Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

didkaj

Потребител
  • Регистрация

  • Последно онлайн

  1. ИСКАМ ДА ВИ КАЖА ЕДНО ОГРОМНО БЛАГОДАРЯ ЗА ТЪРПЕНИЕТО И ВНИМАНИЕТО, КОЕТО МИ ОТДЕЛИХТЕ ! ИЗПЪЛНИХ ВСИЧКО, КАКТО МИ ПИСАХТЕ И СЕГА ВСИЧКО Е НАРЕД! ВСИЧКИ ВИРУСИ СЕ ИЗЧИСТИХА, ПРЕИНСТАЛИРАХ WINDOWS, ИНСТАЛИРАХ ОТНОВО И АНТИВИРУСНА ПРОГРАМА. МНОГО, МНОГО, МНОГО ВИ БЛАГОДАРЯ !!! ПОЖЕЛАВАМ ВИ НАЙ-ВЕЧЕ ДА СТЕ ЗДРАВИ И МНОГО УСПЕХИ ВЪВ ВСЯКО НАЧИНАНИЕ !!! УСПЕХ !!!
  2. Извинявам се за въпроса, но незнам как да отстраня заразите.Изтеглих МВАМ, пуснах да се сканира и показа, че има 3 заплахи и 103 инфекции, но незнам как да ги премахна.
  3. СТЪПКА 2 : ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=c0e7448016a4ab4286967e43e69fc294 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-22 07:05:37 # local_time=2010-03-22 09:05:37 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 3799 3799 0 0 # scanned=33494 # found=55 # cleaned=55 # scan_time=2929 C:\_OTL.rar multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL Win32/FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL a variant of Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL probably a variant of Win32/Toolbar.MyWebSearch application (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\WINDOWS\system32\f3PSSavr.scr Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\pdjeodramxdrd.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\tfjckxjqajn.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\tjroarhsgtbrfjk.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\bhfsu.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\bxlogdzqkdrnhryskkgmu.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\fxhgunfsixhzpvyoc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\mhuwnjeunfsngpvofeze.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\bxlogdzqkdrnhryskkgmu.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\fxhgunfsixhzpvyoc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\mhuwnjeunfsngpvofeze.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\ohsshbuizpatkrvmby.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\speibzwojdspkvdyrspwfq.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\ypywjbsethqhwbds.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\ztfgwrlasjvphpumcau.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\bxlogdzqkdrnhryskkgmu.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\fxhgunfsixhzpvyoc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\mhuwnjeunfsngpvofeze.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\ohsshbuizpatkrvmby.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\speibzwojdspkvdyrspwfq.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\ypywjbsethqhwbds.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\ztfgwrlasjvphpumcau.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\D_\pdjeodramxdrd.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\D_\tfjckxjqajn.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\D_\tjroarhsgtbrfjk.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\ПРОГРАМИ\NOD32\patch.rar probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=c0e7448016a4ab4286967e43e69fc294 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-24 08:30:29 # local_time=2010-03-24 10:30:29 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 181614 181614 0 0 # scanned=32181 # found=0 # cleaned=0 # scan_time=3005
  4. СТЪПКА 1 : 1. Download Link: Щракнете тук, за да изтеглите файл http://rapidshare.com/files/367699127/iepeers.rar.html MD5: D74BE9039ECEDD407AC3982BA1972A08
  5. СТЪПКА 1: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. File C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL not found. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ not found. File C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar Search Scope Monitor deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin deleted successfully. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin deleted successfully. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully. Starting removal of ActiveX control {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.1.3.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} C:\WINDOWS\Downloaded Program Files\jinstall-6u11.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. File tfjckxjqajn.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. File tjroarhsgtbrfjk.bat _ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. File pdjeodramxdrd.bat _ not found. ========== FILES ========== C:\Program Files\FunWebProducts\Shared\Cache folder moved successfully. C:\Program Files\FunWebProducts\Shared folder moved successfully. C:\Program Files\FunWebProducts\ScreenSaver\Images folder moved successfully. C:\Program Files\FunWebProducts\ScreenSaver folder moved successfully. C:\Program Files\FunWebProducts folder moved successfully. C:\Program Files\MyWebSearch\bar\Settings folder moved successfully. C:\Program Files\MyWebSearch\bar\Notifier folder moved successfully. C:\Program Files\MyWebSearch\bar\Message\COMMON folder moved successfully. C:\Program Files\MyWebSearch\bar\Message folder moved successfully. C:\Program Files\MyWebSearch\bar\icons folder moved successfully. C:\Program Files\MyWebSearch\bar\History folder moved successfully. C:\Program Files\MyWebSearch\bar\Game folder moved successfully. C:\Program Files\MyWebSearch\bar\Cache folder moved successfully. C:\Program Files\MyWebSearch\bar\Avatar folder moved successfully. C:\Program Files\MyWebSearch\bar\1.bin\chrome folder moved successfully. C:\Program Files\MyWebSearch\bar\1.bin folder moved successfully. C:\Program Files\MyWebSearch\bar folder moved successfully. C:\Program Files\MyWebSearch folder moved successfully. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgemc.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgupd.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgnsx.exe deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: MASTER ->Temp folder emptied: 472466 bytes ->Temporary Internet Files folder emptied: 25113160 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 1242 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 697 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 19998294 bytes Total Files Cleaned = 44.00 mb OTL by OldTimer - Version 3.1.37.3 log created on 03232010_213743 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DF792D.tmp not found! File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DF7938.tmp not found! File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DF9056.tmp not found! File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DF9061.tmp not found! C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\RDOILB7V\banner[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\RDOILB7V\box[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\RDOILB7V\sh14[1].html moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\RDOILB7V\translate_google_com[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\PJYHMRHZ\ads[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\GOJHH4N6\eBayISAPI[1].txt moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\GOJHH4N6\fan[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\BNC0TQWD\afr[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\BNC0TQWD\index[1].php moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\7TTGAE68\ads[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\4U51M8F5\ads[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\4U51M8F5\ads[2].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully. Registry entries deleted on Reboot... СТЪПКА 2 : SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 21:50 on 23/03/2010 by MASTER (Administrator - Elevation successful) ========== filefind ========== Searching for "iepeers.dll" C:\WINDOWS\ie8\iepeers.dll --a--c 251904 bytes [12:56 02/12/2009] [09:00 14/04/2008] 4AFAE79DF77AD81DDBE4E07A51834DED C:\WINDOWS\system32\dllcache\iepeers.dll --a--c 251904 bytes [09:00 14/04/2008] [09:00 14/04/2008] 4AFAE79DF77AD81DDBE4E07A51834DED C:\WINDOWS\system32\iepeers.dll --a--- 183808 bytes [09:00 14/04/2008] [02:31 08/03/2009] 254CA8F8B2A387CD59E659991E3E3DBD -=End Of File=-
  6. OTL logfile created on: 3/23/2010 12:27:42 AM - Run 2 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\MASTER\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000402 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 49.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free Paging file location(s): C:\pagefile.sys 1920 3840 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.30 Gb Total Space | 22.49 Gb Free Space | 76.76% Space Free | Partition Type: NTFS Drive D: | 124.08 Gb Total Space | 84.94 Gb Free Space | 68.46% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MASTER-FADE9DED Current User Name: MASTER Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found PRC - C:\Documents and Settings\MASTER\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) PRC - C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe (Alex Rosenbaum and KishKish.com) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.) PRC - C:\WINDOWS\system32\S3Trayp.exe (S3 Graphics Co., Ltd.) PRC - C:\ПРОГРАМИ\бележки\ATnotes\ATnotes.exe (Thomas Ascher) PRC - C:\WINDOWS\Vm_sti.exe (VM.) PRC - C:\WINDOWS\Datecs\Flex2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\MASTER\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (MyWebSearch.com) MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (MyWebSearchService) -- File not found SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) ========== Driver Services (SafeList) ========== DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider) DRV - (VIAHdAudAddService) -- C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.) DRV - (ViaIde) -- C:\WINDOWS\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (Tcpip6) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider) DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation) DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation) DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation) DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation) DRV - (S3GIGP) -- C:\WINDOWS\system32\drivers\S3gIGPm.sys (S3 Graphics Co., Ltd.) DRV - (xfilt) -- C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc) DRV - (videX32) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.) DRV - (ip100xp) -- C:\WINDOWS\system32\drivers\ipfnd51.sys (IC Plus Corp. ) DRV - (ZSMC302) -- C:\WINDOWS\system32\drivers\usbvm302.sys (Creative Technology Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie'>http://www.google.com/ie IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/ IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = bg IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 92 96 50 BC 5D 73 CA 01 [binary data] IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie'>http://www.google.com/ie IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie'>http://www.google.com/ie IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL File not found IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\MyWebSearch\bar\1.bin [2010/03/22 20:28:40 | 000,000,000 | ---D | M] O1 HOSTS File: ([2008/04/14 11:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found. O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O4 - HKLM..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE (VM.) O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com) O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [s3Trayp] C:\WINDOWS\System32\S3Trayp.exe (S3 Graphics Co., Ltd.) O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [ATnotes.exe] C:\ПРОГРАМИ\бележки\ATnotes\ATnotes.exe (Thomas Ascher) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [sMS by Jeko Ianev] C:\ПРОГРАМИ\SMS\sms\sms.exe (Jeko Ianev www.ianev.org) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O7 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-5/myWebFaceInitialSetup1.0.1.3.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.6.0/jinstall-6u11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 87.120.16.1 87.120.16.2 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Моята текуща начална страница) - About:Home O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/12/02 14:55:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\Shell\AutoRun\command - "" = tfjckxjqajn.bat O33 - MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\Shell\explore\Command - "" = tjroarhsgtbrfjk.bat _ O33 - MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\Shell\open\Command - "" = pdjeodramxdrd.bat _ O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/12/02 14:54:27 | 000,000,000 | ---D | M] NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: WmdmPmSp - File not found ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7 ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Security Update for Windows XP (KB923789) ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler) Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.) Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll () Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll () Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org) ========== Files/Folders - Created Within 30 Days ========== [2010/03/22 20:13:30 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2010/03/22 00:58:44 | 000,000,000 | ---D | C] -- C:\_OTL [2010/03/21 00:00:12 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MASTER\Desktop\OTL.exe [2010/03/18 10:40:39 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\MASTER\Recent [2010/03/04 18:30:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MASTER\Local Settings\Application Data\Identities [2010/03/04 16:26:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google [2010/02/23 20:53:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\McAfee [2010/02/21 20:47:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee [2010/02/21 20:47:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan [2010/02/21 20:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan [2010/02/03 19:42:50 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2010/02/03 19:42:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2010/02/03 19:42:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2010/02/03 19:28:15 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009/12/17 11:56:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google ========== Files - Modified Within 30 Days ========== [2010/03/23 00:06:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010/03/22 22:45:17 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9DCC3BFD-677C-4E12-A4CB-47B8E38C7796}.job [2010/03/22 10:06:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010/03/22 09:38:48 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010/03/22 09:37:53 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010/03/22 09:37:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/03/22 03:26:58 | 003,670,016 | -H-- | M] () -- C:\Documents and Settings\MASTER\NTUSER.DAT [2010/03/22 03:26:58 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\MASTER\ntuser.ini [2010/03/22 01:32:09 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\SMETKA-Koh.doc [2010/03/21 15:41:00 | 000,000,476 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for MASTER.job [2010/03/21 13:59:54 | 000,000,040 | ---- | M] () -- C:\WINDOWS\nero.INI [2010/03/21 11:32:11 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Microsoft Office Word 2003.lnk [2010/03/21 00:00:25 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MASTER\Desktop\OTL.exe [2010/03/19 11:46:00 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk [2010/03/18 01:01:34 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk [2010/03/16 22:01:24 | 000,000,185 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\eBay Countdown.url [2010/03/15 10:40:08 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\dieta.doc [2010/03/11 14:48:48 | 000,044,616 | ---- | M] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2010/03/10 15:40:52 | 000,000,738 | ---- | M] () -- C:\WINDOWS\win.ini [2010/03/08 10:03:57 | 000,199,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/03/08 00:46:54 | 000,000,803 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\българо-немски речник.lnk [2010/03/05 01:39:34 | 000,815,616 | ---- | M] () -- C:\Documents and Settings\MASTER\My Documents\SPISUK ITEMI.doc [2010/02/25 17:23:20 | 000,000,155 | ---- | M] () -- C:\WINDOWS\winamp.ini [2010/02/23 20:53:30 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk [2010/02/23 20:53:30 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ========== Files Created - No Company Name ========== [2010/03/21 12:09:42 | 000,000,040 | ---- | C] () -- C:\WINDOWS\nero.INI [2010/03/18 23:12:43 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\SMETKA-Koh.doc [2010/03/15 10:39:40 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\dieta.doc [2010/03/08 00:46:54 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\българо-немски речник.lnk [2010/03/05 01:39:33 | 000,815,616 | ---- | C] () -- C:\Documents and Settings\MASTER\My Documents\SPISUK ITEMI.doc [2010/02/21 20:47:39 | 000,001,619 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk [2010/02/21 20:47:39 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2010/02/01 23:32:35 | 002,701,824 | R--- | C] () -- C:\WINDOWS\System32\s3gcil_inv.dll [2009/12/08 14:03:57 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\CSDLGE1LIB.dll [2009/12/03 15:09:50 | 000,258,113 | ---- | C] () -- C:\WINDOWS\System32\MPLEX.DLL [2009/12/03 09:47:19 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\FASTWiz.log [2009/12/02 23:11:43 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/12/02 16:28:02 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009/12/02 16:20:31 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll [2009/12/02 16:19:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI [2009/12/02 16:14:11 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini [2009/12/02 16:13:26 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009/12/02 16:13:26 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2009/12/02 16:13:24 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009/12/02 16:13:23 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009/12/02 16:13:23 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009/12/02 16:13:22 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009/12/02 16:13:22 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI ========== LOP Check ========== [2009/12/11 21:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\Gizmoz [2009/12/08 14:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\LGSync [2010/01/25 10:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\piksi Publisher [2010/02/01 23:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\uTorrent [2010/03/22 22:45:17 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{9DCC3BFD-677C-4E12-A4CB-47B8E38C7796}.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2009/12/02 14:55:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009/12/02 14:49:40 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2009/12/02 14:55:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2009/12/02 14:55:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009/12/02 14:55:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2008/04/14 11:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008/04/14 11:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr [2010/03/22 09:37:47 | 2013,265,920 | -HS- | M] () -- C:\pagefile.sys [2009/12/28 18:26:10 | 000,107,008 | -HS- | M] () -- C:\Thumbs.db < MD5 for: AGP440.SYS > [2009/09/09 13:20:18 | 017,776,636 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys < MD5 for: ATAPI.SYS > [2009/09/09 13:20:18 | 017,776,636 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008/04/14 11:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: EVENTLOG.DLL > [2008/04/14 11:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll [2008/04/14 11:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: NETLOGON.DLL > [2008/04/14 11:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll [2008/04/14 11:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2008/04/14 11:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll [2008/04/14 11:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2009/03/08 04:31:56 | 000,183,808 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\iepeers.dll < %systemroot%\Tasks\*.job /lockedfiles > < %PROGRAMFILES%\*. > [2009/12/02 16:21:14 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe [2009/12/02 16:17:07 | 000,000,000 | ---D | M] -- C:\Program Files\Ahead [2010/02/05 15:42:42 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files [2009/12/02 14:51:46 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications [2009/12/02 16:15:09 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink [2009/12/03 15:10:05 | 000,000,000 | ---D | M] -- C:\Program Files\directx [2010/01/31 19:11:07 | 000,000,000 | ---D | M] -- C:\Program Files\DivX [2010/03/22 20:13:30 | 000,000,000 | ---D | M] -- C:\Program Files\ESET [2010/02/06 10:40:39 | 000,000,000 | ---D | M] -- C:\Program Files\FunWebProducts [2010/01/30 11:16:01 | 000,000,000 | ---D | M] -- C:\Program Files\Google [2010/02/01 23:32:21 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information [2009/12/02 15:02:16 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer [2010/01/31 21:00:42 | 000,000,000 | ---D | M] -- C:\Program Files\Java [2009/12/02 16:13:24 | 000,000,000 | ---D | M] -- C:\Program Files\K-Lite Codec Pack [2009/12/08 14:04:38 | 000,000,000 | ---D | M] -- C:\Program Files\LG Electronics [2009/12/08 14:03:58 | 000,000,000 | ---D | M] -- C:\Program Files\LGE GSM PC Sync [2010/02/23 20:53:27 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee Security Scan [2010/03/15 10:39:09 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger [2009/12/02 16:26:45 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync [2009/12/02 14:59:10 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage [2009/12/02 16:26:25 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office [2009/12/02 16:26:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET [2009/12/02 14:52:58 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker [2009/12/02 14:50:47 | 000,000,000 | ---D | M] -- C:\Program Files\MSN [2009/12/02 14:51:18 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone [2010/02/05 23:49:34 | 000,000,000 | ---D | M] -- C:\Program Files\MyWebSearch [2009/12/02 14:53:10 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting [2009/12/02 14:51:34 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services [2009/12/02 14:53:06 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express [2009/12/03 15:10:05 | 000,000,000 | ---D | M] -- C:\Program Files\Pleomax Camera Plus 1.0 [2010/02/01 23:33:29 | 000,000,000 | ---D | M] -- C:\Program Files\S3 [2009/12/02 16:19:51 | 000,000,000 | ---D | M] -- C:\Program Files\SA Dictionary 2002 Professional [2009/12/04 21:08:01 | 000,000,000 | R--D | M] -- C:\Program Files\Skype [2010/03/15 10:39:10 | 000,000,000 | ---D | M] -- C:\Program Files\TRADER.BG2 [2009/12/02 15:03:43 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information [2009/12/02 16:18:10 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent [2010/02/01 23:26:09 | 000,000,000 | ---D | M] -- C:\Program Files\VIA [2009/12/03 15:08:46 | 000,000,000 | ---D | M] -- C:\Program Files\Vimicro [2009/12/02 16:14:52 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp [2010/03/15 10:39:10 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2 [2009/12/02 14:54:56 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player [2009/12/02 14:51:10 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT [2009/12/02 14:53:41 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate [2009/12/02 16:18:52 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR [2009/12/02 14:59:10 | 000,000,000 | ---D | M] -- C:\Program Files\xerox < %userprofile%\Desktop\*.* > [2009/12/20 20:24:36 | 000,062,464 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\AL-kupane_izlojba.doc [2010/02/19 23:41:07 | 000,001,639 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\CCleaner.lnk [2010/03/15 10:40:08 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\dieta.doc [2010/01/31 19:10:50 | 000,001,472 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\DivX Movies.lnk [2010/03/16 22:01:24 | 000,000,185 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\eBay Countdown.url [2010/03/21 00:07:24 | 000,029,158 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Extras.Txt [2009/12/02 15:04:32 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Internet Explorer.lnk [2009/12/02 16:28:59 | 000,002,044 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Microsoft Office Excel 2003.lnk [2010/03/21 11:32:11 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Microsoft Office Word 2003.lnk [2009/12/02 16:17:54 | 000,001,251 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Nero StartSmart.lnk [2010/03/21 00:00:25 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MASTER\Desktop\OTL.exe [2010/03/21 00:07:18 | 000,060,480 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\OTL.Txt [2009/12/08 10:28:46 | 000,001,139 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Photoshop.lnk [2010/03/22 01:32:09 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\SMETKA-Koh.doc [2009/12/03 13:03:13 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\The KMPlayer.lnk [2009/11/23 15:17:50 | 000,001,523 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\TRADER_BG Demo.lnk [2009/12/03 14:25:36 | 042,064,933 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\unics.exe [2009/12/02 16:14:35 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Winamp.lnk [2009/12/02 15:04:56 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Windows Media Player.lnk [2009/12/02 16:18:52 | 000,000,692 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\WinRAR.lnk [2009/12/15 20:08:47 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\MASTER\Desktop\~$-kupane_izlojba.doc [2009/12/02 16:18:10 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\µTorrent.lnk [2010/03/08 00:46:54 | 000,000,803 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\българо-немски речник.lnk [2009/12/02 21:46:54 | 000,000,333 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Пряк път до DC++.lnk [2009/12/03 13:50:37 | 000,000,625 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Пряк път до sms.lnk [2009/12/03 13:11:35 | 000,000,977 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Пряк път до StrongDC.lnk < %userprofile%\Desktop\*. > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > < End of report > OTL Extras logfile created on: 3/23/2010 12:27:42 AM - Run 2 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\MASTER\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000402 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 49.00% Memory free 3.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free Paging file location(s): C:\pagefile.sys 1920 3840 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.30 Gb Total Space | 22.49 Gb Free Space | 76.76% Space Free | Partition Type: NTFS Drive D: | 124.08 Gb Total Space | 84.94 Gb Free Space | 68.46% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MASTER-FADE9DED Current User Name: MASTER Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- File not found "C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- File not found "C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- File not found "C:\ПРОГРАМИ\StrongDC++\StrongDC++ v2.21\StrongDC++ v2.21\StrongDC.exe" = C:\ПРОГРАМИ\StrongDC++\StrongDC++ v2.21\StrongDC++ v2.21\StrongDC.exe:*:Enabled:StrongDC++ -- () "C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe" = C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe:*:Enabled:KishKish Lie Detector -- (Alex Rosenbaum and KishKish.com) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0B7BA3EE-D7AC-494E-999D-DA58D6D01DAC}" = LG_MobileSync "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 11 "{2EAF7E61-068E-11DF-953C-005056806466}" = Google Земя "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features "{5EA24DA8-F398-42C7-8CDC-39273493C514}" = PLEOMAX Web Camera "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{966DF92F-3EB4-499F-BDFD-9275470AC546}" = Pleomax Camera Plus 1.0 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1026-7B44-A91000000001}" = Adobe Reader 9.1 - Bulgarian "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "ATnotes_is1" = ATnotes Version 9.5 "CCleaner" = CCleaner "ESET Online Scanner" = ESET Online Scanner v3 "EuroDictXP" = KoralSoft - EuroDictXP "FlexType 2K" = FlexType 2K "Google Chrome" = Google Chrome "HijackThis" = HijackThis 2.0.2 "ie8" = Windows Internet Explorer 8 "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager "KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.7 (Full) "McAfee Security Scan" = McAfee Security Scan Plus "MyWebSearch bar Uninstall" = My Web Search (MyWebFace) "Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM "Picasa 3" = Picasa 3 "SA Dictionary 2002 Professional" = SA Dictionary 2002 Professional "SMS_is1" = SMS version 3.0.4.4 "The KMPlayer" = The KMPlayer 2.9.4.1434 "TRADER.BG2_is1" = TRADER.BG2 1.48 "VIA Chrome9 HC IGP Display" = VIA/S3G Display Driver 6.14.10.0067 "VLC media player" = VideoLAN VLC media player 0.8.6f "Winamp" = Winamp (remove only) "WinRAR archiver" = WinRAR archiver ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 2/2/2010 9:13:32 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/3/2010 9:41:25 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/3/2010 1:20:43 PM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/5/2010 9:45:30 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/7/2010 9:41:17 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/10/2010 9:50:33 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/12/2010 11:35:01 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/14/2010 9:42:23 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/17/2010 9:41:10 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/19/2010 9:41:27 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. [ System Events ] Error - 3/18/2010 5:14:18 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/18/2010 5:14:42 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/18/2010 5:47:49 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/18/2010 5:47:51 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 0.0.0.0 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/19/2010 4:29:05 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/20/2010 4:29:56 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/20/2010 4:30:20 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/21/2010 3:02:49 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/21/2010 6:58:45 PM | Computer Name = MASTER-FADE9DED | Source = Service Control Manager | ID = 7034 Description = The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). Error - 3/21/2010 7:02:20 PM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. < End of report >
  7. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=c0e7448016a4ab4286967e43e69fc294 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-22 07:05:37 # local_time=2010-03-22 09:05:37 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 3799 3799 0 0 # scanned=33494 # found=55 # cleaned=55 # scan_time=2929 C:\_OTL.rar multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE Win32/Adware.FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL Win32/FunWeb application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL a variant of Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL probably a variant of Win32/Toolbar.MyWebSearch application (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\WINDOWS\system32\f3PSSavr.scr Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\pdjeodramxdrd.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\tfjckxjqajn.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_\tjroarhsgtbrfjk.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\bhfsu.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\bxlogdzqkdrnhryskkgmu.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\fxhgunfsixhzpvyoc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_Documents and Settings\MASTER\Local Settings\Temp\mhuwnjeunfsngpvofeze.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\bxlogdzqkdrnhryskkgmu.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\fxhgunfsixhzpvyoc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\mhuwnjeunfsngpvofeze.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\ohsshbuizpatkrvmby.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\speibzwojdspkvdyrspwfq.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\ypywjbsethqhwbds.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\ztfgwrlasjvphpumcau.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\bxlogdzqkdrnhryskkgmu.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\fxhgunfsixhzpvyoc.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\mhuwnjeunfsngpvofeze.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\ohsshbuizpatkrvmby.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\speibzwojdspkvdyrspwfq.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\ypywjbsethqhwbds.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\C_WINDOWS\system32\ztfgwrlasjvphpumcau.exe Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\D_\pdjeodramxdrd.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\D_\tfjckxjqajn.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\03222010_005844\D_\tjroarhsgtbrfjk.bat Win32/AutoRun.Agent.UD worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\ПРОГРАМИ\NOD32\patch.rar probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C
  8. 1. Download Link: Click here to download file http://rapidshare.com/files/366793322/_OTL.rar.html MD5: 77E97FD97FAB876F4ED78265EB557E68
  9. All processes killed ========== OTL ========== No active process named mhuwnjeunfsngpvofeze.exe was found! No active process named bhfsu.exe was found! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\oxyotdmq deleted successfully. C:\WINDOWS\system32\mhuwnjeunfsngpvofeze.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\qfmitjyivhodqt deleted successfully. C:\Documents and Settings\MASTER\Local Settings\Temp\fxhgunfsixhzpvyoc.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\zzGBK deleted successfully. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Run\\oxyotdmq deleted successfully. C:\Documents and Settings\MASTER\Local Settings\Temp\bxlogdzqkdrnhryskkgmu.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Run\\tfjckxjqajn deleted successfully. C:\WINDOWS\system32\ztfgwrlasjvphpumcau.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\fpriozjow deleted successfully. C:\WINDOWS\system32\fxhgunfsixhzpvyoc.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\pdjeodramxdrd deleted successfully. File C:\Documents and Settings\MASTER\Local Settings\Temp\fxhgunfsixhzpvyoc.exe not found. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\fpriozjow deleted successfully. C:\Documents and Settings\MASTER\Local Settings\Temp\mhuwnjeunfsngpvofeze.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\qdiclzmufpuh deleted successfully. C:\WINDOWS\system32\ohsshbuizpatkrvmby.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\yjmelxioxf deleted successfully. C:\WINDOWS\fxhgunfsixhzpvyoc.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\zhhwajr deleted successfully. File C:\DOCUME~1\MASTER\LOCALS~1\Temp\bxlogdzqkdrnhryskkgmu.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\ not found. File F:\tfjckxjqajn.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\ not found. File F:\tjroarhsgtbrfjk.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\ not found. File F:\pdjeodramxdrd.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\ not found. File G:\tfjckxjqajn.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\ not found. File G:\tjroarhsgtbrfjk.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\ not found. File G:\pdjeodramxdrd.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. D:\tfjckxjqajn.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. D:\tjroarhsgtbrfjk.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9381-df4f-11de-93a3-806d6172696f}\ not found. D:\pdjeodramxdrd.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9383-df4f-11de-93a3-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9383-df4f-11de-93a3-806d6172696f}\ not found. C:\tfjckxjqajn.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9383-df4f-11de-93a3-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9383-df4f-11de-93a3-806d6172696f}\ not found. C:\tjroarhsgtbrfjk.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8a9383-df4f-11de-93a3-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8b8a9383-df4f-11de-93a3-806d6172696f}\ not found. C:\pdjeodramxdrd.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\ not found. File F:\tfjckxjqajn.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\ not found. File F:\tjroarhsgtbrfjk.bat not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\ not found. File F:\pdjeodramxdrd.bat not found. C:\WINDOWS\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh moved successfully. C:\Program Files\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh moved successfully. C:\Documents and Settings\MASTER\Local Settings\Application Data\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh moved successfully. C:\WINDOWS\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff moved successfully. C:\Program Files\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff moved successfully. C:\Documents and Settings\MASTER\Local Settings\Application Data\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff moved successfully. C:\WINDOWS\system32\sxughnssvxuzcvlopydsjcfrho.qcd moved successfully. C:\WINDOWS\sxughnssvxuzcvlopydsjcfrho.qcd moved successfully. C:\Program Files\sxughnssvxuzcvlopydsjcfrho.qcd moved successfully. C:\Documents and Settings\MASTER\Local Settings\Application Data\sxughnssvxuzcvlopydsjcfrho.qcd moved successfully. C:\WINDOWS\system32\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff moved successfully. C:\WINDOWS\ztfgwrlasjvphpumcau.exe moved successfully. C:\WINDOWS\speibzwojdspkvdyrspwfq.exe moved successfully. C:\WINDOWS\ohsshbuizpatkrvmby.exe moved successfully. C:\WINDOWS\mhuwnjeunfsngpvofeze.exe moved successfully. File C:\WINDOWS\fxhgunfsixhzpvyoc.exe not found. C:\WINDOWS\bxlogdzqkdrnhryskkgmu.exe moved successfully. C:\WINDOWS\ypywjbsethqhwbds.exe moved successfully. C:\WINDOWS\system32\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh moved successfully. C:\autorun.inf moved successfully. File C:\WINDOWS\System32\ztfgwrlasjvphpumcau.exe not found. C:\WINDOWS\system32\speibzwojdspkvdyrspwfq.exe moved successfully. File C:\WINDOWS\System32\ohsshbuizpatkrvmby.exe not found. File C:\WINDOWS\System32\fxhgunfsixhzpvyoc.exe not found. C:\WINDOWS\system32\bxlogdzqkdrnhryskkgmu.exe moved successfully. C:\WINDOWS\system32\ypywjbsethqhwbds.exe moved successfully. File C:\WINDOWS\System32\mhuwnjeunfsngpvofeze.exe not found. C:\WINDOWS\system32\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz moved successfully. C:\WINDOWS\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz moved successfully. C:\Program Files\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz moved successfully. C:\Documents and Settings\MASTER\Local Settings\Application Data\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz moved successfully. File C:\Program Files\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff not found. File C:\Documents and Settings\MASTER\Local Settings\Application Data\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff not found. File C:\Program Files\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz not found. File C:\Documents and Settings\MASTER\Local Settings\Application Data\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz not found. File C:\Program Files\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh not found. File C:\Documents and Settings\MASTER\Local Settings\Application Data\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh not found. C:\Program Files\tjroarhsgtbrfjkykeuuwaolmeuczlcsdremc.uvj moved successfully. C:\Documents and Settings\MASTER\Local Settings\Application Data\tjroarhsgtbrfjkykeuuwaolmeuczlcsdremc.uvj moved successfully. File C:\Program Files\sxughnssvxuzcvlopydsjcfrho.qcd not found. File C:\Documents and Settings\MASTER\Local Settings\Application Data\sxughnssvxuzcvlopydsjcfrho.qcd not found. ========== FILES ========== File\Folder C:\WINDOWS\system32\mhuwnjeunfsngpvofeze.exe not found. C:\Documents and Settings\MASTER\Local Settings\Temp\bhfsu.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: MASTER ->Temp folder emptied: 6425290 bytes ->Temporary Internet Files folder emptied: 54632368 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 1964675 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33237 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2402044 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 9553 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 76411961 bytes Total Files Cleaned = 135.00 mb OTL by OldTimer - Version 3.1.37.3 log created on 03222010_005844 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DF88A4.tmp not found! File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DF8944.tmp not found! File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DFEAE6.tmp not found! File\Folder C:\Documents and Settings\MASTER\Local Settings\Temp\~DFEAF5.tmp not found! C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\XH51Z1CS\ads[2].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\XH51Z1CS\sh14[1].html moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\QF9QXMAM\ads[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\QF9QXMAM\ads[2].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\QF9QXMAM\ads[3].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\QF9QXMAM\afr[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\QF9QXMAM\index[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\QCQ148ZF\a[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\C27V59M6\eBayISAPI[4].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\8EY4J51J\banner[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\8EY4J51J\box[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\8EY4J51J\inside[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\Content.IE5\7NYGYUO0\ads[1].htm moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Documents and Settings\MASTER\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully. Registry entries deleted on Reboot...
  10. БЛАГОДАРЯ ! Extras.txt OTL Extras logfile created on: 3/21/2010 12:03:11 AM - Run 1 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\MASTER\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000402 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free 3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free Paging file location(s): C:\pagefile.sys 1920 3840 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.30 Gb Total Space | 22.59 Gb Free Space | 77.09% Space Free | Partition Type: NTFS Drive D: | 124.08 Gb Total Space | 84.98 Gb Free Space | 68.49% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MASTER-FADE9DED Current User Name: MASTER Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- File not found "C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- File not found "C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- File not found "C:\ПРОГРАМИ\StrongDC++\StrongDC++ v2.21\StrongDC++ v2.21\StrongDC.exe" = C:\ПРОГРАМИ\StrongDC++\StrongDC++ v2.21\StrongDC++ v2.21\StrongDC.exe:*:Enabled:StrongDC++ -- () "C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe" = C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe:*:Enabled:KishKish Lie Detector -- (Alex Rosenbaum and KishKish.com) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0B7BA3EE-D7AC-494E-999D-DA58D6D01DAC}" = LG_MobileSync "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 11 "{2EAF7E61-068E-11DF-953C-005056806466}" = Google Земя "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features "{5EA24DA8-F398-42C7-8CDC-39273493C514}" = PLEOMAX Web Camera "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{966DF92F-3EB4-499F-BDFD-9275470AC546}" = Pleomax Camera Plus 1.0 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1026-7B44-A91000000001}" = Adobe Reader 9.1 - Bulgarian "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "ATnotes_is1" = ATnotes Version 9.5 "CCleaner" = CCleaner "EuroDictXP" = KoralSoft - EuroDictXP "FlexType 2K" = FlexType 2K "Google Chrome" = Google Chrome "HijackThis" = HijackThis 2.0.2 "ie8" = Windows Internet Explorer 8 "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager "KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.7 (Full) "McAfee Security Scan" = McAfee Security Scan Plus "MyWebSearch bar Uninstall" = My Web Search (MyWebFace) "Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM "Picasa 3" = Picasa 3 "SA Dictionary 2002 Professional" = SA Dictionary 2002 Professional "SMS_is1" = SMS version 3.0.4.4 "The KMPlayer" = The KMPlayer 2.9.4.1434 "TRADER.BG2_is1" = TRADER.BG2 1.48 "VIA Chrome9 HC IGP Display" = VIA/S3G Display Driver 6.14.10.0067 "VLC media player" = VideoLAN VLC media player 0.8.6f "Winamp" = Winamp (remove only) "WinRAR archiver" = WinRAR archiver ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 2/2/2010 9:13:32 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/3/2010 9:41:25 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/3/2010 1:20:43 PM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/5/2010 9:45:30 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/7/2010 9:41:17 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/10/2010 9:50:33 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/12/2010 11:35:01 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/14/2010 9:42:23 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/17/2010 9:41:10 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. Error - 2/19/2010 9:41:27 AM | Computer Name = MASTER-FADE9DED | Source = Application Error | ID = 1000 Description = Faulting application nss.exe, version 2.7.0.52, faulting module ccl80u.dll, version 108.0.1.7, fault address 0x00044e18. [ System Events ] Error - 3/18/2010 3:38:25 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/18/2010 4:36:54 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/18/2010 4:41:10 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/18/2010 5:14:18 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/18/2010 5:14:42 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/18/2010 5:47:49 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/18/2010 5:47:51 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 0.0.0.0 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/19/2010 4:29:05 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 3/20/2010 4:29:56 AM | Computer Name = MASTER-FADE9DED | Source = Dhcp | ID = 1002 Description = The IP address lease 192.168.1.100 for the Network Card with network address 0023CDB22AA0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). Error - 3/20/2010 4:30:20 AM | Computer Name = MASTER-FADE9DED | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. < End of report > OTL.Txt OTL logfile created on: 3/21/2010 12:03:11 AM - Run 1 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\MASTER\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000402 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free 3.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free Paging file location(s): C:\pagefile.sys 1920 3840 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29.30 Gb Total Space | 22.59 Gb Free Space | 77.09% Space Free | Partition Type: NTFS Drive D: | 124.08 Gb Total Space | 84.98 Gb Free Space | 68.49% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MASTER-FADE9DED Current User Name: MASTER Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\MASTER\Desktop\OTL.exe (OldTimer Tools) PRC - C:\WINDOWS\system32\mhuwnjeunfsngpvofeze.exe () PRC - C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com) PRC - C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) PRC - C:\Documents and Settings\MASTER\Local Settings\Temp\bhfsu.exe () PRC - C:\ПРОГРАМИ\SMS\sms\sms.exe (Jeko Ianev www.ianev.org) PRC - C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe (Alex Rosenbaum and KishKish.com) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.) PRC - C:\WINDOWS\system32\S3Trayp.exe (S3 Graphics Co., Ltd.) PRC - C:\ПРОГРАМИ\бележки\ATnotes\ATnotes.exe (Thomas Ascher) PRC - C:\WINDOWS\Vm_sti.exe (VM.) PRC - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation) PRC - C:\WINDOWS\Datecs\Flex2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\MASTER\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (MyWebSearch.com) MOD - C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (MyWebSearch.com) MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (MyWebSearchService) -- C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (MyWebSearch.com) SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.) ========== Driver Services (SafeList) ========== DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider) DRV - (VIAHdAudAddService) -- C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.) DRV - (ViaIde) -- C:\WINDOWS\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (Tcpip6) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider) DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation) DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation) DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation) DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation) DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation) DRV - (S3GIGP) -- C:\WINDOWS\system32\drivers\S3gIGPm.sys (S3 Graphics Co., Ltd.) DRV - (xfilt) -- C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc) DRV - (videX32) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.) DRV - (ip100xp) -- C:\WINDOWS\system32\drivers\ipfnd51.sys (IC Plus Corp. ) DRV - (ZSMC302) -- C:\WINDOWS\system32\drivers\usbvm302.sys (Creative Technology Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie'>http://www.google.com/ie IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.bg/ IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = bg IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 92 96 50 BC 5D 73 CA 01 [binary data] IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie'>http://www.google.com/ie IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie'>http://www.google.com/ie IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com) IE - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\MyWebSearch\bar\1.bin [2010/02/05 23:49:38 | 000,000,000 | ---D | M] O1 HOSTS File: ([2008/04/14 11:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL (MyWebSearch.com) O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found. O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O4 - HKLM..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE (VM.) O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (MyWebSearch.com) O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com) O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [oxyotdmq] C:\WINDOWS\System32\mhuwnjeunfsngpvofeze.exe () O4 - HKLM..\Run: [qfmitjyivhodqt] C:\Documents and Settings\MASTER\Local Settings\Temp\fxhgunfsixhzpvyoc.exe () O4 - HKLM..\Run: [s3Trayp] C:\WINDOWS\System32\S3Trayp.exe (S3 Graphics Co., Ltd.) O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.) O4 - HKLM..\Run: [zzGBK] E:\setup.exe File not found O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [ATnotes.exe] C:\ПРОГРАМИ\бележки\ATnotes\ATnotes.exe (Thomas Ascher) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (MyWebSearch.com) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [oxyotdmq] C:\Documents and Settings\MASTER\Local Settings\Temp\bxlogdzqkdrnhryskkgmu.exe () O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [sMS by Jeko Ianev] C:\ПРОГРАМИ\SMS\sms\sms.exe (Jeko Ianev www.ianev.org) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\Run: [tfjckxjqajn] C:\WINDOWS\System32\ztfgwrlasjvphpumcau.exe () O4 - HKLM..\RunOnce: [fpriozjow] C:\WINDOWS\System32\fxhgunfsixhzpvyoc.exe () O4 - HKLM..\RunOnce: [pdjeodramxdrd] C:\Documents and Settings\MASTER\Local Settings\Temp\fxhgunfsixhzpvyoc.exe () O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\RunOnce: [fpriozjow] C:\Documents and Settings\MASTER\Local Settings\Temp\mhuwnjeunfsngpvofeze.exe () O4 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003..\RunOnce: [qdiclzmufpuh] C:\WINDOWS\System32\ohsshbuizpatkrvmby.exe () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: yjmelxioxf = fxhgunfsixhzpvyoc.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: zhhwajr = C:\DOCUME~1\MASTER\LOCALS~1\Temp\bxlogdzqkdrnhryskkgmu.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O7 - HKU\S-1-5-21-1220945662-57989841-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-5/myWebFaceInitialSetup1.0.1.3.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.6.0/jinstall-6u11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Моята текуща начална страница) - About:Home O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/12/02 14:55:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2010/03/20 10:33:05 | 000,000,801 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2010/03/20 10:33:06 | 000,000,818 | RHS- | M] () - D:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\Shell\AutoRun\command - "" = F:\tfjckxjqajn.bat -- File not found O33 - MountPoints2\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\Shell\explore\Command - "" = F:\tjroarhsgtbrfjk.bat -- File not found O33 - MountPoints2\{50f0ca1f-e356-11de-bfa2-0023cdb22aa0}\Shell\open\Command - "" = F:\pdjeodramxdrd.bat -- File not found O33 - MountPoints2\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\Shell\AutoRun\command - "" = G:\tfjckxjqajn.bat -- File not found O33 - MountPoints2\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\Shell\explore\Command - "" = G:\tjroarhsgtbrfjk.bat -- File not found O33 - MountPoints2\{50f0ca20-e356-11de-bfa2-0023cdb22aa0}\Shell\open\Command - "" = G:\pdjeodramxdrd.bat -- File not found O33 - MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\Shell\AutoRun\command - "" = D:\tfjckxjqajn.bat -- [2009/07/04 03:03:27 | 000,577,536 | RHS- | M] () O33 - MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\Shell\explore\Command - "" = D:\tjroarhsgtbrfjk.bat -- [2009/06/12 05:09:50 | 000,577,536 | RHS- | M] () O33 - MountPoints2\{8b8a9381-df4f-11de-93a3-806d6172696f}\Shell\open\Command - "" = D:\pdjeodramxdrd.bat -- [2009/06/08 07:13:20 | 000,577,536 | RHS- | M] () O33 - MountPoints2\{8b8a9383-df4f-11de-93a3-806d6172696f}\Shell\AutoRun\command - "" = C:\tfjckxjqajn.bat -- [2009/05/16 09:16:39 | 000,577,536 | RHS- | M] () O33 - MountPoints2\{8b8a9383-df4f-11de-93a3-806d6172696f}\Shell\explore\Command - "" = C:\tjroarhsgtbrfjk.bat -- [2009/06/18 05:20:54 | 000,577,536 | RHS- | M] () O33 - MountPoints2\{8b8a9383-df4f-11de-93a3-806d6172696f}\Shell\open\Command - "" = C:\pdjeodramxdrd.bat -- [2009/04/12 03:26:44 | 000,577,536 | RHS- | M] () O33 - MountPoints2\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\Shell\AutoRun\command - "" = F:\tfjckxjqajn.bat -- File not found O33 - MountPoints2\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\Shell\explore\Command - "" = F:\tjroarhsgtbrfjk.bat -- File not found O33 - MountPoints2\{9044beee-dff9-11de-bf9f-0023cdb22aa0}\Shell\open\Command - "" = F:\pdjeodramxdrd.bat -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010/03/21 00:00:12 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MASTER\Desktop\OTL.exe [2010/03/18 10:40:39 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\MASTER\Recent [2010/03/04 18:30:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MASTER\Local Settings\Application Data\Identities [2010/03/04 16:26:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google [2010/02/23 20:53:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\McAfee [2010/02/21 20:47:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee [2010/02/21 20:47:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan [2010/02/21 20:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan [2010/02/03 19:42:50 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2010/02/03 19:42:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2010/02/03 19:42:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2010/02/03 19:28:15 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009/12/17 11:56:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010/03/21 00:07:12 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh [2010/03/21 00:07:12 | 000,000,316 | -H-- | M] () -- C:\Program Files\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh [2010/03/21 00:07:12 | 000,000,316 | -H-- | M] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh [2010/03/21 00:07:03 | 000,002,120 | -H-- | M] () -- C:\WINDOWS\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff [2010/03/21 00:07:03 | 000,002,120 | -H-- | M] () -- C:\Program Files\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff [2010/03/21 00:07:03 | 000,002,120 | -H-- | M] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff [2010/03/21 00:07:03 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\System32\sxughnssvxuzcvlopydsjcfrho.qcd [2010/03/21 00:07:03 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\sxughnssvxuzcvlopydsjcfrho.qcd [2010/03/21 00:07:03 | 000,000,280 | -H-- | M] () -- C:\Program Files\sxughnssvxuzcvlopydsjcfrho.qcd [2010/03/21 00:07:03 | 000,000,280 | -H-- | M] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\sxughnssvxuzcvlopydsjcfrho.qcd [2010/03/21 00:07:01 | 000,002,120 | -H-- | M] () -- C:\WINDOWS\System32\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff [2010/03/21 00:06:53 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\ztfgwrlasjvphpumcau.exe [2010/03/21 00:06:53 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\speibzwojdspkvdyrspwfq.exe [2010/03/21 00:06:53 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\ohsshbuizpatkrvmby.exe [2010/03/21 00:06:53 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\mhuwnjeunfsngpvofeze.exe [2010/03/21 00:06:53 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\fxhgunfsixhzpvyoc.exe [2010/03/21 00:06:53 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\bxlogdzqkdrnhryskkgmu.exe [2010/03/21 00:06:52 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\ypywjbsethqhwbds.exe [2010/03/21 00:06:12 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\System32\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh [2010/03/21 00:06:05 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010/03/21 00:00:25 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MASTER\Desktop\OTL.exe [2010/03/20 23:27:17 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9DCC3BFD-677C-4E12-A4CB-47B8E38C7796}.job [2010/03/20 12:03:53 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\Microsoft Office Word 2003.lnk [2010/03/20 10:33:05 | 000,000,801 | RHS- | M] () -- C:\autorun.inf [2010/03/20 10:32:30 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ztfgwrlasjvphpumcau.exe [2010/03/20 10:32:30 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\speibzwojdspkvdyrspwfq.exe [2010/03/20 10:32:30 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ohsshbuizpatkrvmby.exe [2010/03/20 10:32:30 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\fxhgunfsixhzpvyoc.exe [2010/03/20 10:32:30 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\bxlogdzqkdrnhryskkgmu.exe [2010/03/20 10:32:29 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\ypywjbsethqhwbds.exe [2010/03/20 10:32:18 | 000,577,536 | RHS- | M] () -- C:\WINDOWS\System32\mhuwnjeunfsngpvofeze.exe [2010/03/20 10:32:18 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010/03/20 10:32:15 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010/03/20 10:29:56 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010/03/20 10:29:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/03/20 01:56:41 | 003,670,016 | -H-- | M] () -- C:\Documents and Settings\MASTER\NTUSER.DAT [2010/03/20 01:56:41 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\MASTER\ntuser.ini [2010/03/19 15:41:00 | 000,000,476 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for MASTER.job [2010/03/19 11:46:00 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk [2010/03/18 23:34:54 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\SMETKA-Koh.doc [2010/03/18 01:01:34 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk [2010/03/16 22:01:24 | 000,000,185 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\eBay Countdown.url [2010/03/15 10:40:08 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\dieta.doc [2010/03/11 14:48:48 | 000,044,616 | ---- | M] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2010/03/10 15:40:52 | 000,000,738 | ---- | M] () -- C:\WINDOWS\win.ini [2010/03/10 11:26:58 | 000,001,958 | -H-- | M] () -- C:\WINDOWS\System32\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz [2010/03/10 11:26:58 | 000,001,958 | -H-- | M] () -- C:\WINDOWS\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz [2010/03/10 11:26:58 | 000,001,958 | -H-- | M] () -- C:\Program Files\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz [2010/03/10 11:26:58 | 000,001,958 | -H-- | M] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz [2010/03/08 10:03:57 | 000,199,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/03/08 00:46:54 | 000,000,803 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\българо-немски речник.lnk [2010/03/05 01:39:34 | 000,815,616 | ---- | M] () -- C:\Documents and Settings\MASTER\My Documents\SPISUK ITEMI.doc [2010/02/25 17:23:20 | 000,000,155 | ---- | M] () -- C:\WINDOWS\winamp.ini [2010/02/23 20:53:30 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk [2010/02/23 20:53:30 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2010/02/19 23:41:07 | 000,001,639 | ---- | M] () -- C:\Documents and Settings\MASTER\Desktop\CCleaner.lnk [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/03/18 23:12:43 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\SMETKA-Koh.doc [2010/03/15 10:39:40 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\dieta.doc [2010/03/08 00:46:54 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\българо-немски речник.lnk [2010/03/05 01:39:33 | 000,815,616 | ---- | C] () -- C:\Documents and Settings\MASTER\My Documents\SPISUK ITEMI.doc [2010/02/21 20:47:39 | 000,001,619 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk [2010/02/21 20:47:39 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2010/02/19 23:41:07 | 000,001,639 | ---- | C] () -- C:\Documents and Settings\MASTER\Desktop\CCleaner.lnk [2010/02/01 23:32:35 | 002,701,824 | R--- | C] () -- C:\WINDOWS\System32\s3gcil_inv.dll [2009/12/29 20:53:24 | 000,002,126 | -H-- | C] () -- C:\Program Files\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff [2009/12/29 20:53:24 | 000,002,126 | -H-- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\qfmitjyivhodqttgrkzyzcpllcryufvkuhta.cff [2009/12/29 20:53:21 | 000,001,958 | -H-- | C] () -- C:\Program Files\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz [2009/12/29 20:53:21 | 000,001,958 | -H-- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\ohsshbuizpatkrvmbyruzgxxbwpaapjcqhxibszd.jgz [2009/12/29 20:53:21 | 000,000,316 | -H-- | C] () -- C:\Program Files\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh [2009/12/29 20:53:21 | 000,000,316 | -H-- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\fxhgunfsixhzpvyocyqswcsruogqpdwobrgqiye.xlh [2009/12/29 20:52:56 | 000,004,248 | -H-- | C] () -- C:\Program Files\tjroarhsgtbrfjkykeuuwaolmeuczlcsdremc.uvj [2009/12/29 20:52:56 | 000,004,248 | -H-- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\tjroarhsgtbrfjkykeuuwaolmeuczlcsdremc.uvj [2009/12/29 20:52:55 | 000,000,280 | -H-- | C] () -- C:\Program Files\sxughnssvxuzcvlopydsjcfrho.qcd [2009/12/29 20:52:55 | 000,000,280 | -H-- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\sxughnssvxuzcvlopydsjcfrho.qcd [2009/12/08 14:03:57 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\CSDLGE1LIB.dll [2009/12/03 15:09:50 | 000,258,113 | ---- | C] () -- C:\WINDOWS\System32\MPLEX.DLL [2009/12/03 09:47:19 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\FASTWiz.log [2009/12/02 23:11:43 | 000,008,704 | ---- | C] () -- C:\Documents and Settings\MASTER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/12/02 16:28:02 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009/12/02 16:20:31 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll [2009/12/02 16:19:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI [2009/12/02 16:14:11 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini [2009/12/02 16:13:26 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009/12/02 16:13:26 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2009/12/02 16:13:24 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009/12/02 16:13:23 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009/12/02 16:13:23 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009/12/02 16:13:22 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009/12/02 16:13:22 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI ========== LOP Check ========== [2009/12/11 21:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\Gizmoz [2009/12/08 14:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\LGSync [2010/01/25 10:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\piksi Publisher [2010/02/01 23:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MASTER\Application Data\uTorrent [2010/03/20 23:27:17 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{9DCC3BFD-677C-4E12-A4CB-47B8E38C7796}.job ========== Purity Check ========== < End of report >
  11. Благодаря за съветите, но НЕ МОГА ДА ВЛЯЗА В НИТО ЕДИН САЙТ С АНТИВИРУСНА ПРОГРАМА ! В МОМЕНТА НА ОТВАРЯНЕТО - СЕ ЗАТВАРЯ САМ .
  12. Моля за помощ! Преди около месец през Скайп /от познат адрес, но без намесата на познатия/започнаха да идват съобщения да вляза в даден линк и аз по инерция взех, че влязох. Започнаха да мигат всички програми, десктопа, да идват още такива съобщения, въобще стана лудница. Единственият начин да спре всичко това бе да спра компютъра. Като го включих, Антивирусната програма /AVG Free 9.0/ беше изчезнала и от тогава до сега нито една антивирусна програма не може да се инсталира. В момента на отваряне на сайт с дадена Антивирусна прогр.- Сайта сам се затваря.Със сигурност има вирус в компютъра, но незнам какво да направя, за да се махне, а и не съм голям специалист. Благодаря предварително за помощта!

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.