Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Dilyara

Потребител
  • Регистрация

  • Последно онлайн

  1. Здравейте!Искам първо да Ви поздравя за празниците с пожелание за здраве и много професионални успехи! За Коледа си купих лаптоп,но направих голямата глупост да си сваля картика с някакви пеещи елфчета и разбира се си лепнах вирус-който е следния...как да си го изчистя в безизходица съм
  2. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4361 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 28/07/2010 09:17:51 mbam-log-2010-07-28 (09-17-51).txt Scan type: Quick scan Objects scanned: 127347 Time elapsed: 5 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: Не,нямам проблеми с Windows,a дали е имало инсталиран щпионин на компютъра ми?Сигурно задавам смешни въпроси,но моля да ме извините за невежеството..
  3. File mstime.dll received on 2010.07.27 13:22:51 (UTC) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Съжелявам за късния отговор..,но бях в отпуск.Продължавам по стъпките Result: 0/42 (0%) Loading server information... Your file is queued in position: 5. Estimated start time is between 78 and 112 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2010.07.27.00 2010.07.26 - AntiVir 8.2.4.26 2010.07.27 - Antiy-AVL 2.0.3.7 2010.07.26 - Authentium 5.2.0.5 2010.07.27 - Avast 4.8.1351.0 2010.07.26 - Avast5 5.0.332.0 2010.07.26 - AVG 9.0.0.851 2010.07.27 - BitDefender 7.2 2010.07.27 - CAT-QuickHeal 11.00 2010.07.27 - ClamAV 0.96.0.3-git 2010.07.27 - Comodo 5556 2010.07.27 - DrWeb 5.0.2.03300 2010.07.27 - Emsisoft 5.0.0.34 2010.07.27 - eSafe 7.0.17.0 2010.07.26 - eTrust-Vet 36.1.7742 2010.07.27 - F-Prot 4.6.1.107 2010.07.27 - F-Secure 9.0.15370.0 2010.07.27 - Fortinet 4.1.143.0 2010.07.24 - GData 21 2010.07.27 - Ikarus T3.1.1.84.0 2010.07.27 - Jiangmin 13.0.900 2010.07.26 - Kaspersky 7.0.0.125 2010.07.27 - McAfee 5.400.0.1158 2010.07.27 - McAfee-GW-Edition 2010.1 2010.07.27 - Microsoft 1.6004 2010.07.27 - NOD32 5316 2010.07.27 - Norman 6.05.11 2010.07.27 - nProtect 2010-07-27.01 2010.07.27 - Panda 10.0.2.7 2010.07.27 - PCTools 7.0.3.5 2010.07.27 - Prevx 3.0 2010.07.27 - Rising 22.58.01.04 2010.07.27 - Sophos 4.55.0 2010.07.27 - Sunbelt 6647 2010.07.27 - SUPERAntiSpyware 4.40.0.1006 2010.07.27 - Symantec 20101.1.1.7 2010.07.27 - TheHacker 6.5.2.1.326 2010.07.27 - TrendMicro 9.120.0.1004 2010.07.27 - TrendMicro-HouseCall 9.120.0.1004 2010.07.27 - VBA32 3.12.12.6 2010.07.27 - ViRobot 2010.7.24.3958 2010.07.27 - VirusBuster 5.0.27.0 2010.07.27 - Additional information File size: 532480 bytes MD5...: e1a5918bd11d7d68f7770728182ea519 SHA1..: 2f5efa266b635a0b3eb87aa204c196fb0633dedf SHA256: c8a833861cb508746eea69fe78a27155c6af9875eb31b003e5e246c2cbe4176f ssdeep: 12288:GOJ2a0rcULOZRQMgqGC54DYhCG+drQOSqDLIpAeIfo:vEa0rcULOZRQFqd 4DYL+d8OvNe4 PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x1382b timedatestamp.....: 0x4802a182 (Mon Apr 14 00:12:50 2008) machinetype.......: 0x14c (I386) ( 5 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x6eb21 0x6ec00 6.57 d1fb23b932c0a4aa49f7044f16439026 .orpc 0x70000 0x6b 0x200 1.75 9e2de71f8f7cdf4e1673ec8e5e292cfe .data 0x71000 0x1e28 0x1c00 3.25 aed3ec88fecf3f145c0c1a61e48984c3 .rsrc 0x73000 0x91a0 0x9200 4.50 4f1413445b21ef205875dcb65c3fe0d7 .reloc 0x7d000 0x7eb2 0x8000 6.04 11c9d2cf857262edbc0869889e0f6d4f ( 12 imports ) > msvcrt.dll: __dllonexit, bsearch, _itow, wcscmp, _adjust_fdiv, malloc, _onexit, free, memmove, _wtoi, ceil, floor, _ftol, _HUGE, wcslen, _initterm, _except_handler3 > KERNEL32.dll: SetUnhandledExceptionFilter, GetProcessHeap, FreeLibraryAndExitThread, SetEvent, WaitForMultipleObjectsEx, CreateThread, GetProcAddress, GetVersionExA, WaitForSingleObjectEx, GlobalFree, GlobalHandle, GlobalSize, GlobalReAlloc, UnhandledExceptionFilter, IsBadReadPtr, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, VirtualFree, VirtualAlloc, HeapReAlloc, HeapFree, HeapAlloc, SetFilePointer, WriteFile, GetTimeZoneInformation, GetSystemTime, SystemTimeToFileTime, IsBadWritePtr, InterlockedExchange, ReadFile, GetLocalTime, DisableThreadLibraryCalls, HeapDestroy, lstrlenW, lstrcpyW, GetUserDefaultLCID, InterlockedDecrement, InterlockedIncrement, GetFileSize, FreeLibrary, GlobalAlloc, GlobalLock, GlobalUnlock, lstrcatW, CloseHandle, GetCurrentProcess, GetCurrentThreadId, lstrlenA, MultiByteToWideChar, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, GetLastError > USER32.dll: wsprintfA, ReleaseCapture, TranslateMessage, CopyRect, SetRectEmpty, FillRect, SetTimer, KillTimer, MsgWaitForMultipleObjects, GetSystemMetrics, DestroyWindow, wsprintfW, MapWindowPoints, GetDC, ReleaseDC, SetRect, IntersectRect, EqualRect > GDI32.dll: BitBlt, DeleteObject, DeleteDC, GetDeviceCaps, CreateDIBSection, GetPaletteEntries, CreateSolidBrush, StretchBlt, SetTextColor, SetBkColor, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, SetPixel, GetPixel, SetStretchBltMode > ADVAPI32.dll: RegCloseKey > ole32.dll: CoTaskMemFree, CoTaskMemAlloc, CoInitializeEx, CoUninitialize, StringFromCLSID, ProgIDFromCLSID, CoCreateInstance, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, OleRun, StringFromGUID2 > OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, - > urlmon.dll: CoInternetCombineUrl, FindMimeFromData, URLDownloadToCacheFileW, CoGetClassObjectFromURL, CreateAsyncBindCtx, CompatFlagsFromClsid > WININET.dll: InternetGetConnectedStateExW, InternetCombineUrlW, InternetCrackUrlW > DDRAW.dll: DirectDrawCreate > SHLWAPI.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, StrCmpIW, PathAppendW, StrCmpNIW, StrStrIW, PathFindExtensionW, PathFileExistsW, StrCatW, StrCpyW, PathFindFileNameW, StrCpyNW, StrCSpnIW, StrStrW, StrCmpW, wvnsprintfW, wnsprintfW, StrSpnW, StrNCatW, StrRChrW, StrCmpNW, StrCatBuffW, -, -, -, -, -, -, -, -, -, -, -, -, -, - > RPCRT4.dll: CStdStubBuffer_IsIIDSupported, CStdStubBuffer_CountRefs, CStdStubBuffer_Invoke, CStdStubBuffer_Disconnect, CStdStubBuffer_Connect, CStdStubBuffer_AddRef, CStdStubBuffer_QueryInterface, CStdStubBuffer_DebugServerQueryInterface, IUnknown_Release_Proxy, IUnknown_AddRef_Proxy, IUnknown_QueryInterface_Proxy, NdrCStdStubBuffer_Release, NdrOleAllocate, CStdStubBuffer_DebugServerRelease, NdrDllUnregisterProxy, NdrDllRegisterProxy, NdrDllGetClassObject, NdrDllCanUnloadNow, NdrOleFree ( 5 exports ) DllCanUnloadNow, DllEnumClassObjects, DllGetClassObject, DllRegisterServer, DllUnregisterServer RDS...: NSRL Reference Data Set - pdfid.: - trid..: Windows OCX File (85.9%) Win32 Executable Generic (5.9%) Win32 Dynamic Link Library (generic) (5.2%) Generic Win/DOS Executable (1.3%) DOS Executable Generic (1.3%) sigcheck: publisher....: Microsoft Corporation copyright....: © Microsoft Corporation. All rights reserved. product......: Microsoft_ Windows_ Operating System description..: Microsoft ® Timed Interactive Multimedia Extensions to HTML original name: MSTIME.DLL internal name: MSTIME file version.: 6.00.2900.5512 (xpsp.080413-2105) comments.....: n/a signers......: - signing date.: - OTL logfile created on: 27/07/2010 16:40:25 - Run 2 OTL by OldTimer - Version 3.2.8.1 Folder = C:\Documents and Settings\User\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd/MM/yyyy 998.00 Mb Total Physical Memory | 395.00 Mb Available Physical Memory | 40.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free Paging file location(s): C:\pagefile.sys 1500 3000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 19.54 Gb Total Space | 11.50 Gb Free Space | 58.87% Space Free | Partition Type: NTFS Drive D: | 54.99 Gb Total Space | 26.27 Gb Free Space | 47.77% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: NEC-8EBEED200FC Current User Name: User Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2010/07/09 14:10:36 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe PRC - [2010/06/30 14:52:22 | 000,836,464 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2010/06/28 23:57:18 | 002,837,864 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2010/06/20 05:06:46 | 000,349,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe PRC - [2010/06/10 09:13:05 | 000,116,104 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe PRC - [2010/06/10 09:12:39 | 000,378,248 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardian.exe PRC - [2008/06/10 20:26:28 | 000,222,456 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/12/03 08:59:52 | 000,037,376 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe PRC - [2007/08/03 16:09:34 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe PRC - [2007/08/03 16:09:34 | 000,063,040 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe PRC - [2006/07/29 12:20:34 | 000,098,304 | R--- | M] (Intel) -- C:\Program Files\Intel\AMT\LMS.exe PRC - [2002/05/19 10:24:00 | 000,095,232 | ---- | M] () -- C:\Program Files\Datecs\FlexType 2K\FType2K.exe PRC - [2001/01/25 15:07:54 | 000,225,353 | ---- | M] (Quazar Software GmbH) -- C:\Program Files\UPS\Upsman\www\ServiceDriver.exe ========== Modules (SafeList) ========== MOD - [2010/07/09 14:10:36 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe MOD - [2008/04/14 03:12:06 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolss.dll MOD - [2008/04/14 03:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx MOD - [2006/07/26 02:01:10 | 000,100,544 | ---- | M] (KYOCERA MITA Corporation) -- C:\WINDOWS\system32\KMPJLMN.DLL MOD - [2002/04/23 01:17:06 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ) SRV - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner) SRV - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner) SRV - [2010/06/28 23:57:15 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2010/06/10 09:13:05 | 000,116,104 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint) SRV - [2008/06/10 20:26:28 | 000,222,456 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service) SRV - [2007/08/03 16:09:34 | 000,063,040 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn) SRV - [2006/07/29 12:20:34 | 000,098,304 | R--- | M] (Intel) [Auto | Running] -- C:\Program Files\Intel\AMT\LMS.exe -- (LMS) Intel® SRV - [2006/07/22 02:28:22 | 002,768,982 | ---- | M] (Generex GmbH) [Auto | Stopped] -- C:\Program Files\UPS\Upsman\upsman.exe -- (UPSMan) SRV - [2001/01/25 15:07:54 | 000,225,353 | ---- | M] (Quazar Software GmbH) [Auto | Running] -- C:\Program Files\UPS\Upsman\www\ServiceDriver.exe -- (qHTTPs) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\nod32drv.sys -- (nod32drv) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\68.tmp -- (MEMSWEEP2) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys -- (catchme) DRV - [2010/06/28 23:37:52 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2010/06/28 23:37:30 | 000,165,456 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2010/06/28 23:33:13 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2010/06/28 23:32:45 | 000,100,176 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2010/06/28 23:32:33 | 000,017,744 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2010/06/28 23:32:16 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2010/06/10 09:12:43 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP) DRV - [2010/05/10 21:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL) DRV - [2010/02/17 21:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV) DRV - [2008/10/20 09:11:02 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver) DRV - [2008/04/13 19:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008/02/28 15:31:50 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo) DRV - [2006/11/01 12:39:16 | 000,246,680 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel® DRV - [2006/07/24 17:15:04 | 004,353,024 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2006/07/21 15:12:00 | 001,095,968 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm) DRV - [2006/06/19 15:18:56 | 000,043,264 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel® ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://mail30.abv.bg/app/j/box.jsp?fid=10|about:blank" FF - prefs.js..network.proxy.type: 2 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/30 16:40:08 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/02 09:03:40 | 000,000,000 | ---D | M] [2009/04/07 13:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions [2009/04/07 13:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x93nprk2.default\extensions [2009/04/07 13:01:55 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions O1 HOSTS File: ([2010/07/09 16:52:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\ShellBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKCU\..\Toolbar\ShellBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKCU..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = C:\Program Files\Datecs\FlexType 2K\FType2K.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O8 - Extra context menu item: Open in new background tab - C:\Program Files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui (Microsoft Corporation) O8 - Extra context menu item: Open in new foreground tab - C:\Program Files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui (Microsoft Corporation) O15 - HKCU\..Trusted Domains: ([]msn in My Computer) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation) O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007/12/05 19:46:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation) Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation) Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation) Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation) Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation) Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation) Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation) Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation) Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation) Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation) Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation) Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation) Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation) Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation) Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation) Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation) Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation) Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation) Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation) CREATERESTOREPOINT Restore point Set: OTL Restore Point (16902053519425536) ========== Files/Folders - Created Within 30 Days ========== [2010/07/26 12:43:54 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2010/07/20 09:24:52 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe [2010/07/09 16:54:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2010/07/09 16:48:22 | 000,000,000 | RHSD | C] -- C:\cmdcons [2010/07/09 16:46:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2010/07/09 16:46:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2010/07/09 16:46:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2010/07/09 16:46:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2010/07/09 16:46:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2010/07/09 16:46:30 | 000,000,000 | ---D | C] -- C:\Qoobox [2010/07/09 16:21:19 | 000,000,000 | ---D | C] -- C:\_OTL [2010/07/09 14:10:32 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe [2010/07/09 12:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com [2010/07/09 12:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com [2010/07/09 12:01:03 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware [2010/07/09 11:57:03 | 009,070,816 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\User\Desktop\SUPERAntiSpyware.exe [2010/07/09 10:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos [2010/07/08 16:32:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Malwarebytes [2010/07/08 16:32:16 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010/07/08 16:32:13 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010/07/08 16:32:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2010/07/08 16:32:12 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010/07/07 14:25:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\WinRAR [2010/07/02 14:16:32 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\User\PrivacIE [2010/07/02 14:16:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\User\IECompatCache [2010/07/02 13:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\My Documents\Backups [2010/07/02 13:24:20 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll [2010/07/02 13:24:19 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll [2010/07/02 13:24:18 | 001,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll [2010/07/02 13:24:17 | 011,076,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll [2010/07/02 13:24:16 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll [2010/07/02 13:23:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM [2010/07/02 13:21:58 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieencode.dll [2010/07/02 13:21:58 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieencode.dll [2010/07/01 09:45:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google [2010/07/01 09:40:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Temp [2010/07/01 09:40:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google [2010/07/01 09:40:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Google [2010/07/01 09:40:44 | 000,000,000 | ---D | C] -- C:\Program Files\Google [2010/06/29 09:07:41 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\WINDOWS\avastSS.scr ========== Files - Modified Within 30 Days ========== [2010/07/27 15:47:00 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job [2010/07/27 15:45:00 | 000,001,040 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010/07/27 14:18:02 | 000,046,265 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Letter9166-126-27.07.2010-AdmistrativniNarushenia.pdf [2010/07/27 10:58:48 | 008,126,464 | ---- | M] () -- C:\Documents and Settings\User\NTUSER.DAT [2010/07/27 09:45:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010/07/26 14:50:52 | 002,285,750 | ---- | M] () -- C:\Documents and Settings\User\My Documents\protokol1-1.tif [2010/07/26 14:50:40 | 002,285,750 | ---- | M] () -- C:\Documents and Settings\User\My Documents\protokol2-1.tif [2010/07/26 12:43:12 | 000,001,091 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Microsoft Outlook Web Access - Agro.url [2010/07/26 09:07:22 | 000,473,088 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Copy of National reserve_2010 - 2011_MZH1_raboten_10_07-10_sled_dim__Zapov_okon_sled_ODZ.XLS [2010/07/26 08:58:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010/07/26 08:58:20 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010/07/26 08:58:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/07/22 10:47:05 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini [2010/07/09 16:52:15 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2010/07/09 16:52:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2010/07/09 16:48:27 | 000,000,281 | RHS- | M] () -- C:\boot.ini [2010/07/09 16:40:01 | 003,728,667 | R--- | M] () -- C:\Documents and Settings\User\Desktop\ff2.exe [2010/07/09 15:59:47 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Метереологична станция.doc [2010/07/09 14:10:36 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe [2010/07/09 12:48:21 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\User\Desktop\ОБЛАСТ ДОБРИЧ.doc [2010/07/09 12:46:41 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\User\My Documents\ОБЛАСТ ДОБРИЧ.doc [2010/07/09 12:01:09 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk [2010/07/09 11:57:52 | 009,070,816 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\User\Desktop\SUPERAntiSpyware.exe [2010/07/09 11:55:05 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2010/07/09 11:54:59 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/07/09 10:40:31 | 001,376,832 | ---- | M] () -- C:\Documents and Settings\User\Desktop\sar_15_sfx.exe [2010/07/09 09:56:23 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\User\Desktop\за гери.doc [2010/07/09 09:25:53 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\User\Desktop\dds.scr [2010/07/09 09:21:12 | 000,867,892 | ---- | M] () -- C:\Documents and Settings\User\Desktop\SecurityCheck.exe [2010/07/09 08:59:29 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Microsoft Office Word 2003.lnk [2010/07/08 16:04:37 | 000,001,891 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2010/07/07 15:37:19 | 000,010,752 | ---- | M] () -- C:\YIEL10-Incoherence_Data.xls [2010/07/06 14:03:09 | 000,000,492 | ---- | M] () -- C:\Documents and Settings\User\My Documents\spider.sav [2010/07/06 13:06:56 | 009,646,080 | ---- | M] () -- C:\DECIDEV2.01.MDB [2010/07/06 10:21:14 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk [2010/07/05 11:09:12 | 000,002,495 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Microsoft Office Excel 2003.lnk [2010/07/02 16:35:33 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2010/07/02 13:37:59 | 000,102,400 | ---- | M] () -- C:\Documents and Settings\User\My Documents\db1.mdb [2010/06/29 09:07:43 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2010/06/28 23:57:33 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\WINDOWS\avastSS.scr [2010/06/28 23:57:12 | 000,165,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2010/06/28 23:37:52 | 000,046,672 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2010/06/28 23:37:30 | 000,165,456 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2010/06/28 23:33:13 | 000,023,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2010/06/28 23:32:45 | 000,100,176 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2010/06/28 23:32:42 | 000,094,544 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2010/06/28 23:32:33 | 000,017,744 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2010/06/28 23:32:16 | 000,028,880 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2010/06/28 16:02:56 | 000,358,914 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010/06/28 16:02:56 | 000,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010/06/28 16:02:56 | 000,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat ========== Files Created - No Company Name ========== [2010/07/27 14:16:14 | 000,046,265 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Letter9166-126-27.07.2010-AdmistrativniNarushenia.pdf [2010/07/26 14:50:51 | 002,285,750 | ---- | C] () -- C:\Documents and Settings\User\My Documents\protokol1-1.tif [2010/07/26 14:50:39 | 002,285,750 | ---- | C] () -- C:\Documents and Settings\User\My Documents\protokol2-1.tif [2010/07/26 12:43:12 | 000,001,091 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Microsoft Outlook Web Access - Agro.url [2010/07/26 09:13:33 | 000,473,088 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Copy of National reserve_2010 - 2011_MZH1_raboten_10_07-10_sled_dim__Zapov_okon_sled_ODZ.XLS [2010/07/09 16:48:27 | 000,000,211 | ---- | C] () -- C:\Boot.bak [2010/07/09 16:48:25 | 000,260,272 | ---- | C] () -- C:\cmldr [2010/07/09 16:46:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe [2010/07/09 16:46:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2010/07/09 16:46:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2010/07/09 16:46:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe [2010/07/09 16:46:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2010/07/09 16:39:50 | 003,728,667 | R--- | C] () -- C:\Documents and Settings\User\Desktop\ff2.exe [2010/07/09 15:51:41 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Метереологична станция.doc [2010/07/09 12:48:21 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\User\Desktop\ОБЛАСТ ДОБРИЧ.doc [2010/07/09 12:46:41 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\User\My Documents\ОБЛАСТ ДОБРИЧ.doc [2010/07/09 12:01:09 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk [2010/07/09 10:40:29 | 001,376,832 | ---- | C] () -- C:\Documents and Settings\User\Desktop\sar_15_sfx.exe [2010/07/09 09:56:23 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\User\Desktop\за гери.doc [2010/07/09 09:25:33 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\User\Desktop\dds.scr [2010/07/09 09:21:10 | 000,867,892 | ---- | C] () -- C:\Documents and Settings\User\Desktop\SecurityCheck.exe [2010/07/06 14:03:09 | 000,000,492 | ---- | C] () -- C:\Documents and Settings\User\My Documents\spider.sav [2010/07/05 10:53:48 | 000,010,752 | ---- | C] () -- C:\YIEL10-Incoherence_Data.xls [2010/07/01 09:40:52 | 000,001,040 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010/07/01 09:40:51 | 000,001,036 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2008/10/07 15:06:18 | 000,000,048 | ---- | C] () -- C:\WINDOWS\scmate.ini [2008/04/08 11:47:04 | 000,000,322 | ---- | C] () -- C:\WINDOWS\SWWATER.INI [2008/01/17 15:03:18 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll [2008/01/10 16:54:02 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2007/12/05 20:39:23 | 000,192,512 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4642.dll [2007/12/05 20:39:22 | 000,348,880 | R--- | C] () -- C:\WINDOWS\System32\igmedkrn.dll [2007/12/05 20:36:44 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2007/12/05 20:33:07 | 000,000,508 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2007/12/05 16:26:02 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2007/12/05 19:46:50 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2008/01/01 22:25:43 | 000,000,211 | ---- | M] () -- C:\Boot.bak [2010/07/09 16:48:27 | 000,000,281 | RHS- | M] () -- C:\boot.ini [2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr [2010/07/09 16:54:02 | 000,015,767 | ---- | M] () -- C:\ComboFix.txt [2007/12/05 19:46:50 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2010/07/06 13:06:56 | 009,646,080 | ---- | M] () -- C:\DECIDEV2.01.MDB [2007/12/05 19:46:50 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2007/12/05 19:46:50 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2007/12/05 20:17:01 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2009/07/21 11:32:17 | 000,250,048 | RHS- | M] () -- C:\ntldr [2010/07/26 08:58:04 | 1572,864,000 | -HS- | M] () -- C:\pagefile.sys [2010/07/07 15:37:19 | 000,010,752 | ---- | M] () -- C:\YIEL10-Incoherence_Data.xls < %systemroot%\*. /mp /s > < %systemroot%\*.scr > [2010/06/28 23:57:33 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\WINDOWS\avastSS.scr < %systemroot%\*._sy > < %systemroot%\Fonts\*.com > < %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini > [2007/12/05 19:46:35 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini < %systemroot%\Fonts\*.ini2 > < %systemroot%\system32\*.wt > < %systemroot%\system32\*.ruy > < %systemroot%\system32\*.jpg > < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll > [2010/06/10 09:12:42 | 000,053,632 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll [2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll < %systemroot%\system32\spool\prtprocs\w32x86\*.tmp > < %systemroot%\system32\*.dll /lockedfiles > [2008/04/14 03:11:52 | 000,357,888 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll [2008/04/14 03:11:52 | 000,205,312 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll [2008/04/14 03:12:00 | 000,532,480 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\mstime.dll < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav > [2007/12/04 21:33:41 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav [2007/12/04 21:33:41 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav [2007/12/04 21:33:40 | 000,421,888 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav < %systemroot%\system32\mstime.dll /md5 > [2008/04/14 03:12:00 | 000,532,480 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\mstime.dll < End of report >
  4. All processes killed ========== OTL ========== Starting removal of ActiveX control {31435657-9980-0010-8000-00AA00389B71} C:\WINDOWS\Downloaded Program Files\wvc1dmo.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31435657-9980-0010-8000-00AA00389B71}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found. Starting removal of ActiveX control {32505657-9980-0010-8000-00AA00389B71} C:\WINDOWS\Downloaded Program Files\wmvadvd.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{32505657-9980-0010-8000-00AA00389B71}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32505657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{32505657-9980-0010-8000-00AA00389B71}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32505657-9980-0010-8000-00AA00389B71}\ not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{224dc1ec-8947-11dd-b53d-001bb9fd7e0a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224dc1ec-8947-11dd-b53d-001bb9fd7e0a}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{224dc1ec-8947-11dd-b53d-001bb9fd7e0a}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{224dc1ec-8947-11dd-b53d-001bb9fd7e0a}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c551c90c-8af8-11de-b621-001bb9fd7e0a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c551c90c-8af8-11de-b621-001bb9fd7e0a}\ not found. File l61yyp.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c551c90c-8af8-11de-b621-001bb9fd7e0a}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c551c90c-8af8-11de-b621-001bb9fd7e0a}\ not found. File l61yyp.exe not found. ========== FILES ========== C:\WINDOWS\002235_.tmp moved successfully. C:\WINDOWS\005750_.tmp moved successfully. C:\WINDOWS\SET3.tmp moved successfully. C:\WINDOWS\SET7.tmp moved successfully. C:\WINDOWS\system32\CONFIG.TMP moved successfully. C:\WINDOWS\system32\SET17E9.tmp moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 65716 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 438408 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: User ->Temp folder emptied: 200980944 bytes ->Temporary Internet Files folder emptied: 4108596808 bytes ->FireFox cache emptied: 83269849 bytes ->Google Chrome cache emptied: 5955674 bytes ->Opera cache emptied: 15520671 bytes ->Flash cache emptied: 1605586 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 62204047 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 12373208 bytes Total Files Cleaned = 4 283.00 mb [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: User ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.8.1 log created on 07092010_162119 Files\Folders moved on Reboot... File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot... ComboFix 10-07-08.02 - User 09/07/2010 16:48:50.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.998.646 [GMT 3:00] Running from: c:\documents and settings\User\Desktop\ff2.exe AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\setup.ini . ((((((((((((((((((((((((( Files Created from 2010-06-09 to 2010-07-09 ))))))))))))))))))))))))))))))) . 2010-07-09 13:21 . 2010-07-09 13:21 -------- d-----w- C:\_OTL 2010-07-09 09:02 . 2010-07-09 09:02 63488 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2010-07-09 09:02 . 2010-07-09 09:02 52224 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-07-09 09:02 . 2010-07-09 09:02 117760 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-07-09 09:01 . 2010-07-09 09:01 -------- d-----w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com 2010-07-09 09:01 . 2010-07-09 09:01 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2010-07-09 09:01 . 2010-07-09 09:01 -------- d-----w- c:\program files\SUPERAntiSpyware 2010-07-09 07:41 . 2010-07-09 07:41 -------- d-----w- c:\program files\Sophos 2010-07-08 13:32 . 2010-07-08 13:32 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes 2010-07-08 13:32 . 2010-04-29 09:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-07-08 13:32 . 2010-07-08 13:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-07-08 13:32 . 2010-04-29 09:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-07-08 13:32 . 2010-07-08 13:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-07-02 11:16 . 2010-07-02 11:16 -------- d-sh--w- c:\documents and settings\User\PrivacIE 2010-07-02 11:16 . 2010-07-02 11:16 -------- d-sh--w- c:\documents and settings\User\IECompatCache 2010-07-02 10:24 . 2010-05-06 10:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2010-07-02 10:24 . 2010-05-06 10:41 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-07-02 10:24 . 2010-05-06 10:41 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2010-07-02 10:24 . 2010-05-06 10:41 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2010-07-02 10:24 . 2010-05-06 10:41 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2010-07-02 10:24 . 2010-05-06 10:41 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll 2010-07-02 10:24 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll 2010-07-02 10:24 . 2010-04-16 11:43 41984 -c----w- c:\windows\system32\dllcache\iecompat.dll 2010-07-02 10:21 . 2010-04-16 16:09 81920 ----a-w- c:\windows\system32\ieencode.dll 2010-07-02 10:21 . 2010-04-16 16:09 81920 ----a-w- c:\windows\system32\dllcache\ieencode.dll 2010-07-01 06:45 . 2010-07-01 06:45 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google 2010-07-01 06:40 . 2010-07-02 11:45 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Temp 2010-07-01 06:40 . 2010-07-01 06:40 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google 2010-07-01 06:40 . 2010-07-01 07:20 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Google 2010-07-01 06:40 . 2010-07-01 06:42 -------- d-----w- c:\program files\Google 2010-06-29 14:31 . 2010-06-29 14:31 45336 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-06-29 06:07 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-09 13:45 . 2008-01-08 13:51 -------- d-----w- c:\documents and settings\User\Application Data\Skype 2010-07-09 13:01 . 2008-01-08 13:53 -------- d-----w- c:\documents and settings\User\Application Data\skypePM 2010-07-09 05:46 . 2008-02-01 16:40 -------- d-----w- c:\program files\LogMeIn 2010-07-07 11:56 . 2010-02-15 12:31 -------- d-----w- c:\program files\Winferno 2010-07-07 11:56 . 2008-01-08 14:57 -------- d-----w- c:\program files\PowerArchiver 2010-07-06 07:21 . 2008-01-08 12:27 -------- d-----w- c:\program files\Opera 2010-07-02 05:58 . 2009-12-10 07:11 -------- d-----r- c:\program files\Skype 2010-06-28 20:57 . 2010-05-04 09:54 165032 ----a-w- c:\windows\system32\aswBoot.exe 2010-06-28 20:37 . 2010-05-04 09:54 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2010-06-28 20:37 . 2010-05-04 09:54 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys 2010-06-28 20:33 . 2010-05-04 09:54 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2010-06-28 20:32 . 2010-05-04 09:54 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2010-06-28 20:32 . 2010-05-04 09:54 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys 2010-06-28 20:32 . 2010-05-04 09:54 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2010-06-28 20:32 . 2010-05-04 09:54 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2010-06-10 06:12 . 2008-02-01 16:40 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll 2010-06-10 06:12 . 2008-02-01 16:40 29568 ----a-w- c:\windows\system32\LMIport.dll 2010-06-10 06:12 . 2008-02-01 16:40 87424 ----a-w- c:\windows\system32\LMIinit.dll 2010-06-01 17:37 . 2010-02-04 08:03 221568 ------w- c:\windows\system32\MpSigStub.exe 2010-05-02 05:22 . 2001-08-23 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys 2010-04-20 05:30 . 2001-08-23 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll 2010-04-16 16:09 . 2001-08-23 12:00 667136 ----a-w- c:\windows\system32\wininet.dll 2008-01-15 13:46 . 2008-01-15 13:46 6583976 -c--a-w- c:\program files\Opera_9.25_International_Setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-06-29 2403568] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632] "SkyTel"="SkyTel.EXE" [2006-05-16 2879488] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016] "Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-12-03 37376] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2008-1-17 95232] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2010-06-10 06:12 87424 ----a-w- c:\windows\system32\LMIinit.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10724:TCP"= 10724:TCP:BitComet 10724 TCP "10724:UDP"= 10724:UDP:BitComet 10724 UDP R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [04/05/2010 12:54 165456] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 21:25 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 21:41 67656] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/05/2010 12:54 17744] R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [18/02/2009 15:16 222456] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [03/08/2007 16:09 12856] R2 qHTTPs;UPSMAN HTTP;c:\program files\UPS\Upsman\www\ServiceDriver.exe [06/12/2007 14:25 225353] S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys --> c:\windows\system32\drivers\nod32drv.sys [?] S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [01/07/2010 09:40 136176] S2 UPSMan;UPSMan;c:\program files\UPS\Upsman\upsman.exe [06/12/2007 14:25 2768982] S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\68.tmp --> c:\windows\system32\68.tmp [?] . Contents of the 'Scheduled Tasks' folder 2010-07-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 14:39] 2010-07-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-07-01 06:40] 2010-07-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-07-01 06:40] 2010-05-04 c:\windows\Tasks\RPCReminder.job - c:\program files\Winferno\RegistryPowerCleaner\RPCReminder.exe [2010-02-15 12:34] . . ------- Supplementary Scan ------- . uStart Page = abv.bg uSearchURL,(Default) = hxxp://g.msn.co.in/0SEENIN/SAOS01?FORM=TOOLBR IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui/229?31f69b1a09bb44e3b0a77379e04eadab IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui/230?31f69b1a09bb44e3b0a77379e04eadab TCP: {9486A418-6C51-47FE-A75B-1340A73769C4} = 83.222.183.2,83.222.183.3 FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\x93nprk2.default\ FF - prefs.js: browser.startup.homepage - hxxp://mail30.abv.bg/app/j/box.jsp?fid=10|about:blank FF - prefs.js: network.proxy.type - 2 FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - ORPHANS REMOVED - - - - HKCU-Run-BitComet - c:\program files\BitComet\BitComet.exe HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-07-09 16:52 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\68.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(760) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\LMIinit.dll . Completion time: 2010-07-09 16:54:01 ComboFix-quarantined-files.txt 2010-07-09 13:53 Pre-Run: 12 489 543 680 bytes free Post-Run: 12 456 001 536 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn - - End Of File - - E1765B3930AB499600AC77692A581697 Компютъра ми се роди!!!Работи така бързо!!Благодаря Ви много!Радвам се ,че има такъв полезен сайт,с толкова добри специалисти!
  5. Изпращам последните корекции Extras.Txt OTL.Txt
  6. Резултат от SUPER ANTISPYWARE FREE SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/09/2010 at 12:36 PM Application Version : 4.40.1002 Core Rules Database Version : 5177 Trace Rules Database Version: 2989 Scan type : Complete Scan Total Scan Time : 00:27:19 Memory items scanned : 558 Memory threats detected : 0 Registry items scanned : 5415 Registry threats detected : 0 File items scanned : 14937 File threats detected : 42 Adware.Tracking Cookie C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@cgi-bin[2].txt C:\Documents and Settings\User\Cookies\user@fastclick[1].txt C:\Documents and Settings\User\Cookies\user@apmebf[1].txt C:\Documents and Settings\User\Cookies\user@atwola[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@smartadserver[2].txt C:\Documents and Settings\User\Cookies\user@tribalfusion[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@atdmt[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@tacoda[1].txt C:\Documents and Settings\User\Cookies\user@doubleclick[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@mediaplex[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@interclick[1].txt C:\Documents and Settings\User\Cookies\user@advertising[2].txt googleads.g.doubleclick.net [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] interclick.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] m1.emea.2mdn.net [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] macromedia.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] media.marica.bg [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] media.mtvnservices.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] media.scanscout.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] multimedia.metacafe [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] objects.tremormedia.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] oddcast.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] secure-it.imrworldwide.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] serving-sys.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] yield.audience.digitalmedia.bg [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] yo.static.presidiomedia.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\3VSQWNRZ ] .imrworldwide.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x93nprk2.default\cookies.sqlite ] .imrworldwide.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x93nprk2.default\cookies.sqlite ] Adware.Flash Tracking Cookie C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\SERVING-SYS.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\MEDIA.SCANSCOUT.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\MULTIMEDIA.METACAFE C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\OBJECTS.TREMORMEDIA.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\INTERCLICK.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\M1.EMEA.2MDN.NET C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3VSQWNRZ\SECURE-IT.IMRWORLDWIDE.COM Trojan.Agent/Gen-Nullo[short] D:\SYSTEM VOLUME INFORMATION\_RESTORE{5756A2F3-9B33-42C8-9091-AD06F2A81C66}\RP529\A0058720.EXE
  7. Папка sarscan Sophos Anti-Rootkit Version 1.5.4 © 2009 Sophos Plc Started logging on 09/07/2010 at 10:41:19 User "User" on computer "NEC-8EBEED200FC" Windows version 5.1 SP 3.0 Service Pack 3 build 2600 SM=0x100 PT=0x1 Win32 Info: Starting process scan. Info: Starting registry scan. Info: Starting disk scan of C: (NTFS). Hidden: file C:\System Volume Information\_restore{5756A2F3-9B33-42C8-9091-AD06F2A81C66}\RP515\A0057758.exe Hidden: file C:\WINDOWS\system32\dllcache\msw3prt.dll Hidden: file C:\ACDSee32\UNWISE.EXE Hidden: file C:\System Volume Information\_restore{5756A2F3-9B33-42C8-9091-AD06F2A81C66}\RP515\A0057762.exe Hidden: file C:\Program Files\LogMeIn\x64\LogMeIn.dll Hidden: file C:\Program Files\LogMeIn\x86\LogMeInToolkit.exe Hidden: file C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL Hidden: file C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Hidden: file C:\WINDOWS\ServicePackFiles\i386\unregmp2.exe Hidden: file C:\Documents and Settings\User\My Documents\Downloads\Malwarebytes Anti-Malware 1.46 (kaldata.com).exe Hidden: file C:\WINDOWS\system32\WISPTIS.EXE Hidden: file C:\Program Files\Realtek\InstallShield\RTHDCPL.exe Hidden: file C:\WINDOWS\RTHDCPL.exe Hidden: file C:\WINDOWS\system32\igxpun.exe Hidden: file C:\System Volume Information\_restore{5756A2F3-9B33-42C8-9091-AD06F2A81C66}\RP524\A0058618.EXE Hidden: file C:\Program Files\PowerArchiver\SFXS\PASZIPSFX.DAT Hidden: file C:\Program Files\PowerArchiver\PABURNTOOLS.EXE Hidden: file C:\Downloads\BS.Player.Pro.v2.21.950.Multilingual.Incl.Keymaker.Read.NFO-CORE\keygen.exe Hidden: file C:\Downloads\BS.Player.Pro.v2.21.950.Multilingual.Incl.Keymaker.Read.NFO-CORE\setup.exe Hidden: file C:\Documents and Settings\User\Desktop\dds.scr Hidden: file C:\Program Files\Ahead\Nero\SHORTCUT.DLL Hidden: file C:\Program Files\Common Files\Ahead\AudioPlugins\msa.dll Hidden: file C:\Program Files\Common Files\Ahead\AudioPlugins\Aac.dll Hidden: file C:\Program Files\Ahead\Nero\Uninstall\UNNero.exe Hidden: file C:\Program Files\Ahead\Nero Toolkit\CDSpeed.exe Hidden: file C:\Program Files\Ahead\Nero Toolkit\DriveSpeed.exe Hidden: file C:\Program Files\Ahead\ImageDrive\ImageDrive.exe Hidden: file C:\Program Files\StrongDC205\StrongDC.exe Hidden: file C:\WINDOWS\system32\Adobe\Shockwave 11\UNWISE.EXE Hidden: file C:\Downloads\SkypeSetup.exe Hidden: file C:\Documents and Settings\User\Application Data\Astro Gemini Software\Screensaver Manager 2.0\Installed\solarsystem.exe Hidden: file C:\Program Files\KoralSoft\EuroDictXP\EuroDictXP.exe Hidden: file C:\WINDOWS\system32\msw3prt.dll Hidden: file C:\WINDOWS\system32\dllcache\unregmp2.exe Hidden: file C:\WINDOWS\ServicePackFiles\i386\winmm.dll Hidden: file C:\WINDOWS\ServicePackFiles\i386\msw3prt.dll Hidden: file C:\Program Files\Winferno\RegistryPowerCleaner\SysRst.exe Info: Starting disk scan of D: (NTFS). Hidden: file D:\PROGRAMS\K-Lite Codec Pack 2.84 Full.exe Hidden: file D:\PROGRAMS\Opera_9.27_International_Setup.exe Hidden: file D:\PROGRAMS\vlc-0.8.6d-win32.exe Hidden: file D:\PROGRAMS\WebTrance 2.0.0.12.exe Hidden: file D:\Muzik\Opera_951_in_Setup.exe Hidden: file D:\PROGRAMS\Opera_9.23_International_Setup.exe Hidden: file D:\Muzik\Baladi\Winamp 5.08\DFX For Winamp 5.0\cr-df7wp.exe Hidden: file D:\ЛИЧНИ\AVAST\setup_av_free.exe Stopped logging on 09/07/2010 at 11:21:06 Sophos Anti-Rootkit Version 1.5.4 © 2009 Sophos Plc Started logging on 09/07/2010 at 11:39:11 User "User" on computer "NEC-8EBEED200FC" Windows version 5.1 SP 3.0 Service Pack 3 build 2600 SM=0x100 PT=0x1 Win32 Info: Starting process scan. Info: Starting registry scan. Info: Starting disk scan of C: (NTFS).
  8. Здравейте !Благодаря за бързия отговор!Изпълнила съм указанията..Ето ги резултатите.... Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4294 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 09/07/2010 09:11:13 mbam-log-2010-07-09 (09-11-13).txt Scan type: Quick scan Objects scanned: 130734 Time elapsed: 10 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Results of screen317's Security Check version 0.99.4 Windows XP Service Pack 3 Internet Explorer 6 Out of date! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! avast! Free Antivirus OneCare Advisor (Windows Live Toolbar) Microsoft Security Essentials Antivirus up to date! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Winferno Registry Power Cleaner Adobe Flash Player 10.0.45.2 Adobe Reader 9.3.3 - Bulgarian Mozilla Firefox (3.6.6) ```````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSMpEng.exe Malwarebytes' Anti-Malware mbam.exe Microsoft Security Essentials msseces.exe Alwil Software Avast5 AvastSvc.exe ALWILS~1 Avast5 avastUI.exe ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Ето и последната трета стъпка: DDS.txt Attach.txt
  9. Мисля ,че комютъра ми е следен!Инсталирах Malwarebytes"Anti-Malware.Резултата е по -долу:Дали съм успяла да ги изстрия?Благодаря предварително! Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4291 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 08/07/2010 17:16:11 mbam-log-2010-07-08 (17-16-11).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 168323 Time elapsed: 37 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: D:\PROGRAMS\webtrance2_crack.EXE (HackTool.Gen) -> Quarantined and deleted successfully. C:\Program Files\ICQToolbar\4753\toolbaru.dll (Trojan.BHO) -> Delete on reboot.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.