-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Компютърът ми вече се пуска нормално и скайпа не забива. Благодаря Ви!!!
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
ComboFix 09-11-05.05 - DUDU 11.2009 г. 17:32.4.2 - FAT32x86 Running from: c:\documents and settings\DUDU\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\DUDU\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\DUDU\DoctorWeb c:\documents and settings\DUDU\DoctorWeb\CureIt.log C:\FOUND.000 c:\found.000\FILE0000.CHK c:\found.000\FILE0001.CHK c:\found.000\FILE0002.CHK c:\found.000\FILE0003.CHK c:\found.000\FILE0004.CHK c:\found.000\FILE0005.CHK c:\found.000\FILE0006.CHK c:\found.000\FILE0007.CHK c:\found.000\FILE0008.CHK c:\found.000\FILE0009.CHK c:\found.000\FILE0010.CHK c:\found.000\FILE0011.CHK C:\FOUND.001 c:\found.001\FILE0000.CHK c:\found.001\FILE0001.CHK c:\found.001\FILE0002.CHK c:\found.001\FILE0003.CHK c:\found.001\FILE0004.CHK c:\found.001\FILE0005.CHK c:\found.001\FILE0006.CHK c:\found.001\FILE0007.CHK c:\found.001\FILE0008.CHK c:\found.001\FILE0009.CHK c:\found.001\FILE0010.CHK c:\found.001\FILE0011.CHK c:\found.001\FILE0012.CHK c:\found.001\FILE0013.CHK c:\found.001\FILE0014.CHK c:\found.001\FILE0015.CHK c:\found.001\FILE0016.CHK c:\found.001\FILE0017.CHK c:\found.001\FILE0018.CHK c:\found.001\FILE0019.CHK c:\found.001\FILE0020.CHK c:\found.001\FILE0021.CHK c:\found.001\FILE0022.CHK c:\found.001\FILE0023.CHK c:\found.001\FILE0024.CHK c:\found.001\FILE0025.CHK c:\found.001\FILE0026.CHK c:\found.001\FILE0027.CHK c:\found.001\FILE0028.CHK c:\found.001\FILE0029.CHK c:\found.001\FILE0030.CHK c:\found.001\FILE0031.CHK c:\found.001\FILE0032.CHK c:\found.001\FILE0033.CHK c:\found.001\FILE0034.CHK c:\found.001\FILE0035.CHK c:\found.001\FILE0036.CHK c:\found.001\FILE0037.CHK c:\found.001\FILE0038.CHK c:\found.001\FILE0039.CHK c:\found.001\FILE0040.CHK c:\found.001\FILE0041.CHK c:\found.001\FILE0042.CHK C:\FOUND.002 c:\found.002\FILE0000.CHK C:\FOUND.003 c:\found.003\FILE0000.CHK C:\FOUND.004 c:\found.004\FILE0000.CHK c:\found.004\FILE0001.CHK c:\found.004\FILE0002.CHK c:\found.004\FILE0003.CHK c:\found.004\FILE0004.CHK c:\found.004\FILE0005.CHK c:\found.004\FILE0006.CHK c:\found.004\FILE0007.CHK c:\found.004\FILE0008.CHK c:\found.004\FILE0009.CHK c:\found.004\FILE0010.CHK c:\found.004\FILE0011.CHK c:\found.004\FILE0012.CHK c:\found.004\FILE0013.CHK c:\found.004\FILE0014.CHK c:\found.004\FILE0015.CHK c:\found.004\FILE0016.CHK c:\found.004\FILE0017.CHK c:\found.004\FILE0018.CHK c:\found.004\FILE0019.CHK c:\found.004\FILE0020.CHK c:\found.004\FILE0021.CHK c:\found.004\FILE0022.CHK c:\found.004\FILE0023.CHK c:\found.004\FILE0024.CHK c:\found.004\FILE0025.CHK c:\found.004\FILE0026.CHK c:\found.004\FILE0027.CHK c:\found.004\FILE0028.CHK c:\found.004\FILE0029.CHK c:\found.004\FILE0030.CHK c:\found.004\FILE0031.CHK c:\found.004\FILE0032.CHK c:\found.004\FILE0033.CHK c:\found.004\FILE0034.CHK c:\found.004\FILE0035.CHK c:\found.004\FILE0036.CHK c:\found.004\FILE0037.CHK c:\found.004\FILE0038.CHK c:\found.004\FILE0039.CHK C:\FOUND.005 c:\found.005\FILE0000.CHK c:\found.005\FILE0001.CHK c:\found.005\FILE0002.CHK c:\found.005\FILE0003.CHK c:\found.005\FILE0004.CHK C:\FOUND.006 c:\found.006\FILE0000.CHK C:\FOUND.007 c:\found.007\FILE0000.CHK c:\found.007\FILE0001.CHK c:\found.007\FILE0002.CHK C:\FOUND.008 c:\found.008\FILE0000.CHK c:\found.008\FILE0001.CHK c:\found.008\FILE0002.CHK c:\found.008\FILE0003.CHK c:\found.008\FILE0004.CHK C:\FOUND.009 c:\found.009\FILE0000.CHK c:\found.009\FILE0001.CHK c:\found.009\FILE0002.CHK c:\found.009\FILE0003.CHK c:\found.009\FILE0004.CHK c:\found.009\FILE0005.CHK c:\found.009\FILE0006.CHK c:\found.009\FILE0007.CHK c:\found.009\FILE0008.CHK c:\found.009\FILE0009.CHK c:\found.009\FILE0010.CHK c:\found.009\FILE0011.CHK c:\found.009\FILE0012.CHK c:\found.009\FILE0013.CHK c:\found.009\FILE0014.CHK c:\found.009\FILE0015.CHK c:\found.009\FILE0016.CHK . ((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 ))))))))))))))))))))))))))))))) . 2009-11-06 14:31 . 2004-03-02 15:37 5504 ----a-w- c:\windows\system32\drivers\imagedrv.sys 2009-10-26 09:59 . 2009-10-26 09:59 -------- d-----w- c:\program files\Foxit Software 2009-10-25 21:00 . 2009-10-25 21:00 -------- d-----w- c:\windows\system32\CatRoot_bak 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----r- c:\program files\Skype 2009-10-22 21:39 . 2009-10-22 21:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 16:18 . 2009-10-22 16:18 44808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll 2009-10-22 16:18 . 2009-10-22 16:18 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys 2009-10-22 16:18 . 2009-10-22 16:18 208616 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe 2009-10-22 16:18 . 2009-10-22 16:18 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys 2009-10-22 16:03 . 2009-10-22 16:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 16:03 . 2009-10-22 16:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 15:54 . 2009-11-06 15:36 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 15:54 . 2009-11-06 15:36 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-21 23:32 . 2009-10-21 23:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-20 16:52 . 2009-10-20 16:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 16:40 . 2009-10-20 16:40 -------- d-----w- c:\windows\Sun 2009-10-20 16:39 . 2009-10-20 16:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 16:39 . 2009-10-20 16:39 -------- d-----w- c:\program files\Java 2009-10-20 16:39 . 2009-10-20 16:39 152576 ----a-w- c:\documents and settings\DUDU\Application Data\Sun\Java\jre1.6.0_16\lzma.dll 2009-10-20 15:57 . 2009-10-20 15:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 15:57 . 2009-10-20 15:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 15:44 . 2009-10-09 15:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 15:44 . 2009-10-09 15:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 15:42 . 2009-10-09 15:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 15:41 . 2009-10-09 15:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 15:41 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-06 15:36 . 2009-10-22 15:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-11-06 15:36 . 2009-10-22 15:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-11-06 15:36 . 2007-10-25 03:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-24 11:01 . 2007-10-18 19:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-22 16:18 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-09-18 17:15 . 2009-09-18 17:15 -------- d-----w- c:\program files\BORLANDC . ((((((((((((((((((((((((((((( SnapShot@2009-11-06_14.43.43 ))))))))))))))))))))))))))))))))))))))))) . + 2009-11-06 15:37 . 2009-11-06 15:37 16384 c:\windows\temp\Perflib_Perfdata_60c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "combofix"="c:\combofix\CF31421.exe" [2009-11-06 388608] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-06 17:41 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . ------------------------ Other Running Processes ------------------------ . c:\program files\BlueSoleil\BTNtService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE . ************************************************************************** . Completion time: 2009-11-06 17:41 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-06 15:41 ComboFix2.txt 2009-11-06 14:47 Pre-Run: 6 042 910 720 bytes free Post-Run: 5 786 992 640 bytes free - - End Of File - - 0F68209ED23931798614946AB7225FD2
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
ComboFix 09-11-05.05 - DUDU 11.2009 г. 16:33.3.2 - FAT32x86 Running from: c:\documents and settings\DUDU\desktop\ComboFix.exe Command switches used :: /KillAll * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected Restored copy from - Kitty ate it . . 2009-11-06 14:43 . 2009-11-06 14:43 -------- d-----w- C:\FOUND.009 2009-11-06 14:31 . 2004-03-02 15:37 5504 ----a-w- c:\windows\system32\drivers\imagedrv.sys 2009-11-05 10:07 . 2009-11-05 10:07 -------- d-----w- C:\FOUND.008 2009-11-04 23:35 . 2009-11-04 23:35 -------- d-----w- C:\FOUND.007 2009-11-02 18:15 . 2009-11-02 18:15 -------- d-----w- C:\FOUND.006 2009-11-02 18:08 . 2009-11-02 18:08 -------- d-----w- C:\FOUND.005 2009-11-02 18:00 . 2009-11-02 18:00 -------- d-----w- C:\FOUND.004 2009-11-02 17:55 . 2009-11-02 17:55 -------- d-----w- C:\FOUND.003 2009-11-02 12:04 . 2009-11-02 12:04 -------- d-----w- C:\FOUND.002 2009-11-01 21:05 . 2009-11-01 21:05 -------- d-----w- C:\FOUND.001 2009-10-26 09:59 . 2009-10-26 09:59 -------- d-----w- c:\program files\Foxit Software 2009-10-25 21:22 . 2009-10-25 21:22 -------- d-----w- C:\FOUND.000 2009-10-25 21:00 . 2009-10-25 21:00 -------- d-----w- c:\windows\system32\CatRoot_bak 2009-10-24 12:18 . 2009-10-24 12:18 -------- d-----w- c:\documents and settings\DUDU\DoctorWeb 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----r- c:\program files\Skype 2009-10-22 21:39 . 2009-10-22 21:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 16:18 . 2009-10-22 16:18 44808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll 2009-10-22 16:18 . 2009-10-22 16:18 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys 2009-10-22 16:18 . 2009-10-22 16:18 208616 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe 2009-10-22 16:18 . 2009-10-22 16:18 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys 2009-10-22 16:03 . 2009-10-22 16:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 16:03 . 2009-10-22 16:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 15:54 . 2009-11-06 14:40 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 15:54 . 2009-11-06 14:40 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-21 23:32 . 2009-10-21 23:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-20 16:52 . 2009-10-20 16:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 16:40 . 2009-10-20 16:40 -------- d-----w- c:\windows\Sun 2009-10-20 16:39 . 2009-10-20 16:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 16:39 . 2009-10-20 16:39 -------- d-----w- c:\program files\Java 2009-10-20 16:39 . 2009-10-20 16:39 152576 ----a-w- c:\documents and settings\DUDU\Application Data\Sun\Java\jre1.6.0_16\lzma.dll 2009-10-20 15:57 . 2009-10-20 15:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 15:57 . 2009-10-20 15:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 15:44 . 2009-10-09 15:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 15:44 . 2009-10-09 15:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 15:42 . 2009-10-09 15:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 15:41 . 2009-10-09 15:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 15:41 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll . . 2009-11-06 14:40 . 2009-10-22 15:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-11-06 14:40 . 2009-10-22 15:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-11-06 14:40 . 2007-10-25 03:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-24 11:01 . 2007-10-18 19:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-22 16:18 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-09-18 17:15 . 2009-09-18 17:15 -------- d-----w- c:\program files\BORLANDC . . . REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "combofix"="c:\combofix\CF20546.exe" [2009-11-06 388608] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8018:TCP"= 8018:TCP:WWW R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 11264] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] --- --- *Deregistered* - mbr . . ------- ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### ---- ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . - - - - - - - - HKCU-Run-tempo - c:\docume~1\DUDU\LOCALS~1\Temp\clean-temp.exe HKCU-Run-clean-temp - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKCU-Run-winupdate - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-Run-tempo - c:\docume~1\DUDU\LOCALS~1\Temp\clean-temp.exe HKLM-Run-clean-temp - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-Run-winupdate - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-RunServices-tempo - c:\docume~1\DUDU\LOCALS~1\Temp\clean-temp.exe HKLM-RunServices-clean-temp - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-RunServices-winupdate - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-06 16:45 Windows 5.1.2600 Service Pack 2 FAT NTAPI : 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . --------------------- --------------------- - - - - - - - > 'explorer.exe'(2888) c:\windows\system32\msi.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ ------------------------ . c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE . ************************************************************************** . : 2009-11-06 16:47 - ComboFix-quarantined-files.txt 2009-11-06 14:47 Pre-Run: 5 787 090 944 bytes free : 5 819 400 192 bytes free - - End Of File - - 15F6147BA59FCDB682BE38BF3DA8106B Имах предвид, че имам два инсталационни Windows XP SP2 на харда. Вече имам и bootable XP, пуснах repair от диска, но проблема си остана.
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
CureIt направи много голям лог, който не може да се пейстне във форума. Но на пръв поглед нещата са добре. ----------------------------------------------------------------------------- Статистика на проверката ----------------------------------------------------------------------------- Обектите са проверени: 11536 Инфектирани: 0 Инфектирани с модификации: 0 Подозрителни: 0 Рекламни програми: 0 Програми dialers: 0 Програми-шеги: 0 Потенциално опасни програми: 0 Програми за взлом: 0 Излекуван: 0 Изтрит: 0 Преименуван: 0 Преместен: 0 Игнориран: 0 Скорост на проверката: 5139 Kb/s Време за проверка: 00:11:35 ----------------------------------------------------------------------------- ============================================================================= Обща статистика на сесиите ============================================================================= Обектите са проверени: 11536 Инфектирани: 0 Инфектирани с модификации: 0 Подозрителни: 0 Рекламни програми: 0 Програми dialers: 0 Програми-шеги: 0 Потенциално опасни програми: 0 Програми за взлом: 0 Излекуван: 0 Изтрит: 0 Преименуван: 0 Преместен: 0 Игнориран: 0 Скорост на проверката: 5059 Kb/s Време за проверка: 00:11:46 =============================================================================
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Нямам Daemon Tools.
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
SP3 не иска да се запише. Изписва грешка: Доколкото разбрах, това е драйвър за IDE, та значи трябва ли да си откача втория хард диск, който е ATA, за да запиша SP3?
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Не мога да се разправям, започвам да събирам пари от закуски за нов компютър Благодаря Ви за отделеното време!
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Изтеглих го, но не тръгва. Изписва:
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Norman SinowalMBR Cleaner Copyright © 1990 - 2008, Norman ASA. Built 2008/05/13 17:21:18 Norman Scanner Engine Version: 5.92.04 Nvcbin.def Version: 5.92.00, Date: 2008/05/13 17:21:18, Variants: 0 Running pre-scan cleanup routine: Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 2 Logged on user: HYUNDAI\DUDU Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\WINDOWS\system32\winmm.dll" -> "" Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000 Scan started: 24/10/2009 00:38:55 Scanning bootsectors... No SinowalMBR hooks found Number of sectors found: 2 Number of sectors scanned: 2 Number of sectors not scanned: 0 Number of infections found: 0 Number of infections removed: 0 Total scanning time: 0s 359ms Scanning running processes and process memory... Number of processes/threads found: 1408 Number of processes/threads scanned: 1408 Number of processes/threads not scanned: 0 Number of infected processes/threads terminated: 0 Total scanning time: 16s Scanning file system... Scanning: C:\*.* Scanning: Z:\*.* Z:\Sweet Home Alabama 2002\0sweet_home_alabama(subs[1].unacs.bg).rar/CMT (Error whilst scanning file: I/O Error) Z:\Sweet Home Alabama 2002\0sweet_home_alabama(subs[1].unacs.bg).rar/RR (Error whilst scanning file: I/O Error) Running post-scan cleanup routine: Number of files found: 26028 Number of archives unpacked: 65 Number of files scanned: 25996 Number of files not scanned: 32 Number of files skipped due to exclude list: 0 Number of infected files found: 0 Number of infected files repaired/deleted: 0 Number of infections removed: 0 Total scanning time: 6m 46s На компютъра имам 2 уиндоуса XP2 SP2, но на диск нямам.
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Не виждам да е създаден нов лог файл, а старият е непроменен. Това става при изпълнение на командата:
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Рестартирах го и после пак трябваше да го пускам с Debugging Mode.
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK copy of MBR has been found in sector 62 ! Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK copy of MBR has been found in sector 62 ! edit: Аз два пъти го написах в ДОС, защото не бях сигурен, че е станало и може би за това е излязло така.
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
GMER 1.0.15.15163 - http://www.gmer.net Rootkit quick scan 2009-10-23 23:53:35 Windows 5.1.2600 Service Pack 2 Running: gmer.exe; Driver: C:\DOCUME~1\DUDU\LOCALS~1\Temp\awldipod.sys ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 sector 62: copy of MBR ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateKey [0xB72AD940] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateValueKey [0xB72AD9A8] Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) ---- EOF - GMER 1.0.15 ----
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
Като пусна windows-а в нормален мод, той зарежда и след зареждането му, екрана остава черен (синият екран с надпис Welcome никога не се и показва). 3GP Video Converter 3 Adobe Audition 1.5 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 7.0.7 Adobe Stock Photos 1.0 Any Video Converter 2.5.8 Apple Software Update Auto Gordian Knot 2.45 AutoCAD LT 2009 - English Avant Browser (remove only) AVI Splitter AviSynth 2.5 Battle Rush BD/HD Advisor 1.0 BlueSoleil Boilsoft Video Joiner 5.24 BS.Player FREE powered by AdVantage CCleaner (remove only) Counter-Strike 1.6 Decal Converter Diablo II DriverAgent by eSupport.com DynGate eMule EVEREST Home Edition v2.00 Favorite-Games 5.16 FlashFXP FlashGet 1.9.4.1063 FlexType 2K Fraps (remove only) Garena GFunction 2.1 Google Talk (remove only) HijackThis 2.0.2 I-Doser v4 Java 6 Update 16 K-Lite Codec Pack 3.9.0 Full Kaspersky Internet Security 2009 Magic Video Converter Trial Version (English) 8.0.1.18 Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Microsoft .NET Framework 3.0 Microsoft Office XP Professional with FrontPage Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.5.3) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB925673) Nero 6 Ultra Edition Nokia Connectivity Cable Driver Nokia PC Suite NVIDIA Drivers PartitionMagic Platform PowerQuest PartitionMagic 8.0 Realtek AC'97 Audio REALTEK GbE & FE Ethernet PCI NIC Driver Realtek High Definition Audio Driver SA Dictionary 2005 T2 SAMSUNG CDMA Modem Driver Set SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio Security Update for Windows XP (KB921883) Skype™ 4.1 SolveigMM AVI Trimmer SpyBlocker Subtitle Workshop 2.51 Sumatra PDF reader TeamViewer Tunatic Ventrilo Client Ventrilo Server VIA Platform Device Manager VLC media player 0.9.9 Vodafone 804SS USB driver Software Warcraft III 1.22 Patch Warcraft III: All Products WebFldrs XP Winamp (remove only) Windows Communication Foundation Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Media Format 11 runtime Windows Media Player 11 Windows Presentation Foundation Windows Workflow Foundation XML Paper Specification Shared Components Pack 1.0 XP Codec Pack Xvid 1.1.3 final uninstall XviD MPEG4 Video Codec (remove only) ррхёІ°тѕр WinRAR µTorrent These Windows services are started: Automatic Updates BlueSoleil Hid Service Bluetooth Support Service COM+ Event System Computer Browser CryptSvc DCOM Server Process Launcher DHCP Client Distributed Link Tracking Client Error Reporting Service Event Log Fast User Switching Compatibility Help and Support IPSEC Services Java Quick Starter Kaspersky Internet Security Logical Disk Manager Machine Debug Manager Network Connections Network Location Awareness (NLA) NVIDIA Display Driver Service Plug and Play Print Spooler Protected Storage Remote Access Connection Manager Remote Procedure Call (RPC) Remote Registry Secondary Logon Security Accounts Manager Server Shell Hardware Detection SSDP Discovery Service System Event Notification System Restore Service Task Scheduler TCP/IP NetBIOS Helper Telephony Terminal Services Themes WebClient Windows Audio Windows Time Wireless Zero Configuration Workstation The command completed successfully.
-
Компютърът ми забива при пускане на скайп [РЕШЕН]
ComboFix 09-10-22.01 - DUDU 10.2009 г. 21:50.2.2 - FAT32x86 Running from: c:\documents and settings\DUDU\Desktop\tempo.exe Command switches used :: c:\documents and settings\DUDU\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\$AVG c:\$avg\$VAULT\V_00000001.fil c:\$avg\$VAULT\vvfolder.idx c:\documents and settings\All Users\Application Data\avg9 c:\documents and settings\All Users\Application Data\avg9\Cfg\changecfgreg.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\krnl.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\mail.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\malrep.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\scan.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\sched.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\update.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\user.cfg c:\documents and settings\All Users\Application Data\avg9\CfgAll\krnlall.cfg c:\documents and settings\All Users\Application Data\avg9\Log\avgcfg.log c:\documents and settings\All Users\Application Data\avg9\Log\avgcfg.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgchjw.log c:\documents and settings\All Users\Application Data\avg9\Log\avgchjw.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgchjwsrv.log c:\documents and settings\All Users\Application Data\avg9\Log\avgchjwsrv.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgcore.log c:\documents and settings\All Users\Application Data\avg9\Log\avgcore.log.1 c:\documents and settings\All Users\Application Data\avg9\Log\avgcore.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgfrw.log c:\documents and settings\All Users\Application Data\avg9\Log\avgfrw.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgldr.log c:\documents and settings\All Users\Application Data\avg9\Log\avgldr.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avglng.log c:\documents and settings\All Users\Application Data\avg9\Log\avglng.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgns.log c:\documents and settings\All Users\Application Data\avg9\Log\avgns.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgrs.log c:\documents and settings\All Users\Application Data\avg9\Log\avgrs.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgscan.log c:\documents and settings\All Users\Application Data\avg9\Log\avgscan.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log.1 c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log.2 c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgsrm.log c:\documents and settings\All Users\Application Data\avg9\Log\avgsrm.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgtdi.log c:\documents and settings\All Users\Application Data\avg9\Log\avgtdi.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgui.log c:\documents and settings\All Users\Application Data\avg9\Log\avgui.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgupd.log c:\documents and settings\All Users\Application Data\avg9\Log\avgupd.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgwd.log c:\documents and settings\All Users\Application Data\avg9\Log\avgwd.log.1 c:\documents and settings\All Users\Application Data\avg9\Log\avgwd.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgwdsvc.log c:\documents and settings\All Users\Application Data\avg9\Log\avgwdsvc.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\commonpriv.log c:\documents and settings\All Users\Application Data\avg9\Log\commonpriv.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\fixcfg.log c:\documents and settings\All Users\Application Data\avg9\Log\fixcfg.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\history.xml c:\documents and settings\All Users\Application Data\avg9\Log\vault.log c:\documents and settings\All Users\Application Data\avg9\Log\vault.log.lock c:\documents and settings\All Users\Application Data\avg9\scanlogs\I_00000005.log c:\documents and settings\All Users\Application Data\avg9\scanlogs\I_00000006.log c:\documents and settings\All Users\Application Data\avg9\scanlogs\srm.idx c:\documents and settings\All Users\Application Data\avg9\Temp\24b9b1d4-b5e4-49a2-bbc3-a442135273a6-b0-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\309eb055-0974-4c6e-bba8-903d38b5a0ad-7c4-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\b477a6e1-4979-441e-ac43-292697bcd329-654-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\be6c25a1-62ed-47ad-9de3-3d5bae2132b1-b4-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\c7e3260a-0607-47de-9480-c83ca9f29896-cc8-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\cff8d4e9-9fc8-4f96-b014-fe6b97eadcf9-7ec-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\file9514.tmp c:\documents and settings\All Users\Application Data\Norton c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\isolate.ini c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Module9000.txt c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\Connections\connections.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{65190544-26C3-43a4-A78A-694964901607}.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{6E3396BD-C6A6-4f0f-9254-267F9058FEC4}.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{71B3DD3A-BC1F-40cc-A74F-C0C30DFCE7D5}.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{D4F4CC32-7A41-4684-AE57-41E59E9B4503}.dat c:\documents and settings\All Users\Application Data\Norton\symdata.xml c:\documents and settings\All Users\Application Data\NortonInstaller c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\10-22-2009-12h41m18s\Install.1.mft.7z c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\10-22-2009-12h41m18s\NortonInstall-10-22-2009-12h41m18s.log c:\documents and settings\All Users\Application Data\Symantec c:\documents and settings\All Users\Application Data\Symantec\symdata.xml C:\FOUND.014 c:\found.014\FILE0000.CHK c:\found.014\FILE0001.CHK c:\found.014\FILE0002.CHK c:\found.014\FILE0003.CHK c:\found.014\FILE0004.CHK c:\found.014\FILE0005.CHK c:\found.014\FILE0006.CHK c:\found.014\FILE0007.CHK c:\found.014\FILE0008.CHK c:\found.014\FILE0009.CHK c:\found.014\FILE0010.CHK c:\found.014\FILE0011.CHK c:\found.014\FILE0012.CHK c:\found.014\FILE0013.CHK c:\found.014\FILE0014.CHK C:\FOUND.015 c:\found.015\FILE0000.CHK c:\found.015\FILE0001.CHK C:\FOUND.016 c:\found.016\FILE0000.CHK c:\found.016\FILE0001.CHK c:\found.016\FILE0002.CHK c:\found.016\FILE0003.CHK c:\found.016\FILE0004.CHK c:\found.016\FILE0005.CHK c:\found.016\FILE0006.CHK c:\found.016\FILE0007.CHK c:\found.016\FILE0008.CHK c:\found.016\FILE0009.CHK c:\found.016\FILE0010.CHK c:\found.016\FILE0011.CHK c:\found.016\FILE0012.CHK c:\found.016\FILE0013.CHK c:\found.016\FILE0014.CHK c:\found.016\FILE0015.CHK c:\found.016\FILE0016.CHK C:\FOUND.017 c:\found.017\FILE0000.CHK c:\found.017\FILE0001.CHK c:\found.017\FILE0002.CHK c:\found.017\FILE0003.CHK c:\found.017\FILE0004.CHK c:\found.017\FILE0005.CHK c:\found.017\FILE0006.CHK c:\found.017\FILE0007.CHK c:\found.017\FILE0008.CHK c:\found.017\FILE0009.CHK c:\found.017\FILE0010.CHK c:\found.017\FILE0011.CHK c:\found.017\FILE0012.CHK c:\found.017\FILE0013.CHK c:\found.017\FILE0014.CHK c:\found.017\FILE0015.CHK c:\found.017\FILE0016.CHK c:\found.017\FILE0017.CHK c:\found.017\FILE0018.CHK c:\found.017\FILE0019.CHK c:\found.017\FILE0020.CHK c:\found.017\FILE0021.CHK c:\found.017\FILE0022.CHK c:\found.017\FILE0023.CHK C:\FOUND.018 c:\found.018\FILE0000.CHK c:\found.018\FILE0001.CHK C:\FOUND.019 c:\found.019\FILE0000.CHK c:\found.019\FILE0001.CHK c:\found.019\FILE0002.CHK c:\found.019\FILE0003.CHK c:\found.019\FILE0004.CHK c:\found.019\FILE0005.CHK c:\found.019\FILE0006.CHK c:\found.019\FILE0007.CHK c:\found.019\FILE0008.CHK c:\found.019\FILE0009.CHK c:\found.019\FILE0010.CHK c:\found.019\FILE0011.CHK c:\found.019\FILE0012.CHK C:\FOUND.020 c:\found.020\FILE0000.CHK c:\found.020\FILE0001.CHK C:\FOUND.021 c:\found.021\FILE0000.CHK c:\found.021\FILE0001.CHK c:\program files\Common Files\Symantec Shared c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\catalog.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\cceraser.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ecmsvr32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\eeCtrl.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.grd c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.sig c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.spm c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ESRDEF.BIN c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\hh c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\naveng.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\naveng32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\navex15.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\navex32a.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ncsacert.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\scrauth.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\symaveng.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\symaveng.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\SymErase.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\SymErase.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCDEFS.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCSCAN7.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCSCAN8.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCSCAN9.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\technote.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TINF.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\tinfidx.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TINFL.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TSCAN1.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\tscan1hd.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\V.GRD c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\V.SIG c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\virscan.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN1.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN2.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN3.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN4.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN5.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN6.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN7.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN8.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN9.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\vscanmsx.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\WHATSNEW.TXT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\zdone.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\catalog.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\cceraser.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ecmsvr32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\eeCtrl.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.grd c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.sig c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.spm c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\esrdef.bin c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\hh c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\naveng.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\naveng32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\navex15.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\navex32a.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ncsacert.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\scrauth.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\symaveng.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\symaveng.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\SymErase.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\SymErase.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcdefs.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcscan7.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcscan8.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcscan9.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\technote.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tinf.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tinfidx.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tinfl.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tscan1.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tscan1hd.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\v.grd c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\v.sig c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan1.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan2.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan3.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan4.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan5.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan6.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan7.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan8.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan9.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\whatsnew.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\zdone.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\definfo.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\usage.dat c:\windows\BDOSCAN8 c:\windows\BDOSCAN8\bdcore.dll c:\windows\BDOSCAN8\bdoscan.ini c:\windows\BDOSCAN8\bdoscan.log c:\windows\BDOSCAN8\ipsupd.dll c:\windows\BDOSCAN8\lang.ini c:\windows\BDOSCAN8\libfn.dll c:\windows\BDOSCAN8\live.ini c:\windows\BDOSCAN8\oscan82.ocx c:\windows\BDOSCAN8\scanoptions.tsi c:\windows\BDOSCAN8\scanoptions.tsk c:\windows\system32\drivers\NSS c:\windows\system32\drivers\NSS\0203000.02C\isolate.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_FXDRV32 -------\Legacy_YTXYY -------\Service_FXDrv32 -------\Service_ytxyy ((((((((((((((((((((((((( Files Created from 2009-09-23 to 2009-10-23 ))))))))))))))))))))))))))))))) . 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 14:54 . 2009-09-10 11:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 14:54 . 2009-09-10 11:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 13:47 . 2009-10-23 13:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 13:47 . 2009-10-23 13:47 -------- d-----r- c:\program files\Skype 2009-10-22 20:39 . 2009-10-22 20:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\QuickTime 2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\3GP Video Converter 3 2009-10-22 15:03 . 2009-10-22 15:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 15:03 . 2009-10-22 15:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 14:54 . 2009-10-23 18:53 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 14:54 . 2009-10-23 18:53 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 14:54 . 2009-10-22 14:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 14:54 . 2009-10-22 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-21 22:32 . 2009-10-21 22:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-21 22:32 . 2009-10-21 22:32 -------- d-----w- c:\program files\SumatraPDF 2009-10-20 15:52 . 2009-10-20 15:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 15:40 . 2009-10-20 15:40 -------- d-----w- c:\windows\Sun 2009-10-20 15:39 . 2009-10-20 15:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 15:39 . 2009-10-20 15:39 -------- d-----w- c:\program files\Java 2009-10-20 14:57 . 2009-10-20 14:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 14:57 . 2009-10-20 14:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 14:44 . 2009-10-09 14:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 14:44 . 2009-10-09 14:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 14:42 . 2009-10-09 14:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 14:41 . 2009-10-09 14:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 14:41 . 2006-06-29 10:07 14048 ------w- c:\windows\system32\spmsg2.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-23 18:53 . 2009-10-22 14:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-10-23 18:53 . 2009-10-22 14:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-23 18:53 . 2007-10-25 02:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-22 15:18 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-10-09 15:00 . 2007-10-18 18:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-18 16:15 . 2009-09-18 16:15 -------- d-----w- c:\program files\BORLANDC 2009-08-06 16:24 . 2007-10-18 17:35 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-06 16:24 . 2007-10-18 17:35 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-06 16:24 . 2007-10-18 17:35 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-06 16:24 . 2007-07-30 16:19 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-06 16:24 . 2007-10-18 17:35 53472 ------w- c:\windows\system32\wuauclt.exe 2009-08-06 16:24 . 2008-11-21 16:33 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-06 16:23 . 2007-10-18 17:35 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-06 16:23 . 2007-10-18 17:35 1929952 ----a-w- c:\windows\system32\wuaueng.dll . ((((((((((((((((((((((((((((( SnapShot@2009-10-23_16.51.20 ))))))))))))))))))))))))))))))))))))))))) . + 2009-10-23 18:54 . 2009-10-23 18:54 16384 c:\windows\temp\Perflib_Perfdata_4a4.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\winmm.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8018:TCP"= 8018:TCP:WWW R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### . - - - - ORPHANS REMOVED - - - - AddRemove-HijackThis - c:\documents and settings\DUDU\Desktop\HijackThis.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-23 21:54 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3272) c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\tempo\CF30448.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE c:\tempo\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-23 21:57 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-23 18:57 ComboFix2.txt 2009-10-23 16:53 Pre-Run: 10 243 670 016 bytes free Post-Run: 10 191 372 288 bytes free - - End Of File - - 31F3886F954603B89FE30B065D4AADA6
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.