Всичко публикувано от neroplayf
-
Имам за съмнения за зловреден софтуер [решен]
Благодаря ти.Значи мога да съм спокойна вече.Найстина благодаря за отделеното време и търпение! Пожелавам ти всичко най-хубаво!!!!
-
Имам за съмнения за зловреден софтуер [решен]
Нормално си е.Притеснява ме дали сега вече някой може да ми влезе в копютъра и дали от направените неща разбрахме имало ли е влизане
-
Имам за съмнения за зловреден софтуер [решен]
Avira AntiVir Personal Report file date: 02 Април 2011 г. 16:09 Scanning for 2555303 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : valya Computer name : COMPUTERS Version information: BUILD.DAT : 10.0.0.635 31822 Bytes 07.3.2011 г. 12:15:00 AVSCAN.EXE : 10.0.3.5 435368 Bytes 04.3.2011 г. 11:36:52 AVSCAN.DLL : 10.0.3.0 46440 Bytes 01.4.2010 г. 09:57:04 LUKE.DLL : 10.0.3.2 104296 Bytes 04.3.2011 г. 11:36:59 LUKERES.DLL : 10.0.0.1 12648 Bytes 10.2.2010 г. 20:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 г. 06:05:36 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 г. 11:37:07 VBASE002.VDF : 7.11.3.0 1950720 Bytes 09.2.2011 г. 11:37:08 VBASE003.VDF : 7.11.3.1 2048 Bytes 09.2.2011 г. 11:37:08 VBASE004.VDF : 7.11.3.2 2048 Bytes 09.2.2011 г. 11:37:08 VBASE005.VDF : 7.11.3.3 2048 Bytes 09.2.2011 г. 11:37:08 VBASE006.VDF : 7.11.3.4 2048 Bytes 09.2.2011 г. 11:37:08 VBASE007.VDF : 7.11.3.5 2048 Bytes 09.2.2011 г. 11:37:08 VBASE008.VDF : 7.11.3.6 2048 Bytes 09.2.2011 г. 11:37:08 VBASE009.VDF : 7.11.3.7 2048 Bytes 09.2.2011 г. 11:37:08 VBASE010.VDF : 7.11.3.8 2048 Bytes 09.2.2011 г. 11:37:08 VBASE011.VDF : 7.11.3.9 2048 Bytes 09.2.2011 г. 11:37:09 VBASE012.VDF : 7.11.3.10 2048 Bytes 09.2.2011 г. 11:37:09 VBASE013.VDF : 7.11.3.59 157184 Bytes 14.2.2011 г. 11:37:09 VBASE014.VDF : 7.11.3.97 120320 Bytes 16.2.2011 г. 11:37:09 VBASE015.VDF : 7.11.3.148 128000 Bytes 19.2.2011 г. 11:37:09 VBASE016.VDF : 7.11.3.183 140288 Bytes 22.2.2011 г. 11:37:09 VBASE017.VDF : 7.11.3.216 124416 Bytes 24.2.2011 г. 15:02:23 VBASE018.VDF : 7.11.3.251 159232 Bytes 28.2.2011 г. 13:08:03 VBASE019.VDF : 7.11.4.33 148992 Bytes 02.3.2011 г. 15:30:49 VBASE020.VDF : 7.11.4.73 150016 Bytes 06.3.2011 г. 13:14:47 VBASE021.VDF : 7.11.4.108 122880 Bytes 08.3.2011 г. 13:07:46 VBASE022.VDF : 7.11.4.150 133120 Bytes 10.3.2011 г. 13:07:47 VBASE023.VDF : 7.11.4.183 122368 Bytes 14.3.2011 г. 13:07:48 VBASE024.VDF : 7.11.4.228 123392 Bytes 16.3.2011 г. 13:07:48 VBASE025.VDF : 7.11.5.8 246272 Bytes 21.3.2011 г. 13:07:49 VBASE026.VDF : 7.11.5.38 137216 Bytes 23.3.2011 г. 13:07:50 VBASE027.VDF : 7.11.5.82 151552 Bytes 27.3.2011 г. 13:07:51 VBASE028.VDF : 7.11.5.122 154112 Bytes 30.3.2011 г. 13:07:51 VBASE029.VDF : 7.11.5.123 2048 Bytes 30.3.2011 г. 13:07:52 VBASE030.VDF : 7.11.5.124 2048 Bytes 30.3.2011 г. 13:07:52 VBASE031.VDF : 7.11.5.168 150528 Bytes 01.4.2011 г. 13:07:52 Engineversion : 8.2.4.192 AEVDF.DLL : 8.1.2.1 106868 Bytes 04.3.2011 г. 11:36:49 AESCRIPT.DLL : 8.1.3.57 1261947 Bytes 02.4.2011 г. 13:08:05 AESCN.DLL : 8.1.7.2 127349 Bytes 04.3.2011 г. 11:36:48 AESBX.DLL : 8.1.3.2 254324 Bytes 04.3.2011 г. 11:36:48 AERDL.DLL : 8.1.9.9 639347 Bytes 02.4.2011 г. 13:08:03 AEPACK.DLL : 8.2.4.13 524662 Bytes 02.4.2011 г. 13:08:02 AEOFFICE.DLL : 8.1.1.18 205178 Bytes 02.4.2011 г. 13:08:01 AEHEUR.DLL : 8.1.2.91 3387767 Bytes 02.4.2011 г. 13:08:00 AEHELP.DLL : 8.1.16.1 246134 Bytes 04.3.2011 г. 11:36:41 AEGEN.DLL : 8.1.5.3 397684 Bytes 02.4.2011 г. 13:07:54 AEEMU.DLL : 8.1.3.0 393589 Bytes 04.3.2011 г. 11:36:40 AECORE.DLL : 8.1.19.2 196983 Bytes 04.3.2011 г. 11:36:40 AEBB.DLL : 8.1.1.0 53618 Bytes 04.3.2011 г. 11:36:39 AVWINLL.DLL : 10.0.0.0 19304 Bytes 04.3.2011 г. 11:36:53 AVPREF.DLL : 10.0.0.0 44904 Bytes 04.3.2011 г. 11:36:52 AVREP.DLL : 10.0.0.8 62209 Bytes 17.6.2010 г. 11:27:13 AVREG.DLL : 10.0.3.2 53096 Bytes 04.3.2011 г. 11:36:52 AVSCPLR.DLL : 10.0.3.2 84328 Bytes 04.3.2011 г. 11:36:53 AVARKT.DLL : 10.0.22.6 231784 Bytes 04.3.2011 г. 11:36:50 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 04.3.2011 г. 11:36:51 SQLITE3.DLL : 3.6.19.0 355688 Bytes 17.6.2010 г. 11:27:22 AVSMTP.DLL : 10.0.0.17 63848 Bytes 04.3.2011 г. 11:36:53 NETNT.DLL : 10.0.0.0 11624 Bytes 17.6.2010 г. 11:27:21 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 04.3.2011 г. 11:37:12 RCTEXT.DLL : 10.0.58.0 97128 Bytes 04.3.2011 г. 11:37:12 Configuration settings for the scan: Jobname.............................: Short system scan after installation Configuration file..................: c:\program files\avira\antivir desktop\setupprf.dat Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Process scan........................: on Scan registry.......................: on Search for rootkits.................: off Integrity checking of system files..: off Scan all files......................: Intelligent file selection Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Start of the scan: 02 Април 2011 г. 16:09 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'notepad.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'avconfig.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'avshadow.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'setup.exe' - '1' Module(s) have been scanned Scan process 'presetup.exe' - '1' Module(s) have been scanned Scan process 'avira_antivir_personal_en.exe' - '1' Module(s) have been scanned Scan process 'jucheck.exe' - '1' Module(s) have been scanned Scan process 'firefox.exe' - '1' Module(s) have been scanned Scan process 'wscntfy.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'NBService.exe' - '1' Module(s) have been scanned Scan process 'jqs.exe' - '1' Module(s) have been scanned Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned Scan process 'Flex2K.exe' - '1' Module(s) have been scanned Scan process 'uTorrent.exe' - '1' Module(s) have been scanned Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned Scan process 'Domino.exe' - '1' Module(s) have been scanned Scan process 'ZSSnp211.exe' - '1' Module(s) have been scanned Scan process 'Disk_Monitor.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned Scan process 'Explorer.EXE' - '1' Module(s) have been scanned Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned Scan process 'CNAB4RPK.EXE' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Start scanning boot sectors: Starting to scan executable files (registry). The registry was scanned ( '429' files ). End of the scan: 02 Април 2011 г. 16:10 Used time: 00:59 Minute(s) The scan has been done completely. 0 Scanned directories 907 Files were scanned 0 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 0 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 907 Files not concerned 3 Archives were scanned 0 Warnings 0 Notes След сканирането
-
Имам за съмнения за зловреден софтуер [решен]
Направих ги по този начин(редактирания) но пак не се променя свободната памет.Преди да натисна ОК ми излиза това : You have chosen to turn off System Restore.If you continue ,all existing restor points will be delete,and you will not be able to track or undo changes to your komputer. Do you want to turn off System Restore? Аз натискам ок,после отивам връщам пак старите настройки....и нищо.
-
Имам за съмнения за зловреден софтуер [решен]
Свободното пространство в С ми е 38.40 GB но и преди това почистване беше толкова,сигурно не съм направила нищо.Тегля тази антивирусна Avira AntiVir Personal и
-
Имам за съмнения за зловреден софтуер [решен]
ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2011/04/02 15:25 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB2E29000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8A60000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB2443000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: C:\System Volume Information\_restore{CEA043A5-BF76-4907-B698-AD642074964F}\RP2\A0000347.old Status: Visible to the Windows API, but not on disk. ==EOF==
-
Имам за съмнения за зловреден софтуер [решен]
Нещо май не се получава.като го копирам и сложа в козолата изписва това: 'c:\K.exe' is not recognized as an internal or external command,operable program ot batch file.
-
Имам за съмнения за зловреден софтуер [решен]
Не,няма.След като направих тази операция се рестартира и не изписа никакво съобщение,само ми изкочи текст документа които ти копирах.
-
Имам за съмнения за зловреден софтуер [решен]
All processes killed ========== OTL ========== Service NMIndexingService stopped successfully! Service NMIndexingService deleted successfully! File File not found not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully! HKU\S-1-5-21-1229272821-1757981266-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "Ask" removed from browser.search.defaultenginename Prefs.js: "Ask" removed from browser.search.order.1 Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "http://www.ask.com/?o=13928&l=dis" removed from browser.startup.homepage Prefs.js: "http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=" removed from keyword.URL Prefs.js: "plimus.com,regnow.com" removed from network.proxy.no_proxies_on Prefs.js: "127.0.0.1" removed from network.proxy.socks Prefs.js: 7070 removed from network.proxy.socks_port C:\Documents and Settings\valya\Application Data\Mozilla\Firefox\Profiles\pia7eil6.default\searchplugins\ask.xml moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{FE063DB9-4EC0-403e-8DD8-394C54984B2C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-1229272821-1757981266-1417001333-1004\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Soltek deleted successfully. C:\WINDOWS\system32\Autorun.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found. Registry value HKEY_USERS\S-1-5-21-1229272821-1757981266-1417001333-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1\\* deleted successfully. Invalid CLSID key: * Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. ========== FILES ========== autorun.inf not found in C:\ autorun.inf not found in D:\ autorun.inf not found in J:\ autorun.exe not found in C:\ autorun.exe not found in D:\ autorun.exe not found in J:\ recycler not found in C:\ D:\RECYCLER\S-1-5-21-73586283-746137067-725345543-1004 folder moved successfully. D:\RECYCLER\S-1-5-21-73586283-746137067-725345543-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-725345543-1220945662-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd92 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd9 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd8 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd7 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Sprite folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Sound folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Pass folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Pal folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Frndata folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Bakdata folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Atr folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61\Act folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd61 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd60 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd6 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd59 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd58\Greatest Hits Vol. 1 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd58\1996 - Life Is Peachy folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd58\1994 - Korn folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd58 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd57.131\St.Anger folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd57.131\96`Load folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd57.131\84` Ride the lighting folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd57.131 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56\nightwish folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56\drygi nqkvi\WishMaster 00\Bonus CD folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56\drygi nqkvi\WishMaster 00 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56\drygi nqkvi\Oceanborn 98 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56\drygi nqkvi\Angels Fall First 97 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56\drygi nqkvi folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd56 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\other folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\HIM - Silver Blade Collection 2001 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\HIM - 1997 Greatest Lovesong Vol.666 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\H.I.M-Dark_Light-2005-XXL folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\Finish versions folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\Deep shadows and Brilliant Highlights folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\Acoustic versions\New Folder folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\Acoustic versions folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\2004 - Solitary Man folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\2003 - Love Metal folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131\1999-Razorblade romance folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd55.131 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd5 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd4 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd3 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd22\Counter Strike 1.6_Wepons folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd22 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd21 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd20 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\Voyageur-2003 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\2001 LSD The Greatest Hits folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\2001 LSD Love Sensuality Devotion The Remix Collection folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\1999 The Screen Behind The Mirror'' folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\1998-Metamorphosis folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\1996 Le Roi Est Mort Vive Le Roi! folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\1994 The Cross Of Changes' folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2\1990 MCMXC a.D folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd2 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd19\Register\register\DLL folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd19\Register\register folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd19\Register folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd19\Manual folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd19\DirectX folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd19 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd18 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd17 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\txd folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\TEXT folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\skins folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\MTA folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\mp3 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\movies folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\Icons folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City\anim folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16\Grand Theft Auto Vice City folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd16 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd15 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd14.1906 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd13 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd12.3 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd11\generic folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd11\coll folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd11 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd10 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003\Dd1 folder moved successfully. D:\RECYCLER\S-1-5-21-484763869-1604221776-839522115-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1229272821-1757981266-1417001333-1004 folder moved successfully. D:\RECYCLER\S-1-5-21-1123561945-261903793-839522115-1003 folder moved successfully. D:\RECYCLER folder moved successfully. J:\RECYCLER\S-1-5-21-1229272821-1757981266-1417001333-1004 folder moved successfully. J:\RECYCLER folder moved successfully. < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Documents and Settings\valya\Desktop\cmd.bat deleted successfully. C:\Documents and Settings\valya\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: valya ->Temp folder emptied: 9974 bytes ->Temporary Internet Files folder emptied: 6688827 bytes ->Java cache emptied: 61632498 bytes ->FireFox cache emptied: 62178077 bytes ->Flash cache emptied: 1964666 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2402044 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 129,00 mb [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: valya ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04022011_143624 Files\Folders moved on Reboot... Registry entries deleted on Reboot...
-
Имам за съмнения за зловреден софтуер [решен]
Здравей.Вече съм на моя компютър.При стартирането му ми изписа Information : This OS is not supported!! If you have any question,please contact us!!. Flex Type пак ми се върна,без да инсталирам нищо. Направих го това. Extras.Txt..txt OTL.Txt..txt
-
Имам за съмнения за зловреден софтуер [решен]
Добро утро За съжаление нямам инсталационен диск на Windows XP.
-
Имам за съмнения за зловреден софтуер [решен]
ComboFix 11-04-01.01 - valya 04.2011 г. 1:24.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.293 [GMT 3:00] Running from: c:\documents and settings\valya\Desktop\ff2.exe.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\AskSearch\bin\DefaultSearch.dll c:\windows\system32\autorun.ini . . ((((((((((((((((((((((((( Files Created from 2011-03-01 to 2011-04-01 ))))))))))))))))))))))))))))))) . . 2011-04-01 21:45 . 2011-04-01 21:45 -------- d-----w- c:\documents and settings\valya\Application Data\Malwarebytes 2011-04-01 21:45 . 2010-12-20 15:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-01 21:45 . 2011-04-01 21:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-04-01 21:45 . 2011-04-01 21:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-04-01 21:45 . 2010-12-20 15:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-03-15 19:56 . 2011-03-15 19:56 -------- d-----w- c:\documents and settings\valya\Application Data\Magic Academy 2 2011-03-15 17:16 . 2011-03-15 17:16 -------- d-sh--w- c:\documents and settings\valya\IECompatCache 2011-03-15 17:15 . 2011-03-15 17:15 -------- d-sh--w- c:\documents and settings\valya\PrivacIE 2011-03-15 17:14 . 2011-03-15 17:14 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2011-03-15 17:14 . 2011-03-15 17:14 -------- d-sh--w- c:\documents and settings\valya\IETldCache 2011-03-15 17:10 . 2011-03-15 17:11 -------- dc-h--w- c:\windows\ie8 2011-03-13 18:44 . 2011-03-13 19:23 -------- d-----w- c:\documents and settings\valya\Application Data\Magic3 2011-03-13 18:44 . 2011-03-13 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\AlawarWrapper 2011-03-13 18:42 . 2011-03-15 18:41 -------- d-----w- c:\program files\Magic Encyclopedia 3 Illusions 2011-03-06 19:55 . 2011-03-06 19:55 -------- d-----w- c:\program files\Skypr . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-01-29 12:13 . 2011-01-29 12:13 40960 ----a-r- c:\documents and settings\valya\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut3_8527C3D5BA1D46E988D2AF25544311A3.exe 2011-01-29 12:13 . 2011-01-29 12:13 40960 ----a-r- c:\documents and settings\valya\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2005-09-03 94208] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-11-05 328056] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Soltek"="c:\windows\system32\autorun.exe" [2001-10-29 61440] "SoundMan"="SOUNDMAN.EXE" [2003-12-19 65024] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-03 335872] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-13 149280] "Disk Monitor"="c:\program files\IC\Card Reader Driver v1.9e2\Disk_Monitor.exe" [2003-06-18 466944] "ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344] "Domino"="c:\windows\Domino.exe" [2006-08-18 49152] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_3"="advpack.dll" [2009-03-08 128512] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2009-5-17 151552] . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\FlashGet\\flashget.exe"= "c:\\WINDOWS\\system32\\CNAB4RPK.EXE"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [5/24/2008 9:26 PM 16640] R3 slnt;RTL8139D PCI Fast Ethernet Adapter;c:\windows\system32\drivers\slnt.sys [6/20/2010 1:07 PM 18004] S3 CAM1690;USB PC Camera ;c:\windows\system32\drivers\cam1690.sys [9/20/2007 7:03 PM 177280] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2/1/2010 12:45 AM 36608] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [10/23/2010 10:54 PM 98432] S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [10/23/2010 10:54 PM 14848] S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [10/23/2010 10:54 PM 123648] S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2/21/2011 12:58 AM 480128] S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2/21/2011 12:58 AM 1472000] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/1/2009 11:10 PM 721904] . Contents of the 'Scheduled Tasks' folder . 2011-04-01 c:\windows\Tasks\User_Feed_Synchronization-{50E8D91E-AC6D-4915-ADD5-85174F9CD8AF}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 02:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://adventurersbg.info uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm FF - ProfilePath - c:\documents and settings\valya\Application Data\Mozilla\Firefox\Profiles\pia7eil6.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=13928&l=dis FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: DAEMON Tools Toolbar: [email protected] - %profile%\extensions\[email protected] FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff . - - - - ORPHANS REMOVED - - - - . HKCU-Run-12Voip - c:\program files\12Voip.com\12Voip\12Voip.exe HKCU-Run-AutoStartNPSAgent - c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe HKCU-Run-LowRateVoip - c:\program files\LowRateVoip.com\LowRateVoip\LowRateVoip.exe HKCU-Run-AutoStart PC Studio - c:\program files\Samsung\Samsung New PC Studio\NewPCStudio.exe HKCU-Run-VoipBuster - c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe HKLM-Run-NPSStartup - (no file) HKLM-Run-Waiting1690 - c:\windows\stid1690.exe Notify-WgaLogon - (no file) AddRemove-GTASA_is1 - c:\games\GTASA\unins000.exe AddRemove-Magic Encyclopedia 3 Illusions1.0 - c:\program files\Magic Encyclopedia 3 Illusions\uninstall.exe AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-04-02 01:29 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(796) c:\windows\system32\Ati2evxx.dll . Completion time: 2011-04-02 01:31:16 ComboFix-quarantined-files.txt 2011-04-01 22:30 . Pre-Run: 32 494 071 808 bytes free Post-Run: 41 189 449 728 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - D214B20DB225841080538E5C1DE3123A Da,po dobre utre da produlji.Izvinqvam se che ne pisha na bulgarski no mi se iztri flextype sled tazi operaciq.Do utre
-
Имам за съмнения за зловреден софтуер [решен]
Каква промяна да има? Имам нещо червено долу windows security alerts Направих ново сканиране с тази програма Malwarebytes' Anti-Malware този път нищо не намери. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6241 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 02.4.2011 г. 01:10:30 mbam-log-2011-04-02 (01-10-30).txt Scan type: Quick scan Objects scanned: 143482 Time elapsed: 3 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
-
Имам за съмнения за зловреден софтуер [решен]
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6241 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 02.4.2011 г. 00:52:03 mbam-log-2011-04-02 (00-52-03).txt Scan type: Quick scan Objects scanned: 143501 Time elapsed: 4 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Value: ForceClassicControlPanel -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\valya\local settings\Temp\utt685.tmp.exe (Trojan.Pakes) -> Quarantined and deleted successfully.
-
Имам за съмнения за зловреден софтуер [решен]
Ще я махна,но ако ми кажеш как.Може би ти изглеждам много тъпа,но не разбирам нищо.Извинявай.Ако това премахване означава да я деинсталирам,ок,ще го направя. Готово,деинсталирах и двете неща.
-
Имам за съмнения за зловреден софтуер [решен]
Помагай(преполагам нямате нищо против да ви говоря на ти).Не разбирам нищо.Имам нод 32 само това знам,одеве го сканирах няма вируси
-
Имам за съмнения за зловреден софтуер [решен]
DDS: DDS (Ver_11-03-05.01) - NTFSx86 Run by valya at 0:11:34,84 on 02.04.2011 Ј. Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.47 [GMT 3:00] . AV: ESET NOD32 antivirus system 2.70 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\CNAB4RPK.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\IC\Card Reader Driver v1.9e2\Disk_Monitor.exe C:\WINDOWS\ZSSnp211.exe C:\WINDOWS\Domino.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\uTorrent\uTorrent.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\Datecs\Flex2K.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Documents and Settings\valya\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://adventurersbg.info uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll mWinlogon: SfcDisable=-99 (0xffffff9d) BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll BHO: Ask Toolbar BHO: {fe063db1-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\1.bin\ASKTBAR.DLL TB: Ask Toolbar: {fe063db9-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\1.bin\ASKTBAR.DLL TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll uRun: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" uRun: [12Voip] "c:\program files\12voip.com\12voip\12Voip.exe" -nosplash -minimized uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount uRun: [LowRateVoip] "c:\program files\lowratevoip.com\lowratevoip\LowRateVoip.exe" -nosplash -minimized uRun: [AutoStart PC Studio] c:\program files\samsung\samsung new pc studio\NewPCStudio.exe uRun: [VoipBuster] "c:\program files\voipbuster.com\voipbuster\VoipBuster.exe" -nosplash -minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [soltek] c:\windows\system32\autorun.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [NPSStartup] mRun: [Disk Monitor] c:\program files\ic\card reader driver v1.9e2\Disk_Monitor.exe mRun: [updateReminder] c:\program files\eset\UpdateReminder.exe mRun: [Waiting1690] c:\windows\stid1690.exe mRun: [ZSSnp211] c:\windows\ZSSnp211.exe mRun: [Domino] c:\windows\Domino.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\flexty~1.lnk - c:\windows\datecs\Flex2K.exe uPolicies-explorer: ForceClassicControlPanel = 1 (0x1) dPolicies-explorer: ForceClassicControlPanel = 1 (0x1) IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSP: c:\windows\system32\imon.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\valya\applic~1\mozilla\firefox\profiles\pia7eil6.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=13928&l=dis FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q= FF - component: c:\documents and settings\valya\application data\mozilla\firefox\profiles\pia7eil6.default\extensions\[email protected]\components\DTToolbarFF.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: DAEMON Tools Toolbar: [email protected] - %profile%\extensions\[email protected] FF - Ext: Java Quick Starter: [email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff . ============= SERVICES / DRIVERS =============== . R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [2008-5-24 16640] R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-5-17 15424] R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2009-5-17 549256] R3 slnt;RTL8139D PCI Fast Ethernet Adapter;c:\windows\system32\drivers\slnt.sys [2010-6-20 18004] S2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968] S3 CAM1690;USB PC Camera ;c:\windows\system32\drivers\cam1690.sys [2007-9-20 177280] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-2-1 36608] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-10-23 98432] S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-10-23 14848] S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-10-23 123648] S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2011-2-21 480128] S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2011-2-21 1472000] . =============== Created Last 30 ================ . 2011-03-15 19:56:10 -------- d-----w- c:\docume~1\valya\applic~1\Magic Academy 2 2011-03-15 17:16:23 -------- d-sh--w- c:\documents and settings\valya\IECompatCache 2011-03-15 17:15:53 -------- d-sh--w- c:\documents and settings\valya\PrivacIE 2011-03-15 17:14:31 -------- d-sh--w- c:\documents and settings\valya\IETldCache 2011-03-15 17:10:24 -------- dc-h--w- c:\windows\ie8 2011-03-13 18:44:20 -------- d-----w- c:\docume~1\valya\applic~1\Magic3 2011-03-13 18:44:16 -------- d-----w- c:\docume~1\alluse~1\applic~1\AlawarWrapper 2011-03-13 18:42:41 -------- d-----w- c:\program files\Magic Encyclopedia 3 Illusions 2011-03-06 19:55:12 -------- d-----w- c:\program files\Skypr . ==================== Find3M ==================== . . ============= FINISH: 0:12:00,12 =============== ATTACH: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/17/2009 11:40:30 AM System Uptime: 4/1/2011 6:40:26 PM (6 hours ago) . Motherboard: | | nVidia-nForce2 Processor: AMD Sempron 3000+ | Socket A | 2004/166mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 49 GiB total, 30.284 GiB free. D: is FIXED (NTFS) - 79 GiB total, 45.665 GiB free. E: is CDROM () J: is FIXED (NTFS) - 25 GiB total, 10.849 GiB free. K: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: Description: Multimedia Controller Device ID: PCI\VEN_1131&DEV_7133&SUBSYS_00001131&REV_D0\4&3B1D9AB8&0&2840 Manufacturer: Name: Multimedia Controller PNP Device ID: PCI\VEN_1131&DEV_7133&SUBSYS_00001131&REV_D0\4&3B1D9AB8&0&2840 Service: . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . Архиватор WinRAR µTorrent 1.1 Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Default Language CS3 Adobe Device Central CS3 Adobe ExtendScript Toolkit 2 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Fonts All Adobe Help Viewer CS3 Adobe Linguistics CS3 Adobe PDF Library Files Adobe Photoshop CS3 Adobe Reader 8.1.3 Adobe Setup Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 Advertising Center Ask Toolbar ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver AV Voice Changer Software DIAMOND 6.0 Canon LBP2900 DAEMON Tools Toolbar Dark Tales - Edgar Allan Poes Murders in the Rue Morgue 1.00 Dream Chronicles 4 Book of Air CE 1.00 DVD Decrypter (Remove Only) EVEREST Corporate Edition v5.50 Favorite-Games 5.17 FlashGet 1.8.6.1008 FlexType 2K Heavyweight Thunder Hotfix for Windows Media Player 11 (KB944110) Hotfix for Windows Media Player 11 (KB944882) Hotfix for Windows Media Player 11 (KB946665) IC Card Reader Driver v1.9e2 ImagXpress Java 6 Update 17 K-Lite Codec Pack 4.1.7 (Full) Magic Academy 2 1.00 Magic Encyclopedia 3 Illusions Managed DirectX (0900) Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.5 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mortimer Beckett and the Secrets of Spooky Manor 1.01 Mozilla Firefox (3.0.19) MSN Nero 7 Premium Nero CoverDesigner Nero PhotoSnap Nero Recode Nero ShowTime Nero StartSmart Nero Vision NeroBurningROM NeroExpress neroxml NOD32 antivirus system NOD32 FiX v1.7 NVIDIA Drivers NVIDIA Gart Driver NVIDIA Windows 2000/XP nForce Drivers PC Connectivity Solution PDF Settings Realtek AC'97 Audio SAMSUNG CDMA Modem Driver Set SAMSUNG Mobile Composite Device Software Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio 3 USB Driver Installer SAMSUNG SYMBIAN USB Download Driver SAMSUNG USB Driver for Mobile Phones SamsungConnectivityCableDriver Security Update for Windows XP (KB941569) Skype Toolbars SkypeLauncher Skype™ 3.8 Skypr 1.1 SoundTrax The KMPlayer 2.9.4.1434 The Nightshift Code 1.00 Timed Shutdown 0.5b USB PC Camera Veronica Rivers - Portals to the Unknown 1.00 WebFldrs XP Winamp (remove only) Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) Windows Internet Explorer 8 XML Paper Specification Shared Components Pack 1.0 ZSMC USB PC Camera (ZS0211) . ==== Event Viewer Messages From Past Week ======== . 3/31/2011 6:13:26 PM, information: Windows File Protection [64032] - Windows File Protection is not active on this system. . ==== End Of File =========================== Надавам се да е това
-
Имам за съмнения за зловреден софтуер [решен]
Здравейте.Имам съмнение,че някой ми е влизал в компютъра.Искам да се предпазя и ако може да се разбере по някакъв начин дали найстина някой е влизал,защото може и да блъфира човека.Благодаря ви предварително!
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.