Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

rzarector

Потребител
  • Регистрация

  • Последно онлайн

  1. Тук се поставят логове само от HiJackThis. Изключения има,само тогава когато е наистина наложително и трябва да се реагира сравнително бързо,но в последствие се изтриват от темата!
  2. могa ли да деинсталирам ComboFix пo др. на4ин 4e сaM с Vista и нeмам Run v Start Menu деинсталираx ComboFix Malwarebytes' Anti-Malware 1.38 Database version: 2328 Windows 6.0.6001 Service Pack 1 6/24/2009 4:21:56 PM mbam-log-2009-06-24 (16-21-56).txt Scan type: Quick Scan Objects scanned: 73806 Time elapsed: 3 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
  3. ComboFix 09-06-23.01 - SYSTEM 06/24/2009 15:10.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3070.1910 [GMT 3:00] Running from: c:\windows\system32\config\systemprofile\Desktop\Combo-Fix.exe Command switches used :: c:\windows\system32\config\systemprofile\Desktop\CFScript.txt AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 ))))))))))))))))))))))))))))))) . 2009-06-24 12:14 . 2009-06-24 12:15 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2009-06-24 12:14 . 2009-06-24 12:14 -------- d-----w- c:\users\Rzarector\AppData\Local\temp 2009-06-24 08:09 . 2009-06-24 08:09 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes 2009-06-24 08:08 . 2009-06-17 08:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-24 08:08 . 2009-06-24 08:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-24 08:08 . 2009-06-24 08:08 -------- d-----w- c:\programdata\Malwarebytes 2009-06-24 08:08 . 2009-06-17 08:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-23 16:26 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll 2009-06-23 16:26 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll 2009-06-23 16:02 . 2009-06-16 09:40 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVEX32A.DLL 2009-06-23 16:02 . 2009-06-16 09:40 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVENG.SYS 2009-06-23 16:02 . 2009-06-16 09:40 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVEX15.SYS 2009-06-23 16:02 . 2009-06-16 09:40 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\EECTRL.SYS 2009-06-23 16:02 . 2009-06-16 09:40 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\ECMSVR32.DLL 2009-06-23 16:02 . 2009-06-16 09:40 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\CCERASER.DLL 2009-06-23 16:02 . 2009-06-16 09:40 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVENG32.DLL 2009-06-23 16:02 . 2009-06-16 09:40 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\ERASER.SYS . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-24 12:15 . 2008-06-25 04:04 168787 ----a-w- c:\programdata\nvModes.dat 2009-06-24 12:14 . 2008-06-25 04:18 12 ----a-w- c:\windows\bthservsdp.dat 2009-06-24 07:47 . 2008-06-25 03:41 -------- d-----w- c:\programdata\NVIDIA 2009-06-23 22:29 . 2008-03-21 07:18 -------- d-----w- c:\programdata\Microsoft Help 2009-06-23 22:02 . 2008-06-25 03:35 103584 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT 2009-06-23 21:48 . 2008-06-25 04:01 -------- d-----w- c:\program files\Google 2009-06-23 21:34 . 2008-06-25 22:15 -------- d-----w- c:\programdata\Apple Computer 2009-06-23 21:31 . 2008-03-21 06:52 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-23 20:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-06-23 17:34 . 2008-03-21 07:20 -------- d-----w- c:\program files\Microsoft Works 2009-06-23 16:00 . 2009-01-30 10:25 -------- d-----w- c:\programdata\Google Updater 2009-06-23 15:40 . 2008-06-25 15:20 1356 ----a-w- c:\users\Rzarector\AppData\Local\d3d9caps.dat 2009-06-16 09:40 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys 2009-06-16 09:40 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys 2009-06-16 09:40 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys 2009-06-16 09:40 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll 2009-06-16 09:40 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll 2009-06-16 09:40 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll 2009-06-16 09:40 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys 2009-06-16 09:40 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll 2009-05-28 00:32 . 2008-10-18 03:51 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2009-05-28 00:32 . 2008-10-18 03:51 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-05-28 00:32 . 2008-10-16 21:11 -------- d-----r- c:\program files\Skype 2009-05-28 00:32 . 2009-02-04 15:42 -------- d-----w- c:\program files\Common Files\Skype 2009-05-28 00:32 . 2008-10-18 04:06 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-05-28 00:32 . 2008-06-25 22:34 -------- d-----w- c:\program files\Bit Che 2009-05-25 14:44 . 2009-02-04 15:42 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Skype 2009-05-25 13:04 . 2008-06-25 04:09 -------- d-----w- c:\users\Rzarector\AppData\Roaming\skypePM 2009-05-21 09:30 . 2008-06-25 03:40 103584 ----a-w- c:\users\Rzarector\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-19 22:31 . 2008-03-21 06:57 -------- d-----w- c:\program files\Acer 2009-05-13 16:55 . 2009-05-08 16:29 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Skype 2009-05-13 16:54 . 2009-05-08 16:30 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\skypePM 2009-05-08 07:05 . 2009-05-08 07:05 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Uniblue 2009-05-08 06:45 . 2009-05-08 06:45 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Intel 2009-05-08 06:45 . 2009-05-08 06:45 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Intel 2009-05-08 06:45 . 2009-05-08 06:45 -------- d-----w- c:\programdata\Roaming 2009-05-08 06:44 . 2009-05-08 06:44 -------- d-----w- c:\program files\Cisco 2009-05-08 06:44 . 2009-05-08 06:44 -------- d-----w- c:\programdata\Intel 2009-05-08 06:44 . 2008-03-21 06:46 -------- d-----w- c:\program files\Intel 2009-05-07 09:09 . 2008-08-13 04:51 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Apple Computer 2009-05-07 06:58 . 2009-05-07 06:58 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-05-07 06:58 . 2009-05-07 06:58 -------- d-----w- c:\program files\iTunes(246) 2009-05-07 06:58 . 2009-05-07 06:58 -------- d-----w- c:\program files\iPod(245) 2009-05-07 06:58 . 2008-08-13 04:48 -------- d-----w- c:\program files\Common Files\Apple 2009-05-04 16:25 . 2009-05-04 16:25 -------- d-----w- c:\programdata\PC Drivers HeadQuarters 2009-04-29 17:10 . 2009-04-29 17:10 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Uniblue 2009-04-29 17:02 . 2009-04-29 17:02 -------- dc-h--w- c:\programdata\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1} 2009-04-29 12:20 . 2008-03-21 06:52 319456 ----a-w- c:\windows\DIFxAPI.dll 2009-04-29 00:01 . 2008-11-22 18:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2009-04-26 08:55 . 2009-04-26 08:55 -------- d-----w- c:\programdata\WindowsSearch 2009-04-24 16:05 . 2009-06-23 16:14 827904 ----a-w- c:\windows\system32\wininet.dll 2009-04-24 16:02 . 2009-06-23 16:14 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-24 13:44 . 2009-06-23 16:14 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-04-23 12:43 . 2009-06-23 16:14 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:42 . 2009-06-23 16:14 636928 ----a-w- c:\windows\system32\localspl.dll 2009-04-21 11:55 . 2009-06-23 16:14 2033152 ----a-w- c:\windows\system32\win32k.sys . ((((((((((((((((((((((((((((( SnapShot@2009-06-24_10.57.59 ))))))))))))))))))))))))))))))))))))))))) . - 2008-01-21 01:58 . 2009-06-24 10:35 68742 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2008-01-21 01:58 . 2009-06-24 11:35 68742 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2008-06-25 03:41 . 2009-06-24 11:35 12860 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-61857225-2502580657-359961809-1000_UserData.bin - 2008-06-25 03:36 . 2009-06-24 10:57 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-06-25 03:36 . 2009-06-24 12:15 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-04-29 10:34 . 2009-06-24 11:34 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat - 2009-04-29 10:34 . 2009-06-24 10:35 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat + 2009-06-24 10:59 . 2009-06-24 10:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat + 2006-11-02 13:05 . 2009-06-24 11:35 103098 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2009-06-24 10:57 . 2009-06-24 12:15 163840 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-06-25 03:36 . 2009-06-24 10:57 147456 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-06-25 03:36 . 2009-06-24 12:15 147456 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2006-11-02 10:33 . 2009-06-24 11:39 3370978 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2009-06-24 11:39 1089818 c:\windows\System32\perfc009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-05 06:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-07 13527584] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-07 92704] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-25 723760] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000] 2008-06-25 03:44 3024384 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{FEE6146F-FF33-41E5-88D6-A550CFB90D21}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{6CEE7A7F-DD8F-4A27-948B-7CB5F6CBC7E5}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe "{B0D6A975-C143-4552-9D1C-051306D65D43}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe "{89A86A7E-74AA-4474-BF25-CE5206CF42E5}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe "{BC24146F-82BD-4C12-BDE9-1B1281CA7210}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe "{E09502F9-8921-49AF-A000-02F12646F216}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe "{F354F89D-2CF0-4A6D-90B4-508E9B59C56F}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe "{7E6114F6-E392-4CC9-BF23-539452182A08}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM "{04DA423E-E404-4176-9943-CAA27E42BD4F}"= UDP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System "{80D045BB-9C5F-463D-B9B9-FFCE93CCD884}"= TCP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System "{0D9CF7C0-9347-42C4-8A78-3E6CA3DA7102}"= UDP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor "{8133EB54-C725-4AB9-8DCE-84ED9546CD99}"= TCP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor "{E18C3035-B729-4315-A0B4-FEA2181834B1}"= UDP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio "{FD9020E1-9CB7-42A7-A282-B9D9CB45805F}"= TCP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio "TCP Query User{18F781D3-234A-4418-A0E0-866DD478FF48}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord "UDP Query User{2DE7D455-8516-4884-8CDA-0CB0E7118BAE}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord "TCP Query User{6AB9339A-BA46-40DE-9F57-6673DC3804F3}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts "UDP Query User{EF750EA3-968B-4CC9-8F4A-1CD407AE4819}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts "{198A73FB-4624-4CC5-A6F2-0F59EB66607E}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus "{9B5BE1DF-CB88-4467-B248-DBD16C339FD5}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus "{055FF55F-7914-4B8E-8BC0-DC8BECE9917A}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email "{D9D1127A-2382-44FF-8764-BAC7D58D0467}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email "TCP Query User{DC4B9D15-8176-4CD1-8D6C-E21266D1B447}c:\\users\\rzarector\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\rzarector\appdata\local\google\chrome\application\chrome.exe:chrome.exe "UDP Query User{30A6BFFD-268F-441E-B4F2-C9757B2EF492}c:\\users\\rzarector\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\rzarector\appdata\local\google\chrome\application\chrome.exe:chrome.exe "{4E5151E4-86F5-4202-B09E-AEF21A742291}"= UDP:d:\games\New Folder (3)\PES2008.exe:Pro Evolution Soccer 2008 "{6B06C9A5-4377-49AD-894A-82657C076D25}"= TCP:d:\games\New Folder (3)\PES2008.exe:Pro Evolution Soccer 2008 "{C1CD543C-A2B6-4AC9-B5A5-3D8088BC3390}"= UDP:d:\games\pes install\CRACK\PES2008.exe:Pro Evolution Soccer 2008 "{40EFD27A-DF0F-441E-A978-C9F090F0C6F1}"= TCP:d:\games\pes install\CRACK\PES2008.exe:Pro Evolution Soccer 2008 "{1FC01AB3-AB21-44A5-9D19-5498F61CC576}"= UDP:d:\games\Pro E\PES2008.exe:Pro Evolution Soccer 2008 "{9368DE89-5567-45BD-9EE3-F9E5B450C41E}"= TCP:d:\games\Pro E\PES2008.exe:Pro Evolution Soccer 2008 "{6945D53D-3395-4CF5-B298-55434C2543C9}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{3AD1DB3C-8F12-4405-B802-DF46AF577DF7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{3E4FE5B5-0E28-4832-A851-173D3C4D9BFA}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{A22AAF35-9DC7-4C0B-913F-626104690C21}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{324D7471-DA81-444F-A457-B1623BFEE1CF}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{110F32DC-4E79-4A9F-BEA3-2E0BE6B60772}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe: "{03BF7FB8-0CA2-4A09-92E5-DF6237B588D2}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe: "{3E88AF5C-6892-428B-A4DB-3E9230C6BA25}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddjswx.exe: "{D8537AA9-0ACD-461C-8654-46BBB9B4597E}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddjswx.exe: "{B9764C9B-B053-49C7-B964-2DF7CD039810}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe: "{91D48567-3559-434B-985C-B4F1DE39B026}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe: "{062D784B-AF60-4702-9885-92AEA8A0ACFF}"= UDP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{F58E9B1E-8790-4131-B434-FBF740F521E9}"= TCP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{31C0EF90-2351-42D0-8ED8-57F24A11F9B2}"= UDP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{785E9C9D-39CB-4E68-AB78-AD0EBAEE3CA7}"= TCP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{AF9617E2-5129-4255-AF15-0B71D6B0BA7A}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008 "{C24B813E-A9D0-4CFE-8963-69918A202C6C}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008 "{AE6DC9B4-C9D6-4426-A6F5-AC12BD38210E}"= UDP:c:\users\Rzarector\Desktop\RS.com.Pro.Evolution.Soccer.2009.BURGUM.PATCH.v0.40.Keygen.exe:enable "{793D0168-5B7D-4A9B-B82D-9566B90D04D5}"= TCP:c:\users\Rzarector\Desktop\RS.com.Pro.Evolution.Soccer.2009.BURGUM.PATCH.v0.40.Keygen.exe:enable "{84747405-4474-4A5A-97DE-537594DB84FB}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "{EAC6CF08-9E93-4FA3-973C-4AE3F8C17133}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "{5F231265-9594-4DE1-B174-D0FC0C11DB2F}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "{635E3031-2F1A-49CF-B590-82CEAE60901A}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "TCP Query User{F9D1743A-2862-41FB-A91E-74159E636B86}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "UDP Query User{3351853F-F4CD-4578-A1A6-8EFA91128A0B}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "{FA19F0A4-D48A-455E-A114-F00A3EFA2AEE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8B4BE52C-2FD6-4790-8605-EA75B878F904}"= c:\program files\Skype\Phone\Skype.exe:Skype "{621256A2-0C20-4A2F-8012-D88F65E84A48}"= c:\program files\Skype\Phone\Skype.exe:Skype "{9E733A64-C6AA-43FE-B5AF-C2850F4C1A6E}"= c:\program files\Skype\Phone\Skype.exe:Skype "{A2575BC4-8FAD-41C7-A446-838395BFEC5F}"= c:\program files\Skype\Phone\Skype.exe:Skype "{944968CF-FA36-4144-8850-5921393A5BA2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{D04FB8E5-3A7D-4B02-8B81-BABF472A3C07}"= c:\program files\Skype\Phone\Skype.exe:Skype "{25511F51-EF4A-4753-A71B-F3C71E2EB99E}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C9655B8E-C86C-4C43-B64C-D0DF33634D71}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C848396C-227A-47E8-A79F-1049760F815D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{DE40EBFE-D6A8-4668-B47E-E1C67CA5B353}"= c:\program files\Skype\Phone\Skype.exe:Skype "{3EF074C8-3B71-44E0-AEDE-9CC3BDC8F673}"= c:\program files\Skype\Phone\Skype.exe:Skype "{DC956A3B-D46D-4BF6-BC3A-A0E82C09EF86}"= c:\program files\Skype\Phone\Skype.exe:Skype "{EEDAEE41-46C4-484B-9915-3853E41712A7}"= c:\program files\Skype\Phone\Skype.exe:Skype "{6A47343C-335C-4D30-B021-AF6050592C4C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C9C09738-9DF7-40BF-A4FE-1DF92698D9D1}"= c:\program files\Skype\Phone\Skype.exe:Skype "{93B9807F-4802-4E0B-80AF-A40EAC2A1793}"= c:\program files\Skype\Phone\Skype.exe:Skype "{73EB7D17-755C-482B-87BF-CB63FB0F8CA8}"= c:\program files\Skype\Phone\Skype.exe:Skype "{9D31C61D-0189-4D91-96C7-058B3C048B7C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C91C7477-6D64-413D-AB06-D18DC249DDA7}"= c:\program files\Skype\Phone\Skype.exe:Skype "{6AAEBC38-EE72-4492-A4FE-419CC935B2AD}"= c:\program files\Skype\Phone\Skype.exe:Skype "{56C08EC9-FAE1-4D86-8944-61B7EFE6F2AB}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B9EAF079-7C5F-49FA-A5B6-F9D729C740F4}"= c:\program files\Skype\Phone\Skype.exe:Skype "{4CD39576-1D78-4C05-8349-117FF38E13A3}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8D87E91E-53A6-462F-A120-0F2CA3DE0F48}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8BE3E407-BC7D-4118-AEB4-389CD737ED43}"= c:\program files\Skype\Phone\Skype.exe:Skype "{242BC850-C2BC-4B32-A527-E858DEE154A2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{EFA71C70-4EBD-4AD8-AB77-0B5392EF5319}"= c:\program files\Skype\Phone\Skype.exe:Skype "{995C121E-AC23-473D-9ED9-1416DBA43C62}"= c:\program files\Skype\Phone\Skype.exe:Skype "{93D1A363-5D88-4AE8-AFC9-72914878EC79}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B2FB5F6C-C0F4-4386-8CD6-77B7D42671B4}"= c:\program files\Skype\Phone\Skype.exe:Skype "TCP Query User{73A2DA71-D001-4575-B48C-9CBE0DAFCFC7}d:\\games\\fifa 09\\fifa09.exe"= UDP:d:\games\fifa 09\fifa09.exe:FIFA09 "UDP Query User{2CD29A48-F7FD-42AD-852A-CF905CD2B56B}d:\\games\\fifa 09\\fifa09.exe"= TCP:d:\games\fifa 09\fifa09.exe:FIFA09 "TCP Query User{1CA93A6C-16B5-41C6-8402-5CB3AA28F2C4}d:\\games\\cssv34\\hl2.exe"= UDP:d:\games\cssv34\hl2.exe:hl2 "UDP Query User{CBF4E26B-CF80-4520-ACCA-91F3ADBF1CD5}d:\\games\\cssv34\\hl2.exe"= TCP:d:\games\cssv34\hl2.exe:hl2 "{CC066ACD-F6EE-4E78-958A-D70FB0CAF88B}"= c:\program files\Skype\Phone\Skype.exe:Skype "{74CC348D-05C6-446B-A359-A3B69B03EDAF}"= c:\program files\Skype\Phone\Skype.exe:Skype "{3779E2BC-32EC-479F-AAEE-11CEECB90774}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8876A13D-157B-4ED4-A417-E14FA5426830}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2236BF5A-40E1-40BC-8099-A1336C206A48}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C76A59C2-C1C2-4437-928D-83BD27EB146B}"= c:\program files\Skype\Phone\Skype.exe:Skype "{61ED61B8-4701-4E94-99AA-810D99291F84}"= c:\program files\Skype\Phone\Skype.exe:Skype "{78023C96-82BC-4CB6-8CC3-164D1340B1D9}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B2D9102F-7C07-4634-938C-503ABB5DC519}"= c:\program files\Skype\Phone\Skype.exe:Skype "{FF35E412-F497-42F0-B816-489B0B77B767}"= c:\program files\Skype\Phone\Skype.exe:Skype "{AD75424C-364C-46DB-8502-9A33F5FFDE93}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C2CD3250-EFA4-4B21-98FA-043B79D9BF00}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C2761E26-FDF6-4340-A0DE-4FC1015034CC}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C5B99A0B-E7DD-4E45-A4EE-96A51E34B7C9}"= c:\program files\Skype\Phone\Skype.exe:Skype "{EDC9D8E6-C765-44E0-A9FF-778D64C3B5CF}"= c:\program files\Skype\Phone\Skype.exe:Skype "{FD58BA65-628C-447F-8092-DB760ADD3F1D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8817CE02-9F56-498A-80FC-385573B3A329}"= c:\program files\Skype\Phone\Skype.exe:Skype "{407F7E91-66E7-484E-8623-AEBAA4D7FD4C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{67E168FF-BBC3-4020-905B-E975EA656342}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2203E252-6BBE-4378-9514-8583F64EE781}"= c:\program files\Skype\Phone\Skype.exe:Skype "{1EA3B454-86ED-493F-90DE-CFB3AFB04BB2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{7C3A2B2B-B4FD-4711-B40E-517DA8871F36}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5209DED9-A43F-4C67-B648-258C099A726D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{9734A418-439F-4DD1-A42C-10EB5C89E1BB}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8C6620E7-9424-4EC5-AA27-E55690A3E51D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8F935627-DB13-458E-98F7-6AFCDE4C37AE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{E2B063F3-6CE9-4CC1-A5A9-6581E1A6B18B}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5E010C30-2540-4C08-A4EA-7B6F454C2E2C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{F409D612-5081-4B9F-8B84-FF4921BB36DE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{86439D28-3B97-48D7-91ED-FCEA19DB2DF3}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2A80DC9E-A33D-479D-BE47-207C99C49AD4}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009 "{A6C9C6A8-1D21-4B0C-BCD5-38C2128FF923}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009 "TCP Query User{63B92970-6A9E-440F-A480-0DA012E23F18}c:\\users\\rzarector\\documents\\downloads\\uniblue_registry_booster_2_2.exe"= UDP:c:\users\rzarector\documents\downloads\uniblue_registry_booster_2_2.exe:uniblue_registry_booster_2_2.exe "UDP Query User{DABFC3C3-A2BE-4273-A9AC-0F81ED5FF075}c:\\users\\rzarector\\documents\\downloads\\uniblue_registry_booster_2_2.exe"= TCP:c:\users\rzarector\documents\downloads\uniblue_registry_booster_2_2.exe:uniblue_registry_booster_2_2.exe "{E8897CAA-4EE8-42B8-AB0C-9F3E6F517DCB}"= c:\program files\Skype\Phone\Skype.exe:Skype "{BBAF4650-69FB-4186-9571-0CCD43269ECD}"= c:\program files\Skype\Phone\Skype.exe:Skype "{51DC1897-DA0D-479D-9DA1-A606E495182A}"= UDP:c:\windows\System32\winlogon.exe:ENABLE "{8006E06E-F563-4A77-B160-CBBF10609AE4}"= TCP:c:\windows\System32\winlogon.exe:ENABLE "{694F7B23-841C-4A04-B71A-4D2700A76A61}"= UDP:c:\windows\System32\userinit.exe:ENABLE "{9AAA7E61-C0C6-428C-A249-A7A27A51A3F8}"= TCP:c:\windows\System32\userinit.exe:ENABLE "{B9194E98-92A0-48AF-9830-4B1FB871D19E}"= UDP:c:\windows\System32\dwm.exe:ENABLE "{502BAA41-3C84-474D-91E1-54973802B7E5}"= TCP:c:\windows\System32\dwm.exe:ENABLE R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\System32\drivers\AlfaFF.sys [6/25/2008 6:44 AM 43184] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2/26/2008 4:57 AM 21752] R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [3/21/2008 9:57 AM 24576] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2/25/2008 12:02 PM 49152] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2/26/2008 4:53 AM 131072] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [10/18/2008 6:51 AM 809296] R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [2/15/2008 4:09 PM 595248] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/6/2009 9:01 PM 101936] R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [3/21/2008 9:56 AM 54784] R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [3/21/2008 9:55 AM 80912] R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [12/16/2008 7:05 AM 48128] R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [2/15/2008 4:09 PM 40752] S2 gupdate1c98a92b17a2c9f;Google Update Service (gupdate1c98a92b17a2c9f);c:\program files\Google\Update\GoogleUpdate.exe [2/9/2009 11:44 AM 133104] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [11/28/2006 1:34 PM 122008] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ . Contents of the 'Scheduled Tasks' folder 2009-06-24 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-30 20:43] 2009-06-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 08:44] 2009-05-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-61857225-2502580657-359961809-1000.job - c:\users\Rzarector\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-22 15:55] . . ------- Supplementary Scan ------- . mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-24 15:15 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet007\Services\N] "ImagePath"="\??\c:\program files\NewTech Infosystems\NTI Media Maker 8\NTI Ripper Suite\" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(2240) c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll c:\windows\system32\btmmhook.dll c:\windows\system32\btncopy.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe c:\windows\System32\agrsmsvc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\program files\Symantec AntiVirus\DefWatch.exe c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\acer\Mobility Center\MobilityService.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\windows\System32\WUDFHost.exe c:\windows\System32\wbem\unsecapp.exe c:\windows\System32\rundll32.exe c:\windows\System32\wbem\WMIADAP.exe . ************************************************************************** . Completion time: 2009-06-24 15:20 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-24 12:20 ComboFix2.txt 2009-06-24 11:03 Pre-Run: 74,956,054,528 bytes free Post-Run: 74,853,261,312 bytes free 340 --- E O F --- 2009-06-23 22:30
  4. Поправиx нещата в HijackThis без O15 защото Не се появявaт давa ги Кaтo "Trusted Zones" премахнаx намерените зарази с Malwarebytes ComboFix 09-06-23.01 - SYSTEM 06/24/2009 13:51.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3070.1931 [GMT 3:00] Running from: c:\windows\system32\config\systemprofile\Desktop\Combo-Fix.exe AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-61857225-2502580657-359961809-1001 C:\-1642110727 c:\$recycle.bin\S-1-5-21-61857225-2502580657-359961809-1001\desktop.ini c:\windows\system32\cds.txt c:\windows\system32\dz1.txt c:\windows\system32\p1.txt c:\windows\system32\r24.txt c:\windows\system32\sdd.txt C:\wutvvdr.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_TDSSSERV.SYS -------\Service_ovfsthxxltisyqc -------\Service_TDSSserv.sys ((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 ))))))))))))))))))))))))))))))) . 2009-06-24 10:55 . 2009-06-24 10:58 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2009-06-24 10:55 . 2009-06-24 10:55 -------- d-----w- c:\users\Rzarector\AppData\Local\temp 2009-06-24 08:09 . 2009-06-24 08:09 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes 2009-06-24 08:08 . 2009-06-17 08:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-24 08:08 . 2009-06-24 08:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-24 08:08 . 2009-06-24 08:08 -------- d-----w- c:\programdata\Malwarebytes 2009-06-24 08:08 . 2009-06-17 08:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-23 16:26 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll 2009-06-23 16:26 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll 2009-06-23 16:02 . 2009-06-16 09:40 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVEX32A.DLL 2009-06-23 16:02 . 2009-06-16 09:40 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVENG.SYS 2009-06-23 16:02 . 2009-06-16 09:40 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVEX15.SYS 2009-06-23 16:02 . 2009-06-16 09:40 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\EECTRL.SYS 2009-06-23 16:02 . 2009-06-16 09:40 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\ECMSVR32.DLL 2009-06-23 16:02 . 2009-06-16 09:40 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\CCERASER.DLL 2009-06-23 16:02 . 2009-06-16 09:40 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\NAVENG32.DLL 2009-06-23 16:02 . 2009-06-16 09:40 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090623.002\ERASER.SYS . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-24 10:58 . 2008-06-25 04:04 168787 ----a-w- c:\programdata\nvModes.dat 2009-06-24 10:56 . 2008-06-25 04:18 12 ----a-w- c:\windows\bthservsdp.dat 2009-06-24 07:47 . 2008-06-25 03:41 -------- d-----w- c:\programdata\NVIDIA 2009-06-23 22:29 . 2008-03-21 07:18 -------- d-----w- c:\programdata\Microsoft Help 2009-06-23 22:02 . 2008-06-25 03:35 103584 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT 2009-06-23 21:48 . 2008-06-25 04:01 -------- d-----w- c:\program files\Google 2009-06-23 21:34 . 2008-06-25 22:15 -------- d-----w- c:\programdata\Apple Computer 2009-06-23 21:31 . 2008-03-21 06:52 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-23 20:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-06-23 17:34 . 2008-03-21 07:20 -------- d-----w- c:\program files\Microsoft Works 2009-06-23 16:00 . 2009-01-30 10:25 -------- d-----w- c:\programdata\Google Updater 2009-06-23 15:40 . 2008-06-25 15:20 1356 ----a-w- c:\users\Rzarector\AppData\Local\d3d9caps.dat 2009-06-16 09:40 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys 2009-06-16 09:40 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys 2009-06-16 09:40 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys 2009-06-16 09:40 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll 2009-06-16 09:40 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll 2009-06-16 09:40 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll 2009-06-16 09:40 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys 2009-06-16 09:40 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll 2009-05-28 00:32 . 2008-10-18 03:51 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2009-05-28 00:32 . 2008-10-18 03:51 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-05-28 00:32 . 2008-10-16 21:11 -------- d-----r- c:\program files\Skype 2009-05-28 00:32 . 2009-02-04 15:42 -------- d-----w- c:\program files\Common Files\Skype 2009-05-28 00:32 . 2008-10-18 04:06 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-05-28 00:32 . 2008-06-25 22:34 -------- d-----w- c:\program files\Bit Che 2009-05-25 14:44 . 2009-02-04 15:42 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Skype 2009-05-25 13:04 . 2008-06-25 04:09 -------- d-----w- c:\users\Rzarector\AppData\Roaming\skypePM 2009-05-21 09:30 . 2008-06-25 03:40 103584 ----a-w- c:\users\Rzarector\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-19 22:31 . 2008-03-21 06:57 -------- d-----w- c:\program files\Acer 2009-05-13 16:55 . 2009-05-08 16:29 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Skype 2009-05-13 16:54 . 2009-05-08 16:30 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\skypePM 2009-05-08 07:05 . 2009-05-08 07:05 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Uniblue 2009-05-08 06:45 . 2009-05-08 06:45 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Intel 2009-05-08 06:45 . 2009-05-08 06:45 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Intel 2009-05-08 06:45 . 2009-05-08 06:45 -------- d-----w- c:\programdata\Roaming 2009-05-08 06:44 . 2009-05-08 06:44 -------- d-----w- c:\program files\Cisco 2009-05-08 06:44 . 2009-05-08 06:44 -------- d-----w- c:\programdata\Intel 2009-05-08 06:44 . 2008-03-21 06:46 -------- d-----w- c:\program files\Intel 2009-05-07 09:09 . 2008-08-13 04:51 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Apple Computer 2009-05-07 06:58 . 2009-05-07 06:58 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-05-07 06:58 . 2009-05-07 06:58 -------- d-----w- c:\program files\iTunes(246) 2009-05-07 06:58 . 2009-05-07 06:58 -------- d-----w- c:\program files\iPod(245) 2009-05-07 06:58 . 2008-08-13 04:48 -------- d-----w- c:\program files\Common Files\Apple 2009-05-04 16:25 . 2009-05-04 16:25 -------- d-----w- c:\programdata\PC Drivers HeadQuarters 2009-04-29 17:10 . 2009-04-29 17:10 -------- d-----w- c:\users\Rzarector\AppData\Roaming\Uniblue 2009-04-29 17:02 . 2009-04-29 17:02 -------- dc-h--w- c:\programdata\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1} 2009-04-29 12:20 . 2008-03-21 06:52 319456 ----a-w- c:\windows\DIFxAPI.dll 2009-04-29 00:01 . 2008-11-22 18:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2009-04-26 08:55 . 2009-04-26 08:55 -------- d-----w- c:\programdata\WindowsSearch 2009-04-24 16:05 . 2009-06-23 16:14 827904 ----a-w- c:\windows\system32\wininet.dll 2009-04-24 16:02 . 2009-06-23 16:14 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-24 13:44 . 2009-06-23 16:14 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-04-23 12:43 . 2009-06-23 16:14 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:42 . 2009-06-23 16:14 636928 ----a-w- c:\windows\system32\localspl.dll 2009-04-21 11:55 . 2009-06-23 16:14 2033152 ----a-w- c:\windows\system32\win32k.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-05 06:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-07 13527584] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-07 92704] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-25 723760] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000] 2008-06-25 03:44 3024384 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{FEE6146F-FF33-41E5-88D6-A550CFB90D21}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{6CEE7A7F-DD8F-4A27-948B-7CB5F6CBC7E5}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe "{B0D6A975-C143-4552-9D1C-051306D65D43}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe "{89A86A7E-74AA-4474-BF25-CE5206CF42E5}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe "{BC24146F-82BD-4C12-BDE9-1B1281CA7210}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe "{E09502F9-8921-49AF-A000-02F12646F216}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe "{F354F89D-2CF0-4A6D-90B4-508E9B59C56F}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe "{7E6114F6-E392-4CC9-BF23-539452182A08}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM "{04DA423E-E404-4176-9943-CAA27E42BD4F}"= UDP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System "{80D045BB-9C5F-463D-B9B9-FFCE93CCD884}"= TCP:c:\windows\System32\lxddcoms.exe:Lexmark Communications System "{0D9CF7C0-9347-42C4-8A78-3E6CA3DA7102}"= UDP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor "{8133EB54-C725-4AB9-8DCE-84ED9546CD99}"= TCP:c:\program files\Lexmark 2500 Series\lxddamon.exe:Lexmark Device Monitor "{E18C3035-B729-4315-A0B4-FEA2181834B1}"= UDP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio "{FD9020E1-9CB7-42A7-A282-B9D9CB45805F}"= TCP:c:\program files\Lexmark 2500 Series\App4R.exe:Lexmark Imaging Studio "TCP Query User{18F781D3-234A-4418-A0E0-866DD478FF48}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord "UDP Query User{2DE7D455-8516-4884-8CDA-0CB0E7118BAE}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord "TCP Query User{6AB9339A-BA46-40DE-9F57-6673DC3804F3}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts "UDP Query User{EF750EA3-968B-4CC9-8F4A-1CD407AE4819}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts "{198A73FB-4624-4CC5-A6F2-0F59EB66607E}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus "{9B5BE1DF-CB88-4467-B248-DBD16C339FD5}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus "{055FF55F-7914-4B8E-8BC0-DC8BECE9917A}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email "{D9D1127A-2382-44FF-8764-BAC7D58D0467}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email "TCP Query User{DC4B9D15-8176-4CD1-8D6C-E21266D1B447}c:\\users\\rzarector\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\rzarector\appdata\local\google\chrome\application\chrome.exe:chrome.exe "UDP Query User{30A6BFFD-268F-441E-B4F2-C9757B2EF492}c:\\users\\rzarector\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\rzarector\appdata\local\google\chrome\application\chrome.exe:chrome.exe "{4E5151E4-86F5-4202-B09E-AEF21A742291}"= UDP:d:\games\New Folder (3)\PES2008.exe:Pro Evolution Soccer 2008 "{6B06C9A5-4377-49AD-894A-82657C076D25}"= TCP:d:\games\New Folder (3)\PES2008.exe:Pro Evolution Soccer 2008 "{C1CD543C-A2B6-4AC9-B5A5-3D8088BC3390}"= UDP:d:\games\pes install\CRACK\PES2008.exe:Pro Evolution Soccer 2008 "{40EFD27A-DF0F-441E-A978-C9F090F0C6F1}"= TCP:d:\games\pes install\CRACK\PES2008.exe:Pro Evolution Soccer 2008 "{1FC01AB3-AB21-44A5-9D19-5498F61CC576}"= UDP:d:\games\Pro E\PES2008.exe:Pro Evolution Soccer 2008 "{9368DE89-5567-45BD-9EE3-F9E5B450C41E}"= TCP:d:\games\Pro E\PES2008.exe:Pro Evolution Soccer 2008 "{6945D53D-3395-4CF5-B298-55434C2543C9}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{3AD1DB3C-8F12-4405-B802-DF46AF577DF7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{3E4FE5B5-0E28-4832-A851-173D3C4D9BFA}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{A22AAF35-9DC7-4C0B-913F-626104690C21}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{324D7471-DA81-444F-A457-B1623BFEE1CF}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{110F32DC-4E79-4A9F-BEA3-2E0BE6B60772}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe: "{03BF7FB8-0CA2-4A09-92E5-DF6237B588D2}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddpswx.exe: "{3E88AF5C-6892-428B-A4DB-3E9230C6BA25}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddjswx.exe: "{D8537AA9-0ACD-461C-8654-46BBB9B4597E}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddjswx.exe: "{B9764C9B-B053-49C7-B964-2DF7CD039810}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe: "{91D48567-3559-434B-985C-B4F1DE39B026}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxddtime.exe: "{062D784B-AF60-4702-9885-92AEA8A0ACFF}"= UDP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{F58E9B1E-8790-4131-B434-FBF740F521E9}"= TCP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{31C0EF90-2351-42D0-8ED8-57F24A11F9B2}"= UDP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{785E9C9D-39CB-4E68-AB78-AD0EBAEE3CA7}"= TCP:c:\program files\Lexmark 2500 Series\lxddmon.exe: "{AF9617E2-5129-4255-AF15-0B71D6B0BA7A}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008 "{C24B813E-A9D0-4CFE-8963-69918A202C6C}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008 "{AE6DC9B4-C9D6-4426-A6F5-AC12BD38210E}"= UDP:c:\users\Rzarector\Desktop\RS.com.Pro.Evolution.Soccer.2009.BURGUM.PATCH.v0.40.Keygen.exe:enable "{793D0168-5B7D-4A9B-B82D-9566B90D04D5}"= TCP:c:\users\Rzarector\Desktop\RS.com.Pro.Evolution.Soccer.2009.BURGUM.PATCH.v0.40.Keygen.exe:enable "{84747405-4474-4A5A-97DE-537594DB84FB}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "{EAC6CF08-9E93-4FA3-973C-4AE3F8C17133}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "{5F231265-9594-4DE1-B174-D0FC0C11DB2F}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "{635E3031-2F1A-49CF-B590-82CEAE60901A}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009 "TCP Query User{F9D1743A-2862-41FB-A91E-74159E636B86}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "UDP Query User{3351853F-F4CD-4578-A1A6-8EFA91128A0B}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "{FA19F0A4-D48A-455E-A114-F00A3EFA2AEE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8B4BE52C-2FD6-4790-8605-EA75B878F904}"= c:\program files\Skype\Phone\Skype.exe:Skype "{621256A2-0C20-4A2F-8012-D88F65E84A48}"= c:\program files\Skype\Phone\Skype.exe:Skype "{9E733A64-C6AA-43FE-B5AF-C2850F4C1A6E}"= c:\program files\Skype\Phone\Skype.exe:Skype "{A2575BC4-8FAD-41C7-A446-838395BFEC5F}"= c:\program files\Skype\Phone\Skype.exe:Skype "{944968CF-FA36-4144-8850-5921393A5BA2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{D04FB8E5-3A7D-4B02-8B81-BABF472A3C07}"= c:\program files\Skype\Phone\Skype.exe:Skype "{25511F51-EF4A-4753-A71B-F3C71E2EB99E}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C9655B8E-C86C-4C43-B64C-D0DF33634D71}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C848396C-227A-47E8-A79F-1049760F815D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{DE40EBFE-D6A8-4668-B47E-E1C67CA5B353}"= c:\program files\Skype\Phone\Skype.exe:Skype "{3EF074C8-3B71-44E0-AEDE-9CC3BDC8F673}"= c:\program files\Skype\Phone\Skype.exe:Skype "{DC956A3B-D46D-4BF6-BC3A-A0E82C09EF86}"= c:\program files\Skype\Phone\Skype.exe:Skype "{EEDAEE41-46C4-484B-9915-3853E41712A7}"= c:\program files\Skype\Phone\Skype.exe:Skype "{6A47343C-335C-4D30-B021-AF6050592C4C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C9C09738-9DF7-40BF-A4FE-1DF92698D9D1}"= c:\program files\Skype\Phone\Skype.exe:Skype "{93B9807F-4802-4E0B-80AF-A40EAC2A1793}"= c:\program files\Skype\Phone\Skype.exe:Skype "{73EB7D17-755C-482B-87BF-CB63FB0F8CA8}"= c:\program files\Skype\Phone\Skype.exe:Skype "{9D31C61D-0189-4D91-96C7-058B3C048B7C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C91C7477-6D64-413D-AB06-D18DC249DDA7}"= c:\program files\Skype\Phone\Skype.exe:Skype "{6AAEBC38-EE72-4492-A4FE-419CC935B2AD}"= c:\program files\Skype\Phone\Skype.exe:Skype "{56C08EC9-FAE1-4D86-8944-61B7EFE6F2AB}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B9EAF079-7C5F-49FA-A5B6-F9D729C740F4}"= c:\program files\Skype\Phone\Skype.exe:Skype "{4CD39576-1D78-4C05-8349-117FF38E13A3}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8D87E91E-53A6-462F-A120-0F2CA3DE0F48}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8BE3E407-BC7D-4118-AEB4-389CD737ED43}"= c:\program files\Skype\Phone\Skype.exe:Skype "{242BC850-C2BC-4B32-A527-E858DEE154A2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{EFA71C70-4EBD-4AD8-AB77-0B5392EF5319}"= c:\program files\Skype\Phone\Skype.exe:Skype "{995C121E-AC23-473D-9ED9-1416DBA43C62}"= c:\program files\Skype\Phone\Skype.exe:Skype "{93D1A363-5D88-4AE8-AFC9-72914878EC79}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B2FB5F6C-C0F4-4386-8CD6-77B7D42671B4}"= c:\program files\Skype\Phone\Skype.exe:Skype "TCP Query User{73A2DA71-D001-4575-B48C-9CBE0DAFCFC7}d:\\games\\fifa 09\\fifa09.exe"= UDP:d:\games\fifa 09\fifa09.exe:FIFA09 "UDP Query User{2CD29A48-F7FD-42AD-852A-CF905CD2B56B}d:\\games\\fifa 09\\fifa09.exe"= TCP:d:\games\fifa 09\fifa09.exe:FIFA09 "TCP Query User{1CA93A6C-16B5-41C6-8402-5CB3AA28F2C4}d:\\games\\cssv34\\hl2.exe"= UDP:d:\games\cssv34\hl2.exe:hl2 "UDP Query User{CBF4E26B-CF80-4520-ACCA-91F3ADBF1CD5}d:\\games\\cssv34\\hl2.exe"= TCP:d:\games\cssv34\hl2.exe:hl2 "{CC066ACD-F6EE-4E78-958A-D70FB0CAF88B}"= c:\program files\Skype\Phone\Skype.exe:Skype "{74CC348D-05C6-446B-A359-A3B69B03EDAF}"= c:\program files\Skype\Phone\Skype.exe:Skype "{3779E2BC-32EC-479F-AAEE-11CEECB90774}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8876A13D-157B-4ED4-A417-E14FA5426830}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2236BF5A-40E1-40BC-8099-A1336C206A48}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C76A59C2-C1C2-4437-928D-83BD27EB146B}"= c:\program files\Skype\Phone\Skype.exe:Skype "{61ED61B8-4701-4E94-99AA-810D99291F84}"= c:\program files\Skype\Phone\Skype.exe:Skype "{78023C96-82BC-4CB6-8CC3-164D1340B1D9}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B2D9102F-7C07-4634-938C-503ABB5DC519}"= c:\program files\Skype\Phone\Skype.exe:Skype "{FF35E412-F497-42F0-B816-489B0B77B767}"= c:\program files\Skype\Phone\Skype.exe:Skype "{AD75424C-364C-46DB-8502-9A33F5FFDE93}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C2CD3250-EFA4-4B21-98FA-043B79D9BF00}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C2761E26-FDF6-4340-A0DE-4FC1015034CC}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C5B99A0B-E7DD-4E45-A4EE-96A51E34B7C9}"= c:\program files\Skype\Phone\Skype.exe:Skype "{EDC9D8E6-C765-44E0-A9FF-778D64C3B5CF}"= c:\program files\Skype\Phone\Skype.exe:Skype "{FD58BA65-628C-447F-8092-DB760ADD3F1D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8817CE02-9F56-498A-80FC-385573B3A329}"= c:\program files\Skype\Phone\Skype.exe:Skype "{407F7E91-66E7-484E-8623-AEBAA4D7FD4C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{67E168FF-BBC3-4020-905B-E975EA656342}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2203E252-6BBE-4378-9514-8583F64EE781}"= c:\program files\Skype\Phone\Skype.exe:Skype "{1EA3B454-86ED-493F-90DE-CFB3AFB04BB2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{7C3A2B2B-B4FD-4711-B40E-517DA8871F36}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5209DED9-A43F-4C67-B648-258C099A726D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{9734A418-439F-4DD1-A42C-10EB5C89E1BB}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8C6620E7-9424-4EC5-AA27-E55690A3E51D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{8F935627-DB13-458E-98F7-6AFCDE4C37AE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{E2B063F3-6CE9-4CC1-A5A9-6581E1A6B18B}"= c:\program files\Skype\Phone\Skype.exe:Skype "{5E010C30-2540-4C08-A4EA-7B6F454C2E2C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{F409D612-5081-4B9F-8B84-FF4921BB36DE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{86439D28-3B97-48D7-91ED-FCEA19DB2DF3}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2A80DC9E-A33D-479D-BE47-207C99C49AD4}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009 "{A6C9C6A8-1D21-4B0C-BCD5-38C2128FF923}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009 "TCP Query User{63B92970-6A9E-440F-A480-0DA012E23F18}c:\\users\\rzarector\\documents\\downloads\\uniblue_registry_booster_2_2.exe"= UDP:c:\users\rzarector\documents\downloads\uniblue_registry_booster_2_2.exe:uniblue_registry_booster_2_2.exe "UDP Query User{DABFC3C3-A2BE-4273-A9AC-0F81ED5FF075}c:\\users\\rzarector\\documents\\downloads\\uniblue_registry_booster_2_2.exe"= TCP:c:\users\rzarector\documents\downloads\uniblue_registry_booster_2_2.exe:uniblue_registry_booster_2_2.exe "TCP Query User{9A956294-AD3E-479C-B53E-20E7F3413010}c:\\wutvvdr.exe"= UDP:C:\wutvvdr.exe:wutvvdr "UDP Query User{96FB1D26-CE29-47EB-8A19-B36AFFE2F73B}c:\\wutvvdr.exe"= TCP:C:\wutvvdr.exe:wutvvdr "{E8897CAA-4EE8-42B8-AB0C-9F3E6F517DCB}"= c:\program files\Skype\Phone\Skype.exe:Skype "{BBAF4650-69FB-4186-9571-0CCD43269ECD}"= c:\program files\Skype\Phone\Skype.exe:Skype "{51DC1897-DA0D-479D-9DA1-A606E495182A}"= UDP:c:\windows\System32\winlogon.exe:ENABLE "{8006E06E-F563-4A77-B160-CBBF10609AE4}"= TCP:c:\windows\System32\winlogon.exe:ENABLE "{694F7B23-841C-4A04-B71A-4D2700A76A61}"= UDP:c:\windows\System32\userinit.exe:ENABLE "{9AAA7E61-C0C6-428C-A249-A7A27A51A3F8}"= TCP:c:\windows\System32\userinit.exe:ENABLE "{B9194E98-92A0-48AF-9830-4B1FB871D19E}"= UDP:c:\windows\System32\dwm.exe:ENABLE "{502BAA41-3C84-474D-91E1-54973802B7E5}"= TCP:c:\windows\System32\dwm.exe:ENABLE R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\System32\drivers\AlfaFF.sys [6/25/2008 6:44 AM 43184] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2/26/2008 4:57 AM 21752] R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [3/21/2008 9:57 AM 24576] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2/25/2008 12:02 PM 49152] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2/26/2008 4:53 AM 131072] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [10/18/2008 6:51 AM 809296] R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [2/15/2008 4:09 PM 595248] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/6/2009 9:01 PM 101936] R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [3/21/2008 9:56 AM 54784] R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [3/21/2008 9:55 AM 80912] R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [12/16/2008 7:05 AM 48128] R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [2/15/2008 4:09 PM 40752] S2 gupdate1c98a92b17a2c9f;Google Update Service (gupdate1c98a92b17a2c9f);c:\program files\Google\Update\GoogleUpdate.exe [2/9/2009 11:44 AM 133104] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [11/28/2006 1:34 PM 122008] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs gkdpdnwq ikqetnpu . Contents of the 'Scheduled Tasks' folder 2009-06-24 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-30 20:43] 2009-06-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 08:44] 2009-05-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-61857225-2502580657-359961809-1000.job - c:\users\Rzarector\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-22 15:55] . . ------- Supplementary Scan ------- . mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-24 13:58 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet007\Services\N] "ImagePath"="\??\c:\program files\NewTech Infosystems\NTI Media Maker 8\NTI Ripper Suite\" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\system\ControlSet007\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet007\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet007\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet007\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet007\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(2168) c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll c:\windows\system32\btmmhook.dll c:\windows\system32\btncopy.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\nvvsvc.exe c:\windows\System32\audiodg.exe c:\windows\System32\rundll32.exe c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe c:\windows\System32\agrsmsvc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\program files\Symantec AntiVirus\DefWatch.exe c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\acer\Mobility Center\MobilityService.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\windows\System32\WUDFHost.exe c:\windows\System32\wbem\unsecapp.exe c:\windows\System32\rundll32.exe c:\windows\System32\wbem\WMIADAP.exe . ************************************************************************** . Completion time: 2009-06-24 14:02 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-24 11:02 Pre-Run: 75,452,600,320 bytes free Post-Run: 74,964,164,608 bytes free 370 --- E O F --- 2009-06-23 22:30
  5. Malwarebytes' Anti-Malware 1.38 Database version: 2328 Windows 6.0.6001 Service Pack 1 6/24/2009 11:57:52 AM mbam-log-2009-06-24 (11-57-45).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 207519 Time elapsed: 47 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 26 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 14 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\Windows\System32\lubgusr.dll (Trojan.Vundo.H) -> No action taken. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24245b03-7d1e-4fc4-8ef3-d0d2a972b945} (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kbhmrzps (Trojan.Vundo.H) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{24245b03-7d1e-4fc4-8ef3-d0d2a972b945} (Trojan.Vundo.H) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46b35542-a3cf-4cca-9c0b-259db2fff078} (Trojan.Banker) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gkdpdnwq (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\gkdpdnwq (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gkdpdnwq (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ikqetnpu (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ikqetnpu (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ikqetnpu (Trojan.Vundo.H) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{24245b03-7d1e-4fc4-8ef3-d0d2a972b945} (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ksi32sk (Rootkit.Agent) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\amd64si (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\securentm (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi32 (Rootkit.Spamtool) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Systemntmi (Rootkit.Spamtool) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ws2_32sik (Rootkit.Agent) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\netsik (Rootkit.Agent) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Windows\System32\lubgusr.dll (Trojan.Vundo.H) -> No action taken. c:\begaxy.exe (Trojan.Downloader) -> No action taken. c:\rvlksh.exe (Trojan.Downloader) -> No action taken. c:\wmjtkohy.exe (Trojan.Downloader) -> No action taken. c:\program files\Skype\Phone\multi_skype_eng.exe (Trojan.Downloader) -> No action taken. c:\Windows\System32\config\systemprofile\Desktop\highjackthis\backups\backup-20090624-110544-282.dll (Trojan.Vundo.H) -> No action taken. c:\Windows\System32\config\systemprofile\Desktop\highjackthis\backups\backup-20090624-110544-887.dll (Trojan.Vundo.H) -> No action taken. C:\Windows\System32\MSVolume.dll (Fake.Dropped.Malware) -> No action taken. c:\Windows\System32\ovfsthxwsqospmb.dll (Trojan.Agent) -> No action taken. c:\Windows\System32\ovfsthxuxliprip.dat (Trojan.Agent) -> No action taken. c:\Windows\System32\ovfsthxysxffint.dat (Trojan.Agent) -> No action taken. C:\Windows\System32\surrd.sys (Rootkit.Agent) -> No action taken. C:\lsass.exe (Trojan.Agent) -> No action taken. c:\Windows\System32\TDSStawq.dll (Rootkit.Agent) -> No action taken.
  6. 2.1 Писането на български език с кирилица е задължително. Теми и съобщения, написани на латиница или само с главни букви, се изтриват без предупреждение. iovi

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.