-
Какво да правя [РЕШЕН]
Готово, всичко е ОК Още веднъж, изказвам огромни благодарности
-
Какво да правя [РЕШЕН]
Вие сте невероятни! Ето резултата: Database version: 4345 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 24.7.2010 г. 23:24:31 mbam-log-2010-07-24 (23-24-31).txt Scan type: Quick scan Objects scanned: 141415 Time elapsed: 10 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
-
Какво да правя [РЕШЕН]
ОК, сърдечно благодаря за помощта Ви. Имам да черпя
-
Какво да правя [РЕШЕН]
Ето и резултата: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/24/2010 at 11:17 AM Application Version : 4.41.1000 Core Rules Database Version : 5261 Trace Rules Database Version: 3073 Scan type : Complete Scan Total Scan Time : 00:42:28 Memory items scanned : 528 Memory threats detected : 0 Registry items scanned : 7987 Registry threats detected : 0 File items scanned : 17610 File threats detected : 262 Adware.Tracking Cookie C:\Documents and Settings\User\Cookies\user@statcounter[2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@legolas-media[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@yadro[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@imrworldwide[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@serving-sys[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@pointroll[1].txt C:\Documents and Settings\User\Cookies\user@fastclick[1].txt C:\Documents and Settings\User\Cookies\user@mediaforge[2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@trafficmp[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][3].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@adtech[1].txt C:\Documents and Settings\User\Cookies\user@list[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@downloadwarez[2].txt C:\Documents and Settings\User\Cookies\user@ru4[2].txt C:\Documents and Settings\User\Cookies\user@warezkey[2].txt C:\Documents and Settings\User\Cookies\user@apmebf[2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@shinystat[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@revsci[1].txt C:\Documents and Settings\User\Cookies\user@tribalfusion[2].txt C:\Documents and Settings\User\Cookies\user@kontera[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@media6degrees[1].txt C:\Documents and Settings\User\Cookies\user@questionmarket[1].txt C:\Documents and Settings\User\Cookies\[email protected][3].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@casalemedia[2].txt C:\Documents and Settings\User\Cookies\user@atdmt[2].txt C:\Documents and Settings\User\Cookies\user@tacoda[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@zedo[1].txt C:\Documents and Settings\User\Cookies\user@doubleclick[1].txt C:\Documents and Settings\User\Cookies\user@hotlog[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@mediaplex[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@specificclick[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@eyewonder[1].txt C:\Documents and Settings\User\Cookies\user@chitika[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@adlegend[2].txt C:\Documents and Settings\User\Cookies\user@liveperson[3].txt C:\Documents and Settings\User\Cookies\user@advertising[2].txt C:\Documents and Settings\User\Cookies\user@mediafire[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@partypoker[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@adbrite[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@xiti[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@adviva[2].txt C:\Documents and Settings\User\Cookies\user@2o7[1].txt C:\Documents and Settings\User\Cookies\user@clicksor[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@lynxtrack[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][3].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@smartadserver[1].txt C:\Documents and Settings\User\Cookies\user@efindsite[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@collective-media[1].txt C:\Documents and Settings\User\Cookies\[email protected][7].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@bluestreak[1].txt C:\Documents and Settings\User\Cookies\user@realmedia[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@dmtracker[1].txt C:\Documents and Settings\User\Cookies\user@liveperson[1].txt C:\Documents and Settings\User\Cookies\user@tradedoubler[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][3].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@blackporno[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@trafficregenerator[2].txt C:\Documents and Settings\User\Cookies\user@myroitracking[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@hitbox[1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@insightexpressai[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\user@invitemedia[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][6].txt C:\Documents and Settings\User\Cookies\user@partyaccount[1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][5].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@naiadsystems[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\user@interclick[2].txt C:\Documents and Settings\User\Cookies\[email protected][1].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt C:\Documents and Settings\User\Cookies\[email protected][2].txt ad.yieldmanager.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] banners.bgmaps.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] banners.bgmaps.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] banners.bgmaps.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] media.wii.ign.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] media.wii.ign.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] media.wii.ign.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .richmedia.yahoo.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .mediafire.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .mediafire.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .mediafire.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] banners.bgmaps.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] banners.bgmaps.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] webstat.dsv.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .doubleclick.net [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] rem.rezonmedia.eu [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .apmebf.com [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] .fastclick.net [ C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\cookies.sqlite ] 149.memecounter.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] a.media.abcfamily.go.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] acvs.mediaonenetwork.net [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] adsatt.espn.go.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] atdmt.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] bc.youporn.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] cdn5.specificclick.net [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] cds017.ph1.media.scanscout.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] ds.serving-sys.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] googleads.g.doubleclick.net [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] ia.media-imdb.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] interclick.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] m.uk.2mdn.net [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] macromedia.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media.freedomoftheseas.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media.ign.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media.mtvnservices.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media.nintendo.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media.scanscout.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media1.break.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] media1.clubpenguin.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] memecounter.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] naiadsystems.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] objects.tremormedia.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] pornminded.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] secure-it.imrworldwide.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] secure-us.imrworldwide.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] spe.atdmt.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] videomedia.ign.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] www.pornhub.com [ C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\#SharedObjects\XLHKEHXU ] C:\Documents and Settings\User\Cookies\user@stats[2].txt .revsci.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .revsci.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] counter.search.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .imrworldwide.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .doubleclick.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .liveperson.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] server.iad.liveperson.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .liveperson.net [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .smartadserver.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] media.easyads.bg [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .content.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] .content.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] ad.yieldmanager.com [ C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ] Adware.Flash Tracking Cookie C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\DS.SERVING-SYS.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\149.MEMECOUNTER.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEMECOUNTER.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\BC.YOUPORN.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\ACVS.MEDIAONENETWORK.NET C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\IA.MEDIA-IMDB.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA.FREEDOMOFTHESEAS.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA.IGN.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA.MTVNSERVICES.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA.NINTENDO.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA.SCANSCOUT.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA1.BREAK.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\MEDIA1.CLUBPENGUIN.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\OBJECTS.TREMORMEDIA.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\VIDEOMEDIA.IGN.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\INTERCLICK.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\ATDMT.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\SPE.ATDMT.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\NAIADSYSTEMS.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\M.UK.2MDN.NET C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\SECURE-IT.IMRWORLDWIDE.COM C:\Documents and Settings\User\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XLHKEHXU\SECURE-US.IMRWORLDWIDE.COM Trojan.Agent/Gen-CDesc[Gen] C:\WINDOWS\YLUMEA.EXE
-
Какво да правя [РЕШЕН]
Добро утро, Аз също се предадох снощи. Приключих с ComboFix със следното отклонение от инструкциите: по време на сканирането рестартира компютъра, при което автоматично си се включи и антивирусната програма. Също рестартира и преди да генерира лог-а, но тогава вече видях, че Avast се е включил и го изключих. Това проблем ли е? Имам и въпрос относно Win32:Delfcrylt, който бе открит от Avast - да трия ли файла от клетката (описал съм го във втория си пост)? Поздрави: Владо Ето и копие: ComboFix 10-07-23.01 - User 07.2010 г. 3:15.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1251.359.1033.18.894.478 [GMT 3:00] Running from: c:\documents and settings\User\Desktop\ff2.exe AV: avast! antivirus 4.8.1368 [VPS 100723-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_SSHNAS ((((((((((((((((((((((((( Files Created from 2010-06-24 to 2010-07-24 ))))))))))))))))))))))))))))))) . 2010-07-23 18:55 . 2010-07-23 18:55 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes 2010-07-23 18:55 . 2010-04-29 09:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-07-23 18:55 . 2010-07-23 18:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-07-23 18:55 . 2010-07-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-07-23 18:55 . 2010-04-29 09:19 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-06-28 20:22 . 2010-06-28 20:22 -------- d-----w- c:\program files\uTorrent 2010-06-27 18:50 . 2010-06-27 19:01 -------- d-----w- c:\program files\Audiograbber . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-23 14:56 . 2007-03-03 17:58 -------- d-----w- c:\documents and settings\User\Application Data\Skype 2010-07-23 13:07 . 2008-03-10 17:58 -------- d-----w- c:\documents and settings\User\Application Data\skypePM 2010-07-18 18:24 . 2007-03-20 13:03 -------- d-----w- c:\documents and settings\User\Application Data\uTorrent 2010-06-28 07:15 . 2010-06-20 16:18 -------- d-----w- c:\program files\MP3 CD Converter Professional 2010-06-23 19:24 . 2010-06-23 19:24 50354 ----a-w- c:\documents and settings\User\Application Data\Facebook\uninstall.exe 2010-06-23 19:24 . 2010-06-23 19:24 -------- d-----w- c:\documents and settings\User\Application Data\Facebook 2010-06-22 06:43 . 2010-06-22 06:35 -------- d-----w- c:\program files\ChrisTV_Add-on 2010-06-22 06:39 . 2010-06-22 06:33 -------- d-----w- c:\program files\ChrisTV Lite 2010-06-22 06:35 . 2010-06-22 06:35 -------- d-----w- c:\program files\Conduit 2010-06-09 15:39 . 2010-05-25 07:36 4136960 ----a-w- c:\documents and settings\User\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe 2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\documents and settings\User\Application Data\Facebook\npfbplugin_1_0_3.dll 2010-05-31 18:13 . 2010-05-31 18:13 189440 ----a-w- c:\windows\Ylumea.exe 2010-05-30 11:20 . 2007-05-17 06:45 -------- d-----w- c:\program files\URUSoft 2010-05-25 07:36 . 2010-05-25 07:36 917504 ----a-w- c:\documents and settings\User\Application Data\PowerChallenge\PowerSoccer\TVE3.dll 2010-05-25 07:36 . 2010-05-25 07:36 253952 ----a-w- c:\documents and settings\User\Application Data\PowerChallenge\PowerSoccer\OpenAL32.dll 2010-05-25 07:36 . 2010-05-25 07:36 889488 ----a-w- c:\documents and settings\User\Application Data\PowerChallenge\PowerSoccer\DFEngine.dll 2010-05-25 07:36 . 2010-05-25 07:36 656088 ----a-w- c:\documents and settings\User\Application Data\PowerChallenge\loader8.dll 2010-05-25 07:36 . 2010-05-25 07:36 -------- d-----w- c:\documents and settings\User\Application Data\PowerChallenge 2010-05-20 06:21 . 2010-04-21 07:02 34192 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-04-19 16:26 . 2010-04-19 16:26 2 --shatr- c:\windows\winstart.bat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-17 39408] "Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-18 136176] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-11 344064] "RTHDCPL"="RTHDCPL.EXE" [2006-06-28 16248320] "AGRSMMSG"="AGRSMMSG.exe" [2006-03-18 89541] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-07 761946] "Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2006-08-01 1773568] "TPSMain"="TPSMain.exe" [2006-02-08 266240] "NDSTray.exe"="NDSTray.exe" [bU] "SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-05-12 118784] "PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-21 1077330] "SkyTel"="SkyTel.EXE" [2006-05-16 2879488] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792] "Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-08 623880] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe" [2009-11-10 417792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-10-14 23:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1] 2004-08-04 12:00 44032 ----a-w- c:\windows\ime\imkr6_1\imekrmig.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1] 2004-08-04 12:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager] 2008-09-08 22:21 623880 ----a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2010-02-15 16:07 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002] 2004-08-04 12:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray] 2008-12-03 10:47 1205760 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A] 2004-08-04 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync] 2004-08-04 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-10 21:08 417792 ----a-w- c:\program files\K-Lite Codec Pack\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] 2006-05-16 17:04 2879488 ----a-w- c:\windows\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView] 2005-05-12 09:31 118784 ----a-w- c:\program files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\dplaysvr.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\ASUS\\WL-530g Router\\Discovery530g.exe"= "c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"= "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "12854:TCP"= 12854:TCP:*:Disabled:BitComet 12854 TCP "12854:UDP"= 12854:UDP:*:Disabled:BitComet 12854 UDP "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [17.9.2008 г. 22:37 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.9.2008 г. 22:37 20560] S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys --> c:\windows\system32\drivers\Partizan.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 г. 13:16 130384] S2 gupdate;Услуга Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18.5.2010 г. 08:52 135664] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 г. 13:16 753504] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.1.2008 г. 20:44 691696] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}] 2009-03-04 13:32 8192 -c--a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 01:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder 2010-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-18 05:51] 2010-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-18 05:51] 2010-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-580227777-1523733259-986476005-1006Core.job - c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-06-29 05:57] 2010-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-580227777-1523733259-986476005-1006UA.job - c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-06-29 05:57] 2010-07-24 c:\windows\Tasks\User_Feed_Synchronization-{B442EB57-6EEF-46CB-98DB-C9D4E66EAB71}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 01:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.bg/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: Convert for CLIE - c:\program files\Sony Handheld\menu.htm IE: Convert for CLIЙ - c:\program files\Sony Handheld\menu.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\k1tjbj45.default\ FF - prefs.js: browser.startup.homepage - www.google.bg FF - prefs.js: network.proxy.type - 2 FF - plugin: c:\docume~1\User\APPLIC~1\POWERC~1\nppowerloader.dll FF - plugin: c:\documents and settings\User\Application Data\Facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\User\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\documents and settings\User\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: c:\progra~1\SONYHA~1\PACKAG~1\NPInstal.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\Java\jre1.5.0_07\bin\NPJPI150_07.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - ORPHANS REMOVED - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKCU-Run-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe MSConfigStartUp-LanguageShortcut - c:\program files\CyberLink\PowerDVD\Language\Language.exe MSConfigStartUp-NeroFilterCheck - c:\windows\system32\NeroCheck.exe MSConfigStartUp-RemoteControl - c:\program files\CyberLink\PowerDVD\PDVDServ.exe MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AddRemove-Medieval Total War (Demo Version) - c:\program files\Total War\Medieval - Total War (Demo Version)\Uninst.isu ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-07-24 03:37 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(564) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(1008) c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\TPwrCfg.DLL c:\windows\system32\TPwrReg.dll c:\windows\system32\TPSTrace.DLL c:\windows\system32\msi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\windows\system32\acs.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe c:\windows\system32\TODDSrv.exe c:\program files\Canon\CAL\CALMAIN.exe c:\windows\system32\Ati2evxx.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\windows\AGRSMMSG.exe c:\program files\TOSHIBA\ConfigFree\NDSTray.exe c:\program files\Microsoft ActiveSync\Wcescomm.exe c:\progra~1\MICROS~3\rapimgr.exe c:\windows\system32\TPSBattM.exe c:\program files\PC Connectivity Solution\ServiceLayer.exe c:\program files\PC Connectivity Solution\Transports\NclIrSrv.exe c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe . ************************************************************************** . Completion time: 2010-07-24 03:45:04 - machine was rebooted ComboFix-quarantined-files.txt 2010-07-24 00:45 Pre-Run: 22 719 438 848 bytes free Post-Run: 23 866 408 960 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - E687E2EAE39758496EC859F94BA85398
-
Какво да правя [РЕШЕН]
Здравейте, ОК, да инсталирам ли SP3 сега? И да пусна ли пак Malware? Прикачени са и DDS файловете По принцип компютъра работи без проблеми, преди ок. 2 месеца Avast откри серия от вируси. Изчистиха го, но оттогава периодично - на 2 седмици намира по нещо. Ето резултата на Security Check: Results of screen317's Security Check version 0.99.4 Windows XP Service Pack 2 Out of date service pack!! Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Security Center service is not running! This report may not be accurate! Windows Firewall Enabled! avast! Antivirus avast! successfully updated! ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Adobe Flash Player 10.0.45.2 Adobe Reader 8.1.3 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Alwil Software Avast4 aswUpdSv.exe Alwil Software Avast4 ashServ.exe Alwil Software Avast4 ashDisp.exe Alwil Software Avast4 ashMaiSv.exe Alwil Software Avast4 ashWebSv.exe ```````````````````````````````` DNS Vulnerability Check: Unknown. This method cannot test your vulnerability to DNS cache poisoning. ``````````End of Log```````````` DDS.txt Attach.txt
-
Какво да правя [РЕШЕН]
Здравейте, Прилагам логовете. Също - докато сканирах с Malware, Avast откри следното: А0112181.exe C;\System Volume Information\_restore{42ED9E7D-FF5B-4E09-9CA6-4A172F8CAACD}\RP940 Win32:Delfcrypt-E[Drp} Преместил съм го в клетка, съгласно предложението на Avast Благодаря за съдействието Поздрави: Владо Не мога да прикача Hijack лог-а, ето го: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:32:18, on 23.7.2010 г. Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\Wcescomm.exe C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\acs.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\TODDSrv.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\V368NSP5\HijackThis[1].exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:/Documents and Settings/User/My Documents/Radiotracker/Temp/RT/WebRip/profile/rrproxy_ie_4a393093.pac R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file) O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe O4 - HKLM\..\Run: [smoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user') O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: Convert for CLIE - C:\Program Files\Sony Handheld\menu.htm O8 - Extra context menu item: Convert for CLIЙ - C:\Program Files\Sony Handheld\menu.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing) O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Услуга Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero 7\Nero BackItUp\NBService.exe O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe -- End of file - 11979 bytes mbam-log-2010-07-23 (23-22-32).txt
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.