fs_Rec - ok

14:44:55.0906 1584 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

14:44:55.0906 1584 Ftdisk - ok

14:44:56.0000 1584 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

14:44:56.0015 1584 Gpc - ok

14:44:56.0093 1584 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys

14:44:56.0093 1584 HDAudBus - ok

14:44:56.0171 1584 HidBth (7bd2de4c85eb4241eed57672b16a7d8d) C:\WINDOWS\system32\DRIVERS\hidbth.sys

14:44:56.0187 1584 HidBth - ok

14:44:56.0265 1584 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

14:44:56.0281 1584 hidusb - ok

14:44:56.0343 1584 hpn - ok

14:44:56.0500 1584 HSF_DPV (e8ec1767ea315a39a0dd8989952ca0e9) C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys

14:44:56.0531 1584 HSF_DPV - ok

14:44:56.0609 1584 HSXHWAZL (61478fa42ee04562e7f11f4dca87e9c8) C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys

14:44:56.0609 1584 HSXHWAZL - ok

14:44:56.0734 1584 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

14:44:56.0781 1584 HTTP - ok

14:44:56.0921 1584 i2omgmt - ok

14:44:56.0984 1584 i2omp - ok

14:44:57.0062 1584 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

14:44:57.0062 1584 i8042prt - ok

14:44:57.0171 1584 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

14:44:57.0171 1584 Imapi - ok

14:44:57.0281 1584 ini910u - ok

14:44:57.0468 1584 IntelIde - ok

14:44:57.0531 1584 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys

14:44:57.0546 1584 intelppm - ok

14:44:57.0593 1584 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

14:44:57.0593 1584 Ip6Fw - ok

14:44:57.0656 1584 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

14:44:57.0656 1584 IpFilterDriver - ok

14:44:57.0750 1584 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

14:44:57.0750 1584 IpInIp - ok

14:44:57.0812 1584 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

14:44:57.0812 1584 IpNat - ok

14:44:57.0875 1584 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

14:44:57.0875 1584 IPSec - ok

14:44:57.0937 1584 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys

14:44:57.0937 1584 irda - ok

14:44:58.0000 1584 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

14:44:58.0000 1584 IRENUM - ok

14:44:58.0125 1584 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys

14:44:58.0125 1584 isapnp - ok

14:44:58.0203 1584 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

14:44:58.0203 1584 Kbdclass - ok

14:44:58.0265 1584 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

14:44:58.0265 1584 kbdhid - ok

14:44:58.0328 1584 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

14:44:58.0343 1584 kmixer - ok

14:44:58.0406 1584 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

14:44:58.0406 1584 KSecDD - ok

14:44:58.0515 1584 lbrtfdc - ok

14:44:58.0718 1584 LVPr2Mon (8be71d7edb8c7494913722059f760dd0) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys

14:44:58.0718 1584 LVPr2Mon - ok

14:44:58.0843 1584 LVRS (a1857fbb9b4930eeb2fd92386c45c529) C:\WINDOWS\system32\DRIVERS\lvrs.sys

14:44:58.0843 1584 LVRS - ok

14:44:59.0390 1584 LVUVC (3703406af0726badd24c5e552493e5b1) C:\WINDOWS\system32\DRIVERS\lvuvc.sys

14:44:59.0609 1584 LVUVC - ok

14:44:59.0781 1584 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys

14:44:59.0781 1584 mdmxsdk - ok

14:44:59.0859 1584 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

14:44:59.0859 1584 mnmdd - ok

14:44:59.0953 1584 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys

14:44:59.0953 1584 Modem - ok

14:45:00.0015 1584 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys

14:45:00.0015 1584 Mouclass - ok

14:45:00.0078 1584 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys

14:45:00.0078 1584 mouhid - ok

14:45:00.0125 1584 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

14:45:00.0125 1584 MountMgr - ok

14:45:00.0234 1584 mraid35x - ok

14:45:00.0312 1584 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

14:45:00.0312 1584 MRxDAV - ok

14:45:00.0375 1584 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

14:45:00.0390 1584 MRxSmb - ok

14:45:00.0515 1584 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

14:45:00.0515 1584 Msfs - ok

14:45:00.0609 1584 MSIRCOMM (95c6432151ccff8617352f8e616a1aa4) C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys

14:45:00.0609 1584 MSIRCOMM - ok

14:45:00.0750 1584 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

14:45:00.0750 1584 MSKSSRV - ok

14:45:00.0812 1584 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

14:45:00.0812 1584 MSPCLOCK - ok

14:45:00.0875 1584 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

14:45:00.0875 1584 MSPQM - ok

14:45:00.0937 1584 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

14:45:00.0937 1584 mssmbios - ok

14:45:01.0078 1584 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys

14:45:01.0078 1584 MSTEE - ok

14:45:01.0140 1584 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys

14:45:01.0156 1584 Mup - ok

14:45:01.0218 1584 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

14:45:01.0218 1584 NABTSFEC - ok

14:45:01.0468 1584 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

14:45:01.0484 1584 NDIS - ok

14:45:01.0515 1584 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

14:45:01.0531 1584 NdisIP - ok

14:45:01.0687 1584 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

14:45:01.0687 1584 NdisTapi - ok

14:45:01.0750 1584 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

14:45:01.0750 1584 Ndisuio - ok

14:45:01.0812 1584 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

14:45:01.0812 1584 NdisWan - ok

14:45:01.0875 1584 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys

14:45:01.0875 1584 NDProxy - ok

14:45:01.0921 1584 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

14:45:01.0921 1584 NetBIOS - ok

14:45:02.0000 1584 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

14:45:02.0000 1584 NetBT - ok

14:45:02.0234 1584 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys

14:45:02.0234 1584 NIC1394 - ok

14:45:02.0359 1584 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

14:45:02.0359 1584 Npfs - ok

14:45:02.0453 1584 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

14:45:02.0484 1584 Ntfs - ok

14:45:02.0609 1584 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

14:45:02.0609 1584 Null - ok

14:45:02.0843 1584 nv (5796a04ccc99542fdfb43f2accd803df) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

14:45:02.0953 1584 nv - ok

14:45:03.0109 1584 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

14:45:03.0109 1584 NwlnkFlt - ok

14:45:03.0171 1584 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

14:45:03.0171 1584 NwlnkFwd - ok

14:45:03.0234 1584 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys

14:45:03.0234 1584 NwlnkIpx - ok

14:45:03.0296 1584 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys

14:45:03.0296 1584 NwlnkNb - ok

14:45:03.0359 1584 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys

14:45:03.0359 1584 NwlnkSpx - ok

14:45:03.0453 1584 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys

14:45:03.0468 1584 ohci1394 - ok

14:45:03.0625 1584 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys

14:45:03.0640 1584 Parport - ok

14:45:03.0703 1584 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

14:45:03.0703 1584 PartMgr - ok

14:45:03.0765 1584 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys

14:45:03.0781 1584 ParVdm - ok

14:45:03.0875 1584 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys

14:45:03.0890 1584 PCI - ok

14:45:03.0968 1584 PCIDump - ok

14:45:04.0046 1584 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys

14:45:04.0046 1584 PCIIde - ok

14:45:04.0109 1584 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys

14:45:04.0109 1584 Pcmcia - ok

14:45:04.0156 1584 PDCOMP - ok

14:45:04.0218 1584 PDFRAME - ok

14:45:04.0265 1584 PDRELI - ok

14:45:04.0328 1584 PDRFRAME - ok

14:45:04.0390 1584 perc2 - ok

14:45:04.0453 1584 perc2hib - ok

14:45:04.0796 1584 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

14:45:04.0796 1584 PptpMiniport - ok

14:45:04.0906 1584 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

14:45:04.0906 1584 PSched - ok

14:45:05.0000 1584 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

14:45:05.0000 1584 Ptilink - ok

14:45:05.0078 1584 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys

14:45:05.0078 1584 PxHelp20 - ok

14:45:05.0109 1584 ql1080 - ok

14:45:05.0171 1584 Ql10wnt - ok

14:45:05.0234 1584 ql12160 - ok

14:45:05.0296 1584 ql1240 - ok

14:45:05.0359 1584 ql1280 - ok

14:45:05.0421 1584 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

14:45:05.0421 1584 RasAcd - ok

14:45:05.0515 1584 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys

14:45:05.0515 1584 Rasirda - ok

14:45:05.0593 1584 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

14:45:05.0593 1584 Rasl2tp - ok

14:45:05.0671 1584 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

14:45:05.0671 1584 RasPppoe - ok

14:45:05.0765 1584 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

14:45:05.0781 1584 Raspti - ok

14:45:05.0843 1584 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

14:45:05.0843 1584 Rdbss - ok

14:45:05.0890 1584 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

14:45:05.0890 1584 RDPCDD - ok

14:45:06.0031 1584 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

14:45:06.0046 1584 rdpdr - ok

14:45:06.0281 1584 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys

14:45:06.0281 1584 RDPWD - ok

14:45:06.0390 1584 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys

14:45:06.0390 1584 redbook - ok

14:45:06.0531 1584 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys

14:45:06.0531 1584 RFCOMM - ok

14:45:06.0781 1584 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

14:45:06.0781 1584 Secdrv - ok

14:45:06.0890 1584 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys

14:45:06.0890 1584 serenum - ok

14:45:06.0953 1584 Serial - ok

14:45:07.0187 1584 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

14:45:07.0203 1584 Sfloppy - ok

14:45:07.0296 1584 Si3112 - ok

14:45:07.0390 1584 Si3124 - ok

14:45:07.0468 1584 Si3132 - ok

14:45:07.0531 1584 Si3132r5 - ok

14:45:07.0593 1584 Si3531 - ok

14:45:07.0656 1584 Simbad - ok

14:45:07.0750 1584 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys

14:45:07.0750 1584 SLIP - ok

14:45:07.0812 1584 SMCIRDA (707647a1aa0edb6cbef61b0c75c28ed3) C:\WINDOWS\system32\DRIVERS\smcirda.sys

14:45:07.0812 1584 SMCIRDA - ok

14:45:07.0968 1584 sonypvs1 (dfadfc2c86662f40759bf02add27d569) C:\WINDOWS\system32\DRIVERS\sonypvs1.sys

14:45:07.0968 1584 sonypvs1 - ok

14:45:08.0015 1584 Sparrow - ok

14:45:08.0078 1584 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

14:45:08.0093 1584 splitter - ok

14:45:08.0218 1584 sptd (cdddec541bc3c96f91ecb48759673505) C:\WINDOWS\system32\Drivers\sptd.sys

14:45:08.0218 1584 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505

14:45:08.0234 1584 sptd ( LockedFile.Multi.Generic ) - warning

14:45:08.0234 1584 sptd - detected LockedFile.Multi.Generic (1)

14:45:08.0359 1584 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys

14:45:08.0375 1584 sr - ok

14:45:08.0546 1584 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys

14:45:08.0609 1584 Srv - ok

14:45:08.0953 1584 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys

14:45:08.0984 1584 STHDA - ok

14:45:09.0140 1584 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

14:45:09.0140 1584 streamip - ok

14:45:09.0187 1584 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

14:45:09.0187 1584 swenum - ok

14:45:09.0265 1584 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

14:45:09.0281 1584 swmidi - ok

14:45:09.0343 1584 symc810 - ok

14:45:09.0406 1584 symc8xx - ok

14:45:09.0468 1584 sym_hi - ok

14:45:09.0515 1584 sym_u3 - ok

14:45:09.0609 1584 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

14:45:09.0609 1584 sysaudio - ok

14:45:09.0734 1584 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

14:45:09.0734 1584 Tcpip - ok

14:45:09.0875 1584 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

14:45:09.0875 1584 TDPIPE - ok

14:45:09.0937 1584 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

14:45:09.0953 1584 TDTCP - ok

14:45:10.0000 1584 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

14:45:10.0000 1584 TermDD - ok

14:45:10.0140 1584 TosIde - ok

14:45:10.0265 1584 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

14:45:10.0265 1584 Udfs - ok

14:45:10.0312 1584 UIUSys - ok

14:45:10.0375 1584 ultra - ok

14:45:10.0531 1584 UnlockerDriver5 - ok

14:45:10.0703 1584 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

14:45:10.0718 1584 Update - ok

14:45:10.0843 1584 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys

14:45:10.0859 1584 usbaudio - ok

14:45:10.0921 1584 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

14:45:10.0921 1584 usbccgp - ok

14:45:11.0000 1584 USBCCID (6b5e4d5e6e5ecd6acd14aed59768ce5c) C:\WINDOWS\system32\DRIVERS\usbccid.sys

14:45:11.0000 1584 USBCCID - ok

14:45:11.0203 1584 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

14:45:11.0218 1584 usbehci - ok

14:45:11.0265 1584 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

14:45:11.0281 1584 usbhub - ok

14:45:11.0328 1584 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys

14:45:11.0328 1584 usbprint - ok

14:45:11.0390 1584 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys

14:45:11.0390 1584 usbscan - ok

14:45:11.0468 1584 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

14:45:11.0484 1584 USBSTOR - ok

14:45:11.0531 1584 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

14:45:11.0531 1584 usbuhci - ok

14:45:11.0625 1584 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys

14:45:11.0625 1584 usbvideo - ok

14:45:11.0687 1584 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

14:45:11.0687 1584 VgaSave - ok

14:45:11.0734 1584 ViaIde - ok

14:45:11.0796 1584 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys

14:45:11.0796 1584 VolSnap - ok

14:45:11.0984 1584 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys

14:45:12.0031 1584 w39n51 - ok

14:45:12.0156 1584 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

14:45:12.0156 1584 Wanarp - ok

14:45:12.0203 1584 WDICA - ok

14:45:12.0265 1584 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

14:45:12.0281 1584 wdmaud - ok

14:45:12.0406 1584 winachsf (ba6b6fb242a6ba4068c8b763063beb63) C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys

14:45:12.0421 1584 winachsf - ok

14:45:12.0812 1584 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

14:45:12.0828 1584 WSTCODEC - ok

14:45:13.0109 1584 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0

14:45:13.0468 1584 \Device\Harddisk0\DR0 - ok

14:45:13.0515 1584 Boot (0x1200) (bffbfd22aaa839410bef7cc150e93d86) \Device\Harddisk0\DR0\Partition0

14:45:13.0515 1584 \Device\Harddisk0\DR0\Partition0 - ok

14:45:13.0578 1584 Boot (0x1200) (f99feb293cd6f6c940478ac36b9bd1c3) \Device\Harddisk0\DR0\Partition1

14:45:13.0593 1584 \Device\Harddisk0\DR0\Partition1 - ok

14:45:13.0640 1584 Boot (0x1200) (de02260f4d0d537d7442de3951bf893e) \Device\Harddisk0\DR0\Partition2

14:45:13.0640 1584 \Device\Harddisk0\DR0\Partition2 - ok

14:45:13.0703 1584 Boot (0x1200) (e916dea42a87e8122faba89596bb7713) \Device\Harddisk0\DR0\Partition3

14:45:13.0703 1584 \Device\Harddisk0\DR0\Partition3 - ok

14:45:13.0718 1584 ============================================================

14:45:13.0718 1584 Scan finished

14:45:13.0718 1584 ============================================================

14:45:13.0812 1616 Detected object count: 1

14:45:13.0812 1616 Actual detected object count: 1

14:45:29.0750 1616 C:\WINDOWS\system32\Drivers\sptd.sys - copied to quarantine

14:45:29.0750 1616 sptd ( LockedFile.Multi.Generic ) - User select action: Quarantine

14:45:34.0140 1332 Deinitialize success

RKreport[1]

RogueKiller V6.2.3 [01/09/2012] by Tigzy

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Shushi [Admin rights]

Mode: Scan -- Date : 01/10/2012 06:36:21

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 6 ¤¤¤

[sUSP PATH] HKCU\[...]\Run : balancerfc (C:\Documents and Settings\Shushi\Application Data\balancerfc.exe) -> FOUND

[sUSP PATH] HKLM\[...]\Run : balancerfc (C:\Documents and Settings\Shushi\Application Data\balancerfc.exe) -> FOUND

[sUSP PATH] HKUS\S-1-5-21-602162358-1383384898-1801674531-1003[...]\Run : balancerfc (C:\Documents and Settings\Shushi\Application Data\balancerfc.exe) -> FOUND

[bLACKLIST] HKLM\[...]\services : 14209318 (14209318.sys) -> FOUND

[bLACKLIST] HKLM\[...]\services : 14209318 (14209318.sys) -> FOUND

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ZeroAccess ¤¤¤

[ZeroAccess] (LOCKED) windir\NtUpdateKBxxxx present!

¤¤¤ HOSTS File: ¤¤¤

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++

--- User ---

[MBR] dbc4ab13da5764983623fda5ebbf27ff

[bSP] 11d467b9f31927f29d49c85858b51038 : Windows XP MBR Code

Partition table:

0 - [XXXXXX] FAT16 [HIDDEN!] Offset (sectors): 63 | Size: 98 Mo

1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 192780 | Size: 31453 Mo

2 - [XXXXXX] UNKNW [VISIBLE] Offset (sectors): 61625340 | Size: 48471 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1].txt >>

RKreport[1].txt

Редактирано от Papadopoulos (преглед на промените)

Как извършихте проверката с Combofix ? Просто го стартирахте или изпълнихте скрипта който ви казах ? Мисля, че не сте изпълнили скрипта... http://www.kaldata.com/forums/index.php?showtopic=189390&view=findpost&p=2155891

  • Автор

Деинсталирах ,свалих отново и стартирах. Извинявам се, без скрипта е. :((((((((

Нали ви казах нищо да не деинсталирате...само да изтриете старата версия (или за вас изтривам = деинсталирам)...ако е така ок, но да кажа, че между двата процеса има разлика. Combofix ще деинсталираме накрая на почистващия процес...

  • Автор

Не се изразих правилно - деинсталирах Аваст, изтрих иконата на КомбоФикс, свалих КомбоФикс и стартирах от иконата. :(

  • Автор

Не мога да повярвам,колко бързо стана този път. Благодаря за търпението! Ето и него: ComboFix 12-01-10.02 - Shushi 01.2012 г. 12:55:14.5.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1022.739 [GMT -8:00] Running from: c:\documents and settings\Shushi\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Shushi\Desktop\CFScript.txt . FILE :: "c:\windows\system32\drivers\83182158.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33 c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\@ c:\documents and settings\Shushi\Local Settings\Application Data\d5201a33\loader.tlb . . ((((((((((((((((((((((((( Files Created from 2011-12-11 to 2012-01-11 ))))))))))))))))))))))))))))))) . . 2012-01-11 00:49 . 2012-01-11 19:44 -------- d-----w- c:\program files\sms 2012-01-10 14:35 . 2012-01-10 14:40 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2012-01-10 12:45 . 2012-01-10 12:45 -------- d-----w- c:\program files\CCleaner 2011-12-27 22:45 . 2012-01-10 19:31 -------- d-----w- C:\TDSSKiller_Quarantine . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-27 22:20 . 2008-04-14 00:45 64512 ----a-w- c:\windows\system32\drivers\serial.sys 2011-11-23 13:25 . 2008-04-14 01:00 1859584 ----a-w- c:\windows\system32\win32k.sys 2011-11-01 16:07 . 2008-04-14 05:42 1288704 ----a-w- c:\windows\system32\ole32.dll 2011-10-31 23:43 . 2008-04-23 11:39 832512 ----a-w- c:\windows\system32\wininet.dll 2011-10-31 23:43 . 2008-04-23 11:39 1830912 ----a-w- c:\windows\system32\inetcpl.cpl 2011-10-31 23:43 . 2008-04-23 11:38 78336 ----a-w- c:\windows\system32\ieencode.dll 2011-10-31 23:43 . 2008-04-23 11:38 17408 ----a-w- c:\windows\system32\corpol.dll 2011-10-28 05:31 . 2008-04-14 05:41 33280 ----a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37 . 2008-04-14 00:54 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52 . 2008-04-13 21:01 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13 . 2008-04-14 05:41 186880 ----a-w- c:\windows\system32\encdec.dll 2011-08-12 06:09 . 2011-08-18 12:33 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((((((((((((((((((( SR_Search )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2008-04-23 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040] "DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-18 39408] "SMS by Jeko Ianev"="c:\program files\sms\sms.exe" [2011-12-19 13506048] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7401472] "nwiz"="nwiz.exe" [2006-01-19 1519616] "NVHotkey"="nvHotkey.dll" [2006-01-19 73728] "Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128] "SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-22 149280] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792] "LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-08 165208] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ STK02H 2.3 PNP Monitor.lnk - c:\windows\STK02H\STK02HM.exe [2010-5-30 163840] STK02N 2.4 PNP Monitor.lnk - c:\windows\STK02N\STK02NM.exe [2010-5-30 163840] . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "d:\\Program Files\\WinHTTrack\\WinHTTrack.exe"= "c:\\Documents and Settings\\Shushi\\temp\\TeamViewer\\Version5\\TeamViewer.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "7001:TCP"= 7001:TCP:BitComet 7001 TCP "7001:UDP"= 7001:UDP:BitComet 7001 UDP . R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07.11.2010 г. 11:00 691696] S0 Si3124;Si3124; [x] S0 Si3531;Si3531; [x] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 12:16 130384] S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [03.5.2010 г. 19:46 223232] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 12:16 753504] . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2007-04-19 21:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.bg/ uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm TCP: DhcpNameServer = 84.54.128.6 192.168.4.1 DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF} FF - ProfilePath - c:\documents and settings\Shushi\Application Data\Mozilla\Firefox\Profiles\j1ok8789.default\ FF - prefs.js: browser.startup.homepage - google.bg FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=bg&q= . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-01-11 13:05 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial] "ImagePath"="system32\drivers\tsk89.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\B20@O=5 *=0 *C*C*l*e*a*n*e*r*& \command] @="c:\\Program Files\\CCleaner\\ccleaner.exe" . Completion time: 2012-01-11 13:09:13 ComboFix-quarantined-files.txt 2012-01-11 21:09 ComboFix2.txt 2012-01-11 20:21 ComboFix3.txt 2012-01-11 17:08 . Pre-Run: 5 526 151 168 bytes free Post-Run: 5 515 620 352 bytes free . - - End Of File - - 6E440D2D20A0106514CEAE9AB207238F

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.