-
Вирус,изпратен по Скайп. [РЕШЕН]
Благодаря ви много за неоценимата помощ!Много усмивки,здраве и щастие през новата година!
-
Вирус,изпратен по Скайп. [РЕШЕН]
OTL logfile created on: 25.12.2009 г. 15:52:14 - Run 3 OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Desi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 71,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 84,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 22,92 Gb Free Space | 46,94% Space Free | Partition Type: NTFS Drive D: | 104,55 Gb Total Space | 23,08 Gb Free Space | 22,07% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Desi\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\DrWeb\spideragent.exe (Doctor Web, Ltd.) PRC - C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe (Doctor Web, Ltd.) PRC - C:\Program Files\DrWeb\spiderui.exe (Doctor Web, Ltd.) PRC - C:\Program Files\DrWeb\spidernt.exe (Doctor Web, Ltd.) PRC - C:\Program Files\DrWeb\spiderml.exe (Doctor Web, Ltd.) PRC - C:\Program Files\Winamp\winampa.exe () PRC - C:\Program Files\Anti Trojan Elite\TJEnder.exe (ISecSoft) PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation) PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) PRC - C:\Program Files\Opera\opera.exe (Opera Software) PRC - C:\Program Files\ICQ6Toolbar\ICQ Service.exe () PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG) PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG) PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) PRC - C:\WINDOWS\VMSnap23.exe () PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.) PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Desi\Desktop\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (DrWebEngine) Dr.Web ® Scanning Engine (DrWebEngine) -- C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe (Doctor Web, Ltd.) SRV - (SPIDERNT) -- C:\Program Files\DrWeb\spidernt.exe (Doctor Web, Ltd.) SRV - (nvsvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) SRV - (ICQ Service) -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe () SRV - (NBService) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG) SRV - (NMIndexingService) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG) SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (DwProt) -- C:\WINDOWS\system32\drivers\dwprot.sys (Doctor Web, Ltd.) DRV - (SPIDER) -- C:\Program Files\DrWeb\spider.sys (Doctor Web, Ltd.) DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation) DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider) DRV - (ZSMC326) Vimicro USB2.0 PC Camera(VC0323) -- C:\WINDOWS\system32\drivers\usbvm323.sys (Vimicro Corporation) DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (vmfilter323) -- C:\WINDOWS\system32\drivers\vmfilter323.sys (Vimicro Corporation) DRV - (ADIHdAudAddService) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.) DRV - (AEAudioService) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation) DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura) DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/ IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: (98 bytes) - C:\WINDOWS\system32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe (ISecSoft) O4 - HKLM..\Run: [bigDogPath323Domino] C:\WINDOWS\Domino.exe File not found O4 - HKLM..\Run: [bigDogPath323VMSnap] C:\WINDOWS\VMSnap23.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [spIDerAgent] C:\Program Files\DrWeb\SpIDerAgent.exe (Doctor Web, Ltd.) O4 - HKLM..\Run: [spIDerMail] C:\Program Files\DrWeb\spiderml.exe (Doctor Web, Ltd.) O4 - HKLM..\Run: [spIDerNT] C:\Program Files\DrWeb\spiderui.exe (Doctor Web, Ltd.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [iCQ] C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.07 10:58:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2009.12.23 08:14:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage [2009.12.23 03:01:50 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0 [2009.12.23 00:46:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall [2009.12.23 00:46:13 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$ [2009.12.22 22:17:15 | 00,000,000 | ---D | C] -- C:\Program Files\ESET [2009.12.22 20:32:53 | 00,107,000 | ---- | C] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\dwprot.sys [2009.12.22 20:32:45 | 00,000,000 | ---D | C] -- C:\Program Files\DrWeb [2009.12.22 20:32:45 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Doctor Web [2009.12.22 20:32:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Doctor Web [2009.12.22 20:29:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Desktop\Dr.Web 5.0.0.12180 [2009.12.22 18:41:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Application Data\Malwarebytes [2009.12.22 18:41:28 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009.12.22 18:41:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2009.12.22 18:41:20 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009.12.22 18:41:20 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009.12.22 18:40:31 | 04,844,296 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Desi\Desktop\Malwarebytes Anti-Malware 1.42 (kaldata.com).exe [2009.12.22 17:16:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\DoctorWeb [2009.12.22 15:35:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution [2009.12.22 15:04:01 | 00,000,000 | ---D | C] -- C:\_OTL [2009.12.22 14:28:33 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 13:54:31 | 00,000,000 | ---D | C] -- C:\Program Files\MSECACHE [2009.12.22 13:01:59 | 02,025,768 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 13:01:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2009.12.21 22:58:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:21 | 00,891,208 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.21 22:33:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData [2009.12.21 22:05:35 | 00,000,000 | ---D | C] -- C:\Program Files\Anti Trojan Elite [2009.12.21 21:44:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.12.20 16:40:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\My Documents\ICQ [2009.12.12 10:40:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Desktop\sborna papka [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2009.10.08 13:40:58 | 00,848,712 | ---- | C] (AVG Technologies) -- C:\Program Files\avg_free_stb_all_8_32_cnet.exe [2009.08.26 14:40:55 | 02,032,936 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2009.08.26 14:15:38 | 16,445,408 | ---- | C] (Macrovision Corporation) -- C:\Program Files\install_abv_icq65.exe [2009.08.26 14:11:57 | 01,925,024 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\install_flash_player.exe [2009.08.26 14:06:42 | 07,562,568 | ---- | C] (Opera Software ASA) -- C:\Program Files\Opera_964_int_Setup.exe ========== Files - Modified Within 30 Days ========== [2009.12.25 15:32:40 | 00,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2009.12.25 15:32:40 | 00,311,740 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2009.12.25 15:32:40 | 00,040,128 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2009.12.25 15:31:29 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009.12.25 15:31:28 | 00,229,488 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2009.12.25 15:30:59 | 00,000,300 | ---- | M] () -- C:\WINDOWS\tasks\Dr.Web Update.job [2009.12.25 15:27:50 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009.12.25 15:27:41 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009.12.23 11:39:23 | 06,815,744 | -H-- | M] () -- C:\Documents and Settings\Desi\NTUSER.DAT [2009.12.23 11:38:55 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2009.12.23 11:38:22 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Desi\ntuser.ini [2009.12.23 11:16:26 | 00,004,834 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\legitcheck.hta [2009.12.23 03:32:20 | 00,112,584 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009.12.22 22:17:15 | 02,672,312 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\esetsmartinstaller_enu.exe [2009.12.22 20:32:46 | 00,000,697 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Dr.Web Scanner.lnk [2009.12.22 20:29:57 | 00,007,195 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\Dr.Web 5.0.0.12180.torrent [2009.12.22 20:27:29 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\cureit.exe [2009.12.22 18:41:30 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009.12.22 18:40:51 | 04,844,296 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Desi\Desktop\Malwarebytes Anti-Malware 1.42 (kaldata.com).exe [2009.12.22 18:02:47 | 00,002,844 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\dr.web-cureit-5.00.9-12.12.2009-.exe.torrent [2009.12.22 18:02:47 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\dr.web-cureit-5.00.9-12.12.2009-.exe [2009.12.22 17:03:14 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 15:54:05 | 00,185,065 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\FixPolicies.exe [2009.12.22 15:33:13 | 00,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts [2009.12.22 13:02:01 | 02,025,768 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 00:26:26 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-132452.backup [2009.12.21 23:22:19 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-002625.backup [2009.12.21 22:59:35 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.21 22:58:37 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:28 | 00,891,208 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.18 16:57:52 | 05,740,883 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:57:18 | 06,163,989 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:56:38 | 05,642,632 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:56:08 | 05,342,296 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:55:42 | 05,164,651 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:55:28 | 04,970,130 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:55:06 | 05,198,565 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:54:46 | 04,665,685 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:54:31 | 05,819,569 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:54:11 | 04,926,737 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:53:00 | 04,747,578 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:53:00 | 04,563,397 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:51:37 | 07,578,481 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.18 16:50:15 | 05,965,924 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:50:05 | 04,880,562 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:49:20 | 04,958,286 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:49:19 | 04,316,218 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:48:37 | 04,425,408 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:46:08 | 04,318,089 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:45:55 | 03,073,303 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:43:59 | 04,030,138 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:39:27 | 03,220,078 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:38:58 | 04,887,211 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.16 12:34:00 | 00,000,766 | ---- | M] () -- C:\WINDOWS\win.ini [2009.12.15 22:17:42 | 00,066,351 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.06 10:15:41 | 00,022,528 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.12.05 20:39:22 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009.12.05 20:17:21 | 00,103,675 | ---- | M] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [2009.12.03 16:14:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009.12.03 16:13:56 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys ========== Files Created - No Company Name ========== [2009.12.23 11:16:26 | 00,004,834 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\legitcheck.hta [2009.12.22 22:17:01 | 02,672,312 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\esetsmartinstaller_enu.exe [2009.12.22 20:32:51 | 00,000,300 | ---- | C] () -- C:\WINDOWS\tasks\Dr.Web Update.job [2009.12.22 20:32:46 | 00,000,697 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Dr.Web Scanner.lnk [2009.12.22 20:29:57 | 00,007,195 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\Dr.Web 5.0.0.12180.torrent [2009.12.22 18:41:30 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009.12.22 18:12:27 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\cureit.exe [2009.12.22 18:02:47 | 00,002,844 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\dr.web-cureit-5.00.9-12.12.2009-.exe.torrent [2009.12.22 18:02:47 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\dr.web-cureit-5.00.9-12.12.2009-.exe [2009.12.22 15:39:51 | 00,185,065 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\FixPolicies.exe [2009.12.21 22:59:35 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.18 16:51:38 | 05,740,883 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:29:23 | 06,163,989 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:26:15 | 05,342,296 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:25:48 | 05,198,565 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:25:48 | 05,164,651 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:25:48 | 04,970,130 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:25:48 | 04,926,737 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:25:48 | 04,665,685 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:25:11 | 04,887,211 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.18 16:25:11 | 04,880,562 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:25:11 | 04,747,578 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:24:04 | 05,819,569 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:24:04 | 04,318,089 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:24:04 | 04,316,218 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:24:04 | 04,030,138 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:23:40 | 05,965,924 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:23:40 | 04,563,397 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:23:40 | 04,425,408 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:23:40 | 03,220,078 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:23:40 | 03,073,303 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:23:17 | 05,642,632 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:23:17 | 04,958,286 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:22:33 | 07,578,481 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.15 22:17:42 | 00,066,351 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.05 20:17:21 | 00,103,675 | ---- | C] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [2009.09.13 09:48:02 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\vmcoinst_vc0323.dll [2009.09.13 09:45:31 | 21,117,732 | ---- | C] () -- C:\Program Files\CNR-WCAM413_Drv_XPWV.zip [2009.08.31 08:49:21 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009.06.07 14:07:12 | 00,022,528 | ---- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.07 14:03:10 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009.06.07 14:03:08 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009.06.07 14:03:08 | 02,255,360 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2009.06.07 14:03:08 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009.06.07 14:03:08 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009.06.07 14:03:07 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009.06.07 14:03:07 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2009.06.07 12:45:13 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009.04.30 23:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009.04.30 23:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009.04.30 23:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009.04.30 23:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll ========== LOP Check ========== [2009.12.22 20:32:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Doctor Web [2009.08.26 14:17:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ [2009.08.26 14:33:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\ICQ [2009.08.26 14:07:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\Opera [2009.12.18 18:15:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\XnView [2009.12.25 15:30:59 | 00,000,300 | ---- | M] () -- C:\WINDOWS\Tasks\Dr.Web Update.job ========== Purity Check ========== < End of report > Другият файл не го виждам къде е..Благодаря!
-
Вирус,изпратен по Скайп. [РЕШЕН]
При повторната проверка с ESET изписа,че няма вируси!
-
Вирус,изпратен по Скайп. [РЕШЕН]
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=9132a98612a90f4ba78b08b2a1775261 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-22 10:53:56 # local_time=2009-12-23 12:53:56 (+0200, FLE Standard Time) # country="Bulgaria" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777215 100 0 6510836 6510836 0 0 # compatibility_mode=4354 16777213 100 93 3737 77963161 0 0 # compatibility_mode=8192 67108863 100 0 3842 3842 0 0 # scanned=60437 # found=31 # cleaned=31 # scan_time=9159 C:\bhszozgrwf.bat Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\rvejwfkt.bat Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C_\tboxobkxepbf.bat Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe a variant of Win32/AutoRun.Agent.TG worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Temp\crlbztjdrjcntduvqcg.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Temp\rfynkdslyphrwfvvpa.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\bnermdqhshxfipdb.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\crlbztjdrjcntduvqcg.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\evrjjfxtjdyltfybymsjf.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\ivnbxpdvhxoxbjyxq.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\pfarqlcxmfzlsdvxtglb.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\rfynkdslyphrwfvvpa.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\vnkdeburidznwjdhfubtqj.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\bnermdqhshxfipdb.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\crlbztjdrjcntduvqcg.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\evrjjfxtjdyltfybymsjf.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\ivnbxpdvhxoxbjyxq.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\pfarqlcxmfzlsdvxtglb.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\rfynkdslyphrwfvvpa.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\vnkdeburidznwjdhfubtqj.exe Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\12222009_180509\C__OTL\MovedFiles\12222009_153306\D_\autorun.inf INF/Autorun.Gen virus (deleted - quarantined) 00000000000000000000000000000000 C D:\bhszozgrwf.bat Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\rvejwfkt.bat Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\tboxobkxepbf.bat Win32/AutoRun.Agent.TV worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Disk E\Instal 2\Programi DVD\programi dvd\DVD2one130.exe probably a variant of Win32/Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Install Software\Nero 7 Premium Reloaded v.7.10.1.0\Nero-7.10.1.0_eng.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251
-
Вирус,изпратен по Скайп. [РЕШЕН]
все още не е приключила проверката с ESET,но засега има 30 инфектирани файла,ами сега...
-
Вирус,изпратен по Скайп. [РЕШЕН]
Здравейте,опитах да изтегля от друго място програмата,но се опасявам,че е стара версия и не можах да я ъптейтна,показа,че няма вируси.Какво да правя от тук нататък.
-
Вирус,изпратен по Скайп. [РЕШЕН]
Malwarebytes' Anti-Malware 1.42 Database version: 3408 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 22.12.2009 г. 20:09:47 mbam-log-2009-12-22 (20-09-47).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|) Objects scanned: 158646 Time elapsed: 16 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: D:\Disk E\Instal 2\Install\ACDSee24\cr-acd24.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
-
Вирус,изпратен по Скайп. [РЕШЕН]
All processes killed ========== OTL ========== C:\Documents and Settings\Desi\Desktop\FixPolicies folder moved successfully. C:\Documents and Settings\Desi\Desktop\6m3ze36z.exe moved successfully. C:\Documents and Settings\Desi\Desktop\SafeBootKeyRepair.exe moved successfully. C:\_OTL\MovedFiles\12222009_180509\C_Documents and Settings\Desi\Desktop\FixPolicies folder moved successfully. C:\_OTL\MovedFiles\12222009_180509\C_Documents and Settings\Desi\Desktop folder moved successfully. C:\_OTL\MovedFiles\12222009_180509\C_Documents and Settings\Desi folder moved successfully. C:\_OTL\MovedFiles\12222009_180509\C_Documents and Settings folder moved successfully. C:\_OTL\MovedFiles\12222009_180509 folder moved successfully. C:\_OTL\MovedFiles\12222009_170755 folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\D_ folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\drivers\etc folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_WINDOWS\system32\drivers folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_WINDOWS\system32 folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_WINDOWS folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Program Files folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Temp folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings\Application Data folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Local Settings folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi\Desktop folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Documents and Settings\Desi folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_Documents and Settings folder moved successfully. C:\_OTL\MovedFiles\12222009_153306\C_ folder moved successfully. C:\_OTL\MovedFiles\12222009_153306 folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_WINDOWS\System32\drivers\etc folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_WINDOWS\System32\drivers folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_WINDOWS\System32 folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_WINDOWS folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5\A9W1M5O1 folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5 folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings\Temporary Internet Files folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings\Temp folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Local Settings folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi\Desktop folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings\Desi folder moved successfully. C:\_OTL\MovedFiles\12222009_150401\C_Documents and Settings folder moved successfully. C:\_OTL\MovedFiles\12222009_150401 folder moved successfully. C:\_OTL\MovedFiles folder moved successfully. C:\_OTL folder moved successfully. C:\Documents and Settings\Desi\Desktop\cureit.exe moved successfully. C:\Documents and Settings\Desi\Desktop\launch.exe moved successfully. C:\tboxobkxepbf.bat moved successfully. File rity] not found. File ptytemp] not found. File sethosts] not found. File boot] not found. OTL by OldTimer - Version 3.1.19.0 log created on 12222009_180509 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Отново не мога да изтегля програмата,защо така..
-
Вирус,изпратен по Скайп. [РЕШЕН]
Моля ви дайте ми друг линк за Dr.Web ! Ето пак проверката с новите резултати-OTL logfile created on: 22.12.2009 г. 17:08:08 - Run 2 OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Desi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 73,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 87,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 24,16 Gb Free Space | 49,48% Space Free | Partition Type: NTFS Drive D: | 104,55 Gb Total Space | 23,08 Gb Free Space | 22,08% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Desi\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Winamp\winampa.exe () PRC - C:\Program Files\Anti Trojan Elite\TJEnder.exe (ISecSoft) PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) PRC - C:\Program Files\Opera\opera.exe (Opera Software) PRC - C:\Program Files\ICQ6Toolbar\ICQ Service.exe () PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG) PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG) PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) PRC - C:\WINDOWS\VMSnap23.exe () PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.) PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Desi\Desktop\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (nvsvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) SRV - (ICQ Service) -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe () SRV - (NBService) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG) SRV - (NMIndexingService) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG) SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation) DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider) DRV - (ZSMC326) Vimicro USB2.0 PC Camera(VC0323) -- C:\WINDOWS\system32\drivers\usbvm323.sys (Vimicro Corporation) DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (vmfilter323) -- C:\WINDOWS\system32\drivers\vmfilter323.sys (Vimicro Corporation) DRV - (ADIHdAudAddService) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.) DRV - (AEAudioService) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation) DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura) DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/ IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: (98 bytes) - C:\WINDOWS\system32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe (ISecSoft) O4 - HKLM..\Run: [bigDogPath323Domino] C:\WINDOWS\Domino.exe File not found O4 - HKLM..\Run: [bigDogPath323VMSnap] C:\WINDOWS\VMSnap23.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [iCQ] C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.07 10:58:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2009.12.22 15:54:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Desktop\FixPolicies [2009.12.22 15:41:14 | 14,827,320 | ---- | C] (Doctor Web, Ltd.) -- C:\Documents and Settings\Desi\Desktop\6m3ze36z.exe [2009.12.22 15:35:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution [2009.12.22 15:35:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood [2009.12.22 15:25:19 | 00,288,654 | ---- | C] ( ) -- C:\Documents and Settings\Desi\Desktop\SafeBootKeyRepair.exe [2009.12.22 15:04:01 | 00,000,000 | ---D | C] -- C:\_OTL [2009.12.22 14:28:33 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 13:54:31 | 00,000,000 | ---D | C] -- C:\Program Files\MSECACHE [2009.12.22 13:01:59 | 02,025,768 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 13:01:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2009.12.21 22:58:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:21 | 00,891,208 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.21 22:33:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData [2009.12.21 22:05:35 | 00,000,000 | ---D | C] -- C:\Program Files\Anti Trojan Elite [2009.12.21 21:44:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.12.20 16:40:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\My Documents\ICQ [2009.12.12 10:40:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Desktop\sborna papka [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2009.10.08 13:40:58 | 00,848,712 | ---- | C] (AVG Technologies) -- C:\Program Files\avg_free_stb_all_8_32_cnet.exe [2009.08.26 14:40:55 | 02,032,936 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2009.08.26 14:15:38 | 16,445,408 | ---- | C] (Macrovision Corporation) -- C:\Program Files\install_abv_icq65.exe [2009.08.26 14:11:57 | 01,925,024 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\install_flash_player.exe [2009.08.26 14:06:42 | 07,562,568 | ---- | C] (Opera Software ASA) -- C:\Program Files\Opera_964_int_Setup.exe ========== Files - Modified Within 30 Days ========== [2009.12.22 17:05:33 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\cureit.exe [2009.12.22 17:03:14 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 16:01:52 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\launch.exe [2009.12.22 15:55:52 | 00,288,654 | ---- | M] ( ) -- C:\Documents and Settings\Desi\Desktop\SafeBootKeyRepair.exe [2009.12.22 15:54:05 | 00,185,065 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\FixPolicies.exe [2009.12.22 15:41:48 | 14,827,320 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\Desi\Desktop\6m3ze36z.exe [2009.12.22 15:34:53 | 00,229,488 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2009.12.22 15:34:16 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009.12.22 15:34:15 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009.12.22 15:33:23 | 06,553,600 | -H-- | M] () -- C:\Documents and Settings\Desi\NTUSER.DAT [2009.12.22 15:33:23 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Desi\ntuser.ini [2009.12.22 15:33:13 | 00,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts [2009.12.22 15:07:10 | 00,983,040 | RHS- | M] () -- C:\tboxobkxepbf.bat [2009.12.22 13:02:01 | 02,025,768 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 00:26:26 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-132452.backup [2009.12.21 23:22:19 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-002625.backup [2009.12.21 22:59:35 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.21 22:58:37 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:28 | 00,891,208 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.20 11:01:01 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009.12.18 16:57:52 | 05,740,883 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:57:18 | 06,163,989 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:56:38 | 05,642,632 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:56:08 | 05,342,296 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:55:42 | 05,164,651 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:55:28 | 04,970,130 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:55:06 | 05,198,565 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:54:46 | 04,665,685 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:54:31 | 05,819,569 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:54:11 | 04,926,737 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:53:00 | 04,747,578 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:53:00 | 04,563,397 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:51:37 | 07,578,481 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.18 16:50:15 | 05,965,924 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:50:05 | 04,880,562 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:49:20 | 04,958,286 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:49:19 | 04,316,218 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:48:37 | 04,425,408 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:46:08 | 04,318,089 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:45:55 | 03,073,303 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:43:59 | 04,030,138 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:39:27 | 03,220,078 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:38:58 | 04,887,211 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.16 12:34:00 | 00,000,766 | ---- | M] () -- C:\WINDOWS\win.ini [2009.12.15 22:17:42 | 00,066,351 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.06 10:15:41 | 00,022,528 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.12.05 20:39:22 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009.12.05 20:17:21 | 00,103,675 | ---- | M] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt ========== Files Created - No Company Name ========== [2009.12.22 17:05:33 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\cureit.exe [2009.12.22 16:01:47 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\launch.exe [2009.12.22 15:39:51 | 00,185,065 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\FixPolicies.exe [2009.12.21 22:59:35 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.18 16:51:38 | 05,740,883 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:29:23 | 06,163,989 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:26:15 | 05,342,296 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:25:48 | 05,198,565 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:25:48 | 05,164,651 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:25:48 | 04,970,130 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:25:48 | 04,926,737 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:25:48 | 04,665,685 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:25:11 | 04,887,211 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.18 16:25:11 | 04,880,562 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:25:11 | 04,747,578 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:24:04 | 05,819,569 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:24:04 | 04,318,089 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:24:04 | 04,316,218 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:24:04 | 04,030,138 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:23:40 | 05,965,924 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:23:40 | 04,563,397 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:23:40 | 04,425,408 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:23:40 | 03,220,078 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:23:40 | 03,073,303 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:23:17 | 05,642,632 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:23:17 | 04,958,286 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:22:33 | 07,578,481 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.15 22:17:42 | 00,066,351 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.05 20:17:21 | 00,103,675 | ---- | C] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [2009.09.13 09:48:02 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\vmcoinst_vc0323.dll [2009.09.13 09:45:31 | 21,117,732 | ---- | C] () -- C:\Program Files\CNR-WCAM413_Drv_XPWV.zip [2009.08.31 08:49:21 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009.06.07 14:07:12 | 00,022,528 | ---- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.07 14:03:10 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009.06.07 14:03:08 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009.06.07 14:03:08 | 02,255,360 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2009.06.07 14:03:08 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009.06.07 14:03:08 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009.06.07 14:03:07 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009.06.07 14:03:07 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2009.06.07 12:45:13 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009.04.30 23:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009.04.30 23:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009.04.30 23:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009.04.30 23:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll ========== LOP Check ========== [2009.08.26 14:17:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ [2009.08.26 14:33:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\ICQ [2009.08.26 14:07:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\Opera [2009.12.18 18:15:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\XnView ========== Purity Check ========== < End of report > OTL Extras logfile created on: 22.12.2009 г. 17:08:08 - Run 2 OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Desi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 73,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 87,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 24,16 Gb Free Space | 49,48% Space Free | Partition Type: NTFS Drive D: | 104,55 Gb Total Space | 23,08 Gb Free Space | 22,08% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Directory [Разглеждане с XnView] -- "C:\Program Files\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.) "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{36820BCA-FC55-452E-9085-6E6F1F55508D}" = Vimicro USB2.0 PC Camera (VC0323) "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5 "{6AECFE2F-86D3-4EA8-B110-19CDAA343199}" = ItaEst - Taka e! "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{C67A767D-F3B4-11D5-9118-000102B7E8EE}" = Phonetic XP "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition "{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64 "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook! "ICQToolbar" = ICQ Toolbar "KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.0 (Full) "NVIDIA Drivers" = NVIDIA Drivers "VLC media player" = VLC media player 0.9.7 "Winamp" = Winamp "Winamp Toolbar" = Winamp Toolbar "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = Архиватор WinRAR "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 08.10.2009 г. 07:52:12 | Computer Name = HOME-PC1 | Source = Application Hang | ID = 1002 Description = Hanging application opera.exe, version 9.64.10487.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 20.10.2009 г. 07:43:32 | Computer Name = HOME-PC1 | Source = Application Hang | ID = 1002 Description = Hanging application winamp.exe, version 5.5.6.2512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 26.10.2009 г. 12:11:12 | Computer Name = HOME-PC1 | Source = Application Error | ID = 1000 Description = Faulting application opera.exe, version 9.64.10487.0, faulting module npswf32.dll, version 10.0.32.18, fault address 0x00096ee0. [ System Events ] Error - 22.12.2009 г. 03:38:13 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 07:10:55 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 09:04:02 | Computer Name = HOME-PC1 | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). Error - 22.12.2009 г. 09:04:02 | Computer Name = HOME-PC1 | Source = Service Control Manager | ID = 7034 Description = The ICQ Service service terminated unexpectedly. It has done this 1 time(s). Error - 22.12.2009 г. 09:04:02 | Computer Name = HOME-PC1 | Source = Service Control Manager | ID = 7034 Description = The NMIndexingService service terminated unexpectedly. It has done this 1 time(s). Error - 22.12.2009 г. 09:06:51 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 09:33:06 | Computer Name = HOME-PC1 | Source = Service Control Manager | ID = 7034 Description = The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). Error - 22.12.2009 г. 09:33:06 | Computer Name = HOME-PC1 | Source = Service Control Manager | ID = 7034 Description = The ICQ Service service terminated unexpectedly. It has done this 1 time(s). Error - 22.12.2009 г. 09:33:07 | Computer Name = HOME-PC1 | Source = Service Control Manager | ID = 7034 Description = The NMIndexingService service terminated unexpectedly. It has done this 1 time(s). Error - 22.12.2009 г. 09:34:41 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. < End of report >
-
Вирус,изпратен по Скайп. [РЕШЕН]
Reg export of SafeBoot key after repair: ======================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot] "AlternateShell"="cmd.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SharedAccess] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] @="Net" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] @="NetClient" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] @="NetService" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] @="NetTrans" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" ======================== За ссъйаление не мога да изтегля Dr.Web CureIt Не мога да изтегля Dr.Web CureIt Моля ви дайте ми друг линк за Dr.Web !
-
Вирус,изпратен по Скайп. [РЕШЕН]
Ето го,по начина,който трябва All processes killed ========== OTL ========== No active process named rmslt[1].exe was found! No active process named rmslt.exe was found! No active process named ivnbxpdvhxoxbjyxq.exe was found! No active process named cfnrdlp.exe was found! No active process named TeaTimer.exe was found! Registry value HKEY_USERS\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_USERS\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\bhszozgrwf deleted successfully. C:\WINDOWS\system32\bnermdqhshxfipdb.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\bnermdqhshxfipdb deleted successfully. C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\bhszozgrwf deleted successfully. C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\sbpzrfpdlxkpp deleted successfully. C:\WINDOWS\system32\ivnbxpdvhxoxbjyxq.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\wdpxnzhtzju deleted successfully. C:\WINDOWS\system32\rfynkdslyphrwfvvpa.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\whxjdtfvftiprxk deleted successfully. C:\Documents and Settings\Desi\Local Settings\Temp\rfynkdslyphrwfvvpa.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\tdsdwlwluhvbch deleted successfully. C:\WINDOWS\system32\pfarqlcxmfzlsdvxtglb.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\wdpxnzhtzju deleted successfully. File C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\tboxobkxepbf deleted successfully. C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\inxdrbhrv deleted successfully. C:\Documents and Settings\Desi\Local Settings\Temp\crlbztjdrjcntduvqcg.exe moved successfully. C:\autorun.inf moved successfully. D:\autorun.inf moved successfully. C:\WINDOWS\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx moved successfully. C:\WINDOWS\system32\eflnxdfllpurjfivcaqrxzjprxx.gdv moved successfully. C:\WINDOWS\eflnxdfllpurjfivcaqrxzjprxx.gdv moved successfully. C:\Program Files\eflnxdfllpurjfivcaqrxzjprxx.gdv moved successfully. C:\Documents and Settings\Desi\Local Settings\Application Data\eflnxdfllpurjfivcaqrxzjprxx.gdv moved successfully. C:\WINDOWS\system32\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx moved successfully. C:\Program Files\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx moved successfully. C:\Documents and Settings\Desi\Local Settings\Application Data\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx moved successfully. C:\WINDOWS\system32\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj moved successfully. C:\WINDOWS\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj moved successfully. C:\Program Files\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj moved successfully. C:\Documents and Settings\Desi\Local Settings\Application Data\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj moved successfully. C:\WINDOWS\vnkdeburidznwjdhfubtqj.exe moved successfully. C:\WINDOWS\rfynkdslyphrwfvvpa.exe moved successfully. C:\WINDOWS\pfarqlcxmfzlsdvxtglb.exe moved successfully. File C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe not found. C:\WINDOWS\evrjjfxtjdyltfybymsjf.exe moved successfully. C:\WINDOWS\crlbztjdrjcntduvqcg.exe moved successfully. C:\WINDOWS\bnermdqhshxfipdb.exe moved successfully. File C:\Documents and Settings\Desi\Desktop\rmslt.exe not found. C:\Documents and Settings\Desi\Desktop\ComboFix.exe moved successfully. C:\WINDOWS\system32\vnkdeburidznwjdhfubtqj.exe moved successfully. File C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe not found. File C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe not found. File C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe not found. C:\WINDOWS\system32\evrjjfxtjdyltfybymsjf.exe moved successfully. C:\WINDOWS\system32\crlbztjdrjcntduvqcg.exe moved successfully. File C:\WINDOWS\System32\bnermdqhshxfipdb.exe not found. C:\WINDOWS\system32\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz moved successfully. C:\WINDOWS\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz moved successfully. C:\Program Files\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz moved successfully. C:\Documents and Settings\Desi\Local Settings\Application Data\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz moved successfully. C:\WINDOWS\system32\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh moved successfully. C:\WINDOWS\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh moved successfully. C:\Program Files\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh moved successfully. C:\Documents and Settings\Desi\Local Settings\Application Data\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh moved successfully. ========== FILES ========== File\Folder C:\Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5\A9W1M5O1\rmslt[1].exe not found. File\Folder C:\Documents and Settings\Desi\Desktop\rmslt.exe not found. File\Folder C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe not found. C:\Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Desi ->Temp folder emptied: 3028760 bytes ->Temporary Internet Files folder emptied: 7198540 bytes ->Opera cache emptied: 9569847 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 19,00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.1.19.0 log created on 12222009_153306 Files\Folders moved on Reboot... Registry entries deleted on Reboot...
-
Вирус,изпратен по Скайп. [РЕШЕН]
All processes killed Error: Unable to interpret <PRC - [2009.12.22 14:05:40 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5\A9W1M5O1\rmslt[1].exe> in the current context! Error: Unable to interpret <PRC - [2009.12.22 14:04:50 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe> in the current context! Error: Unable to interpret <PRC - [2009.12.22 09:38:05 | 00,569,344 | RHS- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe> in the current context! Error: Unable to interpret <PRC - [2009.12.21 21:23:56 | 00,696,320 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe> in the current context! Error: Unable to interpret <PRC - [2009.03.05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe> in the current context! Error: Unable to interpret <IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found> in the current context! Error: Unable to interpret <O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.> in the current context! Error: Unable to interpret <O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.> in the current context! Error: Unable to interpret <O4 - HKLM..\Run: [bhszozgrwf] C:\WINDOWS\System32\bnermdqhshxfipdb.exe ()> in the current context! Error: Unable to interpret <O4 - HKLM..\Run: [bnermdqhshxfipdb] C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe ()> in the current context! Error: Unable to interpret <O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bhszozgrwf] C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe ()> in the current context! Error: Unable to interpret <O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [sbpzrfpdlxkpp] C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe ()> in the current context! Error: Unable to interpret <O4 - HKLM..\RunOnce: [wdpxnzhtzju] C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe ()> in the current context! Error: Unable to interpret <O4 - HKLM..\RunOnce: [whxjdtfvftiprxk] C:\Documents and Settings\Desi\Local Settings\Temp\rfynkdslyphrwfvvpa.exe ()> in the current context! Error: Unable to interpret <O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\RunOnce: [tdsdwlwluhvbch] C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe ()> in the current context! Error: Unable to interpret <O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\RunOnce: [wdpxnzhtzju] C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe ()> in the current context! Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tboxobkxepbf = ivnbxpdvhxoxbjyxq.exe ()> in the current context! Error: Unable to interpret <O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: inxdrbhrv = C:\DOCUME~1\Desi\LOCALS~1\Temp\crlbztjdrjcntduvqcg.exe ()> in the current context! Error: Unable to interpret <O32 - AutoRun File - [2009.12.22 13:28:52 | 00,000,821 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]> in the current context! Error: Unable to interpret <O32 - AutoRun File - [2009.12.22 13:28:52 | 00,000,810 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]> in the current context! Error: Unable to interpret <[2009.12.22 14:36:32 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx> in the current context! Error: Unable to interpret <[2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\eflnxdfllpurjfivcaqrxzjprxx.gdv> in the current context! Error: Unable to interpret <[2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\eflnxdfllpurjfivcaqrxzjprxx.gdv> in the current context! Error: Unable to interpret <[2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\Program Files\eflnxdfllpurjfivcaqrxzjprxx.gdv> in the current context! Error: Unable to interpret <[2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\eflnxdfllpurjfivcaqrxzjprxx.gdv> in the current context! Error: Unable to interpret <[2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx> in the current context! Error: Unable to interpret <[2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\Program Files\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx> in the current context! Error: Unable to interpret <[2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx> in the current context! Error: Unable to interpret <[2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj> in the current context! Error: Unable to interpret <[2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\WINDOWS\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj> in the current context! Error: Unable to interpret <[2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\Program Files\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj> in the current context! Error: Unable to interpret <[2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\vnkdeburidznwjdhfubtqj.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\rfynkdslyphrwfvvpa.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\pfarqlcxmfzlsdvxtglb.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\evrjjfxtjdyltfybymsjf.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\crlbztjdrjcntduvqcg.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\bnermdqhshxfipdb.exe> in the current context! Error: Unable to interpret <[2009.12.22 14:04:50 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:43:47 | 03,861,572 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ComboFix.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\vnkdeburidznwjdhfubtqj.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\evrjjfxtjdyltfybymsjf.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcg.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\bnermdqhshxfipdb.exe> in the current context! Error: Unable to interpret <[2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz> in the current context! Error: Unable to interpret <[2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\WINDOWS\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz> in the current context! Error: Unable to interpret <[2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\Program Files\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz> in the current context! Error: Unable to interpret <[2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz> in the current context! Error: Unable to interpret <[2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh> in the current context! Error: Unable to interpret <[2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh> in the current context! Error: Unable to interpret <[2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh> in the current context! Error: Unable to interpret <[2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh> in the current context! ========== FILES ========== C:\Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5\A9W1M5O1\rmslt[1].exe moved successfully. C:\Documents and Settings\Desi\Desktop\rmslt.exe moved successfully. C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe moved successfully. C:\Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Desi ->Temp folder emptied: 45678430 bytes ->Temporary Internet Files folder emptied: 106599752 bytes ->Opera cache emptied: 65710498 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2162283 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 210,00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.1.19.0 log created on 12222009_150401 Files\Folders moved on Reboot... C:\Documents and Settings\Desi\Local Settings\Temp\28cab0.msi moved successfully. Registry entries deleted on Reboot...
-
Вирус,изпратен по Скайп. [РЕШЕН]
Здравейте,напоследък чета,че се вихри вирус по Скайп и да се оплача снощи явно заразих компа с нещо такова.Не мога да пусна антивирусна,да изтегля друга,и въобще целия компютър е много зле!Прочетох подобна тема преди малко,инсталнах OTL и ми излязоха тези файлове.Моля помогнете ми!!!-Ето и какво излезе след OTL-G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2009.12.22 14:28:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe PRC - [2009.12.22 14:05:40 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5\A9W1M5O1\rmslt[1].exe PRC - [2009.12.22 14:04:50 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe PRC - [2009.12.22 13:54:31 | 00,359,656 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Desi\Desktop\msicuu2.exe PRC - [2009.12.22 09:38:05 | 00,569,344 | RHS- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe PRC - [2009.12.21 21:23:56 | 00,696,320 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe PRC - [2009.07.01 18:37:06 | 00,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe PRC - [2009.06.14 02:48:44 | 04,076,544 | ---- | M] (ISecSoft) -- C:\Program Files\Anti Trojan Elite\TJEnder.exe PRC - [2009.04.30 23:30:18 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe PRC - [2009.03.05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PRC - [2009.03.01 12:59:42 | 00,172,792 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ6.5\ICQ.exe PRC - [2008.10.19 13:30:02 | 00,222,456 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe PRC - [2008.04.14 04:42:24 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe PRC - [2008.04.14 04:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007.06.27 18:04:00 | 01,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2007.06.27 18:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe PRC - [2007.06.27 18:03:40 | 00,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe PRC - [2007.01.09 11:57:02 | 00,212,992 | ---- | M] () -- C:\WINDOWS\VMSnap23.exe PRC - [2005.07.26 08:54:28 | 00,716,800 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4.exe PRC - [2005.05.18 15:00:00 | 00,925,696 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe ========== Modules (SafeList) ========== MOD - [2009.12.22 14:28:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2009.04.30 23:30:18 | 00,168,004 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (nvsvc) SRV - [2008.10.19 13:30:02 | 00,222,456 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2007.06.29 18:16:56 | 00,800,040 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService) SRV - [2007.06.27 18:04:00 | 00,279,848 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService) SRV - [2003.07.28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - [2009.04.30 21:02:00 | 08,055,584 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2009.04.28 22:20:06 | 00,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20) DRV - [2008.04.13 21:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv) DRV - [2008.04.13 21:06:06 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2007.04.03 15:22:12 | 00,260,224 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbvm323.sys -- (ZSMC326) Vimicro USB2.0 PC Camera(VC0323) DRV - [2006.08.14 05:09:00 | 00,083,200 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2006.08.08 10:25:40 | 00,476,672 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vmfilter323.sys -- (vmfilter323) DRV - [2006.07.04 23:01:00 | 00,151,552 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService) DRV - [2005.12.19 15:00:00 | 00,092,800 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (AEAudioService) DRV - [2005.06.07 15:00:00 | 00,393,088 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService) DRV - [2004.08.04 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/ IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: (366461 bytes) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 12612 more lines... O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe (ISecSoft) O4 - HKLM..\Run: [bhszozgrwf] C:\WINDOWS\System32\bnermdqhshxfipdb.exe () O4 - HKLM..\Run: [bigDogPath323Domino] C:\WINDOWS\Domino.exe File not found O4 - HKLM..\Run: [bigDogPath323VMSnap] C:\WINDOWS\VMSnap23.exe () O4 - HKLM..\Run: [bnermdqhshxfipdb] C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bhszozgrwf] C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [iCQ] C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [sbpzrfpdlxkpp] C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKLM..\RunOnce: [wdpxnzhtzju] C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe () O4 - HKLM..\RunOnce: [wextract_cleanup0] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation) O4 - HKLM..\RunOnce: [whxjdtfvftiprxk] C:\Documents and Settings\Desi\Local Settings\Temp\rfynkdslyphrwfvvpa.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\RunOnce: [tdsdwlwluhvbch] C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\RunOnce: [wdpxnzhtzju] C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tboxobkxepbf = ivnbxpdvhxoxbjyxq.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: inxdrbhrv = C:\DOCUME~1\Desi\LOCALS~1\Temp\crlbztjdrjcntduvqcg.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptbehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptbehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O7 - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.07 10:58:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009.12.22 13:28:52 | 00,000,821 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2009.12.22 13:28:52 | 00,000,810 | RHS- | M] () - D:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2009.12.22 14:28:33 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 13:54:31 | 00,000,000 | ---D | C] -- C:\Program Files\MSECACHE [2009.12.22 13:54:24 | 00,359,656 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Desi\Desktop\msicuu2.exe [2009.12.22 13:01:59 | 02,025,768 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 13:01:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2009.12.21 22:58:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:21 | 00,891,208 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.21 22:33:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData [2009.12.21 22:05:35 | 00,000,000 | ---D | C] -- C:\Program Files\Anti Trojan Elite [2009.12.21 21:44:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.12.20 16:40:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\My Documents\ICQ [2009.12.12 10:40:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Desktop\sborna papka [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2009.10.08 13:40:58 | 00,848,712 | ---- | C] (AVG Technologies) -- C:\Program Files\avg_free_stb_all_8_32_cnet.exe [2009.08.26 14:40:55 | 02,032,936 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2009.08.26 14:15:38 | 16,445,408 | ---- | C] (Macrovision Corporation) -- C:\Program Files\install_abv_icq65.exe [2009.08.26 14:11:57 | 01,925,024 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\install_flash_player.exe [2009.08.26 14:06:42 | 07,562,568 | ---- | C] (Opera Software ASA) -- C:\Program Files\Opera_964_int_Setup.exe [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2009.12.22 14:36:32 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\Program Files\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\Program Files\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\WINDOWS\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\Program Files\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\vnkdeburidznwjdhfubtqj.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\rfynkdslyphrwfvvpa.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\pfarqlcxmfzlsdvxtglb.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\evrjjfxtjdyltfybymsjf.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\crlbztjdrjcntduvqcg.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\bnermdqhshxfipdb.exe [2009.12.22 14:28:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 14:04:50 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe [2009.12.22 13:54:31 | 00,359,656 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Desi\Desktop\msicuu2.exe [2009.12.22 13:43:47 | 03,861,572 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ComboFix.exe [2009.12.22 13:28:52 | 00,000,821 | RHS- | M] () -- C:\autorun.inf [2009.12.22 13:26:51 | 06,553,600 | -H-- | M] () -- C:\Documents and Settings\Desi\NTUSER.DAT [2009.12.22 13:24:52 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\vnkdeburidznwjdhfubtqj.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\evrjjfxtjdyltfybymsjf.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcg.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\bnermdqhshxfipdb.exe [2009.12.22 13:10:33 | 00,229,488 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2009.12.22 13:10:30 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009.12.22 13:10:28 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009.12.22 13:09:30 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Desi\ntuser.ini [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\WINDOWS\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\Program Files\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:02:01 | 02,025,768 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 00:26:26 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-132452.backup [2009.12.21 23:22:19 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-002625.backup [2009.12.21 22:59:35 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.21 22:58:37 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:28 | 00,891,208 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.20 11:01:01 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009.12.18 16:57:52 | 05,740,883 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:57:18 | 06,163,989 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:56:38 | 05,642,632 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:56:08 | 05,342,296 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:55:42 | 05,164,651 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:55:28 | 04,970,130 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:55:06 | 05,198,565 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:54:46 | 04,665,685 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:54:31 | 05,819,569 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:54:11 | 04,926,737 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:53:00 | 04,747,578 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:53:00 | 04,563,397 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:51:37 | 07,578,481 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.18 16:50:15 | 05,965,924 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:50:05 | 04,880,562 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:49:20 | 04,958,286 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:49:19 | 04,316,218 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:48:37 | 04,425,408 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:46:08 | 04,318,089 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:45:55 | 03,073,303 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:43:59 | 04,030,138 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:39:27 | 03,220,078 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:38:58 | 04,887,211 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.16 12:34:00 | 00,000,766 | ---- | M] () -- C:\WINDOWS\win.ini [2009.12.15 22:17:42 | 00,066,351 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.06 10:15:41 | 00,022,528 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.12.05 20:39:22 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009.12.05 20:17:21 | 00,103,675 | ---- | M] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2009.12.22 14:04:37 | 02,767,360 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe [2009.12.22 13:43:47 | 03,861,572 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\ComboFix.exe [2009.12.21 22:59:35 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.21 21:24:20 | 00,000,821 | RHS- | C] () -- C:\autorun.inf [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\System32\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\Program Files\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\WINDOWS\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\Program Files\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\WINDOWS\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\Program Files\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\System32\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\Program Files\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\System32\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\Program Files\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\vnkdeburidznwjdhfubtqj.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\vnkdeburidznwjdhfubtqj.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\rfynkdslyphrwfvvpa.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\pfarqlcxmfzlsdvxtglb.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\evrjjfxtjdyltfybymsjf.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\evrjjfxtjdyltfybymsjf.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcg.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\crlbztjdrjcntduvqcg.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\bnermdqhshxfipdb.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\bnermdqhshxfipdb.exe [2009.12.18 16:51:38 | 05,740,883 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:29:23 | 06,163,989 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:26:15 | 05,342,296 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:25:48 | 05,198,565 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:25:48 | 05,164,651 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:25:48 | 04,970,130 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:25:48 | 04,926,737 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:25:48 | 04,665,685 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:25:11 | 04,887,211 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.18 16:25:11 | 04,880,562 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:25:11 | 04,747,578 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:24:04 | 05,819,569 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:24:04 | 04,318,089 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:24:04 | 04,316,218 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:24:04 | 04,030,138 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:23:40 | 05,965,924 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:23:40 | 04,563,397 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:23:40 | 04,425,408 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:23:40 | 03,220,078 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:23:40 | 03,073,303 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:23:17 | 05,642,632 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:23:17 | 04,958,286 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:22:33 | 07,578,481 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.15 22:17:42 | 00,066,351 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.05 20:17:21 | 00,103,675 | ---- | C] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [2009.09.13 09:48:02 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\vmcoinst_vc0323.dll [2009.09.13 09:45:31 | 21,117,732 | ---- | C] () -- C:\Program Files\CNR-WCAM413_Drv_XPWV.zip [2009.08.31 08:49:21 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009.06.07 14:07:12 | 00,022,528 | ---- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.07 14:03:10 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009.06.07 14:03:08 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009.06.07 14:03:08 | 02,255,360 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2009.06.07 14:03:08 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009.06.07 14:03:08 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009.06.07 14:03:07 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009.06.07 14:03:07 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2009.06.07 12:45:13 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009.04.30 23:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009.04.30 23:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009.04.30 23:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009.04.30 23:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll ========== LOP Check ========== [2009.08.26 14:17:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ [2009.08.26 14:33:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\ICQ [2009.08.26 14:07:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\Opera [2009.12.18 18:15:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\XnView ========== Purity Check ========== OTL Extras logfile created on: 22.12.2009 г. 14:35:50 - Run 1 OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Desi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 76,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 89,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 24,02 Gb Free Space | 49,19% Space Free | Partition Type: NTFS Drive D: | 104,55 Gb Total Space | 23,08 Gb Free Space | 22,08% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Directory [Разглеждане с XnView] -- "C:\Program Files\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.) "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{36820BCA-FC55-452E-9085-6E6F1F55508D}" = Vimicro USB2.0 PC Camera (VC0323) "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5 "{6AECFE2F-86D3-4EA8-B110-19CDAA343199}" = ItaEst - Taka e! "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{C67A767D-F3B4-11D5-9118-000102B7E8EE}" = Phonetic XP "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition "{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64 "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook! "ICQToolbar" = ICQ Toolbar "KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.0 (Full) "NVIDIA Drivers" = NVIDIA Drivers "VLC media player" = VLC media player 0.9.7 "Winamp" = Winamp "Winamp Toolbar" = Winamp Toolbar "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = Архиватор WinRAR "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 08.10.2009 г. 07:52:12 | Computer Name = HOME-PC1 | Source = Application Hang | ID = 1002 Description = Hanging application opera.exe, version 9.64.10487.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 20.10.2009 г. 07:43:32 | Computer Name = HOME-PC1 | Source = Application Hang | ID = 1002 Description = Hanging application winamp.exe, version 5.5.6.2512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 26.10.2009 г. 12:11:12 | Computer Name = HOME-PC1 | Source = Application Error | ID = 1000 Description = Faulting application opera.exe, version 9.64.10487.0, faulting module npswf32.dll, version 10.0.32.18, fault address 0x00096ee0. [ System Events ] Error - 11.12.2009 г. 06:52:03 | Computer Name = HOME-PC1 | Source = Cdrom | ID = 262155 Description = The driver detected a controller error on \Device\CdRom0. Error - 21.12.2009 г. 16:07:15 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 21.12.2009 г. 17:23:57 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 03:38:13 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 07:10:55 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. < End of report > < End of report
-
Вирус,изпратен по Скайп. [РЕШЕН]
Здравейте и аз имам същият проблем,кажете какво точно да направя и много благодаря предварително! Отворете си нова тема и опишете проблема си! Ето и какво излезе след OTL-G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2009.12.22 14:28:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe PRC - [2009.12.22 14:05:40 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temporary Internet Files\Content.IE5\A9W1M5O1\rmslt[1].exe PRC - [2009.12.22 14:04:50 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe PRC - [2009.12.22 13:54:31 | 00,359,656 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Desi\Desktop\msicuu2.exe PRC - [2009.12.22 09:38:05 | 00,569,344 | RHS- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe PRC - [2009.12.21 21:23:56 | 00,696,320 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Temp\cfnrdlp.exe PRC - [2009.07.01 18:37:06 | 00,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe PRC - [2009.06.14 02:48:44 | 04,076,544 | ---- | M] (ISecSoft) -- C:\Program Files\Anti Trojan Elite\TJEnder.exe PRC - [2009.04.30 23:30:18 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe PRC - [2009.03.05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PRC - [2009.03.01 12:59:42 | 00,172,792 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ6.5\ICQ.exe PRC - [2008.10.19 13:30:02 | 00,222,456 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe PRC - [2008.04.14 04:42:24 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe PRC - [2008.04.14 04:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007.06.27 18:04:00 | 01,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2007.06.27 18:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe PRC - [2007.06.27 18:03:40 | 00,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe PRC - [2007.01.09 11:57:02 | 00,212,992 | ---- | M] () -- C:\WINDOWS\VMSnap23.exe PRC - [2005.07.26 08:54:28 | 00,716,800 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4.exe PRC - [2005.05.18 15:00:00 | 00,925,696 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe ========== Modules (SafeList) ========== MOD - [2009.12.22 14:28:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2009.04.30 23:30:18 | 00,168,004 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (nvsvc) SRV - [2008.10.19 13:30:02 | 00,222,456 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2007.06.29 18:16:56 | 00,800,040 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService) SRV - [2007.06.27 18:04:00 | 00,279,848 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService) SRV - [2003.07.28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose) ========== Driver Services (SafeList) ========== DRV - [2009.04.30 21:02:00 | 08,055,584 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2009.04.28 22:20:06 | 00,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20) DRV - [2008.04.13 21:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv) DRV - [2008.04.13 21:06:06 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2007.04.03 15:22:12 | 00,260,224 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbvm323.sys -- (ZSMC326) Vimicro USB2.0 PC Camera(VC0323) DRV - [2006.08.14 05:09:00 | 00,083,200 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2006.08.08 10:25:40 | 00,476,672 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vmfilter323.sys -- (vmfilter323) DRV - [2006.07.04 23:01:00 | 00,151,552 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService) DRV - [2005.12.19 15:00:00 | 00,092,800 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (AEAudioService) DRV - [2005.06.07 15:00:00 | 00,393,088 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService) DRV - [2004.08.04 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/ IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKU\S-1-5-21-823518204-602609370-725345543-1003\S-1-5-21-823518204-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: (366461 bytes) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 1-2005-search.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 12612 more lines... O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe (ISecSoft) O4 - HKLM..\Run: [bhszozgrwf] C:\WINDOWS\System32\bnermdqhshxfipdb.exe () O4 - HKLM..\Run: [bigDogPath323Domino] C:\WINDOWS\Domino.exe File not found O4 - HKLM..\Run: [bigDogPath323VMSnap] C:\WINDOWS\VMSnap23.exe () O4 - HKLM..\Run: [bnermdqhshxfipdb] C:\Documents and Settings\Desi\Local Settings\Temp\ivnbxpdvhxoxbjyxq.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [bhszozgrwf] C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [iCQ] C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [sbpzrfpdlxkpp] C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKLM..\RunOnce: [wdpxnzhtzju] C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe () O4 - HKLM..\RunOnce: [wextract_cleanup0] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation) O4 - HKLM..\RunOnce: [whxjdtfvftiprxk] C:\Documents and Settings\Desi\Local Settings\Temp\rfynkdslyphrwfvvpa.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\RunOnce: [tdsdwlwluhvbch] C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe () O4 - HKU\S-1-5-21-823518204-602609370-725345543-1003..\RunOnce: [wdpxnzhtzju] C:\Documents and Settings\Desi\Local Settings\Temp\pfarqlcxmfzlsdvxtglb.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: tboxobkxepbf = ivnbxpdvhxoxbjyxq.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: inxdrbhrv = C:\DOCUME~1\Desi\LOCALS~1\Temp\crlbztjdrjcntduvqcg.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 O7 - HKU\S-1-5-21-823518204-602609370-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.) O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKU\S-1-5-21-823518204-602609370-725345543-1003\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone. O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.07 10:58:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009.12.22 13:28:52 | 00,000,821 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2009.12.22 13:28:52 | 00,000,810 | RHS- | M] () - D:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2009.12.22 14:28:33 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 13:54:31 | 00,000,000 | ---D | C] -- C:\Program Files\MSECACHE [2009.12.22 13:54:24 | 00,359,656 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Desi\Desktop\msicuu2.exe [2009.12.22 13:01:59 | 02,025,768 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 13:01:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2009.12.21 22:59:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2009.12.21 22:58:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:21 | 00,891,208 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.21 22:33:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData [2009.12.21 22:05:35 | 00,000,000 | ---D | C] -- C:\Program Files\Anti Trojan Elite [2009.12.21 21:44:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.12.20 16:40:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\My Documents\ICQ [2009.12.12 10:40:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Desi\Desktop\sborna papka [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2009.10.08 13:46:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2009.10.08 13:40:58 | 00,848,712 | ---- | C] (AVG Technologies) -- C:\Program Files\avg_free_stb_all_8_32_cnet.exe [2009.08.26 14:40:55 | 02,032,936 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2009.08.26 14:15:38 | 16,445,408 | ---- | C] (Macrovision Corporation) -- C:\Program Files\install_abv_icq65.exe [2009.08.26 14:11:57 | 01,925,024 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\install_flash_player.exe [2009.08.26 14:06:42 | 07,562,568 | ---- | C] (Opera Software ASA) -- C:\Program Files\Opera_964_int_Setup.exe [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2009.12.22 14:36:32 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\System32\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\WINDOWS\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\Program Files\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:32 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\WINDOWS\System32\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\Program Files\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:31 | 00,002,408 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\WINDOWS\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\Program Files\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:36:19 | 00,002,348 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\vnkdeburidznwjdhfubtqj.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\rfynkdslyphrwfvvpa.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\pfarqlcxmfzlsdvxtglb.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\evrjjfxtjdyltfybymsjf.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\crlbztjdrjcntduvqcg.exe [2009.12.22 14:35:30 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\bnermdqhshxfipdb.exe [2009.12.22 14:28:36 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Desi\Desktop\OTL.exe [2009.12.22 14:04:50 | 02,767,360 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe [2009.12.22 13:54:31 | 00,359,656 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Desi\Desktop\msicuu2.exe [2009.12.22 13:43:47 | 03,861,572 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ComboFix.exe [2009.12.22 13:28:52 | 00,000,821 | RHS- | M] () -- C:\autorun.inf [2009.12.22 13:26:51 | 06,553,600 | -H-- | M] () -- C:\Documents and Settings\Desi\NTUSER.DAT [2009.12.22 13:24:52 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\vnkdeburidznwjdhfubtqj.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\evrjjfxtjdyltfybymsjf.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcg.exe [2009.12.22 13:10:50 | 00,569,344 | RHS- | M] () -- C:\WINDOWS\System32\bnermdqhshxfipdb.exe [2009.12.22 13:10:33 | 00,229,488 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2009.12.22 13:10:30 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009.12.22 13:10:28 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009.12.22 13:09:30 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Desi\ntuser.ini [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\WINDOWS\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\Program Files\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:07:58 | 00,000,528 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.22 13:02:01 | 02,025,768 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\Desi\Desktop\SkypeSetup.exe [2009.12.22 00:26:26 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-132452.backup [2009.12.21 23:22:19 | 00,366,461 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20091222-002625.backup [2009.12.21 22:59:35 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.21 22:58:37 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Desi\Desktop\spybotsd162.exe [2009.12.21 22:54:28 | 00,891,208 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Desi\Desktop\avg_free_stb_en_9_40_free.exe [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\System32\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\WINDOWS\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\Program Files\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.20 11:01:01 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009.12.18 16:57:52 | 05,740,883 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:57:18 | 06,163,989 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:56:38 | 05,642,632 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:56:08 | 05,342,296 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:55:42 | 05,164,651 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:55:28 | 04,970,130 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:55:06 | 05,198,565 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:54:46 | 04,665,685 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:54:31 | 05,819,569 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:54:11 | 04,926,737 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:53:00 | 04,747,578 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:53:00 | 04,563,397 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:51:37 | 07,578,481 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.18 16:50:15 | 05,965,924 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:50:05 | 04,880,562 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:49:20 | 04,958,286 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:49:19 | 04,316,218 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:48:37 | 04,425,408 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:46:08 | 04,318,089 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:45:55 | 03,073,303 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:43:59 | 04,030,138 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:39:27 | 03,220,078 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:38:58 | 04,887,211 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.16 12:34:00 | 00,000,766 | ---- | M] () -- C:\WINDOWS\win.ini [2009.12.15 22:17:42 | 00,066,351 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | M] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.06 10:15:41 | 00,022,528 | ---- | M] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.12.05 20:39:22 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2009.12.05 20:17:21 | 00,103,675 | ---- | M] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2009.12.22 14:04:37 | 02,767,360 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\rmslt.exe [2009.12.22 13:43:47 | 03,861,572 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\ComboFix.exe [2009.12.21 22:59:35 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\Spybot - Search & Destroy.lnk [2009.12.21 21:24:20 | 00,000,821 | RHS- | C] () -- C:\autorun.inf [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\WINDOWS\System32\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\Program Files\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:11 | 00,002,408 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\whxjdtfvftiprxkhyggrhtndpfpdszbhuriqq.rdx [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\WINDOWS\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\Program Files\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,002,348 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\rfynkdslyphrwfvvpadrkzwpexkbtdirhhbmpdwl.bqj [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\WINDOWS\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\Program Files\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:10 | 00,000,528 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\crlbztjdrjcntduvqcgvpfdxnhvngrxhyzugkztjh.rlz [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\System32\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\WINDOWS\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\Program Files\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\bnermdqhshxfipdbtcdpgtofsjujzhkrfdvefr.vqh [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\System32\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\WINDOWS\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\Program Files\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:24:01 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\eflnxdfllpurjfivcaqrxzjprxx.gdv [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\vnkdeburidznwjdhfubtqj.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\vnkdeburidznwjdhfubtqj.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\rfynkdslyphrwfvvpa.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\rfynkdslyphrwfvvpa.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\pfarqlcxmfzlsdvxtglb.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\pfarqlcxmfzlsdvxtglb.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\ivnbxpdvhxoxbjyxq.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\ivnbxpdvhxoxbjyxq.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\evrjjfxtjdyltfybymsjf.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\evrjjfxtjdyltfybymsjf.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\crlbztjdrjcntduvqcg.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\crlbztjdrjcntduvqcg.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\System32\bnermdqhshxfipdb.exe [2009.12.21 21:23:48 | 00,569,344 | RHS- | C] () -- C:\WINDOWS\bnermdqhshxfipdb.exe [2009.12.18 16:51:38 | 05,740,883 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3358.JPG [2009.12.18 16:29:23 | 06,163,989 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_2951.JPG [2009.12.18 16:26:15 | 05,342,296 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3330.JPG [2009.12.18 16:25:48 | 05,198,565 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3309.JPG [2009.12.18 16:25:48 | 05,164,651 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3320.JPG [2009.12.18 16:25:48 | 04,970,130 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3318.JPG [2009.12.18 16:25:48 | 04,926,737 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3319.JPG [2009.12.18 16:25:48 | 04,665,685 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3317.JPG [2009.12.18 16:25:11 | 04,887,211 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3270.JPG [2009.12.18 16:25:11 | 04,880,562 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3271.JPG [2009.12.18 16:25:11 | 04,747,578 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3284.JPG [2009.12.18 16:24:04 | 05,819,569 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3229.JPG [2009.12.18 16:24:04 | 04,318,089 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3242.JPG [2009.12.18 16:24:04 | 04,316,218 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3243.JPG [2009.12.18 16:24:04 | 04,030,138 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3241.JPG [2009.12.18 16:23:40 | 05,965,924 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3207.JPG [2009.12.18 16:23:40 | 04,563,397 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3172.JPG [2009.12.18 16:23:40 | 04,425,408 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3215.JPG [2009.12.18 16:23:40 | 03,220,078 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3205.JPG [2009.12.18 16:23:40 | 03,073,303 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3217.JPG [2009.12.18 16:23:17 | 05,642,632 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3137.JPG [2009.12.18 16:23:17 | 04,958,286 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3164.JPG [2009.12.18 16:22:33 | 07,578,481 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\IMG_3096.JPG [2009.12.15 22:17:42 | 00,066,351 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\PICT3644.JPG [2009.12.15 22:17:10 | 00,068,674 | ---- | C] () -- C:\Documents and Settings\Desi\Desktop\ad.jpg [2009.12.05 20:17:21 | 00,103,675 | ---- | C] () -- C:\Documents and Settings\Desi\My Documents\ca05f20fb380c76093faeeec86ab44e4a711b48einf-proposal.srt [2009.09.13 09:48:02 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\vmcoinst_vc0323.dll [2009.09.13 09:45:31 | 21,117,732 | ---- | C] () -- C:\Program Files\CNR-WCAM413_Drv_XPWV.zip [2009.08.31 08:49:21 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009.06.07 14:07:12 | 00,022,528 | ---- | C] () -- C:\Documents and Settings\Desi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.07 14:03:10 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009.06.07 14:03:08 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009.06.07 14:03:08 | 02,255,360 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2009.06.07 14:03:08 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009.06.07 14:03:08 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009.06.07 14:03:07 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009.06.07 14:03:07 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2009.06.07 12:45:13 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009.04.30 23:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009.04.30 23:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009.04.30 23:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009.04.30 23:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll ========== LOP Check ========== [2009.08.26 14:17:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ [2009.08.26 14:33:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\ICQ [2009.08.26 14:07:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\Opera [2009.12.18 18:15:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Desi\Application Data\XnView ========== Purity Check ========== OTL Extras logfile created on: 22.12.2009 г. 14:35:50 - Run 1 OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Desi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 76,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 89,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 24,02 Gb Free Space | 49,19% Space Free | Partition Type: NTFS Drive D: | 104,55 Gb Total Space | 23,08 Gb Free Space | 22,08% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-PC1 Current User Name: Desi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Directory [Разглеждане с XnView] -- "C:\Program Files\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.) "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{36820BCA-FC55-452E-9085-6E6F1F55508D}" = Vimicro USB2.0 PC Camera (VC0323) "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5 "{6AECFE2F-86D3-4EA8-B110-19CDAA343199}" = ItaEst - Taka e! "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{C67A767D-F3B4-11D5-9118-000102B7E8EE}" = Phonetic XP "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CF097717-F174-4144-954A-FBC4BF301033}" = Nero 7 Ultra Edition "{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64 "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook! "ICQToolbar" = ICQ Toolbar "KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.0 (Full) "NVIDIA Drivers" = NVIDIA Drivers "VLC media player" = VLC media player 0.9.7 "Winamp" = Winamp "Winamp Toolbar" = Winamp Toolbar "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = Архиватор WinRAR "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 08.10.2009 г. 07:52:12 | Computer Name = HOME-PC1 | Source = Application Hang | ID = 1002 Description = Hanging application opera.exe, version 9.64.10487.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 20.10.2009 г. 07:43:32 | Computer Name = HOME-PC1 | Source = Application Hang | ID = 1002 Description = Hanging application winamp.exe, version 5.5.6.2512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 26.10.2009 г. 12:11:12 | Computer Name = HOME-PC1 | Source = Application Error | ID = 1000 Description = Faulting application opera.exe, version 9.64.10487.0, faulting module npswf32.dll, version 10.0.32.18, fault address 0x00096ee0. [ System Events ] Error - 11.12.2009 г. 06:52:03 | Computer Name = HOME-PC1 | Source = Cdrom | ID = 262155 Description = The driver detected a controller error on \Device\CdRom0. Error - 21.12.2009 г. 16:07:15 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 21.12.2009 г. 17:23:57 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 03:38:13 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Error - 22.12.2009 г. 07:10:55 | Computer Name = HOME-PC1 | Source = sr | ID = 1 Description = The System Restore filter encountered the unexpected error '0xC0000034' while processing the file '_filelst.cfg' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. < End of report > < End of report >
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.