Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Vladimirov92

Потребител
  • Регистрация

  • Последно онлайн

Всичко публикувано от Vladimirov92

  1. :? Тука примерно става ли и какво да въведа ? Ето и от OTL.exe All processes killed ========== FILES ========== C:\DOCUME~1\Vladimir\LOCALS~1\temp\c.exe moved successfully. C:\WINDOWS\msa.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 16384 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Vladimir ->Temp folder emptied: 32477610 bytes ->Temporary Internet Files folder emptied: 96165 bytes ->FireFox cache emptied: 46127630 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 33792 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 75,22 mb OTL by OldTimer - Version 3.1.15.1 log created on 12112009_213636 Files\Folders moved on Reboot... Registry entries deleted on Reboot...
  2. SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** Process: Name: [system Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\smss.exe PID: 568 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\csrss.exe PID: 648 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\winlogon.exe PID: 672 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 728 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\lsass.exe PID: 740 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 912 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 972 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1072 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1152 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1248 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\spoolsv.exe PID: 1480 Hidden: No Window Visible: No Name: C:\WINDOWS\explorer.exe PID: 1652 Hidden: No Window Visible: No Name: C:\DOCUME~1\Vladimir\LOCALS~1\temp\c.exe PID: 192 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\nvraidservice.exe PID: 240 Hidden: No Window Visible: No Name: C:\WINDOWS\msa.exe PID: 252 Hidden: No Window Visible: No Name: C:\WINDOWS\SOUNDMAN.EXE PID: 268 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\rundll32.exe PID: 280 Hidden: No Window Visible: No Name: C:\Program Files\Winamp\winampa.exe PID: 308 Hidden: No Window Visible: No Name: C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe PID: 316 Hidden: No Window Visible: No Name: C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe PID: 340 Hidden: No Window Visible: No Name: C:\Program Files\Datecs\FlexType 2K\FType2K.exe PID: 432 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\nvsvc32.exe PID: 540 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wdfmgr.exe PID: 588 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\alg.exe PID: 224 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wbem\wmiprvse.exe PID: 556 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wbem\unsecapp.exe PID: 1176 Hidden: No Window Visible: No Name: C:\Program Files\PC Connectivity Solution\ServiceLayer.exe PID: 1844 Hidden: No Window Visible: No Name: C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe PID: 1912 Hidden: No Window Visible: No Name: C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe PID: 968 Hidden: No Window Visible: No Name: C:\Program Files\Mozilla Firefox\firefox.exe PID: 1976 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\wuauclt.exe PID: 2444 Hidden: No Window Visible: No Name: C:\Documents and Settings\Vladimir\Desktop\SysProt\SysProt.exe PID: 2496 Hidden: No Window Visible: Yes Name: C:\WINDOWS\system32\wuauclt.exe PID: 2504 Hidden: No Window Visible: No ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \??\C:\Documents and Settings\Vladimir\Desktop\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: F6C3D000 Module End: F6C48000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS Service Name: Fastfat Module Base: B9674000 Module End: B9698000 Hidden: No Module Name: \WINDOWS\system32\ntkrnlpa.exe Service Name: --- Module Base: 804D7000 Module End: 806CF580 Hidden: No Module Name: \WINDOWS\system32\hal.dll Service Name: --- Module Base: 806D0000 Module End: 806F0300 Hidden: No Module Name: \WINDOWS\system32\KDCOM.DLL Service Name: --- Module Base: F7ADC000 Module End: F7ADE000 Hidden: No Module Name: \WINDOWS\system32\BOOTVID.dll Service Name: --- Module Base: F79EC000 Module End: F79EF000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ACPI.sys Service Name: ACPI Module Base: F74AD000 Module End: F74DB000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS Service Name: --- Module Base: F7ADE000 Module End: F7AE0000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pci.sys Service Name: PCI Module Base: F749C000 Module End: F74AD000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\isapnp.sys Service Name: isapnp Module Base: F75DC000 Module End: F75E6000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PCIIde.sys Service Name: PCIIde Module Base: F7BA4000 Module End: F7BA5000 Hidden: No Module Name: \WINDOWS\System32\Drivers\PCIIDEX.SYS Service Name: --- Module Base: F785C000 Module End: F7863000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys Service Name: MountMgr Module Base: F75EC000 Module End: F75F7000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys Service Name: Disk Module Base: F747D000 Module End: F749C000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\dmload.sys Service Name: dmload Module Base: F7AE0000 Module End: F7AE2000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\dmio.sys Service Name: dmio Module Base: F7457000 Module End: F747D000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\nvraid.sys Service Name: nvraid Module Base: F7446000 Module End: F7457000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS Service Name: --- Module Base: F75FC000 Module End: F7609000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys Service Name: PartMgr Module Base: F7864000 Module End: F7869000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys Service Name: VolSnap Module Base: F760C000 Module End: F7619000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\atapi.sys Service Name: atapi Module Base: F742E000 Module End: F7446000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\nvatabus.sys Service Name: nvatabus Module Base: F741A000 Module End: F742E000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\disk.sys Service Name: --- Module Base: F761C000 Module End: F7625000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys Service Name: FltMgr Module Base: F73FA000 Module End: F741A000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys Service Name: PxHelp20 Module Base: F762C000 Module End: F7636000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys Service Name: KSecDD Module Base: F73E3000 Module End: F73FA000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys Service Name: Ntfs Module Base: F7356000 Module End: F73E3000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\NDIS.sys Service Name: NDIS Module Base: F7329000 Module End: F7356000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\nv_agp.sys Service Name: nv_agp Module Base: F786C000 Module End: F7872000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Mup.sys Service Name: Mup Module Base: F730F000 Module End: F7329000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\AmdK8.sys Service Name: AmdK8 Module Base: F76AC000 Module End: F76BB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbohci.sys Service Name: usbohci Module Base: F79AC000 Module End: F79B1000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS Service Name: --- Module Base: F6BA9000 Module End: F6BCD000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: F79B4000 Module End: F79BC000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys Service Name: nvnetbus Module Base: F7AB4000 Module End: F7AB8000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\NVNRM.SYS Service Name: --- Module Base: F76BC000 Module End: F76CB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\NVSNPU.SYS Service Name: --- Module Base: F6B7A000 Module End: F6BA9000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ALCXWDM.SYS Service Name: ALCXWDM Module Base: F6677000 Module End: F68AA000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\portcls.sys Service Name: --- Module Base: F6653000 Module End: F6677000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\drmk.sys Service Name: --- Module Base: F6C2D000 Module End: F6C3C000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ks.sys Service Name: --- Module Base: F6630000 Module End: F6653000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys Service Name: Imapi Module Base: F6C1D000 Module End: F6C28000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys Service Name: Cdrom Module Base: F6C0D000 Module End: F6C1D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys Service Name: redbook Module Base: F6BFD000 Module End: F6C0C000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys Service Name: nv Module Base: F6323000 Module End: F6630000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS Service Name: --- Module Base: F630F000 Module End: F6323000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\serial.sys Service Name: Serial Module Base: F6BED000 Module End: F6BFD000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\serenum.sys Service Name: serenum Module Base: F7AC4000 Module End: F7AC8000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\parport.sys Service Name: Parport Module Base: F62FB000 Module End: F630F000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys Service Name: i8042prt Module Base: F6BDD000 Module End: F6BEA000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys Service Name: Mouclass Module Base: F788C000 Module End: F7892000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys Service Name: Kbdclass Module Base: F7894000 Module End: F789A000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys Service Name: audstub Module Base: F7D0B000 Module End: F7D0C000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: F6BCD000 Module End: F6BDA000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: F7AC8000 Module End: F7ACB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: F62E4000 Module End: F62FB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: F775C000 Module End: F7767000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: F776C000 Module End: F7778000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS Service Name: --- Module Base: F789C000 Module End: F78A1000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys Service Name: PSched Module Base: F6233000 Module End: F6244000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys Service Name: Gpc Module Base: F777C000 Module End: F7785000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys Service Name: Ptilink Module Base: F78A4000 Module End: F78A9000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys Service Name: Raspti Module Base: F78AC000 Module End: F78B1000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys Service Name: rdpdr Module Base: F6203000 Module End: F6233000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys Service Name: TermDD Module Base: F778C000 Module End: F7796000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys Service Name: swenum Module Base: F7AF6000 Module End: F7AF8000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\update.sys Service Name: Update Module Base: F617D000 Module End: F61DB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: F72E3000 Module End: F72E7000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: F77EC000 Module End: F77F6000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: F77FC000 Module End: F780B000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS Service Name: --- Module Base: F7B10000 Module End: F7B12000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys Service Name: NVENETFD Module Base: F4954000 Module End: F495D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\flpydisk.sys Service Name: Flpydisk Module Base: F443E000 Module End: F4443000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Service Name: Fs_Rec Module Base: F7B68000 Module End: F7B6A000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Null.SYS Service Name: Null Module Base: F444F000 Module End: F4450000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS Service Name: Beep Module Base: F7B6A000 Module End: F7B6C000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\vga.sys Service Name: VgaSave Module Base: F442E000 Module End: F4434000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS Service Name: mnmdd Module Base: F7B6C000 Module End: F7B6E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: F7B6E000 Module End: F7B70000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: F4426000 Module End: F442B000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: F441E000 Module End: F4426000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: F4BA5000 Module End: F4BA8000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys Service Name: IPSec Module Base: F1F21000 Module End: F1F34000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys Service Name: Tcpip Module Base: F1EC8000 Module End: F1F21000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys Service Name: NetBT Module Base: F1EA0000 Module End: F1EC8000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\afd.sys Service Name: AFD Module Base: F1E7E000 Module End: F1EA0000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: F4573000 Module End: F457C000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys Service Name: Rdbss Module Base: F1E53000 Module End: F1E7E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys Service Name: MRxSmb Module Base: F1DE3000 Module End: F1E53000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS Service Name: Fips Module Base: F4553000 Module End: F455E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys Service Name: IpNat Module Base: F1DBD000 Module End: F1DE3000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: F4543000 Module End: F454C000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys Service Name: hidusb Module Base: F44CB000 Module End: F44CE000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS Service Name: --- Module Base: F4533000 Module End: F453C000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS Service Name: --- Module Base: F4416000 Module End: F441D000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS Service Name: Cdfs Module Base: EEA7E000 Module End: EEA8E000 Hidden: No Module Name: \SystemRoot\System32\Drivers\dump_nvatabus.sys Service Name: --- Module Base: EE336000 Module End: EE34A000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: EE362000 Module End: EE364000 Hidden: Yes Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys Service Name: --- Module Base: F439C000 Module End: F439F000 Hidden: No Module Name: C:\WINDOWS\System32\watchdog.sys Service Name: --- Module Base: F420D000 Module End: F4212000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys Service Name: --- Module Base: F7BB3000 Module End: F7BB4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: F7AA8000 Module End: F7AAC000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys Service Name: wdmaud Module Base: BA54B000 Module End: BA560000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys Service Name: sysaudio Module Base: EE534000 Module End: EE543000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys Service Name: MRxDAV Module Base: BA3B6000 Module End: BA3E3000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS Service Name: ParVdm Module Base: F7B94000 Module End: F7B96000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys Service Name: Srv Module Base: BA2C4000 Module End: BA316000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys Service Name: HTTP Module Base: BA1E3000 Module End: BA224000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\fdc.sys Service Name: Fdc Module Base: F7884000 Module End: F788B000 Hidden: No ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** No IRP Hooks found ****************************************************************************************** ****************************************************************************************** Ports: Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1148 Remote Address: 74.125.97.24:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1147 Remote Address: EW-IN-F100.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1146 Remote Address: HOST-212-75-5-143.BBCCABLE.NET:NETBIOS-SSN Type: TCP Process: [system Idle Process] State: TIME_WAIT Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1145 Remote Address: 80.97.209.25:HTTP Type: TCP Process: C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1140 Remote Address: 168.75.207.20:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1137 Remote Address: 168.75.207.20:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1135 Remote Address: 80.97.209.10:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1130 Remote Address: EW-IN-F100.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1094 Remote Address: WW-IN-F154.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1071 Remote Address: WW-IN-F154.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1070 Remote Address: WW-IN-F154.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1061 Remote Address: WW-IN-F154.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1044 Remote Address: WW-IN-F99.1E100.NET:HTTP Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1032 Remote Address: 80.97.209.25:HTTP Type: TCP Process: [system Idle Process] State: TIME_WAIT Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: VLADIMIR-8DDE1D:1043 Remote Address: LOCALHOST:1042 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D:1042 Remote Address: LOCALHOST:1043 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D:1034 Remote Address: LOCALHOST:1033 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D:1033 Remote Address: LOCALHOST:1034 Type: TCP Process: C:\Program Files\Mozilla Firefox\firefox.exe State: ESTABLISHED Local Address: VLADIMIR-8DDE1D:1029 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\alg.exe State: LISTENING Local Address: VLADIMIR-8DDE1D:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: VLADIMIR-8DDE1D:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: VLADIMIR-8DDE1D.SERVU1.BBCCABLE.NET:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: VLADIMIR-8DDE1D:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: VLADIMIR-8DDE1D:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: VLADIMIR-8DDE1D:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: VLADIMIR-8DDE1D:1041 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: VLADIMIR-8DDE1D:1031 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: VLADIMIR-8DDE1D:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: VLADIMIR-8DDE1D:MICROSOFT-DS Remote Address: NA Type: UDP Process: System State: NA ****************************************************************************************** ****************************************************************************************** No hidden files/folders found
  3. Като го пусна да сканирва и компа забива ..
  4. Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully kernel: MBR read successfully user & kernel MBR OK ???
  5. Днес по едно време ми се появи тва..
  6. Ще направя още каквото трябва ) Айде лека,че даскало ме чака утре И още веднъж Благодаря !
  7. Лека и от мен.Пак ти благодаря спести ми много главоболия.В България рядко се срещат хора като теб да помагат така .. Евала ! Ако има нещо в бъдеще ще пиша )
  8. Ето лога от Security Check Results of screen317's Security Check version 0.99.1 Windows XP Service Pack 2 Out of date service pack!! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! ESET Online Scanner v3 WMIC entry does not exist for antivirus; attempting automatic update. `````````````````````````````` Anti-malware/Other Utilities Check: HijackThis 2.0.2 Adobe Flash Player 10 `````````````````````````````` Process Check: objlist.exe by Laurent `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` Значи компа сега е пушка.. до одеве преди всичките процеси направо насичаше и бях се отчаял .. ЕДНО ГОЛЯМО БЛАГОДАРЯ ЗА СЪВЕТИТЕ И ПОМОЩТА! ВЕЛИК СИ !!
  9. Така.. Тук проверка на C:\ и D:\ Malwarebytes' Anti-Malware 1.42 Database version: 3340 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 10.12.2009 г. 23:46:41 mbam-log-2009-12-10 (23-46-39).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 181819 Time elapsed: 31 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Vladimir\My Documents\Downloads\Winamp 5.56 Build 2512\Big and sure KeyGenerator.exe (Trojan.Downloader) -> No action taken. C:\System Volume Information\_restore{3BE0E642-8453-438B-A29E-16EC3DDBD71A}\RP2\A0002354.sys (Rootkit.Agent) -> No action taken. C:\System Volume Information\_restore{3BE0E642-8453-438B-A29E-16EC3DDBD71A}\RP2\A0002540.sys (Rootkit.Agent) -> No action taken. C:\System Volume Information\_restore{3BE0E642-8453-438B-A29E-16EC3DDBD71A}\RP2\A0002610.sys (Rootkit.Agent) -> No action taken. D:\System Volume Information\_restore{3BE0E642-8453-438B-A29E-16EC3DDBD71A}\RP2\A0002730.exe (Malware.Packer) -> No action taken. И съответно в E:\|F:\|G: Malwarebytes' Anti-Malware 1.42 Database version: 3340 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 10.12.2009 г. 23:14:13 mbam-log-2009-12-10 (23-14-10).txt Scan type: Full Scan (E:\|F:\|G:\|) Objects scanned: 167337 Time elapsed: 23 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: G:\PRograms\Malwarebytes Anti-Malware 1.28 + Keygen\keygen.exe (Trojan.Downloader) -> No action taken. ---------------------------------------------- HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:48:33, on 10.12.2009 г. Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvraidservice.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Winamp\winampa.exe C:\Program Files\Datecs\FlexType 2K\FType2K.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Trend Micro\HijackThis\Kaldata.exe..exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O4 - Global Startup: FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 2649 bytes
  10. Това е лог-а след ЕСЕТ-а като искам да добавя,че един път се рестартира компютъра по време на сканирането @High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=c3baa43738bca04a9c189f850c5e228a # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-10 08:32:11 # local_time=2009-12-10 10:32:11 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=8192 67108863 100 0 7071 7071 0 0 # scanned=12928 # found=0 # cleaned=0 # scan_time=621 ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251
  11. http://rapidshare.de/files/48817754/_OTL.rar.html След малко ще постна и другите работи (още сканира ЕСЕТ-а )
  12. OTL logfile created on: 10.12.2009 г. 21:14:41 - Run 3 OTL by OldTimer - Version 3.1.14.0 Folder = C:\Documents and Settings\Vladimir\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1023,48 Mb Total Physical Memory | 616,04 Mb Available Physical Memory | 60,19% Memory free 2,40 Gb Paging File | 2,14 Gb Available in Paging File | 89,11% Paging File free Paging file location(s): c:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 11,72 Gb Total Space | 8,46 Gb Free Space | 72,15% Space Free | Partition Type: NTFS Drive D: | 32,23 Gb Total Space | 7,50 Gb Free Space | 23,29% Space Free | Partition Type: NTFS Drive E: | 32,37 Gb Total Space | 1,67 Gb Free Space | 5,15% Space Free | Partition Type: NTFS Drive F: | 39,07 Gb Total Space | 12,93 Gb Free Space | 33,09% Space Free | Partition Type: NTFS Drive G: | 37,60 Gb Total Space | 11,66 Gb Free Space | 31,01% Space Free | Partition Type: NTFS H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: VLADIMIR-8DDE1D Current User Name: Vladimir Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Vladimir\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Winamp\winampa.exe () PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies) PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation) PRC - C:\Program Files\Datecs\FlexType 2K\FType2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Vladimir\Desktop\OTL.exe (OldTimer Tools) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation) MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (NVSvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) ========== Driver Services (SafeList) ========== DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation) DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.) DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices) DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys () DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.) DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation) DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation) DRV - (nvraid) NVIDIA NForce -- C:\WINDOWS\system32\DRIVERS\nvraid.sys (NVIDIA Corporation) DRV - (nvatabus) -- C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation) DRV - (GVCplDrv) -- C:\WINDOWS\system32\drivers\GVCplDrv.sys () DRV - (nv_agp) -- C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-776561741-1563985344-839522115-1003\S-1-5-21-776561741-1563985344-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.12.10 16:44:53 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009.12.10 16:44:49 | 00,000,000 | ---D | M] [2009.12.10 16:44:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Vladimir\Application Data\Mozilla\Extensions [2009.12.10 16:44:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\j4026pxg.default\extensions [2009.12.10 17:01:52 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2008.10.24 19:34:06 | 00,001,083 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\911bg.xml [2008.10.24 19:34:06 | 00,002,442 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\diribg.xml [2008.10.24 19:34:06 | 00,001,515 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pe-bg.xml [2008.10.24 19:34:06 | 00,001,857 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\portalbgdict.xml [2008.10.24 19:34:06 | 00,001,220 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-bg.xml O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation) O4 - HKLM..\Run: [soundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation) O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-776561741-1563985344-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-776561741-1563985344-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-776561741-1563985344-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-776561741-1563985344-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-776561741-1563985344-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.91.210.2 213.91.210.3 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.12.10 15:53:06 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2009.12.10 20:46:03 | 00,000,000 | -HSD | C] -- C:\RECYCLER [2009.12.10 20:46:02 | 00,000,000 | ---D | C] -- C:\_OTL [2009.12.10 20:13:05 | 00,537,600 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Vladimir\Desktop\OTL.exe [2009.12.10 19:36:31 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp [2009.12.10 17:56:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss [2009.12.10 17:42:42 | 00,000,000 | -HSD | C] -- C:\WINDOWS\Installer [2009.12.10 17:42:41 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC [2009.12.10 17:42:38 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines [2009.12.10 17:42:38 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared [2009.12.10 17:42:37 | 00,000,000 | R--D | C] -- C:\Program Files [2009.12.10 17:42:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files [2009.12.10 17:42:14 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu [2009.12.10 17:42:14 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents [2009.12.10 17:42:14 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates [2009.12.10 17:42:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites [2009.12.10 17:42:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop [2009.12.10 17:42:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2 [2009.12.10 17:42:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot [2009.12.10 17:41:54 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft [2009.12.10 17:41:54 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data [2009.12.10 17:41:35 | 00,000,000 | -HSD | C] -- C:\System Volume Information [2009.12.10 17:41:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings [2009.12.10 17:39:31 | 00,000,000 | ---D | C] -- C:\Program Files\NortonInstaller [2009.12.10 17:39:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller [2009.12.10 17:34:32 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts [2009.12.10 17:34:32 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache [2009.12.10 17:34:32 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web [2009.12.10 17:34:32 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32 [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32 [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\system [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\security [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Provisioning [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\PeerNet [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\pchealth [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\java [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\ehome [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi [2009.12.10 17:34:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033 [2009.12.10 17:30:34 | 00,000,000 | RHSD | C] -- C:\cmdcons [2009.12.10 17:29:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009.12.10 17:18:38 | 76,846,000 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Vladimir\Desktop\NAV10TBEN.exe [2009.12.10 17:11:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\RegisteredPackages [2009.12.10 17:10:25 | 00,000,000 | ---D | C] -- C:\Program Files\Winamp [2009.12.10 17:10:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\Winamp [2009.12.10 17:09:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\My Documents\Downloads [2009.12.10 17:09:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\uTorrent [2009.12.10 17:02:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\My Documents\The KMPlayer [2009.12.10 17:00:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\utorrent [2009.12.10 17:00:08 | 00,000,000 | ---D | C] -- C:\Program Files\utorrent [2009.12.10 16:56:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\skypePM [2009.12.10 16:52:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Local Settings\Application Data\Identities [2009.12.10 16:51:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\Skype [2009.12.10 16:51:28 | 00,000,000 | ---D | C] -- C:\Program Files\Skype [2009.12.10 16:51:28 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2009.12.10 16:51:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype [2009.12.10 16:46:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\Macromedia [2009.12.10 16:46:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\Adobe [2009.12.10 16:44:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Local Settings\Application Data\Mozilla [2009.12.10 16:44:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\Mozilla [2009.12.10 16:44:48 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2009.12.10 16:44:28 | 00,000,000 | ---D | C] -- C:\Program Files\The KMPlayer [2009.12.10 16:43:53 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang [2009.12.10 16:41:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch [2009.12.10 16:40:05 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll [2009.12.10 16:40:05 | 00,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll [2009.12.10 16:40:05 | 00,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll [2009.12.10 16:39:02 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll [2009.12.10 16:39:02 | 00,045,056 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll [2009.12.10 16:39:02 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll [2009.12.10 16:38:50 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys [2009.12.10 16:08:36 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek Sound Manager [2009.12.10 16:08:33 | 00,000,000 | ---D | C] -- C:\Program Files\AvRack [2009.12.10 16:07:53 | 00,000,000 | ---D | C] -- C:\Program Files\AMD [2009.12.10 16:07:52 | 00,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information [2009.12.10 16:05:58 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups [2009.12.10 16:05:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\WinRAR [2009.12.10 16:04:44 | 00,000,000 | ---D | C] -- C:\Program Files\Datecs [2009.12.10 16:04:30 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR [2009.12.10 16:02:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles [2009.12.10 16:00:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview [2009.12.10 15:59:51 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield [2009.12.10 15:57:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Application Data\Identities [2009.12.10 15:57:30 | 00,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information [2009.12.10 15:57:27 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Vladimir\My Documents\My Pictures [2009.12.10 15:57:27 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Vladimir\My Documents\My Music [2009.12.10 15:57:23 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Vladimir\Application Data\Microsoft [2009.12.10 15:57:23 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Vladimir\Cookies [2009.12.10 15:57:23 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Vladimir\Application Data [2009.12.10 15:57:23 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Vladimir\My Documents [2009.12.10 15:57:23 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Vladimir\Favorites [2009.12.10 15:57:23 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Vladimir\Local Settings [2009.12.10 15:57:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Local Settings\Application Data\Microsoft [2009.12.10 15:57:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vladimir\Desktop [2009.12.10 15:57:22 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Vladimir\SendTo [2009.12.10 15:57:22 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Vladimir\Recent [2009.12.10 15:57:22 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Vladimir\Start Menu [2009.12.10 15:57:22 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Vladimir\Templates [2009.12.10 15:57:22 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Vladimir\PrintHood [2009.12.10 15:57:22 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Vladimir\NetHood [2009.12.10 15:56:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution [2009.12.10 15:56:44 | 00,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft [2009.12.10 15:56:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2009.12.10 15:56:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.12.10 15:53:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom [2009.12.10 15:53:26 | 00,000,000 | ---D | C] -- C:\Program Files\xerox [2009.12.10 15:53:25 | 00,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage [2009.12.10 15:52:58 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009.12.10 15:52:58 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2009.12.10 15:52:02 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM [2009.12.10 15:51:51 | 00,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files [2009.12.10 15:51:51 | 00,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages [2009.12.10 15:51:39 | 00,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate [2009.12.10 15:51:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX [2009.12.10 15:50:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Services [2009.12.10 15:50:52 | 00,000,000 | --SD | C] -- C:\WINDOWS\Tasks [2009.12.10 15:50:51 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap [2009.12.10 15:50:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\srchasst [2009.12.10 15:50:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed [2009.12.10 15:50:40 | 00,000,000 | ---D | C] -- C:\Program Files\Movie Maker [2009.12.10 15:50:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore [2009.12.10 15:50:30 | 00,000,000 | ---D | C] -- C:\Program Files\NetMeeting [2009.12.10 15:50:27 | 00,000,000 | ---D | C] -- C:\Program Files\Outlook Express [2009.12.10 15:50:21 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\System [2009.12.10 15:50:19 | 00,000,000 | ---D | C] -- C:\Program Files\Internet Explorer [2009.12.10 15:50:18 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures [2009.12.10 15:49:41 | 00,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications [2009.12.10 15:49:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\Registration [2009.12.10 15:49:25 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music [2009.12.10 15:49:25 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Media Player [2009.12.10 15:49:25 | 00,000,000 | ---D | C] -- C:\Program Files\Online Services [2009.12.10 15:49:16 | 00,000,000 | ---D | C] -- C:\Program Files\Messenger [2009.12.10 15:49:11 | 00,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone [2009.12.10 15:48:34 | 00,000,000 | ---D | C] -- C:\Program Files\MSN [2009.12.10 15:48:33 | 00,281,088 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe [2009.12.10 15:48:31 | 00,000,000 | ---D | C] -- C:\Program Files\Windows NT [2009.12.10 15:48:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc [2009.12.10 15:48:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Com [2009.12.10 15:48:12 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos ========== Files - Modified Within 30 Days ========== [2009.12.10 21:06:54 | 02,672,312 | ---- | M] () -- C:\Documents and Settings\Vladimir\Desktop\esetsmartinstaller_enu.exe [2009.12.10 20:59:02 | 00,284,590 | ---- | M] () -- C:\Documents and Settings\Vladimir\Desktop\gmer.zip [2009.12.10 20:47:29 | 00,029,204 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2009.12.10 20:46:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009.12.10 20:46:51 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009.12.10 20:46:12 | 00,786,432 | -H-- | M] () -- C:\Documents and Settings\Vladimir\NTUSER.DAT [2009.12.10 20:46:12 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Vladimir\ntuser.ini [2009.12.10 20:13:07 | 00,537,600 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vladimir\Desktop\OTL.exe [2009.12.10 19:36:27 | 00,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009.12.10 19:36:27 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009.12.10 19:36:27 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009.12.10 19:35:21 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2009.12.10 19:35:13 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009.12.10 18:30:52 | 00,096,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009.12.10 18:21:48 | 00,013,432 | ---- | M] () -- C:\Documents and Settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT [2009.12.10 17:39:28 | 76,846,000 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Vladimir\Desktop\NAV10TBEN.exe [2009.12.10 17:30:37 | 00,000,281 | RHS- | M] () -- C:\boot.ini [2009.12.10 17:12:15 | 00,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk [2009.12.10 16:56:40 | 00,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat [2009.12.10 16:51:31 | 00,001,870 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk [2009.12.10 16:44:49 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2009.12.10 16:44:31 | 00,000,690 | ---- | M] () -- C:\Documents and Settings\Vladimir\Desktop\The KMPlayer.lnk [2009.12.10 16:41:50 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009.12.10 16:40:47 | 00,000,288 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf [2009.12.10 16:38:05 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb [2009.12.10 16:38:05 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb [2009.12.10 16:37:57 | 00,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI [2009.12.10 16:37:00 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest [2009.12.10 16:37:00 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest [2009.12.10 16:36:43 | 00,000,477 | ---- | M] () -- C:\WINDOWS\win.ini [2009.12.10 16:35:57 | 00,022,720 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat [2009.12.10 16:34:38 | 00,000,211 | ---- | M] () -- C:\Boot.bak [2009.12.10 16:09:52 | 00,224,988 | ---- | M] () -- C:\WINDOWS\setupapi.old [2009.12.10 16:09:44 | 02,650,940 | -H-- | M] () -- C:\Documents and Settings\Vladimir\Local Settings\Application Data\IconCache.db [2009.12.10 16:08:36 | 00,001,519 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AvRack.lnk [2009.12.10 16:04:49 | 00,000,729 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2009.12.10 15:56:25 | 00,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD [2009.12.10 15:55:35 | 00,004,438 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2009.12.10 15:53:06 | 00,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2009.12.10 15:53:06 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2009.12.10 15:53:06 | 00,000,000 | RHS- | M] () -- C:\IO.SYS [2009.12.10 15:53:06 | 00,000,000 | ---- | M] () -- C:\WINDOWS\control.ini [2009.12.10 15:53:06 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS [2009.12.10 15:53:06 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009.12.10 15:49:39 | 00,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini [2009.12.10 15:49:39 | 00,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini [2009.12.08 12:29:32 | 00,292,864 | ---- | M] () -- C:\Documents and Settings\Vladimir\Desktop\gmer.exe ========== Files Created - No Company Name ========== [2009.12.10 21:06:44 | 02,672,312 | ---- | C] () -- C:\Documents and Settings\Vladimir\Desktop\esetsmartinstaller_enu.exe [2009.12.10 20:59:06 | 00,292,864 | ---- | C] () -- C:\Documents and Settings\Vladimir\Desktop\gmer.exe [2009.12.10 20:59:00 | 00,284,590 | ---- | C] () -- C:\Documents and Settings\Vladimir\Desktop\gmer.zip [2009.12.10 17:42:45 | 00,004,438 | ---- | C] () -- C:\WINDOWS\imsins.BAK [2009.12.10 17:42:39 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd [2009.12.10 17:42:39 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa [2009.12.10 17:42:39 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf [2009.12.10 17:42:38 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa [2009.12.10 17:42:36 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls [2009.12.10 17:42:36 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls [2009.12.10 17:42:35 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls [2009.12.10 17:42:35 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls [2009.12.10 17:42:33 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls [2009.12.10 17:42:33 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS [2009.12.10 17:42:32 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls [2009.12.10 17:42:32 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS [2009.12.10 17:42:31 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls [2009.12.10 17:42:31 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS [2009.12.10 17:42:28 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20127.nls [2009.12.10 17:42:28 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls [2009.12.10 17:42:25 | 00,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT [2009.12.10 17:42:12 | 00,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat [2009.12.10 17:41:54 | 00,224,988 | ---- | C] () -- C:\WINDOWS\setupapi.old [2009.12.10 17:41:34 | 00,096,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009.12.10 17:40:32 | 00,000,281 | RHS- | C] () -- C:\boot.ini [2009.12.10 17:40:29 | 00,000,288 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf [2009.12.10 17:30:37 | 00,000,211 | ---- | C] () -- C:\Boot.bak [2009.12.10 17:30:34 | 00,260,272 | ---- | C] () -- C:\cmldr [2009.12.10 17:12:15 | 00,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk [2009.12.10 16:56:40 | 00,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2009.12.10 16:51:31 | 00,001,870 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk [2009.12.10 16:44:49 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2009.12.10 16:44:31 | 00,000,690 | ---- | C] () -- C:\Documents and Settings\Vladimir\Desktop\The KMPlayer.lnk [2009.12.10 16:40:36 | 00,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls [2009.12.10 16:40:00 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls [2009.12.10 16:40:00 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls [2009.12.10 16:39:58 | 00,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll [2009.12.10 16:39:37 | 00,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls [2009.12.10 16:39:36 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex [2009.12.10 16:39:30 | 00,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe [2009.12.10 16:39:29 | 00,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe [2009.12.10 16:39:27 | 00,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex [2009.12.10 16:39:18 | 13,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll [2009.12.10 16:39:13 | 00,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex [2009.12.10 16:39:05 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll [2009.12.10 16:38:53 | 00,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll [2009.12.10 16:38:49 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls [2009.12.10 16:38:49 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls [2009.12.10 16:38:49 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls [2009.12.10 16:38:48 | 00,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls [2009.12.10 16:38:48 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls [2009.12.10 16:38:48 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls [2009.12.10 16:38:48 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls [2009.12.10 16:38:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls [2009.12.10 16:38:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls [2009.12.10 16:38:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls [2009.12.10 16:38:48 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls [2009.12.10 16:38:47 | 00,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls [2009.12.10 16:38:47 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls [2009.12.10 16:38:46 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls [2009.12.10 16:38:45 | 00,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls [2009.12.10 16:38:45 | 00,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls [2009.12.10 16:38:45 | 00,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls [2009.12.10 16:38:45 | 00,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls [2009.12.10 16:38:45 | 00,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls [2009.12.10 16:38:45 | 00,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls [2009.12.10 16:38:45 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls [2009.12.10 16:38:45 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls [2009.12.10 16:38:44 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls [2009.12.10 16:38:43 | 00,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls [2009.12.10 16:38:43 | 00,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls [2009.12.10 16:38:43 | 00,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls [2009.12.10 16:38:43 | 00,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls [2009.12.10 16:38:43 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls [2009.12.10 16:38:43 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls [2009.12.10 16:38:42 | 00,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls [2009.12.10 16:38:42 | 00,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls [2009.12.10 16:37:00 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest [2009.12.10 16:36:54 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest [2009.12.10 16:25:25 | 01,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT [2009.12.10 16:25:25 | 00,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT [2009.12.10 16:25:25 | 00,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT [2009.12.10 16:25:25 | 00,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat [2009.12.10 16:25:25 | 00,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat [2009.12.10 16:25:25 | 00,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT [2009.12.10 16:25:25 | 00,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat [2009.12.10 16:25:25 | 00,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT [2009.12.10 16:25:25 | 00,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat [2009.12.10 16:25:25 | 00,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT [2009.12.10 16:25:25 | 00,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT [2009.12.10 16:25:25 | 00,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat [2009.12.10 16:25:25 | 00,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT [2009.12.10 16:25:25 | 00,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT [2009.12.10 16:25:25 | 00,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT [2009.12.10 16:25:25 | 00,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT [2009.12.10 16:25:24 | 02,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT [2009.12.10 16:25:24 | 00,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT [2009.12.10 16:09:53 | 00,244,224 | R--- | C] () -- C:\WINDOWS\System32\NvRaidMan.exe [2009.12.10 16:09:53 | 00,000,464 | R--- | C] () -- C:\WINDOWS\System32\nvide.nvu [2009.12.10 16:08:36 | 00,001,519 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AvRack.lnk [2009.12.10 16:08:33 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini [2009.12.10 16:08:30 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll [2009.12.10 16:08:29 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2009.12.10 16:08:25 | 00,141,016 | ---- | C] () -- C:\WINDOWS\System32\ALSNDMGR.WAV [2009.12.10 16:06:10 | 00,002,509 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu [2009.12.10 16:06:07 | 00,000,789 | R--- | C] () -- C:\WINDOWS\System32\nvsmb.nvu [2009.12.10 16:05:59 | 00,002,124 | ---- | C] () -- C:\WINDOWS\System32\nvgart.nvu [2009.12.10 16:04:49 | 00,000,729 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2009.12.10 16:04:44 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\C_856.nls [2009.12.10 16:04:44 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll [2009.12.10 16:00:22 | 00,029,204 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml [2009.12.10 16:00:11 | 00,014,757 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu [2009.12.10 15:59:07 | 00,023,040 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys [2009.12.10 15:57:24 | 00,000,178 | -HS- | C] () -- C:\Documents and Settings\Vladimir\ntuser.ini [2009.12.10 15:57:22 | 00,786,432 | -H-- | C] () -- C:\Documents and Settings\Vladimir\NTUSER.DAT [2009.12.10 15:56:25 | 00,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD [2009.12.10 15:55:29 | 00,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2009.12.10 15:53:06 | 00,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT [2009.12.10 15:53:06 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS [2009.12.10 15:53:06 | 00,000,000 | RHS- | C] () -- C:\IO.SYS [2009.12.10 15:53:06 | 00,000,000 | ---- | C] () -- C:\CONFIG.SYS [2009.12.10 15:53:06 | 00,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT [2009.12.10 15:52:57 | 00,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb [2009.12.10 15:52:57 | 00,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb [2009.12.10 15:51:50 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest [2009.12.10 15:51:44 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest [2009.12.10 15:51:25 | 04,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex [2009.12.10 15:51:01 | 00,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp [2009.12.10 15:51:01 | 00,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp [2009.12.10 15:50:56 | 00,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf [2009.12.10 15:50:45 | 00,004,639 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.exe [2009.12.10 15:50:35 | 00,376,320 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll [2009.12.10 15:49:54 | 00,022,720 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2009.12.10 15:48:59 | 00,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp [2009.12.10 15:48:59 | 00,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp [2009.12.10 15:48:59 | 00,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp [2009.12.10 15:48:59 | 00,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp [2009.12.10 15:48:59 | 00,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp [2009.12.10 15:48:59 | 00,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp [2009.12.10 15:48:59 | 00,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp [2009.12.10 15:48:58 | 00,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce [2009.12.10 15:48:58 | 00,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp [2009.12.10 15:48:58 | 00,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp [2009.12.10 15:48:58 | 00,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce [2009.12.10 15:48:58 | 00,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp [2009.12.10 15:48:58 | 00,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce [2009.12.10 15:48:58 | 00,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce [2009.12.10 15:48:58 | 00,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce [2009.12.10 15:48:58 | 00,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp [2009.12.10 15:48:57 | 00,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce [2009.12.10 15:48:57 | 00,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce [2009.12.10 15:48:57 | 00,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce [2009.12.10 15:48:56 | 00,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd [2009.12.10 15:48:55 | 00,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h [2009.12.10 15:48:54 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h [2009.12.10 15:48:49 | 00,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc [2005.07.20 15:07:00 | 00,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll [2004.08.04 14:00:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll [2004.08.04 14:00:00 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys ========== LOP Check ========== [2009.12.10 18:25:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Vladimir\Application Data\uTorrent ========== Purity Check ========== < End of report > ------------------------------------------------------------------------------------------------------------- OTL Extras logfile created on: 10.12.2009 г. 21:16:16 - Run 3 OTL by OldTimer - Version 3.1.14.0 Folder = C:\Documents and Settings\Vladimir\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1023,48 Mb Total Physical Memory | 659,15 Mb Available Physical Memory | 64,40% Memory free 2,40 Gb Paging File | 2,17 Gb Available in Paging File | 90,36% Paging File free Paging file location(s): c:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 11,72 Gb Total Space | 8,46 Gb Free Space | 72,15% Space Free | Partition Type: NTFS Drive D: | 32,23 Gb Total Space | 7,50 Gb Free Space | 23,29% Space Free | Partition Type: NTFS Drive E: | 32,37 Gb Total Space | 1,67 Gb Free Space | 5,15% Space Free | Partition Type: NTFS Drive F: | 39,07 Gb Total Space | 12,93 Gb Free Space | 33,09% Space Free | Partition Type: NTFS Drive G: | 37,60 Gb Total Space | 11,66 Gb Free Space | 31,01% Space Free | Partition Type: NTFS H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: VLADIMIR-8DDE1D Current User Name: Vladimir Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- "%SYSTEMROOT%\hh.exe" %1 .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-776561741-1563985344-839522115-1003\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8 "{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "FlexType 2K" = FlexType 2K "Mozilla Firefox (3.0.5)" = Mozilla Firefox (3.0.5) "NVIDIA Drivers" = NVIDIA Drivers "The KMPlayer" = The KMPlayer 2.9.4.1434 "utorrentv 1.7.5" = utorrent "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format Runtime "WinRAR archiver" = WinRAR archiver ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-776561741-1563985344-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 10.12.2009 г. 10:56:47 | Computer Name = VLADIMIR-8DDE1D | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: An internal certificate chaining error has occurred. Error - 10.12.2009 г. 10:56:47 | Computer Name = VLADIMIR-8DDE1D | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: An internal certificate chaining error has occurred. [ System Events ] Error - 10.12.2009 г. 12:31:11 | Computer Name = VLADIMIR-8DDE1D | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 10.12.2009 г. 13:19:29 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 13:19:29 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 13:19:30 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The Print Spooler service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 13:22:13 | Computer Name = VLADIMIR-8DDE1D | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 10.12.2009 г. 13:32:16 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 13:32:16 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 13:32:16 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The Print Spooler service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 13:32:16 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). Error - 10.12.2009 г. 14:46:02 | Computer Name = VLADIMIR-8DDE1D | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). < End of report > ------------------------------------------------------------------------------------------------------------------ Тва с gmer нещо не ми се получава пускам го,изчаквам цъкам copy и нищо .. даже нямам антивирусна и всичко е изключено..
  13. Значи като стартирам gmer.exe трябва ли да спра скайп и сякви други неща .. И новия лог в OTL.exe ще рече ново сканирване ли ?
  14. All processes killed Error: Unable to interpret <
  15. http://rapidshare.de/files/48817354/OTL.Txt.html http://rapidshare.de/files/48817356/Extras.Txt.html
  16. http://rapidshare.de/files/48817266/Qoobox.rar.html ------------------------------------------- Reg export of SafeBoot key after repair: ======================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot] "AlternateShell"="cmd.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PEVSystemStart] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\procexp90.Sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PEVSystemStart] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\procexp90.Sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SharedAccess] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] @="Net" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] @="NetClient" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] @="NetService" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] @="NetTrans" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" ======================== HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\PEVSystemStart HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\procexp90.Sys
  17. ComboFix 09-12-09.04 - Vladimir 12.2009 г. 19:32:28.4.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1023.723 [GMT 2:00] Running from: c:\documents and settings\Vladimir\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Vladimir\Desktop\CFScript.txt FILE :: "c:\program files\bfwzzfexyyqxrqqetevzvq.yib" "c:\program files\ofjzmfrxlydxeqdegeiziqayvbswmzsekyl.krd" "c:\program files\phmdrlyfuiojresuxwbtdmxwubtypdxkrgua.dqe" "c:\program files\shjxizjnzknfkufeeacryemidhwymxoyc.zcu" "c:\program files\xlmzjzilwgizdmwutopdjovqknbcpzpy.mwy" "c:\windows\azljefznjerticxgqwihy.exe" "c:\windows\ezhbspfphyhfqgxci.exe" "c:\windows\ljurllermgsthauclqbz.exe" "c:\windows\njsnfdufyqazlcuahk.exe" "c:\windows\rredzbwliesvlgcmxerrja.exe" "c:\windows\system32\azljefznjerticxgqwihy.exe" "c:\windows\system32\ezhbspfphyhfqgxci.exe" "c:\windows\system32\ljurllermgsthauclqbz.exe" "c:\windows\system32\njsnfdufyqazlcuahk.exe" "c:\windows\system32\rredzbwliesvlgcmxerrja.exe" "c:\windows\system32\xryrhdsbsiqnxmcg.exe" "c:\windows\system32\yvfbutlxrkvviataimw.exe" "c:\windows\xryrhdsbsiqnxmcg.exe" "c:\windows\yvfbutlxrkvviataimw.exe" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\bfwzzfexyyqxrqqetevzvq.yib c:\program files\ofjzmfrxlydxeqdegeiziqayvbswmzsekyl.krd c:\program files\phmdrlyfuiojresuxwbtdmxwubtypdxkrgua.dqe c:\program files\shjxizjnzknfkufeeacryemidhwymxoyc.zcu c:\program files\xlmzjzilwgizdmwutopdjovqknbcpzpy.mwy c:\windows\azljefznjerticxgqwihy.exe c:\windows\ezhbspfphyhfqgxci.exe c:\windows\ljurllermgsthauclqbz.exe c:\windows\njsnfdufyqazlcuahk.exe c:\windows\rredzbwliesvlgcmxerrja.exe c:\windows\system32\azljefznjerticxgqwihy.exe c:\windows\system32\ezhbspfphyhfqgxci.exe c:\windows\system32\ljurllermgsthauclqbz.exe c:\windows\system32\njsnfdufyqazlcuahk.exe c:\windows\system32\rredzbwliesvlgcmxerrja.exe c:\windows\system32\xryrhdsbsiqnxmcg.exe c:\windows\system32\yvfbutlxrkvviataimw.exe c:\windows\xryrhdsbsiqnxmcg.exe c:\windows\yvfbutlxrkvviataimw.exe . ((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 ))))))))))))))))))))))))))))))) . 2009-12-10 16:21 . 2009-12-10 16:21 13432 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-10 17:31 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype 2009-12-10 16:36 . 2009-12-10 15:39 -------- d-----w- c:\program files\NortonInstaller 2009-12-10 16:31 . 2009-12-10 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2009-12-10 16:25 . 2009-12-10 15:09 -------- d-----w- c:\documents and settings\Vladimir\Application Data\uTorrent 2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp 2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\program files\Winamp 2009-12-10 15:02 . 2009-12-10 14:44 -------- d-----w- c:\program files\The KMPlayer 2009-12-10 15:00 . 2009-12-10 15:00 -------- d-----w- c:\program files\utorrent 2009-12-10 14:56 . 2009-12-10 14:56 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-12-10 14:56 . 2009-12-10 14:56 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Skype 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Common Files\Skype 2009-12-10 14:44 . 2009-12-10 14:44 0 ----a-w- c:\windows\nsreg.dat 2009-12-10 14:35 . 2009-12-10 13:49 22720 ----a-w- c:\windows\system32\emptyregdb.dat 2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\Realtek Sound Manager 2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\AvRack 2009-12-10 14:08 . 2009-12-10 14:07 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-12-10 14:08 . 2009-12-10 13:59 -------- d-----w- c:\program files\Common Files\InstallShield 2009-12-10 14:07 . 2009-12-10 14:07 -------- d-----w- c:\program files\AMD 2009-12-10 14:04 . 2009-12-10 14:04 -------- d-----w- c:\program files\Datecs 2009-12-10 14:02 . 2009-12-10 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles 2009-12-10 13:53 . 2009-12-10 13:53 -------- d-----w- c:\program files\microsoft frontpage 2009-12-10 13:52 . 2009-12-10 13:52 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat . ((((((((((((((((((((((((((((( SnapShot@2009-12-10_15.34.42 ))))))))))))))))))))))))))))))))))))))))) . - 2004-08-04 12:00 . 2009-12-10 14:53 39992 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2009-12-10 17:26 39992 c:\windows\system32\perfc009.dat - 2009-12-10 15:41 . 2009-12-10 14:41 96664 c:\windows\system32\FNTCACHE.DAT + 2009-12-10 15:41 . 2009-12-10 16:30 96664 c:\windows\system32\FNTCACHE.DAT + 2004-08-04 12:00 . 2009-12-10 17:26 311604 c:\windows\system32\perfh009.dat - 2004-08-04 12:00 . 2009-12-10 14:53 311604 c:\windows\system32\perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-20 7110656] "nwiz"="nwiz.exe" [2005-07-20 1519616] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968] "SoundMan"="SOUNDMAN.EXE" [2004-12-22 77824] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-20 86016] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544] c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-12-10 95232] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 0 (0x0) "EnableInstallerDetection"= 0 (0x0) "EnableSecureUIAPaths"= 0 (0x0) "EnableVirtualization"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . ------- Supplementary Scan ------- . FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\j4026pxg.default\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-10 19:35 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(1632) c:\windows\system32\newdll.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\SOUNDMAN.EXE c:\windows\system32\RUNDLL32.EXE c:\windows\system32\nvsvc32.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe c:\windows\system32\wbem\unsecapp.exe . ************************************************************************** . Completion time: 2009-12-10 19:36:29 - machine was rebooted ComboFix-quarantined-files.txt 2009-12-10 17:36 ComboFix2.txt 2009-12-10 17:23 ComboFix3.txt 2009-12-10 17:04 ComboFix4.txt 2009-12-10 15:35 Pre-Run: 9 053 401 088 bytes free Post-Run: 9 014 411 264 bytes free - - End Of File - - F4D4DC67209B134D3151E9E315A6A20B
  18. ComboFix 09-12-09.04 - Vladimir 12.2009 г. 19:19:31.3.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1023.577 [GMT 2:00] Running from: c:\documents and settings\Vladimir\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Vladimir\Desktop\CFScript.txt . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\autorun.inf C:\errdmbjlv.bat C:\ofjzmfrxlydxe.bat C:\shjxizjnzkn.bat D:\Autorun.inf D:\errdmbjlv.bat D:\ofjzmfrxlydxe.bat D:\shjxizjnzkn.bat E:\Autorun.inf E:\errdmbjlv.bat E:\ofjzmfrxlydxe.bat E:\shjxizjnzkn.bat F:\Autorun.inf F:\errdmbjlv.bat F:\ofjzmfrxlydxe.bat F:\shjxizjnzkn.bat G:\Autorun.inf G:\errdmbjlv.bat G:\ofjzmfrxlydxe.bat G:\shjxizjnzkn.bat . ((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 ))))))))))))))))))))))))))))))) . 2009-12-10 16:21 . 2009-12-10 16:21 13432 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-10 17:19 . 2009-12-10 13:59 507904 --sh--r- c:\windows\azljefznjerticxgqwihy.exe 2009-12-10 17:19 . 2009-12-10 13:59 507904 ----a-w- c:\windows\rredzbwliesvlgcmxerrja.exe 2009-12-10 17:19 . 2009-12-10 13:59 507904 --sh--r- c:\windows\yvfbutlxrkvviataimw.exe 2009-12-10 17:19 . 2009-12-10 13:59 507904 --sh--r- c:\windows\xryrhdsbsiqnxmcg.exe 2009-12-10 17:19 . 2009-12-10 13:59 507904 --sh--r- c:\windows\njsnfdufyqazlcuahk.exe 2009-12-10 17:19 . 2009-12-10 13:59 507904 --sh--r- c:\windows\ljurllermgsthauclqbz.exe 2009-12-10 17:19 . 2009-12-10 13:59 507904 --sh--r- c:\windows\ezhbspfphyhfqgxci.exe 2009-12-10 17:19 . 2009-12-10 14:07 2408 ---h--w- c:\program files\xlmzjzilwgizdmwutopdjovqknbcpzpy.mwy 2009-12-10 17:19 . 2009-12-10 13:59 272 ---h--w- c:\program files\bfwzzfexyyqxrqqetevzvq.yib 2009-12-10 17:18 . 2009-12-10 14:07 316 ---h--w- c:\program files\ofjzmfrxlydxeqdegeiziqayvbswmzsekyl.krd 2009-12-10 17:17 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\yvfbutlxrkvviataimw.exe 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\rredzbwliesvlgcmxerrja.exe 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\njsnfdufyqazlcuahk.exe 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\ljurllermgsthauclqbz.exe 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\ezhbspfphyhfqgxci.exe 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\azljefznjerticxgqwihy.exe 2009-12-10 17:05 . 2009-12-10 13:59 507904 --sh--r- c:\windows\system32\xryrhdsbsiqnxmcg.exe 2009-12-10 16:36 . 2009-12-10 15:39 -------- d-----w- c:\program files\NortonInstaller 2009-12-10 16:31 . 2009-12-10 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2009-12-10 16:25 . 2009-12-10 15:09 -------- d-----w- c:\documents and settings\Vladimir\Application Data\uTorrent 2009-12-10 15:26 . 2009-12-10 14:07 138 ---h--w- c:\program files\phmdrlyfuiojresuxwbtdmxwubtypdxkrgua.dqe 2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp 2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\program files\Winamp 2009-12-10 15:02 . 2009-12-10 14:44 -------- d-----w- c:\program files\The KMPlayer 2009-12-10 15:00 . 2009-12-10 15:00 -------- d-----w- c:\program files\utorrent 2009-12-10 14:56 . 2009-12-10 14:56 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-12-10 14:56 . 2009-12-10 14:56 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Skype 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Common Files\Skype 2009-12-10 14:44 . 2009-12-10 14:44 0 ----a-w- c:\windows\nsreg.dat 2009-12-10 14:35 . 2009-12-10 13:49 22720 ----a-w- c:\windows\system32\emptyregdb.dat 2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\Realtek Sound Manager 2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\AvRack 2009-12-10 14:08 . 2009-12-10 14:07 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-12-10 14:08 . 2009-12-10 13:59 -------- d-----w- c:\program files\Common Files\InstallShield 2009-12-10 14:07 . 2009-12-10 14:07 -------- d-----w- c:\program files\AMD 2009-12-10 14:04 . 2009-12-10 14:04 -------- d-----w- c:\program files\Datecs 2009-12-10 14:02 . 2009-12-10 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles 2009-12-10 13:59 . 2009-12-10 13:59 4008 ---ha-w- c:\program files\shjxizjnzknfkufeeacryemidhwymxoyc.zcu 2009-12-10 13:53 . 2009-12-10 13:53 -------- d-----w- c:\program files\microsoft frontpage 2009-12-10 13:52 . 2009-12-10 13:52 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat . ((((((((((((((((((((((((((((( SnapShot@2009-12-10_15.34.42 ))))))))))))))))))))))))))))))))))))))))) . - 2004-08-04 12:00 . 2009-12-10 14:53 39992 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2009-12-10 17:12 39992 c:\windows\system32\perfc009.dat - 2009-12-10 15:41 . 2009-12-10 14:41 96664 c:\windows\system32\FNTCACHE.DAT + 2009-12-10 15:41 . 2009-12-10 16:30 96664 c:\windows\system32\FNTCACHE.DAT + 2004-08-04 12:00 . 2009-12-10 17:12 311604 c:\windows\system32\perfh009.dat - 2004-08-04 12:00 . 2009-12-10 14:53 311604 c:\windows\system32\perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-20 7110656] "nwiz"="nwiz.exe" [2005-07-20 1519616] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968] "SoundMan"="SOUNDMAN.EXE" [2004-12-22 77824] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-20 86016] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544] c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-12-10 95232] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 0 (0x0) "EnableInstallerDetection"= 0 (0x0) "EnableSecureUIAPaths"= 0 (0x0) "EnableVirtualization"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= . ------- Supplementary Scan ------- . FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\j4026pxg.default\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-10 19:22 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3232) c:\windows\system32\newdll.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\SOUNDMAN.EXE c:\windows\system32\RUNDLL32.EXE c:\windows\system32\nvsvc32.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\system32\wscntfy.exe c:\windows\system32\imapi.exe . ************************************************************************** . Completion time: 2009-12-10 19:23:26 - machine was rebooted ComboFix-quarantined-files.txt 2009-12-10 17:23 ComboFix2.txt 2009-12-10 17:04 ComboFix3.txt 2009-12-10 15:35 Pre-Run: 8 973 414 400 bytes free Post-Run: 8 947 032 064 bytes free - - End Of File - - 044CE893E9A028B4B76F7E597FF1FEF8
  19. И аз имам същия проблем само ,че като тръгна да свалям каквато и да било програма ме изхвърля от мозилата ... Значи пратиха ми някакъв линк в скайп аз взех ,че влезнах и ми прееба компа.Преинсталирах никакъв ефект няма .. В Task managera има няколко измислени ненужни процеса.. Някой ако има идея кво да правя да казва,че си ебало мамата.. ComboFix 09-12-09.04 - Vladimir 12.2009 г. 19:00:55.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1023.524 [GMT 2:00] Running from: c:\documents and settings\Vladimir\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\autorun.inf C:\errdmbjlv.bat C:\ofjzmfrxlydxe.bat C:\shjxizjnzkn.bat D:\autorun.inf D:\errdmbjlv.bat D:\ofjzmfrxlydxe.bat D:\shjxizjnzkn.bat E:\Autorun.inf E:\errdmbjlv.bat E:\ofjzmfrxlydxe.bat E:\shjxizjnzkn.bat F:\Autorun.inf F:\errdmbjlv.bat F:\ofjzmfrxlydxe.bat F:\shjxizjnzkn.bat G:\autorun.inf G:\errdmbjlv.bat G:\ofjzmfrxlydxe.bat G:\shjxizjnzkn.bat . ((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 ))))))))))))))))))))))))))))))) . 2009-12-10 16:21 . 2009-12-10 16:21 13432 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-10 17:03 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype 2009-12-10 17:00 . 2009-12-10 14:07 2408 ---h--w- c:\program files\xlmzjzilwgizdmwutopdjovqknbcpzpy.mwy 2009-12-10 17:00 . 2009-12-10 13:59 272 ---h--w- c:\program files\bfwzzfexyyqxrqqetevzvq.yib 2009-12-10 16:59 . 2009-12-10 14:07 316 ---h--w- c:\program files\ofjzmfrxlydxeqdegeiziqayvbswmzsekyl.krd 2009-12-10 16:36 . 2009-12-10 15:39 -------- d-----w- c:\program files\NortonInstaller 2009-12-10 16:31 . 2009-12-10 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2009-12-10 16:25 . 2009-12-10 15:09 -------- d-----w- c:\documents and settings\Vladimir\Application Data\uTorrent 2009-12-10 15:26 . 2009-12-10 14:07 138 ---h--w- c:\program files\phmdrlyfuiojresuxwbtdmxwubtypdxkrgua.dqe 2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp 2009-12-10 15:14 . 2009-12-10 15:10 -------- d-----w- c:\program files\Winamp 2009-12-10 15:02 . 2009-12-10 14:44 -------- d-----w- c:\program files\The KMPlayer 2009-12-10 15:00 . 2009-12-10 15:00 -------- d-----w- c:\program files\utorrent 2009-12-10 14:56 . 2009-12-10 14:56 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-12-10 14:56 . 2009-12-10 14:56 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Skype 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2009-12-10 14:51 . 2009-12-10 14:51 -------- d-----w- c:\program files\Common Files\Skype 2009-12-10 14:44 . 2009-12-10 14:44 0 ----a-w- c:\windows\nsreg.dat 2009-12-10 14:35 . 2009-12-10 13:49 22720 ----a-w- c:\windows\system32\emptyregdb.dat 2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\Realtek Sound Manager 2009-12-10 14:08 . 2009-12-10 14:08 -------- d-----w- c:\program files\AvRack 2009-12-10 14:08 . 2009-12-10 14:07 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-12-10 14:08 . 2009-12-10 13:59 -------- d-----w- c:\program files\Common Files\InstallShield 2009-12-10 14:07 . 2009-12-10 14:07 -------- d-----w- c:\program files\AMD 2009-12-10 14:04 . 2009-12-10 14:04 -------- d-----w- c:\program files\Datecs 2009-12-10 14:02 . 2009-12-10 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles 2009-12-10 13:59 . 2009-12-10 13:59 4008 ---ha-w- c:\program files\shjxizjnzknfkufeeacryemidhwymxoyc.zcu 2009-12-10 13:53 . 2009-12-10 13:53 -------- d-----w- c:\program files\microsoft frontpage 2009-12-10 13:52 . 2009-12-10 13:52 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat . ((((((((((((((((((((((((((((( SnapShot@2009-12-10_15.34.42 ))))))))))))))))))))))))))))))))))))))))) . - 2009-12-10 15:41 . 2009-12-10 14:41 96664 c:\windows\system32\FNTCACHE.DAT + 2009-12-10 15:41 . 2009-12-10 16:30 96664 c:\windows\system32\FNTCACHE.DAT + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\yvfbutlxrkvviataimw.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\yvfbutlxrkvviataimw.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\xryrhdsbsiqnxmcg.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\xryrhdsbsiqnxmcg.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\yvfbutlxrkvviataimw.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\yvfbutlxrkvviataimw.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\xryrhdsbsiqnxmcg.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\xryrhdsbsiqnxmcg.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\rredzbwliesvlgcmxerrja.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\rredzbwliesvlgcmxerrja.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\njsnfdufyqazlcuahk.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\njsnfdufyqazlcuahk.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\ljurllermgsthauclqbz.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\ljurllermgsthauclqbz.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\ezhbspfphyhfqgxci.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\ezhbspfphyhfqgxci.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\system32\azljefznjerticxgqwihy.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\system32\azljefznjerticxgqwihy.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\rredzbwliesvlgcmxerrja.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\rredzbwliesvlgcmxerrja.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\njsnfdufyqazlcuahk.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\njsnfdufyqazlcuahk.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\ljurllermgsthauclqbz.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\ljurllermgsthauclqbz.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\ezhbspfphyhfqgxci.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\ezhbspfphyhfqgxci.exe - 2009-12-10 13:59 . 2009-12-10 15:31 507904 c:\windows\azljefznjerticxgqwihy.exe + 2009-12-10 13:59 . 2009-12-10 17:01 507904 c:\windows\azljefznjerticxgqwihy.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "errdmbjlv"="yvfbutlxrkvviataimw.exe" [2009-12-10 507904] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "yjhrylr"="c:\docume~1\Vladimir\LOCALS~1\Temp\xryrhdsbsiqnxmcg.exe ." [X] "xlmzjzilwg"="njsnfdufyqazlcuahk.exe" [2009-12-10 507904] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "lvsbht"="njsnfdufyqazlcuahk.exe" [2009-12-10 507904] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-20 7110656] "nwiz"="nwiz.exe" [2005-07-20 1519616] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968] "SoundMan"="SOUNDMAN.EXE" [2004-12-22 77824] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-20 86016] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "shjxizjnzkn"="c:\docume~1\Vladimir\LOCALS~1\Temp\yvfbutlxrkvviataimw.exe ." [X] "yjhrylr"="xryrhdsbsiqnxmcg.exe" [2009-12-10 507904] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] "errdmbjlv"="njsnfdufyqazlcuahk.exe" [2009-12-10 507904] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "yjhrylr"="c:\windows\TEMP\azljefznjerticxgqwihy.exe ." [X] "xlmzjzilwg"="yvfbutlxrkvviataimw.exe" [2009-12-10 507904] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544] [HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run] "nzyjrfmn"="xryrhdsbsiqnxmcg.exe" [2009-12-10 507904] c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-12-10 95232] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 0 (0x0) "EnableInstallerDetection"= 0 (0x0) "EnableSecureUIAPaths"= 0 (0x0) "EnableVirtualization"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) SafeBoot registry key needs repairs. This machine cannot enter Safe Mode. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= . ------- Supplementary Scan ------- . FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\j4026pxg.default\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-10 19:03 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-12-10 19:04:46 ComboFix-quarantined-files.txt 2009-12-10 17:04 ComboFix2.txt 2009-12-10 15:35 Pre-Run: 9 060 462 592 bytes free Post-Run: 9 038 155 776 bytes free - - End Of File - - 2BA9EF355DCE96967C096DF956E2E8CC След сканирането от ComboFix

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.