Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

radisto

Потребител
  • Регистрация

  • Последно онлайн

Всичко публикувано от radisto

  1. Компютърът ми вече се пуска нормално и скайпа не забива. Благодаря Ви!!!
  2. ComboFix 09-11-05.05 - DUDU 11.2009 г. 17:32.4.2 - FAT32x86 Running from: c:\documents and settings\DUDU\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\DUDU\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\DUDU\DoctorWeb c:\documents and settings\DUDU\DoctorWeb\CureIt.log C:\FOUND.000 c:\found.000\FILE0000.CHK c:\found.000\FILE0001.CHK c:\found.000\FILE0002.CHK c:\found.000\FILE0003.CHK c:\found.000\FILE0004.CHK c:\found.000\FILE0005.CHK c:\found.000\FILE0006.CHK c:\found.000\FILE0007.CHK c:\found.000\FILE0008.CHK c:\found.000\FILE0009.CHK c:\found.000\FILE0010.CHK c:\found.000\FILE0011.CHK C:\FOUND.001 c:\found.001\FILE0000.CHK c:\found.001\FILE0001.CHK c:\found.001\FILE0002.CHK c:\found.001\FILE0003.CHK c:\found.001\FILE0004.CHK c:\found.001\FILE0005.CHK c:\found.001\FILE0006.CHK c:\found.001\FILE0007.CHK c:\found.001\FILE0008.CHK c:\found.001\FILE0009.CHK c:\found.001\FILE0010.CHK c:\found.001\FILE0011.CHK c:\found.001\FILE0012.CHK c:\found.001\FILE0013.CHK c:\found.001\FILE0014.CHK c:\found.001\FILE0015.CHK c:\found.001\FILE0016.CHK c:\found.001\FILE0017.CHK c:\found.001\FILE0018.CHK c:\found.001\FILE0019.CHK c:\found.001\FILE0020.CHK c:\found.001\FILE0021.CHK c:\found.001\FILE0022.CHK c:\found.001\FILE0023.CHK c:\found.001\FILE0024.CHK c:\found.001\FILE0025.CHK c:\found.001\FILE0026.CHK c:\found.001\FILE0027.CHK c:\found.001\FILE0028.CHK c:\found.001\FILE0029.CHK c:\found.001\FILE0030.CHK c:\found.001\FILE0031.CHK c:\found.001\FILE0032.CHK c:\found.001\FILE0033.CHK c:\found.001\FILE0034.CHK c:\found.001\FILE0035.CHK c:\found.001\FILE0036.CHK c:\found.001\FILE0037.CHK c:\found.001\FILE0038.CHK c:\found.001\FILE0039.CHK c:\found.001\FILE0040.CHK c:\found.001\FILE0041.CHK c:\found.001\FILE0042.CHK C:\FOUND.002 c:\found.002\FILE0000.CHK C:\FOUND.003 c:\found.003\FILE0000.CHK C:\FOUND.004 c:\found.004\FILE0000.CHK c:\found.004\FILE0001.CHK c:\found.004\FILE0002.CHK c:\found.004\FILE0003.CHK c:\found.004\FILE0004.CHK c:\found.004\FILE0005.CHK c:\found.004\FILE0006.CHK c:\found.004\FILE0007.CHK c:\found.004\FILE0008.CHK c:\found.004\FILE0009.CHK c:\found.004\FILE0010.CHK c:\found.004\FILE0011.CHK c:\found.004\FILE0012.CHK c:\found.004\FILE0013.CHK c:\found.004\FILE0014.CHK c:\found.004\FILE0015.CHK c:\found.004\FILE0016.CHK c:\found.004\FILE0017.CHK c:\found.004\FILE0018.CHK c:\found.004\FILE0019.CHK c:\found.004\FILE0020.CHK c:\found.004\FILE0021.CHK c:\found.004\FILE0022.CHK c:\found.004\FILE0023.CHK c:\found.004\FILE0024.CHK c:\found.004\FILE0025.CHK c:\found.004\FILE0026.CHK c:\found.004\FILE0027.CHK c:\found.004\FILE0028.CHK c:\found.004\FILE0029.CHK c:\found.004\FILE0030.CHK c:\found.004\FILE0031.CHK c:\found.004\FILE0032.CHK c:\found.004\FILE0033.CHK c:\found.004\FILE0034.CHK c:\found.004\FILE0035.CHK c:\found.004\FILE0036.CHK c:\found.004\FILE0037.CHK c:\found.004\FILE0038.CHK c:\found.004\FILE0039.CHK C:\FOUND.005 c:\found.005\FILE0000.CHK c:\found.005\FILE0001.CHK c:\found.005\FILE0002.CHK c:\found.005\FILE0003.CHK c:\found.005\FILE0004.CHK C:\FOUND.006 c:\found.006\FILE0000.CHK C:\FOUND.007 c:\found.007\FILE0000.CHK c:\found.007\FILE0001.CHK c:\found.007\FILE0002.CHK C:\FOUND.008 c:\found.008\FILE0000.CHK c:\found.008\FILE0001.CHK c:\found.008\FILE0002.CHK c:\found.008\FILE0003.CHK c:\found.008\FILE0004.CHK C:\FOUND.009 c:\found.009\FILE0000.CHK c:\found.009\FILE0001.CHK c:\found.009\FILE0002.CHK c:\found.009\FILE0003.CHK c:\found.009\FILE0004.CHK c:\found.009\FILE0005.CHK c:\found.009\FILE0006.CHK c:\found.009\FILE0007.CHK c:\found.009\FILE0008.CHK c:\found.009\FILE0009.CHK c:\found.009\FILE0010.CHK c:\found.009\FILE0011.CHK c:\found.009\FILE0012.CHK c:\found.009\FILE0013.CHK c:\found.009\FILE0014.CHK c:\found.009\FILE0015.CHK c:\found.009\FILE0016.CHK . ((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 ))))))))))))))))))))))))))))))) . 2009-11-06 14:31 . 2004-03-02 15:37 5504 ----a-w- c:\windows\system32\drivers\imagedrv.sys 2009-10-26 09:59 . 2009-10-26 09:59 -------- d-----w- c:\program files\Foxit Software 2009-10-25 21:00 . 2009-10-25 21:00 -------- d-----w- c:\windows\system32\CatRoot_bak 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----r- c:\program files\Skype 2009-10-22 21:39 . 2009-10-22 21:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 16:18 . 2009-10-22 16:18 44808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll 2009-10-22 16:18 . 2009-10-22 16:18 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys 2009-10-22 16:18 . 2009-10-22 16:18 208616 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe 2009-10-22 16:18 . 2009-10-22 16:18 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys 2009-10-22 16:03 . 2009-10-22 16:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 16:03 . 2009-10-22 16:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 15:54 . 2009-11-06 15:36 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 15:54 . 2009-11-06 15:36 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-21 23:32 . 2009-10-21 23:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-20 16:52 . 2009-10-20 16:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 16:40 . 2009-10-20 16:40 -------- d-----w- c:\windows\Sun 2009-10-20 16:39 . 2009-10-20 16:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 16:39 . 2009-10-20 16:39 -------- d-----w- c:\program files\Java 2009-10-20 16:39 . 2009-10-20 16:39 152576 ----a-w- c:\documents and settings\DUDU\Application Data\Sun\Java\jre1.6.0_16\lzma.dll 2009-10-20 15:57 . 2009-10-20 15:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 15:57 . 2009-10-20 15:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 15:44 . 2009-10-09 15:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 15:44 . 2009-10-09 15:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 15:42 . 2009-10-09 15:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 15:41 . 2009-10-09 15:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 15:41 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-06 15:36 . 2009-10-22 15:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-11-06 15:36 . 2009-10-22 15:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-11-06 15:36 . 2007-10-25 03:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-24 11:01 . 2007-10-18 19:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-22 16:18 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-09-18 17:15 . 2009-09-18 17:15 -------- d-----w- c:\program files\BORLANDC . ((((((((((((((((((((((((((((( SnapShot@2009-11-06_14.43.43 ))))))))))))))))))))))))))))))))))))))))) . + 2009-11-06 15:37 . 2009-11-06 15:37 16384 c:\windows\temp\Perflib_Perfdata_60c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "combofix"="c:\combofix\CF31421.exe" [2009-11-06 388608] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-06 17:41 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . ------------------------ Other Running Processes ------------------------ . c:\program files\BlueSoleil\BTNtService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE . ************************************************************************** . Completion time: 2009-11-06 17:41 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-06 15:41 ComboFix2.txt 2009-11-06 14:47 Pre-Run: 6 042 910 720 bytes free Post-Run: 5 786 992 640 bytes free - - End Of File - - 0F68209ED23931798614946AB7225FD2
  3. ComboFix 09-11-05.05 - DUDU 11.2009 г. 16:33.3.2 - FAT32x86 Running from: c:\documents and settings\DUDU\desktop\ComboFix.exe Command switches used :: /KillAll * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected Restored copy from - Kitty ate it . . 2009-11-06 14:43 . 2009-11-06 14:43 -------- d-----w- C:\FOUND.009 2009-11-06 14:31 . 2004-03-02 15:37 5504 ----a-w- c:\windows\system32\drivers\imagedrv.sys 2009-11-05 10:07 . 2009-11-05 10:07 -------- d-----w- C:\FOUND.008 2009-11-04 23:35 . 2009-11-04 23:35 -------- d-----w- C:\FOUND.007 2009-11-02 18:15 . 2009-11-02 18:15 -------- d-----w- C:\FOUND.006 2009-11-02 18:08 . 2009-11-02 18:08 -------- d-----w- C:\FOUND.005 2009-11-02 18:00 . 2009-11-02 18:00 -------- d-----w- C:\FOUND.004 2009-11-02 17:55 . 2009-11-02 17:55 -------- d-----w- C:\FOUND.003 2009-11-02 12:04 . 2009-11-02 12:04 -------- d-----w- C:\FOUND.002 2009-11-01 21:05 . 2009-11-01 21:05 -------- d-----w- C:\FOUND.001 2009-10-26 09:59 . 2009-10-26 09:59 -------- d-----w- c:\program files\Foxit Software 2009-10-25 21:22 . 2009-10-25 21:22 -------- d-----w- C:\FOUND.000 2009-10-25 21:00 . 2009-10-25 21:00 -------- d-----w- c:\windows\system32\CatRoot_bak 2009-10-24 12:18 . 2009-10-24 12:18 -------- d-----w- c:\documents and settings\DUDU\DoctorWeb 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 15:54 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 15:54 . 2009-10-23 15:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 14:47 . 2009-10-23 14:47 -------- d-----r- c:\program files\Skype 2009-10-22 21:39 . 2009-10-22 21:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 16:18 . 2009-10-22 16:18 44808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll 2009-10-22 16:18 . 2009-10-22 16:18 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys 2009-10-22 16:18 . 2009-10-22 16:18 208616 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe 2009-10-22 16:18 . 2009-10-22 16:18 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys 2009-10-22 16:03 . 2009-10-22 16:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 16:03 . 2009-10-22 16:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 15:54 . 2009-11-06 14:40 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 15:54 . 2009-11-06 14:40 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 15:54 . 2009-10-22 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-21 23:32 . 2009-10-21 23:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-20 16:52 . 2009-10-20 16:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 16:40 . 2009-10-20 16:40 -------- d-----w- c:\windows\Sun 2009-10-20 16:39 . 2009-10-20 16:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 16:39 . 2009-10-20 16:39 -------- d-----w- c:\program files\Java 2009-10-20 16:39 . 2009-10-20 16:39 152576 ----a-w- c:\documents and settings\DUDU\Application Data\Sun\Java\jre1.6.0_16\lzma.dll 2009-10-20 15:57 . 2009-10-20 15:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 15:57 . 2009-10-20 15:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 15:45 . 2009-10-09 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 15:44 . 2009-10-09 15:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 15:44 . 2009-10-09 15:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 15:42 . 2009-10-09 15:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 15:41 . 2009-10-09 15:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 15:41 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll . . 2009-11-06 14:40 . 2009-10-22 15:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-11-06 14:40 . 2009-10-22 15:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-11-06 14:40 . 2007-10-25 03:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-24 11:01 . 2007-10-18 19:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-22 16:18 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-09-18 17:15 . 2009-09-18 17:15 -------- d-----w- c:\program files\BORLANDC . . . REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "combofix"="c:\combofix\CF20546.exe" [2009-11-06 388608] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8018:TCP"= 8018:TCP:WWW R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 11264] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] --- --- *Deregistered* - mbr . . ------- ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### ---- ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . - - - - - - - - HKCU-Run-tempo - c:\docume~1\DUDU\LOCALS~1\Temp\clean-temp.exe HKCU-Run-clean-temp - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKCU-Run-winupdate - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-Run-tempo - c:\docume~1\DUDU\LOCALS~1\Temp\clean-temp.exe HKLM-Run-clean-temp - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-Run-winupdate - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-RunServices-tempo - c:\docume~1\DUDU\LOCALS~1\Temp\clean-temp.exe HKLM-RunServices-clean-temp - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe HKLM-RunServices-winupdate - c:\docume~1\DUDU\LOCALS~1\Temp\svchost.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-06 16:45 Windows 5.1.2600 Service Pack 2 FAT NTAPI : 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . --------------------- --------------------- - - - - - - - > 'explorer.exe'(2888) c:\windows\system32\msi.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ ------------------------ . c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE . ************************************************************************** . : 2009-11-06 16:47 - ComboFix-quarantined-files.txt 2009-11-06 14:47 Pre-Run: 5 787 090 944 bytes free : 5 819 400 192 bytes free - - End Of File - - 15F6147BA59FCDB682BE38BF3DA8106B Имах предвид, че имам два инсталационни Windows XP SP2 на харда. Вече имам и bootable XP, пуснах repair от диска, но проблема си остана.
  4. CureIt направи много голям лог, който не може да се пейстне във форума. Но на пръв поглед нещата са добре. ----------------------------------------------------------------------------- Статистика на проверката ----------------------------------------------------------------------------- Обектите са проверени: 11536 Инфектирани: 0 Инфектирани с модификации: 0 Подозрителни: 0 Рекламни програми: 0 Програми dialers: 0 Програми-шеги: 0 Потенциално опасни програми: 0 Програми за взлом: 0 Излекуван: 0 Изтрит: 0 Преименуван: 0 Преместен: 0 Игнориран: 0 Скорост на проверката: 5139 Kb/s Време за проверка: 00:11:35 ----------------------------------------------------------------------------- ============================================================================= Обща статистика на сесиите ============================================================================= Обектите са проверени: 11536 Инфектирани: 0 Инфектирани с модификации: 0 Подозрителни: 0 Рекламни програми: 0 Програми dialers: 0 Програми-шеги: 0 Потенциално опасни програми: 0 Програми за взлом: 0 Излекуван: 0 Изтрит: 0 Преименуван: 0 Преместен: 0 Игнориран: 0 Скорост на проверката: 5059 Kb/s Време за проверка: 00:11:46 =============================================================================
  5. SP3 не иска да се запише. Изписва грешка: Доколкото разбрах, това е драйвър за IDE, та значи трябва ли да си откача втория хард диск, който е ATA, за да запиша SP3?
  6. Не мога да се разправям, започвам да събирам пари от закуски за нов компютър Благодаря Ви за отделеното време!
  7. Изтеглих го, но не тръгва. Изписва:
  8. Norman SinowalMBR Cleaner Copyright © 1990 - 2008, Norman ASA. Built 2008/05/13 17:21:18 Norman Scanner Engine Version: 5.92.04 Nvcbin.def Version: 5.92.00, Date: 2008/05/13 17:21:18, Variants: 0 Running pre-scan cleanup routine: Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 2 Logged on user: HYUNDAI\DUDU Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\WINDOWS\system32\winmm.dll" -> "" Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000 Scan started: 24/10/2009 00:38:55 Scanning bootsectors... No SinowalMBR hooks found Number of sectors found: 2 Number of sectors scanned: 2 Number of sectors not scanned: 0 Number of infections found: 0 Number of infections removed: 0 Total scanning time: 0s 359ms Scanning running processes and process memory... Number of processes/threads found: 1408 Number of processes/threads scanned: 1408 Number of processes/threads not scanned: 0 Number of infected processes/threads terminated: 0 Total scanning time: 16s Scanning file system... Scanning: C:\*.* Scanning: Z:\*.* Z:\Sweet Home Alabama 2002\0sweet_home_alabama(subs[1].unacs.bg).rar/CMT (Error whilst scanning file: I/O Error) Z:\Sweet Home Alabama 2002\0sweet_home_alabama(subs[1].unacs.bg).rar/RR (Error whilst scanning file: I/O Error) Running post-scan cleanup routine: Number of files found: 26028 Number of archives unpacked: 65 Number of files scanned: 25996 Number of files not scanned: 32 Number of files skipped due to exclude list: 0 Number of infected files found: 0 Number of infected files repaired/deleted: 0 Number of infections removed: 0 Total scanning time: 6m 46s На компютъра имам 2 уиндоуса XP2 SP2, но на диск нямам.
  9. Не виждам да е създаден нов лог файл, а старият е непроменен. Това става при изпълнение на командата:
  10. Рестартирах го и после пак трябваше да го пускам с Debugging Mode.
  11. Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK copy of MBR has been found in sector 62 ! Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK copy of MBR has been found in sector 62 ! edit: Аз два пъти го написах в ДОС, защото не бях сигурен, че е станало и може би за това е излязло така.
  12. GMER 1.0.15.15163 - http://www.gmer.net Rootkit quick scan 2009-10-23 23:53:35 Windows 5.1.2600 Service Pack 2 Running: gmer.exe; Driver: C:\DOCUME~1\DUDU\LOCALS~1\Temp\awldipod.sys ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 sector 62: copy of MBR ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateKey [0xB72AD940] SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateValueKey [0xB72AD9A8] Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab) ---- EOF - GMER 1.0.15 ----
  13. Като пусна windows-а в нормален мод, той зарежда и след зареждането му, екрана остава черен (синият екран с надпис Welcome никога не се и показва). 3GP Video Converter 3 Adobe Audition 1.5 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 7.0.7 Adobe Stock Photos 1.0 Any Video Converter 2.5.8 Apple Software Update Auto Gordian Knot 2.45 AutoCAD LT 2009 - English Avant Browser (remove only) AVI Splitter AviSynth 2.5 Battle Rush BD/HD Advisor 1.0 BlueSoleil Boilsoft Video Joiner 5.24 BS.Player FREE powered by AdVantage CCleaner (remove only) Counter-Strike 1.6 Decal Converter Diablo II DriverAgent by eSupport.com DynGate eMule EVEREST Home Edition v2.00 Favorite-Games 5.16 FlashFXP FlashGet 1.9.4.1063 FlexType 2K Fraps (remove only) Garena GFunction 2.1 Google Talk (remove only) HijackThis 2.0.2 I-Doser v4 Java 6 Update 16 K-Lite Codec Pack 3.9.0 Full Kaspersky Internet Security 2009 Magic Video Converter Trial Version (English) 8.0.1.18 Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Microsoft .NET Framework 3.0 Microsoft Office XP Professional with FrontPage Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.5.3) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB925673) Nero 6 Ultra Edition Nokia Connectivity Cable Driver Nokia PC Suite NVIDIA Drivers PartitionMagic Platform PowerQuest PartitionMagic 8.0 Realtek AC'97 Audio REALTEK GbE & FE Ethernet PCI NIC Driver Realtek High Definition Audio Driver SA Dictionary 2005 T2 SAMSUNG CDMA Modem Driver Set SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio Security Update for Windows XP (KB921883) Skype™ 4.1 SolveigMM AVI Trimmer SpyBlocker Subtitle Workshop 2.51 Sumatra PDF reader TeamViewer Tunatic Ventrilo Client Ventrilo Server VIA Platform Device Manager VLC media player 0.9.9 Vodafone 804SS USB driver Software Warcraft III 1.22 Patch Warcraft III: All Products WebFldrs XP Winamp (remove only) Windows Communication Foundation Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Media Format 11 runtime Windows Media Player 11 Windows Presentation Foundation Windows Workflow Foundation XML Paper Specification Shared Components Pack 1.0 XP Codec Pack Xvid 1.1.3 final uninstall XviD MPEG4 Video Codec (remove only) ррхёІ°тѕр WinRAR µTorrent These Windows services are started: Automatic Updates BlueSoleil Hid Service Bluetooth Support Service COM+ Event System Computer Browser CryptSvc DCOM Server Process Launcher DHCP Client Distributed Link Tracking Client Error Reporting Service Event Log Fast User Switching Compatibility Help and Support IPSEC Services Java Quick Starter Kaspersky Internet Security Logical Disk Manager Machine Debug Manager Network Connections Network Location Awareness (NLA) NVIDIA Display Driver Service Plug and Play Print Spooler Protected Storage Remote Access Connection Manager Remote Procedure Call (RPC) Remote Registry Secondary Logon Security Accounts Manager Server Shell Hardware Detection SSDP Discovery Service System Event Notification System Restore Service Task Scheduler TCP/IP NetBIOS Helper Telephony Terminal Services Themes WebClient Windows Audio Windows Time Wireless Zero Configuration Workstation The command completed successfully.
  14. ComboFix 09-10-22.01 - DUDU 10.2009 г. 21:50.2.2 - FAT32x86 Running from: c:\documents and settings\DUDU\Desktop\tempo.exe Command switches used :: c:\documents and settings\DUDU\Desktop\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\$AVG c:\$avg\$VAULT\V_00000001.fil c:\$avg\$VAULT\vvfolder.idx c:\documents and settings\All Users\Application Data\avg9 c:\documents and settings\All Users\Application Data\avg9\Cfg\changecfgreg.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\krnl.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\mail.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\malrep.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\scan.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\sched.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\update.cfg c:\documents and settings\All Users\Application Data\avg9\Cfg\user.cfg c:\documents and settings\All Users\Application Data\avg9\CfgAll\krnlall.cfg c:\documents and settings\All Users\Application Data\avg9\Log\avgcfg.log c:\documents and settings\All Users\Application Data\avg9\Log\avgcfg.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgchjw.log c:\documents and settings\All Users\Application Data\avg9\Log\avgchjw.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgchjwsrv.log c:\documents and settings\All Users\Application Data\avg9\Log\avgchjwsrv.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgcore.log c:\documents and settings\All Users\Application Data\avg9\Log\avgcore.log.1 c:\documents and settings\All Users\Application Data\avg9\Log\avgcore.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgfrw.log c:\documents and settings\All Users\Application Data\avg9\Log\avgfrw.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgldr.log c:\documents and settings\All Users\Application Data\avg9\Log\avgldr.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avglng.log c:\documents and settings\All Users\Application Data\avg9\Log\avglng.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgns.log c:\documents and settings\All Users\Application Data\avg9\Log\avgns.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgrs.log c:\documents and settings\All Users\Application Data\avg9\Log\avgrs.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgscan.log c:\documents and settings\All Users\Application Data\avg9\Log\avgscan.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log.1 c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log.2 c:\documents and settings\All Users\Application Data\avg9\Log\avgsched.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgsrm.log c:\documents and settings\All Users\Application Data\avg9\Log\avgsrm.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgtdi.log c:\documents and settings\All Users\Application Data\avg9\Log\avgtdi.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgui.log c:\documents and settings\All Users\Application Data\avg9\Log\avgui.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgupd.log c:\documents and settings\All Users\Application Data\avg9\Log\avgupd.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgwd.log c:\documents and settings\All Users\Application Data\avg9\Log\avgwd.log.1 c:\documents and settings\All Users\Application Data\avg9\Log\avgwd.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\avgwdsvc.log c:\documents and settings\All Users\Application Data\avg9\Log\avgwdsvc.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\commonpriv.log c:\documents and settings\All Users\Application Data\avg9\Log\commonpriv.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\fixcfg.log c:\documents and settings\All Users\Application Data\avg9\Log\fixcfg.log.lock c:\documents and settings\All Users\Application Data\avg9\Log\history.xml c:\documents and settings\All Users\Application Data\avg9\Log\vault.log c:\documents and settings\All Users\Application Data\avg9\Log\vault.log.lock c:\documents and settings\All Users\Application Data\avg9\scanlogs\I_00000005.log c:\documents and settings\All Users\Application Data\avg9\scanlogs\I_00000006.log c:\documents and settings\All Users\Application Data\avg9\scanlogs\srm.idx c:\documents and settings\All Users\Application Data\avg9\Temp\24b9b1d4-b5e4-49a2-bbc3-a442135273a6-b0-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\309eb055-0974-4c6e-bba8-903d38b5a0ad-7c4-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\b477a6e1-4979-441e-ac43-292697bcd329-654-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\be6c25a1-62ed-47ad-9de3-3d5bae2132b1-b4-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\c7e3260a-0607-47de-9480-c83ca9f29896-cc8-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\cff8d4e9-9fc8-4f96-b014-fe6b97eadcf9-7ec-oopp.tmp c:\documents and settings\All Users\Application Data\avg9\Temp\file9514.tmp c:\documents and settings\All Users\Application Data\Norton c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\isolate.ini c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Module9000.txt c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\Connections\connections.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{65190544-26C3-43a4-A78A-694964901607}.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{6E3396BD-C6A6-4f0f-9254-267F9058FEC4}.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{71B3DD3A-BC1F-40cc-A74F-C0C30DFCE7D5}.dat c:\documents and settings\All Users\Application Data\Norton\{397E31AA-0D78-4649-A01C-339D73A2ED35}\Norton\itbLUReg\{D4F4CC32-7A41-4684-AE57-41E59E9B4503}.dat c:\documents and settings\All Users\Application Data\Norton\symdata.xml c:\documents and settings\All Users\Application Data\NortonInstaller c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\10-22-2009-12h41m18s\Install.1.mft.7z c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\10-22-2009-12h41m18s\NortonInstall-10-22-2009-12h41m18s.log c:\documents and settings\All Users\Application Data\Symantec c:\documents and settings\All Users\Application Data\Symantec\symdata.xml C:\FOUND.014 c:\found.014\FILE0000.CHK c:\found.014\FILE0001.CHK c:\found.014\FILE0002.CHK c:\found.014\FILE0003.CHK c:\found.014\FILE0004.CHK c:\found.014\FILE0005.CHK c:\found.014\FILE0006.CHK c:\found.014\FILE0007.CHK c:\found.014\FILE0008.CHK c:\found.014\FILE0009.CHK c:\found.014\FILE0010.CHK c:\found.014\FILE0011.CHK c:\found.014\FILE0012.CHK c:\found.014\FILE0013.CHK c:\found.014\FILE0014.CHK C:\FOUND.015 c:\found.015\FILE0000.CHK c:\found.015\FILE0001.CHK C:\FOUND.016 c:\found.016\FILE0000.CHK c:\found.016\FILE0001.CHK c:\found.016\FILE0002.CHK c:\found.016\FILE0003.CHK c:\found.016\FILE0004.CHK c:\found.016\FILE0005.CHK c:\found.016\FILE0006.CHK c:\found.016\FILE0007.CHK c:\found.016\FILE0008.CHK c:\found.016\FILE0009.CHK c:\found.016\FILE0010.CHK c:\found.016\FILE0011.CHK c:\found.016\FILE0012.CHK c:\found.016\FILE0013.CHK c:\found.016\FILE0014.CHK c:\found.016\FILE0015.CHK c:\found.016\FILE0016.CHK C:\FOUND.017 c:\found.017\FILE0000.CHK c:\found.017\FILE0001.CHK c:\found.017\FILE0002.CHK c:\found.017\FILE0003.CHK c:\found.017\FILE0004.CHK c:\found.017\FILE0005.CHK c:\found.017\FILE0006.CHK c:\found.017\FILE0007.CHK c:\found.017\FILE0008.CHK c:\found.017\FILE0009.CHK c:\found.017\FILE0010.CHK c:\found.017\FILE0011.CHK c:\found.017\FILE0012.CHK c:\found.017\FILE0013.CHK c:\found.017\FILE0014.CHK c:\found.017\FILE0015.CHK c:\found.017\FILE0016.CHK c:\found.017\FILE0017.CHK c:\found.017\FILE0018.CHK c:\found.017\FILE0019.CHK c:\found.017\FILE0020.CHK c:\found.017\FILE0021.CHK c:\found.017\FILE0022.CHK c:\found.017\FILE0023.CHK C:\FOUND.018 c:\found.018\FILE0000.CHK c:\found.018\FILE0001.CHK C:\FOUND.019 c:\found.019\FILE0000.CHK c:\found.019\FILE0001.CHK c:\found.019\FILE0002.CHK c:\found.019\FILE0003.CHK c:\found.019\FILE0004.CHK c:\found.019\FILE0005.CHK c:\found.019\FILE0006.CHK c:\found.019\FILE0007.CHK c:\found.019\FILE0008.CHK c:\found.019\FILE0009.CHK c:\found.019\FILE0010.CHK c:\found.019\FILE0011.CHK c:\found.019\FILE0012.CHK C:\FOUND.020 c:\found.020\FILE0000.CHK c:\found.020\FILE0001.CHK C:\FOUND.021 c:\found.021\FILE0000.CHK c:\found.021\FILE0001.CHK c:\program files\Common Files\Symantec Shared c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\catalog.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\cceraser.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ecmsvr32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\eeCtrl.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.grd c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.sig c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.spm c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ERASER.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ESRDEF.BIN c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\hh c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\naveng.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\naveng32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\navex15.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\navex32a.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\ncsacert.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\scrauth.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\symaveng.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\symaveng.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\SymErase.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\SymErase.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCDEFS.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCSCAN7.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCSCAN8.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TCSCAN9.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\technote.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TINF.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\tinfidx.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TINFL.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\TSCAN1.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\tscan1hd.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\V.GRD c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\V.SIG c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\virscan.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN1.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN2.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN3.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN4.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN5.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN6.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN7.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN8.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\VIRSCAN9.DAT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\vscanmsx.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\WHATSNEW.TXT c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20091021.002\zdone.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\catalog.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\cceraser.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ecmsvr32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\eeCtrl.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.grd c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.sig c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.spm c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\esrdef.bin c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\hh c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\naveng.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\naveng32.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\navex15.sys c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\navex32a.dll c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ncsacert.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\scrauth.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\symaveng.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\symaveng.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\SymErase.cat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\SymErase.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcdefs.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcscan7.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcscan8.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tcscan9.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\technote.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tinf.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tinfidx.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tinfl.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tscan1.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\tscan1hd.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\v.grd c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\v.sig c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan.inf c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan1.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan2.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan3.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan4.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan5.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan6.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan7.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan8.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\virscan9.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\whatsnew.txt c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\zdone.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\definfo.dat c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\usage.dat c:\windows\BDOSCAN8 c:\windows\BDOSCAN8\bdcore.dll c:\windows\BDOSCAN8\bdoscan.ini c:\windows\BDOSCAN8\bdoscan.log c:\windows\BDOSCAN8\ipsupd.dll c:\windows\BDOSCAN8\lang.ini c:\windows\BDOSCAN8\libfn.dll c:\windows\BDOSCAN8\live.ini c:\windows\BDOSCAN8\oscan82.ocx c:\windows\BDOSCAN8\scanoptions.tsi c:\windows\BDOSCAN8\scanoptions.tsk c:\windows\system32\drivers\NSS c:\windows\system32\drivers\NSS\0203000.02C\isolate.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_FXDRV32 -------\Legacy_YTXYY -------\Service_FXDrv32 -------\Service_ytxyy ((((((((((((((((((((((((( Files Created from 2009-09-23 to 2009-10-23 ))))))))))))))))))))))))))))))) . 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 14:54 . 2009-09-10 11:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 14:54 . 2009-09-10 11:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 13:47 . 2009-10-23 13:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 13:47 . 2009-10-23 13:47 -------- d-----r- c:\program files\Skype 2009-10-22 20:39 . 2009-10-22 20:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\QuickTime 2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\3GP Video Converter 3 2009-10-22 15:03 . 2009-10-22 15:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 15:03 . 2009-10-22 15:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 14:54 . 2009-10-23 18:53 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 14:54 . 2009-10-23 18:53 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 14:54 . 2009-10-22 14:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 14:54 . 2009-10-22 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-21 22:32 . 2009-10-21 22:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-21 22:32 . 2009-10-21 22:32 -------- d-----w- c:\program files\SumatraPDF 2009-10-20 15:52 . 2009-10-20 15:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 15:40 . 2009-10-20 15:40 -------- d-----w- c:\windows\Sun 2009-10-20 15:39 . 2009-10-20 15:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 15:39 . 2009-10-20 15:39 -------- d-----w- c:\program files\Java 2009-10-20 14:57 . 2009-10-20 14:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 14:57 . 2009-10-20 14:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 14:44 . 2009-10-09 14:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 14:44 . 2009-10-09 14:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 14:42 . 2009-10-09 14:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 14:41 . 2009-10-09 14:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 14:41 . 2006-06-29 10:07 14048 ------w- c:\windows\system32\spmsg2.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-23 18:53 . 2009-10-22 14:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-10-23 18:53 . 2009-10-22 14:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-23 18:53 . 2007-10-25 02:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-22 15:18 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-10-09 15:00 . 2007-10-18 18:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-18 16:15 . 2009-09-18 16:15 -------- d-----w- c:\program files\BORLANDC 2009-08-06 16:24 . 2007-10-18 17:35 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-06 16:24 . 2007-10-18 17:35 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-06 16:24 . 2007-10-18 17:35 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-06 16:24 . 2007-07-30 16:19 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-06 16:24 . 2007-10-18 17:35 53472 ------w- c:\windows\system32\wuauclt.exe 2009-08-06 16:24 . 2008-11-21 16:33 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-06 16:23 . 2007-10-18 17:35 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-06 16:23 . 2007-10-18 17:35 1929952 ----a-w- c:\windows\system32\wuaueng.dll . ((((((((((((((((((((((((((((( SnapShot@2009-10-23_16.51.20 ))))))))))))))))))))))))))))))))))))))))) . + 2009-10-23 18:54 . 2009-10-23 18:54 16384 c:\windows\temp\Perflib_Perfdata_4a4.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\winmm.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8018:TCP"= 8018:TCP:WWW R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### . - - - - ORPHANS REMOVED - - - - AddRemove-HijackThis - c:\documents and settings\DUDU\Desktop\HijackThis.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-23 21:54 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3272) c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\tempo\CF30448.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE c:\tempo\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-23 21:57 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-23 18:57 ComboFix2.txt 2009-10-23 16:53 Pre-Run: 10 243 670 016 bytes free Post-Run: 10 191 372 288 bytes free - - End Of File - - 31F3886F954603B89FE30B065D4AADA6
  15. ComboFix 09-10-22.01 - DUDU 10.2009 г. 19:46.1.2 - FAT32x86 Running from: c:\documents and settings\DUDU\desktop\ComboFix.exe Command switches used :: /KillAll * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_OREANS32 -------\Service_oreans32 ((((((((((((((((((((((((( Files Created from 2009-09-23 to 2009-10-23 ))))))))))))))))))))))))))))))) . 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\documents and settings\DUDU\Application Data\Malwarebytes 2009-10-23 14:54 . 2009-09-10 11:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-23 14:54 . 2009-09-10 11:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-23 14:54 . 2009-10-23 14:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-23 14:45 . 2009-10-23 14:45 -------- d-----w- C:\FOUND.021 2009-10-23 14:35 . 2009-10-23 14:35 -------- d-----w- C:\FOUND.020 2009-10-23 14:27 . 2009-10-23 14:27 -------- d-----w- C:\FOUND.019 2009-10-23 13:47 . 2009-10-23 13:47 -------- d-----w- c:\program files\Common Files\Skype 2009-10-23 13:47 . 2009-10-23 13:47 -------- d-----r- c:\program files\Skype 2009-10-23 13:43 . 2009-10-23 13:43 -------- d-----w- C:\FOUND.018 2009-10-23 13:35 . 2009-10-23 13:35 -------- d-----w- C:\FOUND.017 2009-10-22 20:39 . 2009-10-22 20:39 -------- d-----w- c:\program files\CCleaner 2009-10-22 20:23 . 2009-10-22 20:23 -------- d-----w- C:\FOUND.016 2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\QuickTime 2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\3GP Video Converter 3 2009-10-22 15:03 . 2009-10-22 15:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-22 15:03 . 2009-10-22 15:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-22 14:54 . 2009-10-23 16:50 46624 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-22 14:54 . 2009-10-23 16:50 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-22 14:54 . 2009-10-22 14:54 -------- d-----w- c:\program files\Kaspersky Lab 2009-10-22 14:54 . 2009-10-22 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-22 09:42 . 2009-10-22 09:42 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-10-22 09:41 . 2009-10-22 09:41 -------- d-----w- c:\windows\system32\drivers\NSS 2009-10-22 09:41 . 2009-10-22 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2009-10-22 09:41 . 2009-10-22 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2009-10-22 09:41 . 2009-10-22 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2009-10-22 09:20 . 2009-10-22 09:20 -------- d-----w- c:\windows\BDOSCAN8 2009-10-21 22:32 . 2009-10-21 22:32 -------- d-----w- c:\documents and settings\DUDU\Application Data\SumatraPDF 2009-10-21 22:32 . 2009-10-21 22:32 -------- d-----w- c:\program files\SumatraPDF 2009-10-20 16:43 . 2009-10-20 16:43 -------- d-----w- C:\$AVG 2009-10-20 15:52 . 2009-10-20 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9 2009-10-20 15:52 . 2009-10-20 15:52 -------- d-----w- c:\windows\SxsCaPendDel 2009-10-20 15:40 . 2009-10-20 15:40 -------- d-----w- c:\windows\Sun 2009-10-20 15:39 . 2009-10-20 15:39 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-20 15:39 . 2009-10-20 15:39 -------- d-----w- c:\program files\Java 2009-10-20 14:57 . 2009-10-20 14:57 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS 2009-10-20 14:57 . 2009-10-20 14:57 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\eSupport.com 2009-10-19 09:13 . 2009-10-19 09:13 -------- d-----w- C:\FOUND.015 2009-10-12 14:21 . 2009-10-12 14:21 -------- d-----w- C:\FOUND.014 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\program files\Common Files\Autodesk Shared 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\program files\AutoCAD LT 2009 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\DUDU\Local Settings\Application Data\Autodesk 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\DUDU\Application Data\Autodesk 2009-10-09 14:45 . 2009-10-09 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk 2009-10-09 14:44 . 2009-10-09 14:45 -------- d-----w- c:\program files\MSBuild 2009-10-09 14:44 . 2009-10-09 14:44 108552 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-09 14:42 . 2009-10-09 14:42 -------- d-----w- c:\windows\system32\XPSViewer 2009-10-09 14:41 . 2009-10-09 14:41 -------- d-----w- c:\program files\Reference Assemblies 2009-10-09 14:41 . 2006-06-29 10:07 14048 ------w- c:\windows\system32\spmsg2.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-23 16:50 . 2009-10-22 14:54 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-10-23 16:50 . 2009-10-22 14:54 1444 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-23 16:50 . 2007-10-25 02:13 12 ----a-w- c:\windows\bthservsdp.dat 2009-10-22 15:18 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-10-09 15:00 . 2007-10-18 18:20 72584 ----a-w- c:\documents and settings\DUDU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-18 16:15 . 2009-09-18 16:15 -------- d-----w- c:\program files\BORLANDC 2009-08-06 16:24 . 2007-10-18 17:35 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-06 16:24 . 2007-10-18 17:35 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-06 16:24 . 2007-10-18 17:35 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-06 16:24 . 2007-07-30 16:19 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-06 16:24 . 2007-10-18 17:35 53472 ----a-w- c:\windows\system32\wuauclt.exe 2009-08-06 16:24 . 2008-11-21 16:33 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-06 16:23 . 2007-10-18 17:35 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-06 16:23 . 2007-10-18 17:35 1929952 ----a-w- c:\windows\system32\wuaueng.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936] "DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-20 149280] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-22 208616] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-11-17 1622016] "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\winmm.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Avant Browser\\avant.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "8018:TCP"= 8018:TCP:WWW R2 ytxyy;ytxyy;c:\windows\system32\svchost.exe [2004-08-03 14336] R3 FXDrv32;FXDrv32;H:\FXDrv32.sys [x] R3 GarenaPEngine;GarenaPEngine;c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp [x] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-22 33808] S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 11264] S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: &Сваляне на всички с FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Сваляне с FlashGet - c:\program files\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 TCP: {92A948B5-F3FB-4643-9AA9-1785A9243BCC} = 78.90.92.1,89.190.192.162 FF - ProfilePath - c:\documents and settings\DUDU\Application Data\Mozilla\Firefox\Profiles\1m1k4rbd.default\ FF - prefs.js: browser.startup.homepage - ###### . - - - - ORPHANS REMOVED - - - - Notify-avldr - avldr.dll AddRemove-NSS - c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.3.0.44\InstStub.exe AddRemove-Counter Stike 1.6 Install - c:\games\Counter Strike\Uninstal.exe AddRemove-{C8C8387B-A98B-44E8-807A-1A9B7F51FFDA} - c:\documents and settings\DUDU\Local Settings\Application Data\{737AEA7B-5AB3-4A1C-BC5A-EAAB803F2D97}\setup_blazemp.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-23 19:51 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\DUDU\LOCALS~1\Temp\IJA3FE6.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(4076) c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\combofix\CF26973.exe c:\program files\BlueSoleil\BTNtService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE c:\combofix\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-23 19:53 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-23 16:53 Pre-Run: 9 729 507 328 bytes free Post-Run: 10 232 856 576 bytes free - - End Of File - - 18A73DF9572C63E77B7B07520ADAAE08 А и да допълня нещо, и в момента компютъра ми се пуска само на debugging mode, като видимо работи добре.
  16. Компютърът ми забива при пускане или опит за деинсталация на скайп. Вчера май отворих някакъв вирус и екрана стана син, после компютърът не искаше да се пуска дори на safe mode, но за щастие се пусна на debugging mode и тогава инсталирах Kaspersky (преди това бях с AVG Free, която няколко години ми върши добра работа), той намери два троянски конника и по всичко личеше, че всичко е наред, докато не пуснах скайп... Malwarebytes' Anti-Malware 1.41 Версия на базата от данни: 3019 Windows 5.1.2600 Service Pack 2 23.10.2009 г. 18:21:56 mbam-log-2009-10-23 (18-21-56).txt Тип сканиране: Пълно сканиране (C:\|Z:\|) Сканирани обекти: 196546 Изминало време: 25 minute(s), 23 second(s) Заразени процеси в паметта: 0 Заразени модули в паметта: 0 Заразени ключове в регистратурата: 1 Заразени стойности в регистратурата: 0 Заразени информационни обекти в регистратурата: 0 Заразени папки: 0 Заразени файлове: 2 Заразени процеси в паметта: (Не бяха открити заплахи) Заразени модули в паметта: (Не бяха открити заплахи) Заразени ключове в регистратурата: HKEY_CURRENT_USER\SOFTWARE\advantage (Adware.Vomba) -> Quarantined and deleted successfully. Заразени стойности в регистратурата: (Не бяха открити заплахи) Заразени информационни обекти в регистратурата: (Не бяха открити заплахи) Заразени папки: (Не бяха открити заплахи) Заразени файлове: C:\WINDOWS\system32\drivers\oreans32.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\Reinstall\NOD32 Complete Software 2008 -4in1- (AIO)\NOD32 Complete 2008\Antivirus\Nod32Patch.exe (Trojan.Agent) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:23:16, on 23.10.2009 г. Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe C:\Program Files\BlueSoleil\BTNtService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\DUDU\Desktop\Kaldata.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll O2 - BHO: (no name) - {9018F6A8-2495-45DF-9F16-C738F8F3C8FF} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\S-1-5-21-842925246-854245398-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Сваляне на всички с FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Сваляне с FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{92A948B5-F3FB-4643-9AA9-1785A9243BCC}: NameServer = 78.90.92.1,89.190.192.162 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: winmm.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 6718 bytes

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.