-
Анализ на лог от OTL - Win32.Chydo
мерси мн братле,за пореден пат ми помогна. :lighter: :lighter: :lighter: :)
-
Анализ на лог от OTL - Win32.Chydo
здравей братле имам един много голям проблем наскоро преди вие да ми помогнете бях си преинсталирал компа но проблема от там запо4на драивера за видео диска ми е надраскан и не6те да го инсталира затоваа намерих в нета един дривер за картина и го сложих от там запо4на проблема сега ми излиза това като пусна компа: Microsoft .NET Framework 2.0 is required to run ATI Catalist Control Center. Please download and install the software from Microsoft's website. моля те помогни ми,какво да правя. много 6те сам ти презнат. :) :wors:
-
Анализ на лог от OTL - Win32.Chydo
заповядай братле Results of screen317's Security Check version 0.99.7 Windows XP Service Pack 3 (UAC is disabled!) Internet Explorer 7 Out of date! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! ESET Online Scanner v3 WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Adobe Flash Player 10.2.152.32 Mozilla Firefox (3.6.15) ```````````````````````````````` Process Check: objlist.exe by Laurent ``````````End of Log```````````` братле компа 6то стана толкова барз.като цакна един пат примерно в Д и ми отваря о6те една папка. :eek: :eek: log.txt
-
Анализ на лог от OTL - Win32.Chydo
братле правя вси4ко което ми казва6 но ми забива компа и до там 6то така се полу4ава.
-
Анализ на лог от OTL - Win32.Chydo
братле заповядай ! A0003149.bat;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003151.bat;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003152.bat;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003154.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003155.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003156.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003157.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003158.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003159.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003160.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003161.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003162.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003163.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003164.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003165.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003166.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003167.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003169.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003170.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003171.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003172.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003173.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Kypes.2;Deleted.; A0003174.exe;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003175.bat;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003177.bat;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003178.bat;C:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003183.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003184.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003185.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003186.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003187.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003188.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003189.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003190.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003191.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003192.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003193.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003194.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003195.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003196.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003197.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003198.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003199.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003200.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003201.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003202.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003203.bat;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Packed.654;Deleted.; A0003204.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Polipos;Cured.; A0003206.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003206.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.DownLoad2.16307;Incurable.Moved.; A0003208.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003209.dll;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Trojan.Click1.9767;Incurable.Moved.; A0003210.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003211.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003213.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003214.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003215.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003216.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003217.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003218.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003219.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003220.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003221.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003223.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003224.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003225.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003226.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003227.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003228.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003229.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003230.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003231.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003233.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003234.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003235.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003236.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003237.EXE;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003238.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003240.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003241.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003242.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003243.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003244.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003245.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003246.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; A0003247.exe;D:\System Volume Information\_restore{60D3FC6D-34A1-41B7-BBEE-A1EDDE9C77A5}\RP1;Win32.Sector.28480;Cured.; мерси братле
-
Анализ на лог от OTL - Win32.Chydo
братле никаде не пи6е тегли http://www.kaldata.com/forums/public/style_emoticons/<#EMO_DIR#>/sad.gif
-
Анализ на лог от OTL - Win32.Chydo
братле ако преинстална Д 6те се премахнат виросите,но пак за сметка на тожа вси4ко отива по дяволите,вси4ките ми фаилове.мерси мн братле 4е ми помага6 на дали друг хте постапи като теб,мерси много братле,ето следва6тите текст фаилове. Attach.txt DDS.txt
-
Анализ на лог от OTL - Win32.Chydo
заповядаи братле:незнам как да ти се облагодаря. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6425 # api_version=3.0.2 # EOSSerial=1ced3449de04694da3845b7c092e1f3a # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-03-11 11:46:46 # local_time=2011-03-11 01:46:46 (+0200, FLE Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=8192 67108863 100 0 3774 3774 0 0 # scanned=75364 # found=69 # cleaned=69 # scan_time=3379 D:\bioeozhpzh.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\bitapxaoui.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\jzmyoxlboyouc.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\mdmalwfwlqru.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\mfqgtgrkbilqop.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\nbmwkrdrcky.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\nepcisiuhnyu.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\ngtiqcuixfsqbi.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\pqgkwfgr.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\rwaowflr.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\rwqyobgvlfie.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\scocrxockznbi.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\tckcoblvhrbn.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\tcpypzeucsfk.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\tetexjqiskzgpo.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\ujqclubqdg.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\vkteiqeozd.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\weoanrgsylx.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\wiwmdleuevlbkko.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\zcuaozcpdv.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\zlucotdpy.bat a variant of Win32/AutoRun.Agent.UA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\cs16patch_full_V21.exe Win32/Polip virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Alien h4x\Alien h4x.dll a variant of Win32/GameHack.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Alien h4x\Alien h4x.exe probably a variant of Win32/DllInject.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Evil h00k\Evil h00k\Evil h00k\Evil h00k.dll a variant of Win32/GameHack.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Evil h00k\Evil h00k\Evil h00k\Evil h00k.exe probably a variant of Win32/DllInject.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Loadin\faller\SS Wall v3.7.dll Win32/HackTool.SuperSimpleWall application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Loadin\faller\SS Wall v3.7.exe probably a variant of Win32/DllInject.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\Loadin\Loadin\Loadin.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\MOTOTRAX\MTX.Mototrax.part1.rar probably a variant of Win32/Spy.Agent.KFGNNWH trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\VeLoCiTy\VeLoCiTy\VeLoCiTy.dll a variant of Win32/GameHack.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\G A M E S F O R C S 1 . 6\cs 1.6 ful + pa4 21 + botove+ hakove\VeLoCiTy\VeLoCiTy\VeLoCiTy.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Counter-Strike LH 2011\hl.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Counter-Strike LH 2011\hlds.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Counter-Strike LH 2011\hltv.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Counter-Strike LH 2011\ucp.exe a variant of Win32/Packed.PECrypt32.B application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\IGRI\Diablo II Full\Diablo II\BNUpdate.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Diablo II Full\Diablo II\D2VidTst.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Diablo II Full\Diablo II\Diablo II.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Need For Speed Most Wanted\speed.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\Test.Drive.Unlimited.PROPER-ViTALiTY\TestDriveUnlimited.exe probably a variant of Win32/Genetik trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\IGRI\Test.Drive.Unlimited.PROPER-ViTALiTY\vty-tdu.iso probably a variant of Win32/Genetik trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\CL07.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\eauninstall.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\UEFA_CL0607.iso probably a variant of Win32/Agent.EVJVYU trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\Support\EasyInfo.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\Support\EReg.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\Support\UEFA Champions League 2006-2007_code.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\IGRI\UEFA Champions League 2006-2007-Razor19111\Support\UEFA Champions League 2006-2007_uninst.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\SkypeLauncher.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Atomic Alarm Clock v5.9\Crack\AtomicAlarmClock.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\CD HacK by DUmBO\CD HacK by DUmBO.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Cowon JetAudio\Setup Pro 8.0.exe Win32/VB.OTU trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Cracks & Cheats\Cheath-book\Cheath Book.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Cracks & Cheats\Cheath-book\Uninstal.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Cracks & Cheats\Cheats book\chtb0904.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Cracks & Cheats\Cheats book\Uninstal.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\FLEX TYPE\PZ_FT2K.EXE Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\HACK\cdhack.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\jedai hack 2\Jedai Hack 2.dll a variant of Win32/GameHack.Q application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\jedai hack 2\Jedai Hack 2.exe probably a variant of Win32/DllInject.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\jedai hack 2\Нов WinRAR архив.rar multiple threats (deleted - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\NFSMW\speed.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\SkypeLauncher 1.4\SkypeLauncher.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\SkypeLauncher 1.4\SkypeLauncher_Config.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Useful programs pack\Nero Lite\Keygen.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Useful programs pack\Reg-Supreme\RegSupremePro.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Useful programs pack\Ultra-ISO\Patch.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C D:\NE PIPAI\Useful programs pack\Win-Rar\Crack.exe Win32/Sality.NAJ virus (cleaned - quarantined) 00000000000000000000000000000000 C
-
Анализ на лог от OTL - Win32.Chydo
ето братле: Reg export of SafeBoot key after repair: ======================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot] "AlternateShell"="cmd.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SharedAccess] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] @="Net" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] @="NetClient" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] @="NetService" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] @="NetTrans" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" ========================
-
Анализ на лог от OTL - Win32.Chydo
мерси много братле ве4е няма да се затруднявам с кирилаца. вси4ко направих както ми каза ето резултата,извеняваи за правописа. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6009 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 3/10/2011 2:34:03 PM mbam-log-2011-03-10 (14-34-03).txt Scan type: Quick scan Objects scanned: 139730 Time elapsed: 1 minute(s), 53 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) братле това ли е вси4ко,има ли о6те,много сам ти благодарен,искам да бе6е от моя град за да те по4ерпя. мерси братле отново.
-
Анализ на лог от OTL - Win32.Chydo
Izvenqvai bratle che pisha na latinica imam problem s kirilicata: mn mi pomogna nz kak da ti se oblagodarq. Bratle zashtitnata stena na windows se varna veche nqmam problemi no tvoi kolega ili priqtel mi kaza che ima ohte mn rabota,zatova zapovqdai OTL text All processes killed ========== OTL ========== Process wantx.exe killed successfully! No active process named tigxmvqdsjxntaad.exe was found! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\aqphxhdrhzofmuvzm deleted successfully. File move failed. C:\Documents and Settings\kobra\Local Settings\Temp\hacxqdctmhztdoszpjce.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-21-1085031214-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\DriverScanner deleted successfully. Registry value HKEY_USERS\S-1-5-21-1085031214-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\lyujwdwhujvjns deleted successfully. File move failed. C:\WINDOWS\system32\jaatkvshyrhzhqsxld.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-21-1085031214-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\oyrdnrhpzlu deleted successfully. C:\Documents and Settings\kobra\Local Settings\Temp\hacxqdctmhztdoszpjce.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\lwqdotkterbn deleted successfully. C:\WINDOWS\system32\hacxqdctmhztdoszpjce.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\tigxmvqdsjxntaad deleted successfully. C:\Documents and Settings\kobra\Local Settings\Temp\wqtpjxxpjfyteqvdupjmi.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-1085031214-1409082233-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\lwqdotkterbn deleted successfully. C:\Documents and Settings\kobra\Local Settings\Temp\jaatkvshyrhzhqsxld.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\kwrfrxpzlzkxa deleted successfully. C:\WINDOWS\System32\jaatkvshyrhzhqsxld.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\tcuforgnwh deleted successfully. C:\Documents and Settings\kobra\Local Settings\Temp\umnhzljzrlcveorxmfx.exe moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10656f3b-4a29-11e0-be4e-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10656f3b-4a29-11e0-be4e-806d6172696f}\ not found. D:\aizjrthnv.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10656f3b-4a29-11e0-be4e-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10656f3b-4a29-11e0-be4e-806d6172696f}\ not found. D:\kwrfrxpzlzkxa.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10656f3b-4a29-11e0-be4e-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10656f3b-4a29-11e0-be4e-806d6172696f}\ not found. D:\oyrdnrhpzlu.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10656f3d-4a29-11e0-be4e-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10656f3d-4a29-11e0-be4e-806d6172696f}\ not found. C:\aizjrthnv.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10656f3d-4a29-11e0-be4e-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10656f3d-4a29-11e0-be4e-806d6172696f}\ not found. C:\kwrfrxpzlzkxa.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10656f3d-4a29-11e0-be4e-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10656f3d-4a29-11e0-be4e-806d6172696f}\ not found. C:\oyrdnrhpzlu.bat moved successfully. C:\WINDOWS\System32\3076 folder moved successfully. C:\WINDOWS\System32\2052 folder moved successfully. C:\WINDOWS\System32\1054 folder moved successfully. C:\WINDOWS\System32\1042 folder moved successfully. C:\WINDOWS\System32\1041 folder moved successfully. C:\WINDOWS\System32\1037 folder moved successfully. Folder move failed. C:\WINDOWS\System32\1033 scheduled to be moved on reboot. C:\WINDOWS\System32\1031 folder moved successfully. C:\WINDOWS\System32\1028 folder moved successfully. C:\WINDOWS\System32\1025 folder moved successfully. C:\WINDOWS\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve moved successfully. C:\WINDOWS\system32\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve moved successfully. C:\Program Files\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve moved successfully. C:\Documents and Settings\kobra\Local Settings\Application Data\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve moved successfully. C:\WINDOWS\xwefexczyzxxneobxxwefe.czy moved successfully. C:\WINDOWS\system32\xwefexczyzxxneobxxwefe.czy moved successfully. C:\Program Files\xwefexczyzxxneobxxwefe.czy moved successfully. C:\Documents and Settings\kobra\Local Settings\Application Data\xwefexczyzxxneobxxwefe.czy moved successfully. C:\WINDOWS\wqtpjxxpjfyteqvdupjmi.exe moved successfully. C:\WINDOWS\umnhzljzrlcveorxmfx.exe moved successfully. C:\WINDOWS\nimjetunifzvhuajbxswto.exe moved successfully. C:\WINDOWS\hacxqdctmhztdoszpjce.exe moved successfully. C:\WINDOWS\tigxmvqdsjxntaad.exe moved successfully. C:\WINDOWS\jaatkvshyrhzhqsxld.exe moved successfully. C:\WINDOWS\aqphxhdrhzofmuvzm.exe moved successfully. C:\WINDOWS\system32\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr moved successfully. C:\WINDOWS\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr moved successfully. C:\Program Files\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr moved successfully. C:\Documents and Settings\kobra\Local Settings\Application Data\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr moved successfully. File move failed. C:\Documents and Settings\kobra\NTUSER.DAT scheduled to be moved on reboot. File C:\oyrdnrhpzlu.bat not found. File C:\kwrfrxpzlzkxa.bat not found. C:\autorun.inf moved successfully. C:\WINDOWS\system32\nimjetunifzvhuajbxswto.exe moved successfully. File C:\WINDOWS\System32\hacxqdctmhztdoszpjce.exe not found. C:\WINDOWS\system32\umnhzljzrlcveorxmfx.exe moved successfully. C:\WINDOWS\system32\tigxmvqdsjxntaad.exe moved successfully. File C:\WINDOWS\System32\jaatkvshyrhzhqsxld.exe not found. C:\WINDOWS\system32\aqphxhdrhzofmuvzm.exe moved successfully. C:\WINDOWS\system32\wqtpjxxpjfyteqvdupjmi.exe moved successfully. C:\WINDOWS\system32\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel moved successfully. C:\WINDOWS\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel moved successfully. C:\Program Files\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel moved successfully. C:\Documents and Settings\kobra\Local Settings\Application Data\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel moved successfully. C:\WINDOWS\system32\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib moved successfully. C:\WINDOWS\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib moved successfully. C:\Program Files\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib moved successfully. C:\Documents and Settings\kobra\Local Settings\Application Data\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib moved successfully. File C:\WINDOWS\System32\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr not found. File C:\WINDOWS\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr not found. File C:\Program Files\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr not found. File C:\Documents and Settings\kobra\Local Settings\Application Data\kwrfrxpzlzkxaebbkxjesekcmymxknrooxk.rfr not found. File C:\WINDOWS\System32\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel not found. File C:\WINDOWS\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel not found. File C:\Program Files\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel not found. File C:\Documents and Settings\kobra\Local Settings\Application Data\lyujwdwhujvjnsqrbpcynahalynznrwuvftg.rel not found. File C:\WINDOWS\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve not found. File C:\WINDOWS\System32\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve not found. File C:\Program Files\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve not found. File C:\Documents and Settings\kobra\Local Settings\Application Data\tcuforgnwhpzzaurxhqitcfubkvdnnoi.lve not found. File C:\WINDOWS\System32\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib not found. File C:\WINDOWS\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib not found. File C:\Program Files\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib not found. File C:\Documents and Settings\kobra\Local Settings\Application Data\oyrdnrhpzlufgidbitdwiswmueqzklnig.yib not found. File C:\WINDOWS\xwefexczyzxxneobxxwefe.czy not found. File C:\WINDOWS\System32\xwefexczyzxxneobxxwefe.czy not found. File C:\Program Files\xwefexczyzxxneobxxwefe.czy not found. File C:\Documents and Settings\kobra\Local Settings\Application Data\xwefexczyzxxneobxxwefe.czy not found. File C:\WINDOWS\wqtpjxxpjfyteqvdupjmi.exe not found. File C:\WINDOWS\System32\wqtpjxxpjfyteqvdupjmi.exe not found. File C:\WINDOWS\umnhzljzrlcveorxmfx.exe not found. File C:\WINDOWS\System32\umnhzljzrlcveorxmfx.exe not found. File C:\WINDOWS\tigxmvqdsjxntaad.exe not found. File C:\WINDOWS\System32\tigxmvqdsjxntaad.exe not found. File C:\WINDOWS\System32\nimjetunifzvhuajbxswto.exe not found. File C:\WINDOWS\nimjetunifzvhuajbxswto.exe not found. File C:\WINDOWS\System32\jaatkvshyrhzhqsxld.exe not found. File C:\WINDOWS\jaatkvshyrhzhqsxld.exe not found. File C:\WINDOWS\System32\hacxqdctmhztdoszpjce.exe not found. File C:\WINDOWS\hacxqdctmhztdoszpjce.exe not found. File C:\WINDOWS\System32\aqphxhdrhzofmuvzm.exe not found. File C:\WINDOWS\aqphxhdrhzofmuvzm.exe not found. ========== FILES ========== C:\Documents and Settings\kobra\Local Settings\Temp\wantx.exe moved successfully. C:\Documents and Settings\kobra\Local Settings\Temp\tigxmvqdsjxntaad.exe moved successfully. autorun.inf not found in C:\ D:\autorun.inf moved successfully. autorun.exe not found in C:\ autorun.exe not found in D:\ C:\RECYCLER\S-1-5-21-1085031214-1409082233-1801674531-1003 folder moved successfully. C:\RECYCLER folder moved successfully. D:\RECYCLER\S-1-5-21-839522115-57989841-2146896963-500 folder moved successfully. D:\RECYCLER\S-1-5-21-823518204-1563985344-682003330-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-776561741-602162358-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-776561741-1229272821-725345543-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-606747145-796845957-725345543-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-515967899-162531612-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-329068152-1454471165-682003330-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-299502267-1958367476-839522115-500 folder moved successfully. D:\RECYCLER\S-1-5-21-220523388-299502267-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-2052111302-1364589140-682003330-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-2052111302-1220945662-1417001333-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-2025429265-2052111302-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1960408961-764733703-725345543-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1960408961-515967899-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1935655697-1563985344-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1715567821-329068152-725345543-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1715567821-179605362-839522115-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1715567821-1390067357-725345543-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1715567821-117609710-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1708537768-1659004503-839522115-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1645522239-1647877149-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1606980848-839522115-2142218280-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1547161642-329068152-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1547161642-1682526488-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1417001333-573735546-839522115-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1409082233-606747145-1417001333-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1229272821-1202660629-725345543-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1220945662-1965331169-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1202660629-1482476501-682003330-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1202660629-113007714-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-117609710-1770027372-725345543-500 folder moved successfully. D:\RECYCLER\S-1-5-21-1085031214-776561741-1417001333-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1085031214-1409082233-1801674531-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1004336348-1788223648-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1004336348-1604221776-725345543-500 folder moved successfully. D:\RECYCLER folder moved successfully. < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Documents and Settings\kobra\My Documents\Downloads\cmd.bat deleted successfully. C:\Documents and Settings\kobra\My Documents\Downloads\cmd.txt deleted successfully. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\kobra\Local Settings\Temp\wantx.exe deleted successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Restore points cleared and new OTL Restore Point set! [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: kobra ->Temp folder emptied: 11196969 bytes ->Temporary Internet Files folder emptied: 736467 bytes ->FireFox cache emptied: 101464517 bytes ->Flash cache emptied: 1254 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 108.00 mb [EMPTYFLASH] User: All Users User: Default User User: kobra ->Flash cache emptied: 0 bytes User: LocalService User: NetworkService Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 03092011_182644 Files\Folders moved on Reboot... File\Folder C:\Documents and Settings\kobra\Local Settings\Temp\hacxqdctmhztdoszpjce.exe not found! File\Folder C:\WINDOWS\system32\jaatkvshyrhzhqsxld.exe not found! Folder move failed. C:\WINDOWS\System32\1033 scheduled to be moved on reboot. File move failed. C:\Documents and Settings\kobra\NTUSER.DAT scheduled to be moved on reboot. Registry entries deleted on Reboot... Izvenqvam se bratle iskreno za latinicata Ako imash vreme moje li da mi odgovorish na skype. Blagodarq mn.
-
Анализ на лог от OTL - Win32.Chydo
Molqte priqtel imam sashtiq problem no nishto ne se poluchava pomogni mi hte sam ti preznat mn bratle. molqte kato na brat pomogni mi nameri me na skype kobra11_sl predvaritelno blagodarq. OTL.Txt Extras.Txt
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.