Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

TpuHuTu

Потребител
  • Регистрация

  • Последно онлайн

Всичко публикувано от TpuHuTu

  1. 2011/03/05 01:22:09.0234 3088 TDSS rootkit removing tool 2.4.20.0 Mar 2 2011 10:44:30 2011/03/05 01:22:09.0578 3088 ================================================================================ 2011/03/05 01:22:09.0578 3088 SystemInfo: 2011/03/05 01:22:09.0578 3088 2011/03/05 01:22:09.0578 3088 OS Version: 5.1.2600 ServicePack: 3.0 2011/03/05 01:22:09.0578 3088 Product type: Workstation 2011/03/05 01:22:09.0578 3088 ComputerName: PC 2011/03/05 01:22:09.0578 3088 UserName: Puhi 2011/03/05 01:22:09.0578 3088 Windows directory: C:\WINDOWS 2011/03/05 01:22:09.0578 3088 System windows directory: C:\WINDOWS 2011/03/05 01:22:09.0578 3088 Processor architecture: Intel x86 2011/03/05 01:22:09.0578 3088 Number of processors: 2 2011/03/05 01:22:09.0578 3088 Page size: 0x1000 2011/03/05 01:22:09.0578 3088 Boot type: Normal boot 2011/03/05 01:22:09.0578 3088 ================================================================================ 2011/03/05 01:22:09.0718 3088 Initialize success 2011/03/05 01:22:13.0562 2940 ================================================================================ 2011/03/05 01:22:13.0562 2940 Scan started 2011/03/05 01:22:13.0562 2940 Mode: Manual; 2011/03/05 01:22:13.0562 2940 ================================================================================ 2011/03/05 01:22:14.0281 2940 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/03/05 01:22:14.0312 2940 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/03/05 01:22:14.0375 2940 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/03/05 01:22:14.0406 2940 AFD (38d7b715504da4741df35e3594fe2099) C:\WINDOWS\System32\drivers\afd.sys 2011/03/05 01:22:14.0531 2940 AmdLLD (ad8fa28d8ed0d0a689a0559085ce0f18) C:\WINDOWS\system32\DRIVERS\AmdLLD.sys 2011/03/05 01:22:14.0781 2940 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/03/05 01:22:14.0812 2940 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/03/05 01:22:14.0937 2940 ati2mtag (8763ede3e0cd40f5c3450571ac57f205) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/03/05 01:22:15.0015 2940 atksgt (3c4b9850a2631c2263507400d029057b) C:\WINDOWS\system32\DRIVERS\atksgt.sys 2011/03/05 01:22:15.0031 2940 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/03/05 01:22:15.0078 2940 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/03/05 01:22:15.0109 2940 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/03/05 01:22:15.0156 2940 BlueletAudio (04e84c8049ee93614a2ff6d676d1e247) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys 2011/03/05 01:22:15.0203 2940 BT (d1813668a0117ae05bc0b81c874f91d4) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys 2011/03/05 01:22:15.0234 2940 Btcsrusb (7304acc25455746912de37d7ded387ed) C:\WINDOWS\system32\Drivers\btcusb.sys 2011/03/05 01:22:15.0265 2940 BTHidEnum (161969d2dd1d39cd2f1edbc60c61fa99) C:\WINDOWS\system32\DRIVERS\vbtenum.sys 2011/03/05 01:22:15.0312 2940 BTHidMgr (a9164c2a39bd917b9f42ae087560ac3d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys 2011/03/05 01:22:15.0359 2940 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/03/05 01:22:15.0390 2940 CCDECODE (fdc06e2ada8c468ebb161624e03976cf) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/03/05 01:22:15.0437 2940 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/03/05 01:22:15.0453 2940 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/03/05 01:22:15.0484 2940 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/03/05 01:22:15.0609 2940 d347bus (5776322f93cdb91086111f5ffbfda2a0) C:\WINDOWS\system32\DRIVERS\d347bus.sys 2011/03/05 01:22:15.0625 2940 d347prt (b49f79ace459763f4e0380071be9cb45) C:\WINDOWS\System32\Drivers\d347prt.sys 2011/03/05 01:22:15.0687 2940 Disk (47b6aaec570f2c11d8bad80a064d8ed1) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/03/05 01:22:15.0734 2940 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/03/05 01:22:15.0781 2940 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/03/05 01:22:15.0796 2940 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/03/05 01:22:15.0843 2940 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/03/05 01:22:15.0906 2940 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/03/05 01:22:15.0953 2940 DynCal (1354a16a54a444a388d89e18c4f73e17) C:\WINDOWS\system32\drivers\Dyncal.sys 2011/03/05 01:22:16.0000 2940 exFat (4d893323dae445e34a4c9038b0551bc9) C:\WINDOWS\system32\drivers\exFat.sys 2011/03/05 01:22:16.0031 2940 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/03/05 01:22:16.0062 2940 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/03/05 01:22:16.0093 2940 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/03/05 01:22:16.0109 2940 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/03/05 01:22:16.0156 2940 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2011/03/05 01:22:16.0187 2940 Fs_Rec (30d42943a54704ef13e2562911dbfcea) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/03/05 01:22:16.0203 2940 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/03/05 01:22:16.0234 2940 ggflt (007aea2e06e7cef7372e40c277163959) C:\WINDOWS\system32\DRIVERS\ggflt.sys 2011/03/05 01:22:16.0265 2940 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\WINDOWS\system32\DRIVERS\ggsemc.sys 2011/03/05 01:22:16.0328 2940 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/03/05 01:22:16.0359 2940 hamachi (528a9128caf32cea4cf4ccb572c4831f) C:\WINDOWS\system32\DRIVERS\hamachi.sys 2011/03/05 01:22:16.0406 2940 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/03/05 01:22:16.0453 2940 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/03/05 01:22:16.0500 2940 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/03/05 01:22:16.0578 2940 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/03/05 01:22:16.0609 2940 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/03/05 01:22:16.0765 2940 IntcAzAudAddService (a799e941c3d19bcf6f93cbe12b55bc17) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2011/03/05 01:22:16.0843 2940 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2011/03/05 01:22:16.0875 2940 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/03/05 01:22:16.0890 2940 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/03/05 01:22:16.0921 2940 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/03/05 01:22:16.0937 2940 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/03/05 01:22:16.0968 2940 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/03/05 01:22:17.0015 2940 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/03/05 01:22:17.0062 2940 Jukebox3 (c08c6dcbcffea9a92b25622b5ea153ac) C:\WINDOWS\system32\DRIVERS\ctpdusb.sys 2011/03/05 01:22:17.0093 2940 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/03/05 01:22:17.0125 2940 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/03/05 01:22:17.0156 2940 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/03/05 01:22:17.0234 2940 lirsgt (4127e8b6ddb4090e815c1f8852c277d3) C:\WINDOWS\system32\DRIVERS\lirsgt.sys 2011/03/05 01:22:17.0281 2940 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/03/05 01:22:17.0312 2940 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/03/05 01:22:17.0343 2940 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/03/05 01:22:17.0375 2940 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/03/05 01:22:17.0406 2940 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/03/05 01:22:17.0437 2940 MRxDAV (65e818c473e220b6ab762e1966296fd1) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/03/05 01:22:17.0468 2940 MRxSmb (dacb333a5d3758e7117522c1361075c6) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/03/05 01:22:17.0515 2940 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/03/05 01:22:17.0562 2940 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/03/05 01:22:17.0593 2940 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/03/05 01:22:17.0609 2940 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/03/05 01:22:17.0640 2940 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/03/05 01:22:17.0687 2940 MSTEE (d5059366b361f0e1124753447af08aa2) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/03/05 01:22:17.0703 2940 Mup (6546fe6639499fa4bef180bdf08266a1) C:\WINDOWS\system32\drivers\Mup.sys 2011/03/05 01:22:17.0750 2940 NABTSFEC (ac31b352ce5e92704056d409834beb74) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/03/05 01:22:17.0796 2940 NDIS (b5b1080d35974c0e718d64280761bcd5) C:\WINDOWS\system32\drivers\NDIS.sys 2011/03/05 01:22:17.0828 2940 NdisIP (abd7629cf2796250f315c1dd0b6cf7a0) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/03/05 01:22:17.0859 2940 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/03/05 01:22:17.0875 2940 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/03/05 01:22:17.0890 2940 NdisWan (b053a8411045fd0664b389a090cb2bbc) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/03/05 01:22:17.0921 2940 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/03/05 01:22:17.0937 2940 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/03/05 01:22:17.0968 2940 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/03/05 01:22:18.0015 2940 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/03/05 01:22:18.0046 2940 Ntfs (ae8cad8f28db13b515a68510a539b0b8) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/03/05 01:22:18.0093 2940 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/03/05 01:22:18.0125 2940 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/03/05 01:22:18.0140 2940 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/03/05 01:22:18.0171 2940 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/03/05 01:22:18.0187 2940 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/03/05 01:22:18.0218 2940 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/03/05 01:22:18.0250 2940 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/03/05 01:22:18.0296 2940 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/03/05 01:22:18.0328 2940 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/03/05 01:22:18.0500 2940 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/03/05 01:22:18.0515 2940 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 2011/03/05 01:22:18.0546 2940 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/03/05 01:22:18.0562 2940 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/03/05 01:22:18.0609 2940 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/03/05 01:22:18.0734 2940 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/03/05 01:22:18.0781 2940 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/03/05 01:22:18.0796 2940 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/03/05 01:22:18.0812 2940 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/03/05 01:22:18.0843 2940 Rdbss (77050c6615f6eb5402f832b27fd695e0) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/03/05 01:22:18.0859 2940 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/03/05 01:22:18.0921 2940 rdpdr (c694a927eb7c354f7ae97955043a9641) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/03/05 01:22:18.0953 2940 RDPWD (e8e3107243b16a549b88d145ec051b06) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/03/05 01:22:19.0000 2940 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/03/05 01:22:19.0062 2940 rspndr (743d7d59767073a617b1dcc6c546f234) C:\WINDOWS\system32\DRIVERS\rspndr.sys 2011/03/05 01:22:19.0093 2940 RTLE8023xp (e6e5af7d6920824b066832d3e1665506) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 2011/03/05 01:22:19.0156 2940 SE1008mdm (8f6b775f31d01f1f4d04a683c8d0d349) C:\WINDOWS\system32\DRIVERS\SE1008mdm.sys 2011/03/05 01:22:19.0187 2940 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/03/05 01:22:19.0234 2940 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/03/05 01:22:19.0250 2940 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/03/05 01:22:19.0312 2940 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys 2011/03/05 01:22:19.0328 2940 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys 2011/03/05 01:22:19.0343 2940 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/03/05 01:22:19.0375 2940 sfsync02 (efebbc1d13fdb77a6af4eddfc7232edf) C:\WINDOWS\system32\drivers\sfsync02.sys 2011/03/05 01:22:19.0390 2940 sfvfs02 (9ef50060cc7e6953bab83f2a42ccc421) C:\WINDOWS\system32\drivers\sfvfs02.sys 2011/03/05 01:22:19.0453 2940 SLIP (1ffc44d6787ec1ea9a2b1440a90fa5c1) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/03/05 01:22:19.0515 2940 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/03/05 01:22:19.0546 2940 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/03/05 01:22:19.0593 2940 Srv (e89b42b216bc86ada4345908284519cb) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/03/05 01:22:19.0640 2940 streamip (a9f9fd0212e572b84edb9eb661f6bc04) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/03/05 01:22:19.0656 2940 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/03/05 01:22:19.0687 2940 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/03/05 01:22:19.0796 2940 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/03/05 01:22:19.0828 2940 Tcpip (25a740d70e8007814a48d3fa1b34fa34) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/03/05 01:22:19.0859 2940 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/03/05 01:22:19.0875 2940 TDTCP (c0578456f29e5f26285f81b7b71fe57d) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/03/05 01:22:19.0921 2940 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/03/05 01:22:19.0984 2940 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/03/05 01:22:20.0031 2940 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/03/05 01:22:20.0093 2940 usbehci (4bac8df07f1d8434fc640e677a62204e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/03/05 01:22:20.0125 2940 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/03/05 01:22:20.0140 2940 usbohci (c5e11cd822adf0019a5a862d9c4e2222) C:\WINDOWS\system32\DRIVERS\usbohci.sys 2011/03/05 01:22:20.0187 2940 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/03/05 01:22:20.0218 2940 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/03/05 01:22:20.0250 2940 VComm (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys 2011/03/05 01:22:20.0281 2940 VcommMgr (630bbdbf5490f8f57abe650da63661a0) C:\WINDOWS\system32\Drivers\VcommMgr.sys 2011/03/05 01:22:20.0312 2940 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/03/05 01:22:20.0359 2940 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/03/05 01:22:20.0406 2940 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/03/05 01:22:20.0453 2940 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys 2011/03/05 01:22:20.0531 2940 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/03/05 01:22:20.0609 2940 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 2011/03/05 01:22:20.0671 2940 WSTCODEC (233cdd1c06942115802eb7ce6669e099) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/03/05 01:22:20.0703 2940 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/03/05 01:22:20.0734 2940 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/03/05 01:22:20.0796 2940 ================================================================================ 2011/03/05 01:22:20.0796 2940 Scan finished 2011/03/05 01:22:20.0796 2940 ================================================================================
  2. ComboFix 11-03-04.04 - Puhi 03.2011 г. 0:38.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1023.639 [GMT 2:00] Running from: c:\documents and settings\Puhi\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Puhi\Desktop\CFScript.txt . FILE :: "c:\windows\system32\drivers\pafsxqei.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\klipxm32.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\Service_pafsxqei . . ((((((((((((((((((((((((( Files Created from 2011-02-04 to 2011-03-04 ))))))))))))))))))))))))))))))) . . 2011-03-04 15:15 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-04 15:14 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-03-04 15:14 . 2011-03-04 15:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-03-03 08:07 . 2011-03-03 08:07 -------- d-----w- c:\program files\Common Files\Java 2011-03-03 08:07 . 2011-02-02 19:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2011-03-03 08:07 . 2011-02-02 19:40 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-03-03 08:06 . 2011-03-03 08:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2011-02-26 19:27 . 2011-02-26 19:27 -------- d-----w- c:\program files\VideoLAN 2011-02-23 21:59 . 2011-03-03 15:17 -------- d-----w- c:\documents and settings\Puhi\Application Data\goalbit 2011-02-23 21:58 . 2011-02-23 21:58 -------- d-----w- c:\program files\InhatchTeam 2011-02-05 13:25 . 2011-02-05 13:25 -------- d-----w- c:\program files\BACL . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-02-02 17:19 . 2009-05-27 09:53 73728 ----a-w- c:\windows\system32\javacpl.cpl 2010-12-05 16:02 . 2010-12-05 16:02 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys 2010-12-05 16:02 . 2010-12-05 16:02 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2007-05-10 16342528] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-10 37888] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2009-7-12 151552] . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "WRP"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk backup=c:\windows\pss\BlueSoleil.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk backup=c:\windows\pss\Windows Search.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amd_dc_opt] 2008-07-22 11:53 77824 ----a-w- c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] 2004-08-22 14:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 02:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-10-29 12:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "d:\\Games\\Heroes III all versions full\\Heroes 3\\h3wog.exe"= "c:\\WINDOWS\\system32\\dplaysvr.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\Dream Match Tennis Pro Online\\FA.exe"= "d:\\INSTALL\\malki\\GAMES\\volley\\volley.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"= "c:\\Program Files\\SopCast\\SopCast.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2706:TCP"= 2706:TCP:Inhatch P2P Streaming "2707:TCP"= 2707:TCP:Inhatch P2P Streaming "2708:TCP"= 2708:TCP:Inhatch P2P Streaming "2709:TCP"= 2709:TCP:Inhatch P2P Streaming . R3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [12.9.2004 і. 09:45 8320] S2 gupdate;Ус»уі° Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [06.4.2009 і. 08:13 13224] S3 SE1008mdm;Sony Ericsson SE1008 Mobile Device Full USB Driver;c:\windows\system32\drivers\SE1008mdm.sys [02.11.2010 і. 23:19 58536] S4 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [01.6.2009 і. 22:36 155136] S4 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [01.6.2009 і. 22:36 5248] . . ------- Supplementary Scan ------- . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2224613 uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyServer = http=127.0.0.1:63636 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\ FF - prefs.js: browser.search.selectedEngine - ZiggyTV FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 63636 FF - prefs.js: network.proxy.type - 1 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar FF - Ext: TVU Web Player: [email protected] - %profile%\extensions\[email protected] . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-03-05 00:43 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(696) c:\windows\system32\Ati2evxx.dll . - - - - - - - > 'explorer.exe'(3876) c:\windows\system32\WININET.dll c:\windows\system32\newdll.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTJBNS2.dll c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTIntrfc.dll c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTConfig.DLL c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\JBNSRES.DLL c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\RTHDCPL.EXE c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2011-03-05 00:44:52 - machine was rebooted ComboFix-quarantined-files.txt 2011-03-04 22:44 ComboFix2.txt 2011-03-04 21:57 . Pre-Run: 56 267 853 824 bytes free Post-Run: 56 175 230 976 bytes free . - - End Of File - - 309F3D639BE601987B1C771299F660D9
  3. ComboFix 11-03-04.02 - Puhi 03.2011 г. 23:55:09.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1023.676 [GMT 2:00] Running from: c:\documents and settings\Puhi\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Puhi\Desktop\CFScript.txt . - REDUCED FUNCTIONALITY MODE - . FILE :: "c:\windows\system32\drivers\pafsxqei.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\daemon.dll . . ((((((((((((((((((((((((( Files Created from 2011-02-04 to 2011-03-04 ))))))))))))))))))))))))))))))) . . 2011-03-04 15:15 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-04 15:14 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-03-04 15:14 . 2011-03-04 15:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-03-03 08:07 . 2011-03-03 08:07 -------- d-----w- c:\program files\Common Files\Java 2011-03-03 08:07 . 2011-02-02 19:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2011-03-03 08:07 . 2011-02-02 19:40 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-03-03 08:06 . 2011-03-03 08:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2011-02-26 19:27 . 2011-02-26 19:27 -------- d-----w- c:\program files\VideoLAN 2011-02-23 21:59 . 2011-03-03 15:17 -------- d-----w- c:\documents and settings\Puhi\Application Data\goalbit 2011-02-23 21:58 . 2011-02-23 21:58 -------- d-----w- c:\program files\InhatchTeam 2011-02-05 13:25 . 2011-02-05 13:25 -------- d-----w- c:\program files\BACL . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-02-02 17:19 . 2009-05-27 09:53 73728 ----a-w- c:\windows\system32\javacpl.cpl 2010-12-05 16:02 . 2010-12-05 16:02 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys 2010-12-05 16:02 . 2010-12-05 16:02 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys . . ------- Sigcheck ------- . [-] 2009-04-18 . 25A740D70E8007814A48D3FA1B34FA34 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys . [-] 2009-04-18 . C951DB3D9B6EF3CF4B82454D30A8BF59 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2007-05-10 16342528] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-10 37888] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2009-7-12 151552] . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "WRP"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk backup=c:\windows\pss\BlueSoleil.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk backup=c:\windows\pss\Windows Search.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amd_dc_opt] 2008-07-22 11:53 77824 ----a-w- c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] 2004-08-22 14:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 02:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-10-29 12:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "d:\\Games\\Heroes III all versions full\\Heroes 3\\h3wog.exe"= "c:\\WINDOWS\\system32\\dplaysvr.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\Dream Match Tennis Pro Online\\FA.exe"= "d:\\INSTALL\\malki\\GAMES\\volley\\volley.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"= "c:\\Program Files\\SopCast\\SopCast.exe"= "c:\\Program Files\\Internet Explorer\\iexplore.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2706:TCP"= 2706:TCP:Inhatch P2P Streaming "2707:TCP"= 2707:TCP:Inhatch P2P Streaming "2708:TCP"= 2708:TCP:Inhatch P2P Streaming "2709:TCP"= 2709:TCP:Inhatch P2P Streaming . R3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [12.9.2004 і. 09:45 8320] S1 pafsxqei;pafsxqei;\??\c:\windows\system32\drivers\pafsxqei.sys --> c:\windows\system32\drivers\pafsxqei.sys [?] S2 gupdate;Ус»уі° Google Update (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [06.4.2009 і. 08:13 13224] S3 SE1008mdm;Sony Ericsson SE1008 Mobile Device Full USB Driver;c:\windows\system32\drivers\SE1008mdm.sys [02.11.2010 і. 23:19 58536] S4 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [01.6.2009 і. 22:36 155136] S4 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [01.6.2009 і. 22:36 5248] . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2224613 uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 TCP: {0CF875B8-F761-4EBB-A9E0-A02372AB26A6} = 213.231.128.30 213.231.128.190 FF - ProfilePath - c:\documents and settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\ FF - prefs.js: browser.search.selectedEngine - ZiggyTV FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 63636 FF - prefs.js: network.proxy.type - 1 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar FF - Ext: TVU Web Player: [email protected] - %profile%\extensions\[email protected] . - - - - ORPHANS REMOVED - - - - . AddRemove-3GP Converter_is1 - c:\program files\3GPconverter\unins000.exe AddRemove-EVEREST Home Edition_is1 - c:\program files\Lavalys\EVEREST Home Edition\unins000.exe AddRemove-Xilisoft 3GP Video Converter 6 - c:\program files\Xilisoft\3GP Video Converter 6\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-03-04 23:55 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1214440339-515967899-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5B35E063-1464-767F-B45A-775E97B2240D}*] "iakahopphbceggbfkg"=hex:6a,61,6c,64,6f,6d,68,6b,69,62,61,64,62,67,64,62,62,65, 6e,6a,00,00 "haidfndnhnocndhe"=hex:6a,61,6c,64,6f,6d,68,6b,69,62,61,64,62,67,64,62,62,65, 6e,6a,00,1d . [HKEY_USERS\S-1-5-21-1214440339-515967899-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96C37413-36DA-8882-E1C9-85B5D38186F4}*] "dahnpcoa"=hex:64,62,69,70,69,6e,70,67,6b,68,63,6d,64,64,64,6a,65,67,6c,6b,64, 70,6a,6b,6e,64,64,65,70,65,6c,70,70,64,70,6b,61,6e,6b,70,00,00 "iamjcmmgclmplgillb"=hex:6a,61,6e,63,6d,6a,6b,64,6a,6e,64,69,6b,6d,65,6b,65,65, 63,6c,00,00 "hacpikochanahcdf"=hex:6a,61,6e,63,6d,6a,6b,64,6a,6e,64,69,6b,6d,65,6b,65,65, 63,6c,00,00 . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(696) c:\windows\system32\Ati2evxx.dll . Completion time: 2011-03-04 23:57:05 ComboFix-quarantined-files.txt 2011-03-04 21:56 . Pre-Run: 55 897 366 528 bytes free Post-Run: 56 264 155 136 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer . - - End Of File - - 4AD74098687395DA17BF21A92ED8C62B
  4. Привет драги съфорумци, От заглавието става ясно, че РС-то ми е заразено с вирус(и). Всичко започна преди 2 дни, когато NOD32 ми изпрати съобщение, което гласеше, че е открит вирус, вариант на Win32/Kryptik.LHY Trojan. Дадох му да го delete-не през антивирусната, рестартирах и като направих сканиране пак го откри. Ръчно отидох в директорията и го изтрих, с което мислех, че съм решил проблемите си. Да ама не. Днес отново намира заразен файл ****.exe , само че с друго име, в същата директория. Проблема е, че освен него антивирусната откри и още куп заразени файлове, които онзи ден ги нямаше. След като направих написаното с Malware ми поиска рестарт. След рестарта обаче, skype се вписва и пиша с другите абонати, а като се опитам да вляза в интернет през браузъра не става. Пише, че няма връзка. Пробвах и с Опера, Мозила и ИЕ. Не знам дали е свързано с нещата, които Malware е изтрил, но реших да го спомена. Затова информацията я пратих на приятел, който да я постне. Очаквам някакъв отговор, като предварително благодаря. Desktop.zip
  5. Като за начало Благодаря за времето,което ми отделихте,за да ми помогнете. Добра новина е,че не сте отрили вируси или други зарази,но все още ме притеснява фактът,че от няколко седмици насам се изключва толкова бавно.Програмите,които използвам не са толкова много,за да ги спира дълго време.Може би е нормално,но просто преди се влючваше и гасеше за по 30-ина секунди,а сега му отнема към минута-две докато се огаси. А относно програмите за сигорност(Стената и антивирусната) ще обмисля дали,и евентуално какви да използвам,тъй като досега Firewall и NOD 32 ми вършат идеална работа-последната преинсталация на Windows беше миналата година през месец юни.Ако наистина сега е бил чист от заплахи оставам доста изненадан от работата им,тъй като,когато е имало евентуални заплахи винаги са ги засичали и са ме предупреждавали.Все пак се пазя доста,и по голямо време прекарвам под линукс,но работата им не е за подценяване Отново Благодаря за отделеното време и желая успех на вас и вашият екип. Поздрави.
  6. В последният ви коментар,не успявам да разбера какво точно трябва да се направи и защо трябва да си премахна антивирусната/-ите/ програми.Ако можете да ми обясните отново,по-подробно,ще съм благодарен.И във крайна сметка какво се оказа-имах ли вируси,други заплахи или какво точно се установи.
  7. Новите логове. Сега излизам и няма да мога да съдействам на момента,утре като се наспя дано се засечем и продължим. OTL II.txt RootRepeal report II.txt
  8. Съжалявам,че се забавих,но снощи не бях в града.Надявам се днес да съм на линия и да отговарям на време.А ето ги и логовете: SIGVERIF.TXT Rootrepeal.txt
  9. OTL OTL logfile created on: 07.4.2010 г. 22:08:25 - Run 1 OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\Puhi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1 023,00 Mb Total Physical Memory | 364,00 Mb Available Physical Memory | 36,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 78,00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 60,81 Gb Total Space | 53,37 Gb Free Space | 87,77% Space Free | Partition Type: NTFS Drive D: | 220,86 Gb Total Space | 184,75 Gb Free Space | 83,65% Space Free | Partition Type: NTFS Drive E: | 524,05 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: Puhi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Puhi\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Eset\nod32kui.exe (Eset ) PRC - C:\Program Files\Eset\nod32krn.exe (Eset ) PRC - C:\Program Files\Winamp\winamp.exe (Nullsoft) PRC - C:\Program Files\Winamp\winampa.exe () PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe () PRC - C:\WINDOWS\system32\CTPdeSrv.exe (Creative Technology Ltd) PRC - C:\Program Files\D-Tools\daemon.exe (DAEMON'S HOME) PRC - C:\WINDOWS\Datecs\Flex2K.exe () ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Puhi\Desktop\OTL.exe (OldTimer Tools) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll (Microsoft Corporation) MOD - C:\WINDOWS\system32\newdll.dll () ========== Win32 Services (SafeList) ========== SRV - (NOD32krn) -- C:\Program Files\Eset\nod32krn.exe (Eset ) SRV - (BlueSoleil Hid Service) -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe () ========== Driver Services (SafeList) ========== DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (Applied Networking Inc.) DRV - (AMON) -- C:\WINDOWS\system32\drivers\amon.sys (Eset ) DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider) DRV - (AmdLLD) -- C:\WINDOWS\system32\drivers\AmdLLD.sys (AMD, Inc.) DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (CDRPDACC) Quinnware CDDA Driver (by InfinaDyne) -- C:\Program Files\Quintessential Media Player\cdrpdacc.sys (Arrowkey) DRV - (BlueletAudio) -- C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation) DRV - (Btcsrusb) -- C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation) DRV - (BTHidEnum) -- C:\WINDOWS\system32\drivers\vbtenum.sys () DRV - (BTHidMgr) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation) DRV - (BT) -- C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation) DRV - (VcommMgr) -- C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation) DRV - (VComm) -- C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation) DRV - (Jukebox3) -- C:\WINDOWS\system32\drivers\ctpdusb.sys (Creative Technology Ltd.) DRV - (d347prt) -- C:\WINDOWS\System32\Drivers\d347prt.sys ( ) DRV - (d347bus) -- C:\WINDOWS\system32\DRIVERS\d347bus.sys ( ) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\S-1-5-21-1214440339-515967899-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/ IE - HKU\S-1-5-21-1214440339-515967899-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.bg/" FF - prefs.js..extensions.enabledItems: [email protected]:1.0 FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.10.1 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.05 15:28:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.04 11:39:09 | 000,000,000 | ---D | M] [2010.01.04 23:48:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\Mozilla\Extensions [2010.04.07 15:13:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\extensions [2009.06.08 16:28:34 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2009.08.22 05:14:54 | 000,000,900 | ---- | M] () -- C:\Documents and Settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\searchplugins\conduit.xml [2009.10.26 22:08:12 | 000,002,149 | ---- | M] () -- C:\Documents and Settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\searchplugins\MyStart Search.xml [2009.12.31 00:14:08 | 000,000,358 | ---- | M] () -- C:\Documents and Settings\Puhi\Application Data\Mozilla\Firefox\Profiles\6fajuafp.default\searchplugins\winamp-search.xml [2010.04.07 15:13:19 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2010.03.16 21:02:38 | 000,001,083 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\911bg.xml [2010.03.16 21:02:38 | 000,002,442 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\diribg.xml [2010.03.16 21:02:38 | 000,001,515 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pe-bg.xml [2010.03.16 21:02:38 | 000,001,857 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\portalbgdict.xml [2010.03.16 21:02:38 | 000,001,220 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-bg.xml O1 HOSTS File: ([2008.04.14 18:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll (www.flashget.com) O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll (www.flashget.com) O3 - HKLM\..\Toolbar: (FlashGet) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll (Amaze Soft) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD) O4 - HKLM..\Run: [DAEMON Tools-1033] C:\Program Files\D-Tools\daemon.exe (DAEMON'S HOME) O4 - HKLM..\Run: [KernelFaultCheck] File not found O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset ) O4 - HKLM..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\S-1-5-21-1214440339-515967899-682003330-1004..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe File not found O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe (IVT Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1214440339-515967899-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\JC_ALL.HTM () O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\JC_LINK.HTM () O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars) O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com) O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com) O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe (PokerStars) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\Puhi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Puhi\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.05.27 12:48:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [1940.09.08 14:08:20 | 000,000,212 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - C:\WINDOWS\system32\ias [2009.05.27 12:48:07 | 000,000,000 | ---D | M] NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe - (Microsoft Corporation) MsConfig - State: "system.ini" - 0 MsConfig - State: "win.ini" - 0 MsConfig - State: "bootini" - 0 MsConfig - State: "services" - 0 MsConfig - State: "startup" - 2 SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun) ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML) ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4 ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015C} - Microsoft DirectX ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8 ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366) ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} - ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1 ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Macromedia Shockwave Flash ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {EF289A85-8E57-408d-BE47-73B55609861A} - RootsUpdate ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIEActiveSetup SIGNUP ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE ActiveX: >{99820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: Microsoft Base Smart Card Crypto Provider Package - Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler) Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo8 - VfWWDM32.dll File not found Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.) Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll () Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll () Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org) ========== Files/Folders - Created Within 30 Days ========== [2010.04.07 22:05:01 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Puhi\Desktop\OTL.exe [2010.04.07 22:00:53 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Puhi\Desktop\TFC.exe [2010.04.07 21:09:20 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2010.04.07 21:08:27 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Puhi\Desktop\Kaldata.exe [2010.04.03 02:16:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Puhi\My Documents\Downloads [2010.04.01 12:00:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2010.03.27 21:24:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun [2010.03.27 21:24:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2009.11.28 16:20:34 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2009.06.01 23:36:09 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys [2009.06.01 23:36:09 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys [2009.05.27 12:50:58 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2009.05.27 12:48:41 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.05.27 12:48:41 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft ========== Files - Modified Within 30 Days ========== [2010.04.07 22:05:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Puhi\Desktop\OTL.exe [2010.04.07 22:05:18 | 006,291,456 | -H-- | M] () -- C:\Documents and Settings\Puhi\NTUSER.DAT [2010.04.07 22:03:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010.04.07 22:03:34 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010.04.07 22:03:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010.04.07 22:02:48 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Puhi\ntuser.ini [2010.04.07 22:01:13 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Puhi\Desktop\TFC.exe [2010.04.07 21:09:22 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\HijackThis.lnk [2010.04.07 21:08:28 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Puhi\Desktop\Kaldata.exe [2010.04.07 15:30:10 | 000,110,592 | ---- | M] () -- C:\Documents and Settings\Puhi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.04.07 03:44:14 | 001,578,072 | -H-- | M] () -- C:\Documents and Settings\Puhi\Local Settings\Application Data\IconCache.db [2010.04.07 02:37:09 | 000,091,543 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\untitled.JPG [2010.04.07 00:45:04 | 000,040,319 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\34.jpg [2010.04.01 22:46:51 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2010.03.28 10:29:32 | 000,522,498 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010.03.28 10:29:32 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010.03.28 10:29:32 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010.03.14 20:06:00 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PokerStars.lnk [2010.03.12 16:36:56 | 000,002,560 | ---- | M] () -- C:\WINDOWS\_MSRSTRT.EXE [2010.03.12 16:36:42 | 000,000,850 | ---- | M] () -- C:\WINDOWS\ao2000pr.ini ========== Files Created - No Company Name ========== [2010.04.07 21:09:22 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Puhi\Desktop\HijackThis.lnk [2010.04.07 02:37:09 | 000,091,543 | ---- | C] () -- C:\Documents and Settings\Puhi\Desktop\untitled.JPG [2010.04.07 00:45:01 | 000,040,319 | ---- | C] () -- C:\Documents and Settings\Puhi\Desktop\34.jpg [2010.04.01 19:21:44 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk [2010.03.14 20:06:00 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PokerStars.lnk [2010.03.12 16:36:56 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE [2010.03.12 14:55:26 | 000,000,850 | ---- | C] () -- C:\WINDOWS\ao2000pr.ini [2009.12.14 01:50:05 | 000,336,896 | ---- | C] () -- C:\WINDOWS\System32\ammppg.dll [2009.12.14 01:50:05 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll [2009.12.14 01:50:05 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\a1.dll [2009.12.14 01:50:04 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\qscl.dll [2009.12.14 01:50:04 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\amrdec.dll [2009.12.14 01:50:04 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\qcpsdk.dll [2009.12.13 19:10:58 | 000,013,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\BTNetFilter.sys [2009.12.13 19:10:57 | 000,011,860 | ---- | C] () -- C:\WINDOWS\System32\drivers\vbtenum.sys [2009.12.13 19:04:59 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\PdeSrvps.dll [2009.10.29 12:07:36 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\klipxm32.dll [2009.09.28 01:02:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Puhi\skypemeup.properties [2009.08.13 22:24:57 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll [2009.08.12 16:31:24 | 000,000,307 | ---- | C] () -- C:\WINDOWS\game.ini [2009.07.31 01:37:23 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2009.07.31 00:52:41 | 000,138,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2009.07.12 16:22:34 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll [2009.07.05 02:18:55 | 000,001,160 | ---- | C] () -- C:\Documents and Settings\Puhi\D2090705.txt [2009.06.19 20:06:22 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll [2009.06.19 20:06:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll [2009.06.06 12:14:54 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009.06.02 14:47:17 | 000,110,592 | ---- | C] () -- C:\Documents and Settings\Puhi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009.06.02 14:28:04 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll [2009.06.01 23:38:43 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009.06.01 23:38:42 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009.06.01 23:38:42 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009.06.01 23:38:41 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009.06.01 23:38:41 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009.06.01 23:38:41 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2009.05.30 17:39:55 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Puhi\ntuser.ini [2009.05.30 17:39:54 | 006,291,456 | -H-- | C] () -- C:\Documents and Settings\Puhi\NTUSER.DAT [2009.05.30 17:39:54 | 000,007,287 | ---- | C] () -- C:\Documents and Settings\Puhi\ASPNETSetup.log [2009.05.30 17:39:54 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Puhi\ntuser.dat.LOG [2009.05.27 12:51:01 | 000,249,144 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat [2009.05.27 12:44:05 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [2009.05.27 12:44:05 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2009.05.27 12:44:05 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2004.08.22 17:04:56 | 000,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll [2003.01.07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI ========== LOP Check ========== [2009.05.27 12:57:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search [2009.12.13 20:06:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bluetooth [2009.10.26 22:09:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IM [2009.10.26 22:08:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail [2010.01.31 00:40:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VOWSoft [2009.12.16 13:29:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\Dreamingsoft [2010.04.04 15:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\HLSW [2009.07.30 23:34:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\Leadertech [2009.12.06 18:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\Octoshape [2009.12.12 12:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\SystemRequirementsLab [2009.12.28 17:01:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\TeamViewer [2010.04.07 16:29:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\uTorrent [2009.06.08 01:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Puhi\Application Data\Windows Search ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2009.05.27 12:48:47 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009.12.09 01:28:00 | 000,000,223 | RHS- | M] () -- C:\boot.ini [2009.05.27 12:48:47 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2009.05.27 12:48:47 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009.05.27 12:48:47 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2008.04.14 18:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008.04.14 18:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr [2010.04.07 22:03:30 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys < MD5 for: ATAPI.SYS > [2008.04.14 03:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys < MD5 for: EVENTLOG.DLL > [2008.04.14 18:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll [2008.04.14 18:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll < MD5 for: IASTOR.SYS > [2009.04.19 02:52:05 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\WINDOWS\NLDRV\001\iastor.sys < MD5 for: NETLOGON.DLL > [2009.02.07 00:37:59 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=DAB13813B25B3D009B2AC1194CF5D0A2 -- C:\WINDOWS\system32\dllcache\netlogon.dll [2009.02.07 00:37:59 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=DAB13813B25B3D009B2AC1194CF5D0A2 -- C:\WINDOWS\system32\netlogon.dll < MD5 for: SCECLI.DLL > [2008.04.14 18:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll [2008.04.14 18:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2009.02.26 00:42:32 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 -- C:\WINDOWS\system32\ATIDEMGX.dll < %systemroot%\Tasks\*.job /lockedfiles > < %PROGRAMFILES%\*. > [2009.07.05 22:29:41 | 000,000,000 | ---D | M] -- C:\Program Files\3DO [2010.01.31 00:40:01 | 000,000,000 | ---D | M] -- C:\Program Files\ABC 3GP Converter [2009.11.26 12:16:25 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe [2009.09.22 15:52:45 | 000,000,000 | ---D | M] -- C:\Program Files\AGEIA Technologies [2009.12.09 01:27:50 | 000,000,000 | ---D | M] -- C:\Program Files\AMD [2010.01.16 01:58:55 | 000,000,000 | ---D | M] -- C:\Program Files\AnMing [2009.05.30 17:29:57 | 000,000,000 | ---D | M] -- C:\Program Files\ATI Technologies [2010.04.01 12:00:00 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files [2009.07.23 17:41:53 | 000,000,000 | ---D | M] -- C:\Program Files\Conduit [2009.12.13 19:07:02 | 000,000,000 | ---D | M] -- C:\Program Files\Creative [2009.08.31 14:20:24 | 000,000,000 | ---D | M] -- C:\Program Files\Custom-Strike [2009.06.01 23:36:09 | 000,000,000 | ---D | M] -- C:\Program Files\D-Tools [2009.07.12 16:22:34 | 000,000,000 | ---D | M] -- C:\Program Files\Datecs [2009.06.02 14:12:22 | 000,000,000 | ---D | M] -- C:\Program Files\Dream Match Tennis Pro [2009.06.28 01:10:04 | 000,000,000 | ---D | M] -- C:\Program Files\Dream Match Tennis Pro Online [2009.06.08 22:02:50 | 000,000,000 | ---D | M] -- C:\Program Files\Eset [2009.07.24 23:33:26 | 000,000,000 | ---D | M] -- C:\Program Files\FlashGet [2010.01.31 02:31:44 | 000,000,000 | ---D | M] -- C:\Program Files\Gaberoff Koral [2009.12.28 13:40:18 | 000,000,000 | ---D | M] -- C:\Program Files\Hamachi [2010.04.01 18:31:48 | 000,000,000 | --SD | M] -- C:\Program Files\HLSW [2009.12.26 00:43:09 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information [2010.01.31 02:25:31 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer [2009.12.13 19:10:56 | 000,000,000 | ---D | M] -- C:\Program Files\IVT Corporation [2010.03.27 21:23:36 | 000,000,000 | ---D | M] -- C:\Program Files\Java [2009.06.07 13:18:50 | 000,000,000 | ---D | M] -- C:\Program Files\K-Lite Codec Pack [2010.02.13 16:59:19 | 000,000,000 | ---D | M] -- C:\Program Files\Lavalys [2010.02.24 12:17:19 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware [2009.05.27 12:42:52 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger [2009.06.06 12:14:20 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync [2009.05.27 12:53:26 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage [2009.06.06 12:14:09 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office [2009.12.12 10:59:44 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight [2009.06.06 12:13:59 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET [2009.05.27 12:46:26 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker [2010.04.04 11:39:14 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox [2009.05.27 12:50:47 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild [2009.05.27 12:42:17 | 000,000,000 | ---D | M] -- C:\Program Files\MSN [2009.05.27 12:42:48 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone [2009.05.27 12:44:01 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0 [2009.05.27 12:46:43 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting [2009.05.27 12:47:23 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services [2009.05.27 12:46:39 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express [2010.04.06 01:02:14 | 000,000,000 | ---D | M] -- C:\Program Files\PokerStars [2009.11.02 21:54:37 | 000,000,000 | ---D | M] -- C:\Program Files\PokerStars.NET [2009.06.07 13:25:57 | 000,000,000 | ---D | M] -- C:\Program Files\Quintessential Media Player [2009.05.30 17:27:45 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek [2009.05.27 12:50:44 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies [2009.11.14 13:01:23 | 000,000,000 | R--D | M] -- C:\Program Files\Skype [2010.04.07 17:44:30 | 000,000,000 | ---D | M] -- C:\Program Files\sXe Injected [2009.12.12 12:31:19 | 000,000,000 | ---D | M] -- C:\Program Files\SystemRequirementsLab [2009.12.28 17:01:02 | 000,000,000 | ---D | M] -- C:\Program Files\TeamViewer [2009.07.16 01:28:52 | 000,000,000 | ---D | M] -- C:\Program Files\The KMPlayer [2010.04.07 21:09:20 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro [2010.03.14 18:43:20 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent [2010.04.07 16:30:14 | 000,000,000 | ---D | M] -- C:\Program Files\Valve [2009.10.22 22:07:20 | 000,000,000 | ---D | M] -- C:\Program Files\vloader [2009.06.08 16:23:49 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp [2009.06.19 21:04:39 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp Remote [2009.05.27 12:44:13 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Desktop Search [2009.05.27 12:47:14 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2 [2009.05.27 12:48:43 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player [2009.05.27 12:42:40 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT [2009.11.07 09:45:43 | 000,000,000 | ---D | M] -- C:\Program Files\WinISO [2009.11.08 14:15:40 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR [2009.05.27 12:53:26 | 000,000,000 | ---D | M] -- C:\Program Files\xerox [2010.02.23 12:29:06 | 000,000,000 | ---D | M] -- C:\Program Files\маваре < %userprofile%\Desktop\*.* > [2010.04.07 00:45:04 | 000,040,319 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\34.jpg [2010.02.28 02:39:26 | 000,001,607 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\Counter Strike 1.6 Non Steam.lnk [2009.06.28 00:47:27 | 000,000,822 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\Dream Match Tennis Pro.lnk [2010.02.13 16:59:39 | 000,000,787 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\EVEREST Ultimate Edition.lnk [2010.04.07 21:09:22 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\HijackThis.lnk [2010.04.07 21:09:50 | 000,007,029 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\hijackthis.log [2009.08.29 17:01:10 | 000,000,626 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\HLSW.lnk [2010.04.07 21:08:28 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Puhi\Desktop\Kaldata.exe [2010.04.07 21:06:23 | 000,000,904 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\mbam-log-2010-04-07 (21-05-43).txt [2009.12.14 01:50:06 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\MP3 To Ringtone Gold.lnk [2010.04.07 22:05:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Puhi\Desktop\OTL.exe [2009.12.09 18:32:46 | 000,692,224 | ---- | M] (binaerkombinat) -- C:\Documents and Settings\Puhi\Desktop\SkypeLauncher.exe [2010.02.28 02:34:57 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\sXe Injected.lnk [2010.04.07 22:01:13 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Puhi\Desktop\TFC.exe [2010.04.07 02:37:09 | 000,091,543 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\untitled.JPG [2009.10.22 22:07:17 | 000,000,616 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\vloader.lnk [2009.08.03 13:20:36 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\Puhi\Desktop\µTorrent.lnk < %userprofile%\Desktop\*. > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > < End of report > Extras OTL Extras logfile created on: 07.4.2010 г. 22:08:25 - Run 1 OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\Puhi\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.' 1 023,00 Mb Total Physical Memory | 364,00 Mb Available Physical Memory | 36,00% Memory free 2,00 Gb Paging File | 2,00 Gb Available in Paging File | 78,00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 60,81 Gb Total Space | 53,37 Gb Free Space | 87,77% Space Free | Partition Type: NTFS Drive D: | 220,86 Gb Total Space | 184,75 Gb Free Space | 83,65% Space Free | Partition Type: NTFS Drive E: | 524,05 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: Puhi Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 1 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Games\Counter Strike\cstrike.exe" = C:\Games\Counter Strike\cstrike.exe:*:Enabled:Condition Zero Launcher -- File not found "C:\Games\Counter Strike\hl.exe" = C:\Games\Counter Strike\hl.exe:*:Enabled:Half-Life Launcher -- File not found "C:\Games\Counter Strike\hltv.exe" = C:\Games\Counter Strike\hltv.exe:*:Enabled:HLTV Launcher -- File not found "C:\Program Files\FlashGet\flashget.exe" = C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget -- (FlashGet.com) "C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb -- File not found "C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray -- File not found "C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client -- File not found "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\IncrediMail\Bin\IncMail.exe" = C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail -- File not found "C:\Program Files\IncrediMail\Bin\ImApp.exe" = C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail -- File not found "C:\Program Files\IncrediMail\Bin\ImpCnt.exe" = C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail -- File not found "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil -- (IVT Corporation) "C:\Program Files\TeamViewer\Version5\TeamViewer.exe" = C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser "{1E99F5D7-4262-4C7C-9135-F066E7485811}" = System Requirements Lab "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 18 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools "{4324BC93-C82F-ED16-BA86-5E34B9E05303}" = ccc-core-static "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4ED118EE-785C-CC18-5D2E-D5CA4BAA03F0}" = Catalyst Control Center Graphics Full New "{539475B7-44B7-8B0A-134C-F01B9C8B7569}" = ccc-core-preinstall "{5AC7AE54-55DF-1126-076C-623F008D40B6}" = Catalyst Control Center Graphics Full Existing "{5BB207D6-0E1E-11D5-9B6A-00C04F7EC248}" = Decal Converter "{5DB65884-C963-4454-AABA-4CA3089281FA}" = NVIDIA PhysX "{6351D217-3EE3-1967-29BE-6A77635FE485}" = Skins "{6AB9CD3A-F91F-233B-923B-6C59BA63524D}" = Catalyst Control Center HydraVision Full "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{85A91C22-C369-FCFB-5F1F-D59EB21AD0E1}" = CCC Help English "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6 "{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A6D0140F-E62F-9D1E-2408-9CFF91FF6FC8}" = ccc-utility "{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2 "{B9F499B8-D1F0-42FC-84BE-CC552123CCCB}" = BlueSoleil "{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2 "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C44A7422-E380-44BE-79FE-1C032D8A03A7}" = Catalyst Control Center Core Implementation "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2 "{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding "{D944236D-7992-41D6-8257-930B5832F1CC}" = Creative Zen Micro "{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1" = NOD32 FiX v1.9 "{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}" = Prince of Persia T2T "{E5D24929-91A4-B0A1-DE00-AFC453921EF7}" = Catalyst Control Center Graphics Light "{E6C09BFB-BA75-15C7-5B18-A2CE31C4F42B}" = Catalyst Control Center Graphics Previews Common "{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "ABC 3GP/MP4 Converter" = ABC 3GP/MP4 Converter 3.00 "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "All ATI Software" = ATI - Software Uninstall Utility "ATI Display Driver" = ATI Display Driver "Bulgarian_KBD'S_Atanasov" = Bulgarian Keyboards XP by G. Atanasov "Creative Jukebox Driver" = Creative Jukebox Driver "Creative Removable Disk Manager" = Creative Removable Disk Manager "Dream Match Tennis Pro_is1" = Dream Match Tennis Pro "EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.30 "FlashGet" = FlashGet 1.81 "FlexType 2K" = FlexType 2K "Gaberoff Koral English Free Dictionary 1.0" = Gaberoff Koral English Free Dictionary 1.0 "Hamachi" = Hamachi 1.0.0.46 "Heroes of Might and Magic® III" = Heroes of Might and Magic® III Complete "HijackThis" = HijackThis 2.0.2 "HLSW_is1" = HLSW v1.2.1 "KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.5.3 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft Silverlight" = Microsoft Silverlight "Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3) "MP3 To Ringtone Gold_is1" = MP3 To Ringtone Gold 8.7 "NOD32" = NOD32 antivirus system "NVIDIA Drivers" = NVIDIA Drivers "PokerStars" = PokerStars "PokerStars.net" = PokerStars.net "Quintessential Media Player" = Quintessential Media Player "ST6UNST #1" = Hero Editor "ST6UNST #2" = Hero Editor V0.96 "sXe Injected" = sXe Injected "SysInfo" = Creative System Information "TeamViewer 5" = TeamViewer 5 "The KMPlayer" = The KMPlayer (remove only) "vloader 2.4" = vloader 2.4 "Winamp" = Winamp "WinISO_is1" = WinISO 5.3 "WinRAR archiver" = Архиватор WinRAR ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1214440339-515967899-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 26.11.2009 г. 04:25:31 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application acrord32.exe, version 5.0.5.452, faulting module acrord32.exe, version 5.0.5.452, fault address 0x00002b15. Error - 26.11.2009 г. 04:26:10 | Computer Name = PC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.8.20081.21709, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 26.11.2009 г. 04:26:11 | Computer Name = PC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.8.20081.21709, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 26.11.2009 г. 04:26:28 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application acrord32.exe, version 5.0.5.452, faulting module acrord32.exe, version 5.0.5.452, fault address 0x00002b15. Error - 26.11.2009 г. 04:26:54 | Computer Name = PC | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.8.20081.21709, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 26.11.2009 г. 05:06:57 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application acrord32.exe, version 5.0.5.452, faulting module acrord32.exe, version 5.0.5.452, fault address 0x00002b15. Error - 26.11.2009 г. 05:09:38 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application acrord32.exe, version 5.0.5.452, faulting module acrord32.exe, version 5.0.5.452, fault address 0x00002b15. Error - 27.11.2009 г. 05:09:41 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application uninst1.exe, version 0.0.0.0, faulting module gentee.dll, version 0.0.0.0, fault address 0x00006308. Error - 27.11.2009 г. 05:10:00 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application sxeinjectedsetup.8.4.exe, version 0.0.0.0, faulting module gentee.dll, version 0.0.0.0, fault address 0x000069c3. Error - 27.11.2009 г. 20:46:50 | Computer Name = PC | Source = Application Error | ID = 1000 Description = Faulting application kmplayer.exe, version 2.9.4.1434, faulting module unknown, version 0.0.0.0, fault address 0x00000000. [ System Events ] Error - 24.3.2010 г. 09:41:55 | Computer Name = PC | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 24.3.2010 г. 09:41:55 | Computer Name = PC | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 24.3.2010 г. 19:39:11 | Computer Name = PC | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 24.3.2010 г. 19:39:11 | Computer Name = PC | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 24.3.2010 г. 19:39:26 | Computer Name = PC | Source = W32Time | ID = 39452689 Description = Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Error - 24.3.2010 г. 19:39:26 | Computer Name = PC | Source = W32Time | ID = 39452701 Description = The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time. Error - 07.4.2010 г. 15:02:04 | Computer Name = PC | Source = Service Control Manager | ID = 7034 Description = The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s). Error - 07.4.2010 г. 15:02:04 | Computer Name = PC | Source = Service Control Manager | ID = 7034 Description = The BlueSoleil Hid Service service terminated unexpectedly. It has done this 1 time(s). Error - 07.4.2010 г. 15:02:04 | Computer Name = PC | Source = Service Control Manager | ID = 7034 Description = The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). Error - 07.4.2010 г. 15:02:04 | Computer Name = PC | Source = Service Control Manager | ID = 7031 Description = The NOD32 Kernel Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. < End of report >
  10. Добър ден, побликувам логовете от двете програми,поради причината,че напоследък машината ми като за начало се пуска и изключва по бавно,а съм оставил със стартирането да се пускат само необходимите ми програми.Работата на компютърът също е по-бавна в сравнение от преди и като цяло ми се струва,че съм хванал някой друг вирус от "Замунда".Надявам се да съм се изразил достатъчно ясно,а ето ги и логовете: Malwarebytes' Anti-Malware Malwarebytes' Anti-Malware 1.44 Database version: 3779 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 07.4.2010 г. 21:05:43 mbam-log-2010-04-07 (21-05-43).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|H:\|I:\|) Objects scanned: 165782 Time elapsed: 15 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) TrendMicro™ HijackThis™ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:09:42, on 07.4.2010 г. Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\D-Tools\daemon.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\Datecs\Flex2K.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files\Winamp\winamp.exe C:\WINDOWS\system32\CTPdeSrv.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: BlueSoleil.lnk = ? O4 - Global Startup: FlexType 2K.lnk = C:\WINDOWS\Datecs\Flex2K.exe O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O13 - Gopher Prefix: O17 - HKLM\System\CCS\Services\Tcpip\..\{0CF875B8-F761-4EBB-A9E0-A02372AB26A6}: NameServer = 213.231.129.5 213.231.128.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{7D31D7D9-C142-4564-87ED-8C035D0F8524}: NameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{0CF875B8-F761-4EBB-A9E0-A02372AB26A6}: NameServer = 213.231.129.5 213.231.128.1 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe -- End of file - 7028 bytes

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.