Премини към съдържанието

Филтри за търсене

Показани резултати за тагове 'Решен'.

  • Търсене по таг

    Въведете тагове разделени със запетая
  • Търсене по автор

Търсене в


Форуми

  • Софтуер
    • Нови Програми
    • Търсене на Програми
    • Програми - Проблеми и Дискусии
    • Драйвери - Търсене, Проблеми, Линкове
    • Операционни системи
    • Сигурност и антивирусна защита
    • Игри
  • Хардуер
    • Общи хардуерни въпроси
    • Преносими компютри
    • Дънни платки
    • Запаметяващи устройства и памети
    • Монитори, Аудио и Видеокарти
    • Периферия
    • Овърклок и PC модинг
    • Нови конфигурации и части, въпроси, препоръки и мнения
  • Мобилни телефони, GSM, Мобилни приложения, Комуникации
    • Мобилни телефони - Въпроси, Проблеми, Софтуер
    • Съвети при избор на телефон
    • Мобилни Приложения (Apps)
    • Мобилни оператори, Мрежи, Промоции, Абонаменти, Услуги
    • Други теми относно мобилни телефони
  • Уеб дизайн, Графичен дизайн, Програмиране
    • Програмиране
    • Графичен Дизайн и Визуални изкуства
    • CMS, Форумни и Торент системи
    • Хостинг, Домейни, Уеб сървъри
    • SEO, Уеб оптимизация и стандарти
  • Битова Техника
    • Аудиотехника
    • Телевизори, Видео и Фото техника, Видео наблюдение
    • Климатици - проблеми, съвети, въпроси
    • Бойлери, Печки, Отопление
    • Друга битова техника
  • Интернет, Локални Мрежи и GPS Навигации
    • Интернет, WiFi, xDSL и Локална Мрежа
    • Биткойн и Криптовалути
    • Онлайн бизнес, AdSense, Affilate програми
    • Рутери, Модеми, Суичове
    • Facebook - проблеми, въпроси, вируси
    • Skype, VoIP - Интернет телефония
    • GPS, Навигационни системи - Въпроси, Карти, Проблеми
  • Изкуство
    • Музика
    • Кино и Телевизия
    • Поезия и Лично творчество
    • Изкуство - Изящно, Приложно и Сценично
    • Фотография и Фотографска техника
    • Литература, Книги (e-books, video trainings, tutorials & etc.)
  • Други
    • Статии и ревюта
    • Образование и обща култура
    • Религия, Мистика, Езотерика
    • История
    • Философия
    • Психология и Психотерапия
    • Новини от България и Света
    • Българите по света
    • Политика
    • Право и Юридически консултации
    • Здраве и Mедицина
    • Банки, Застраховане, Финанси, Кредити
    • Тийн Зона (Teen Zone)
    • Купувам / Продавам
    • Всичко останало
  • Хоби, Развлечение и Свободно време
    • Спорт
    • Автомобили
    • Дом и семейство
    • Домашни любимци
    • Пътешествия и туризъм
    • Кулинар
    • Изповеди
    • Празни приказки и забава
  • За kaldata.com
    • Новини относно сайта
    • Предложения, Въпроси и Проблеми свързани със сайта
  • групите за са стадото аз съм вълк единак Теми
  • Photoshop майнаци Теми
  • python3 data types
  • какви са ви любимите игри?? Темиигри за вас
  • супрески игри и рекорди Темиигри за вас

Блогове

Няма резултати

Няма резултати

Категории

  • Компютри
    • Компютърни конфигурации
    • Компютърни компоненти
    • Периферни устройства
    • Дънни платки
    • Мултимедия
    • Компютърни игри и софтуер
    • Администриране и интернет услуги
    • Компютърни аксесоари
    • Лаптопи и таблети
    • Видеокарти
    • Монитори
    • Процесори
    • Хард дискове и Памети
    • Други
  • Електроника
    • Телефони, GSM апарати
    • Аудио
    • Битова електроника
    • GPS и навигационни системи
    • Фотоапарати и обективи
    • TV и Видео
    • Други
  • Имоти
    • Гарсониери
    • Къщи и вили
    • Търговски площи
    • Гаражи
    • Апартаменти
    • Терени
    • Офиси
    • Други имоти в продажба
  • Авто-мото
    • Автомобили
    • Велосипеди
    • Лодки
    • Резервни части
    • Авто аксесоари
    • Мотоциклети
    • Скутери и ATV
    • Камиони и Автобуси
    • Авто сервизи и Rent-a-Car
    • Други
  • Работа
    • Работа в страната
    • Работа в чужбина
    • Стажове
    • Работа от вкъщи
    • Непълно работно време
  • Услуги
  • Строителство
  • Туризъм
  • Курсове и обучение
  • Домашни любимци
  • Други
  • супрески игри и рекорди Обяви
  • супрески игри и рекорди Обяви

Категории

  • Домашни любимци и Животни
  • Игри
  • Инциденти и Екстремни
  • Коли и превозни средства
  • Музика
    • Българска музика
    • Джаз
    • Електронна
    • Метъл и Рок
    • Народна и Фолклор
    • Поп и Диско
    • Поп-фолк
    • Рап и хип-хоп
    • Ритъм енд блус и соул
    • Друга
  • Новини и политика
  • Реклами
  • Смях и Развлечение
  • Спорт
  • Технологии, Компютри, Хардуер
  • ТВ Предавания и Шоу Програми
  • Хора и блогове
  • Филми и анимация
  • Други
  • Old School Hip-Hop and Electroo 80" Видео клипчета

Календари

  • Събития
  • Изложения
  • Семинари
  • Парти
  • Празници в България

Групи продукти

  • Банер Реклами

Търсене в...

Търси резултати които съдържат...


Дата

  • Начало

    Край


Последно обновяване

  • Начало

    Край


Филтриране по брой...

Регистрация

  • Начало

    Край


Група


Skype


Facebook


Google+


Twitter


ICQ


Yahoo


Интернет сайт


Град


Интереси

Открити 302 резултата

  1. Здравейте, бих била благодарна, ако хвърлите едно око над това, което ме притеснява. Ето резултатите от диагностиката с MalwareBytes: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.08.28.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 toshiba :: TOSHIBA-PC [administrator] 29.8.2013 г. 16:46:29 ч. MBAM-log-2013-08-29 (17-27-50).txt Scan type: Full scan (C:|D:|E:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 342385 Time elapsed: 39 minute(s), 46 second(s) Memory Processes Detected: 1 C:Program Files (x86)SweetIMMessengerSweetIM.exe (PUP.Optional.SweetIM) -> 4024 -> No action taken. Memory Modules Detected: 8 C:Program Files (x86)SweetIMMessengermgAdaptersProxy.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgUpdateSupport.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgsimcommon.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgcommon.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgcommunication.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermghooking.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgxml_wrapper.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgconfig.dll (PUP.Optional.SweetIM) -> No action taken. Registry Keys Detected: 13 HKCRCLSID{f34c9277-6577-4dff-b2d7-7d58092f272f} (PUP.Datamngr) -> No action taken. HKCUSOFTWAREMicrosoftWindowsCurrentVersionExtSettings{F34C9277-6577-4DFF-B2D7-7D58092F272F} (PUP.Datamngr) -> No action taken. HKCUSOFTWAREMicrosoftWindowsCurrentVersionExtStats{F34C9277-6577-4DFF-B2D7-7D58092F272F} (PUP.Datamngr) -> No action taken. HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{F34C9277-6577-4DFF-B2D7-7D58092F272F} (PUP.Datamngr) -> No action taken. HKCRCLSID{82AC53B4-164C-4B07-A016-437A8388B81A} (PUP.Optional.SweetIM) -> No action taken. HKCRTypeLib{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} (PUP.Optional.SweetIM) -> No action taken. HKCRInterface{A439801C-961D-452C-AB42-7848E9CBD289} (PUP.Optional.SweetIM) -> No action taken. HKCRMgMediaPlayer.GifAnimator.1 (PUP.Optional.SweetIM) -> No action taken. HKCRMgMediaPlayer.GifAnimator (PUP.Optional.SweetIM) -> No action taken. HKCUSOFTWAREDataMngr_Toolbar (PUP.Optional.DataMngr) -> No action taken. HKCUSoftwareDatamngr (PUP.Optional.DataMngr) -> No action taken. HKCUSOFTWARESWEETIM (PUP.Optional.SweetIM.A) -> No action taken. HKLMSOFTWARESWEETIM (PUP.Optional.SweetIM.A) -> No action taken. Registry Values Detected: 3 HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun|SweetIM (PUP.Optional.SweetIM) -> Data: C:Program Files (x86)SweetIMMessengerSweetIM.exe -> No action taken. HKCUSoftwareSweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {15124F06-4EBB-11E2-BC61-20689DA5D4E3} -> No action taken. HKLMSoftwareSweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {15124F06-4EBB-11E2-BC61-20689DA5D4E3} -> No action taken. Registry Data Items Detected: 1 HKCUSOFTWAREMicrosoftInternet ExplorerMain|Start Page (PUP.Optional.Conduit) -> Bad: (http://search.conduit.com?SearchSource=10&CUI=UN26900632892211815&UM=2&ctid=CT3078318&SSPV=TB_CS7) Good: (http://www.google.com) -> No action taken. Folders Detected: 3 C:UserstoshibaAppDataRoamingOpenCandy (PUP.Optional.OpenCandy) -> No action taken. C:UserstoshibaAppDataRoamingOpenCandy2FC790928F794B7A8C88FCE52BED2DEF (PUP.Optional.OpenCandy) -> No action taken. C:UserstoshibaAppDataRoamingOpenCandy321CD728BD2E4B309D39408927D2AD67 (PUP.Optional.OpenCandy) -> No action taken. Files Detected: 47 C:Program Files (x86)SweetIMMessengermgAdaptersProxy.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengerSweetIM.exe (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgUpdateSupport.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgsimcommon.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgcommon.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgcommunication.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermghooking.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgxml_wrapper.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgconfig.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)BS_PlayerBS_PlayerToolbarHelper.exe (PUP.Optional.Conduit.A) -> No action taken. C:Program Files (x86)BS_PlayerBS_PlayerToolbarHelper1.exe (PUP.Optional.Conduit.A) -> No action taken. C:Program Files (x86)SweetIMMessengerContentPackagesActivationHandler.exe (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgArchive.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgFlashPlayer.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgICQAuto.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgICQMessengerAdapter.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermglogger.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgMediaPlayer.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgMsnAuto.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgMsnMessengerAdapter.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgSweetIM.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgYahooAuto.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengermgYahooMessengerAdapter.dll (PUP.Optional.SweetIM) -> No action taken. C:Program Files (x86)SweetIMMessengerresourcessqlitemgSqlite3.dll (PUP.Optional.SweetIM) -> No action taken. C:UserstoshibaAppDataLocalConduitCT1750559BS_PlayerAutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE52VCTFQYZchecktbexist[1].exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5P8E6BXBYytbyclick_wpf[1].exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5PT79WS5Hytbyclick[1].exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5PU235UP7statisticsstub[1].exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempmgsqlite3.dll (PUP.Optional.SweetIM) -> No action taken. C:UserstoshibaAppDataLocalTempPIPInstaller_PTV_.exe (PUP.Optional.BundledToolBar.A) -> No action taken. C:UserstoshibaAppDataLocalTempShortcut_bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> No action taken. C:UserstoshibaAppDataLocalTempToolbarHelper.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempCT1750559ctbe.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempCT1750559ieLogic.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempCT1750559statisticsStub.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempct3078318chLogic.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempct3078318ctbe.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempct3078318ieLogic.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempct3078318spch.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempct3078318statisticsStub.exe (PUP.Optional.Conduit.A) -> No action taken. C:UserstoshibaAppDataLocalTempnsc5EF4.tmpOCSetupHlp.dll (PUP.Optional.OpenCandy) -> No action taken. C:WindowsInstaller3cfd6e.msi (PUP.Optional.SweetIM) -> No action taken. C:WindowsInstaller3cfd86.msi (PUP.Optional.SweetIM) -> No action taken. D:филмиBS.Player 2.64 Build 1073 Finalbsplayer264.1073.exe (PUP.Optional.OpenCandy) -> No action taken. C:UserstoshibaAppDataRoamingOpenCandy2FC790928F794B7A8C88FCE52BED2DEFTuneUpUtilities2013_2200319_en-US.exe (PUP.Optional.OpenCandy) -> No action taken. C:UserstoshibaAppDataRoamingOpenCandy321CD728BD2E4B309D39408927D2AD67RealPlayerR71POC6_p2v1.exe (PUP.Optional.OpenCandy) -> No action taken. (end) DDS: DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 9.10.9200.16660 Run by toshiba at 19:34:21 on 2013-08-28 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.8082.5093 [GMT 3:00] . AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} . ============== Running Processes =============== . C:Windowssystem32wininit.exe C:Windowssystem32lsm.exe C:Windowssystem32svchost.exe -k DcomLaunch C:Windowssystem32svchost.exe -k RPCSS C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted C:Windowssystem32svchost.exe -k LocalService C:Windowssystem32svchost.exe -k netsvcs C:Windowssystem32svchost.exe -k NetworkService C:Program FilesAVAST SoftwareAvastAvastSvc.exe C:WindowsSystem32spoolsv.exe C:Windowssystem32svchost.exe -k LocalServiceNoNetwork C:Program Files (x86)ComodoDragondragon_updater.exe C:Program FilesInteliCLS ClientHeciServer.exe C:Program Files (x86)IntelIntel® Management Engine ComponentsFWServiceIntelMeFWService.exe C:Program Files (x86)IntelIntel® Management Engine ComponentsDALjhi_service.exe C:Program Files (x86)T-MobileConnection ManagerBackgroundServiceServiceManager.exe C:ProgramDataSkypeToolbarsSkype C2C Servicec2c_service.exe C:Windowssystem32svchost.exe -k imgsvc C:Program FilesTOSHIBAPower SaverTosCoSrv.exe C:PROGRA~2VIDEOD~2bar1.bin4zbarsvc.exe C:Program Files (x86)Common FilesAVG Secure SearchvToolbarUpdater15.5.0ToolbarUpdater.exe C:Program Files (x86)Common FilesAVG Secure SearchvToolbarUpdater15.5.0loggingserver.exe C:Windowssystem32conhost.exe C:Windowssystem32svchost.exe -k bthsvcs C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation C:WindowsSystem32WUDFHost.exe C:Windowssystem32taskhost.exe C:Windowssystem32Dwm.exe C:WindowsExplorer.EXE C:Program FilesSynapticsSynTPSynTPEnh.exe C:Program FilesTOSHIBAPower SaverTPwrMain.exe C:Program FilesTOSHIBAFlashCardsTCrdMain.exe C:WindowsSystem32igfxtray.exe C:WindowsSystem32hkcmd.exe C:WindowsSystem32igfxpers.exe C:PROGRAM FILESSYNAPTICSSYNTPSYNTPHELPER.EXE C:Program Files (x86)SkypePhoneSkype.exe C:Program Files (x86)IntelIntel® USB 3.0 eXtensible Host Controller DriverApplicationiusb3mon.exe C:Program Files (x86)SweetIMMessengerSweetIM.exe C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe C:Program FilesAVAST SoftwareAvastAvastUI.exe C:Windowssystem32SearchIndexer.exe C:Program Files (x86)AVG Secure Searchvprot.exe C:Program Files (x86)VideoDownloadConverter_4zbar1.bin4zbrmon.exe C:Program Files (x86)T-MobileConnection ManagerBackgroundModemListener.exe C:Program FilesWindows Media Playerwmpnetwk.exe C:WindowsSystem32svchost.exe -k LocalServicePeerNet C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe C:WindowsSystem32svchost.exe -k secsvcs C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSmartSrv.exe C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSENotify.exe C:Program Files (x86)Operaopera.exe C:Program Files (x86)Malwarebytes' Anti-Malwarembam.exe C:Program Files (x86)IntelIntel® ME FW Recovery Agentbinismagent.exe C:Program Files (x86)IntelIntel® ME FW Recovery Agentbinupdateui.exe C:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE C:Windowssystem32wuauclt.exe C:Program Files (x86)Microsoft OfficeOffice14WINWORD.EXE C:Windowssplwow64.exe C:Windowssystem32taskeng.exe C:Windowssystem32conhost.exe C:Windowssystem32DllHost.exe C:Windowssystem32wbemwmiprvse.exe C:WindowsSystem32cscript.exe . ============== Pseudo HJT Report =============== . uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTo2.dll uURLSearchHooks: <No Name>: {93a3111f-4f74-4ed8-895e-d9708497629e} - C:Program Files (x86)VideoDownloadConverter_4zbar1.bin4zSrcAs.dll uURLSearchHooks: BS Player ControlBar Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:Program Files (x86)BS_PlayerprxtbBS_0.dll mURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTo2.dll mURLSearchHooks: BS Player ControlBar Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:Program Files (x86)BS_PlayerprxtbBS_0.dll mWinlogon: Userinit = userinit.exe BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:Program Files (x86)VideoDownloadConverter_4zbar1.bin4zbar.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program Files (x86)Microsoft OfficeOffice14GROOVEEX.DLL BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTo2.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned> BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program Files (x86)Microsoft OfficeOffice14URLREDIR.DLL BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:Program Files (x86)VideoDownloadConverter_4zbar1.bin4zSrcAs.dll BHO: BS Player ControlBar Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:Program Files (x86)BS_PlayerprxtbBS_0.dll TB: uTorrentControl_v2 Toolbar: {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:Program Files (x86)uTorrentControl_v2prxtbuTo2.dll TB: BS Player ControlBar Toolbar: {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - C:Program Files (x86)BS_PlayerprxtbBS_0.dll TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:Program Files (x86)uTorrentControl_v2prxtbuTo2.dll TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:Program Files (x86)VideoDownloadConverter_4zbar1.bin4zbar.dll TB: BS Player ControlBar Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:Program Files (x86)BS_PlayerprxtbBS_0.dll uRun: [uTorrent] "C:Program Files (x86)uTorrentuTorrent.exe" /MINIMIZED uRun: [DAEMON Tools Lite] "C:Program Files (x86)DAEMON Tools LiteDTLite.exe" -autorun uRun: [skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrun mRun: [uSB3MON] "C:Program Files (x86)IntelIntel® USB 3.0 eXtensible Host Controller DriverApplicationiusb3mon.exe" mRun: [sweetIM] C:Program Files (x86)SweetIMMessengerSweetIM.exe mRun: [bCSSync] "C:Program Files (x86)Microsoft OfficeOffice14BCSSync.exe" /DelayServices mRun: [Adobe Reader Speed Launcher] "C:Program Files (x86)AdobeReader 9.0ReaderReader_sl.exe" mRun: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe" mRun: [avast] "C:Program FilesAVAST SoftwareAvastavastUI.exe" /nogui mRun: [vProt] "C:Program Files (x86)AVG Secure Searchvprot.exe" mRun: [VideoDownloadConverter Search Scope Monitor] "C:PROGRA~2VIDEOD~2bar1.bin4zsrchmn.exe" /m=2 /w /h mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:PROGRA~2VIDEOD~2bar1.bin4zbrmon.exe mRun: [T-Mobile ModemListener] C:Program Files (x86)T-MobileConnection ManagerBackgroundModemListener.exe start mRunOnce: [Malwarebytes Anti-Malware] C:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exe /install /silent StartupFolder: C:PROGRA~3MICROS~1WindowsSTARTM~1ProgramsStartupBLUETO~1.LNK - C:Program Files (x86)TOSHIBABluetooth MonitorBtMon2.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: E&xport to Microsoft Excel - C:PROGRA~2MICROS~1Office14EXCEL.EXE/3000 IE: Se&nd to OneNote - C:PROGRA~2MICROS~1Office14ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll TCP: NameServer = 192.168.1.1 TCP: Interfaces{DA1D689C-6383-4AE0-87D7-85EC745289D0} : DHCPNameServer = 192.168.1.1 TCP: Interfaces{DA1D689C-6383-4AE0-87D7-85EC745289D0}244534D2144435C4 : DHCPNameServer = 192.168.1.1 TCP: Interfaces{DA1D689C-6383-4AE0-87D7-85EC745289D0}6594651434F4D4F5E45445 : DHCPNameServer = 192.168.1.1 TCP: Interfaces{DA1D689C-6383-4AE0-87D7-85EC745289D0}669666478666C6F6F627 : DHCPNameServer = 192.168.1.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program Files (x86)Common FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:Program Files (x86)Common FilesAVG Secure SearchViProtocolInstaller15.5.0ViProtocol.dll SSODL: WebCheck - <orphaned> SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program Files (x86)Microsoft OfficeOffice14GROOVEEX.DLL mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:Program Files (x86)GoogleChromeApplication29.0.1547.57Installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dll x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program Files (x86)SkypeToolbarsInternet Explorer x64skypeieplugin.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dll x64-Run: [TosSENotify] C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosWaitSrv.exe x64-Run: [TosVolRegulator] C:Program FilesTOSHIBATosVolRegulatorTosVolRegulator.exe x64-Run: [synTPEnh] C:Program Files (x86)SynapticsSynTPSynTPEnh.exe x64-Run: [TPwrMain] C:Program Files (x86)TOSHIBAPower SaverTPwrMain.EXE x64-Run: [TCrdMain] C:Program Files (x86)TOSHIBAFlashCardsTCrdMain.exe x64-Run: [igfxTray] C:WindowsSystem32igfxtray.exe x64-Run: [HotKeysCmds] C:WindowsSystem32hkcmd.exe x64-Run: [Persistence] C:WindowsSystem32igfxpers.exe x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorer x64skypeieplugin.dll x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program Files (x86)SkypeToolbarsInternet Explorer x64skypeieplugin.dll x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned> x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - <orphaned> x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL . ============= SERVICES / DRIVERS =============== . R0 aswKbd;aswKbd;C:WindowsSystem32driversaswKbd.sys [2013-3-5 22600] R0 aswRvrt;aswRvrt;C:WindowsSystem32driversaswRvrt.sys [2013-3-5 65336] R0 aswVmm;aswVmm;C:WindowsSystem32driversaswVmm.sys [2013-3-5 178624] R0 BMLoad;Bytemobile Boot Time Load Driver;C:WindowsSystem32driversBMLoad.sys [2013-3-20 16512] R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:WindowsSystem32driversiusb3hcs.sys [2012-1-5 16152] R1 aswSnx;aswSnx;C:WindowsSystem32driversaswSnx.sys [2013-2-10 1025808] R1 aswSP;aswSP;C:WindowsSystem32driversaswSP.sys [2013-2-10 377920] R1 avgtp;avgtp;C:WindowsSystem32driversavgtpx64.sys [2013-2-15 45856] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:WindowsSystem32driversdtsoftbus01.sys [2012-12-25 283200] R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32driversvwififlt.sys [2009-7-14 59904] R2 aswFsBlk;aswFsBlk;C:WindowsSystem32driversaswFsBlk.sys [2013-2-10 33400] R2 aswMonFlt;aswMonFlt;C:WindowsSystem32driversaswMonFlt.sys [2013-2-10 80816] R2 avast! Antivirus;avast! Antivirus;C:Program FilesAVAST SoftwareAvastAvastSvc.exe [2013-3-12 45248] R2 DragonUpdater;COMODO Dragon Update Service;C:Program Files (x86)ComodoDragondragon_updater.exe [2012-12-24 1868432] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:Program FilesInteliCLS ClientHeciServer.exe [2012-2-2 628448] R2 Intel® ME Service;Intel® ME Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsFWServiceIntelMeFWService.exe [2012-12-19 128280] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsDALJhi_service.exe [2012-12-19 161560] R2 Modem Device Helper;Modem Device Helper;C:Program Files (x86)T-MobileConnection ManagerBackgroundServiceServiceManager.exe -start --> C:Program Files (x86)T-MobileConnection ManagerBackgroundServiceServiceManager.exe -start [?] R2 Skype C2C Service;Skype C2C Service;C:ProgramDataSkypeToolbarsSkype C2C Servicec2c_service.exe [2013-8-14 3291008] R2 UNS;Intel® Management and Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2012-12-19 363800] R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:PROGRA~2VIDEOD~2bar1.bin4zbarsvc.exe [2013-2-17 42504] R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;C:Program Files (x86)Common FilesAVG Secure SearchvToolbarUpdater15.5.0ToolbarUpdater.exe [2013-8-15 1643184] R3 IntcDAud;Intel® Display Audio;C:WindowsSystem32driversIntcDAud.sys [2011-12-6 331264] R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:WindowsSystem32driversiusb3hub.sys [2012-1-5 355096] R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:WindowsSystem32driversiusb3xhc.sys [2012-1-5 786200] R3 MEIx64;Intel® Management Engine Interface ;C:WindowsSystem32driversHECIx64.sys [2012-12-19 60184] R3 osppsvc;Office Software Protection Platform;C:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE [2010-1-9 4925184] R3 PGEffect;Pangu effect driver;C:WindowsSystem32driversPGEffect.sys [2012-12-19 38096] R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:WindowsSystem32driversrtwlane.sys [2012-12-26 1082472] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSmartSrv.exe [2011-11-25 138152] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576] S2 gupdate;Услуга на Google Актуализация (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2012-12-25 116648] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2012-12-21 257416] S3 cphs;Intel® Content Protection HECI Service;C:WindowsSysWOW64IntelCpHeciSvc.exe [2012-5-10 276248] S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2011-4-12 71168] S3 gupdatem;Услуга на Google Актуализация (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2012-12-25 116648] S3 jrdusbser;Mobile Connector Device for Legacy Serial Communication;C:WindowsSystem32driversjrdusbser.sys [2013-3-20 119680] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:Program Files (x86)Microsoft OfficeOffice14GROOVE.EXE [2012-9-20 30785672] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2010-11-21 20992] S3 RTL8167;Realtek 8167 NT Driver;C:WindowsSystem32driversRt64win7.sys [2012-12-19 565352] S3 Synth3dVsc;Synth3dVsc;C:WindowsSystem32driversSynth3dVsc.sys [2011-4-12 88960] S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32driversterminpt.sys [2011-4-12 34816] S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-21 31232] S3 tsusbhub;tsusbhub;C:WindowsSystem32driverstsusbhub.sys [2011-4-12 117248] S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2012-12-27 1255736] S4 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-2-28 161384] . =============== Created Last 30 ================ . 2013-08-28 14:57:25 -------- d-----w- C:UserstoshibaAppDataRoamingMalwarebytes 2013-08-28 14:53:39 -------- d-----w- C:ProgramDataMalwarebytes 2013-08-28 14:53:38 25928 ----a-w- C:WindowsSystem32driversmbam.sys 2013-08-28 14:53:38 -------- d-----w- C:Program Files (x86)Malwarebytes' Anti-Malware 2013-08-28 14:52:09 -------- d-----w- C:UserstoshibaAppDataLocalPrograms 2013-08-27 11:15:49 9515512 ----a-w- C:ProgramDataMicrosoftWindows DefenderDefinition Updates{A8E226B2-60E9-4E94-9D09-FF819BD721F6}mpengine.dll 2013-08-04 22:13:02 -------- d-----w- C:Lyrics 2013-08-04 22:10:31 -------- d-----w- C:Program Files (x86)MiniLyrics . ==================== Find3M ==================== . 2013-08-21 14:35:08 71048 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl 2013-08-21 14:35:08 692104 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe 2013-08-14 22:00:23 45856 ----a-w- C:WindowsSystem32driversavgtpx64.sys 2013-07-26 05:13:37 2241024 ----a-w- C:WindowsSystem32wininet.dll 2013-07-26 05:12:08 3958784 ----a-w- C:WindowsSystem32jscript9.dll 2013-07-26 05:12:04 136704 ----a-w- C:WindowsSystem32iesysprep.dll 2013-07-26 05:12:03 67072 ----a-w- C:WindowsSystem32iesetup.dll 2013-07-26 03:35:08 2706432 ----a-w- C:WindowsSystem32mshtml.tlb 2013-07-26 03:13:24 1767936 ----a-w- C:WindowsSysWow64wininet.dll 2013-07-26 03:12:04 2877440 ----a-w- C:WindowsSysWow64jscript9.dll 2013-07-26 03:12:00 61440 ----a-w- C:WindowsSysWow64iesetup.dll 2013-07-26 03:12:00 109056 ----a-w- C:WindowsSysWow64iesysprep.dll 2013-07-26 02:49:14 2706432 ----a-w- C:WindowsSysWow64mshtml.tlb 2013-07-26 02:39:38 89600 ----a-w- C:WindowsSystem32RegisterIEPKEYs.exe 2013-07-26 01:59:38 71680 ----a-w- C:WindowsSysWow64RegisterIEPKEYs.exe 2013-07-25 09:25:54 1888768 ----a-w- C:WindowsSystem32WMVDECOD.DLL 2013-07-25 08:57:27 1620992 ----a-w- C:WindowsSysWow64WMVDECOD.DLL 2013-07-19 01:58:42 2048 ----a-w- C:WindowsSystem32tzres.dll 2013-07-19 01:41:01 2048 ----a-w- C:WindowsSysWow64tzres.dll 2013-07-09 06:03:30 5550528 ----a-w- C:WindowsSystem32ntoskrnl.exe 2013-07-09 05:54:22 1732032 ----a-w- C:WindowsSystem32ntdll.dll 2013-07-09 05:53:12 243712 ----a-w- C:WindowsSystem32wow64.dll 2013-07-09 05:52:52 224256 ----a-w- C:WindowsSystem32wintrust.dll 2013-07-09 05:51:16 1217024 ----a-w- C:WindowsSystem32rpcrt4.dll 2013-07-09 05:46:20 184320 ----a-w- C:WindowsSystem32cryptsvc.dll 2013-07-09 05:46:20 1472512 ----a-w- C:WindowsSystem32crypt32.dll 2013-07-09 05:46:20 139776 ----a-w- C:WindowsSystem32cryptnet.dll 2013-07-09 05:03:34 3968960 ----a-w- C:WindowsSysWow64ntkrnlpa.exe 2013-07-09 05:03:34 3913664 ----a-w- C:WindowsSysWow64ntoskrnl.exe 2013-07-09 04:53:47 1292192 ----a-w- C:WindowsSysWow64ntdll.dll 2013-07-09 04:52:33 663552 ----a-w- C:WindowsSysWow64rpcrt4.dll 2013-07-09 04:52:33 5120 ----a-w- C:WindowsSysWow64wow32.dll 2013-07-09 04:52:10 175104 ----a-w- C:WindowsSysWow64wintrust.dll 2013-07-09 04:46:31 140288 ----a-w- C:WindowsSysWow64cryptsvc.dll 2013-07-09 04:46:31 1166848 ----a-w- C:WindowsSysWow64crypt32.dll 2013-07-09 04:46:31 103936 ----a-w- C:WindowsSysWow64cryptnet.dll 2013-07-09 04:45:07 44032 ----a-w- C:Windowsapppatchacwow64.dll 2013-07-09 02:49:42 25600 ----a-w- C:WindowsSysWow64setup16.exe 2013-07-09 02:49:41 7680 ----a-w- C:WindowsSysWow64instnm.exe 2013-07-09 02:49:39 14336 ----a-w- C:WindowsSysWow64ntvdm64.dll 2013-07-09 02:49:38 2048 ----a-w- C:WindowsSysWow64user.exe 2013-07-08 17:54:48 57096 ----a-w- C:WindowsSystem32certsentry.dll 2013-07-08 17:54:48 48392 ----a-w- C:WindowsSysWow64certsentry.dll 2013-07-08 16:18:18 348160 ----a-w- C:WindowsSysWow64msvcr71.dll 2013-07-08 16:18:18 1700352 ----a-w- C:WindowsSysWow64gdiplus.dll 2013-07-08 16:18:18 1060864 ----a-w- C:WindowsSysWow64mfc71.dll 2013-07-06 06:03:53 1910208 ----a-w- C:WindowsSystem32driverstcpip.sys 2013-07-03 08:33:03 9728 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-15 04:35:40 1111552 ----a-w- C:WindowsSystem32rdpcorets.dll 2013-06-15 04:32:16 39936 ----a-w- C:WindowsSystem32driverstssecsrv.sys 2013-06-05 03:34:27 3153920 ----a-w- C:WindowsSystem32win32k.sys 2013-06-04 06:00:13 624128 ----a-w- C:WindowsSystem32qedit.dll 2013-06-04 04:53:07 509440 ----a-w- C:WindowsSysWow64qedit.dll . ============= FINISH: 19:34:43,88 =============== Attach: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Ultimate Boot Device: DeviceHarddiskVolume1 Install Date: 19.12.2012 г. 10:36:53 System Uptime: 28.8.2013 г. 15:35:43 (4 hours ago) . Motherboard: Type2 - Board Vendor Name1 | | Type2 - Board Product Name1 Processor: Intel® Celeron® CPU B830 @ 1.80GHz | U3E1 | 1296/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 80 GiB total, 43,616 GiB free. D: is FIXED (NTFS) - 516 GiB total, 353,063 GiB free. E: is CDROM () F: is CDROM (CDFS) H: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: avast! Firewall NDIS Filter Miniport Device ID: ROOTSW_ASWNDISMP0000 Manufacturer: ALWIL Software Name: avast! Firewall NDIS Filter Miniport PNP Device ID: ROOTSW_ASWNDISMP0000 Service: aswNdis . Class GUID: Description: Ethernet Controller Device ID: PCIVEN_10EC&DEV_8136&SUBSYS_FB371179&REV_054&299ABDA1&0&00E2 Manufacturer: Name: Ethernet Controller PNP Device ID: PCIVEN_10EC&DEV_8136&SUBSYS_FB371179&REV_054&299ABDA1&0&00E2 Service: . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . µTorrent Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.3 - Bulgarian AEnglish Dictionary XP 1.72 avast! Free Antivirus AVG Security Toolbar Bluetooth Monitor 4 BS Player Toolbar BS.Player FREE Comodo Dragon Connection Manager DAEMON Tools Lite Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition GOM Player Google Chrome Google Drive Google Update Helper Intel® Manageability Engine Firmware Recovery Agent Intel® Management Engine Components Intel® Processor Graphics Intel® Rapid Storage Technology Intel® USB 3.0 eXtensible Host Controller Driver Intel® Trusted Connect Service Client Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft .NET Framework 4 Client Profile Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared 64-bit MUI (English) 2010 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 oggcodecs 0.71.0946 Opera 12.15 Realtek WLAN Driver SA Dictionary® 2012 Beta1 Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687422) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687276) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition Security Update for Microsoft Publisher 2010 (KB2553147) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2810068) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition Skype Click to Call Skype™ 6.3 SweetIM for Messenger 3.7 SweetPacks bundle uninstaller Synaptics Pointing Device Driver The KMPlayer (remove only) TOSHIBA HDD/SSD Alert TOSHIBA Value Added Package TOSHIBA Web Camera Application Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition uTorrentControl_v2 Toolbar Video Download Converter version 1.0.0.0 VideoDownloadConverter Toolbar WinRAR 4.20 (32-битова версия) . ==== End Of File ===========================
  2. Здравейте, Реших да поразчистя компютъра и направих сканиране с MBAM, която откри нежелани приложения. Потърсих информация в интернет и попаднах на този форум. Искрено се надявам, че с ваша помощ, ще изчистим тази гадинка.Изнесох и прилагам лог от сканирането с мбам. След това ще изпълня другите стъпки в ръководството. Благодаря предварително. Malwarebytes Anti-Malware www.malwarebytes.org Дата на сканиране: 22.4.2015 г. Час на сканиране: 17:02:02 Дневник: mbam.txt Администратор: Да Версия: 2.01.4.1018 База от данни за злонамерен софтуер: v2015.04.22.03 База от данни за рууткити: v2015.04.21.01 Лиценз: Безплатен Защита от злонамерен софтуер: Забранено Защита от злонамерени страници: Забранено Самозащита: Забранено Когато опитах да изтегля Farbar Recovery Scan Tool антивирусната ми програма Аваст, го разпозна като зловреден и го блокира.
  3. Без да искам стартирах един съмнителен файл извън "сандъка" и се оказа миньор, премахнах го, но искам мнение дали системата е изчистена напълно. Благодаря предварително за отделеното време!! DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 9.11.9600.16428 BrowserJavaVersion: 10.45.2Run by Andrei at 12:14:25 on 2013-12-04Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1026.18.2048.802 [GMT 2:00].SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ================.C:Windowssystem32wininit.exeC:Windowssystem32lsm.exeC:Program FilesBitdefenderBitdefendervsserv.exeC:Program FilesCreativeShared FilesCTAudSvc.exeC:WindowsSystem32spoolsv.exeC:Windowssystem32taskhost.exeC:Windowssystem32Dwm.exeC:WindowsExplorer.EXEC:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXEC:Windowssystem32taskeng.exeC:Program FilesMicrosoft Mouse and Keyboard Centeritype.exeC:Program FilesMicrosoft Mouse and Keyboard Centeripoint.exeC:Program FilesBitdefenderBitdefenderupdatesrv.exeC:WindowsSystem32rundll32.exeC:Program FilesBitdefenderBitdefenderbdagent.exeC:Program FilesCyberGhost 5Service.exeC:Program FilesATI TechnologiesATI.ACECore-StaticMOM.exeC:Program FilesATI TechnologiesATI.ACECore-StaticCCC.exeC:Program FilesOpera18.0.1284.49opera.exeC:Program FilesOpera18.0.1284.49opera.exeC:Program FilesOpera18.0.1284.49opera.exeC:Program FilesOpera18.0.1284.49opera.exeC:Program FilesOpera18.0.1284.49opera.exeC:Program FilesOpera18.0.1284.49opera.exeC:Program FilesBitdefenderBitdefenderseccenter.exeC:Windowssystem32sppsvc.exeC:Windowssystem32conhost.exeC:Windowssystem32wbemwmiprvse.exeC:Windowssystem32svchost.exe -k DcomLaunchC:Windowssystem32svchost.exe -k RPCSSC:WindowsSystem32svchost.exe -k LocalServiceNetworkRestrictedC:WindowsSystem32svchost.exe -k LocalSystemNetworkRestrictedC:Windowssystem32svchost.exe -k LocalServiceC:Windowssystem32svchost.exe -k netsvcsC:Windowssystem32svchost.exe -k GPSvcGroupC:Windowssystem32svchost.exe -k NetworkServiceC:Windowssystem32svchost.exe -k LocalServiceNoNetworkC:WindowsSystem32svchost.exe -k HPZ12C:WindowsSystem32svchost.exe -k HPZ12C:Windowssystem32svchost.exe -k imgsvcC:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted.============== Pseudo HJT Report ===============.uStart Page = hxxps://www.google.bg/mStart Page = about:blankuProxyServer = 200.31.172.35:8080BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dllBHO: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - c:program filesbitdefenderbitdefenderpmbxie.dllBHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:program filesjavajre7binssv.dllBHO: Adobe Acrobat Create PDF Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dllBHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - c:program fileslogitechsetpointpSetPointSmooth.dllBHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:program filesmicrosoft officeoffice14URLREDIR.DLLBHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesjavajre7binjp2ssv.dllBHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dllBHO: Adblock Plus for IE Browser Helper Object: {FFCB3198-32F3-4E8B-9539-4324694ED664} - c:program filesadblock plus for ieAdblockPlus32.dllTB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dllTB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dllmRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntrymRun: [Bdagent] "c:program filesbitdefenderbitdefenderbdagent.exe"mRun: [StartCCC] "c:program filesati technologiesati.acecore-staticCLIStart.exe" MSRundRun: [Bitdefender Wallet Agent] "c:program filesbitdefenderbitdefenderpmbxag.exe"dRun: [Bitdefender Wallet] "c:program filesbitdefenderbitdefenderpwdmanui.exe" --hidden --nowizarddRun: [Bitdefender Wallet Application Agent] "c:program filesbitdefenderbitdefenderbdapppassmgr.exe"uPolicies-Explorer: NoDriveTypeAutoRun = dword:145mPolicies-System: ConsentPromptBehaviorAdmin = dword:0mPolicies-System: ConsentPromptBehaviorUser = dword:0mPolicies-System: EnableLUA = dword:0mPolicies-System: EnableUIADesktopToggle = dword:0mPolicies-System: PromptOnSecureDesktop = dword:0IE: &Експортиране към Microsoft Excel - c:progra~1micros~2office14EXCEL.EXE/3000IE: Append Link Target to Existing PDF - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dll/AcroIEAppendSelLinks.htmlIE: Append to Existing PDF - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert Link Target to Adobe PDF - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dll/AcroIECaptureSelLinks.htmlIE: Convert to Adobe PDF - c:program filescommon filesadobeacrobatwcieactivexAcroIEFavClient.dll/AcroIECapture.htmlDPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1379945116496DPF: {7B43048F-DA7A-458F-AF35-D825BDBB6816} - hxxp://83.143.145.93/codebase/NetVideoOCX.cabDPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cabDPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cabTCP: Interfaces{EB592CC3-457B-41D9-A37D-9829A8F0C2DA} : NameServer = 93.152.128.1,93.152.160.5Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:program filescommon filesmicrosoft sharedoffice14MSOXMLMF.DLLHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dllNotify: LBTWlgn - c:program filescommon fileslogishrdbluetoothLBTWlgn.dllSSODL: WebCheck - <orphaned>SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:program filessuperantispywareSASSEH.DLLmASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:program filesgooglechromeapplication31.0.1650.57installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome.============= SERVICES / DRIVERS ===============.R0 avc3;avc3;c:windowssystem32driversavc3.sys [2013-10-8 640560]R0 Bhbase;Baidu Hook Base;c:windowssystem32driversBhbase.sys [2013-9-23 47456]R0 gzflt;gzflt;c:windowssystem32driversgzflt.sys [2013-10-8 165744]R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:program filescommon filesbitdefenderbitdefender firewallbdfndisf6.sys [2013-10-8 78144]R1 bdfwfpf;bdfwfpf;c:program filescommon filesbitdefenderbitdefender firewallbdfwfpf.sys [2013-10-8 90704]R1 SASDIFSV;SASDIFSV;c:program filessuperantispywaresasdifsv.sys [2011-7-22 12880]R1 SASKUTIL;SASKUTIL;c:program filessuperantispywareSASKUTIL.SYS [2011-7-12 67664]R2 CGVPNCliService;CyberGhost VPN 5 Client Service;c:program filescyberghost 5Service.exe [2013-12-1 26600]R2 osppsvc;Office Software Protection Platform;c:program filescommon filesmicrosoft sharedofficesoftwareprotectionplatformOSPPSVC.EXE [2010-1-9 4640000]R2 UPDATESRV;Bitdefender Desktop Update Service;c:program filesbitdefenderbitdefenderupdatesrv.exe [2013-10-16 54424]R3 amdiox86;AMD IO Driver;c:windowssystem32driversamdiox86.sys [2013-3-9 37944]R3 amdkmdag;amdkmdag;c:windowssystem32driversatikmdag.sys [2013-4-30 10070016]R3 amdkmdap;amdkmdap;c:windowssystem32driversatikmpag.sys [2013-4-30 290304]R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:windowssystem32driversAtihdW73.sys [2012-5-14 86656]R3 avchv;avchv Function Driver;c:windowssystem32driversavchv.sys [2013-3-9 242504]R3 avckf;avckf;c:windowssystem32driversavckf.sys [2013-10-8 490144]R3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;c:windowssystem32driversBazisVirtualCDBus.sys [2011-6-4 117584]R3 RTL8167;Realtek 8167 NT Driver;c:windowssystem32driversRt86win7.sys [2013-9-1 669912]S3 AMD External Events Utility;AMD External Events Utility;c:windowssystem32atiesrxx.exe [2013-4-30 217088]S3 AMD FUEL Service;AMD FUEL Service;c:program filesati technologiesati.acefuelFuel.Service.exe [2012-11-16 291840]S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:windowssystem32driversb57nd60x.sys [2009-7-14 229888]S3 bdfwfpf_pc;bdfwfpf_pc;c:program filescommon filesbitdefenderbitdefender firewallbdfwfpf_pc.sys [2013-10-8 108008]S3 BDSandBox;BDSandBox;c:windowssystem32driversbdsandbox.sys [2013-10-8 66832]S3 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2013-9-11 105144]S3 DLKRT32;D-Link DGE-528T Gigabit Ethernet Adapter Driver;c:windowssystem32driversDLKRT32.sys [2013-3-10 277608]S3 dmvsc;dmvsc;c:windowssystem32driversdmvsc.sys [2011-4-12 62464]S3 ggflt;SEMC USB Flash Driver Filter;c:windowssystem32driversggflt.sys [2013-3-30 12400]S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:windowssystem32ieetwcollector.exe [2013-11-7 108032]S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:windowssystem32driversrdpvideominiport.sys [2013-3-9 14848]S3 Sony PC Companion;Sony PC Companion;c:program filessonysony pc companionPCCService.exe [2013-3-11 155824]S3 Synth3dVsc;Synth3dVsc;c:windowssystem32driversSynth3dVsc.sys [2011-4-12 77184]S3 TeamViewer9;TeamViewer 9;c:program filesteamviewerversion9TeamViewer_Service.exe [2013-12-3 5316448]S3 terminpt;Microsoft Remote Desktop Input Driver;c:windowssystem32driversterminpt.sys [2013-3-9 24064]S3 TsUsbFlt;TsUsbFlt;c:windowssystem32driversTsUsbFlt.sys [2013-11-13 49152]S3 TsUsbGD;Remote Desktop Generic USB Device;c:windowssystem32driversTsUsbGD.sys [2013-3-9 27136]S3 tsusbhub;tsusbhub;c:windowssystem32driverstsusbhub.sys [2011-4-12 112640]S3 WatAdminSvc;Услуга на технологиите за активиране на Windows;c:windowssystem32watWatAdminSvc.exe [2013-3-9 1343400]S4 !SASCORE;SAS Core Service;c:program filessuperantispywareSASCore.exe [2013-5-23 119056]S4 AdobeARMservice;Adobe Acrobat Update Service;c:program filescommon filesadobearm1.0armsvc.exe [2012-9-23 65192]S4 BdDesktopParental;Bitdefender Desktop Parental Control;c:program filesbitdefenderbitdefenderbdparentalservice.exe [2013-10-16 69880]S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:program filescommon filescreative labs sharedserviceCTAELicensing.exe [2013-3-9 79360]S4 gupdate;Услуга на Google Актуализация (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2013-3-9 116648]S4 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2013-3-9 116648].=============== File Associations ===============.ShellExec: Opera.exe: open="c:program filesoperaLauncher.exe" "%1".=============== Created Last 30 ================.2013-12-03 09:54:18 -------- d-----w- c:program filesCCleaner2013-12-03 06:58:49 -------- d-----w- c:program filesUnlockroot2013-12-01 10:37:55 -------- d-----w- c:usersandreiappdatalocalCyberGhost2013-12-01 10:37:37 -------- d-----w- c:program filesTAP-Windows2013-12-01 10:37:12 -------- d-----w- c:program filesCyberGhost 52013-11-30 08:15:59 53248 ----a-r- c:usersandreiappdataroamingmicrosoftinstaller{3ee9bcae-e9a9-45e5-9b1c-83a4d357e05c}ARPPRODUCTICON.exe2013-11-30 08:14:45 -------- d-----w- c:usersandreiappdataroamingLogishrd2013-11-29 20:27:02 71048 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl2013-11-29 20:27:02 692616 ----a-w- c:windowssystem32FlashPlayerApp.exe2013-11-29 19:08:39 -------- d-----w- c:usersandreiappdatalocalMacromedia2013-11-28 19:48:35 63920 ----a-w- c:windowssystem32driversvmx_svga.sys2013-11-28 19:48:32 11440 ----a-w- c:windowssystem32driversvmmouse.sys2013-11-28 19:48:29 143344 ----a-w- c:windowssystem32driversvmhgfs.sys2013-11-28 19:48:26 98928 ----a-w- c:windowssystem32driversvmci.sys2013-11-28 19:48:23 25136 ----a-w- c:windowssystem32driversvmaudio.sys2013-11-28 19:48:20 107120 ----a-w- c:windowssystem32driversvm3dmp.sys2013-11-28 19:48:16 118784 ----a-w- c:windowssystem32driversE1G60I32.sys2013-11-28 19:48:10 39424 ----a-w- c:windowssystem32wpnpinst.exe2013-11-28 19:48:06 278528 ----a-w- c:windowssystem32unregmp2.exe2013-11-28 19:48:02 164352 ----a-w- c:windowssystem32SearchProtocolHost.exe2013-11-28 19:47:58 428032 ----a-w- c:windowssystem32SearchIndexer.exe2013-11-28 19:47:55 86528 ----a-w- c:windowssystem32SearchFilterHost.exe2013-11-28 19:47:51 180736 ----a-w- c:windowssystem32hwrreg.exe2013-11-28 19:47:49 34816 ----a-w- c:windowssystem32hwrcomp.exe2013-11-28 19:45:37 -------- d-----w- c:windowssystem32SPReview2013-11-28 19:45:33 386464 ----a-w- c:windowssystem32spoolprtprocsw32x86TPWinPrn.dll2013-11-28 19:45:30 22528 ----a-w- c:windowssystem32spoolprtprocsw32x86jnwppr.dll2013-11-28 19:43:04 -------- d-----w- c:windowssystem32EventProviders2013-11-28 19:41:00 27136 ----a-w- c:windowssystem32wsepno.dll2013-11-28 19:40:57 182272 ----a-w- c:windowssystem32wmpsrcwp.dll2013-11-28 19:40:53 105472 ----a-w- c:windowssystem32wmpshell.dll2013-11-28 19:40:50 144384 ----a-w- c:windowssystem32wmpps.dll2013-11-28 19:40:44 738816 ----a-w- c:windowssystem32wmpmde.dll2013-11-28 19:39:44 12625408 ----a-w- c:windowssystem32wmploc.DLL2013-11-28 19:39:33 1624064 ----a-w- c:windowssystem32WMPEncEn.dll2013-11-28 19:39:29 352256 ----a-w- c:windowssystem32wmpeffects.dll2013-11-28 19:39:25 299520 ----a-w- c:windowssystem32wmpdxm.dll2013-11-28 19:39:22 170496 ----a-w- c:windowssystem32WmpDui.dll2013-11-28 19:39:19 22528 ----a-w- c:windowssystem32wmpcm.dll2013-11-28 19:38:23 2048 ----a-w- c:windowssystem32wmerror.dll2013-11-28 19:38:20 63088 ----a-w- c:windowssystem32vsocklib.dll2013-11-28 19:38:17 16432 ----a-w- c:windowssystem32vmx_mode.dll2013-11-28 19:38:14 173232 ----a-w- c:windowssystem32vmx_fb.dll2013-11-28 19:38:11 50800 ----a-w- c:windowssystem32vmhgfs.dll2013-11-28 19:38:08 34416 ----a-w- c:windowssystem32vmGuestLibJava.dll2013-11-28 19:38:05 53360 ----a-w- c:windowssystem32vmGuestLib.dll2013-11-28 19:38:01 219248 ----a-w- c:windowssystem32vm3dum.dll2013-11-28 19:37:44 3223152 ----a-w- c:windowssystem32vm3dgl.dll2013-11-28 19:37:35 1548288 ----a-w- c:windowssystem32tquery.dll2013-11-28 19:37:32 111912 ----a-w- c:windowssystem32TPVMW32.dll2013-11-28 19:37:29 9072 ----a-w- c:windowssystem32TPVMMonUIjpn.dll2013-11-28 19:37:27 9064 ----a-w- c:windowssystem32TPVMMonUIdeu.dll2013-11-28 19:37:24 79176 ----a-w- c:windowssystem32TPVMMonUI.dll2013-11-28 19:37:21 9576 ----a-w- c:windowssystem32TPVMMonjpn.dll2013-11-28 19:37:18 23904 ----a-w- c:windowssystem32TPVMMondeu.dll2013-11-28 19:37:14 316736 ----a-w- c:windowssystem32TPVMMon.dll2013-11-28 19:37:09 484192 ----a-w- c:windowssystem32TPSvc.dll2013-11-28 19:37:06 144664 ----a-w- c:windowssystem32tprdpw32.dll2013-11-28 19:37:03 7168 ----a-w- c:windowssystem32sysprepMCE.dll2013-11-28 19:35:58 266752 ----a-w- c:windowssystem32MediaMetadataHandler.dll2013-11-28 19:27:30 -------- d-----w- c:windowsehome2013-11-28 19:17:56 -------- d-----w- c:programdataWeskysoft2013-11-28 19:17:21 -------- d-----w- c:program filesDLLSuite2013-11-20 18:58:45 -------- d-----r- c:program filesSkype2013-11-19 15:35:59 -------- d-----w- c:program filesFinalWire2013-11-13 16:38:00 74512 ----a-w- c:windowssystem32bdsandboxuiskin.dll2013-11-13 16:37:57 27168 ----a-w- c:windowssystem32bdsandboxuh.dll2013-11-13 16:04:42 32256 ----a-w- c:windowssystem32TsUsbGDCoInstaller.dll2013-11-13 16:04:41 53248 ----a-w- c:windowssystem32tsgqec.dll2013-11-13 16:04:41 50176 ----a-w- c:windowssystem32MsRdpWebAccess.dll2013-11-13 16:04:41 49152 ----a-w- c:windowssystem32driversTsUsbFlt.sys2013-11-13 16:04:41 17920 ----a-w- c:windowssystem32wksprtPS.dll2013-11-13 16:04:41 14336 ----a-w- c:windowssystem32TsUsbRedirectionGroupPolicyExtension.dll2013-11-13 16:04:41 12800 ----a-w- c:windowssystem32TsUsbRedirectionGroupPolicyControl.exe2013-11-13 16:04:40 855552 ----a-w- c:windowssystem32rdvidcrl.dll2013-11-13 16:04:40 76288 ----a-w- c:windowssystem32TSWbPrxy.exe2013-11-13 16:04:40 5698048 ----a-w- c:windowssystem32mstscax.dll2013-11-13 16:04:40 350208 ----a-w- c:windowssystem32wksprt.exe2013-11-13 16:04:40 1068544 ----a-w- c:windowssystem32mstsc.exe2013-11-07 21:08:21 -------- d-----w- c:program filesAdblock Plus for IE2013-11-05 17:00:26 -------- d-----w- c:usersandreiappdataroamingTeamViewer2013-11-05 16:55:30 -------- d-----w- c:program filesTeamViewer.==================== Find3M ====================.2013-11-30 08:15:45 16400 ----a-w- c:windowssystem32driversLNonPnP.sys2013-11-28 19:37:03 301568 ----a-w- c:windowssystem32srchadmin.dll2013-11-28 19:35:57 68096 ----a-w- c:windowssystem32Mcx2Svc.dll2013-11-28 19:35:54 87552 ----a-w- c:windowssystem32mcsrchPH.dll2013-11-28 19:35:51 727040 ----a-w- c:windowssystem32mcmde.dll2013-11-28 19:35:45 19968 ----a-w- c:windowssystem32jnwmon.dll2013-11-28 19:35:42 219648 ----a-w- c:windowssystem32iTVData.dll2013-11-28 19:35:39 18944 ----a-w- c:windowssystem32inetppui.dll2013-11-28 19:35:36 126464 ----a-w- c:windowssystem32inetpp.dll2013-11-28 19:35:22 4096 ----a-w- c:windowssystem32dxmasf.dll2013-11-28 19:35:19 18432 ----a-w- c:windowssystem32corpol.dll2013-11-28 19:35:16 73216 ----a-w- c:windowssystem32admparse.dll2013-11-28 19:35:13 131584 ----a-w- c:windowssystem32aaclient.dll2013-11-13 16:37:57 66832 ----a-w- c:windowssystem32driversbdsandbox.sys2013-10-16 05:12:49 94632 ----a-w- c:windowssystem32WindowsAccessBridge.dll2013-10-12 01:57:21 657920 ----a-w- c:windowssystem32nshwfp.dll2013-10-12 01:56:41 681472 ----a-w- c:windowssystem32IKEEXT.DLL2013-10-12 01:56:33 216576 ----a-w- c:windowssystem32FWPUCLNT.DLL2013-10-12 01:55:55 496128 ----a-w- c:windowssystem32BFE.DLL2013-10-08 10:44:55 72704 ----a-w- c:windowssystem32driversbdvedisk.sys2013-10-08 10:22:28 505454 ----a-w- c:programdata1381227585.bdinstall.bin2013-10-08 10:06:39 244742 ----a-w- c:programdata1381226742.bdinstall.bin2013-10-05 19:57:25 1168384 ----a-w- c:windowssystem32crypt32.dll2013-10-04 02:02:25 1796608 ----a-w- c:windowssystem32authui.dll2013-10-04 01:58:50 152576 ----a-w- c:windowssystem32SmartcardCredentialProvider.dll2013-10-04 01:56:25 168960 ----a-w- c:windowssystem32credui.dll2013-10-03 01:58:07 305152 ----a-w- c:windowssystem32gdi32.dll2013-10-02 02:46:11 3072 ----a-w- c:windowssystem32driversen-ustsusbflt.sys.mui2013-09-25 02:01:08 136640 ----a-w- c:windowssystem32driversksecpkg.sys2013-09-25 02:01:06 67520 ----a-w- c:windowssystem32driversksecdd.sys2013-09-25 01:57:53 792576 ----a-w- c:windowssystem32TSWorkspace.dll2013-09-25 01:57:46 99840 ----a-w- c:windowssystem32sspicli.dll2013-09-25 01:57:26 22016 ----a-w- c:windowssystem32secur32.dll2013-09-25 01:57:24 247808 ----a-w- c:windowssystem32schannel.dll2013-09-25 01:56:42 220160 ----a-w- c:windowssystem32ncrypt.dll2013-09-25 01:56:02 1038848 ----a-w- c:windowssystem32lsasrv.dll2013-09-25 00:49:20 22016 ----a-w- c:windowssystem32lsass.exe2013-09-25 00:49:18 15872 ----a-w- c:windowssystem32sspisrv.dll2013-09-24 03:04:56 357432 ----a-w- c:windowssystem32LavasoftProxy.dll2013-09-14 01:51:34 240576 ----a-w- c:windowssystem32driversnetio.sys2013-09-14 00:57:08 338944 ----a-w- c:windowssystem32driversafd.sys2013-09-11 18:21:54 863344 ----a-w- c:windowssystem32msvcr110_clr0400.dll2013-09-11 18:21:54 501872 ----a-w- c:windowssystem32msvcp110_clr0400.dll2013-09-11 18:21:54 28776 ----a-w- c:windowssystem32aspnet_counters.dll2013-09-11 18:21:54 18000 ----a-w- c:windowssystem32msvcr100_clr0400.dll2013-09-08 02:03:58 231424 ----a-w- c:windowssystem32mswsock.dll2013-09-07 02:06:48 1309120 ----a-w- c:windowssystem32driverstcpip.sys2013-09-07 02:06:39 187840 ----a-w- c:windowssystem32driversFWPKCLNT.SYS.============= FINISH: 12:14:48.55 ===============.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows 7 Ultimate Boot Device: DeviceHarddiskVolume1Install Date: 8.3.2013 г. 23:20:55System Uptime: 4.12.2013 г. 12:11:04 (0 hours ago).Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7100Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | Socket 939 | 2500/250mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 112 GiB total, 89.29 GiB free.D: is FIXED (NTFS) - 5 GiB total, 1.916 GiB free.E: is FIXED (NTFS) - 60 GiB total, 53.519 GiB free.F: is FIXED (NTFS) - 634 GiB total, 136.958 GiB free.G: is CDROM ().==== Disabled Device Manager Items =============.==== System Restore Points ===================.No restore point in system..==== Installed Programs ======================.µTorrent13101310_Help1310Trb32 Bit HP CIO Components InstallerAdblock Plus for IEAdblock Plus for IE (32-bit)Adobe Acrobat XI ProAdobe Flash Player 11 ActiveXAdobe Flash Player 11 PluginAdobe Shockwave Player 12.0AIDA64 Extreme v4.00AIO_CDB_ProductContextAIO_CDB_SoftwareAIO_ScanAMD Accelerated Video TranscodingAMD Catalyst Install ManagerAMD Drag and Drop TranscodingAMD FuelAMD Media Foundation DecodersAMD VISION Engine Control CenterAshampoo Burning Studio 2013 v.11.0.5Bitdefender Internet SecurityBufferChmCatalyst Control Center - BrandingCatalyst Control Center Graphics Previews CommonCatalyst Control Center InstallProxyCatalyst Control Center Localization Allccc-utilityCCC Help Chinese StandardCCC Help Chinese TraditionalCCC Help CzechCCC Help DanishCCC Help DutchCCC Help EnglishCCC Help FinnishCCC Help FrenchCCC Help GermanCCC Help GreekCCC Help HungarianCCC Help ItalianCCC Help JapaneseCCC Help KoreanCCC Help NorwegianCCC Help PolishCCC Help PortugueseCCC Help RussianCCC Help SpanishCCC Help SwedishCCC Help ThaiCCC Help TurkishCCleanerCreative Audio Control PanelCreative Sound Blaster PropertiesCyberGhost 5Daum PotPlayer 1.5.40688Definition Update for Microsoft Office 2010 (KB982726) 32-Bit EditionDLL Suite 2013DocProcDriver FusioneRegFlashtoolfoobar2000 v1.2.8GetDizGoogle ChromeHashTab 5.1.0.23HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. BHPPhotoGadgetIntel(R) Update ManagerIntel® SSD ToolboxJava 7 Update 45Java Auto UpdaterLogitech SetPoint 6.61Malwarebytes Anti-Malware, версия 1.75.0.1300Microsoft .NET Framework 4.5.1Microsoft CorporationMicrosoft Mouse and Keyboard CenterMicrosoft Office Access MUI (Bulgarian) 2010Microsoft Office Excel MUI (Bulgarian) 2010Microsoft Office Groove MUI (Bulgarian) 2010Microsoft Office InfoPath MUI (Bulgarian) 2010Microsoft Office OneNote MUI (Bulgarian) 2010Microsoft Office Outlook MUI (Bulgarian) 2010Microsoft Office PowerPoint MUI (Bulgarian) 2010Microsoft Office Professional Plus 2010Microsoft Office Proof (Bulgarian) 2010Microsoft Office Proof (English) 2010Microsoft Office Proof (German) 2010Microsoft Office Proof (Russian) 2010Microsoft Office Proofing (Bulgarian) 2010Microsoft Office Proofing Tools 2013 – българскиMicrosoft Office Publisher MUI (Bulgarian) 2010Microsoft Office Shared MUI (Bulgarian) 2010Microsoft Office Word MUI (Bulgarian) 2010Microsoft SilverlightMicrosoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610MSXML 4.0 SP2 (KB954430)MSXML 4.0 SP2 (KB973688)NetworkNVIDIA DriversOCR Software by I.R.I.S. 13.0Opera 12.16Opera Stable 18.0.1284.49ScanScreamer RadioSecurity Update for Microsoft Excel 2010 (KB2826033) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2553284) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2687423) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2760781) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2826023) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2826035) 32-Bit EditionSecurity Update for Microsoft Outlook 2010 (KB2837597) 32-Bit EditionService Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit EditionSkype™ 6.11Sony Ericsson Update EngineSony PC Companion 2.10.181SUPERAntiSpywareswMSMTAP-Windows 9.9.2TeamViewer 9ToolboxUltraISO Premium V9.6UnCleanerUnloadSupportUpdate for Microsoft Access 2010 (KB2553446) 32-Bit EditionUpdate for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2589298) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2589352) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2589375) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2597087) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2760598) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2760631) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2794737) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2825640) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2826026) 32-Bit EditionUpdate for Microsoft OneNote 2010 (KB2810072) 32-Bit EditionUpdate for Microsoft PowerPoint 2010 (KB2553145) 32-Bit EditionUpdate for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit EditionUpdate for Microsoft Word 2010 (KB2827323) 32-Bit EditionVista Shortcut ManagerVoodooShield version 1.27WebRegWinCDEmuWindows Media Player Firefox PluginWinRAR 5.00 (32-битова версия).==== Event Viewer Messages From Past Week ========.30.11.2013 г. 10:25:34, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:25:32, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:25:32, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:25:31, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:19:25, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:19:24, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:19:24, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:19:23, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:12:29, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:12:27, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:12:27, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:12:26, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:07:34, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:07:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}30.11.2013 г. 10:07:26, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:07:26, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}30.11.2013 г. 10:07:24, Error: Service Control Manager [7026] - Неуспешно зареждане на следния драйвер, който се активира с включване на компютъра или стартиране на системата: avc3 bdselfpr Bhbase discache gzflt SASDIFSV SASKUTIL spldr trufos Wanarpv630.11.2013 г. 10:07:24, Error: Service Control Manager [7001] - Услуга Creative Audio Service зависи от услуга Windows Audio, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.30.11.2013 г. 10:07:24, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 10:07:24, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:51:45, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:51:43, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:51:43, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:51:43, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:34:31, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:34:29, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:34:29, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:34:29, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:27:42, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:27:40, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:27:40, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.30.11.2013 г. 09:27:40, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.3.12.2013 г. 08:43:20, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}3.12.2013 г. 08:39:14, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:14, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:14, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:14, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:14, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:14, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:13, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:13, Error: Service Control Manager [7001] - Услуга Network List Service зависи от услуга Network Location Awareness, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:13, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}3.12.2013 г. 08:39:13, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}3.12.2013 г. 08:39:12, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}3.12.2013 г. 08:39:07, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}3.12.2013 г. 08:39:05, Error: Service Control Manager [7026] - Неуспешно зареждане на следния драйвер, който се активира с включване на компютъра или стартиране на системата: AFD avc3 BdfNdisf bdfwfpf bdselfpr Bhbase CSC DfsC discache gzflt NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr tdx trufos Wanarpv6 WfpLwf ws2ifsl3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга Workstation зависи от услуга Network Store Interface Service, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга SMB MiniRedirector Wrapper and Engine зависи от услуга Redirected Buffering Sub Sysytem, която не може да бъде стартирана поради следната грешка: Свързано към системата устройство не функционира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга SMB 2.0 MiniRedirector зависи от услуга SMB MiniRedirector Wrapper and Engine, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга SMB 1.x MiniRedirector зависи от услуга SMB MiniRedirector Wrapper and Engine, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга Network Store Interface Service зависи от услуга NSI proxy service driver., която не може да бъде стартирана поради следната грешка: Свързано към системата устройство не функционира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга Network Location Awareness зависи от услуга Network Store Interface Service, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга IP Helper зависи от услуга Network Store Interface Service, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга DNS Client зависи от услуга Драйвер за поддържане на TDI при NetIO онаследяване, която не може да бъде стартирана поради следната грешка: Свързано към системата устройство не функционира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга DHCP Client зависи от услуга Ancillary Function Driver for Winsock, която не може да бъде стартирана поради следната грешка: Свързано към системата устройство не функционира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга CyberGhost VPN 5 Client Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.3.12.2013 г. 08:39:05, Error: Service Control Manager [7001] - Услуга Creative Audio Service зависи от услуга Windows Audio, която не може да бъде стартирана поради следната грешка: Подчинената услуга или група не успя да стартира.29.11.2013 г. 22:28:28, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:28:26, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:28:26, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:28:26, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:24:26, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:24:24, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:24:24, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 22:24:23, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 21:49:04, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 21:49:02, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 21:49:02, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 21:49:01, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 17:27:32, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 17:27:30, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 17:27:30, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 17:27:29, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.29.11.2013 г. 08:30:59, Error: Schannel [36888] - The following fatal alert was generated: 43. The internal error state is 552.29.11.2013 г. 08:30:59, Error: Schannel [36876] - The certificate received from the remote server has not validated correctly. The error code is 0x80092013. The SSL connection request has failed. The attached data contains the server certificate.29.11.2013 г. 08:30:56, Error: Schannel [36888] - The following fatal alert was generated: 43. The internal error state is 552.29.11.2013 г. 08:30:56, Error: Schannel [36876] - The certificate received from the remote server has not validated correctly. The error code is 0x80092013. The SSL connection request has failed. The attached data contains the server certificate.29.11.2013 г. 08:30:54, Error: Schannel [36888] - The following fatal alert was generated: 43. The internal error state is 552.29.11.2013 г. 08:30:54, Error: Schannel [36876] - The certificate received from the remote server has not validated correctly. The error code is 0x80092013. The SSL connection request has failed. The attached data contains the server certificate.28.11.2013 г. 21:58:32, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:58:30, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:58:30, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:58:29, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:54:39, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:54:37, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:54:37, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 21:54:36, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 18:09:47, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 18:09:45, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 18:09:45, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 18:09:45, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 08:38:46, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 08:38:44, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 08:38:44, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.28.11.2013 г. 08:38:43, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 21:10:09, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 21:10:06, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 14:52:55, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 14:52:53, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 14:52:53, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 14:52:52, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 08:19:45, Error: Service Control Manager [7001] - Услуга WinHTTP Web Proxy Auto-Discovery Service зависи от услуга DHCP Client, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 08:19:43, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 08:19:43, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея.27.11.2013 г. 08:19:42, Error: Service Control Manager [7001] - Услуга Computer Browser зависи от услуга Server, която не може да бъде стартирана поради следната грешка: Услугата не може да бъде стартирана, защото е дезактивирана или защото няма разрешени устройства, асоциирани с нея..==== End Of File ===========================
  4. Здравейте! От седмица имам проблем с изскачащ прозорец в мозила.Сканирам с МБАМ намира ги изтривам после рестарт,но после пак се появяват. Това са логовете от мбам: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Версия на базата от данни: v2013.08.15.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 ExeLline :: EXELLINE-PC [администратор] 15.8.2013 г. 11:26:44 ч. mbam-log-2013-08-15 (11-26-44).txt Тип сканиране: Пълно сканиране (C:|) Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 101255 Изминало време: 18 минута(и), 56 секунда(и) [прекратено] Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 6 HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{3DDB716A-5C14-03B6-081B-82223FA71070} (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{11EF7518-2D10-5ABE-0BD1-2A9E4A9AFDF6} (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{3F04937B-A06C-8828-D91C-395BD5BB0B16} (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{56147F2A-AAB3-CD67-D00F-D7820B098194} (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{9D57EA34-03E4-1FED-FA67-D44879E9D851} (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{1B6AB280-CFEB-251A-FBAA-F5385CBB1883} (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. Открити стойности в системния регистър: 0 (Не бяха открити зловредни обекти) Открити информационни обекти в системния регистър: 0 (Не бяха открити зловредни обекти) Открити папки: 0 (Не бяха открити зловредни обекти) Открити файлове: 15 C:ADCDA2ADBCD.exe (Spyware.PWS) -> Не беше предприето действие. C:$Recycle.BinS-1-5-21-3179165432-4066499773-424368191-1000$RV0AEA0.exe (Trojan.MSIL) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{2F1EF16B-6AAC-4F82-AD69-228EF4FDD39D}Setup.exe (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{2F1EF16B-6AAC-4F82-AD69-228EF4FDD39D}TsuDll.dll (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{545C5118-0701-4FB2-AD59-4F238FBF73EE}Setup.exe (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{545C5118-0701-4FB2-AD59-4F238FBF73EE}TsuDll.dll (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{80404501-3B88-443D-A6D6-73AA5BA367F7}Setup.exe (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{80404501-3B88-443D-A6D6-73AA5BA367F7}TsuDll.dll (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{81ABC41A-7133-4725-A5CE-39115A48E6EC}Setup.exe (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{81ABC41A-7133-4725-A5CE-39115A48E6EC}TsuDll.dll (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{D083B99F-A4CA-4B93-A978-ECE80B609B69}Setup.exe (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{D083B99F-A4CA-4B93-A978-ECE80B609B69}TsuDll.dll (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{ECE68305-BC12-497A-AB91-F4303705A1F3}Setup.exe (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataInstallMate{ECE68305-BC12-497A-AB91-F4303705A1F3}TsuDll.dll (PUP.Optional.Tarma.A) -> Поставен под карантина и изтрит успешно. C:UsersExeLlineAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5KAT3I3FDsearch_defender_166[1].exe (PUP.Optional.SProtect.A) -> Поставен под карантина и изтрит успешно. (край) Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Версия на базата от данни: v2013.08.14.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 ExeLline :: EXELLINE-PC [администратор] 14.8.2013 г. 13:29:04 ч. mbam-log-2013-08-14 (13-29-04).txt Тип сканиране: Пълно сканиране (C:|) Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 82761 Изминало време: 15 минута(и), 20 секунда(и) [прекратено] Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 0 (Не бяха открити зловредни обекти) Открити стойности в системния регистър: 0 (Не бяха открити зловредни обекти) Открити информационни обекти в системния регистър: 0 (Не бяха открити зловредни обекти) Открити папки: 0 (Не бяха открити зловредни обекти) Открити файлове: 2 C:ADCDA2ADBCD.exe (Spyware.PWS) -> Не беше предприето действие. C:UsersExeLlineAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5RWX1X4KRFJ[1].exe (PUP.Adware.MultiPlug) -> Поставен под карантина и изтрит успешно. (край) Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Версия на базата от данни: v2013.08.14.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 ExeLline :: EXELLINE-PC [администратор] 14.8.2013 г. 13:17:59 ч. mbam-log-2013-08-14 (13-17-59).txt Тип сканиране: Пълно сканиране (C:|) Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 55678 Изминало време: 6 минута(и), 49 секунда(и) [прекратено] Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 0 (Не бяха открити зловредни обекти) Открити стойности в системния регистър: 0 (Не бяха открити зловредни обекти) Открити информационни обекти в системния регистър: 0 (Не бяха открити зловредни обекти) Открити папки: 0 (Не бяха открити зловредни обекти) Открити файлове: 6 C:ADCDA2ADBCD.exe (Spyware.PWS) -> Не беше предприето действие. C:ProgramDataSearchNewTabdI.dll (PUP.Optional.MultiPlug.A) -> Поставен под карантина и изтрит успешно. C:ProgramDataSearchNewTabj1.dll (PUP.Optional.MultiPlugin.A) -> Поставен под карантина и изтрит успешно. C:ProgramDatassavenshareBB3wE3eDE.dll (PUP.Optional.MultiPlugin.A) -> Поставен под карантина и изтрит успешно. C:ProgramDatassavensharewNqvBDltQ.dll (PUP.Optional.MultiPlug.A) -> Поставен под карантина и изтрит успешно. C:UsersExeLlineAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5QBD4QDTVlN4i1A1z_[1].exe (PUP.Adware.MultiPlug) -> Поставен под карантина и изтрит успешно. (край) Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Версия на базата от данни: v2013.08.07.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 ExeLline :: EXELLINE-PC [администратор] 7.8.2013 г. 15:37:44 ч. mbam-log-2013-08-07 (15-37-44).txt Тип сканиране: Бързо сканиране Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 241883 Изминало време: 3 минута(и), 41 секунда(и) Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 2 HKCUSoftwareDC3_FEXEC (Malware.Trace) -> Поставен под карантина и изтрит успешно. HKLMSYSTEMCURRENTCONTROLSETSERVICESWSYSSVC (PUP.Optional.Esafe.A) -> Поставен под карантина и изтрит успешно. Открити стойности в системния регистър: 1 HKLMSYSTEMCurrentControlSetServicesWsysSvc|ImagePath (PUP.Optional.Esafe.A) -> Данни: C:ProgramDataeSafeeGdpSvc.exe -> Поставен под карантина и изтрит успешно. Открити информационни обекти в системния регистър: 0 (Не бяха открити зловредни обекти) Открити папки: 1 C:UsersExeLlineAppDataRoamingdclogs (Stolen.Data) -> Поставен под карантина и изтрит успешно. Открити файлове: 3 C:UsersExeLlineAppDataLocalTempRar$EXa0.776Ram heater.zip (Trojan.Agent) -> Поставен под карантина и изтрит успешно. C:UsersExeLlineAppDataRoamingdclogs2013-08-07-4.dc (Stolen.Data) -> Поставен под карантина и изтрит успешно. C:UsersExeLlineAppDataLocalTempAppLaunchService.exe (Trojan.Agent) -> Поставен под карантина и изтрит успешно. (край) Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Версия на базата от данни: v2013.08.07.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 ExeLline :: EXELLINE-PC [администратор] 7.8.2013 г. 15:19:00 ч. mbam-log-2013-08-07 (15-19-00).txt Тип сканиране: Пълно сканиране (C:|D:|) Включени опции за сканиране: Памет | Автоматично зареждане | Системен регистър | Файлова система | Евристики/Допълнителни | Евристики/Shuriken | PUP | PUM Изключени опции за сканиране: P2P Сканирани обекти: 55489 Изминало време: 7 минута(и), 53 секунда(и) [прекратено] Открити процеси в паметта: 0 (Не бяха открити зловредни обекти) Открити модули в паметта: 0 (Не бяха открити зловредни обекти) Открити ключове в системния регистър: 0 (Не бяха открити зловредни обекти) Открити стойности в системния регистър: 1 HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun|JavaTUdate (Backdoor.Bot) -> Данни: C:UsersExeLlineAppDataRoamingJavaTUdate.exe -> Поставен под карантина и изтрит успешно. Открити информационни обекти в системния регистър: 0 (Не бяха открити зловредни обекти) Открити папки: 0 (Не бяха открити зловредни обекти) Открити файлове: 4 C:ADCDA2ADBCD.exe (Spyware.PWS) -> Не беше предприето действие. C:UsersExeLlineAppDataRoamingJavaTUdate.exe (Backdoor.Bot) -> Поставен под карантина и изтрит успешно. C:$Recycle.BinS-1-5-21-3179165432-4066499773-424368191-1000$R00RAYQ.rar (Backdoor.Bot) -> Поставен под карантина и изтрит успешно. C:$Recycle.BinS-1-5-21-3179165432-4066499773-424368191-1000$R4H6BEG.exe (Backdoor.Bot) -> Поставен под карантина и изтрит успешно. (край) DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.25.2 Run by ExeLline at 9:51:45 on 2013-08-16 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.3948.2958 [GMT 3:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:Windowssystem32wininit.exe C:Windowssystem32lsm.exe C:Windowssystem32svchost.exe -k DcomLaunch C:Windowssystem32svchost.exe -k RPCSS C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted C:Windowssystem32svchost.exe -k netsvcs C:Windowssystem32svchost.exe -k LocalService C:Windowssystem32svchost.exe -k NetworkService C:Windowssystem32WLANExt.exe C:Windowssystem32conhost.exe C:WindowsSystem32spoolsv.exe C:Windowssystem32taskhost.exe C:Windowssystem32Dwm.exe C:Windowssystem32svchost.exe -k LocalServiceNoNetwork C:WindowsExplorer.EXE C:Program Files (x86)Common FilesMicrosoft SharedVS7DEBUGmdm.exe C:Program Files (x86)SafeIPSafeIPs.exe C:Windowssystem32svchost.exe -k imgsvc C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe C:WindowsSysWOW64vmnat.exe C:Program Files (x86)VMwareVMware Workstationvmware-authd.exe C:Windowssystem32wbemwmiprvse.exe C:Program Files (x86)VMwareVMware Workstationvmware-tray.exe C:WindowsSysWOW64vmnetdhcp.exe C:Program Files (x86)Common FilesVMwareUSBvmware-usbarbitrator64.exe C:Program Files (x86)VMwareVMware Workstationvmware-hostd.exe C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation C:Program FilesInternet Download ManagerIEMonitor.exe C:UsersExeLlineAppDataRoamingTepfelWebCakeDesktop.exe C:Windowssystem32conhost.exe C:Program Files (x86)TepfelWebCakeDesktop.Updater.exe C:WindowsSystem32cscript.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uProxyOverride = <local> mWinlogon: Userinit = userinit.exe, BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:Program FilesInternet Download ManagerIDMIECC.dll BHO: WebCake: {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:Program Files (x86)TepfelWebCakeIEClient.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program Files (x86)Javajre7binssv.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre7binjp2ssv.dll uRun: [Akamai NetSession Interface] "C:UsersExeLlineAppDataLocalAkamainetsession_win.exe" uRun: [] C:WindowsSystem32AdopeUpdate.exe uRun: [steam] "C:Program Files (x86)SteamSteam.exe" -silent uRun: [WebCake Desktop] "C:UsersExeLlineAppDataRoamingTepfelWebCakeDesktop.exe" mRun: [vmware-tray.exe] "C:Program Files (x86)VMwareVMware Workstationvmware-tray.exe" uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: Свали всички линкове с IDM - C:Program FilesInternet Download ManagerIEGetAll.htm IE: Свали с IDM - C:Program FilesInternet Download ManagerIEExt.htm IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:Program Files (x86)Microsoft OfficeOffice12ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} LSP: C:WindowsSystem32SafeIPs.dll LSP: %windir%system32vsocklib.dll TCP: NameServer = 192.168.0.1 TCP: Interfaces{8E613240-972D-41B1-BF78-4DF8ECB69BFB} : DHCPNameServer = 192.168.0.1 TCP: Interfaces{8E613240-972D-41B1-BF78-4DF8ECB69BFB}0527F6D2E456470203838333436313332313 : DHCPNameServer = 10.50.8.1 10.1.1.1 TCP: Interfaces{8E613240-972D-41B1-BF78-4DF8ECB69BFB}244736D2B62716B62716 : DHCPNameServer = 192.168.1.1 TCP: Interfaces{8E613240-972D-41B1-BF78-4DF8ECB69BFB}6594651434F4D4F5E45445 : DHCPNameServer = 192.168.1.1 SSODL: WebCheck - <orphaned> x64-BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:Program FilesInternet Download ManagerIDMIECC64.dll x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - C:UsersExeLlineAppDataRoamingMozillaFirefoxProfilesyq16v5y8.default FF - prefs.js: network.proxy.type - 1 FF - component: C:UsersExeLlineAppDataRoamingIDMidmmzcc5componentsidmmzcc.dll FF - plugin: C:Program Files (x86)Javajre7binplugin2npjp2.dll FF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32_11_8_800_94.dll FF - plugin: C:WindowsSysWOW64npDeployJava1.dll FF - plugin: C:WindowsSysWOW64npmproxy.dll . ---- FIREFOX POLICIES ---- user_pref(extensions.dntp.origin,'yotamfull_amo'); user_pref(extensions.poweraddon.cid,647); FF - user.js: extentions.webcake.installId - 3a8a100f-2240-42cb-8fe7-1e56b245c4d7 FF - user.js: extentions.webcake.defaultEnableAppsList - layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wc . ============= SERVICES / DRIVERS =============== . R?2 WebCakeUpdater;WebCakeUpdater;C:Program Files (x86)TepfelWebCakeDesktop.Updater.exe [2013-8-16 51992] R0 nvpciflt;nvpciflt;C:WindowsSystem32driversnvpciflt.sys [2013-2-6 30648] R0 oem-drv64;OEM-SLP2.1 Driver (HPD64);C:WindowsSystem32driversoem-drv64.sys [2013-2-6 42496] R0 vsock;vSockets Driver;C:WindowsSystem32driversvsock.sys [2013-8-11 70296] R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32driversvwififlt.sys [2009-7-14 59904] R2 IDMWFP;IDMWFP;C:WindowsSystem32driversidmwfp.sys [2013-4-5 166576] R2 SafeIPS;SafeIPS;C:Program Files (x86)SafeIPSafeIPS.exe [2013-8-10 3860480] R2 TeamViewer8;TeamViewer 8;C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe [2013-4-30 4153184] R2 VMUSBArbService;VMware USB Arbitration Service;C:Program Files (x86)Common FilesVMwareUSBvmware-usbarbitrator64.exe [2012-10-11 918680] R2 VMwareHostd;VMware Workstation Server;C:Program Files (x86)VMwareVMware Workstationvmware-hostd.exe [2012-11-1 13234176] R3 b57xdbd;Broadcom xD Picture Bus Driver Service;C:WindowsSystem32driversb57xdbd.sys [2011-1-20 67624] R3 b57xdmp;Broadcom xD Picture vstorp client drv;C:WindowsSystem32driversb57xdmp.sys [2011-1-20 19496] R3 bScsiMSa;bScsiMSa;C:WindowsSystem32driversbScsiMSa.sys [2011-5-16 51240] R3 bScsiSDa;bScsiSDa;C:WindowsSystem32driversbScsiSDa.sys [2011-5-6 86056] R3 ETD;ELAN PS/2 Port Input Device;C:WindowsSystem32driversETD.sys [2011-4-5 142632] R3 IntcDAud;Intel® Display Audio;C:WindowsSystem32driversIntcDAud.sys [2010-10-15 317440] R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:WindowsSystem32driversk57nd60a.sys [2011-5-9 425000] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576] S2 cpuz135;cpuz135;C:WindowsSystem32driverscpuz135_x64.sys [2013-8-2 21992] S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2010-11-21 71168] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2010-11-21 20992] S3 Synth3dVsc;Synth3dVsc;C:WindowsSystem32driversSynth3dVsc.sys [2010-11-21 88960] S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32driversterminpt.sys [2010-11-21 34816] S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-21 31232] S3 tsusbhub;tsusbhub;C:WindowsSystem32driverstsusbhub.sys [2010-11-21 117248] S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2013-2-6 257416] S4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe [2013-2-6 13592] S4 nvUpdatusService;NVIDIA Update Service Daemon;C:Program Files (x86)NVIDIA CorporationNVIDIA Update Coredaemonu.exe [2013-2-6 1260472] . =============== File Associations =============== . FileExt: .txt: txtfile=C:WindowsSystem32NOTEPAD.EXE %1 [userChoice] . =============== Created Last 30 ================ . 2013-08-16 06:51:37 -------- d-----w- C:UsersExeLlineAppDataRoamingTepfel 2013-08-16 06:51:37 -------- d-----w- C:Program Files (x86)SimilarSites 2013-08-16 06:51:36 -------- d-----w- C:Program Files (x86)Tepfel 2013-08-16 06:51:33 -------- d-----w- C:UsersExeLlineAppDataRoamingSimilarSites 2013-08-16 06:51:28 -------- d-----w- C:ProgramDataTarma Installer 2013-08-14 07:47:54 -------- d-----w- C:Program Files (x86)Steam 2013-08-11 12:56:00 -------- d-----w- C:UsersExeLlineAppDataLocalVMware 2013-08-11 10:53:50 70296 ----a-w- C:WindowsSystem32driversvsock.sys 2013-08-11 10:53:50 67224 ----a-w- C:WindowsSystem32vsocklib.dll 2013-08-11 10:53:50 63128 ----a-w- C:WindowsSysWow64vsocklib.dll 2013-08-11 10:53:48 67224 ----a-w- C:WindowsSystem32driversvmx86.sys 2013-08-11 10:53:21 357016 ----a-w- C:WindowsSysWow64vmnetdhcp.exe 2013-08-11 10:53:17 435864 ----a-w- C:WindowsSysWow64vmnat.exe 2013-08-11 10:53:17 30360 ----a-w- C:WindowsSystem32driversvmnetuserif.sys 2013-08-11 10:53:14 933528 ----a-w- C:WindowsSystem32vnetlib64.dll 2013-08-11 10:53:11 52376 ----a-w- C:WindowsSystem32drivershcmon.sys 2013-08-11 10:52:51 -------- d-----w- C:Program FilesCommon FilesVMware 2013-08-11 10:52:28 -------- d-----w- C:Program Files (x86)VMware 2013-08-11 10:52:28 -------- d-----w- C:Program Files (x86)Common FilesVMware 2013-08-10 13:41:10 534016 ----a-w- C:WindowsSystem32SafeIPs64.dll 2013-08-10 13:41:08 373760 ----a-w- C:WindowsSysWow64SafeIPs.dll 2013-08-10 13:41:07 -------- d-----w- C:Program Files (x86)SafeIP 2013-08-09 12:46:01 -------- d-----w- C:Program Files (x86)SaveShare 2013-08-07 12:11:31 148480 ----a-w- C:WindowsSysWow64AdopeUpdate.exe 2013-08-03 07:39:51 -------- d-----w- C:Program Files (x86)dumps 2013-08-03 07:39:33 -------- d-----w- C:Program Files (x86)Common FilesSteam 2013-08-02 10:05:46 21992 ----a-w- C:WindowsSystem32driverscpuz135_x64.sys 2013-08-02 10:05:46 -------- d-----w- C:Program FilesCPUID 2013-08-02 10:04:05 -------- d-----w- C:UsersExeLlineAppDataRoamingNVIDIA 2013-07-28 10:38:12 -------- d-----w- C:WindowsERUNT 2013-07-27 19:47:55 773712 ----a-w- C:WindowsSysWow64msvcr100.dll 2013-07-27 19:47:55 420944 ----a-w- C:WindowsSysWow64msvcp100.dll 2013-07-23 10:59:53 -------- d-----w- C:Program Files (x86)Counter-Strike 1.6 2013-07-21 11:08:52 -------- d-s---w- C:WindowsSysWow64Microsoft 2013-07-19 10:11:16 96168 ----a-w- C:WindowsSysWow64WindowsAccessBridge-32.dll . ==================== Find3M ==================== . 2013-08-15 15:38:41 6656 ----a-w- C:WindowsSystem32lpcio.dll 2013-08-15 10:57:02 42496 ----a-w- C:WindowsSystem32driversoem-drv64.sys 2013-07-19 10:11:10 867240 ----a-w- C:WindowsSysWow64npDeployJava1.dll 2013-07-19 10:11:10 789416 ----a-w- C:WindowsSysWow64deployJava1.dll 2013-07-10 14:13:39 71048 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl 2013-07-10 14:13:39 692104 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe . ============= FINISH: 9:52:18,11 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Ultimate Boot Device: DeviceHarddiskVolume1 Install Date: 6.2.2013 г. 10:55:09 System Uptime: 15.8.2013 г. 13:57:00 (20 hours ago) . Motherboard: Acer | | JE50_HR Processor: Intel® Core i3-2310M CPU @ 2.10GHz | CPU1 | 798/1333mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 45 GiB total, 6,579 GiB free. D: is FIXED (NTFS) - 551 GiB total, 84,03 GiB free. E: is CDROM () F: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet1 Device ID: ROOTVMWARE0000 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet1 PNP Device ID: ROOTVMWARE0000 Service: VMnetAdapter . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet8 Device ID: ROOTVMWARE0001 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet8 PNP Device ID: ROOTVMWARE0001 Service: VMnetAdapter . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . µTorrent Acer Crystal Eye Webcam Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin AIMP2 AMX Mod X Installer 1.8.1 AWC V4.7 Broadcom 802.11 Network Adapter Broadcom Card Reader Driver Installer Broadcom NetLink Controller CCleaner CDBurnerXP Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Counter-Strike Counter Strike 1.6 p48 build 4554 2.1 CPUID HWMonitor Pro 1.11 CrystalDiskInfo 5.6.2 Shizuku Edition ETDWare PS/2-X64 8.0.6.3_WHQL Favorite-Games 5.22 FileZilla Client 3.7.2 Foxit Phantom Intel® Processor Graphics Intel® Rapid Storage Technology Internet Download Manager Java 7 Update 25 Java Auto Updater Java 7 Update 4 (64-bit) Malwarebytes Anti-Malware, версия 1.75.0.1300 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Office Access MUI (Bulgarian) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (Bulgarian) 2007 Microsoft Office Groove MUI (Bulgarian) 2007 Microsoft Office InfoPath MUI (Bulgarian) 2007 Microsoft Office Office 64-bit Components 2007 Microsoft Office OneNote MUI (Bulgarian) 2007 Microsoft Office Outlook MUI (Bulgarian) 2007 Microsoft Office PowerPoint MUI (Bulgarian) 2007 Microsoft Office Proof (Bulgarian) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proof (Russian) 2007 Microsoft Office Proofing (Bulgarian) 2007 Microsoft Office Publisher MUI (Bulgarian) 2007 Microsoft Office Shared 64-bit MUI (Bulgarian) 2007 Microsoft Office Shared MUI (Bulgarian) 2007 Microsoft Office Word MUI (Bulgarian) 2007 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox 12.0 (x86 bg) Notepad++ NVIDIA Control Panel 310.90 NVIDIA Graphics Driver 310.90 NVIDIA Install Application NVIDIA Optimus 1.11.3 NVIDIA PhysX NVIDIA PhysX System Software 9.12.1031 NVIDIA Update Components Realtek High Definition Audio Driver SafeIP Skype™ 3.8 Steam TeamViewer 8 The KMPlayer (remove only) tools-freebsd tools-linux tools-netware tools-solaris tools-windows tools-winPre2k uGet, версия 2.0.8 VCDS-Lite 1.2 VirtualCloneDrive VLC media player 2.0.1 VMware Workstation Web-Cake 3.00 WinRAR 4.20 beta 3 (64-bit) . ==== Event Viewer Messages From Past Week ======== . 15.8.2013 г. 19:46:15, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 19:45:44, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 19:37:40, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 18:54:47, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 18:49:18, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 18:23:13, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 17:52:40, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 17:37:12, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:28:54, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 16:28:54, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:28:54, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:28:54, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:10:18, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 16:10:18, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:10:18, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:02:27, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 16:00:18, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 15:58:03, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 15:01:31, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 14:44:04, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 14:43:03, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 14:43:03, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:57:33, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 13:57:33, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:57:19, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:47:42, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:47:29, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:45:52, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:45:33, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:44:59, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:44:38, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:44:38, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:44:09, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 13:34:06, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 12:50:46, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 12:50:46, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 12:50:32, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 12:42:43, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 12:42:43, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 12:36:36, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 12:25:53, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 11:50:34, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 11:50:34, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 11:50:25, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 09:30:31, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. 15.8.2013 г. 09:30:31, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. 15.8.2013 г. 09:30:31, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. 15.8.2013 г. 09:30:31, Error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the computer that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. 15.8.2013 г. 09:09:27, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 09:06:05, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 09:05:54, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:50:39, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:50:22, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:50:22, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:44:41, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 08:44:41, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:44:41, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:41:16, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 08:41:16, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:41:16, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:39:49, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 08:39:49, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 08:39:49, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 03:02:27, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 15.8.2013 г. 03:02:27, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 15.8.2013 г. 03:02:27, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 14.8.2013 г. 20:46:24, Error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{8E613240-972D-41B1-BF78-4DF8ECB69BFB} because another computer on the network has the same name. The server could not start. 14.8.2013 г. 20:46:24, Error: NetBT [4321] - The name "EXELLINE-PC :20" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 14.8.2013 г. 20:46:24, Error: NetBT [4321] - The name "EXELLINE-PC :0" could not be registered on the interface with IP address 192.168.0.3. The computer with the IP address 192.168.0.4 did not allow the name to be claimed by this computer. 14.8.2013 г. 18:26:26, Error: Service Control Manager [7031] - The TeamViewer 8 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 2000 milliseconds: Restart the service. . ==== End Of File ===========================
  5. Здравейте колеги Ей така си инсталирах Malwarebytes Anti-Malware да видя дали ще намери вируси и то зе, че намери с бърза проверка 9 вируса Сега какво да правя С Windows 8 съм без антивирусна
  6. Здравейте, роднина ме помоли да му помогна ако мога с лаптопа. Проблема му е, че като цяло работи бавно и това, което ми направи на мен впечатление, е че онзи ден, когато свързах чисто нова флашка с лаптопа тя се зарази с вирус(по късно при пускане на флашката на друг компютър излезна проблемаю) Ето FRST.txt Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-01-2014 03Ran by ADV (administrator) on DELL on 26-01-2014 22:47:53Running from C:Documents and SettingsADVMy DocumentsDownloadsMicrosoft Windows XP Professional Service Pack 2 (X86) OS Language: English(US)Internet Explorer Version 6Boot Mode: NormalThe only official download link for FRST:Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated.See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) ===================() C:WINDOWSsystem32WLTRYSVC.EXE(Dell Inc.) C:WINDOWSsystem32BCMWLTRY.EXE(IDT, Inc.) C:Program FilesIDTXPM09_6047v002WDMstacsv.exe(ReviverSoft LLC) C:Program FilesReviverSoftRegistry ReviverRegistryReviver.exe(Dell Inc.) C:WINDOWSsystem32WLTRAY.EXE(MindSpark) C:Program FilesVideoDownloadConverter_4zbar1.bin4zSrchMn.exe(MindSpark) C:Program FilesFromDocToPDF_65bar1.bin65SrchMn.exe(RealNetworks, Inc.) C:Program FilesRealRealPlayerUpdaterealsched.exe(BitTorrent, Inc.) C:Program FilesuTorrentuTorrent.exe(SqueakyChocolate, LLC) C:Program FilesSqueakyChocolateUpdateCheckerUpdateCheckerApp.exe() C:WINDOWSDatecsFlex2K.exe(McAfee, Inc.) C:Program FilesMcAfee Security Scan3.8.130SSScheduler.exe(Apple Inc.) C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe(Microsoft Corporation) C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE(Apple Inc.) C:Program FilesBonjourmDNSResponder.exe(Ciela Soft And Publishing) C:Program FilesCielaCiela 5.0ServerCielaServer.exe(Firebird Project) C:Program FilesCielaCiela 5.0ServerFirebird-2.1.2.18118-0_Win32binfbserver.exe(Freemake) C:Documents and SettingsAll UsersApplication DataFreemakeFreemakeUtilsServiceFreemakeUtilsService.exe(Oracle Corporation) C:Program FilesJavajre7binjqs.exe(Microsoft Corporation) C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGmdm.exe() C:Program FilesT-MobileConnection ManagerBackgroundServiceServiceManager.exe() C:Program FilesHTCInternet Pass-ThroughPassThruSvr.exe(TuneUp Software) C:Program FilesTuneUp Utilities 2013TuneUpUtilitiesService32.exe() C:Program FilesM-Tel NETAGENTAssistantServices.exe(TuneUp Software) C:Program FilesTuneUp Utilities 2013TuneUpUtilitiesApp32.exe(Microsoft Corporation) C:WINDOWSsystem32wscntfy.exe(Mozilla Corporation) C:Program FilesMozilla Firefoxfirefox.exe(Mozilla Corporation) C:Program FilesMozilla Firefoxplugin-container.exe==================== Registry (Whitelisted) ==================HKLM...Run: [Broadcom Wireless Manager UI] - C:WINDOWSsystem32WLTRAY.exe [2289664 2008-11-26] (Dell Inc.)HKLM...Run: [VideoDownloadConverter Search Scope Monitor] - C:Program FilesVideoDownloadConverter_4zbar1.bin4zSrchMn.exe [44784 2013-09-29] (MindSpark)HKLM...Run: [FromDocToPDF Search Scope Monitor] - C:Program FilesFromDocToPDF_65bar1.bin65SrchMn.exe [42536 2013-04-07] (MindSpark)HKLM...Run: [TkBellExe] - C:Program FilesRealRealPlayerupdaterealsched.exe [295512 2013-11-02] (RealNetworks, Inc.)HKLM...Run: [APSDaemon] - C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe [59720 2013-04-21] (Apple Inc.)HKCU...Run: [uTorrent] - C:Program FilesuTorrentuTorrent.exe [1020816 2012-06-17] (BitTorrent, Inc.)HKCU...Run: [UpdateChecker] - C:Program FilesSqueakyChocolateUpdateCheckerUpdateCheckerApp.exe [7168 2013-08-25] (SqueakyChocolate, LLC)HKCU...Run: [NextLive] - C:Documents and SettingsADVApplication Datanewnext.menengine.dll [1283584 2013-11-14] (NewNextDotMe)MountPoints2: {1db17f4a-b2d1-11e1-895e-b25bfb460082} - I:NAUCIO///takabila.exeMountPoints2: {22d5ade4-5992-11e2-8a06-00225f8858e2} - D:MountPoints2: {27884e0c-7a98-11e1-8911-0023ae2b38ff} - D:AutoRun.exeMountPoints2: {358587e4-6522-11e1-88ee-00225f8858e2} - D:AutoRun.exeMountPoints2: {3acd81c4-5952-11e1-88de-00225f8858e2} - D:AutoRun.exeMountPoints2: {3acd81c7-5952-11e1-88de-00225f8858e2} - D:AutoRun.exeMountPoints2: {570884bd-8bca-11e1-8928-001e101feb89} - J:NAUCIO///takabila.exeMountPoints2: {5aa5ebd6-f775-11e2-8a81-00225f8858e2} - D:Autorun.exeMountPoints2: {5b634fb6-348d-11e1-88b7-00225f8858e2} - H:NAUCIO///takabila.exeMountPoints2: {5b634fb7-348d-11e1-88b7-00225f8858e2} - D:Install_Nokia_Ovi_Suite.exeMountPoints2: {613153bf-13d2-11e2-89cf-00225f8858e2} - H:NAUCIO///takabila.exeMountPoints2: {81d7875c-4121-11e1-88c2-00225f8858e2} - D:NAUCIO///takabila.exeMountPoints2: {bfecfe06-160a-11e2-89d6-00225f8858e2} - D:Startme.exeMountPoints2: {ec981daa-85c7-11e3-8b19-00225f8858e2} - D:NAUCIO///takabila.exeMountPoints2: {f077b58e-57c6-11e1-88da-00225f8858e2} - D:AutoRun.exeMountPoints2: {f077b591-57c6-11e1-88da-00225f8858e2} - D:AutoRun.exeStartup: C:Documents and SettingsADVStart MenuProgramsStartupOneNote 2007 Screen Clipper and Launcher.lnkShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE (Microsoft Corporation)Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupFlexType 2K.lnkShortcutTarget: FlexType 2K.lnk -> C:WINDOWSDatecsFlex2K.exe ()Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupMcAfee Security Scan Plus.lnkShortcutTarget: McAfee Security Scan Plus.lnk -> C:Program FilesMcAfee Security Scan3.8.130SSScheduler.exe (McAfee, Inc.)==================== Internet (Whitelisted) ====================HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://search.conduit.com?SearchSource=10&CUI=UN40251725102757373&UM=2&ctid=CT3282309HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchHKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = %SystemRoot%system32blank.htmHKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhomeHKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchHKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchHKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://websearch.simplespeedy.info/URLSearchHook: HKCU - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No FileURLSearchHook: HKCU - (No Name) - {e5593220-bcaf-4b30-89fe-af988d0eacaa} - No FileURLSearchHook: HKCU - (No Name) - {4c60e5ab-5c68-4c59-abaa-885010b24b32} - C:Program FilesFromDocToPDF_65bar1.bin65SrcAs.dll (MindSpark)URLSearchHook: HKCU - (No Name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:Program FilesVideoDownloadConverter_4zbar1.bin4zSrcAs.dll (MindSpark)URLSearchHook: HKCU - FreemakeGoldTB Toolbar - {7295d29e-90f4-4fa5-99c1-0168b51ac61b} - C:Program FilesFreemakeGoldTBprxtbFre1.dll (Conduit Ltd.)SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.simplespeedy.info/?l=1&q={searchTerms}SearchScopes: HKCU - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3282309&CUI=UN40251725102757373&UM=2SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=IJBME&o=102809&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=4M&apn_dtid=YYYYYYSHBG&apn_uid=E38D5369-293E-44B4-9EEA-3C8408B3E668&apn_sauid=E93915D2-5BA0-4693-A545-4C551EFF114DSearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3282309&CUI=UN40251725102757373&UM=2SearchScopes: HKCU - {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = http://eu.ask.com/web?l=dis&o=APN10019&gct=sb&qsrc=2869&apn_dtid=^YYYYYY^YY^BG&apn_ptnrs=^A4L &apn_uid=7061540000194139&p2=^A4L ^YYYYYY^YY^BG&q={searchTerms}SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.simplespeedy.info/?l=1&q={searchTerms}SearchScopes: HKCU - {DCDBBF03-BC10-457D-911F-EFB0321D22BE} URL = ${SRCH_SCP_URL}BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:Program FilesMcAfee Security Scan3.8.130McAfeeMSS_IE.dll (McAfee, Inc.)BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll (Adobe Systems Incorporated)BHO: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:Program FilesVideoDownloadConverter_4zbar1.bin4zbar.dll (MindSpark)BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll (Microsoft Corporation)BHO: FreemakeGoldTB Toolbar - {7295d29e-90f4-4fa5-99c1-0168b51ac61b} - C:Program FilesFreemakeGoldTBprxtbFre1.dll (Conduit Ltd.)BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll (Oracle Corporation)BHO: Toolbar BHO - {a235e1e3-6296-4710-af39-104a7faa6c7c} - C:Program FilesFromDocToPDF_65bar1.bin65bar.dll (MindSpark)BHO: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:Program FilesVideoDownloadConverter_4zbar1.bin4zSrcAs.dll (MindSpark)BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll (Oracle Corporation)BHO: SmileysWeLoveToolbar - {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - C:Program FilesSmileys We Love Toolbar for IEadxloader.dll ()BHO: Search Assistant BHO - {f236ca79-3123-4afb-9f74-e98117ad5625} - C:Program FilesFromDocToPDF_65bar1.bin65SrcAs.dll (MindSpark)Toolbar: HKLM - FromDocToPDF - {c66a678d-5e6c-4af9-8f57-c6192f42cf74} - C:Program FilesFromDocToPDF_65bar1.bin65bar.dll (MindSpark)Toolbar: HKLM - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No FileToolbar: HKLM - VideoDownloadConverter - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:Program FilesVideoDownloadConverter_4zbar1.bin4zbar.dll (MindSpark)Toolbar: HKLM - FreemakeGoldTB Toolbar - {7295d29e-90f4-4fa5-99c1-0168b51ac61b} - C:Program FilesFreemakeGoldTBprxtbFre1.dll (Conduit Ltd.)Toolbar: HKLM - SmileysWeLove - {CF0F43AB-9C23-4D7B-8040-201B82844854} - C:Program FilesSmileys We Love Toolbar for IEadxloader.dll ()Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:WINDOWSsystem32browseui.dll (Microsoft Corporation)Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:WINDOWSsystem32SHELL32.dll (Microsoft Corporation)Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No FileToolbar: HKCU - FromDocToPDF - {C66A678D-5E6C-4AF9-8F57-C6192F42CF74} - C:Program FilesFromDocToPDF_65bar1.bin65bar.dll (MindSpark)Toolbar: HKCU - VideoDownloadConverter - {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:Program FilesVideoDownloadConverter_4zbar1.bin4zbar.dll (MindSpark)Toolbar: HKCU - FreemakeGoldTB Toolbar - {7295D29E-90F4-4FA5-99C1-0168B51AC61B} - C:Program FilesFreemakeGoldTBprxtbFre1.dll (Conduit Ltd.)DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/bg/Core/Player/2020PlayerAX_IKEA_Win32.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabHandler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:Program FilesMicrosoft OfficeOffice12GrooveSystemServices.dll (Microsoft Corporation)Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies)Winsock: Catalog5 04 C:Program FilesBonjourmdnsNSP.dll [121704] (Apple Inc.)TcpipParameters: [DhcpNameServer] 192.168.0.1Tcpip..Interfaces{AFE50EDA-3E77-414B-AA89-064FFBFFF515}: [NameServer]89.190.192.247,89.190.192.248FireFox:========FF ProfilePath: C:Documents and SettingsADVApplication DataMozillaFirefoxProfilesu4xk9lze.defaultFF user.js: detected! => C:Documents and SettingsADVApplication DataMozillaFirefoxProfilesu4xk9lze.defaultuser.jsFF DefaultSearchEngine: FreemakeGoldTB Customized Web SearchFF SelectedSearchEngine: FreemakeGoldTB Customized Web SearchFF Homepage: hxxp://search.conduit.com/?ctid=CT3282309&CUI=UN35247875342146228&UM=2&SearchSource=13FF Plugin: @adobe.com/FlashPlayer - C:WINDOWSsystem32MacromedFlashNPSWF32_11_9_900_170.dll ()FF Plugin: @Apple.com/iTunes,version=1.0 - C:Program FilesiTunesMozilla Pluginsnpitunes.dll ()FF Plugin: @FromDocToPDF_65.com/Plugin - C:Program FilesFromDocToPDF_65bar1.binNP65Stub.dll (MindSpark)FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:WINDOWSsystem32npDeployJava1.dll (Oracle Corporation)FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:Program FilesJavajre7binplugin2npjp2.dll (Oracle Corporation)FF Plugin: @mcafee.com/McAfeeMssPlugin - C:Program FilesMcAfee Security Scan3.8.130npMcAfeeMss.dll (McAfee, Inc.)FF Plugin: @microsoft.com/WPF,version=3.5 - C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)FF Plugin: @real.com/nppl3260;version=16.0.3.51 - C:Program FilesRealRealPlayerNetscape6nppl3260.dll (RealNetworks, Inc.)FF Plugin: @real.com/nprpplugin;version=16.0.3.51 - C:Program FilesRealRealPlayerNetscape6nprpplugin.dll (RealPlayer)FF Plugin: @VideoDownloadConverter_4z.com/Plugin - C:Program FilesVideoDownloadConverter_4zbar1.binNP4zStub.dll (MindSpark)FF Plugin: Adobe Reader - C:Program FilesAdobeReader 9.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)FF SearchPlugin: C:Documents and SettingsADVApplication DataMozillaFirefoxProfilesu4xk9lze.defaultsearchpluginsaskcom.xmlFF SearchPlugin: C:Documents and SettingsADVApplication DataMozillaFirefoxProfilesu4xk9lze.defaultsearchpluginsconduit.xmlFF SearchPlugin: C:Program Filesmozilla firefoxsearchpluginsask.xmlFF Extension: FreemakeGoldTB - C:Documents and SettingsADVApplication DataMozillaFirefoxProfilesu4xk9lze.defaultExtensions{7295d29e-90f4-4fa5-99c1-0168b51ac61b} [2013-12-22]FF Extension: SmileysWeLove: Smileys for use with Facebook, GMail, and more - C:Documents and SettingsADVApplication DataMozillaFirefoxProfilesu4xk9lze.defaultExtensionsjid1-vW9nopuIAJiRHw@jetpack.xpi [2013-11-02]FF HKLM...FirefoxExtensions: [65ffxtbr@FromDocToPDF_65.com] - C:Program FilesFromDocToPDF_65bar1.binFF Extension: FromDocToPDF - C:Program FilesFromDocToPDF_65bar1.bin [2013-04-07]FF HKLM...FirefoxExtensions: [ff-bmboc@bytemobile.com] - C:Program FilesT-MobileConnection ManageraddonFF Extension: Bytemobile Optimization Client - C:Program FilesT-MobileConnection Manageraddon [2013-07-28]FF HKLM...FirefoxExtensions: [4zffxtbr@VideoDownloadConverter_4z.com] - C:Program FilesVideoDownloadConverter_4zbar1.binFF Extension: VideoDownloadConverter - C:Program FilesVideoDownloadConverter_4zbar1.bin [2013-09-29]FF HKLM...FirefoxExtensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtensionFF Extension: Microsoft .NET Framework Assistant - C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtension []Chrome: =======CHR HomePage: hxxp://websearch.simplespeedy.info/CHR RestoreOnStartup: "hxxp://websearch.simplespeedy.info/"CHR Extension: (coaNtinuettosave) - C:Documents and SettingsADVLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsaehaadobfemdjkfmobancnblnpgkeecn [2013-03-10]CHR Extension: (Free Smileys & Emoticons) - C:Documents and SettingsADVLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsfjbbjfdilbioabojmcplalojlmdngbjl [2013-11-02]CHR HKLM...ChromeExtension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:Documents and SettingsADVApplication DataBabSolutionCRDelta.crx [2013-09-29]========================== Services (Whitelisted) =================R2 CielaServerService; C:Program FilesCielaCiela 5.0ServerCielaServer.exe [208896 2009-09-07] (Ciela Soft And Publishing)R2 FirebirdServerFirebird 2.1 Ciela; C:Program FilesCielaCiela 5.0ServerFirebird-2.1.2.18118-0_Win32binfbserver.exe [2732032 2009-02-28] (Firebird Project)R2 Freemake Improver; C:Documents and SettingsAll UsersApplication DataFreemakeFreemakeUtilsServiceFreemakeUtilsService.exe [96768 2012-07-13] (Freemake)S2 FromDocToPDF_65Service; C:Program FilesFromDocToPDF_65bar1.bin65barsvc.exe [42504 2013-04-07] (COMPANYVERS_NAME)R2 JavaQuickStarterService; C:Program FilesJavajre7binjqs.exe [161768 2012-10-12] (Oracle Corporation)S3 McComponentHostService; C:Program FilesMcAfee Security Scan3.8.130McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.)R2 Modem Device Helper; C:Program FilesT-MobileConnection ManagerBackgroundServiceServiceManager.exe [51576 2012-04-25] ()R2 PassThru Service; C:Program FilesHTCInternet Pass-ThroughPassThruSvr.exe [166912 2012-10-08] ()S3 Sony PC Companion; C:Program FilesSonySony PC CompanionPCCService.exe [155824 2013-02-04] (Avanquest Software)R2 STacSV; c:program filesidtxpm09_6047v002wdmSTacSV.exe [225362 2008-07-21] (IDT, Inc.)R2 TuneUp.UtilitiesSvc; C:Program FilesTuneUp Utilities 2013TuneUpUtilitiesService32.exe [1729336 2013-12-10] (TuneUp Software)R2 UI Assistant Service; C:Program FilesM-Tel NETAGENTAssistantServices.exe [267088 2011-06-09] ()S2 VideoDownloadConverter_4zService; C:Program FilesVideoDownloadConverter_4zbar1.bin4zbarsvc.exe [42504 2013-09-29] (COMPANYVERS_NAME)R2 wltrysvc; C:WINDOWSSystem32bcmwltry.exe [2039808 2008-11-26] (Dell Inc.)R2 yksvc; RUNDLL32.EXE ykx32coinst,serviceStartProc [x]==================== Drivers (Whitelisted) ====================R3 AESTAud; C:WINDOWSSystem32driversAESTAud.sys [108160 2008-07-11] (Andrea Electronics Corporation)R1 APPDRV; C:WINDOWSSYSTEM32DRIVERSAPPDRV.SYS [16128 2008-10-04] (Dell Inc)R3 BCM43XX; C:WINDOWSSystem32DRIVERSbcmwl5.sys [1391104 2008-11-26] (Broadcom Corporation)S3 CCDECODE; C:WINDOWSSystem32DRIVERSCCDECODE.sys [17024 2004-08-04] (Microsoft Corporation)R0 imagedrv; C:WINDOWSSystem32Driversimagedrv.sys [5504 2004-03-02] (Ahead Software AG)R0 imagesrv; C:WINDOWSSystem32DRIVERSimagesrv.sys [125184 2004-03-02] (Ahead Software AG)S3 jrdusbser; C:WINDOWSSystem32DRIVERSjrdusbser.sys [105344 2011-08-05] (TCT International Mobile Ltd)S3 massfilter; C:WINDOWSSystem32driversmassfilter.sys [9216 2011-03-26] (MBB Incorporated)S3 NdisIP; C:WINDOWSSystem32DRIVERSNdisIP.sys [10880 2004-08-04] (Microsoft Corporation)R3 OA009Afx; C:WINDOWSsystem32DriversOA009Afx.sys [148056 2007-06-08] (Creative Technology Ltd.)R3 OA009Ufd; C:WINDOWSSystem32DRIVERSOA009Ufd.sys [144544 2008-10-06] (Creative Technology Ltd.)R3 OA009Vid; C:WINDOWSSystem32DRIVERSOA009Vid.sys [268992 2008-10-07] (Creative Technology Ltd.)R3 RSUSBSTOR; C:WINDOWSSystem32DriversRTS5121.sys [157696 2008-08-26] (Realtek Semiconductor Corp.)S3 Secdrv; C:WINDOWSSystem32DRIVERSsecdrv.sys [27440 2004-07-17] ()R3 STHDA; C:WINDOWSSystem32driverssthda.sys [1384595 2008-07-21] (IDT, Inc.)R3 TuneUpUtilitiesDrv; C:Program FilesTuneUp Utilities 2013TuneUpUtilitiesDriver32.sys [10088 2012-11-16] (TuneUp Software)R3 yukonwxp; C:WINDOWSSystem32DRIVERSyk51x86.sys [289664 2008-07-24] (Marvell)S3 ewusbnet; system32DRIVERSewusbnet.sys [x]S3 ew_hwusbdev; system32DRIVERSew_hwusbdev.sys [x]S3 huawei_enumerator; system32DRIVERSew_jubusenum.sys [x]S3 hwdatacard; system32DRIVERSewusbmdm.sys [x]S4 IntelIde; No ImagePathS3 Rts516xIR; system32DRIVERSRts516xIR.sys [x]S3 USBCCID; system32DRIVERSRts5161ccid.sys [x]U1 WS2IFSL; ==================== NetSvcs (Whitelisted) ======================================= One Month Created Files and Folders ========2014-01-26 22:47 - 2014-01-26 22:47 - 00000000 ____D C:FRST2014-01-25 17:19 - 2014-01-25 17:19 - 00000264 _____ C:WINDOWSTasksPrismDowngrade.job2014-01-25 16:45 - 2014-01-26 22:40 - 00000320 _____ C:WINDOWSTasksStart Registry Reviver for DELL@ADV(logon).job2014-01-25 16:45 - 2014-01-25 16:45 - 00000903 _____ C:Documents and SettingsAll UsersDesktopRegistry Reviver.lnk2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Program FilesReviverSoft2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsReviverSoft2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataReviverSoft2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataRegistryReviver.exe2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsADVMy DocumentsAny Video Converter2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsADVApplication DataAnvSoft2014-01-25 16:44 - 2014-01-25 16:44 - 00000852 _____ C:Documents and SettingsADVDesktopAny Video Converter.lnk2014-01-25 16:44 - 2014-01-25 16:44 - 00000000 ____D C:Program FilesAnvSoft2014-01-25 16:44 - 2014-01-25 16:44 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsAnvSoft2014-01-25 15:55 - 2014-01-25 15:56 - 00004754 _____ C:WINDOWSsetupapi.log2014-01-11 15:52 - 2014-01-11 15:52 - 00000000 ____D C:Program FilesCyrilla2014-01-11 15:52 - 2014-01-11 15:52 - 00000000 ____D C:Documents and SettingsADVStart MenuProgramsКирила Корект 20072014-01-04 22:47 - 2014-01-04 22:47 - 00000218 _____ C:Documents and SettingsADVLocal SettingsApplication Datarecently-used.xbel2013-12-31 14:25 - 2013-12-31 22:40 - 00000000 ____D C:Documents and SettingsADVApplication DataBitLord2013-12-31 14:25 - 2013-12-31 14:25 - 00000000 ____D C:Documents and SettingsADVApplication DataPython-Eggs2013-12-31 14:24 - 2014-01-26 22:42 - 00000000 ____D C:Documents and SettingsADVApplication Datanewnext.me2013-12-31 14:24 - 2014-01-12 12:51 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication DataMobogenie2013-12-31 14:24 - 2014-01-12 12:48 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication Datagenienext2013-12-31 14:24 - 2014-01-11 20:22 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication Datacache2013-12-31 14:24 - 2014-01-10 09:13 - 00001455 _____ C:Documents and SettingsADVdaemonprocess.txt2013-12-31 14:24 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADVMy DocumentsMobogenie2013-12-31 14:24 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADV.android2013-12-31 14:23 - 2014-01-19 15:54 - 00000000 ____D C:Documents and SettingsADVStart MenuProgramsMobogenie2013-12-31 14:23 - 2014-01-04 22:47 - 00000000 ____D C:Documents and SettingsADVMy DocumentsBitLord2013-12-31 14:23 - 2013-12-31 14:23 - 00001664 _____ C:Documents and SettingsADVDesktopBitLord.lnk2013-12-31 14:23 - 2013-12-31 14:23 - 00000000 ____D C:Program FilesBitLord 22013-12-31 14:23 - 2013-12-31 14:23 - 00000000 ____D C:Documents and SettingsADVStart MenuProgramsBitLord2013-12-30 01:04 - 2014-01-03 02:55 - 00271658 _____ C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-S-1-5-21-1715567821-1647877149-725345543-1003-0.dat==================== One Month Modified Files and Folders =======2014-01-26 22:47 - 2014-01-26 22:47 - 00000000 ____D C:FRST2014-01-26 22:46 - 2012-01-07 15:43 - 00000000 ____D C:Documents and SettingsADVApplication DatauTorrent2014-01-26 22:42 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADVApplication Datanewnext.me2014-01-26 22:42 - 2013-11-02 15:24 - 00000274 _____ C:WINDOWSTasksRealPlayerRealUpgradeLogonTaskS-1-5-21-1715567821-1647877149-725345543-1003.job2014-01-26 22:42 - 2012-01-05 11:22 - 00000430 _____ C:WINDOWSsystem32Driversetchosts.ics2014-01-26 22:41 - 2011-12-05 23:08 - 01802541 _____ C:WINDOWSWindowsUpdate.log2014-01-26 22:40 - 2014-01-25 16:45 - 00000320 _____ C:WINDOWSTasksStart Registry Reviver for DELL@ADV(logon).job2014-01-26 22:40 - 2011-12-06 00:58 - 00000157 _____ C:WINDOWSwiadebug.log2014-01-26 22:40 - 2011-12-06 00:58 - 00000052 _____ C:WINDOWSwiaservc.log2014-01-26 22:40 - 2011-12-05 23:12 - 00000006 ____H C:WINDOWSTasksSA.DAT2014-01-26 22:40 - 2001-08-23 14:00 - 00002206 _____ C:WINDOWSsystem32wpa.dbl2014-01-25 23:14 - 2013-08-11 22:31 - 00000830 _____ C:WINDOWSTasksAdobe Flash Player Updater.job2014-01-25 19:30 - 2011-12-05 23:12 - 00032620 _____ C:WINDOWSSchedLgU.Txt2014-01-25 17:19 - 2014-01-25 17:19 - 00000264 _____ C:WINDOWSTasksPrismDowngrade.job2014-01-25 16:45 - 2014-01-25 16:45 - 00000903 _____ C:Documents and SettingsAll UsersDesktopRegistry Reviver.lnk2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Program FilesReviverSoft2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsReviverSoft2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataReviverSoft2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataRegistryReviver.exe2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsADVMy DocumentsAny Video Converter2014-01-25 16:45 - 2014-01-25 16:45 - 00000000 ____D C:Documents and SettingsADVApplication DataAnvSoft2014-01-25 16:44 - 2014-01-25 16:44 - 00000852 _____ C:Documents and SettingsADVDesktopAny Video Converter.lnk2014-01-25 16:44 - 2014-01-25 16:44 - 00000000 ____D C:Program FilesAnvSoft2014-01-25 16:44 - 2014-01-25 16:44 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsAnvSoft2014-01-25 16:44 - 2013-09-29 14:03 - 00000000 ____D C:Documents and SettingsADVApplication DataOpenCandy2014-01-25 16:16 - 2013-11-02 15:24 - 00000282 _____ C:WINDOWSTasksRealPlayerRealUpgradeScheduledTaskS-1-5-21-1715567821-1647877149-725345543-1003.job2014-01-25 16:01 - 2013-04-14 11:32 - 00065536 _____ C:WINDOWSsystem32configTuneUp.evt2014-01-25 16:01 - 2011-12-05 23:13 - 00000178 ___SH C:Documents and SettingsADVntuser.ini2014-01-25 15:56 - 2014-01-25 15:55 - 00004754 _____ C:WINDOWSsetupapi.log2014-01-23 19:22 - 2013-03-05 20:06 - 00000000 ____D C:Documents and SettingsADVApplication DataPriceGong2014-01-21 10:22 - 2013-09-29 14:03 - 00000258 _____ C:WINDOWSTasksEPUpdater.job2014-01-19 18:15 - 2012-06-03 12:05 - 00000000 ____D C:Documents and SettingsADVApplication DataSkype2014-01-19 15:54 - 2013-12-31 14:23 - 00000000 ____D C:Documents and SettingsADVStart MenuProgramsMobogenie2014-01-14 20:46 - 2013-04-14 11:31 - 00000000 ____D C:Program FilesTuneUp Utilities 20132014-01-12 12:51 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication DataMobogenie2014-01-12 12:48 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication Datagenienext2014-01-11 20:22 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication Datacache2014-01-11 15:52 - 2014-01-11 15:52 - 00000000 ____D C:Program FilesCyrilla2014-01-11 15:52 - 2014-01-11 15:52 - 00000000 ____D C:Documents and SettingsADVStart MenuProgramsКирила Корект 20072014-01-11 15:52 - 2011-12-06 09:38 - 00000000 ___HD C:Program FilesInstallShield Installation Information2014-01-11 15:26 - 2012-02-02 13:41 - 00000000 ____D C:WINDOWSDatecs2014-01-10 09:13 - 2013-12-31 14:24 - 00001455 _____ C:Documents and SettingsADVdaemonprocess.txt2014-01-05 15:13 - 2011-12-08 13:56 - 00000000 ____D C:Documents and SettingsADVApplication DataAdobe2014-01-05 14:47 - 2013-11-02 15:21 - 00000000 ____D C:Documents and SettingsADVLocal SettingsApplication DataFreemakeGoldTB2014-01-04 22:47 - 2014-01-04 22:47 - 00000218 _____ C:Documents and SettingsADVLocal SettingsApplication Datarecently-used.xbel2014-01-04 22:47 - 2013-12-31 14:23 - 00000000 ____D C:Documents and SettingsADVMy DocumentsBitLord2014-01-03 02:55 - 2013-12-30 01:04 - 00271658 _____ C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-S-1-5-21-1715567821-1647877149-725345543-1003-0.dat2014-01-03 02:55 - 2013-11-02 17:08 - 00271658 _____ C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-System.dat2013-12-31 22:40 - 2013-12-31 14:25 - 00000000 ____D C:Documents and SettingsADVApplication DataBitLord2013-12-31 14:25 - 2013-12-31 14:25 - 00000000 ____D C:Documents and SettingsADVApplication DataPython-Eggs2013-12-31 14:24 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADVMy DocumentsMobogenie2013-12-31 14:24 - 2013-12-31 14:24 - 00000000 ____D C:Documents and SettingsADV.android2013-12-31 14:24 - 2011-12-05 23:13 - 00000000 ____D C:Documents and SettingsADV2013-12-31 14:23 - 2013-12-31 14:23 - 00001664 _____ C:Documents and SettingsADVDesktopBitLord.lnk2013-12-31 14:23 - 2013-12-31 14:23 - 00000000 ____D C:Program FilesBitLord 22013-12-31 14:23 - 2013-12-31 14:23 - 00000000 ____D C:Documents and SettingsADVStart MenuProgramsBitLord2013-12-31 13:41 - 2011-12-06 17:03 - 00000000 ____D C:Documents and SettingsADVApplication DataMedia Player Classic==================== Bamital & volsnap Check =================C:Windowsexplorer.exe[2004-08-04 00:56] - [2004-08-04 00:56] - 1032192 ____A (Microsoft Corporation) a0732187050030ae399b241436565e64 C:WindowsSystem32winlogon.exe[2004-08-04 00:56] - [2004-08-04 00:56] - 0502272 ____A (Microsoft Corporation) 01c3346c241652f43aed8e2149881bfe C:WindowsSystem32svchost.exe[2004-08-04 00:56] - [2004-08-04 00:56] - 0014336 ____A (Microsoft Corporation) 8f078ae4ed187aaabc0a305146de6716 C:WindowsSystem32services.exe[2004-08-04 00:56] - [2009-02-06 19:14] - 0110592 ____A (Microsoft Corporation) 37561f8d4160d62da86d24ae41fae8de C:WindowsSystem32User32.dll[2004-08-04 00:56] - [2004-08-04 00:56] - 0577024 ____A (Microsoft Corporation) c72661f8552ace7c5c85e16a3cf505c4 C:WindowsSystem32userinit.exe[2004-08-04 00:56] - [2004-08-04 00:56] - 0024576 ____A (Microsoft Corporation) 39b1ffb03c2296323832acbae50d2aff C:WindowsSystem32rpcss.dll[2004-08-04 00:56] - [2004-08-04 00:56] - 0395776 ____N (Microsoft Corporation) 5c83a4408604f737717ab96371201680 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.C:WindowsSystem32Driversvolsnap.sys[2004-08-03 23:00] - [2004-08-03 23:00] - 0052352 ____A (Microsoft Corporation) ee4660083deba849ff6c485d944b379b ==================== End Of Log ============================Ето и Addition.txt Additional scan result of Farbar Recovery Scan Tool (x86) Version: 26-01-2014 03Ran by ADV at 2014-01-26 22:48:21Running from C:Documents and SettingsADVMy DocumentsDownloadsBoot Mode: Normal============================================================================== Security Center ============================================ Installed Programs ======================µTorrent (Version: 3.1.0 - )Ace Utilities (Version: 5.2.5 - Acelogix Software)Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated)Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)Adobe Reader 9.5.5 - Bulgarian (Version: 9.5.5 - Adobe Systems Incorporated)Angry Birds Star Wars (Version: 1.3.0 - Rovio Entertainment Ltd.)Any Video Converter 5.5.4 (Version: - Any-Video-Converter.com)Apple Application Support (Version: 2.3.6 - Apple Inc.)Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)Apple Software Update (Version: 2.1.3.127 - Apple Inc.)Ask Toolbar (Version: 1.15.4.0 - Ask.com) <==== ATTENTIONATI - Software Uninstall Utility (Version: 6.14.10.1022 - )BitLord 2.3 (Version: 2.3.2-245 - House of Life)Bonjour (Version: 3.0.0.10 - Apple Inc.)BulgarianPhonetic XP by G. Atanasov (Version: - )CCleaner (Version: 4.00 - Piriform)Ciela 5.0 (Version: 5.00.0000 - Ciela soft and publishing)Connection Manager (Version: - TCT Mobile Limited)Cyriilization 2007 (HKCU Version: 2.00.0000 - БиЕмДжи ООД)Cyriilization 2007 (Version: 2.00.0000 - БиЕмДжи ООД) HiddenDell Resource CD (Version: 1.00.0000 - Dell Inc.)Dell Wireless WLAN Card Utility (Version: 5.10.38.30 - Dell Inc.)Delta Chrome Toolbar (Version: - Visual Tools) <==== ATTENTIONFlexType 2K (Version: - )Free Audio Converter version 2.3.4.920 (Version: - DVDVideoSoft Ltd.)Freemake Audio Converter version 1.1.0 (Version: 1.1.0 - Ellora Assets Corporation)FreemakeGoldTB Toolbar for IE (Version: 6.17.1.25 - FreemakeGoldTB)FromDocToPDF Toolbar (Version: - Mindspark Interactive Network)High Definition Audio Driver Package - KB835221 (Version: 20040219.000000 - Microsoft Corporation)IDT Audio (Version: 1.0.6047.0 - IDT)Integrated Webcam Driver (1.01.01.1007) (Version: - )Intel(R) Graphics Media Accelerator Driver (Version: - Intel Corporation)IPTInstaller (Version: 4.0.4 - HTC)iTunes (Version: 11.1.3.8 - Apple Inc.)Java 7 Update 7 (Version: 7.0.70 - Oracle)Java Auto Updater (Version: 2.1.9.0 - Sun Microsystems, Inc.) HiddenK-Lite Codec Pack 9.8.5 (Standard) (Version: 9.8.5 - )Marvell Miniport Driver (Version: 10.63.3.3 - Marvell)McAfee Security Scan Plus (Version: 3.8.130.10 - McAfee, Inc.)Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729 - Microsoft Corporation)Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729 - Microsoft Corporation)Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) HiddenMicrosoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) HiddenMicrosoft Base Smart Card Cryptographic Service Provider Package (Version: - Microsoft Corporation)Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Version: - Microsoft Corporation) HiddenMicrosoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version: - Microsoft Corporation) HiddenMicrosoft Office Access MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Enterprise 2007 (Version: 12.0.4518.1014 - Microsoft Corporation)Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Excel MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Groove MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office InfoPath MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office OneNote MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Outlook MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office PowerPoint MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Proof (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Proof (French) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Proof (Spanish) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Publisher MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Shared MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Office Word MUI (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft Software Update for Web Folders (English) 12 (Version: 12.0.4518.1014 - Microsoft Corporation) HiddenMicrosoft User-Mode Driver Framework Feature Pack 1.0 (Version: - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation)Microsoft WinUsb 2.0 (Version: - Microsoft Corporation)Minecraft1.4.7 (Version: - )Mozilla Firefox 26.0 (x86 en-US) (Version: 26.0 - Mozilla)Mozilla Maintenance Service (Version: 26.0 - Mozilla)MSXML 6.0 Parser (KB933579) (Version: 6.10.1200.0 - Microsoft Corporation)M-Tel NETAGENT (Version: 1.0.0.1 - ZTE Corporation)Nero 6 Ultra Edition (Version: - )Prism Video File Converter (Version: 2.01 - NCH Software)QuickSet (Version: 9.1.5 - Dell Computer Corporation)RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) HiddenRealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) HiddenRealPlayer (Version: 16.0.3 - RealNetworks)Realtek Card Reader (Version: 6.0.6000.72 - Realtek)RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) HiddenRegistry Reviver (Version: 3.0.1.144 - ReviverSoft LLC)Skype™ 6.0 (Version: 6.0.126 - Skype Technologies S.A.)Smileys We Love Toolbar for IE (Version: 3.0.19 - SqueekyChocolate, LLC)Sony Ericsson Update Engine (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB)Sony PC Companion 2.10.165 (Version: 2.10.165 - Sony)The KMPlayer (remove only) (Version: - )TuneUp Utilities 2013 (Version: 13.0.4000.181 - TuneUp Software)TuneUp Utilities 2013 (Version: 13.0.4000.181 - TuneUp Software) HiddenTuneUp Utilities Language Pack (en-US) (Version: 13.0.4000.181 - TuneUp Software) HiddenUpdate for Windows XP (KB898461) (Version: 1 - Microsoft Corporation)Update for Windows XP (KB955759) (Version: 1 - Microsoft Corporation)Update for Windows XP (KB967715) (Version: 1 - Microsoft Corporation)Update for Windows XP (KB968389) (Version: 1 - Microsoft Corporation)Update for Windows XP (KB971737) (Version: 1 - Microsoft Corporation)Update for Windows XP (KB973687) (Version: 1 - Microsoft Corporation)Update for Windows XP (KB973815) (Version: 1 - Microsoft Corporation)UpdateChecker (Version: - SqueakyChocolate, LLC) <==== ATTENTIONVideoDownloadConverter Firefox Toolbar (Version: - Mindspark Interactive Network) <==== ATTENTIONVideoDownloadConverter Internet Explorer Toolbar (Version: - Mindspark Interactive Network) <==== ATTENTIONWebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) HiddenWindows Imaging Component (Version: 3.0.0.0 - Microsoft Corporation)Windows Installer 3.1 (KB893803) (Version: 3.1 - Microsoft Corporation)Windows Media Format 11 runtime (Version: - )Windows Media Format 11 runtime (Version: - Microsoft Corporation) HiddenWinRAR archiver (Version: - )==================== Restore Points =========================02-11-2013 14:25:23 Installed Windows XP WIC.02-11-2013 14:27:40 Installed Windows KB954550-v5.02-11-2013 14:27:46 Printer Driver Microsoft XPS Document Writer Installed02-11-2013 14:27:54 Printer Driver Microsoft XPS Document Writer Installed02-11-2013 14:56:31 Removed Ask Toolbar.02-11-2013 14:56:51 Removed Ask Toolbar.03-11-2013 15:11:29 System Checkpoint09-11-2013 12:34:24 Removed Apple Application Support09-11-2013 12:35:36 Removed Apple Mobile Device Support09-11-2013 12:35:42 Removed Apple Mobile Device Support10-11-2013 12:41:29 System Checkpoint11-11-2013 15:16:36 System Checkpoint16-11-2013 12:05:47 System Checkpoint17-11-2013 18:02:31 System Checkpoint23-11-2013 19:11:56 System Checkpoint28-12-2013 16:51:58 System Checkpoint29-12-2013 18:04:06 System Checkpoint31-12-2013 12:23:51 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.2102202-01-2014 19:54:34 System Checkpoint04-01-2014 12:26:13 System Checkpoint05-01-2014 13:36:19 System Checkpoint10-01-2014 18:45:13 System Checkpoint11-01-2014 13:43:15 Инсталиран Cyriilization 200721-01-2014 08:15:55 System Checkpoint25-01-2014 15:11:37 System Checkpoint==================== Hosts content: ==========================2001-08-23 14:00 - 2013-08-15 19:12 - 00000733 ____A C:WINDOWSsystem32Driversetchosts127.0.0.1 localhost==================== Scheduled Tasks (whitelisted) =============Task: C:WINDOWSTasksAdobe Flash Player Updater.job => C:WINDOWSsystem32MacromedFlashFlashPlayerUpdateService.exeTask: C:WINDOWSTasksAppleSoftwareUpdate.job => C:Program FilesApple Software UpdateSoftwareUpdate.exeTask: C:WINDOWSTasksEPUpdater.job => C:DOCUME~1ADVAPPLIC~1BABSOL~1SharedBabMaint.exe <==== ATTENTIONTask: C:WINDOWSTasksPrismDowngrade.job => C:Program FilesNCH SoftwarePrismprism.exeTask: C:WINDOWSTasksRealPlayerRealUpgradeLogonTaskS-1-5-21-1715567821-1647877149-725345543-1003.job => C:Program FilesRealRealUpgraderealupgrade.exeTask: C:WINDOWSTasksRealPlayerRealUpgradeScheduledTaskS-1-5-21-1715567821-1647877149-725345543-1003.job => C:Program FilesRealRealUpgraderealupgrade.exeTask: C:WINDOWSTasksStart Registry Reviver for DELL@ADV(logon).job => C:Program FilesReviverSoftRegistry ReviverRegistryReviver.exe==================== Loaded Modules (whitelisted) =============2011-12-06 16:26 - 2008-11-26 11:39 - 00753664 _____ () C:WINDOWSSystem32bcm1xsup.dll2012-02-02 13:41 - 2000-12-13 00:55 - 00028672 _____ () C:WINDOWSsystem32newdll.dll2009-02-27 18:36 - 2009-02-27 18:36 - 00311296 _____ () C:Program FilesCommon FilesAdobeAcrobatActiveXPDFShell.BGR2012-01-28 02:02 - 2012-01-28 02:02 - 00111256 _____ () C:Program FilesAce Utilitieswipext.dll2011-12-06 17:14 - 2005-10-07 15:05 - 00125440 _____ () C:Program FilesWinRARrarext.dll2011-12-06 16:26 - 2008-11-26 11:39 - 00143360 _____ () C:WINDOWSsystem32preflib.dll2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:Program FilesCommon FilesAppleApple Application Supportzlib1.dll2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:Program FilesCommon FilesAppleApple Application Supportlibxml2.dll2013-11-02 16:34 - 2013-11-02 16:34 - 00003584 _____ () C:WINDOWSMicrosoft.NETFrameworkv2.0.50727Temporary ASP.NET Filesroot1e3356b61809e7d1App_global.asax.6qf7p0k8.dll2013-12-10 20:11 - 2013-12-10 20:11 - 00500024 _____ () C:Program FilesTuneUp Utilities 2013avgreplibx.dll2013-12-23 14:50 - 2013-12-23 14:50 - 03559024 _____ () C:Program FilesMozilla Firefoxmozjs.dll2013-12-22 20:30 - 2013-12-22 20:30 - 16242056 _____ () C:WINDOWSsystem32MacromedFlashNPSWF32_11_9_900_170.dll==================== Alternate Data Streams (whitelisted) =========AlternateDataStreams: C:Documents and SettingsAll UsersApplication DataTEMP:E965A533==================== Safe Mode (whitelisted) ===================HKLMSYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys => ""="Driver"HKLMSYSTEMCurrentControlSetControlSafeBootNetworkWdf01000.sys => ""="Driver"==================== Faulty Device Manager Devices ================================= Event log errors: =========================Application errors:==================Error: (01/22/2014 10:04:09 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledSPRetry 2801047Error: (01/22/2014 10:04:09 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledEvent 2801047Error: (01/22/2014 10:04:09 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: Continuously busy for more than a secondError: (01/22/2014 09:17:32 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledSPRetry 4000Error: (01/22/2014 09:17:32 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledEvent 4000Error: (01/22/2014 09:17:32 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: Continuously busy for more than a secondError: (01/22/2014 09:17:30 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledSPRetry 2047Error: (01/22/2014 09:17:30 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledEvent 2047Error: (01/22/2014 09:17:30 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: Continuously busy for more than a secondError: (01/22/2014 08:49:52 PM) (Source: Bonjour Service) (User: )Description: Task Scheduling Error: m->NextScheduledSPRetry 134922System errors:=============Error: (01/26/2014 10:42:07 PM) (Source: Service Control Manager) (User: )Description: The Freemake Improver service hung on starting.Error: (01/26/2014 10:40:46 PM) (Source: Service Control Manager) (User: )Description: The Microsoft TV/Video Connection service failed to start due to the following error: %%1058Error: (01/26/2014 10:40:46 PM) (Source: Service Control Manager) (User: )Description: The HUAWEI USB-NDIS miniport service failed to start due to the following error: %%2Error: (01/25/2014 09:51:32 PM) (Source: Service Control Manager) (User: )Description: The UI Assistant Service service terminated unexpectedly. It has done this 1 time(s).Error: (01/25/2014 09:51:26 PM) (Source: Service Control Manager) (User: )Description: The Freemake Improver service terminated unexpectedly. It has done this 1 time(s).Error: (01/25/2014 08:31:43 PM) (Source: ipnathlp) (User: )Description: The DHCP allocator has disabled itself on IP address 77.70.89.22,since the IP address is outside the 192.168.0.0/255.255.255.0 scopefrom which addresses are being allocated to DHCP clients.To enable the DHCP allocator on this IP address,please change the scope to include the IP address,or change the IP address to fall within the scope.Error: (01/25/2014 04:16:14 PM) (Source: Service Control Manager) (User: )Description: The Freemake Improver service hung on starting.Error: (01/25/2014 04:14:52 PM) (Source: Service Control Manager) (User: )Description: The Microsoft TV/Video Connection service failed to start due to the following error: %%1058Error: (01/25/2014 04:14:52 PM) (Source: Service Control Manager) (User: )Description: The HUAWEI USB-NDIS miniport service failed to start due to the following error: %%2Error: (01/25/2014 03:16:29 PM) (Source: Service Control Manager) (User: )Description: The Freemake Improver service hung on starting.Microsoft Office Sessions:=========================Error: (03/25/2012 04:11:34 PM) (Source: Microsoft Office 12 Sessions)(User: )Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 15868 seconds with 3600 seconds of active time. This session ended with a crash.==================== Memory info =========================== Percentage of memory in use: 33%Total physical RAM: 3034.29 MBAvailable physical RAM: 2016.95 MBTotal Pagefile: 4920.29 MBAvailable Pagefile: 4055.79 MBTotal Virtual: 2047.88 MBAvailable Virtual: 1958.85 MB==================== Drives ================================Drive c: () (Fixed) (Total:97.65 GB) (Free:36.52 GB) NTFS ==>[Drive with boot components (Windows XP)]Drive e: () (Fixed) (Total:200.43 GB) (Free:175.42 GB) NTFSDrive f: (LG_RC590M) (CDROM) (Total:2.03 GB) (Free:0 GB) UDF==================== MBR & Partition Table ==========================================================================Disk: 0 (MBR Code: Windows XP) (Size: 298 GB) (Disk ID: ADED2F29)Partition 1: (Active) - (Size=98 GB) - (Type=07 NTFS)Partition 2: (Not Active) - (Size=200 GB) - (Type=07 NTFS)==================== End Of Log ============================
  7. Здравейте, имам лаптоп Тоshiba satellitе, който в последно време стана бавен когато съм в интернет. Попринцип отварям 10на таба и си работи ок, но сгеа зарежда бавно което ме наведе на мисълта, че имам вирус. Пуснах аваст да сканира и намери WIN 32 Malware gen. Не съм го трила от антивирусната,защото не знам дали може да го премахне както трябва. Мисля да сваля Malwarebytes' Anti-Malware да сканира. Ако може да ми помогнете да го изтрия и да проверя дали няма и други вируси. Благодаря DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16421 Run by VESELA at 15:01:41 on 2012-09-04 Microsoft Windows 7 Home Premium 6.1.7601.1.1251.359.1033.18.5607.3276 [GMT 3:00] . AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\WTouch\WTouchService.exe C:\Windows\system32\atieclxx.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Program Files\WTouch\WTouchUser.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\Explorer.EXE C:\Windows\system32\Pen_Tablet.exe C:\Windows\system32\WTablet\Pen_TabletUser.exe C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe C:\Windows\system32\Pen_Tablet.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Toshiba\TECO\Teco.exe C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe C:\Program Files\TOSHIBA\TECO\TecoService.exe C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe C:\Windows\system32\DllHost.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe c:\Program Files (x86)\Nero\Update\NASvc.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe C:\Windows\system32\taskeng.exe C:\Windows\SysWOW64\ctfmon.exe C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TEUA&bmod=TEUA uSearch Bar = Preserve mWinlogon: Userinit = userinit.exe BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll uRun: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STAR uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun mRun: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [iTSecMng] C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START mRun: [TSleepSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 mRun: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui dRun: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP StartupFolder: C:\Users\VESELA\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\TRDCRE~1.LNK - C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\TOSHIB~1.LNK - C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {97F922BD-8563-4184-87EE-8C4ACA438823} - {5D29E593-73A5-400A-B3BD-6B7A1AF05A31} - C:\Program Files\Toshiba\BulletinBoard\TosBBCom.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab TCP: NameServer = 192.168.94.1 85.187.216.3 TCP: Interfaces\{EC987100-A9DD-4878-87F3-047D0A4FDECD} : DHCPNameServer = 192.168.94.1 85.187.216.3 TCP: Interfaces\{EC987100-A9DD-4878-87F3-047D0A4FDECD}\34F6E6E6563647966697D20527F626F6F6B6 : DHCPNameServer = 192.168.210.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - <orphaned> SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-Run: [TosReelTimeMonitor] C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe x64-Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe x64-Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE x64-Run: [HSON] C:\Program Files (x86)\TOSHIBA\TBS\HSON.exe x64-Run: [TCrdMain] C:\Program Files (x86)\TOSHIBA\FlashCards\TCrdMain.exe x64-Run: [smartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t x64-Run: [synTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe x64-Run: [Teco] "C:\Program Files (x86)\TOSHIBA\TECO\Teco.exe" /r x64-Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe x64-Run: [TosWaitSrv] C:\Program Files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe x64-Run: [TosNC] C:\Program Files (x86)\Toshiba\BulletinBoard\TosNcCore.exe x64-Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe x64-Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll x64-IE: {97F922BD-8563-4184-87EE-8C4ACA438823} - {5D29E593-73A5-400A-B3BD-6B7A1AF05A31} - C:\Program Files\Toshiba\BulletinBoard\TosBBCom64.dll x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned> x64-SSODL: WebCheck - <orphaned> x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\VESELA\AppData\Roaming\Mozilla\Firefox\Profiles\w9e33dcd.default\ FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-1-17 969200] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-1-17 359464] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2011-12-16 279616] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-10-10 204288] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-1-17 25232] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-1-17 71600] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-9-1 44808] R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-1-28 249200] R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-3-29 598312] R2 TabletServicePen;TabletServicePen;C:\Windows\System32\Pen_Tablet.exe [2012-8-27 5556520] R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2011-2-10 112080] R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\Toshiba\TECO\TecoService.exe [2011-4-7 294328] R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\System32\drivers\TVALZFL.sys [2009-6-19 14472] R2 WTouchService;WTouch Service;C:\Program Files\WTouch\WTouchService.exe [2012-8-27 127784] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2011-10-10 9263616] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-10-10 300544] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-10-10 116752] R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;C:\Windows\System32\drivers\btfilter.sys [2011-10-10 42096] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2011-2-9 77424] R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2011-10-10 38096] R3 QIOMem;Generic IO & Memory Access;C:\Windows\System32\drivers\QIOMem.sys [2009-6-15 12800] R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-10-10 54136] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-12-8 137632] R3 TPCHSrv;TPCH Service;C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [2011-7-1 828856] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-8-17 136176] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-30 250056] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-8-17 136176] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-26 114144] S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864] S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-1-9 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-09-04 09:17:30 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0D145B5C-E7D9-4398-BE6D-6A363536D589}\offreg.dll 2012-09-04 08:13:06 9310152 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0D145B5C-E7D9-4398-BE6D-6A363536D589}\mpengine.dll 2012-09-02 21:50:45 73696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll 2012-08-27 14:37:14 290088 ------w- C:\Windows\System32\Touch_Tablet.dll 2012-08-27 14:37:14 245032 ------w- C:\Windows\SysWow64\Touch_Tablet.dll 2012-08-27 14:37:04 -------- d-----w- C:\Program Files (x86)\TabletPlugins 2012-08-27 14:36:36 7543592 ------w- C:\Windows\System32\PenTablet.cpl 2012-08-27 14:36:32 12848 ----a-w- C:\Windows\System32\drivers\wacommousefilter.sys 2012-08-27 14:36:25 15656 ----a-w- C:\Windows\System32\drivers\wacomvhid.sys 2012-08-27 14:36:16 -------- d-----w- C:\Windows\System32\WTablet 2012-08-27 14:35:55 284160 ------w- C:\Windows\SysWow64\Wintab32.dll 2012-08-27 14:35:54 490280 ------w- C:\Windows\System32\Pen_Tablet.dll 2012-08-27 14:35:54 416040 ------w- C:\Windows\SysWow64\Pen_Tablet.dll 2012-08-27 14:35:50 5556520 ------w- C:\Windows\System32\Pen_Tablet.exe 2012-08-17 14:18:29 503808 ----a-w- C:\Windows\System32\srcore.dll 2012-08-17 14:18:29 43008 ----a-w- C:\Windows\SysWow64\srclient.dll 2012-08-17 14:18:25 751104 ----a-w- C:\Windows\System32\win32spl.dll 2012-08-17 14:18:25 559104 ----a-w- C:\Windows\System32\spoolsv.exe 2012-08-17 14:18:24 67072 ----a-w- C:\Windows\splwow64.exe 2012-08-17 14:18:24 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll 2012-08-17 14:17:16 59392 ----a-w- C:\Windows\System32\browcli.dll 2012-08-17 14:17:16 41984 ----a-w- C:\Windows\SysWow64\browcli.dll 2012-08-17 14:17:16 136704 ----a-w- C:\Windows\System32\browser.dll 2012-08-17 14:17:13 3148800 ----a-w- C:\Windows\System32\win32k.sys 2012-08-17 14:17:12 956928 ----a-w- C:\Windows\System32\localspl.dll 2012-08-06 14:48:48 -------- d-----w- C:\Users\VESELA\AppData\Local\{A45595B8-0C41-48AF-8C87-26518E6E8AA4} 2012-08-06 14:48:47 -------- d-----w- C:\Users\VESELA\AppData\Local\{9C8EE35B-BAB7-463F-858E-E8AEFD05F3C6} . ==================== Find3M ==================== . 2012-08-21 09:13:13 969200 ----a-w- C:\Windows\System32\drivers\aswSnx.sys 2012-08-21 09:13:12 71600 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2012-08-21 09:13:12 54072 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys 2012-08-21 09:12:33 41224 ----a-w- C:\Windows\avastSS.scr 2012-08-17 15:59:22 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-17 15:59:22 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll 2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll 2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl 2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe 2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll 2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll 2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb . ============= FINISH: 15:02:29.14 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 16/12/2011 20:27:51 System Uptime: 04/09/2012 11:15:08 (4 hours ago) . Motherboard: AMD | | Torpedo Processor: AMD A6-3400M APU with Radeon™ HD Graphics | Socket FS1 | 896/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 297 GiB total, 234.012 GiB free. D: is FIXED (NTFS) - 298 GiB total, 185.554 GiB free. E: is CDROM () F: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP88: 17/08/2012 23:55:50 - Windows Update RP89: 21/08/2012 10:32:41 - Windows Update RP90: 24/08/2012 10:38:58 - Windows Update RP91: 28/08/2012 12:16:35 - Windows Update RP92: 04/09/2012 11:12:11 - Windows Update . ==== Installed Programs ====================== . µTorrent Adobe AIR Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe Color Common Settings Adobe ExtendScript Toolkit 2 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Help Viewer CS3 Adobe Illustrator CS4 Adobe Illustrator CS5 Adobe InDesign CS3 Adobe InDesign CS3 Icon Handler Adobe Linguistics CS3 Adobe Photoshop CS5 Adobe Reader X (10.1.4) MUI Adobe Setup Adobe SING CS3 Adobe Stock Photos CS3 Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 AMD VISION Engine Control Center Apple Application Support Apple Software Update ArchiCAD 15 R1 INT Atheros Bluetooth Filter Driver Package Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver Atheros Driver Installation Program ATI Catalyst Install Manager avast! Free Antivirus Bamboo Bandisoft MPEG-1 Decoder BBC iPlayer Desktop Bluetooth Stack for Windows by Toshiba Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Conexant HD Audio Control ActiveX Windows Live Mesh pentru conexiuni la distan?a D3DX10 DAEMON Tools Lite Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition doPDF 7.2 printer DTS+AC3 Filter Fotogalerija Windows Live Galerie foto Windows Live GOM Player Google Chrome Google Toolbar for Internet Explorer Google Update Helper High-Definition Video Playback Java Auto Updater Java™ 6 Update 20 Junk Mail filter update K-Lite Codec Pack 5.5.0 (64-bit) Kontrola Windows Live Mesh ActiveX za daljinske veze Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave Mesh Runtime Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2010 Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office Office 32-bit Components 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared 32-bit MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Primary Interoperability Assemblies 2005 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Minilyrics Mozilla Firefox 15.0 (x86 en-US) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 10 Movie ThemePack Basic Nero BackItUp 10 Nero BackItUp 10 Help (CHM) Nero BurnRights 10 Nero BurnRights 10 Help (CHM) Nero Control Center 10 Nero ControlCenter 10 Help (CHM) Nero Core Components 10 Nero Express 10 Nero Express 10 Help (CHM) Nero InfoTool 10 Nero InfoTool 10 Help (CHM) Nero Kwik Media Nero Multimedia Suite 10 Essentials Nero RescueAgent 10 Nero RescueAgent 10 Help (CHM) Nero StartSmart 10 Nero StartSmart 10 Help (CHM) Nero Update NeroKwikMedia Help (CHM) PlayReady PC Runtime amd64 Posta Windows Live PowerArchiver 2010 QuickTime Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Excel 2010 (KB2597166) 64-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2553322) 64-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2553431) 64-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553260) 64-Bit Edition Security Update for Microsoft Office 2010 (KB2553371) 64-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 64-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 64-Bit Edition Security Update for Microsoft Office 2010 (KB2589322) 64-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 64-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 64-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Visio Viewer 2010 (KB2598287) 64-Bit Edition Skype™ 5.10 Synaptics Pointing Device Driver TOSHIBA Assist TOSHIBA Bulletin Board TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA eco Utility TOSHIBA Face Recognition TOSHIBA Hardware Setup TOSHIBA HDD/SSD Alert Toshiba Manuals TOSHIBA Online Product Information TOSHIBA PC Health Monitor TOSHIBA Places Icon Utility TOSHIBA Recovery Media Creator TOSHIBA Recovery Media Creator Reminder TOSHIBA ReelTime TOSHIBA Service Station TOSHIBA Sleep Utility TOSHIBA Supervisor Password TOSHIBA TEMPRO TOSHIBA Value Added Package TOSHIBA Web Camera Application TOSHIBA Wireless LAN Indicator TRORMCLauncher Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition Update for Microsoft Office 2010 (KB2553272) 64-Bit Edition Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2598289) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2589345) 64-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 64-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition WebTablet IE Plugin WebTablet Netscape Plugin Winamp Winamp Detector Plug-in Windows Live Communications Platform Windows Live Essentials Windows Live Foto-galerija Windows Live Galerija fotografija Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Mesh ActiveX kontrola za daljinske veze Windows Live Messenger Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Posta Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WMV9/VC-1 Video Playback . ==== Event Viewer Messages From Past Week ======== . 31/08/2012 11:24:34, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Notebook Performance Tuning Service (TEMPRO) service to connect. 30/08/2012 18:34:09, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user VESELA-TOSHIBA\VESELA SID (S-1-5-21-2119856864-1918505592-3212183323-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 04/09/2012 13:34:22, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10. 03/09/2012 11:18:14, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WTouchService service. . ==== End Of File ===========================
  8. Здравейте! Това е вируса който открих (Injector Autoit Trojan) но до сега не съм усещал да ми е създавал някакви проблеми. Притежавам компакт диск за операционната ми система. Това е информацията от DDS: DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 9.10.9200.16618 Run by Ick0 at 11:40:06 on 2013-07-01 #Option Extended Search is enabled. Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.3957.2858 [GMT 2:00] . AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} . ============== Running Processes =============== . C:Windowssystem32wininit.exe C:Windowssystem32lsm.exe C:Windowssystem32svchost.exe -k DcomLaunch C:Windowssystem32svchost.exe -k RPCSS C:Program FilesMicrosoft Security ClientMsMpEng.exe C:Windowssystem32atiesrxx.exe C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted C:Windowssystem32svchost.exe -k LocalService C:Windowssystem32svchost.exe -k netsvcs C:Windowssystem32svchost.exe -k GPSvcGroup C:Windowssystem32svchost.exe -k NetworkService C:Windowssystem32atieclxx.exe C:Windowssystem32WLANExt.exe C:Windowssystem32conhost.exe C:WindowsSystem32spoolsv.exe C:Windowssystem32svchost.exe -k LocalServiceNoNetwork C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe C:Program FilesRealtekAudioHDAAERTSr64.exe C:Program FilesWIDCOMMBluetooth Softwarebtwdins.exe C:Windowssystem32svchost.exe -k imgsvc C:Program FilesMicrosoft Security ClientNisSrv.exe C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted C:Windowssystem32taskhost.exe C:Windowssystem32svchost.exe -k bthsvcs C:Windowssystem32Dwm.exe C:WindowsExplorer.EXE C:WindowsSystem32WUDFHost.exe C:Program FilesRealtekAudioHDARAVCpl64.exe C:Program Files (x86)Pando NetworksMedia BoosterPMB.exe C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticMOM.exe C:Program FilesWIDCOMMBluetooth SoftwareBTTray.exe C:Windowssystem32SearchIndexer.exe C:Program FilesWindows Media Playerwmpnetwk.exe C:Program FilesWIDCOMMBluetooth SoftwareBtStackServer.exe C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation C:WindowsSystem32svchost.exe -k LocalServicePeerNet C:Program FilesWIDCOMMBluetooth SoftwareBluetoothHeadsetProxy.exe C:Windowssystem32wbemwmiprvse.exe C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCCC.exe C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe C:Program FilesMicrosoft Security ClientMpCmdRun.exe C:Windowssystem32conhost.exe C:Windowssystem32wbemwmiprvse.exe C:WindowsSystem32cscript.exe . ============== Pseudo HJT Report =============== . uProxyServer = 42.120.49.48:8000 uRun: [skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrun uRun: [Pando Media Booster] C:Program Files (x86)Pando NetworksMedia BoosterPMB.exe mRun: [startCCC] "C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe" MSRun mRun: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe" StartupFolder: C:PROGRA~3MICROS~1WindowsSTARTM~1ProgramsStartupBLUETO~1.LNK - C:Program FilesWIDCOMMBluetooth SoftwareBTTray.exe uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: Send image to &Bluetooth Device... - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm Trusted Zone: dell.com TCP: NameServer = 10.0.0.1 TCP: Interfaces{C64DF948-3441-4423-AF62-B8CCC9FF5F1A} : DHCPNameServer = 10.0.0.1 TCP: Interfaces{C64DF948-3441-4423-AF62-B8CCC9FF5F1A}244534D2144435C4 : DHCPNameServer = 192.168.1.1 TCP: Interfaces{C64DF948-3441-4423-AF62-B8CCC9FF5F1A}3594D6F6 : DHCPNameServer = 88.87.0.2 88.87.10.2 TCP: Interfaces{C64DF948-3441-4423-AF62-B8CCC9FF5F1A}46C696E6B6 : DHCPNameServer = 192.168.0.1 TCP: Interfaces{C64DF948-3441-4423-AF62-B8CCC9FF5F1A}8427963747F6D24556C6E65647 : DHCPNameServer = 88.87.10.2 88.87.0.2 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dll SSODL: WebCheck - <orphaned> mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:Program Files (x86)GoogleChromeApplication27.0.1453.116Installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome x64-Run: [MSC] "C:Program FilesMicrosoft Security Clientmsseces.exe" -hide -runkey x64-Run: [RtHDVCpl] C:Program FilesRealtekAudioHDARAVCpl64.exe -s x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:Program FilesWIDCOMMBluetooth Softwarebtsendto_ie.htm x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-SSODL: WebCheck - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - C:UsersIck0AppDataRoamingMozillaFirefoxProfilessnr1dtrn.default . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;C:WindowsSystem32driversMpFilter.sys [2013-1-20 230320] R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32driversvwififlt.sys [2009-7-14 59904] R2 AdobeARMservice;Adobe Acrobat Update Service;C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [2013-5-11 65640] R2 AERTFilters;Andrea RT Filters Service;C:Program FilesRealtekAudioHDAAERTSr64.exe [2012-6-6 98208] R2 AMD External Events Utility;AMD External Events Utility;C:WindowsSystem32atiesrxx.exe [2012-6-6 203264] R2 NisDrv;Microsoft Network Inspection System;C:WindowsSystem32driversNisDrvWFP.sys [2012-3-20 130008] R2 UNS;Intel® Management & Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2012-6-6 2533400] R3 amdkmdag;amdkmdag;C:WindowsSystem32driversatikmdag.sys [2012-6-6 7884288] R3 amdkmdap;amdkmdap;C:WindowsSystem32driversatikmpag.sys [2012-6-6 285696] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:WindowsSystem32driversAtihdW76.sys [2012-6-6 115216] R3 btusbflt;Bluetooth USB Filter;C:WindowsSystem32driversbtusbflt.sys [2012-6-6 53800] R3 btwl2cap;Bluetooth L2CAP Service;C:WindowsSystem32driversbtwl2cap.sys [2012-6-6 35104] R3 HECIx64;Intel® Management Engine Interface;C:WindowsSystem32driversHECIx64.sys [2012-6-6 56344] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:WindowsSystem32driversL1C62x64.sys [2009-12-22 74280] R3 NisSrv;Microsoft Network Inspection;C:Program FilesMicrosoft Security ClientNisSrv.exe [2013-1-27 379360] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-19 138576] S2 gupdate;Услуга на Google Актуализация (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-4-6 116648] S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-2-28 161384] S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2012-1-29 71168] S3 gupdatem;Услуга на Google Актуализация (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-4-6 116648] S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2012-10-21 117144] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2012-11-28 19456] S3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;C:WindowsSystem32driversSynth3dVsc.sys [2012-1-29 88960] S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32driversterminpt.sys [2012-11-28 29696] S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2012-11-28 57856] S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2012-11-28 30208] S3 tsusbhub;Remote Deskotop USB Hub;C:WindowsSystem32driverstsusbhub.sys [2012-1-29 117248] S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2012-6-7 1255736] . =============== Created Last 60 ================ . 2013-07-01 09:31:00 9552976 ----a-w- C:ProgramDataMicrosoftMicrosoft AntimalwareDefinition Updates{A4A483D7-E044-4DF6-BBA1-B004ED88D24D}mpengine.dll 2013-06-30 23:05:24 -------- d-----w- C:Program Files (x86)ESET 2013-06-30 22:59:47 -------- d-----w- C:UsersIck0AppDataRoamingMalwarebytes 2013-06-30 22:59:10 -------- d-----w- C:ProgramDataMalwarebytes 2013-06-30 22:59:09 25928 ----a-w- C:WindowsSystem32driversmbam.sys 2013-06-30 22:59:09 -------- d-----w- C:Program Files (x86)Malwarebytes' Anti-Malware 2013-06-30 22:58:50 -------- d-----w- C:UsersIck0AppDataLocalPrograms 2013-06-30 22:52:07 -------- d-sh--w- C:$RECYCLE.BIN 2013-06-30 22:49:05 -------- d-----w- C:_OTL 2013-06-30 22:03:14 -------- d-----w- C:WindowsERUNT 2013-06-30 22:03:05 -------- d-----w- C:JRT 2013-06-30 21:26:50 98816 ----a-w- C:Windowssed.exe 2013-06-30 21:26:50 256000 ----a-w- C:WindowsPEV.exe 2013-06-30 21:26:50 208896 ----a-w- C:WindowsMBR.exe 2013-06-30 00:10:41 9552976 ----a-w- C:ProgramDataMicrosoftMicrosoft AntimalwareDefinition UpdatesBackupmpengine.dll 2013-06-27 14:47:16 -------- d-----w- C:UsersIck0AppDataRoamingsystem_folder 2013-06-22 07:11:52 964552 ------w- C:ProgramDataMicrosoftMicrosoft AntimalwareDefinition Updates{D97A4BEC-94B4-47AF-9A8A-6A4B43728DDA}gapaengine.dll 2013-06-12 13:06:44 1910632 ----a-w- C:WindowsSystem32driverstcpip.sys 2013-05-30 13:55:07 -------- d-----w- C:UsersIck0AppDataRoamingPogo 2013-05-30 13:55:07 -------- d-----w- C:ProgramDataPogo 2013-05-24 13:43:12 262552 ----a-w- C:Program Files (x86)Mozilla Firefoxbrowsercomponentsbrowsercomps.dll 2013-05-20 23:41:22 -------- d-sh--r- C:UsersIck0AppDataRoamingsystem 2013-05-20 23:28:49 -------- d-----w- C:UsersIck0AppDataRoaminginstalls 2013-05-11 21:26:16 -------- d-----w- C:UsersIck0AppDataLocalIW4M . ==================== Find6M ==================== . 2013-06-30 21:10:19 71048 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl 2013-06-30 21:10:19 692104 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe 2013-05-13 05:51:01 184320 ----a-w- C:WindowsSystem32cryptsvc.dll 2013-05-13 05:51:00 1464320 ----a-w- C:WindowsSystem32crypt32.dll 2013-05-13 05:51:00 139776 ----a-w- C:WindowsSystem32cryptnet.dll 2013-05-13 05:50:40 52224 ----a-w- C:WindowsSystem32certenc.dll 2013-05-13 04:45:55 140288 ----a-w- C:WindowsSysWow64cryptsvc.dll 2013-05-13 04:45:55 1160192 ----a-w- C:WindowsSysWow64crypt32.dll 2013-05-13 04:45:55 103936 ----a-w- C:WindowsSysWow64cryptnet.dll 2013-05-13 03:43:55 1192448 ----a-w- C:WindowsSystem32certutil.exe 2013-05-13 03:08:10 903168 ----a-w- C:WindowsSysWow64certutil.exe 2013-05-13 03:08:06 43008 ----a-w- C:WindowsSysWow64certenc.dll 2013-05-10 05:49:27 30720 ----a-w- C:WindowsSystem32cryptdlg.dll 2013-05-10 03:20:54 24576 ----a-w- C:WindowsSysWow64cryptdlg.dll 2013-05-02 15:29:56 278800 ------w- C:WindowsSystem32MpSigStub.exe 2013-04-26 05:51:36 751104 ----a-w- C:WindowsSystem32win32spl.dll 2013-04-26 04:55:21 492544 ----a-w- C:WindowsSysWow64win32spl.dll 2013-04-25 23:30:32 1505280 ----a-w- C:WindowsSysWow64d3d11.dll 2013-04-17 07:02:06 1230336 ----a-w- C:WindowsSysWow64WindowsCodecs.dll 2013-04-17 06:24:46 1424384 ----a-w- C:WindowsSystem32WindowsCodecs.dll 2013-04-13 05:49:23 135168 ----a-w- C:WindowsapppatchAppPatch64AcXtrnal.dll 2013-04-13 05:49:19 350208 ----a-w- C:WindowsapppatchAppPatch64AcLayers.dll 2013-04-13 05:49:19 308736 ----a-w- C:WindowsapppatchAppPatch64AcGenral.dll 2013-04-13 05:49:19 111104 ----a-w- C:WindowsapppatchAppPatch64acspecfc.dll 2013-04-13 04:45:16 474624 ----a-w- C:WindowsapppatchAcSpecfc.dll 2013-04-13 04:45:15 2176512 ----a-w- C:WindowsapppatchAcGenral.dll 2013-04-12 14:45:08 1656680 ----a-w- C:WindowsSystem32driversntfs.sys 2013-04-10 06:01:54 265064 ----a-w- C:WindowsSystem32driversdxgmms1.sys 2013-04-10 06:01:53 983400 ----a-w- C:WindowsSystem32driversdxgkrnl.sys 2013-04-10 03:30:50 3153920 ----a-w- C:WindowsSystem32win32k.sys 2013-03-31 22:52:16 1887232 ----a-w- C:WindowsSystem32d3d11.dll 2013-03-19 06:04:06 5550424 ----a-w- C:WindowsSystem32ntoskrnl.exe 2013-03-19 05:53:58 48640 ----a-w- C:WindowsSystem32wwanprotdim.dll 2013-03-19 05:53:58 230400 ----a-w- C:WindowsSystem32wwansvc.dll 2013-03-19 05:46:56 43520 ----a-w- C:WindowsSystem32csrsrv.dll 2013-03-19 05:04:13 3968856 ----a-w- C:WindowsSysWow64ntkrnlpa.exe 2013-03-19 05:04:10 3913560 ----a-w- C:WindowsSysWow64ntoskrnl.exe 2013-03-19 04:47:50 6656 ----a-w- C:WindowsSysWow64apisetschema.dll 2013-03-19 03:06:33 112640 ----a-w- C:WindowsSystem32smss.exe 2013-02-27 06:02:44 111448 ----a-w- C:WindowsSystem32consent.exe 2013-02-27 05:48:00 1930752 ----a-w- C:WindowsSystem32authui.dll 2013-02-27 05:47:10 70144 ----a-w- C:WindowsSystem32appinfo.dll 2013-02-27 04:49:24 1796096 ----a-w- C:WindowsSysWow64authui.dll 2013-02-12 04:12:05 19968 ----a-w- C:WindowsSystem32driversusb8023.sys 2013-01-24 06:01:01 223752 ----a-w- C:WindowsSystem32driversfvevol.sys 2013-01-20 13:59:04 230320 ----a-w- C:WindowsSystem32driversMpFilter.sys 2013-01-20 13:59:04 130008 ----a-w- C:WindowsSystem32driversNisDrvWFP.sys 2013-01-13 21:17:03 9728 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 21:17:02 2560 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 21:16:42 10752 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 21:12:46 3584 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 21:11:21 4096 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 21:11:08 5632 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 21:11:07 5632 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 21:11:07 3072 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 21:11:07 3072 ---ha-w- C:WindowsSysWow64api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:35:31 9728 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 20:35:31 2560 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 20:35:18 10752 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 20:32:07 3584 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 20:31:48 4096 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 20:31:41 5632 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 20:31:40 5632 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 20:31:40 3072 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 20:31:40 3072 ---ha-w- C:WindowsSystem32api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:31:00 1247744 ----a-w- C:WindowsSysWow64DWrite.dll 2013-01-13 20:22:22 1988096 ----a-w- C:WindowsSysWow64d3d10warp.dll 2013-01-13 20:20:31 293376 ----a-w- C:WindowsSysWow64dxgi.dll 2013-01-13 20:09:00 249856 ----a-w- C:WindowsSysWow64d3d10_1core.dll 2013-01-13 20:08:43 220160 ----a-w- C:WindowsSysWow64d3d10core.dll 2013-01-13 19:59:04 1643520 ----a-w- C:WindowsSystem32DWrite.dll 2013-01-13 19:58:28 1175552 ----a-w- C:WindowsSystem32FntCache.dll 2013-01-13 19:54:01 604160 ----a-w- C:WindowsSysWow64d3d10level9.dll 2013-01-13 19:53:58 207872 ----a-w- C:WindowsSysWow64WindowsCodecsExt.dll 2013-01-13 19:53:14 187392 ----a-w- C:WindowsSysWow64UIAnimation.dll 2013-01-13 19:51:30 2565120 ----a-w- C:WindowsSystem32d3d10warp.dll 2013-01-13 19:49:17 363008 ----a-w- C:WindowsSystem32dxgi.dll 2013-01-13 19:48:47 161792 ----a-w- C:WindowsSysWow64d3d10_1.dll 2013-01-13 19:46:25 1080832 ----a-w- C:WindowsSysWow64d3d10.dll 2013-01-13 19:38:39 333312 ----a-w- C:WindowsSystem32d3d10_1core.dll 2013-01-13 19:38:21 296960 ----a-w- C:WindowsSystem32d3d10core.dll 2013-01-13 19:37:57 3419136 ----a-w- C:WindowsSysWow64d2d1.dll 2013-01-13 19:25:04 245248 ----a-w- C:WindowsSystem32WindowsCodecsExt.dll 2013-01-13 19:24:33 648192 ----a-w- C:WindowsSystem32d3d10level9.dll 2013-01-13 19:24:30 221184 ----a-w- C:WindowsSystem32UIAnimation.dll 2013-01-13 19:20:42 194560 ----a-w- C:WindowsSystem32d3d10_1.dll 2013-01-13 19:20:04 1238528 ----a-w- C:WindowsSystem32d3d10.dll 2013-01-13 19:10:36 3928064 ----a-w- C:WindowsSystem32d2d1.dll 2013-01-13 19:02:06 417792 ----a-w- C:WindowsSysWow64WMPhoto.dll 2013-01-13 18:34:58 364544 ----a-w- C:WindowsSysWow64XpsGdiConverter.dll 2013-01-13 18:32:43 465920 ----a-w- C:WindowsSystem32WMPhoto.dll 2013-01-13 18:09:52 522752 ----a-w- C:WindowsSystem32XpsGdiConverter.dll 2013-01-13 17:26:42 1158144 ----a-w- C:WindowsSysWow64XpsPrint.dll 2013-01-13 17:05:09 1682432 ----a-w- C:WindowsSystem32XpsPrint.dll 2013-01-04 06:11:21 2284544 ----a-w- C:WindowsSysWow64msmpeg2vdec.dll 2013-01-04 06:11:13 2776576 ----a-w- C:WindowsSystem32msmpeg2vdec.dll 2013-01-04 05:46:09 215040 ----a-w- C:WindowsSystem32winsrv.dll 2013-01-04 04:51:16 5120 ----a-w- C:WindowsSysWow64wow32.dll 2013-01-04 04:43:21 44032 ----a-w- C:Windowsapppatchacwow64.dll 2013-01-04 02:47:35 25600 ----a-w- C:WindowsSysWow64setup16.exe . ============= FINISH: 11:40:23,48 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Ultimate Boot Device: DeviceHarddiskVolume1 Install Date: 6.6.2012 г. 18:44:33 System Uptime: 1.7.2013 г. 11:31:47 (0 hours ago) . Motherboard: Dell Inc. | | 0PJTXT Processor: Intel® Core i5 CPU M 480 @ 2.67GHz | U2E1 | 2373/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 117 GiB total, 65,31 GiB free. D: is FIXED (NTFS) - 195 GiB total, 156,346 GiB free. E: is FIXED (NTFS) - 386 GiB total, 202,904 GiB free. F: is CDROM () G: is Removable H: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP174: 23.6.2013 г. 08:34:25 - Windows Update RP175: 26.6.2013 г. 11:53:09 - Windows Update RP176: 29.6.2013 г. 18:46:57 - Windows Update RP177: 1.7.2013 г. 00:10:56 - ComboFix created restore point . ==== Installed Programs ====================== . µTorrent Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader XI (11.0.03) ATI AVIVO64 Codecs ATI Catalyst Install Manager Call of Duty Modern Warfare 2 Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish Dell System Detect ESET Online Scanner v3 Google Chrome Google Update Helper Intel® Management Engine Components League of Legends Malwarebytes Anti-Malware, версия 1.75.0.1300 Microsoft .NET Framework 1.1 Microsoft .NET Framework 4 Client Profile Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Monopoly City Mozilla Firefox 21.0 (x86 bg) Mozilla Maintenance Service NVIDIA PhysX Pando Media Booster Quickset64 Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Skype™ 6.3 The KMPlayer (remove only) The Lord of the Rings Online™ v03.07.00.8037 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) WIDCOMM Bluetooth Software Windows Driver Package - Broadcom Corporation (BTHUSB) Bluetooth (03/24/2010 6.3.0.2501) WinRAR 4.11 (64-bit) Your Uninstaller! 7 . ==== Event Viewer Messages From Past Week ======== . 1.7.2013 г. 09:56:19, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. 1.7.2013 г. 00:49:05, Error: Service Control Manager [7034] - The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s). 1.7.2013 г. 00:15:26, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 1.7.2013 г. 00:13:55, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. . ==== End Of File ===========================
  9. Здравейте, Имам голям проблем с троянски кон. Този вид е известен като Dark Comet. Всичко тръгна от един приятел който беше правил клип как се работи с него и аз го изтеглих. ( за което съжалявам много ) След малко цъкнах на програмата да се пусне и нищо не стана, затворих папката след 10 секунди я отворих отново и програмката избягала чак в C диска, папка Users и така така някъде си навътре... Четох много постове и изтеглих някои програми: - Malwarebytes Anti-Malware - esetsmartinstaller_enu - noscript - CryptoPrevent - MyDefrag - FRST64 И изтрих стара ми антивирусна Advanced System Care 8. Програмата Malwarebytes Anti-Malware я пусках да изчисти уж някои неща и какво да видя... Последно не си спомням колко бяха, но говорим за повече от 150. Така, така сега търся помощ в смисъл какво ви е нужно освен двата текстови документа от FRST които прикачих. И както ви е известно четох малко за този троянски кон и както си пише така и стана ... Метнал се е на csrss, но нещо не знам какво направих и изчезна и тей тей си вървъ из файловете, до одеве ми местеше иконите.. Та ся утихна малко тоз кон и се оставям на ваши ръце. Благодаря предварително ! Addition.txt FRST.txt
  10. Здравейте, Проблема е че ми отваря Pagesinxt.com вместо www.lpfc.net. Няколко пъти ми отвори Pagesinxt.com вместо www.arenabg.com , но за сега проблема с арената изчезна и си се отваря нормално. Пробвах няколко спай клинара, но нито те нито антивирусната засича нещо. (На работа сме с офицялна антивирусна "Панда" и там също не открива проблем и страницата си е отваря нормално.) Операционата система на кокмпютърат ми е Win 7 64b SP 1. Ползвам IE 9 и Google chrome като браузери. DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.10.2Run by Gecata at 20:57:57 on 2013-01-11Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.8086.4417 [GMT 2:00].AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ===============.C:Windowssystem32wininit.exeC:Windowssystem32lsm.exeC:Windowssystem32svchost.exe -k DcomLaunchC:Windowssystem32nvvsvc.exeC:Program Files (x86)NVIDIA Corporation3D VisionnvSCPAPISvr.exeC:Windowssystem32svchost.exe -k RPCSSC:WindowsSystem32svchost.exe -k LocalServiceNetworkRestrictedC:WindowsSystem32svchost.exe -k LocalSystemNetworkRestrictedC:Windowssystem32svchost.exe -k netsvcsC:Windowssystem32svchost.exe -k LocalServiceC:Windowssystem32svchost.exe -k NetworkServiceC:Program FilesAVAST SoftwareAvastAvastSvc.exeC:Program FilesNVIDIA CorporationDisplaynvxdsync.exeC:Windowssystem32nvvsvc.exeC:Windowssystem32Dwm.exeC:WindowsSystem32spoolsv.exeC:Windowssystem32taskhost.exeC:Windowssystem32svchost.exe -k LocalServiceNoNetworkC:Program Files (x86)Common FilesAdobeARM1.0armsvc.exeC:Program FilesInteliCLS ClientHeciServer.exeC:Program Files (x86)IntelIntel® Management Engine ComponentsFWServiceIntelMeFWService.exeC:Program FilesIntelIntel® Smart Connect Technology AgentiSCTAgent.exeC:Program Files (x86)IntelIntel® Management Engine ComponentsDALjhi_service.exeC:Windowssystem32svchost.exe -k imgsvcC:Program FilesMicrosoft Mouse and Keyboard Centeritype.exeC:Program FilesMicrosoft Mouse and Keyboard Centeripoint.exeC:Program Files (x86)IntelIntel® USB 3.0 eXtensible Host Controller DriverApplicationiusb3mon.exeC:Program FilesAVAST SoftwareAvastAvastUI.exeC:Program Files (x86)Common FilesJavaJava Updatejusched.exeC:Windowssystem32SearchIndexer.exeC:Program FilesWindows Media Playerwmpnetwk.exeC:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonationC:WindowsSystem32svchost.exe -k LocalServicePeerNetC:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exeC:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exeC:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exeC:Program Files (x86)NVIDIA CorporationNVIDIA Update Coredaemonu.exeC:WindowsSystem32svchost.exe -k secsvcsC:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exeC:Windowsexplorer.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)Mumblemumble.exeC:GamesWoTWorldOfTanks.exeC:Program Files (x86)SkypePhoneSkype.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Windowssystem32NOTEPAD.EXEC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Program Files (x86)GoogleChromeApplicationchrome.exeC:Windowssystem32taskeng.exeC:Windowssystem32conhost.exeC:Windowssystem32wbemwmiprvse.exeC:WindowsSystem32cscript.exe.============== Pseudo HJT Report ===============.uStart Page = about:blankmWinlogon: Userinit = c:windowssyswow64userinit.exe,BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dllBHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program Files (x86)Javajre7binssv.dllBHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dllBHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre7binjp2ssv.dllTB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dllmRun: [iAStorIcon] C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIconLaunch.exe "C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe" 60mRun: [uSB3MON] "C:Program Files (x86)IntelIntel® USB 3.0 eXtensible Host Controller DriverApplicationiusb3mon.exe"mRun: [avast] "C:Program FilesAVAST SoftwareAvastavastUI.exe" /noguimRun: [Adobe ARM] "C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe"mRun: [sunJavaUpdateSched] "C:Program Files (x86)Common FilesJavaJava Updatejusched.exe"mPolicies-Explorer: NoActiveDesktop = dword:1mPolicies-Explorer: NoActiveDesktopChanges = dword:1mPolicies-System: ConsentPromptBehaviorUser = dword:3mPolicies-System: EnableUIADesktopToggle = dword:0mPolicies-System: PromptOnSecureDesktop = dword:0DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cabTCP: NameServer = 77.77.167.55 77.77.167.56TCP: Interfaces{7DD19921-7956-473B-8D87-F6F7737B03B7} : DHCPNameServer = 77.77.167.55 77.77.167.56Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dllSSODL: WebCheck - <orphaned>x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dllx64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dllx64-Run: [igfxTray] C:WindowsSystem32igfxtray.exex64-Run: [HotKeysCmds] C:WindowsSystem32hkcmd.exex64-Run: [Persistence] C:WindowsSystem32igfxpers.exex64-Run: [intelliType Pro] "C:Program FilesMicrosoft Mouse and Keyboard Centeritype.exe"x64-Run: [intelliPoint] "C:Program FilesMicrosoft Mouse and Keyboard Centeripoint.exe"x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>x64-Notify: igfxcui - igfxdev.dllx64-SSODL: WebCheck - <orphaned>.============= SERVICES / DRIVERS ===============.R0 asahci64;asahci64;C:WindowsSystem32driversasahci64.sys [2011-9-21 49760]R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:WindowsSystem32driversiusb3hcs.sys [2012-12-17 16152]R1 AsrAppCharger;AsrAppCharger;C:WindowsSystem32driversAsrAppCharger.sys [2012-12-17 17192]R1 aswSnx;aswSnx;C:WindowsSystem32driversaswSnx.sys [2012-12-18 984144]R1 aswSP;aswSP;C:WindowsSystem32driversaswSP.sys [2012-12-18 370288]R1 HWiNFO32;HWiNFO32/64 Kernel Driver;C:WindowsSystem32driversHWiNFO64A.SYS [2012-12-18 29672]R2 AdobeARMservice;Adobe Acrobat Update Service;C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [2012-12-18 65192]R2 aswFsBlk;aswFsBlk;C:WindowsSystem32driversaswFsBlk.sys [2012-12-18 25232]R2 aswMonFlt;aswMonFlt;C:WindowsSystem32driversaswMonFlt.sys [2012-12-18 71600]R2 avast! Antivirus;avast! Antivirus;C:Program FilesAVAST SoftwareAvastAvastSvc.exe [2012-12-18 44808]R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe [2012-12-17 13632]R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:Program FilesInteliCLS ClientHeciServer.exe [2012-2-2 628448]R2 Intel® ME Service;Intel® ME Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsFWServiceIntelMeFWService.exe [2012-12-17 128280]R2 ISCTAgent;ISCT Always Updated Agent;C:Program FilesIntelIntel® Smart Connect Technology AgentiSCTAgent.exe [2012-2-9 133632]R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsDALJhi_service.exe [2012-12-17 161560]R2 nvUpdatusService;NVIDIA Update Service Daemon;C:Program Files (x86)NVIDIA CorporationNVIDIA Update Coredaemonu.exe [2012-12-17 1260472]R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:Program Files (x86)NVIDIA Corporation3D VisionnvSCPAPISvr.exe [2012-12-29 383416]R2 UNS;Intel® Management and Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2012-12-17 363800]R3 asmthub3;ASMedia USB3 Hub Service;C:WindowsSystem32driversasmthub3.sys [2011-3-4 126952]R3 asmtxhci;ASMEDIA XHCI Service;C:WindowsSystem32driversasmtxhci.sys [2011-3-4 390632]R3 ikbevent;Intel Upper keyboard Class Filter Driver;C:WindowsSystem32driversikbevent.sys [2012-2-9 25536]R3 imsevent;Intel Upper Mouse Class Filter Driver;C:WindowsSystem32driversimsevent.sys [2012-2-9 25536]R3 IntcDAud;Intel® Display Audio;C:WindowsSystem32driversIntcDAud.sys [2012-12-17 331264]R3 ISCT;Intel® Smart Connect Technology Device Driver;C:WindowsSystem32driversISCTD64.sys [2012-2-9 44992]R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:WindowsSystem32driversiusb3hub.sys [2012-12-17 356120]R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:WindowsSystem32driversiusb3xhc.sys [2012-12-17 788760]R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:WindowsSystem32driversk57nd60a.sys [2011-5-9 425000]R3 MEIx64;Intel® Management Engine Interface ;C:WindowsSystem32driversHECIx64.sys [2012-12-17 60184]R3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);C:WindowsSystem32driversWPRO_41_2001.sys [2012-12-17 34752]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576]S2 gupdate;Google Update Service (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2012-12-17 116648]S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2012-11-9 160944]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2012-12-17 251400]S3 cphs;Intel® Content Protection HECI Service;C:WindowsSysWOW64IntelCpHeciSvc.exe [2012-12-17 276288]S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2010-11-21 71168]S3 gupdatem;Google Update Service (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2012-12-17 116648]S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2010-11-21 20992]S3 Synth3dVsc;Synth3dVsc;C:WindowsSystem32driversSynth3dVsc.sys [2010-11-21 88960]S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32driversterminpt.sys [2010-11-21 34816]S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-21 59392]S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-21 31232]S3 tsusbhub;tsusbhub;C:WindowsSystem32driverstsusbhub.sys [2010-11-21 117248]S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2012-7-13 1255736].=============== Created Last 30 ================.2013-01-11 17:37:12 -------- d-----w- C:WindowsERUNT2013-01-11 17:36:59 -------- d-----w- C:JRT2013-01-11 17:13:54 -------- d-----w- C:WindowsSystem32appmgmt2013-01-11 17:13:20 94656 ----a-w- C:WindowsSystem32WPRO_41_2001woem.tmp2013-01-11 16:55:07 -------- d-----w- C:Program FilesEnigma Software Group2013-01-11 16:54:58 -------- d-----w- C:Windows83B952C7F8F34CA3B4C533C85B24E478.TMP2013-01-11 16:54:58 -------- d-----w- C:Program Files (x86)Common FilesWise Installation Wizard2013-01-11 16:16:32 -------- d-----w- C:UsersGecataAppDataLocalOpera2013-01-11 16:04:30 -------- d-----w- C:UsersGecataAppDataRoamingMalwarebytes2013-01-11 16:04:22 -------- d-----w- C:ProgramDataMalwarebytes2013-01-11 16:04:10 -------- d-----w- C:UsersGecataAppDataLocalPrograms2013-01-11 15:55:34 9125352 ----a-w- C:ProgramDataMicrosoftWindows DefenderDefinition Updates{6A13E628-C770-4918-A422-3073D816D9E4}mpengine.dll2013-01-09 18:11:09 -------- d-----w- C:Program FilesMicrosoft Mouse and Keyboard Center2013-01-08 19:25:09 9389888 ----a-w- C:WindowsSystem32nvcuda.dll2012-12-29 00:54:24 550328 ----a-w- C:WindowsSysWow64nvStreaming.exe2012-12-26 21:21:47 859072 ----a-w- C:WindowsSysWow64npDeployJava1.dll2012-12-26 21:21:47 779704 ----a-w- C:WindowsSysWow64deployJava1.dll2012-12-26 21:21:46 95184 ----a-w- C:WindowsSysWow64WindowsAccessBridge-32.dll2012-12-24 09:13:46 -------- d-----w- C:UsersGecataAppDataLocalElevatedDiagnostics2012-12-23 08:56:45 -------- d-----w- C:Program Files (x86)SpeedFan2012-12-22 20:49:26 -------- d-----w- C:UsersGecataAppDataLocalCrashDumps2012-12-21 15:47:07 46080 ----a-w- C:WindowsSystem32atmlib.dll2012-12-21 15:47:07 367616 ----a-w- C:WindowsSystem32atmfd.dll2012-12-21 15:47:07 34304 ----a-w- C:WindowsSysWow64atmlib.dll2012-12-21 15:47:07 295424 ----a-w- C:WindowsSysWow64atmfd.dll2012-12-19 08:37:39 -------- d-----w- C:UsersGecataAppDataLocalAdobe2012-12-18 20:49:15 29672 ----a-w- C:WindowsSystem32driversHWiNFO64A.SYS2012-12-18 20:48:52 -------- d-----w- C:Program FilesHWiNFO642012-12-18 19:28:10 5632 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32DotNetInstaller.exe2012-12-18 17:18:14 -------- d-----w- C:WindowsSystem32wbemFrameworkrootOpenHardwareMonitor2012-12-18 17:18:14 -------- d-----w- C:WindowsSystem32wbemFrameworkroot2012-12-18 17:18:14 -------- d-----w- C:WindowsSystem32wbemFramework2012-12-18 16:24:54 -------- d-----w- C:Program Files (x86)Winamp Detect2012-12-18 16:02:45 -------- d-----w- C:Program Files (x86)Common FilesPX Storage Engine2012-12-18 10:27:34 -------- d-----w- C:Program Files (x86)GRETECH2012-12-18 08:48:53 -------- d-----w- C:ProgramDataCurse Client2012-12-18 08:03:09 984144 ----a-w- C:WindowsSystem32driversaswSnx.sys2012-12-18 08:03:09 71600 ----a-w- C:WindowsSystem32driversaswMonFlt.sys2012-12-18 08:03:09 54072 ----a-w- C:WindowsSystem32driversaswRdr2.sys2012-12-18 08:03:02 41224 ----a-w- C:WindowsavastSS.scr2012-12-18 07:50:54 -------- d-----w- C:ProgramDataAVAST Software2012-12-18 07:50:54 -------- d-----w- C:Program FilesAVAST Software2012-12-18 07:42:11 9728 ----a-w- C:WindowsSystem32Wdfres.dll2012-12-18 07:42:11 785512 ----a-w- C:WindowsSystem32driversWdf01000.sys2012-12-18 07:42:11 54376 ----a-w- C:WindowsSystem32driversWdfLdr.sys2012-12-18 07:42:11 2560 ----a-w- C:WindowsSystem32driversen-USwdf01000.sys.mui2012-12-18 07:41:00 294912 ----a-w- C:WindowsSystem32browserchoice.exe2012-12-18 07:39:37 1659760 ----a-w- C:WindowsSystem32driversntfs.sys2012-12-18 07:36:24 2622464 ----a-w- C:WindowsSystem32wucltux.dll2012-12-18 07:36:22 99840 ----a-w- C:WindowsSystem32wudriver.dll2012-12-18 07:36:22 36864 ----a-w- C:WindowsSystem32wuapp.exe2012-12-18 07:36:22 186752 ----a-w- C:WindowsSystem32wuwebv.dll2012-12-18 07:15:33 -------- d-----w- C:WindowsPanther2012-12-17 22:40:12 -------- d-----w- C:UsersGecataAppDataRoamingWargaming.net2012-12-17 22:38:11 -------- d-----w- C:WindowsSysWow64directx2012-12-17 22:34:37 -------- d-----w- C:Program Files (x86)uTorrent2012-12-17 22:34:29 -------- d-----w- C:UsersGecataAppDataRoaminguTorrent2012-12-17 22:31:51 453456 ----a-w- C:WindowsSysWow64d3dx10_42.dll2012-12-17 22:31:51 235344 ----a-w- C:WindowsSysWow64d3dx11_42.dll2012-12-17 22:31:51 1892184 ----a-w- C:WindowsSysWow64D3DX9_42.dll2012-12-17 22:31:47 -------- d-----w- C:ProgramDataCCP2012-12-17 22:31:24 -------- d-----w- C:UsersGecataAppDataLocalCCP2012-12-17 22:24:17 -------- d-----w- C:Games2012-12-17 22:20:35 -------- d-----w- C:UsersGecataAppDataRoamingNVIDIA2012-12-17 21:55:07 -------- d-----w- C:UsersGecataAppDataRoamingMumble2012-12-17 21:54:57 -------- d-----w- C:Program Files (x86)Mumble2012-12-17 21:51:04 -------- d-----w- C:UsersGecataAppDataLocalGoogle2012-12-17 21:50:59 -------- d-----w- C:UsersGecataAppDataLocalDeployment2012-12-17 21:50:59 -------- d-----w- C:UsersGecataAppDataLocalApps2012-12-17 21:46:37 -------- d-----r- C:Program Files (x86)Skype2012-12-17 21:45:11 -------- d-----w- C:Program Files (x86)NVIDIA Corporation2012-12-17 21:45:10 884152 ----a-w- C:WindowsSystem32nvvsvc.exe2012-12-17 21:45:10 63928 ----a-w- C:WindowsSystem32nvshext.dll2012-12-17 21:45:10 6382008 ----a-w- C:WindowsSystem32nvcpl.dll2012-12-17 21:45:10 3455416 ----a-w- C:WindowsSystem32nvsvc64.dll2012-12-17 21:45:10 118712 ----a-w- C:WindowsSystem32nvmctray.dll2012-12-17 21:45:06 -------- d-----w- C:ProgramDataNVIDIA Corporation2012-12-17 21:44:58 2824656 ----a-w- C:WindowsSystem32nvapi64.dll2012-12-17 21:44:58 2504248 ----a-w- C:WindowsSysWow64nvapi.dll2012-12-17 21:44:58 20450232 ----a-w- C:WindowsSysWow64nvoglv32.dll2012-12-17 21:44:58 1813432 ----a-w- C:WindowsSystem32nvdispco64.dll2012-12-17 21:44:58 1504696 ----a-w- C:WindowsSystem32nvdispgenco64.dll2012-12-17 21:44:45 -------- d-----w- C:Program FilesNVIDIA Corporation2012-12-17 21:44:34 -------- d-----w- C:NVIDIA2012-12-17 21:43:28 74248 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl2012-12-17 21:43:28 697864 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe2012-12-17 21:38:47 -------- d-----w- C:Program Files (x86)Common FilesIntel Corporation2012-12-17 21:36:19 17192 ----a-w- C:WindowsSystem32driversAsrAppCharger.sys2012-12-17 21:36:18 -------- d-----w- C:Program FilesASRock Utility2012-12-17 21:36:05 34752 ----a-w- C:WindowsSystem32driversWPRO_41_2001.sys2012-12-17 21:35:03 -------- d-----w- C:Program Files (x86)ASM106xSATA2012-12-17 21:34:14 -------- d-----w- C:Program Files (x86)ASM104xUSB32012-12-17 21:34:04 16152 ----a-w- C:WindowsSystem32driversiusb3hcs.sys2012-12-17 21:33:58 788760 ----a-w- C:WindowsSystem32driversiusb3xhc.sys2012-12-17 21:33:57 356120 ----a-w- C:WindowsSystem32driversiusb3hub.sys2012-12-17 21:32:35 15128 ----a-w- C:WindowsSystem32driversIntelMEFWVer.dll2012-12-17 21:32:15 -------- d-----w- C:UsersGecataAppDataRoamingIntel Corporation2012-12-17 21:31:42 -------- d-----w- C:Program Files (x86)Common FilespostureAgent2012-12-17 21:31:41 60184 ----a-w- C:WindowsSystem32driversHECIx64.sys2012-12-17 21:30:11 569152 ----a-w- C:WindowsSystem32driversiaStor.sys2012-12-17 21:30:03 -------- d-----w- C:Program FilesBroadcom2012-12-17 21:29:57 -------- d-sh--w- C:WindowsInstaller2012-12-17 21:24:44 53248 ----a-r- C:WindowsSysWow64CSVer.dll2012-12-17 21:24:38 -------- d-----w- C:Intel2012-12-17 21:23:34 1698408 ----a-r- C:WindowsRtlExUpd.dll2012-12-17 21:23:34 -------- d-----w- C:Program Files (x86)Temp2012-12-17 21:23:33 757760 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32iKernel.dll2012-12-17 21:23:33 69715 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32ctor.dll2012-12-17 21:23:33 65024 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32ISBEW64.exe2012-12-17 21:23:33 32768 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTimeObjectps.dll2012-12-17 21:23:33 274432 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32iscript.dll2012-12-17 21:23:33 204800 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32iuser.dll2012-12-17 21:23:33 200836 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32iGdi.dll2012-12-17 21:23:32 331908 ----a-w- C:Program Files (x86)Common FilesInstallShieldProfessionalRunTime1150Intel32setup.dll.==================== Find3M ====================.2012-12-07 13:20:16 441856 ----a-w- C:WindowsSystem32Wpc.dll2012-12-07 13:15:31 2746368 ----a-w- C:WindowsSystem32gameux.dll2012-12-07 12:26:17 308736 ----a-w- C:WindowsSysWow64Wpc.dll2012-12-07 12:20:43 2576384 ----a-w- C:WindowsSysWow64gameux.dll2012-12-07 11:20:04 30720 ----a-w- C:WindowsSystem32usk.rs2012-12-07 11:20:03 43520 ----a-w- C:WindowsSystem32csrr.rs2012-12-07 11:20:03 23552 ----a-w- C:WindowsSystem32oflc.rs2012-12-07 11:20:01 45568 ----a-w- C:WindowsSystem32oflc-nz.rs2012-12-07 11:20:01 44544 ----a-w- C:WindowsSystem32pegibbfc.rs2012-12-07 11:20:01 20480 ----a-w- C:WindowsSystem32pegi-fi.rs2012-12-07 11:20:00 20480 ----a-w- C:WindowsSystem32pegi-pt.rs2012-12-07 11:19:59 20480 ----a-w- C:WindowsSystem32pegi.rs2012-12-07 11:19:58 46592 ----a-w- C:WindowsSystem32fpb.rs2012-12-07 11:19:57 40960 ----a-w- C:WindowsSystem32cob-au.rs2012-12-07 11:19:57 21504 ----a-w- C:WindowsSystem32grb.rs2012-12-07 11:19:57 15360 ----a-w- C:WindowsSystem32djctq.rs2012-12-07 11:19:56 55296 ----a-w- C:WindowsSystem32cero.rs2012-12-07 11:19:55 51712 ----a-w- C:WindowsSystem32esrb.rs2012-11-30 05:45:35 362496 ----a-w- C:WindowsSystem32wow64win.dll2012-11-30 05:45:35 243200 ----a-w- C:WindowsSystem32wow64.dll2012-11-30 05:45:35 13312 ----a-w- C:WindowsSystem32wow64cpu.dll2012-11-30 05:45:14 215040 ----a-w- C:WindowsSystem32winsrv.dll2012-11-30 05:43:12 16384 ----a-w- C:WindowsSystem32ntvdm64.dll2012-11-30 05:41:07 424448 ----a-w- C:WindowsSystem32KernelBase.dll2012-11-30 04:54:00 5120 ----a-w- C:WindowsSysWow64wow32.dll2012-11-30 04:53:59 274944 ----a-w- C:WindowsSysWow64KernelBase.dll2012-11-30 03:23:48 338432 ----a-w- C:WindowsSystem32conhost.exe2012-11-30 02:44:06 25600 ----a-w- C:WindowsSysWow64setup16.exe2012-11-30 02:44:04 7680 ----a-w- C:WindowsSysWow64instnm.exe2012-11-30 02:44:04 14336 ----a-w- C:WindowsSysWow64ntvdm64.dll2012-11-30 02:44:03 2048 ----a-w- C:WindowsSysWow64user.exe2012-11-30 02:38:59 6144 ---ha-w- C:WindowsSysWow64api-ms-win-security-base-l1-1-0.dll2012-11-30 02:38:59 4608 ---ha-w- C:WindowsSysWow64api-ms-win-core-threadpool-l1-1-0.dll2012-11-30 02:38:59 3584 ---ha-w- C:WindowsSysWow64api-ms-win-core-xstate-l1-1-0.dll2012-11-30 02:38:59 3072 ---ha-w- C:WindowsSysWow64api-ms-win-core-util-l1-1-0.dll2012-11-23 03:26:31 3149824 ----a-w- C:WindowsSystem32win32k.sys2012-11-23 03:13:57 68608 ----a-w- C:WindowsSystem32taskhost.exe2012-11-22 05:44:23 800768 ----a-w- C:WindowsSystem32usp10.dll2012-11-22 04:45:03 626688 ----a-w- C:WindowsSysWow64usp10.dll2012-11-20 05:48:49 307200 ----a-w- C:WindowsSystem32ncrypt.dll2012-11-20 04:51:09 220160 ----a-w- C:WindowsSysWow64ncrypt.dll2012-11-14 06:11:44 2312704 ----a-w- C:WindowsSystem32jscript9.dll2012-11-14 06:04:11 1392128 ----a-w- C:WindowsSystem32wininet.dll2012-11-14 06:02:49 1494528 ----a-w- C:WindowsSystem32inetcpl.cpl2012-11-14 05:57:46 599040 ----a-w- C:WindowsSystem32vbscript.dll2012-11-14 05:57:35 173056 ----a-w- C:WindowsSystem32ieUnatt.exe2012-11-14 05:52:40 2382848 ----a-w- C:WindowsSystem32mshtml.tlb2012-11-14 02:09:22 1800704 ----a-w- C:WindowsSysWow64jscript9.dll2012-11-14 01:58:15 1427968 ----a-w- C:WindowsSysWow64inetcpl.cpl2012-11-14 01:57:37 1129472 ----a-w- C:WindowsSysWow64wininet.dll2012-11-14 01:49:25 142848 ----a-w- C:WindowsSysWow64ieUnatt.exe2012-11-14 01:48:27 420864 ----a-w- C:WindowsSysWow64vbscript.dll2012-11-14 01:44:42 2382848 ----a-w- C:WindowsSysWow64mshtml.tlb2012-11-09 05:45:32 750592 ----a-w- C:WindowsSystem32win32spl.dll2012-11-09 05:45:09 2048 ----a-w- C:WindowsSystem32tzres.dll2012-11-09 04:43:04 492032 ----a-w- C:WindowsSysWow64win32spl.dll2012-11-09 04:42:49 2048 ----a-w- C:WindowsSysWow64tzres.dll2012-11-02 13:38:36 862664 ----a-w- C:WindowsSysWow64msvcr110.dll2012-11-02 13:38:36 828872 ----a-w- C:WindowsSystem32msvcr110.dll2012-11-02 13:38:36 661448 ----a-w- C:WindowsSystem32msvcp110.dll2012-11-02 13:38:36 534480 ----a-w- C:WindowsSysWow64msvcp110.dll2012-11-02 13:38:36 354264 ----a-w- C:WindowsSystem32vccorlib110.dll2012-11-02 13:38:36 251864 ----a-w- C:WindowsSysWow64vccorlib110.dll2012-11-02 05:59:11 478208 ----a-w- C:WindowsSystem32dpnet.dll2012-11-02 05:11:31 376832 ----a-w- C:WindowsSysWow64dpnet.dll2012-11-01 05:43:42 2002432 ----a-w- C:WindowsSystem32msxml6.dll2012-11-01 05:43:42 1882624 ----a-w- C:WindowsSystem32msxml3.dll2012-11-01 04:47:54 1389568 ----a-w- C:WindowsSysWow64msxml6.dll2012-11-01 04:47:54 1236992 ----a-w- C:WindowsSysWow64msxml3.dll2012-10-16 08:38:37 135168 ----a-w- C:WindowsapppatchAppPatch64AcXtrnal.dll2012-10-16 08:38:34 350208 ----a-w- C:WindowsapppatchAppPatch64AcLayers.dll2012-10-16 07:39:52 561664 ----a-w- C:WindowsapppatchAcLayers.dll.============= FINISH: 20:58:05,35 =============== .UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows 7 Ultimate Boot Device: DeviceHarddiskVolume1Install Date: 17.12.2012 г. 23:18:48System Uptime: 11.1.2013 г. 19:35:20 (1 hours ago).Motherboard: ASRock | | Z77 Extreme4Processor: Intel® Core i5-3570K CPU @ 3.40GHz | CPUSocket | 3298/100mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 119 GiB total, 70,943 GiB free.D: is FIXED (NTFS) - 120 GiB total, 119,758 GiB free.E: is FIXED (NTFS) - 812 GiB total, 618,187 GiB free.F: is CDROM ().==== Disabled Device Manager Items =============.Class GUID: {4d36e968-e325-11ce-bfc1-08002be10318}Description: Intel® HD Graphics 4000Device ID: PCIVEN_8086&DEV_0162&SUBSYS_01621849&REV_093&11583659&0&10Manufacturer: Intel CorporationName: Intel® HD Graphics 4000PNP Device ID: PCIVEN_8086&DEV_0162&SUBSYS_01621849&REV_093&11583659&0&10Service: igfx.==== System Restore Points ===================.RP20: 4.1.2013 г. 17:30:07 - Windows UpdateRP21: 8.1.2013 г. 17:46:05 - Windows UpdateRP22: 9.1.2013 г. 19:41:51 - Windows UpdateRP23: 9.1.2013 г. 20:10:20 - Windows UpdateRP24: 9.1.2013 г. 20:11:05 - DCInstallRestorePointRP25: 11.1.2013 г. 18:30:29 - Windows UpdateRP26: 11.1.2013 г. 18:34:24 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.RP27: 11.1.2013 г. 18:40:17 - StopZILLA! Restore Point.RP28: 11.1.2013 г. 19:13:45 - Removed SpyHunterRP29: 11.1.2013 г. 19:14:18 - Removed STOPzilla. Available with Windows Installer version 1.2 and later..==== Installed Programs ======================.µTorrent7-Zip 9.20 (x64 edition)Adobe Flash Player 11 ActiveXAdobe Reader XI (11.0.01)Asmedia ASM104x USB 3.0 Host Controller DriverAsmedia ASM106x SATA Host Controller DriverASRock App Charger v1.0.5avast! Free AntivirusBroadcom NetLink ControllerCurse ClientGOM PlayerGoogle ChromeGoogle Update HelperHWiNFO64 Version 4.08Intel® Control CenterIntel® Manageability Engine Firmware Recovery AgentIntel® Management Engine ComponentsIntel® OpenCL CPU RuntimeIntel® Processor GraphicsIntel® Rapid Storage TechnologyIntel® Smart Connect Technology 2.0 x64Intel® USB 3.0 eXtensible Host Controller DriverIntel® Trusted Connect Service ClientJava 7 Update 10Java Auto UpdaterMicrosoft .NET Framework 4 Client ProfileMicrosoft Mouse and Keyboard CenterMicrosoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219Mumble 1.2.3NVIDIA 3D Vision Controller Driver 310.90NVIDIA 3D Vision Driver 310.90NVIDIA Control Panel 310.90NVIDIA Graphics Driver 310.90NVIDIA Install ApplicationNVIDIA PhysXNVIDIA PhysX System Software 9.12.1031NVIDIA Stereoscopic 3D DriverNVIDIA Update 1.11.3NVIDIA Update ComponentsSecurity Update for Microsoft .NET Framework 4 Client Profile (KB2604121)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)Skype™ 6.0Update for Microsoft .NET Framework 4 Client Profile (KB2468871)Update for Microsoft .NET Framework 4 Client Profile (KB2533523)Update for Microsoft .NET Framework 4 Client Profile (KB2600217)WinampWinamp Detector Plug-in.==== End Of File =========================== Благодаря предварително за отделеното време.
  11. Здравейте, имам лаптоп Toshiba Satellite L750D с win 7, 64битов. Имам съмнение за вирус, от вчера като пусна клипче в нета, тръгва и след известно време екрана става бял или черен и процесора удря 86 процента... плюс на моменти като цяло лаптопа ми се вижда по - бавен когато съм в интернет. Пуснах бързо сканиране с Malwarebytes Anti-Malware и ми намери 12 PUP. файла (registry key)....не знам дали наистина са за изтриване. Благодаря предварително! DDS (Ver_2011-09-30.01) - NTFS_AMD64Internet Explorer: 9.10.9200.16721 BrowserJavaVersion: 10.17.2Run by VESELA at 20:45:08 on 2013-12-17Microsoft Windows 7 Home Premium 6.1.7601.1.1251.359.1033.18.5607.3425 [GMT 2:00].AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ===============.C:Windowssystem32wininit.exeC:Windowssystem32lsm.exeC:Windowssystem32svchost.exe -k DcomLaunchC:Windowssystem32svchost.exe -k RPCSSC:Windowssystem32atiesrxx.exeC:WindowsSystem32svchost.exe -k LocalServiceNetworkRestrictedC:WindowsSystem32svchost.exe -k LocalSystemNetworkRestrictedC:Windowssystem32svchost.exe -k LocalServiceC:Windowssystem32svchost.exe -k netsvcsC:Program FilesWTouchWTouchService.exeC:Windowssystem32atieclxx.exeC:WindowsSYSTEM32WISPTIS.EXEC:Windowssystem32svchost.exe -k NetworkServiceC:Windowssystem32WLANExt.exeC:Program FilesAVAST SoftwareAvastAvastSvc.exeC:Windowssystem32conhost.exeC:WindowsSYSTEM32WISPTIS.EXEC:Program FilesCommon Filesmicrosoft sharedinkTabTip.exeC:Program FilesWTouchWTouchUser.exeC:Windowssystem32Dwm.exeC:WindowsSystem32spoolsv.exeC:Program Files (x86)Common FilesMicrosoft SharedInkTabTip32.exeC:Windowssystem32svchost.exe -k LocalServiceNoNetworkC:Windowssystem32taskhost.exeC:WindowsExplorer.EXEC:Program Files (x86)Common FilesAdobeARM1.0armsvc.exeC:Program Files (x86)BonjourmDNSResponder.exeC:Program Files (x86)ConnectifyConnectifyService.exeC:Program Files (x86)ConnectifyConnectifyD.exeC:Windowssystem32conhost.exeC:Windowssystem32svchost.exe -k imgsvcC:Windowssystem32Pen_Tablet.exeC:Program FilesToshibaPower SaverTosCoSrv.exeC:WindowsSystem32svchost.exe -k secsvcsC:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXEC:Program FilesTOSHIBATECOTecoService.exeC:Windowssystem32WTabletPen_TabletUser.exeC:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exeC:Windowssystem32Pen_Tablet.exeC:Windowssystem32svchost.exe -k NetworkServiceNetworkRestrictedC:Windowssystem32wbemwmiprvse.exeC:WindowsSystem32WUDFHost.exeC:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonationC:Program FilesToshibaPower SaverTPwrMain.exeC:Windowssystem32SearchIndexer.exeC:Program FilesToshibaFlashCardsTCrdMain.exeC:Program FilesSynapticsSynTPSynTPEnh.exeC:Program FilesToshibaTECOTeco.exeC:Program FilesSynapticsSynTPSynTPHelper.exeC:Program FilesWindows Sidebarsidebar.exeC:Program Files (x86)SkypePhoneSkype.exeC:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exeC:Program Files (x86)TOSHIBABluetooth Toshiba StackItSecMng.exeC:Program FilesAVAST SoftwareAvastAvastUI.exeC:Program Files (x86)ATI TechnologiesATI.ACECore-StaticMOM.exeC:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCCC.exec:Program Files (x86)NeroUpdateNASvc.exeC:Program FilesWindows Media Playerwmpnetwk.exeC:WindowsMicrosoft.NetFramework64v3.0WPFPresentationFontCache.exeC:Program FilesCommon FilesMicrosoft SharedInkInputPersonalization.exeC:WindowsSystem32svchost.exe -k LocalServicePeerNetC:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSmartSrv.exeC:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSENotify.exeC:Program FilesTOSHIBATPHMTPCHSrv.exeC:Windowssystem32svchost.exe -k SDRSVCC:Program FilesTOSHIBATPHMTPCHWMsg.exeC:Program Files (x86)Mozilla Firefoxfirefox.exeC:Windowssystem32taskmgr.exeC:Program Files (x86)Windows LivePhoto GalleryWLXPhotoGallery.exeC:WindowsSysWOW64ctfmon.exeC:Program FilesCommon Filesmicrosoft sharedinkTabTip.exeC:Windowssystem32DllHost.exeC:Windowssystem32conhost.exeC:Windowssystem32wbemwmiprvse.exeC:WindowsSystem32cscript.exe.============== Pseudo HJT Report ===============.uStart Page = hxxp://search.babylon.com/?affID=119781&tt=gc_&babsrc=HP_ss_din2g&mntrId=B6C0E0CA947056E2BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program Files (x86)Microsoft OfficeOffice14GROOVEEX.DLLBHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dllBHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dllBHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dllBHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program Files (x86)Microsoft OfficeOffice14URLREDIR.DLLTB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dllTB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dllTB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dlluRun: [sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRunuRun: [skype] "C:Program Files (x86)SkypePhoneSkype.exe" /minimized /regrunuRun: [swg] "C:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe"mRun: [startCCC] "C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe" MSRunmRun: [iTSecMng] C:Program Files (x86)TOSHIBABluetooth Toshiba StackItSecMng.exe /STARTmRun: [avast] "C:Program FilesAVAST SoftwareAvastavastUI.exe" /noguimRunOnce: [Malwarebytes Anti-Malware] C:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exe /install /silentuPolicies-Explorer: NoDrives = dword:0mPolicies-Explorer: NoDrives = dword:0mPolicies-System: ConsentPromptBehaviorAdmin = dword:0mPolicies-System: ConsentPromptBehaviorUser = dword:3mPolicies-System: EnableLUA = dword:0mPolicies-System: EnableUIADesktopToggle = dword:0mPolicies-System: PromptOnSecureDesktop = dword:0IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dllIE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIE.dllIE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:Program Files (x86)Microsoft OfficeOffice14ONBttnIELinkedNotes.dllDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cabDPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cabTCP: Interfaces{37EE4525-92BA-4103-B7D2-D63E938D54D2} : NameServer = 212.25.58.229 212.25.58.2TCP: Interfaces{EC987100-A9DD-4878-87F3-047D0A4FDECD}244534D2144435C4 : DHCPNameServer = 192.168.1.1TCP: Interfaces{EC987100-A9DD-4878-87F3-047D0A4FDECD}34F6E6E6563647966697D20527F626F6F6B6 : DHCPNameServer = 192.168.210.1TCP: Interfaces{EC987100-A9DD-4878-87F3-047D0A4FDECD}4657E6166737B696B697470264275656 : DHCPNameServer = 172.16.1.1TCP: Interfaces{EC987100-A9DD-4878-87F3-047D0A4FDECD}56936303 : DHCPNameServer = 192.168.1.1TCP: Interfaces{EC987100-A9DD-4878-87F3-047D0A4FDECD}777777E2E6564777F62787D22676E236F6D6D223 : DHCPNameServer = 212.25.58.8 212.25.58.2Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program Files (x86)Common FilesMicrosoft SharedOFFICE14MSOXMLMF.DLLHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dllHandler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program Files (x86)Windows LivePhoto GalleryAlbumDownloadProtocolHandler.dllSEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program Files (x86)Microsoft OfficeOffice14GROOVEEX.DLLLSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livesspmASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:Program Files (x86)GoogleChromeApplication31.0.1650.63Installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chromex64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dllx64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLLx64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dllx64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dllx64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLLx64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dllx64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dllx64-Run: [TPwrMain] C:Program Files (x86)TOSHIBAPower SaverTPwrMain.EXEx64-Run: [HSON] C:Program Files (x86)TOSHIBATBSHSON.exex64-Run: [TCrdMain] C:Program Files (x86)TOSHIBAFlashCardsTCrdMain.exex64-Run: [synTPEnh] C:Program Files (x86)SynapticsSynTPSynTPEnh.exex64-Run: [Teco] "C:Program Files (x86)TOSHIBATECOTeco.exe" /rx64-Run: [TosSENotify] C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosWaitSrv.exex64-Run: [TosWaitSrv] C:Program Files (x86)TOSHIBATPHMTosWaitSrv.exex64-Run: [TosVolRegulator] C:Program FilesTOSHIBATosVolRegulatorTosVolRegulator.exex64-Run: [smartAudio] C:Program FilesCONEXANTSAIISAIICpl.exe /tx64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dllx64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dllx64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLLx64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL.================= FIREFOX ===================.FF - ProfilePath - C:UsersVESELAAppDataRoamingMozillaFirefoxProfilesw9e33dcd.defaultFF - plugin: C:PROGRA~2MICROS~1Office14NPAUTHZ.DLLFF - plugin: C:PROGRA~2MICROS~1Office14NPSPWRAP.DLLFF - plugin: C:Program Files (x86)AdobeReader 10.0ReaderAIRnppdf32.dllFF - plugin: C:Program Files (x86)GoogleUpdate1.3.22.3npGoogleUpdate3.dllFF - plugin: C:Program Files (x86)Javajre7binplugin2npjp2.dllFF - plugin: c:Program Files (x86)Microsoft Silverlight5.1.20913.0npctrlui.dllFF - plugin: C:Program Files (x86)TabletPluginsnpwacom.dllFF - plugin: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dllFF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32_11_9_900_170.dllFF - plugin: C:WindowsSysWOW64npDeployJava1.dllFF - plugin: C:WindowsSysWOW64npmproxy.dll.---- FIREFOX POLICIES ----FF - user.js: extensions.delta.tlbrSrchUrl -FF - user.js: extensions.delta.id - b6c01fcb000000000000e0ca947056e2FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}FF - user.js: extensions.delta.instlDay - 15855FF - user.js: extensions.delta.vrsn - 1.8.21.5FF - user.js: extensions.delta.vrsni - 1.8.21.5FF - user.js: extensions.delta.vrsnTs - 1.8.21.515:11:35FF - user.js: extensions.delta.prtnrId - deltaFF - user.js: extensions.delta.prdct - deltaFF - user.js: extensions.delta.aflt - babsstFF - user.js: extensions.delta.smplGrp - noneFF - user.js: extensions.delta.tlbrId - baseFF - user.js: extensions.delta.instlRef - sstFF - user.js: extensions.delta.dfltLng - enFF - user.js: extensions.delta.excTlbr - falseFF - user.js: extensions.delta.ffxUnstlRst - trueFF - user.js: extensions.delta.admin - falseFF - user.js: extensions.delta_i.babTrack - affID=119781&tt=gc_FF - user.js: extensions.delta_i.babExt -FF - user.js: extensions.delta_i.srcExt - ssFF - user.js: extensions.delta.autoRvrt - falseFF - user.js: extensions.delta.rvrt - falseFF - user.js: extensions.delta.newTab - false..============= SERVICES / DRIVERS ===============.R0 aswRvrt;aswRvrt;C:WindowsSystem32driversaswRvrt.sys [2013-5-7 65336]R0 aswVmm;aswVmm;C:WindowsSystem32driversaswVmm.sys [2013-5-7 189936]R1 aswSnx;aswSnx;C:WindowsSystem32driversaswSnx.sys [2012-1-17 1030952]R1 aswSP;aswSP;C:WindowsSystem32driversaswSP.sys [2012-1-17 378944]R1 cnnctfy3;Connectify LightWeight Filter;C:WindowsSystem32driverscnnctfy3.sys [2013-11-16 35352]R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:WindowsSystem32driversdtsoftbus01.sys [2011-12-16 279616]R1 vwififlt;Virtual WiFi Filter Driver;C:WindowsSystem32driversvwififlt.sys [2009-7-14 59904]R2 AdobeARMservice;Adobe Acrobat Update Service;C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [2013-5-9 65640]R2 AMD External Events Utility;AMD External Events Utility;C:WindowsSystem32atiesrxx.exe [2011-10-10 204288]R2 aswFsBlk;aswFsBlk;C:WindowsSystem32driversaswFsBlk.sys [2012-1-17 33400]R2 aswMonFlt;aswMonFlt;C:WindowsSystem32driversaswMonFlt.sys [2012-1-17 80816]R2 avast! Antivirus;avast! Antivirus;C:Program FilesAVAST SoftwareAvastAvastSvc.exe [2013-6-5 46808]R2 Connectify;Connectify;C:Program Files (x86)ConnectifyConnectifyService.exe [2013-5-4 487936]R2 NAUpdate;Nero Update;C:Program Files (x86)NeroUpdateNASvc.exe [2011-3-29 598312]R2 TabletServicePen;TabletServicePen;C:WindowsSystem32Pen_Tablet.exe [2012-8-27 5556520]R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:Program FilesToshibaTECOTecoService.exe [2011-4-7 294328]R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:WindowsSystem32driversTVALZFL.sys [2009-6-19 14472]R2 WTouchService;WTouch Service;C:Program FilesWTouchWTouchService.exe [2012-8-27 127784]R3 amdkmdag;amdkmdag;C:WindowsSystem32driversatikmdag.sys [2011-10-10 9263616]R3 amdkmdap;amdkmdap;C:WindowsSystem32driversatikmpag.sys [2011-10-10 300544]R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:WindowsSystem32driversAtihdW76.sys [2011-10-10 116752]R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;C:WindowsSystem32driversbtfilter.sys [2011-10-10 42096]R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:WindowsSystem32driversL1C62x64.sys [2011-2-9 77424]R3 PGEffect;Pangu effect driver;C:WindowsSystem32driversPGEffect.sys [2011-10-10 38096]R3 QIOMem;Generic IO & Memory Access;C:WindowsSystem32driversQIOMem.sys [2009-6-15 12800]R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:Program FilesToshibaTOSHIBA HDD SSD AlertTosSmartSrv.exe [2010-12-8 137632]R3 TPCHSrv;TPCH Service;C:Program FilesToshibaTPHMTPCHSrv.exe [2011-7-1 828856]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2012-7-8 104912]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2012-7-8 123856]S2 gupdate;Google Update Service (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2011-8-17 136176]S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-9-5 171680]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2012-3-30 257416]S3 ggflt;SEMC USB Flash Driver Filter;C:WindowsSystem32driversggflt.sys [2012-12-21 14448]S3 gupdatem;Google Update Service (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2011-8-17 136176]S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE [2012-9-20 50899608]S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2012-4-26 119408]S3 ose64;Office 64 Source Engine;C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2010-1-9 174440]S3 osppsvc;Office Software Protection Platform;C:Program FilesCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE [2010-1-9 4925184]S3 Sony PC Companion;Sony PC Companion;C:Program Files (x86)SonySony PC CompanionPCCService.exe [2012-12-21 155824]S3 SrvHsfHDA;SrvHsfHDA;C:WindowsSystem32driversVSTAZL6.SYS [2009-7-14 292864]S3 SrvHsfV92;SrvHsfV92;C:WindowsSystem32driversVSTDPV6.SYS [2009-7-14 1485312]S3 SrvHsfWinac;SrvHsfWinac;C:WindowsSystem32driversVSTCNXT6.SYS [2009-7-14 740864]S3 SwitchBoard;SwitchBoard;C:Program Files (x86)Common FilesAdobeSwitchBoardSwitchBoard.exe [2010-2-19 517096]S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2010-11-21 59392]S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2010-11-21 31232]S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:WindowsSystem32driversvwifimp.sys [2009-7-14 17920]S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2012-1-8 1255736]S4 wlcrasvc;Windows Live Mesh remote connections service;C:Program FilesWindows LiveMeshwlcrasvc.exe [2010-9-22 57184].=============== Created Last 30 ================.2013-12-17 17:22:40 25928 ----a-w- C:WindowsSystem32driversmbam.sys2013-12-17 17:22:40 -------- d-----w- C:Program Files (x86)Malwarebytes' Anti-Malware2013-11-27 16:11:29 -------- d-----w- C:UsersVESELAAppDataLocal{42811BCC-1CA5-4ED5-8B1D-877AFD84E550}.==================== Find3M ====================.2013-12-11 17:59:25 692616 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe2013-12-11 17:59:24 71048 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl2013-11-16 10:34:56 35352 ----a-w- C:WindowsSystem32driverscnnctfy3.sys2013-09-22 23:28:06 1767936 ----a-w- C:WindowsSysWow64wininet.dll2013-09-22 23:27:49 2876928 ----a-w- C:WindowsSysWow64jscript9.dll2013-09-22 23:27:48 61440 ----a-w- C:WindowsSysWow64iesetup.dll2013-09-22 23:27:48 109056 ----a-w- C:WindowsSysWow64iesysprep.dll2013-09-22 22:55:10 2241024 ----a-w- C:WindowsSystem32wininet.dll2013-09-22 22:54:51 3959296 ----a-w- C:WindowsSystem32jscript9.dll2013-09-22 22:54:50 67072 ----a-w- C:WindowsSystem32iesetup.dll2013-09-22 22:54:50 136704 ----a-w- C:WindowsSystem32iesysprep.dll2013-09-21 03:38:39 2706432 ----a-w- C:WindowsSystem32mshtml.tlb2013-09-21 03:30:24 2706432 ----a-w- C:WindowsSysWow64mshtml.tlb2013-09-21 02:48:36 89600 ----a-w- C:WindowsSystem32RegisterIEPKEYs.exe2013-09-21 02:39:47 71680 ----a-w- C:WindowsSysWow64RegisterIEPKEYs.exe.============= FINISH: 20:46:21.05 =============== .UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows 7 Home PremiumBoot Device: DeviceHarddiskVolume1Install Date: 16/12/2011 20:27:51System Uptime: 17/12/2013 18:30:39 (2 hours ago).Motherboard: AMD | | TorpedoProcessor: AMD A6-3400M APU with Radeon HD Graphics | Socket FS1 | 1190/100mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 297 GiB total, 236.843 GiB free.D: is FIXED (NTFS) - 298 GiB total, 111.063 GiB free.E: is CDROM ()F: is CDROM ()G: is Removable.==== Disabled Device Manager Items =============.==== System Restore Points ===================.No restore point in system..==== Installed Programs ======================.µTorrentAdobe AIRAdobe Anchor Service CS3Adobe Asset Services CS3Adobe Bridge CS3Adobe Bridge Start MeetingAdobe Camera Raw 4.0Adobe Color Common SettingsAdobe ExtendScript Toolkit 2Adobe Flash Player 11 ActiveXAdobe Flash Player 11 PluginAdobe Help Viewer CS3Adobe Illustrator CS4Adobe Illustrator CS5Adobe InDesign CS3Adobe InDesign CS3 Icon HandlerAdobe Linguistics CS3Adobe Photoshop CS5Adobe Reader X (10.1.8) MUIAdobe SetupAdobe SING CS3Adobe Stock Photos CS3Adobe Update Manager CS3Adobe Version Cue CS3 ClientAdobe WinSoft Linguistics PluginAdobe XMP Panels CS3AMD VISION Engine Control CenterApple Application SupportApple Software UpdateArchiCAD 15 R1 INTArtlantis Studio 4.0Atheros Bluetooth Filter Driver PackageAtheros Communications Inc.® AR81Family Gigabit/Fast Ethernet DriverAtheros Driver Installation ProgramATI Catalyst Install Manageravast! Free AntivirusBambooBandisoft MPEG-1 DecoderBBC iPlayer DesktopBluetooth Stack for Windows by ToshibaBS.Player FREECatalyst Control Center - BrandingCatalyst Control Center Graphics Previews CommonCatalyst Control Center InstallProxyCatalyst Control Center Localization Allccc-utility64CCC Help Chinese StandardCCC Help Chinese TraditionalCCC Help CzechCCC Help DanishCCC Help DutchCCC Help EnglishCCC Help FinnishCCC Help FrenchCCC Help GermanCCC Help GreekCCC Help HungarianCCC Help ItalianCCC Help JapaneseCCC Help KoreanCCC Help NorwegianCCC Help PolishCCC Help PortugueseCCC Help RussianCCC Help SpanishCCC Help SwedishCCC Help ThaiCCC Help TurkishCCleanerConexant HD AudioConnectifyControl ActiveX Windows Live Mesh pentru conexiuni la distan?aD3DX10DAEMON Tools LiteDefinition Update for Microsoft Office 2010 (KB982726) 64-Bit EditiondoPDF 7.2 printerDTS+AC3 FilterFotogalerija Windows LiveFTDownloaderGalerie foto Windows LiveGOM PlayerGoogle ChromeGoogle Toolbar for Internet ExplorerGoogle Update HelperHigh-Definition Video PlaybackJava 7 Update 17Java Auto UpdaterJunk Mail filter updateK-Lite Codec Pack 5.5.0 (64-bit)Kontrola Windows Live Mesh ActiveX za daljinske vezeKontrolnik Windows Live Mesh ActiveX za oddaljene povezaveMalwarebytes Anti-Malware version 1.75.0.1300Mesh RuntimeMicrosoft .NET Framework 4.5Microsoft Application Error ReportingMicrosoft Office 2010Microsoft Office 2010 Service Pack 1 (SP1)Microsoft Office Access MUI (English) 2010Microsoft Office Access Setup Metadata MUI (English) 2010Microsoft Office Excel MUI (English) 2010Microsoft Office Groove MUI (English) 2010Microsoft Office InfoPath MUI (English) 2010Microsoft Office Office 32-bit Components 2010Microsoft Office OneNote MUI (English) 2010Microsoft Office Outlook MUI (English) 2010Microsoft Office PowerPoint MUI (English) 2010Microsoft Office Professional Plus 2010Microsoft Office Proof (English) 2010Microsoft Office Proof (French) 2010Microsoft Office Proof (Spanish) 2010Microsoft Office Proofing (English) 2010Microsoft Office Publisher MUI (English) 2010Microsoft Office Shared 32-bit MUI (English) 2010Microsoft Office Shared MUI (English) 2010Microsoft Office Shared Setup Metadata MUI (English) 2010Microsoft Office Word MUI (English) 2010Microsoft Primary Interoperability Assemblies 2005Microsoft SilverlightMicrosoft SQL Server 2005 Compact Edition [ENU]Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2005 Redistributable (x64)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106MiniLyricsMozilla Firefox 26.0 (x86 en-US)Mozilla Maintenance ServiceMSVCRTMSVCRT_amd64MSXML 4.0 SP2 (KB954430)MSXML 4.0 SP2 (KB973688)Nero 10 Movie ThemePack BasicNero BackItUp 10Nero BackItUp 10 Help (CHM)Nero BurnRights 10Nero BurnRights 10 Help (CHM)Nero Control Center 10Nero ControlCenter 10 Help (CHM)Nero Core Components 10Nero Express 10Nero Express 10 Help (CHM)Nero InfoTool 10Nero InfoTool 10 Help (CHM)Nero Kwik MediaNero Multimedia Suite 10 EssentialsNero RescueAgent 10Nero RescueAgent 10 Help (CHM)Nero StartSmart 10Nero StartSmart 10 Help (CHM)Nero UpdateNeroKwikMedia Help (CHM)Networx-BG Помощник версия 0.2.8PlayReady PC Runtime amd64Posta Windows LivePowerArchiver 2010QuickTimeSecurity Update for Microsoft .NET Framework 4.5 (KB2737083)Security Update for Microsoft .NET Framework 4.5 (KB2742613)Security Update for Microsoft .NET Framework 4.5 (KB2789648)Security Update for Microsoft .NET Framework 4.5 (KB2804582)Security Update for Microsoft .NET Framework 4.5 (KB2833957)Security Update for Microsoft .NET Framework 4.5 (KB2840642)Security Update for Microsoft .NET Framework 4.5 (KB2840642v2)Security Update for Microsoft .NET Framework 4.5 (KB2861208)Security Update for Microsoft Excel 2010 (KB2826033) 64-Bit EditionSecurity Update for Microsoft InfoPath 2010 (KB2687422) 64-Bit EditionSecurity Update for Microsoft InfoPath 2010 (KB2760406) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2553371) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2589320) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2598243) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2687276) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2687423) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2687510) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2826023) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB2826035) 64-Bit EditionSecurity Update for Microsoft Outlook 2010 (KB2794707) 64-Bit EditionSecurity Update for Microsoft Publisher 2010 (KB2553147) 64-Bit EditionSecurity Update for Microsoft Visio 2010 (KB2810068) 64-Bit EditionSkype™ 6.11Sony Ericsson Update EngineSony PC Companion 2.10.136Synaptics Pointing Device DriverTOSHIBA eco UtilityTOSHIBA Face RecognitionTOSHIBA Hardware SetupTOSHIBA HDD/SSD AlertTOSHIBA PC Health MonitorTOSHIBA Supervisor PasswordTOSHIBA Value Added PackageTOSHIBA Web Camera ApplicationTRORMCLauncherUpdate for Microsoft .NET Framework 4.5 (KB2750147)Update for Microsoft .NET Framework 4.5 (KB2805221)Update for Microsoft .NET Framework 4.5 (KB2805226)Update for Microsoft Access 2010 (KB2553446) 64-Bit EditionUpdate for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2553065)Update for Microsoft Office 2010 (KB2553181) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2553267) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2553310) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2566458)Update for Microsoft Office 2010 (KB2589298) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2589375) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2598242) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2760598) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2760631) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2767886) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2794737) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2825640) 64-Bit EditionUpdate for Microsoft Office 2010 (KB2826026) 64-Bit EditionUpdate for Microsoft OneNote 2010 (KB2553290) 64-Bit EditionUpdate for Microsoft OneNote 2010 (KB2810072) 64-Bit EditionUpdate for Microsoft Outlook 2010 (KB2687623) 64-Bit EditionUpdate for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit EditionUpdate for Microsoft PowerPoint 2010 (KB2553145) 64-Bit EditionUpdate for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit EditionUpdate for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit EditionUpdate for Microsoft Word 2010 (KB2827323) 64-Bit EditionWebTablet IE PluginWebTablet Netscape PluginWinampWinamp Detector Plug-inWindows Live Communications PlatformWindows Live EssentialsWindows Live Foto-galerijaWindows Live Galerija fotografijaWindows Live ID Sign-in AssistantWindows Live InstallerWindows Live Language SelectorWindows Live MailWindows Live MeshWindows Live Mesh ActiveX Control for Remote ConnectionsWindows Live Mesh ActiveX kontrola za daljinske vezeWindows Live MessengerWindows Live MIME IFilterWindows Live Movie MakerWindows Live Photo CommonWindows Live Photo GalleryWindows Live PIMT PlatformWindows Live PostaWindows Live Remote ClientWindows Live Remote Client ResourcesWindows Live Remote ServiceWindows Live Remote Service ResourcesWindows Live SOXEWindows Live SOXE DefinitionsWindows Live UX PlatformWindows Live UX Platform Language PackWindows Live WriterWindows Live Writer ResourcesWMV9/VC-1 Video Playback.==== Event Viewer Messages From Past Week ========.15/12/2013 19:41:02, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10..==== End Of File ===========================
  12. Здравейте!Проблема се появи за пръв път вчера.В какво се изразява-Появява се нещо като "снеговалеж" по екрана (като на телевизор който не може да хване добре ефирен сигнал).Проблема се наблюдава при браузване с Мозила (при забранени добавки на мозилата си работи нормално ) и при пускане на видео плеъра понякога.(Gom)С Интернет Експлорър-а няма проблем май.(отворих само за проба) Имам инсталирана Malwarebytes Anti-Malware с която сканирах,прилагам лога.След mbam изглеждаше,че съм се отървал,но днес пак се появи. Malwarebytes Anti-Malware 1.70.0.1100www.malwarebytes.orgDatabase version: v2013.02.18.05Windows XP Service Pack 3 x86 NTFSInternet Explorer 8.0.6001.18702Ivan :: 1A [administrator]18.2.2013 г. 12:04:22mbam-log-2013-02-18 (12-04-22).txtScan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 256565Time elapsed: 2 minute(s), 59 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 2HKCRCLSID{82184935-B894-4AB2-8590-603BA7D74B71} (Trojan.WebMoner) -> Quarantined and deleted successfully.HKCRbolnatakoja.eProtocol (Trojan.WebMoner) -> Quarantined and deleted successfully.Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)(end)ддсDDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702Run by Ivan at 15:54:01 on 2013-02-19Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2047.1342 [GMT 2:00]..============== Running Processes ================.C:WINDOWSsystem32nvsvc32.exeC:WINDOWSsystem32spoolsv.exeC:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exeC:Documents and SettingsAll UsersApplication DataSkypeToolbarsSkype C2C Servicec2c_service.exeC:Program FilesNVIDIA CorporationNetworkAccessManagerbin32nSvcAppFlt.exeC:Program FilesNVIDIA CorporationNetworkAccessManagerbin32nSvcIp.exeC:WINDOWSSystem32alg.exeC:Program FilesAnalog DevicesCoresmax4pnp.exeC:Program FilesAnalog DevicesSoundMAXSmax4.exeC:Program FilesuTorrentuTorrent.exeC:WINDOWSsystem32taskmgr.exeC:WINDOWSexplorer.exeC:WINDOWSsystem32HPSIsvc.exeC:Program FilesMozilla Firefoxfirefox.exeC:Program FilesMozilla Firefoxplugin-container.exeC:WINDOWSsystem32wbemwmiprvse.exeC:WINDOWSSystem32svchost.exe -k netsvcsC:WINDOWSsystem32svchost.exe -k NetworkServiceC:WINDOWSsystem32svchost.exe -k LocalServiceC:WINDOWSSystem32svchost.exe -k HTTPFilter.============== Pseudo HJT Report ===============.uStart Page = hxxp://www.vesti.bg/BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dlluRun: [uTorrent] "c:program filesutorrentuTorrent.exe"mRun: [SoundMAXPnP] c:program filesanalog devicescoresmax4pnp.exemRun: [SoundMAX] "c:program filesanalog devicessoundmaxSmax4.exe" /traymRun: [MSConfig] c:windowspchealthhelpctrbinariesMSConfig.exe /autodRun: [CTFMON.EXE] c:windowssystem32ctfmon.exeStartupFolder: c:docume~1alluse~1startm~1programsstartupmicros~1.lnk - c:program filesmicrosoft officeoffice10OSA.EXEuPolicies-Explorer: NoDriveTypeAutoRun = dword:145mPolicies-Explorer: NoDriveTypeAutoRun = dword:145IE: E&xport to Microsoft Excel - c:progra~1micros~2office10EXCEL.EXE/3000IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dllIE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exeIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exeDPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} - hxxps://ebb.ubb.bg/CAPICOM/capicom.cabTCP: NameServer = 192.168.1.1TCP: Interfaces{93BC2C17-BBE4-45DB-94E7-BF51ECCAE95C} : DHCPNameServer = 192.168.1.1Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:program filescommon filesmicrosoft sharedweb foldersPKMCDO.DLLHandler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll.================= FIREFOX ===================.FF - ProfilePath - c:documents and settingsivanapplication datamozillafirefoxprofilesanuh6g35.defaultFF - plugin: c:program filesmicrosoft silverlight5.1.10411.0npctrlui.dllFF - plugin: c:program filesmozilla firefoxpluginsnpdjvu.dllFF - plugin: c:program filesmozilla firefoxpluginsnpFoxitReaderPlugin.dllFF - plugin: c:windowssystem32macromedflashNPSWF32_11_6_602_168.dll.============= SERVICES / DRIVERS ===============.R2 HPSIService;HP SI Service;c:windowssystem32HPSIsvc.exe [2012-11-12 99896]R2 NPF;NetGroup Packet Filter Driver;c:windowssystem32driversnpf.sys [2009-10-20 50704]R2 nvUpdatusService;NVIDIA Update Service Daemon;c:program filesnvidia corporationnvidia update coredaemonu.exe [2012-9-1 1262400]R2 Skype C2C Service;Skype C2C Service;c:documents and settingsall usersapplication dataskypetoolbarsskype c2c servicec2c_service.exe [2012-11-22 3290304]R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2012-10-22 21104]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]S2 MBAMScheduler;MBAMScheduler;c:program filesmalwarebytes' anti-malwarembamscheduler.exe [2012-10-22 398184]S2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2012-10-22 682344]S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2013-1-8 161536]S3 MozillaMaintenance;Mozilla Maintenance Service;c:program filesmozilla maintenance servicemaintenanceservice.exe [2012-9-9 115608]S3 mvusbews;USB EWS Device;c:windowssystem32driversmvusbews.sys [2012-11-12 17408]S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504]S3 XilinxFirmwareEmbeddedLpLoader;XilinxFirmwareEmbeddedLpLoader;c:windowssystem32driversxusb_emb.sys [2012-11-14 17408].=============== File Associations ===============.ShellExec: FOXITR~1.EXE: print="c:progra~1foxits~1foxitr~1FOXITR~1.EXE"/p "%1" ShellExec: FOXITR~1.EXE: printto="c:progra~1foxits~1foxitr~1FOXITR~1.EXE"/t "%1" "%2" "%3" "%4" .=============== Created Last 30 ================..==================== Find3M ====================.2013-02-19 13:35:01 71024 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl2013-02-19 13:35:01 691568 ----a-w- c:windowssystem32FlashPlayerApp.exe2012-12-14 14:49:28 21104 ----a-w- c:windowssystem32driversmbam.sys.============= FINISH: 15:54:13,71 ===============атач.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows XP ProfessionalBoot Device: DeviceHarddiskVolume1Install Date: 9/1/2012 1:29:25 PMSystem Uptime: 2/19/2013 1:29:12 PM (2 hours ago).Motherboard: ASUSTeK Computer INC. | | M2NProcessor: AMD Athlon(tm) 64 X2 Dual Core Processor 3600+ | CPU 1 | 1908/200mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 156 GiB total, 125.974 GiB free.D: is FIXED (NTFS) - 775 GiB total, 65.318 GiB free.E: is CDROM ().==== Disabled Device Manager Items =============.==== System Restore Points ===================.No restore point in system..==== Installed Programs ======================.µTorrentAdobe Flash Player 11 PluginAIMP3ArcSoft MediaImpression 2AsusUpdateAtmel Software FrameworkAtmel Studio 6.0Atmel USBBoilsoft Video Joiner 6.57Boilsoft Video Splitter 6.34Bulgarian Keyboards XP by G. AtanasovDigilent SoftwareElectronic Parts CatalogueFoxit ReaderGOM PlayerHotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)Hotfix for Windows XP (KB942288-v3)Hotfix for Windows XP (KB954550-v5)HP LaserJet Professional P1100-P1560-P1600 SeriesIAR Embedded Workbench for Atmel AVR 5.50JLink OB CDC Driver PackageLizardtech DjVu ControlMalwarebytes Anti-Malware version 1.70.0.1100Microsoft .NET Framework 2.0 Service Pack 2Microsoft .NET Framework 3.0 Service Pack 2Microsoft .NET Framework 3.5 SP1Microsoft .NET Framework 4 Client ProfileMicrosoft .NET Framework 4 ExtendedMicrosoft .NET Framework 4 Multi-Targeting PackMicrosoft Application Error ReportingMicrosoft Help Viewer 1.0Microsoft Kernel-Mode Driver Framework Feature Pack 1.7Microsoft Office XP Professional with FrontPageMicrosoft SilverlightMicrosoft SQL Server 2008 R2 Management ObjectsMicrosoft SQL Server System CLR TypesMicrosoft User-Mode Driver Framework Feature Pack 1.0Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319Microsoft Visual Studio 2010 Shell (Isolated) - ENUMozilla Firefox 18.0.2 (x86 en-US)Mozilla Maintenance ServiceMSVCRT RedistsNero 6 Ultra EditionNVIDIA Control Panel 301.42NVIDIA Display Control PanelNVIDIA DriversNVIDIA ForceWare Network Access ManagerNVIDIA Graphics Driver 301.42NVIDIA Install ApplicationNVIDIA nView 136.27NVIDIA nView Desktop ManagerNVIDIA PhysXNVIDIA PhysX System Software 9.12.0213nVidia Refresh Rate Fix MKII v2.21f ENVIDIA Update 1.8.15NVIDIA Update ComponentsPicture Package Music TransferPowerISOSkype Click to CallSkype™ 6.1Sony Picture UtilitySopCast 3.5.0SoundMAXUnit Conversion Tool 5.1Update for Microsoft Windows (KB971513)Vegas Movie Studio HD Platinum 11.0Vegas Pro 10.0Warcraft III: All ProductsWebFldrs XPWindows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)Windows Driver Package - Segger (jlink) USB (01/09/2007 2.6.5.0)Windows Driver Package - Segger (jlink) USB (04/11/2012 2.6.8.2)Windows Driver Package - SEGGER (usbser) Ports (01/25/2012 6.0.2600.4)Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-RayWindows Internet Explorer 8Windows Media Format 11 runtimeWinPcap 4.1.1WinRAR archiverXilinx Design Tools 14 ISE WebPACK + Vivado WebPACK 14.4 (C:XilinxISE1414.4ISE_DS)Xilinx Design Tools 14 Xilinx Documentation Navigator - Standalone Installation 14.4 (C:XilinxISE14DocNav)Xilinx Embedded Development Kit 7.1iXilinx ISE 7.1i.==== Event Viewer Messages From Past Week ========.2/19/2013 3:07:53 PM, error: Service Control Manager [7034] - The MBAMScheduler service terminated unexpectedly. It has done this 1 time(s).2/19/2013 3:07:47 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).2/19/2013 3:07:43 PM, error: Service Control Manager [7031] - The HP SI Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.2/18/2013 12:32:01 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SCDEmu Tcpip2/18/2013 12:32:01 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.2/18/2013 12:32:01 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.2/18/2013 12:32:01 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.2/18/2013 12:32:01 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.2/18/2013 12:30:36 PM, error: DCOM [10005] - DCOM got error "84" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}2/18/2013 11:56:28 AM, error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).2/16/2013 9:04:42 AM, error: Service Control Manager [7024] - The Background Intelligent Transfer Service service terminated with service-specific error 2147500037 (0x80004005).2/16/2013 10:10:30 AM, error: nvgts [9] - The device, DeviceScsinvgts2, did not respond within the timeout period.2/16/2013 10:10:30 AM, error: nvgts [5] - A parity error was detected on DeviceScsinvgts2..==== End Of File ===========================
  13. Здравейте!При отваряне на линк от приятел по скайп спря да работи Google търсачката.В момента работи Моzilla Firefox,но и при нея не се отварят видео файлове.С програмата Malwarebyte открих 78 елемента,които изтрих.Сега Google отваря страници,но на тях нищо не е активно.Моля помогнете ми! .DDS (Ver_2011-09-30.01) - NTFS_x86 Internet Explorer: 9.0.8112.16421 Run by Home at 11:48:14 on 2012-11-25 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.1535.667 [GMT 2:00] . AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Program Files\D-Link\DWA-123\ALPBCSVC.exe C:\ProgramData\GLOBUL Connection Manager\OnlineUpdate\ouc.exe C:\ProgramData\DatacardService\HWDeviceService.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe C:\Program Files\Microsoft Security Client\NisSrv.exe C:\Windows\system32\taskhost.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\ProgramData\DatacardService\DCSHelper.exe C:\Windows\SOUNDMAN.EXE C:\Windows\PixArt\Pac207\Monitor.exe C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe C:\Windows\system32\taskeng.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Aeria Games\Ignite\aeriaignite.exe C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\System32\spool\drivers\w32x86\3\E_FATIFBE.EXE C:\Users\Home\AppData\Local\Akamai\netsession_win.exe C:\Program Files\FilesFrog Update Checker\update_checker.exe C:\Windows\system32\SearchIndexer.exe C:\Users\Home\AppData\Local\Akamai\netsession_win.exe C:\Program Files\PC Speed Maximizer\SPMReminder.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\svchost.exe -k Akamai C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.bg/ uSearch Bar = Preserve mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10002&barid={66B59D52-21E4-11E2-A6AE-0015F29177DD} uProxyOverride = <local> BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IB Updater: {336D0C35-8A85-403a-B9D2-65C292C39087} - c:\program files\ib updater\Extension32.dll BHO: 4sharedExt: {95525BD9-6136-4A26-8263-9CEE295D442D} - c:\program files\4shared toolbar\4sharedExt32.dll BHO: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll TB: 4shared Toolbar: {95080B13-AA71-4EE8-B951-7E98221E1ED5} - c:\program files\4shared toolbar\4sharedbar32.dll TB: 4shared Toolbar: {95080B13-AA71-4EE8-B951-7E98221E1ED5} - c:\program files\4shared toolbar\4sharedbar32.dll uRun: [skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun uRun: [EPSON SX110 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifbe.exe /fu "c:\windows\temp\E_S8221.tmp" /EF "HKCU" uRun: [Akamai NetSession Interface] "c:\users\home\appdata\local\akamai\netsession_win.exe" uRun: [sDP] c:\program files\filesfrog update checker\update_checker.exe /auto uRun: [speedUpMyPC] "c:\program files\uniblue\speedupmypc\launcher.exe" -d 20000 uRun: [PC Speed Maximizer] c:\program files\pc speed maximizer\SPMLauncher.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [sSDMonitor] c:\program files\common files\pc tools\smonitor\SSDMonitor.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Aeria Ignite] "c:\program files\aeria games\ignite\aeriaignite.exe" silent mRun: [sweetpacks Communicator] c:\program files\sweetim\communicator\SweetPacksUpdateManager.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: &4shared Search - c:\program files\4shared toolbar\4sharedbar32.dll/MENUSEARCH.HTM IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: NameServer = 192.168.0.1 TCP: Interfaces\{2B7515F8-7F12-49F7-AAF7-46519883D678} : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{2B7515F8-7F12-49F7-AAF7-46519883D678}\46C696E6B6 : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{2B7515F8-7F12-49F7-AAF7-46519883D678}\C696E6B6379737 : DHCPNameServer = 212.116.136.2 212.116.128.2 TCP: Interfaces\{2B7515F8-7F12-49F7-AAF7-46519883D678}\D4F62796A7 : DHCPNameServer = 192.168.43.1 TCP: Interfaces\{31632317-CFCD-4995-B11A-BCE4F026747D} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{8015E814-9654-43D6-B038-7C3993681EF2} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{955D30E1-343A-4E5B-A7B4-E3571E25AFD0} : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{955D30E1-343A-4E5B-A7B4-E3571E25AFD0}\4505D2C494E4B4F5733323935434 : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{9AC1DD28-767D-4982-91CB-2F2C6998230F} : DHCPNameServer = 192.168.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll SSODL: WebCheck - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - c:\users\home\appdata\roaming\mozilla\firefox\profiles\qrubrgos.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q= FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\users\home\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\users\home\appdata\roaming\mozilla\firefox\profiles\qrubrgos.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\plugins\np-mswmp.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_287.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll FF - plugin: d:\program files\google\picasa3\npPicasa3.dll . ---- FIREFOX POLICIES ---- FF - user.js: extensions.BabylonToolbar_i.id - b0a0a610000000000000b8a386010e4f FF - user.js: extensions.BabylonToolbar_i.hardId - b0a0a610000000000000b8a386010e4f FF - user.js: extensions.BabylonToolbar_i.instlDay - 15523 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.instlRef - sst FF - user.js: extensions.BabylonToolbar.autoRvrt - false FF - user.js: extensions.BabylonToolbar_i.newTab - false FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=b0a0a610000000000000b8a386010e4f&q= FF - user.js: extensions.BabylonToolbar.id - b0a0a610000000000000b8a386010e4f FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB} FF - user.js: extensions.BabylonToolbar.instlDay - 15655 FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.3.8 FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.3.8 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.3.810:50:30 FF - user.js: extensions.BabylonToolbar.prtnrId - babylon FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar.tlbrId - base FF - user.js: extensions.BabylonToolbar.instlRef - na FF - user.js: extensions.BabylonToolbar.dfltLng - en FF - user.js: extensions.BabylonToolbar.excTlbr - false FF - user.js: extensions.BabylonToolbar.admin - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=17425&tt=4512_7 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - def . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552] R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2012-5-27 12800] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-14 20992] R2 DWA-123_PBC_WPS;DWA-123_PBC_WPS Service;c:\program files\d-link\dwa-123\ALPBCSVC.exe [2012-5-27 61440] R2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\datacardservice\HWDeviceService.exe [2011-3-14 271712] R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-11-23 399432] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-11-23 676936] R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 99272] R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2011-12-20 793048] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2012-3-29 73216] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-11-23 22856] R3 netr28u;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Dnetr28u.sys [2012-5-27 1165152] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-9-12 287824] R3 PAC207;SoC PC-Camera;c:\windows\system32\drivers\PFC027.SYS [2006-12-5 507136] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 GLOBUL Connection Manager. RunOuc;GLOBUL Connection Manager. OUC;c:\users\home\globul\globul connection manager\updatedog\ouc.exe [2012-3-29 655712] S2 gupdate;Услуга Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-6-2 136176] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-17 250808] S3 apf001;apf001;c:\windows\system32\apf001.sys [2012-2-18 10872] S3 apf003;apf003;c:\windows\system32\apf003.sys [2012-7-3 13232] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2012-3-29 102784] S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-6-2 136176] S3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\drivers\ew_jucdcacm.sys [2012-3-29 90368] S3 netr73;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\netr73.sys [2010-2-24 562464] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-25 15872] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-25 52224] S3 WatAdminSvc;WatAdminSvc;c:\windows\system32\wat\WatAdminSvc.exe [2011-6-2 1343400] . =============== Created Last 30 ================ . 2012-11-24 17:31:16 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{42285a1f-fb7f-4e11-ba7c-ee820b007be3}\mpengine.dll 2012-11-23 17:16:01 -------- d-----w- c:\users\home\appdata\roaming\Malwarebytes 2012-11-23 17:15:28 -------- d-----w- c:\programdata\Malwarebytes 2012-11-23 17:15:22 22856 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-11-23 17:15:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-11-22 18:58:17 689664 ----a-w- c:\users\home\appdata\roaming\601D.exe 2012-11-22 18:58:14 15678 ----a-w- c:\users\home\appdata\roaming\530C.exe 2012-11-22 15:50:58 15678 ----a-w- c:\users\home\appdata\roaming\D481.exe 2012-11-22 15:18:08 689664 ----a-w- c:\users\home\appdata\roaming\C3D8.exe 2012-11-22 15:18:03 15678 ----a-w- c:\users\home\appdata\roaming\B34D.exe 2012-11-22 14:59:22 689664 ----a-w- c:\users\home\appdata\roaming\9E5F.exe 2012-11-22 14:59:18 15678 ----a-w- c:\users\home\appdata\roaming\8D85.exe 2012-11-22 12:06:14 15678 ----a-w- c:\users\home\appdata\roaming\1BB9.exe 2012-11-22 11:57:38 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-11-15 09:58:27 9728 ----a-w- c:\windows\system32\Wdfres.dll 2012-11-15 09:58:27 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2012-11-15 09:58:27 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2012-11-15 09:57:17 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2012-11-15 09:57:16 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2012-11-15 09:57:14 73216 ----a-w- c:\windows\system32\WUDFSvc.dll 2012-11-15 09:57:14 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll 2012-11-15 09:57:11 613888 ----a-w- c:\windows\system32\WUDFx.dll 2012-11-15 09:57:11 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2012-11-15 09:57:11 196608 ----a-w- c:\windows\system32\WUDFHost.exe 2012-11-15 06:23:09 78336 ----a-w- c:\windows\system32\synceng.dll 2012-11-15 06:23:08 2345984 ----a-w- c:\windows\system32\win32k.sys 2012-11-15 06:23:01 499712 ----a-w- c:\windows\system32\iphlpsvc.dll 2012-11-15 06:23:01 242176 ----a-w- c:\windows\system32\nlasvc.dll 2012-11-15 06:23:01 175104 ----a-w- c:\windows\system32\netcorehc.dll 2012-11-15 06:23:01 156672 ----a-w- c:\windows\system32\ncsi.dll 2012-11-15 06:23:01 1293680 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-11-15 06:23:00 52224 ----a-w- c:\windows\system32\nlaapi.dll 2012-11-15 06:23:00 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2012-11-15 06:23:00 18944 ----a-w- c:\windows\system32\netevent.dll 2012-11-15 06:22:53 193536 ----a-w- c:\windows\system32\dhcpcore6.dll 2012-11-15 06:22:52 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll 2012-11-11 08:52:04 -------- d-----w- c:\program files\LEGO Software 2012-11-11 08:50:35 -------- d-----w- c:\program files\Babylon 2012-11-11 08:49:25 -------- d-----w- c:\users\home\appdata\roaming\PC Speed Maximizer 2012-11-11 08:48:21 -------- d-----w- c:\users\home\appdata\roaming\Uniblue 2012-11-11 08:48:03 -------- d-----w- c:\program files\Uniblue 2012-11-11 08:48:01 -------- d-----w- c:\program files\PC Speed Maximizer 2012-11-11 07:39:39 -------- d-----w- c:\program files\FilesFrog Update Checker 2012-11-11 07:39:27 -------- d-----w- c:\program files\Perion 2012-11-11 07:39:23 632656 ----a-w- c:\windows\system32\msvcr80.dll 2012-11-11 07:39:23 554832 ----a-w- c:\windows\system32\msvcp80.dll 2012-11-11 07:39:23 479232 ----a-w- c:\windows\system32\msvcm80.dll 2012-11-11 07:39:22 28160 ----a-w- c:\windows\system32\ImHttpComm.dll 2012-11-11 07:39:22 -------- d-----w- c:\windows\system32\ARFC 2012-11-11 07:39:20 -------- d-----w- c:\windows\system32\WNLT 2012-11-11 07:39:12 -------- d-----w- c:\program files\IB Updater 2012-10-29 16:19:10 -------- d-----w- c:\programdata\SweetIM 2012-10-29 16:19:10 -------- d-----w- c:\program files\SweetIM 2012-10-29 16:08:24 -------- d-----w- c:\programdata\boost_interprocess 2012-10-29 16:00:09 -------- d-----w- c:\users\home\appdata\local\Torch . ==================== Find3M ==================== . 2012-10-29 14:39:25 821736 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-10-29 14:39:25 746984 ----a-w- c:\windows\system32\deployJava1.dll 2012-10-09 13:36:49 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-09 13:36:49 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-08 07:56:24 1800704 ----a-w- c:\windows\system32\jscript9.dll 2012-10-08 07:48:03 1129472 ----a-w- c:\windows\system32\wininet.dll 2012-10-08 07:47:44 1427968 ----a-w- c:\windows\system32\inetcpl.cpl 2012-10-08 07:44:05 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2012-10-08 07:43:21 420864 ----a-w- c:\windows\system32\vbscript.dll 2012-10-08 07:40:56 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2012-09-14 18:28:53 2048 ----a-w- c:\windows\system32\tzres.dll 2012-08-31 17:18:09 1211760 ----a-w- c:\windows\system32\drivers\ntfs.sys 2012-08-30 19:03:50 99272 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-08-30 19:03:50 193552 ----a-w- c:\windows\system32\drivers\MpFilter.sys 2012-08-30 17:12:02 3968880 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-08-30 17:12:02 3914096 ----a-w- c:\windows\system32\ntoskrnl.exe . ============= FINISH: 11:49:10,14 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 2.6.2011 г. 03:32:49 System Uptime: 25.11.2012 г. 08:56:57 (3 hours ago) . Motherboard: ASUSTeK Computer INC. | | 'K8N' Processor: AMD Athlon™ 64 Processor 3200+ | Socket 754 | 2210/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 30 GiB total, 2,295 GiB free. D: is FIXED (NTFS) - 123 GiB total, 59,362 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e96c-e325-11ce-bfc1-08002be10318} Description: Conexant 23881 Video Capture (Cx23881 for Japan Final release) Device ID: PCI\VEN_14F1&DEV_8800&SUBSYS_00000000&REV_05\4&22775069&0&4870 Manufacturer: Conexant Name: Conexant 23881 Video Capture (Cx23881 for Japan Final release) PNP Device ID: PCI\VEN_14F1&DEV_8800&SUBSYS_00000000&REV_05\4&22775069&0&4870 Service: CX23880 . ==== System Restore Points =================== . RP377: 24.11.2012 г. 20:25:14 - Removed SweetPacks bundle uninstaller . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) µTorrent 4shared Toolbar Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.2 Adobe Shockwave Player 11.6 Aeria Ignite Akamai NetSession Interface Akamai NetSession Interface Service BS.Player FREE D-Link DWA-123 Eden Eternal EPSON Scan EPSON SX110 Series Printer Uninstall EVEREST Ultimate Edition v5.50 FilesFrog Update Checker GLOBUL Connection Manager Google Земя Google Chrome Google SketchUp 8 Google Update Helper IB Updater 2.0.0.110 IB Updater Service JavaFX 2.1.1 LEGO Universe Malwarebytes Anti-Malware version 1.65.1.1000 Microsoft .NET Framework 4 Client Profile Microsoft Antimalware Service BG-BG Language Pack Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Security Client Microsoft Security Client BG-BG Language Pack Microsoft Security Essentials Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 4.0.1 (x86 bg) Mozilla Firefox 8.0.1 (x86 bg) Nero 7 Premium Nokia Connectivity Cable Driver Norton Security Scan Pando Media Booster PC Speed Maximizer v3.0 PC Tools Registry Mechanic 11.0 Picasa 3 Realtek AC'97 Audio SA Dictionary 2004 Datacenter Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687314) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2687315) 32-Bit Edition Skype Toolbars Skype™ 5.10 SweetPacks bundle uninstaller swMSM Uniblue SpeedUpMyPC Unity Web Player Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760413) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update Manager for SweetPacks 1.1 VLC media player 1.0.2 WinRAR archiver XBMC . ==== Event Viewer Messages From Past Week ======== . 25.11.2012 г. 09:10:00, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.141.329.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft...������Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9002.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 25.11.2012 г. 09:01:30, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 25.11.2012 г. 08:57:31, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 25.11.2012 г. 08:57:31, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 25.11.2012 г. 08:57:08, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 24.11.2012 г. 18:55:53, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service. 24.11.2012 г. 17:22:04, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 24.11.2012 г. 17:22:04, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 24.11.2012 г. 17:21:42, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 24.11.2012 г. 17:18:27, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:18:27, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:18:27, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:40, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:40, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:40, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:40, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 24.11.2012 г. 17:16:40, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 24.11.2012 г. 17:16:39, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 24.11.2012 г. 17:16:32, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 24.11.2012 г. 17:16:20, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:20, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:20, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:15, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache MpFilter spldr Wanarpv6 24.11.2012 г. 17:16:15, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:15, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:15, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 24.11.2012 г. 17:16:11, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d3 (0x8b55ff8b, 0x00000000, 0x00000000, 0x82ad0089). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112412-34203-01. 24.11.2012 г. 15:48:11, Error: Microsoft-Windows-Eventlog [23] - The event logging service encountered an error (res=32) while initializing logging resources for channel Microsoft-Windows-LanguagePackSetup/Operational. 24.11.2012 г. 12:47:05, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 24.11.2012 г. 09:50:04, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 24.11.2012 г. 09:50:04, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 24.11.2012 г. 09:49:41, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23.11.2012 г. 23:36:05, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 23.11.2012 г. 23:36:05, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 23.11.2012 г. 23:35:43, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23.11.2012 г. 22:08:06, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 23.11.2012 г. 22:08:06, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 23.11.2012 г. 22:07:44, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23.11.2012 г. 22:04:16, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 23.11.2012 г. 22:04:16, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 23.11.2012 г. 22:03:52, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23.11.2012 г. 18:36:26, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 23.11.2012 г. 18:25:55, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 23.11.2012 г. 18:25:55, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 23.11.2012 г. 18:25:27, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23.11.2012 г. 11:20:56, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 23.11.2012 г. 11:20:56, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 23.11.2012 г. 11:20:20, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 23.11.2012 г. 10:22:03, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 23.11.2012 г. 10:11:51, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 22.11.2012 г. 20:57:19, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 22.11.2012 г. 20:57:19, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 22.11.2012 г. 20:56:56, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 22.11.2012 г. 17:16:44, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 22.11.2012 г. 17:16:44, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 22.11.2012 г. 17:16:20, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 22.11.2012 г. 16:58:11, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 22.11.2012 г. 16:58:11, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 22.11.2012 г. 16:57:47, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 22.11.2012 г. 13:48:52, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 22.11.2012 г. 13:45:53, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 22.11.2012 г. 13:45:53, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 22.11.2012 г. 13:45:31, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 21.11.2012 г. 19:59:23, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 21.11.2012 г. 18:33:48, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 21.11.2012 г. 18:33:48, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 21.11.2012 г. 18:33:26, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 21.11.2012 г. 18:22:34, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 21.11.2012 г. 08:46:43, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 21.11.2012 г. 08:46:43, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 21.11.2012 г. 08:46:19, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 20.11.2012 г. 21:30:04, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 20.11.2012 г. 16:07:44, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 20.11.2012 г. 14:25:17, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 20.11.2012 г. 14:25:17, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 20.11.2012 г. 14:24:54, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 19.11.2012 г. 19:17:35, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 19.11.2012 г. 19:14:29, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 19.11.2012 г. 19:14:29, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 19.11.2012 г. 19:14:07, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. 18.11.2012 г. 20:40:17, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 19:40:17, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 18:40:21, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 17:40:19, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 16:40:17, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 15:40:17, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 14:40:17, Error: Service Control Manager [7023] - The SPP Notification Service service terminated with the following error: Access is denied. 18.11.2012 г. 10:56:52, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 18.11.2012 г. 10:34:34, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service. 18.11.2012 г. 10:28:55, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the GLOBUL Connection Manager. OUC service to connect. 18.11.2012 г. 10:28:55, Error: Service Control Manager [7000] - The GLOBUL Connection Manager. OUC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 18.11.2012 г. 10:28:30, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. . ==== End Of File ===========================
  14. Здравейте имам съмнения от 1 файл който изтеглих и естествено отворих (Може да е от Dark Comet Cybergate или там каквито са..) . Не съм забелязвал машината да се държи странно,забавяния.. Ето и логовете от Farbar Recovery Scan Tool. (Пускам темата защото имам много важни неща на машината които са платени..)
  15. Здравейте , Мисля,че съм заразен с въпросният вирус,защото като търся нещо в Google ме пренасочва към ipv4.google.com/sorry/... и трябва да въведа знаци (CAPTCHA) за да продължа напред. Сканирах с Аваст и Malwarebytes A-M, също така почистих с Ccleaner, но без никакъв резултат.Надявам се вие да ми помогнете FRST LOG: ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe () C:\Windows\vsnp325.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe () C:\Windows\FixCamera.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [snp325] => C:\Windows\vsnp325.exe [835584 2007-05-10] () HKLM-x32\...\Run: [startCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-25] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [FixCamera] => C:\Windows\FixCamera.exe [20480 2007-07-11] () HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKU\S-1-5-21-1948220024-2437248343-2704207394-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd) HKU\S-1-5-21-1948220024-2437248343-2704207394-1000\...\Run: [uTorrent] => "C:\Users\D>744=\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Гроздан\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF Plugin-x32: @raidcall.kr/RCplugin -> C:\Users\Гроздан\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-30] Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-05-25] (Advanced Micro Devices, Inc.) [File not signed] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-10-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-10-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-10-30] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-11-26] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-16] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 SNP325; C:\Windows\System32\DRIVERS\snp325.sys [10719104 2007-07-24] (Sonix Co. Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 GGSAFERDriver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-16 19:04 - 2014-09-16 19:04 - 00009381 _____ () C:\Users\Гроздан\Desktop\FRST.txt 2014-09-16 19:03 - 2014-09-16 19:04 - 00000000 ____D () C:\FRST 2014-09-16 19:02 - 2014-09-16 19:03 - 02105856 _____ (Farbar) C:\Users\Гроздан\Desktop\FRST64.exe 2014-09-16 14:32 - 2014-09-16 14:32 - 00000000 ____D () C:\Users\Гроздан\AppData\Local\Adobe 2014-09-11 20:23 - 2014-09-11 20:23 - 00000000 ____D () C:\Users\Гроздан\AppData\Roaming\Grand Theft Auto IV 2014-09-11 20:23 - 2014-09-11 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2014-09-10 17:55 - 2014-08-15 18:48 - 17868288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-09-10 17:55 - 2014-08-15 18:36 - 10920960 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-09-10 17:55 - 2014-08-15 18:35 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-09-10 17:55 - 2014-08-15 18:31 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-09-10 17:55 - 2014-08-15 18:31 - 01384960 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-09-10 17:55 - 2014-08-15 18:30 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-09-10 17:55 - 2014-08-15 18:30 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-09-10 17:55 - 2014-08-15 18:30 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 02156032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-09-10 17:55 - 2014-08-15 18:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-09-10 17:55 - 2014-08-15 18:29 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-09-10 17:55 - 2014-08-15 18:28 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-09-10 17:55 - 2014-08-15 18:28 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-09-10 17:55 - 2014-08-15 18:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-09-10 17:55 - 2014-08-15 18:28 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-09-10 17:55 - 2014-08-15 17:51 - 12363264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-09-10 17:55 - 2014-08-15 17:42 - 09739776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-09-10 17:55 - 2014-08-15 17:42 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-09-10 17:55 - 2014-08-15 17:37 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-09-10 17:55 - 2014-08-15 17:37 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-09-10 17:55 - 2014-08-15 17:36 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-09-10 17:55 - 2014-08-15 17:35 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-09-10 17:55 - 2014-08-15 17:35 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-09-10 17:55 - 2014-08-15 17:35 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-09-10 17:55 - 2014-08-15 17:34 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-09-10 17:55 - 2014-08-15 17:34 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-09-10 17:55 - 2014-08-15 17:34 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-09-10 17:55 - 2014-08-15 17:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-09-10 17:55 - 2014-08-15 17:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-09-10 17:44 - 2014-08-01 14:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-09-10 17:44 - 2014-08-01 14:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-09-10 17:44 - 2014-07-07 05:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-09-10 17:44 - 2014-07-07 05:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-09-10 17:44 - 2014-07-07 04:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-09-10 17:44 - 2014-07-07 04:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-09-10 17:44 - 2014-07-07 04:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-09-03 12:26 - 2014-09-16 14:04 - 00003304 _____ () C:\Windows\System32\Tasks\gg_uac_daemon_Гроздан 2014-08-31 14:28 - 2014-08-31 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-28 12:24 - 2014-08-23 05:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-28 12:24 - 2014-08-23 04:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-28 12:24 - 2014-08-23 03:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-22 13:20 - 2014-05-14 19:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-22 13:20 - 2014-05-14 19:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-22 13:20 - 2014-05-14 19:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-22 13:20 - 2014-05-14 19:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-22 13:20 - 2014-05-14 19:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-22 13:20 - 2014-05-14 19:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-22 13:20 - 2014-05-14 19:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-22 13:20 - 2014-05-14 19:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-22 13:20 - 2014-05-14 19:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-22 13:20 - 2014-05-14 19:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-22 13:20 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-22 13:20 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-22 13:20 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-22 13:20 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-16 19:04 - 2014-09-16 19:04 - 00009381 _____ () C:\Users\Гроздан\Desktop\FRST.txt 2014-09-16 19:04 - 2014-09-16 19:03 - 00000000 ____D () C:\FRST 2014-09-16 19:03 - 2014-09-16 19:02 - 02105856 _____ (Farbar) C:\Users\Гроздан\Desktop\FRST64.exe 2014-09-16 18:46 - 2014-01-21 01:18 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-16 18:17 - 2014-04-13 13:22 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-16 16:27 - 2012-11-26 21:32 - 00000000 ____D () C:\Users\Гроздан\AppData\Roaming\uTorrent 2014-09-16 14:32 - 2014-09-16 14:32 - 00000000 ____D () C:\Users\Гроздан\AppData\Local\Adobe 2014-09-16 14:17 - 2012-11-26 11:03 - 01193009 ____N () C:\Windows\WindowsUpdate.log 2014-09-16 14:11 - 2009-07-14 07:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-16 14:11 - 2009-07-14 07:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-16 14:05 - 2012-11-26 15:34 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-09-16 14:04 - 2014-09-03 12:26 - 00003304 _____ () C:\Windows\System32\Tasks\gg_uac_daemon_Гроздан 2014-09-16 14:04 - 2009-07-14 08:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-14 17:43 - 2012-11-27 18:44 - 00000000 ____D () C:\Program Files (x86)\steam 2014-09-14 17:43 - 2012-11-26 21:48 - 00000000 ____D () C:\Users\Гроздан\AppData\Roaming\DAEMON Tools Pro 2014-09-13 21:31 - 2012-11-28 00:15 - 00000000 ____D () C:\Users\Гроздан\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-09-12 14:16 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-09-11 20:23 - 2014-09-11 20:23 - 00000000 ____D () C:\Users\Гроздан\AppData\Roaming\Grand Theft Auto IV 2014-09-11 20:23 - 2014-09-11 20:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics 2014-09-11 17:02 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\rescache 2014-09-10 21:46 - 2014-01-21 01:18 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-10 21:46 - 2014-01-21 01:18 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-10 21:46 - 2014-01-21 01:18 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-10 18:02 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\SysWOW64\bg-BG 2014-09-10 18:02 - 2009-07-14 06:20 - 00000000 ____D () C:\Windows\system32\bg-BG 2014-09-10 17:54 - 2012-11-26 12:50 - 00769944 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-09-10 17:54 - 2009-07-14 08:13 - 00769944 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-10 17:53 - 2013-07-11 09:15 - 00000000 ____D () C:\Windows\system32\MRT 2014-09-10 17:46 - 2012-11-26 12:23 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-09-07 15:47 - 2012-11-27 18:17 - 00000000 ____D () C:\Users\Гроздан\AppData\Roaming\Skype 2014-08-31 14:28 - 2014-08-31 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-08-31 14:28 - 2013-02-17 16:36 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-08-31 14:28 - 2012-11-27 18:17 - 00002515 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-08-31 14:28 - 2012-11-26 15:16 - 00000000 ____D () C:\ProgramData\Skype 2014-08-28 12:27 - 2009-07-14 07:45 - 00408224 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-25 22:52 - 2014-08-15 15:19 - 00000000 ____D () C:\Program Files\CCleaner 2014-08-25 06:53 - 2010-11-21 06:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-23 05:07 - 2014-08-28 12:24 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 04:45 - 2014-08-28 12:24 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-23 03:59 - 2014-08-28 12:24 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-22 12:33 - 2009-07-14 08:08 - 00032538 _____ () C:\Windows\Tasks\SCHEDLGU.TXT ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-07 17:58 ==================== End Of Log ============================ Addition.txt
  16. Ситуацията е следната.Имах проблем със Firefox,изразяваше се във това,че се затваряше бавно.Пуснах MBAM и SAS,като SAS откри въпросния Hijacker и уж го премахна успешно,но във момента браузъра работни мудно при затваряне дори забива и Explorer......Не знам дали SAS успешно е изтрил заразата,прилагам логовете от DDS: DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 8.0.7601.17514 Run by Night Rider at 0:38:43 on 2013-01-24 Microsoft Windows 7 Professional 6.1.7601.1.1251.359.1026.18.4094.2896 [GMT 2:00] . AV: COMODO Antivirus *Enabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D} FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB} . ============== Running Processes =============== . C:Windowssystem32wininit.exe C:Windowssystem32lsm.exe C:Windowssystem32svchost.exe -k DcomLaunch C:Windowssystem32nvvsvc.exe C:Windowssystem32svchost.exe -k RPCSS C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe C:Windowssystem32svchost.exe -k NetworkService C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted C:Windowssystem32svchost.exe -k netsvcs C:Windowssystem32svchost.exe -k GPSvcGroup C:Windowssystem32svchost.exe -k LocalService C:Windowssystem32svchost.exe -k LocalServiceNoNetwork C:Program FilesSUPERAntiSpywareSASCORE64.EXE C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe C:WindowsSysWOW64vmnat.exe C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE C:WindowsSysWOW64vmnetdhcp.exe C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe C:Program Files (x86)Common FilesVMwareUSBvmware-usbarbitrator64.exe C:Windowssystem32SearchIndexer.exe C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation C:Windowssystem32Dwm.exe C:WindowsExplorer.EXE C:Program Files (x86)Malwarebytes' Anti-Malwarembamgui.exe C:Program FilesCOMODOCOMODO Internet Securitycfp.exe C:Program FilesRealtekAudioHDARAVCpl64.exe C:Program Files (x86)RocketDockRocketDock.exe C:Program FilesNVIDIA CorporationDisplaynvxdsync.exe C:Windowssystem32nvvsvc.exe C:Windowssystem32taskhost.exe C:Program Files (x86)MSI AfterburnerMSIAfterburner.exe C:Windowssystem32SearchProtocolHost.exe C:Windowssystem32SearchFilterHost.exe C:Windowssystem32conhost.exe C:Windowssystem32wbemwmiprvse.exe C:WindowsSystem32cscript.exe . ============== Pseudo HJT Report =============== . mWinlogon: Userinit = userinit.exe BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll uRun: [RocketDock] "C:Program Files (x86)RocketDockRocketDock.exe" uPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: E&xport to Microsoft Excel - C:PROGRA~2MICROS~1OFFICE11EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} LSP: %windir%system32vsocklib.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: Interfaces{074B130A-393F-4554-B94E-47A32B33EB3C} : NameServer = 198.153.192.40 198.153.194.40 TCP: Interfaces{6FB8467E-F4A1-4D04-AEF9-2E72D92A8709} : NameServer = 198.153.192.40,198.153.194.40 SSODL: WebCheck - <orphaned> LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll x64-Run: [COMODO Internet Security] "C:Program FilesCOMODOCOMODO Internet Securitycfp.exe" -h x64-Run: [RTHDVCPL] C:Program FilesRealtekAudioHDARAVCpl64.exe -s x64-SSODL: WebCheck - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - C:UsersNight RiderAppDataRoamingMozillaFirefoxProfilesre5wl6x8.default FF - plugin: C:Program Files (x86)Microsoft Silverlight5.1.10411.0npctrlui.dll FF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32_11_5_502_146.dll . ============= SERVICES / DRIVERS =============== . R0 vsock;vSockets Driver;C:WindowsSystem32driversvsock.sys [2012-12-2 70296] R1 cmderd;COMODO Internet Security Eradication Driver;C:WindowsSystem32driverscmderd.sys [2012-11-7 22736] R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:WindowsSystem32driverscmdGuard.sys [2012-11-7 584056] R1 cmdHlp;COMODO Internet Security Helper Driver;C:WindowsSystem32driverscmdhlp.sys [2012-11-7 38144] R1 SASDIFSV;SASDIFSV;C:Program FilesSUPERAntiSpywaresasdifsv64.sys [2011-7-22 14928] R1 SASKUTIL;SASKUTIL;C:Program FilesSUPERAntiSpywaresaskutil64.sys [2011-7-12 12368] R2 !SASCORE;SAS Core Service;C:Program FilesSUPERAntiSpywareSASCore64.exe [2012-7-11 140672] R2 MBAMScheduler;MBAMScheduler;C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe [2012-11-30 398184] R2 MBAMService;MBAMService;C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe [2012-11-30 682344] R2 VMUSBArbService;VMware USB Arbitration Service;C:Program Files (x86)Common FilesVMwareUSBvmware-usbarbitrator64.exe [2012-10-11 918680] R3 MBAMProtector;MBAMProtector;C:WindowsSystem32driversmbam.sys [2012-11-30 24176] R3 RTCore64;RTCore64;C:Program Files (x86)MSI AfterburnerRTCore64.sys [2013-1-23 13368] R3 RTL8167;Realtek 8167 NT Driver;C:WindowsSystem32driversRt64win7.sys [2011-6-10 539240] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2010-3-18 138576] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2012-11-30 251400] S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2011-4-12 71168] S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:WindowsSystem32driversL1C62x64.sys [2009-6-10 57344] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2012-11-30 19456] S3 StorSvc;Storage Service;C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2012-11-30 57856] S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2012-11-30 30208] S3 WatAdminSvc;Услуга на технологиите за активиране на Windows;C:WindowsSystem32WatWatAdminSvc.exe [2012-11-30 1255736] . =============== Created Last 30 ================ . 2013-01-23 15:50:29 16200 ----a-w- C:Windowsstinger.sys 2013-01-23 15:48:21 -------- d-----w- C:Program Files (x86)stinger 2013-01-22 11:13:33 -------- d-----w- C:UsersNight RiderAppDataLocalDiagnostics 2013-01-13 12:38:26 -------- d-----w- C:UsersNight RiderDoctor Web 2013-01-09 09:48:09 800768 ----a-w- C:WindowsSystem32usp10.dll 2013-01-09 09:47:59 51712 ----a-w- C:WindowsSysWow64esrb.rs 2013-01-01 01:15:41 891240 ----a-w- C:WindowsSystem32nvvsvc.exe 2013-01-01 01:15:41 63336 ----a-w- C:WindowsSystem32nvshext.dll 2013-01-01 01:15:41 6200680 ----a-w- C:WindowsSystem32nvcpl.dll 2013-01-01 01:15:41 3536817 ----a-w- C:WindowsSystem32nvcoproc.bin 2013-01-01 01:15:41 3293544 ----a-w- C:WindowsSystem32nvsvc64.dll 2013-01-01 01:15:41 118120 ----a-w- C:WindowsSystem32nvmctray.dll 2013-01-01 01:15:16 -------- d-----w- C:ProgramDataNVIDIA Corporation 2012-12-28 14:16:53 -------- d-----w- C:UsersNight RiderAppDataLocalPrograms . ==================== Find3M ==================== . 2013-01-08 19:52:50 74248 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl 2013-01-08 19:52:50 697864 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe 2013-01-05 20:56:28 12872 ----a-w- C:WindowsSystem32bootdelete.exe 2012-12-16 17:11:22 46080 ----a-w- C:WindowsSystem32atmlib.dll 2012-12-16 14:45:03 367616 ----a-w- C:WindowsSystem32atmfd.dll 2012-12-16 14:13:28 295424 ----a-w- C:WindowsSysWow64atmfd.dll 2012-12-16 14:13:20 34304 ----a-w- C:WindowsSysWow64atmlib.dll 2012-12-14 14:49:28 24176 ----a-w- C:WindowsSystem32driversmbam.sys 2012-12-07 13:20:16 441856 ----a-w- C:WindowsSystem32Wpc.dll 2012-12-07 13:15:31 2746368 ----a-w- C:WindowsSystem32gameux.dll 2012-12-07 12:26:17 308736 ----a-w- C:WindowsSysWow64Wpc.dll 2012-12-07 12:20:43 2576384 ----a-w- C:WindowsSysWow64gameux.dll 2012-12-07 11:20:04 30720 ----a-w- C:WindowsSystem32usk.rs 2012-12-07 11:20:03 43520 ----a-w- C:WindowsSystem32csrr.rs 2012-12-07 11:20:03 23552 ----a-w- C:WindowsSystem32oflc.rs 2012-12-07 11:20:01 45568 ----a-w- C:WindowsSystem32oflc-nz.rs 2012-12-07 11:20:01 44544 ----a-w- C:WindowsSystem32pegibbfc.rs 2012-12-07 11:20:01 20480 ----a-w- C:WindowsSystem32pegi-fi.rs 2012-12-07 11:20:00 20480 ----a-w- C:WindowsSystem32pegi-pt.rs 2012-12-07 11:19:59 20480 ----a-w- C:WindowsSystem32pegi.rs 2012-12-07 11:19:58 46592 ----a-w- C:WindowsSystem32fpb.rs 2012-12-07 11:19:57 40960 ----a-w- C:WindowsSystem32cob-au.rs 2012-12-07 11:19:57 21504 ----a-w- C:WindowsSystem32grb.rs 2012-12-07 11:19:57 15360 ----a-w- C:WindowsSystem32djctq.rs 2012-12-07 11:19:56 55296 ----a-w- C:WindowsSystem32cero.rs 2012-12-07 11:19:55 51712 ----a-w- C:WindowsSystem32esrb.rs 2012-11-30 05:45:35 362496 ----a-w- C:WindowsSystem32wow64win.dll 2012-11-30 05:45:35 243200 ----a-w- C:WindowsSystem32wow64.dll 2012-11-30 05:45:35 13312 ----a-w- C:WindowsSystem32wow64cpu.dll 2012-11-30 05:45:14 215040 ----a-w- C:WindowsSystem32winsrv.dll 2012-11-30 05:43:12 16384 ----a-w- C:WindowsSystem32ntvdm64.dll 2012-11-30 05:41:07 424448 ----a-w- C:WindowsSystem32KernelBase.dll 2012-11-30 04:54:00 5120 ----a-w- C:WindowsSysWow64wow32.dll 2012-11-30 04:53:59 274944 ----a-w- C:WindowsSysWow64KernelBase.dll 2012-11-30 03:23:48 338432 ----a-w- C:WindowsSystem32conhost.exe 2012-11-30 02:44:06 25600 ----a-w- C:WindowsSysWow64setup16.exe 2012-11-30 02:44:04 7680 ----a-w- C:WindowsSysWow64instnm.exe 2012-11-30 02:44:04 14336 ----a-w- C:WindowsSysWow64ntvdm64.dll 2012-11-30 02:44:03 2048 ----a-w- C:WindowsSysWow64user.exe 2012-11-30 02:38:59 6144 ---ha-w- C:WindowsSysWow64api-ms-win-security-base-l1-1-0.dll 2012-11-30 02:38:59 4608 ---ha-w- C:WindowsSysWow64api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 02:38:59 3584 ---ha-w- C:WindowsSysWow64api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 02:38:59 3072 ---ha-w- C:WindowsSysWow64api-ms-win-core-util-l1-1-0.dll 2012-11-23 03:26:31 3149824 ----a-w- C:WindowsSystem32win32k.sys 2012-11-23 03:13:57 68608 ----a-w- C:WindowsSystem32taskhost.exe 2012-11-22 04:45:03 626688 ----a-w- C:WindowsSysWow64usp10.dll 2012-11-20 05:48:49 307200 ----a-w- C:WindowsSystem32ncrypt.dll 2012-11-20 04:51:09 220160 ----a-w- C:WindowsSysWow64ncrypt.dll 2012-11-09 05:45:32 750592 ----a-w- C:WindowsSystem32win32spl.dll 2012-11-09 05:45:09 2048 ----a-w- C:WindowsSystem32tzres.dll 2012-11-09 04:43:04 492032 ----a-w- C:WindowsSysWow64win32spl.dll 2012-11-09 04:42:49 2048 ----a-w- C:WindowsSysWow64tzres.dll 2012-11-07 21:38:02 38144 ----a-w- C:WindowsSystem32driverscmdhlp.sys 2012-11-07 21:38:00 584056 ----a-w- C:WindowsSystem32driverscmdGuard.sys 2012-11-07 21:37:58 22736 ----a-w- C:WindowsSystem32driverscmderd.sys 2012-11-07 21:37:38 41240 ----a-w- C:WindowsSystem32cmdcsr.dll 2012-11-07 21:37:36 301264 ----a-w- C:WindowsSysWow64guard32.dll 2012-11-07 21:37:32 390392 ----a-w- C:WindowsSystem32guard64.dll 2012-11-02 05:59:11 478208 ----a-w- C:WindowsSystem32dpnet.dll 2012-11-02 05:11:31 376832 ----a-w- C:WindowsSysWow64dpnet.dll 2012-11-01 05:43:42 2002432 ----a-w- C:WindowsSystem32msxml6.dll 2012-11-01 05:43:42 1882624 ----a-w- C:WindowsSystem32msxml3.dll 2012-11-01 04:47:54 1389568 ----a-w- C:WindowsSysWow64msxml6.dll 2012-11-01 04:47:54 1236992 ----a-w- C:WindowsSysWow64msxml3.dll 2012-11-01 00:35:20 357016 ----a-w- C:WindowsSysWow64vmnetdhcp.exe 2012-11-01 00:35:18 933528 ----a-w- C:WindowsSystem32vnetlib64.dll 2012-11-01 00:34:58 31384 ----a-w- C:WindowsSystem32driversVMparport.sys 2012-11-01 00:34:54 67224 ----a-w- C:WindowsSystem32driversvmx86.sys 2012-11-01 00:34:52 435864 ----a-w- C:WindowsSysWow64vmnat.exe 2012-11-01 00:34:32 30360 ----a-w- C:WindowsSystem32driversvmnetuserif.sys 2012-11-01 00:34:10 62104 ----a-w- C:WindowsSystem32vmnetbridge.dll 2012-11-01 00:34:10 45720 ----a-w- C:WindowsSystem32driversvmnetbridge.sys 2012-11-01 00:34:08 48792 ----a-w- C:WindowsSystem32vnetinst.dll 2012-11-01 00:34:08 24216 ----a-w- C:WindowsSystem32driversvmnet.sys 2012-11-01 00:34:08 20120 ----a-w- C:WindowsSystem32driversvmnetadapter.sys 2012-11-01 00:34:04 32920 ----a-w- C:WindowsSystem32driversVMkbd.sys 2012-10-31 23:02:08 353280 ----a-w- C:WindowsSysWow64vmnc.dll 2012-10-26 17:01:18 237400 ----a-w- C:WindowsSystem32driversVBoxDrv.sys 2012-10-26 16:59:44 119640 ----a-w- C:WindowsSystem32driversVBoxUSBMon.sys 2012-10-26 16:59:44 105816 ----a-w- C:WindowsSystem32driversVBoxUSB.sys . ============= FINISH: 0:39:36,10 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Professional Boot Device: DeviceHarddiskVolume1 Install Date: 30.11.2012 г. 17:39:34 System Uptime: 23.1.2013 г. 21:31:39 (3 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | G31M-ES2C Processor: Intel® Pentium® Dual CPU E2220 @ 2.40GHz | Socket 775 | 3000/250mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 33 GiB total, 19,045 GiB free. D: is FIXED (NTFS) - 200 GiB total, 82,858 GiB free. E: is CDROM () F: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: Description: Device ID: USBVID_EB1A&PID_28205&21E739F&0&8 Manufacturer: Name: PNP Device ID: USBVID_EB1A&PID_28205&21E739F&0&8 Service: . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . µTorrent AC3Filter 2.5b Adobe Flash Player 11 Plugin Auslogics Disk Defrag BurnAware Free 4.5 CCleaner COMODO Internet Security Far Cry 3 HitmanPro 3.7 Malwarebytes Anti-Malware, версия 1.70.0.1100 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Office File Validation Add-In Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 18.0.1 (x86 bg) MSI Afterburner 2.3.1 NVIDIA Control Panel 306.97 NVIDIA Graphics Driver 306.97 NVIDIA Install Application NVIDIA PhysX NVIDIA PhysX System Software 9.12.1031 PowerISO Realtek High Definition Audio Driver RocketDock 1.3.5 Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) SpywareBlaster 4.6 SumatraPDF SUPERAntiSpyware The KMPlayer (remove only) tools-windows Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) VMware Player Windows Live ID Sign-in Assistant WinRAR archiver Wise Disk Cleaner 7.74 . ==== Event Viewer Messages From Past Week ======== . 24.1.2013 г. 00:37:28, Error: Service Control Manager [7034] - Услуга VMware Authorization Service беше прекъсната неочаквано. Това се е случвало с нея 1 път(и). 23.1.2013 г. 01:30:45, Error: Service Control Manager [7034] - Услуга VMware Authorization Service беше прекъсната неочаквано. Това се е случвало с нея 1 път(и). 22.1.2013 г. 14:33:53, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service NVSvc with arguments "" in order to run the server: {DCAB0989-1301-4319-BE5F-ADE89F88581C} 22.1.2013 г. 14:33:37, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 22.1.2013 г. 14:33:37, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 22.1.2013 г. 14:33:36, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 22.1.2013 г. 14:33:30, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 22.1.2013 г. 14:33:29, Error: Service Control Manager [7026] - Неуспешно зареждане на следния драйвер, който се активира с включване на компютъра или стартиране на системата: cmdGuard discache SASDIFSV SASKUTIL SCDEmu spldr Wanarpv6 21.1.2013 г. 23:44:04, Error: Service Control Manager [7034] - Услуга VMware Authorization Service беше прекъсната неочаквано. Това се е случвало с нея 1 път(и). 19.1.2013 г. 20:47:34, Error: Service Control Manager [7034] - Услуга VMware Authorization Service беше прекъсната неочаквано. Това се е случвало с нея 1 път(и). 18.1.2013 г. 00:08:15, Error: Service Control Manager [7034] - Услуга VMware Authorization Service беше прекъсната неочаквано. Това се е случвало с нея 1 път(и). . ==== End Of File ===========================
  17. Здравейте, за първи път пиша във форума и моля да ме извините ако тук не е точното място на моя въпрос. От няколко дни имам проблем - при зареждане на страници ми изкача прозорец, който блокира съдържанието на страницата. Обикновено се отваря нов прозорец със следното съдържание - data:text/html,<script>window.close();</script> или конкретна реклама на онлайн магазин или досадните "Вие спечелихте...". Използвам Avast, Malwarebytes и adwcleaner, които не индикират проблем. Моля за помощ от Ваша страна. Благодаря за отделеното време и внимание. Хубав и успешен ден!
  18. Здравейте.Сигурно компютъра е лепнал някаква гадина , от известно време е много трудно да се сърфира нормално из интернет ,постоянно излизат разни реклами .Другото което е като дам назад ,за да върна някоя страница трябва да натисна 5-6 пъти стрелката , за да се върне предходната страница (използвам chrome) Забелязах , че с отварянето на браузъра се стартира и някаква добавка - 7savae 2.2 Като я махна се пооправя малко но пак е доста муден Компютъра се използва от всички членове на семейството ,та незнам кой в какви сайтове се рови и какво се сваля,имам антивирусна ( microsoft security essentials) но явно е влезнало нещо . Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015 Ran by Tsvetan (administrator) on TSVETAN-PC on 13-03-2015 18:28:47 Running from C:\Users\Tsvetan\Desktop Loaded Profiles: Tsvetan (Available profiles: Tsvetan) Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Autodata Limited) C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BlueSoleilCS.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsMobileCS.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Prolific Technology Inc.) C:\Windows\System32\IoctlSvc.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsHelpCS.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BtTray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) AppInit_DLLs: 4 0 => 4 0 File Not Found GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKU\S-1-5-21-3399673831-2713686379-3482629517-1000\Software\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.msn.com/?pc=BDT1&ocid=bdtdhp SearchScopes: HKLM -> DefaultScope {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1QzutDtDtC0F0CyC0B0B0FzztCtB0F0CtAyDtN0D0Tzu0CtByEzytN1L2XzutBtFtCtFtCtFtAtCtB&cr=316245494 SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> DefaultScope {3A40E547-20FD-44a2-94D0-1C98342D1507} URL = http://search.daum.net/search?nil_profile=ie&ref_code=ms&q={searchTerms} SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> Backup.Old.DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {3A40E547-20FD-44a2-94D0-1C98342D1507} URL = http://search.daum.net/search?nil_profile=ie&ref_code=ms&q={searchTerms} SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {5E55F9EC-CFEF-E453-B954-71D3D1222C2A} URL = http://search.babylon.com/?q={searchTerms}&AF=109130&tt=090212_noffx&babsrc=SP_ss&mntrId=784efc35000000000000001fc6bbf812 SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {8CB80152-FBCE-473C-ABCD-A81D5C6F4937} URL = http://www.bing.com/search?FORM=BDKTDF&PC=BDT1&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-3399673831-2713686379-3482629517-1000 -> {DD77A081-619B-4378-A4EE-FD7BFBE6A1A5} URL = https://www.google.com/search?q={searchTerms} DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 195.24.90.1 195.24.88.1 Tcpip\..\Interfaces\{1CCA028E-5561-4405-9AAE-567FCDF37FD7}: [NameServer] 10.250.238.3 10.250.238.4 FireFox: ======== FF ProfilePath: C:\Users\Tsvetan\AppData\Roaming\Mozilla\Firefox\Profiles\5wjvx04s.default FF DefaultSearchEngine: WebSearch FF DefaultSearchEngine,S: WebSearch FF DefaultSearchUrl: hxxp://websearch.eazytosearch.info/?pid=724&r=2014/05/17&hid=16964448839413303893&lg=EN&cc=BG&l=1&q= FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.1,S: WebSearch FF SelectedSearchEngine: WebSearch FF SelectedSearchEngine,S: WebSearch FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-04] () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-25] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-25] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-04] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-04] (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-09-07] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-09-07] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npfd.dll [2013-03-27] (FreshDevices Corp.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\911bg.xml [2011-11-21] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\diribg.xml [2011-11-21] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\pe-bg.xml [2011-11-21] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\portalbgdict.xml [2011-11-21] FF Extension: tiAkeshiop - C:\Users\Tsvetan\AppData\Roaming\Mozilla\Firefox\Profiles\5wjvx04s.default\Extensions\L@icf.edu [2015-02-15] FF Extension: aDsy - C:\Users\Tsvetan\AppData\Roaming\Mozilla\Firefox\Profiles\5wjvx04s.default\Extensions\n6pJU@d.org [2015-02-15] FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2013-11-06] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Tsvetan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (7savae) - C:\ProgramData\hcokglkhkdpieiligmplpiebcicfkmin\ [] CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-03-16] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] Opera: ======= OPR StartupUrls: "hxxp://google.com/" ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Autodata Limited License Service; C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe [72704 2014-05-17] (Autodata Limited) [File not signed] R2 BlueSoleilCS; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BlueSoleilCS.exe [850432 2009-02-27] () [File not signed] R3 BsHelpCS; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsHelpCS.exe [98407 2009-02-27] () [File not signed] R2 BsMobileCS; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\BsMobileCS.exe [143467 2009-02-27] () [File not signed] R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] R2 PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed] R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] () S3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [33800 2008-11-25] (IVT Corporation.) S3 BlueletSCOAudio; C:\Windows\System32\DRIVERS\BlueletSCOAudio.sys [27528 2008-11-25] (IVT Corporation.) R3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [39304 2009-01-03] (IVT Corporation.) R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [20744 2009-01-07] (IVT Corporation.) R3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [30088 2008-12-07] () R3 BTNetFilter; D:\Tsvetan\PROGRAMS\IVT.BlueSoleil.v6.4.249.0.x64 & x86 .Incl.Keymaker-EMBRACE\Device\Win2k\BTNetFilter.sys [22416 2006-11-22] (IVT Corporation.) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-03-16] (DT Soft Ltd) S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [27672 2008-04-22] (EnTech Taiwan) R3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [26248 2008-07-02] (IVT Corporation.) R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [48640 2009-08-23] (Atheros Communications, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation) R3 VComm; C:\Windows\System32\DRIVERS\VComm.sys [14856 2008-01-21] (IVT Corporation.) R3 VcommMgr; C:\Windows\System32\Drivers\VcommMgr.sys [31880 2009-01-08] (IVT Corporation.) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1841272 2012-10-22] (VIA Technologies, Inc.) R3 vodafone_K3805-z_dc_enum; C:\Windows\System32\DRIVERS\vodafone_K3805-z_dc_enum.sys [61952 2010-03-01] (Vodafone) R1 wStLib; C:\Windows\System32\drivers\wStLib.sys [52928 2014-03-19] (StdLib) S3 ZTEusbvoice; C:\Windows\System32\DRIVERS\ZTEusbvoice.sys [105856 2010-04-19] (ZTE Incorporated) S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [193536 2011-04-09] (ZTE Incorporated) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 BT; system32\DRIVERS\btnetdrv.sys [X] S0 BTHidEnum; System32\Drivers\vbtenum.sys [X] S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-13 18:28 - 2015-03-13 18:29 - 00016803 _____ () C:\Users\Tsvetan\Desktop\FRST.txt 2015-03-13 18:28 - 2015-03-13 18:28 - 01135104 _____ (Farbar) C:\Users\Tsvetan\Desktop\FRST.exe 2015-03-13 18:28 - 2015-03-13 18:28 - 00000000 ____D () C:\FRST 2015-03-11 12:31 - 2015-03-06 07:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-03-11 12:31 - 2015-03-06 07:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-03-11 12:31 - 2015-03-06 07:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-03-11 12:31 - 2015-03-06 07:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-03-11 12:31 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-03-11 12:31 - 2015-03-06 07:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-03-11 12:31 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-03-11 12:31 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-03-11 12:31 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-11 12:31 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-11 12:31 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-11 12:31 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-11 12:31 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-03-11 12:31 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-11 12:31 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-11 12:31 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-03-11 12:31 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-03-11 12:31 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-11 12:31 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-03-11 12:31 - 2015-02-20 04:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-03-11 12:31 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-11 12:31 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-03-11 12:31 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-03-11 12:31 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-11 12:31 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-11 12:31 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-03-11 12:31 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-03-11 12:31 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-03-11 12:31 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-11 12:31 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-03-11 12:31 - 2015-02-20 03:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-03-11 12:31 - 2015-02-20 03:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-11 12:31 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-11 12:31 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-11 12:31 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-11 12:31 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-11 12:31 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-11 12:31 - 2015-02-20 03:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-03-11 12:31 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-03-11 12:31 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-11 12:31 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-11 12:31 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-11 12:31 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-11 12:31 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-11 12:31 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-03-11 12:31 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-11 12:31 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-03-11 12:31 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-11 12:31 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-03-11 12:31 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-03-11 12:31 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-03-11 12:31 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-03-11 12:31 - 2015-02-03 05:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2015-03-11 12:31 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2015-03-11 12:31 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2015-03-11 12:31 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-03-11 12:31 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-03-11 12:31 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2015-03-11 12:31 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-03-11 12:31 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-11 12:31 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-11 12:31 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-11 12:31 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-03-11 12:31 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-11 12:31 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-11 12:31 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-11 12:31 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-02-25 15:54 - 2015-01-09 01:44 - 00419936 _____ () C:\Windows\system32\locale.nls 2015-02-25 14:19 - 2015-02-04 01:57 - 00606920 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe 2015-02-25 14:14 - 2015-02-04 05:35 - 24199824 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 15294096 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 11272048 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 11209376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 10702664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-02-25 14:14 - 2015-02-04 05:35 - 03987784 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 01060680 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234144.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 00911504 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234144.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 00908432 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2015-02-25 14:14 - 2015-02-04 05:35 - 00870032 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2015-02-17 19:14 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-02-17 19:14 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-02-17 19:14 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-02-17 16:04 - 2015-02-17 16:04 - 01202848 _____ (Microsoft Corporation) C:\Windows\system32\FM20.DLL 2015-02-15 18:23 - 2015-02-15 18:23 - 00028878 _____ () C:\Users\Tsvetan\Downloads\247.degrees.fahrenheit.2011.brrip.xvid-lycan(subsunacs.net) (1).rar 2015-02-15 18:23 - 2015-02-15 18:23 - 00000000 ____D () C:\Users\Tsvetan\Desktop\247.degrees.fahrenheit.2011.brrip.xvid-lycan(subsunacs.net) (1) 2015-02-15 18:20 - 2015-02-15 18:20 - 00028878 _____ () C:\Users\Tsvetan\Downloads\247.degrees.fahrenheit.2011.brrip.xvid-lycan(subsunacs.net).rar 2015-02-15 17:46 - 2015-02-15 17:46 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (6).torrent 2015-02-15 17:44 - 2015-02-15 17:44 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (5).torrent 2015-02-15 17:44 - 2015-02-15 17:44 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (4).torrent 2015-02-15 17:43 - 2015-02-15 17:43 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (3).torrent 2015-02-15 17:43 - 2015-02-15 17:43 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (2).torrent 2015-02-15 17:42 - 2015-02-15 17:42 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to] (1).torrent 2015-02-15 17:41 - 2015-02-15 17:41 - 00020332 _____ () C:\Users\Tsvetan\Downloads\Windows_8.1_PRO._Activated_[by_TorW]_[isohunt.to].torrent 2015-02-13 15:51 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-13 15:50 - 2015-02-04 04:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-02-13 15:50 - 2015-02-04 04:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-02-13 15:50 - 2015-02-04 04:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-02-13 15:50 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-02-13 15:50 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-13 18:22 - 2012-09-03 19:13 - 00000988 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-13 18:22 - 2011-12-13 16:42 - 01428287 _____ () C:\Windows\WindowsUpdate.log 2015-03-13 18:21 - 2013-03-27 17:27 - 00006510 _____ () C:\Windows\system32\LOCALSERVICE.INI 2015-03-13 18:21 - 2013-03-27 17:27 - 00000102 _____ () C:\Windows\system32\LOCALDEVICE.INI 2015-03-13 18:21 - 2009-02-27 17:04 - 00001152 _____ () C:\Windows\system32\bscs.ini 2015-03-13 18:17 - 2009-07-14 06:34 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-13 18:17 - 2009-07-14 06:34 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-13 18:10 - 2014-09-23 17:37 - 00027962 _____ () C:\Windows\setupact.log 2015-03-13 18:10 - 2012-09-03 19:13 - 00000984 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-13 18:10 - 2011-12-13 17:28 - 00001016 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3399673831-2713686379-3482629517-1000UA.job 2015-03-13 18:10 - 2011-12-13 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-03-13 18:10 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-12 20:36 - 2012-05-04 15:04 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-12 19:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2015-03-12 19:41 - 2011-12-13 17:28 - 00000964 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3399673831-2713686379-3482629517-1000Core.job 2015-03-12 17:37 - 2009-07-14 06:33 - 00406024 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-11 15:09 - 2011-12-15 14:29 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-11 15:08 - 2013-08-18 20:39 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-11 15:03 - 2011-12-13 20:52 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-11 12:25 - 2014-10-03 20:00 - 00000000 ____D () C:\Program Files\Opera 2015-03-09 14:31 - 2010-11-20 23:01 - 00786514 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-03-03 15:16 - 2011-12-13 17:37 - 00246920 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-02-25 22:11 - 2013-11-11 19:32 - 00000000 ____D () C:\Users\Tsvetan\AppData\Local\Viber 2015-02-25 22:10 - 2013-11-11 19:32 - 00000000 ____D () C:\Users\Tsvetan\AppData\Roaming\ViberPC 2015-02-25 14:19 - 2014-02-18 21:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-02-22 20:21 - 2011-12-13 18:56 - 00000000 ____D () C:\Users\Tsvetan\AppData\Roaming\Skype 2015-02-18 18:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\tracing 2015-02-15 21:00 - 2011-12-13 18:33 - 00000000 ____D () C:\Users\Tsvetan\AppData\Roaming\uTorrent 2015-02-15 12:36 - 2014-12-12 09:45 - 00000000 ____D () C:\Windows\system32\appraiser 2015-02-15 12:36 - 2014-05-07 15:17 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-02-13 16:26 - 2012-05-01 12:00 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2015-02-13 16:26 - 2012-01-09 21:46 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2015-02-13 16:26 - 2011-12-13 18:54 - 00001945 _____ () C:\Windows\epplauncher.mif ==================== Files in the root of some directories ======= 2014-11-23 18:57 - 2014-12-12 18:52 - 0000004 _____ () C:\Users\Tsvetan\AppData\Roaming\appdataFr2.bin 2011-12-19 15:09 - 2014-06-25 10:56 - 0000088 _____ () C:\Users\Tsvetan\AppData\Roaming\default.pls 2013-12-09 20:09 - 2013-12-09 20:09 - 0004608 _____ () C:\Users\Tsvetan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-09-09 13:11 - 2013-09-09 13:11 - 0003366 _____ () C:\Users\Tsvetan\AppData\Local\HWVendorDetection.log 2012-09-09 19:23 - 2013-07-09 17:10 - 0007634 _____ () C:\Users\Tsvetan\AppData\Local\Resmon.ResmonCfg 2010-04-22 19:37 - 2010-04-22 19:37 - 0155474 ____R () C:\ProgramData\DeviceManager.xml.rc4 2011-12-13 18:57 - 2011-12-13 18:57 - 0000056 ____H () C:\ProgramData\ezsidmv.dat 2014-05-17 16:11 - 2014-07-15 15:02 - 0000483 _____ () C:\ProgramData\Sls.ini Some content of TEMP: ==================== C:\Users\Tsvetan\AppData\Local\temp\jre-8u31-windows-au.exe C:\Users\Tsvetan\AppData\Local\temp\nvSCPAPI.dll C:\Users\Tsvetan\AppData\Local\temp\nvStInst.exe C:\Users\Tsvetan\AppData\Local\temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-06 15:52 Addition.txt
  19. Здравейте! При стартиране на Опера като начална страница всеки път се отварят различни сайтове без да съм ги задавала. При сканиране с Malwarebytes Anti-Malware излезнаха HiJack и domredi.com 1. Някои от проблемите програмата сложи под карантина и аз съответно ги изтрих. Но проблемът продължава.След това сканирах с avira_free_antivirus_en и бяха открити Warnings:18. Ще съм много благодарна ако проверите, има ли действително за какво да се притеснявам. Преди време ползвах услугите ви за друг проблем и останах много доволна.Благодаря предварително!Прилагам и DDS анализите: DDS (Ver_2011-09-30.01) - NTFS_AMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_33 Run by admin at 3:25:55 on 2012-08-14 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.4095.2500 [GMT 3:00] . AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\vVX3000.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Microsoft LifeCam\MSCamS64.exe c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\TCCARGO\tccargo.exe C:\Program Files (x86)\Trans\trans.exe C:\Program Files (x86)\uTorrent\uTorrent.exe C:\Program Files (x86)\Ask.com\Updater\Updater.exe C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\PROGRA~2\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskhost.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Opera\opera.exe C:\Program Files (x86)\Opera\pluginwrapper\opera_plugin_wrapper.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\conhost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.babylon.com/?babsrc=HP_Prot mStart Page = hxxp://home.sweetim.com/?st=1&barid={C8B60AA0-D32F-11E0-9D73-002185720B57} mDefault_Page_URL = hxxp://www.yahoo.com/?ilc=8 uURLSearchHooks: UrlSearchHook Class: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll uURLSearchHooks: YTNavAssistPlugin Class: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: {D4027C7F-154A-4066-A1AD-4243D8127440} - <orphaned> BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: SweetPacks Browser Helper: {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll TB: SweetPacks Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll TB: uTorrentControl2 Toolbar: {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll TB: SweetPacks Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll TB: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [TC Login] c:\tccargo\tccargo.exe --autostart uRun: [Green Christmas Tree] C:\Users\admin\Pictures\GreenChristmasTree.exe uRun: [Messenger (Yahoo!)] ~"C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet uRun: [Facebook Update] "C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver uRun: [RGSC] C:\Users\admin\Desktop\Games\Rockstar Games Social Club\RGSCLauncher.exe /silent uRun: [Trans] C:\Program Files (x86)\Trans\trans.exe uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED uRun: [auiqptq] C:\Users\admin\AppData\Local\yjtixd.exe mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s mRun: [sweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:0 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableLUA = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 IE: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab TCP: NameServer = 84.238.212.1 192.168.0.1 TCP: Interfaces\{70070C10-E0CF-45DB-8C32-2587B406A6EE} : DHCPNameServer = 84.238.212.1 192.168.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe x64-Run: [skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe x64-Run: [VX3000] C:\Windows\vVX3000.exe x64-Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned> . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\8tcqd6hp.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - hxxp://domredi.com/1/ FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=STC-US&o=1716&locale=en_EU&apn_uid=A31759C3-62C7-40C3-A02A-F5298D1F4FE7&apn_ptnrs=^AAO&apn_sauid=1F84DCBD-C0CF-4222-837C-A57059B3F42D&apn_dtid=^YYYYYY^YY^BG&&q= FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Program Files (x86)\Sony Online Entertainment\npsoe.dll FF - plugin: C:\Program Files (x86)\Sony Online Entertainment\npsoeact.dll FF - plugin: C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll FF - plugin: C:\Users\admin\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Users\admin\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll FF - plugin: C:\Users\admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll . ---- FIREFOX POLICIES ---- FF - user.js: extensions.BabylonToolbar_i.newTab - false FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(extensions.BabylonToolbar_i.babTrack, affID=109217 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - c0f12f2700000000000000064f72be4d FF - user.js: extensions.BabylonToolbar_i.hardId - c0f12f2700000000000000064f72be4d FF - user.js: extensions.BabylonToolbar_i.instlDay - 15453 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1721:40:03 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.instlRef - sst . ============= SERVICES / DRIVERS =============== . R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2012-5-13 27760] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928] R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-5-13 86224] R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-5-13 110032] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2012-5-13 98848] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-30 655944] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-5-20 2218600] R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-6-19 3048136] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-7 378472] R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-7-16 2673064] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-12-8 24904] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2011-5-20 174184] R3 RTL85n64;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\System32\drivers\RTL85n64.sys [2009-6-10 378368] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-31 250056] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-5-26 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-5-26 59392] S3 WatAdminSvc;Услуга на технологиите за активиране на Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-5-24 1255736] SUnknown tsusbhub;tsusbhub; [x] . =============== Created Last 30 ================ . 2012-08-10 14:08:42 9133488 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A6D1CD9F-1C45-4AD2-9D7E-F83D2FE94DB1}\mpengine.dll 2012-08-07 16:54:51 -------- d-----w- C:\Program Files (x86)\smartdl 2012-08-01 17:13:16 184700 ----a-w- C:\torrent.exe 2012-07-20 07:24:17 -------- d-----w- C:\Users\admin\temp . ==================== Find3M ==================== . 2012-08-02 23:11:09 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-02 23:11:09 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-07-03 10:46:44 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys 2012-06-12 03:08:36 3148800 ----a-w- C:\Windows\System32\win32k.sys 2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll 2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll 2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll 2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll 2012-06-02 12:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 12:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe 2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys 2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll 2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll 2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll 2012-05-31 09:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe . ============= FINISH: 3:26:20,83 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-09-30.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 20.5.2011 г. 18:11:10 System Uptime: 14.8.2012 г. 02:49:36 (1 hours ago) . Motherboard: ACER | | MCP73PV Processor: Intel® Core™2 Quad CPU Q8200 @ 2.33GHz | SOCKET775 M/B | 2336/333mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 154 GiB total, 36,033 GiB free. D: is FIXED (NTFS) - 298 GiB total, 273,954 GiB free. E: is FIXED (NTFS) - 596 GiB total, 74,916 GiB free. F: is FIXED (NTFS) - 144 GiB total, 23,553 GiB free. G: is CDROM (CDFS) H: is Removable I: is Removable J: is Removable K: is Removable L: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: Description: Coprocessor Device ID: PCI\VEN_10DE&DEV_07DA&SUBSYS_01371025&REV_A2\3&267A616A&0&1B Manufacturer: Name: Coprocessor PNP Device ID: PCI\VEN_10DE&DEV_07DA&SUBSYS_01371025&REV_A2\3&267A616A&0&1B Service: . ==== System Restore Points =================== . RP298: 9.8.2012 г. 13:44:39 - Scheduled Checkpoint . ==== Installed Programs ====================== . ЗБУТ+ (Версия 2.13) Гари Поттер и Принц-Полукровка v1.0 µTorrent 1.1 1ClickDownloader Activision® Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.3) Ashampoo Burning Studio 10.0.1 Ask Toolbar Ask Toolbar Updater Assassin's Creed Assassin's Creed Brotherhood v 1.0 Assassin's Creed Revelations v1.0 Rus-Eng Asterix and Obelix XXL2 Asterix at the Olympic Games Avira Free Antivirus Babylon toolbar on IE Batman Arkham Asylum Batman: Arkham Asylum Battlefield 2™ Battlefield 3 version 1.0 Bugs Bunny & Taz - Time Busters Canon MP280 series MP Drivers Compatibility Pack for the 2007 Office system Crystal Reports 2008 Runtime SP2 Deep Black : Reloaded Disney Tangled Ed, Edd n Eddy - The Mis-Edventures Facebook Video Calling 1.2.0.159 FIFA 11 Ford Racing 2 Ford Racing 3 Garfield Ghostbusters - The Videogame Google Chrome GTA San Andreas B-13 NFS 2011 Harry Potter and the Deathly Hallows Part 2 version 1.5 Harry Potter and the Deathly Hallows™ - Part 2 Harry Potter and the Deathly Hallows™ - Part 2 Demo Harry Potter and the Deathly Hallows™ - Part 1 Harry Potter and the Goblet of Fire™ Harry Potter and the Order of Phoenix v1.0 Harry Potter II HHD Software Free Hex Editor Neo 4.97 Ice Age 3 James Bond 007™ - Blood Stone Java Auto Updater Java™ 6 Update 33 Jungle Kartz LEGO Star Wars II LEGO Universe LEGO® Batman™ LEGO® Harry Potter™: Years 1-4 LEGO® Harry Potter™: Years 5-7 LEGO® Indiana Jones™ LEGO® Indiana Jones™ 2 LEGO® Indiana Jones™ 2: The Adventure Continues LEGO® Pirates of the Caribbean The Video Game Malwarebytes Anti-Malware, версия 1.62.0.1300 Martial Arts Capoeira Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Corporation Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft LifeCam Microsoft Office File Validation Add-In Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 11.0 (x86 bg) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NVIDIA 3D Vision Controller Driver NVIDIA 3D Vision Controller Driver 270.61 NVIDIA 3D Vision Driver 270.61 NVIDIA Control Panel 270.61 NVIDIA Graphics Driver 270.61 NVIDIA HD Audio Driver 1.2.22.1 NVIDIA Install Application NVIDIA PhysX NVIDIA PhysX System Software 9.10.0514 NVIDIA Stereoscopic 3D Driver NVIDIA Update 1.1.34 NVIDIA Update Components Opera 12.01 Pando Media Booster Pole Position 2012 version 1.0 Pro Evolution Soccer 2012 1.01 Realtek High Definition Audio Driver Renegade Ops Republic Heroes Rockstar Games Social Club Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Skype Click to Call Skype™ 5.10 SOE Web Installer Spider-Man™ - Shattered Dimensions Spider-Man: Web of Shadows Stateshift SweetIM for Messenger 3.6 SweetPacks Toolbar for Internet Explorer 4.4 TC Login TeamViewer 7 The Adventures of Tintin - The Secret of the Unicorn 1.0 The Cursed Crusade version 1.0 The Hulk™ The KMPlayer (remove only) The Three Musketeers - D'Artagnan and the 12 Jewels Toy Soldiers TrackMania 2 - Canyon TRANS 4.0.17.3152 Ubisoft Game Launcher Unity Web Player Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) uTorrentControl2 Toolbar VirtualCloneDrive Winamp Winamp Detector Plug-in Windows 7 Codec Pack 2.6.1 Windows Mobile Device Center WinRAR archiver Wizard101 World of Tanks Yahoo! BrowserPlus 2.9.8 Yahoo! Messenger Yahoo! Software Update Yahoo! Toolbar . ==== Event Viewer Messages From Past Week ======== . 9.8.2012 г. 08:21:00, Error: volsnap [25] - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied. 9.8.2012 г. 07:31:33, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 9.8.2012 г. 07:31:33, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 8.8.2012 г. 02:51:22, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 8.8.2012 г. 02:51:22, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 7.8.2012 г. 08:07:27, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 7.8.2012 г. 08:07:27, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 14.8.2012 г. 02:50:02, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 14.8.2012 г. 02:50:02, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 14.8.2012 г. 01:12:51, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 14.8.2012 г. 01:12:51, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 13.8.2012 г. 22:04:26, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 13.8.2012 г. 22:04:26, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 13.8.2012 г. 20:00:50, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 13.8.2012 г. 20:00:50, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 13.8.2012 г. 08:46:05, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 13.8.2012 г. 08:46:05, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.8.2012 г. 19:19:18, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 12.8.2012 г. 19:19:18, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 12.8.2012 г. 17:24:25, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk6\DR7. 12.8.2012 г. 17:24:25, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk6\DR7. 12.8.2012 г. 17:24:24, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk6\DR7. 12.8.2012 г. 17:24:24, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk6\DR7. 12.8.2012 г. 17:24:23, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk6\DR7. 12.8.2012 г. 07:56:58, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 12.8.2012 г. 07:56:58, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 11.8.2012 г. 07:42:08, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 11.8.2012 г. 07:42:08, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. 10.8.2012 г. 06:08:11, Error: Service Control Manager [7000] - Услуга atksgt не може да бъде стартирана поради следната грешка: Зареждането на този драйвер е блокирано 10.8.2012 г. 06:08:11, Error: Application Popup [875] - Driver atksgt.sys has been blocked from loading. . ==== End Of File ===========================
  20. Здравейте. От скоро забелязах, че двата диска C и D се пълнят без известна за мен причина.Дори понякога при диск C нямаше и един килобайт свободно пространство.Почистих ги от ненужни файлове и програми, но нямаше голям ефект. По какви ли начини не пробвах - ефекта винаги беше минимален. Последно пробвах да изчистя с програмата CCleaner и успя да ми освободи голяма част пространства при диск C и за момента нямам проблеми с него ( не знам дали отново ще се напълни ), но при диск D нямаше резултат. В момента съм най-близо до истината, че в компютъра ми има зловреден софтуер. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-11-2014 01 Ran by User (administrator) on USER-PC on 16-11-2014 16:29:33 Running from C:\Users\User\Downloads Loaded Profile: User (Available profiles: User) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Български (България) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe () C:\Program Files\Mobogenie\MgAssist.exe (Mobogenie.com) C:\Program Files\Mobogenie3\MobogenieService.exe (TorchMedia Inc.) C:\Users\User\AppData\Local\Torch\Update\TorchCrashHandler.exe (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe (Realtek Semiconductor Corp.) C:\Windows\RTHDCPL.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files\AVG SafeGuard toolbar\vprot.exe () C:\Program Files\Mobogenie\DaemonProcess.exe () C:\Program Files\Unlocker\UnlockerAssistant.exe (Bandoo Media Inc.) C:\Users\User\AppData\Local\iLivid\iLivid.exe (Softonic) C:\Users\User\AppData\Local\Softonic\Softonic.exe () C:\Program Files\Datecs\FlexType 2K\FType2K.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (mobogenie.com) C:\Program Files\Mobogenie3\mobogenieP2sp.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDCPL] => C:\Windows\RTHDCPL.EXE [16116224 2007-02-06] (Realtek Semiconductor Corp.) HKLM\...\Run: [skyTel] => C:\Windows\SkyTel.EXE [2879488 2006-05-23] (Realtek Semiconductor Corp.) HKLM\...\Run: [Alcmtr] => C:\Windows\ALCMTR.EXE [69632 2005-05-10] (Realtek Semiconductor Corp.) HKLM\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [995184 2013-07-18] (Microsoft Corporation) HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [vProt] => C:\Program Files\AVG SafeGuard toolbar\vprot.exe [2640408 2014-11-06] () HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe [748736 2014-06-01] () HKLM\...\Run: [kbdsprt] => [X] HKLM\...\Run: [unlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-04] () HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [EA Core] => "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\User\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=cfe8a617691547d39ae0d154265d5fc8-89c0334d3c6a5b62b955185ab8fbc974c007b18e /CMPID=1213b HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [iLivid] => C:\Users\User\AppData\Local\iLivid\iLivid.exe [6827008 2013-09-09] (Bandoo Media Inc.) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [softonic for Windows] => C:\Users\User\AppData\Local\Softonic\Softonic.exe [4170224 2014-04-29] (Softonic) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd) HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\MountPoints2: {66178fc2-3664-11e3-b5d3-001d60b9b63b} - G:\setup.exe HKU\S-1-5-21-2270866911-400411527-1567922316-1000\...\MountPoints2: {e59f4acc-5383-11e4-95d6-001d60b9b63b} - F:\setup.exe AppInit_DLLs: C:\PROGRA~2\Wincert\WIN32C~1.DLL => C:\PROGRA~2\Wincert\WIN32C~1.DLL File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browsemngr.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browsermngr.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe IFEO\cltmngsvc.exe: [Debugger] tasklist.exe IFEO\delta babylon.exe: [Debugger] tasklist.exe IFEO\delta tb.exe: [Debugger] tasklist.exe IFEO\delta2.exe: [Debugger] tasklist.exe IFEO\deltainstaller.exe: [Debugger] tasklist.exe IFEO\deltasetup.exe: [Debugger] tasklist.exe IFEO\deltatb.exe: [Debugger] tasklist.exe IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\iminentsetup.exe: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\rjatydimofu.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\sweetimsetup.exe: [Debugger] tasklist.exe IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FlexType 2K.lnk ShortcutTarget: FlexType 2K.lnk -> C:\Program Files\Datecs\FlexType 2K\FType2K.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Изрязване на екран и стартиране на OneNote 2007.lnk ShortcutTarget: Изрязване на екран и стартиране на OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll <===== ATTENTION ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=1235&systemid=406&v=u11465-250&apn_uid=8953571358224052&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^bg&si=pconvIE&ptb=5C62C4C4-EBC7-46CC-89A9-1CDEDF560188&ind=2014050305&n=780bf801&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKCU - {0773FA4C-3093-46A9-9E15-92E8BB088A57} URL = http://www.mysearchresults.com/search?c=8004&t=11&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=94C1001D60B9B63B&affID=128129&tsp=5147 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW&q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={F4AB6EFA-9A33-4482-97C5-19776A4B5267}&mid=cfe8a617691547d39ae0d154265d5fc8-89c0334d3c6a5b62b955185ab8fbc974c007b18e&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-0611:12:01&v=18.0.5.292&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=1235&systemid=406&v=u11465-250&apn_uid=8953571358224052&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^bg&si=pconvIE&ptb=5C62C4C4-EBC7-46CC-89A9-1CDEDF560188&ind=2014050305&n=780bf801&psa=&st=sb&searchfor={searchTerms} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Zula Games -> {2A836234-186C-41A0-9863-40BECDEDED9F} -> C:\Program Files\Zula Games\ScriptHost.dll No File BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Toolbar: HKLM - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search) Tcpip\..\Interfaces\{11412AFA-D2F1-4B36-B258-39C0F2202FC1}: [NameServer] 192.168.15.12,195.24.48.5 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: webssearches FF SelectedSearchEngine: webssearches FF Homepage: hxxp://istart.webssearches.com/?type=hp&ts=1404993434&from=amt&uid=ST3160815AS_5RA2LTSWXXXX5RA2LTSW FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll No File FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll No File FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: TorchVLC -> C:\Users\User\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\911bg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\diribg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\pe-bg.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\portalbgdict.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\webssearches.xml FF Extension: VideoDownloadConverter - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com [2014-11-12] FF Extension: Fast Start - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\Extensions\faststartff@gmail.com [2014-07-13] FF Extension: DownloadHelper - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-15] FF HKLM\...\Firefox\Extensions: [zulagames@ZulaGames.com] - C:\Users\User\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com FF Extension: Zula Games - C:\Users\User\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com [2013-10-17] FF HKLM\...\Firefox\Extensions: [speedanalysis03@SpeedAnalysis.com] - C:\Users\User\AppData\Roaming\Mozilla\Extensions\speedanalysis03@SpeedAnalysis.com FF Extension: No Name - C:\Users\User\AppData\Roaming\Mozilla\Extensions\speedanalysis03@SpeedAnalysis.com [2013-10-17] FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799 FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799 [2014-08-28] FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tg6aayzy.default\extensions\faststartff@gmail.com Chrome: ======= CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (VideoDownloadConverter) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeljlhkkoipjimklndofjoafhpccdfjo [2014-08-02] CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-07] CHR HKLM\...\Chrome\Extension: [adldappccjhelkmbkpiibilgnnjakieg] - C:\Program Files\VideoDownloadConverter_4z Chrome Extension\bar\VideoDownloadConvert@mindspark.com.gen1 [] CHR HKLM\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Users\User\AppData\Roaming\BabSolution\CR\BabylonChrome1.crx [] CHR HKLM\...\Chrome\Extension: [kdidombaedgpfiiedeimiebkmbilgmlc] - C:\Program Files\DefaultTab\DefaultTab.crx [] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.) S2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] R2 MgAssistService; C:\Program Files\Mobogenie\MgAssist.exe [105664 2014-07-22] () R2 MobogenieService; C:\Program Files\Mobogenie3\MobogenieService.exe [116928 2014-11-12] (Mobogenie.com) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-07-18] (Microsoft Corporation) R2 TorchCrashHandler; C:\Users\User\AppData\Local\Torch\Update\TorchCrashHandler.exe [1217032 2014-10-29] (TorchMedia Inc.) <==== ATTENTION R2 vToolbarUpdater18.1.9; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-11] (AVG Secure Search) S3 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-08-06] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [197400 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-08-11] (AVG Technologies) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-10-15] (Disc Soft Ltd) R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-14] (VIA Technologies, Inc. ) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-06-14] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () S1 MpKslb3189f59; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E4CFFD5A-C876-4E80-B999-7C2C8B1B1C08}\MpKslb3189f59.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-16 16:28 - 2014-11-16 16:29 - 00022048 _____ () C:\Users\User\Downloads\Addition.txt 2014-11-16 16:27 - 2014-11-16 16:29 - 00022066 _____ () C:\Users\User\Downloads\FRST.txt 2014-11-16 16:26 - 2014-11-16 16:29 - 00000000 ____D () C:\FRST 2014-11-16 16:26 - 2014-11-16 16:26 - 01108992 _____ (Farbar) C:\Users\User\Downloads\FRST.exe 2014-11-16 16:13 - 2014-11-16 16:13 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-11-16 16:13 - 2014-11-16 16:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-11-16 16:12 - 2014-11-16 16:13 - 00000000 ____D () C:\Program Files\CCleaner 2014-11-16 16:10 - 2014-11-16 16:11 - 04976136 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup419pro.exe 2014-11-15 22:30 - 2014-11-15 22:30 - 00000011 ____R () C:\Windows\amunres.lsl 2014-11-15 22:12 - 2014-11-16 16:19 - 00000000 ____D () C:\Program Files\Steam 2014-11-15 22:10 - 2014-11-15 22:11 - 01142392 _____ () C:\Users\User\Downloads\SteamSetup.exe 2014-11-15 14:16 - 2014-11-15 14:16 - 38381556 _____ () C:\Users\User\Downloads\HideNSeek_BM.dem 2014-11-14 23:09 - 2014-11-15 13:09 - 48651703 _____ () C:\Users\User\Downloads\flipeR.dem 2014-11-13 01:53 - 2014-11-13 01:53 - 00000000 ____D () C:\Users\User\mobogenieP2sp 2014-11-06 22:11 - 2014-11-06 22:11 - 00000000 ____D () C:\ProgramData\Avg_Update_1114tb 2014-11-03 00:05 - 2014-11-03 00:05 - 00017101 _____ () C:\Users\User\Downloads\Deja.Vu.2006.480p.BRRip.AC3.BGAUDIO-SlzD.torrent 2014-11-01 14:41 - 2014-11-01 14:41 - 222995856 _____ () C:\Users\User\cstrike 2014-11-01 14-41-20-99.avi 2014-11-01 14:40 - 2014-11-01 14:40 - 220153856 _____ () C:\Users\User\cstrike 2014-11-01 14-40-25-02.avi 2014-11-01 14:39 - 2014-11-01 14:40 - 221507616 _____ () C:\Users\User\cstrike 2014-11-01 14-39-52-28.avi 2014-11-01 14:39 - 2014-11-01 14:39 - 224203344 _____ () C:\Users\User\cstrike 2014-11-01 14-39-19-88.avi 2014-11-01 14:38 - 2014-11-01 14:39 - 219093188 _____ () C:\Users\User\cstrike 2014-11-01 14-38-42-11.avi 2014-11-01 14:38 - 2014-11-01 14:38 - 215116608 _____ () C:\Users\User\cstrike 2014-11-01 14-38-09-40.avi 2014-11-01 14:37 - 2014-11-01 14:38 - 228522404 _____ () C:\Users\User\cstrike 2014-11-01 14-37-36-12.avi 2014-11-01 14:37 - 2014-11-01 14:37 - 212516652 _____ () C:\Users\User\cstrike 2014-11-01 14-37-03-47.avi 2014-11-01 14:36 - 2014-11-01 14:37 - 230608452 _____ () C:\Users\User\cstrike 2014-11-01 14-36-30-17.avi 2014-11-01 14:33 - 2014-11-01 14:33 - 16519164 _____ () C:\Users\User\cstrike 2014-11-01 14-33-08-79.avi 2014-11-01 14:31 - 2014-11-01 14:31 - 224039848 _____ () C:\Users\User\cstrike 2014-11-01 14-31-25-65.avi 2014-11-01 14:13 - 2014-11-16 16:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps 2014-11-01 14:13 - 2014-11-01 14:13 - 00036079 _____ (Beepa Pty Ltd) C:\Users\Fraps\uninstall.exe 2014-11-01 14:13 - 2014-11-01 14:13 - 00000000 ____D () C:\Users\Fraps\HELP 2014-11-01 14:12 - 2014-11-01 14:13 - 00000000 ____D () C:\Users\Fraps 2014-11-01 14:11 - 2014-11-01 14:12 - 02326976 _____ (Beepa Pty Ltd) C:\Users\User\Downloads\setup.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-16 16:27 - 2013-10-16 15:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype 2014-11-16 16:22 - 2014-04-20 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro Evolution Soccer 2014 2014-11-16 16:22 - 2014-03-15 19:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Custom Strike 2014-11-16 16:22 - 2013-12-16 05:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2014-11-16 16:22 - 2013-12-12 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 2014-11-16 16:22 - 2013-10-30 16:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Casino at bet365 2014-11-16 16:22 - 2013-10-20 16:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resource Hacker 2014-11-16 16:22 - 2013-10-17 15:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2014-11-16 16:22 - 2013-10-16 15:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 2014-11-16 16:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-11-16 16:19 - 2013-12-21 14:56 - 00000000 ____D () C:\Users\User\AppData\Roaming\TeamViewer 2014-11-16 16:19 - 2013-10-16 15:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\uTorrent 2014-11-16 16:19 - 2013-10-16 15:28 - 00000000 ____D () C:\Users\User\AppData\Roaming\DAEMON Tools Lite 2014-11-16 16:18 - 2014-09-13 22:05 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps 2014-11-16 16:18 - 2013-10-16 15:49 - 00000000 ____D () C:\Windows\Panther 2014-11-16 15:59 - 2013-10-16 15:31 - 00000986 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-16 15:56 - 2013-10-16 15:12 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-16 14:37 - 2013-10-16 04:53 - 01106300 ____N () C:\Windows\WindowsUpdate.log 2014-11-16 07:55 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-16 07:55 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-16 07:54 - 2010-11-20 23:01 - 00782154 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-16 07:48 - 2014-07-17 08:40 - 00000000 ____D () C:\Program Files\Mobogenie3 2014-11-16 07:48 - 2014-02-06 10:25 - 00000000 ____D () C:\ProgramData\TorchCrashHandler 2014-11-16 07:48 - 2013-10-16 16:24 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-11-16 07:48 - 2013-10-16 15:31 - 00000982 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-16 07:48 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-15 22:30 - 2014-09-05 03:25 - 00000000 ____D () C:\Users\User\AppData\Roaming\Software Informer 2014-11-15 22:12 - 2014-02-06 17:52 - 00000921 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-11-14 22:22 - 2014-09-30 15:03 - 00000000 ____D () C:\Program Files\mozilla firefox 2014-11-13 23:56 - 2013-10-16 15:12 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-11-13 23:56 - 2013-10-16 15:12 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-11-10 23:06 - 2014-10-16 14:53 - 00000749 _____ () C:\Users\User\Desktop\Нов текстов документ.txt 2014-11-06 22:11 - 2014-08-28 13:53 - 00000000 ____D () C:\Program Files\AVG Security Toolbar 2014-11-05 10:54 - 2014-06-13 04:39 - 00002000 _____ () C:\Users\Public\Desktop\Google Slides.lnk 2014-11-05 10:54 - 2014-06-13 04:39 - 00001998 _____ () C:\Users\Public\Desktop\Google Sheets.lnk 2014-11-05 10:54 - 2014-06-13 04:39 - 00001988 _____ () C:\Users\Public\Desktop\Google Docs.lnk 2014-11-05 10:54 - 2014-01-27 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-11-04 10:51 - 2014-03-29 11:56 - 00000069 _____ () C:\Windows\NeroDigital.ini 2014-11-03 21:41 - 2014-02-06 10:24 - 00000000 ____D () C:\Users\User\AppData\Local\Torch 2014-11-03 21:40 - 2014-02-06 10:25 - 00001206 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk 2014-11-03 21:23 - 2013-11-28 23:17 - 00000000 ____D () C:\Windows\Minidump 2014-10-30 13:24 - 2013-10-16 15:28 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-27 23:55 - 2014-06-03 15:33 - 00002327 _____ () C:\Users\Public\Desktop\Google Chrome.lnk Files to move or delete: ==================== C:\Users\Fraps\fraps.exe C:\Users\Fraps\fraps32.dll C:\Users\Fraps\fraps64.dat C:\Users\Fraps\fraps64.dll C:\Users\Fraps\frapslcd.dll C:\Users\Fraps\uninstall.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-15 04:51 ==================== End Of Log ============================ Addition_16-11-2014_16-30-43.txt
  21. Оперативна памет » C:windowsSystem32cmd.exe - вариант на Win32/Fynloski.AA троянски кон - не може да се почисти Имам проблем с този вирус от преди 3 дена не виждам да ми създава за сега някакви проблеми но четох че бил много гаден ако някой може да помогне моля да пише.Мерси предварително
  22. Сигурен съм, че системата ми е заразена с тези и други вирусчета и това се случи след, като изтеглих това. За сега нищо не се е случило, но искам да се отърва от тях преди да се случи. Не разполагам с компакт диск за моята операционна система. Ето и файловете, които пожелахте. FRST.txt и Addition.txt
  23. преди 4 дена имах хакерска атака и ми напълниха и компа с вируси и исписва някакви грешки при пускане DDS (Ver_2011-09-30.01) - NTFS_AMD64Internet Explorer: 9.11.9600.16428Run by TheReaver at 16:00:18 on 2013-12-25Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1026.18.8167.4962 [GMT 2:00].SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ===============.C:Windowssystem32wininit.exeC:Windowssystem32lsm.exeC:Windowssystem32svchost.exe -k DcomLaunchC:Program Files (x86)Common FilesCOMODOlauncher_service.exeC:Windowssystem32svchost.exe -k RPCSSC:Windowssystem32atiesrxx.exeC:WindowsSystem32svchost.exe -k LocalServiceNetworkRestrictedC:WindowsSystem32svchost.exe -k LocalSystemNetworkRestrictedC:Windowssystem32svchost.exe -k LocalServiceC:Windowssystem32svchost.exe -k netsvcsC:Windowssystem32svchost.exe -k GPSvcGroupC:WindowsSysWOW64fsproflt2.exeC:Windowssystem32atieclxx.exeC:Windowssystem32svchost.exe -k NetworkServiceC:WindowsSystem32spoolsv.exeC:Windowssystem32svchost.exe -k LocalServiceNoNetworkD:xamppapachebinhttpd.exeC:Program Files (x86)ComodoDragondragon_updater.exeC:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonationD:xamppfilezillaftpfilezillaserver.exeC:Program Files (x86)Common FilesCOMODOGeekBuddyRSP.exeC:Program FilesHide Folders 2012hf.exeC:Windowssystem32taskhost.exeC:Windowssystem32Dwm.exeC:Program FilesMicrosoft SQL ServerMSSQL10_50.MSSQLSERVERMSSQLBinnsqlservr.exeC:WindowsExplorer.EXED:xamppapachebinhttpd.exeC:Windowssystem32taskeng.exeC:Program Files (x86)ASRock UtilityAXTUBinAsrXTU.exeC:Program FilesRealtekAudioHDARAVCpl64.exeC:Windowsvmsnap3.exeC:WindowsDomino.exeC:UsersTheReaverAppDataRoamingSearch ProtectionSearchProtection.exeC:UsersTheReaverAppDataRoaminguTorrentuTorrent.exeC:Program Files (x86)IM Magicianvicamon.exeC:Program Files (x86)IM Magicianvmonproc.exeC:Program Files (x86)AdTrustMediaPrivDog1.8.0.18trustedadssvc.exeC:Program Files (x86)Common FilesCOMODOGeekBuddyRSP.exeC:Program FilesCOMODOGeekBuddyunit_manager.exeC:Program FilesCOMODOGeekBuddyunit.exeC:Program Files (x86)RelevantKnowledgerlservice.exeC:WindowsSysWOW64rserver30RServer3.exeC:Program FilesMicrosoft SQL Server90Sharedsqlwriter.exeC:Windowssystem32svchost.exe -k imgsvcC:WindowsSysWOW64rserver30FamItrfc.ExeC:WindowsSysWOW64rserver30FamItrfc.ExeC:Program Files (x86)TeamViewerVersion9TeamViewer_Service.exeC:Windowssystem32SearchIndexer.exeC:Windowssystem32wbemwmiprvse.exeC:Program Files (x86)RelevantKnowledgerlvknlg.exeC:Windowssystem32wbemunsecapp.exeC:PROGRA~2RELEVA~1rlvknlg64.exeC:PROGRA~2RELEVA~1rlvknlg32.exeC:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exeC:WindowsSystem32svchost.exe -k secsvcsC:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exeC:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_9_900_170.exeC:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_9_900_170.exeD:CS 1.6 SERVERSDeathrun [4Fun] 4CS - For Servershlds.exeD:CS 1.6 SERVERSHNS 1CS - For Servershlds.exeD:CS 1.6 SERVERSSURF 4CS - For Servershlds.exeD:CS 1.6 SERVERSZOMBIE 3CS - For Servershlds.exeC:Program Files (x86)Mozilla Firefoxfirefox.exeC:Program Files (x86)Mozilla Firefoxplugin-container.exeC:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_9_900_170.exeC:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_9_900_170.exeC:Program Files (x86)SkypePhoneSkype.exeC:Program Files (x86)OriginOrigin.exeC:Program FilesDAUMPotPlayerPotPlayerMini64.exeC:Windowssystem32SearchProtocolHost.exeC:Windowssystem32SearchFilterHost.exeC:Windowssystem32conhost.exeC:WindowsSystem32cscript.exe.============== Pseudo HJT Report ===============.mWinlogon: Userinit = userinit.exeBHO: Advanced SystemCare Browser Protection: {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:Program Files (x86)IObitSurfing ProtectionBrowerProtectASCPlugin_Protection.dllBHO: PrivDog Extension: {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:Program Files (x86)AdTrustMediaPrivDog1.8.0.18trustedads.dlluRun: [searchProtection] "C:UsersTheReaverAppDataRoamingSearch ProtectionSearchProtection.EXE" /autostartuRun: [uTorrent] "C:UsersTheReaverAppDataRoaminguTorrentuTorrent.exe" /MINIMIZEDuRun: [RSS] wscript "C:UsersTheReaverAppDataRoamingAdobeFlash PlayerFile Cachefile.vbs" "C:UsersTheReaverAppDataRoamingAdobeFlash PlayerFile Cacherss.bat"uRun: [KiwiGuard] C:UsersTheReaverDesktopKiwiGuard-CrackedKiwiGuard-CrackedKiwiGuard.exeuRun: [firebwall] C:Program Files (x86)fireBwallfireBwall.exemRun: [iMMON] "C:Program Files (x86)IM MagicianVicamon.exe"mRun: [iMMONSUPPORT] "C:Program Files (x86)IM Magicianvmonproc.exe" /cls=IMMAGICIAN_CAMERA_MONITOR_I /exe=Vicamon.exemRun: [ComodoFSFirefox] "C:Program Files (x86)AdTrustMediaPrivDogFinalizeSetup.exe" /fmRun: [PrivDogService] "C:Program Files (x86)AdTrustMediaPrivDog1.8.0.18trustedadssvc.exe"mRun: [tvncontrol] "C:Program Files (x86)Common FilesCOMODOGeekBuddyRSP.exe" -controlservice -slaveStartupFolder: C:UsersTHEREA~1AppDataRoamingMICROS~1WindowsSTARTM~1ProgramsStartupGAMERA~1.LNK - C:UsersTheReaverAppDataRoamingGameRangerGameRangerGameRanger.exeStartupFolder: C:PROGRA~3MICROS~1WindowsSTARTM~1ProgramsStartupSQLSER~1.LNK - C:Program Files (x86)Microsoft SQL Server80ToolsBinnscm.exeStartupFolder: C:PROGRA~3MICROS~1WindowsSTARTM~1ProgramsStartupSTARTG~1.LNK - C:Program FilesCOMODOGeekBuddylauncher.exeuPolicies-Explorer: NoDriveTypeAutoRun = dword:145mPolicies-Explorer: NoActiveDesktop = dword:1mPolicies-Explorer: NoActiveDesktopChanges = dword:1mPolicies-System: ConsentPromptBehaviorAdmin = dword:0mPolicies-System: ConsentPromptBehaviorUser = dword:3mPolicies-System: EnableLUA = dword:0mPolicies-System: EnableUIADesktopToggle = dword:0mPolicies-System: PromptOnSecureDesktop = dword:0IE: {2F5C139F-79BD-4C84-A95A-E7140525BC55} - {5B06364D-FF00-4BD5-9D01-4379952513F2} - C:Program Files (x86)AdTrustMediaPrivDog1.8.0.18trustedads.dll.INFO: HKCU has more than 50 listed domains.If you wish to scan all of them, select the 'Force scan all domains' option..TCP: Interfaces{90C7E2AA-A9AE-4207-95B0-24447E8CB857} : NameServer = 88.87.0.2,88.87.10.2Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program Files (x86)Common FilesSkypeSkype4COM.dllSSODL: WebCheck - <orphaned>mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:Program Files (x86)GoogleChromeApplication31.0.1650.63Installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chromex64-BHO: ExplorerWnd Helper: {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:Program Files (x86)IObitIObit UninstallerUninstallExplorer64.dllx64-BHO: PrivDog Extension: {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:Program FilesAdTrustMediaPrivDog1.8.0.18trustedads.dllx64-Run: [RtHDVCpl] C:Program FilesRealtekAudioHDARAVCpl64.exe -sx64-Run: [VMSnap3] C:WindowsVMSnap3.exex64-Run: [Domino] C:WindowsDomino.exex64-IE: {2F5C139F-79BD-4C84-A95A-E7140525BC55} - {5B06364D-FF00-4BD5-9D01-4379952513F2} - C:Program FilesAdTrustMediaPrivDog1.8.0.18trustedads.dllx64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>x64-SSODL: WebCheck - <orphaned>.================= FIREFOX ===================.FF - ProfilePath - C:UsersTheReaverAppDataRoamingMozillaFirefoxProfileso2bq2ky2.defaultFF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=3&q={searchTerms}FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=407453&p=FF - plugin: C:Program Files (x86)GoogleUpdate1.3.22.3npGoogleUpdate3.dllFF - plugin: C:Program Files (x86)Pando NetworksMedia BoosternpPandoWebPlugin.dllFF - plugin: C:WindowsSysWOW64MacromedFlashNPSWF32_11_9_900_170.dll.---- FIREFOX POLICIES ----FF - user.js: nglayout.initialpaint.delay - 750FF - user.js: content.notify.interval - 750000FF - user.js: content.max.tokenizing.time - 2250000FF - user.js: content.switch.threshold - 750000FF - user.js: network.http.pipelining.maxrequests - 8FF - user.js: network.http.request.max-start-delay - 0FF - user.js: network.http.max-connections - 48FF - user.js: network.http.max-connections-per-server - 16FF - user.js: network.http.max-persistent-connections-per-proxy - 16FF - user.js: network.http.max-persistent-connections-per-server - 8FF - user.js: browser.turbo.enabled - trueFF - user.js: browser.display.show_image_placeholders - trueFF - user.js: browser.chrome.favicons - falseFF - user.js: browser.urlbar.autocomplete.enabled - trueFF - user.js: browser.cache.memory.capacity - 65536FF - user.js: content.notify.ontimer - trueFF - user.js: content.interrupt.parsing - trueFF - user.js: plugin.expose_full_path - trueFF - user.js: ui.submenuDelay - 0FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=32d9490d000000000000002522aa4cc7&q=FF - user.js: extensions.BabylonToolbar.id - 32d9490d000000000000002522aa4cc7FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}FF - user.js: extensions.BabylonToolbar.instlDay - 15726FF - user.js: extensions.BabylonToolbar.vrsn - 1.8.7.2FF - user.js: extensions.BabylonToolbar.vrsni - 1.8.7.2FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.8.7.222:44:07FF - user.js: extensions.BabylonToolbar.prtnrId - babylonFF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbarFF - user.js: extensions.BabylonToolbar.aflt - babsstFF - user.js: extensions.BabylonToolbar_i.smplGrp - noneFF - user.js: extensions.BabylonToolbar.tlbrId - baseFF - user.js: extensions.BabylonToolbar.instlRef - sstFF - user.js: extensions.BabylonToolbar.dfltLng - enFF - user.js: extensions.BabylonToolbar_i.excTlbr - falseFF - user.js: extensions.BabylonToolbar.excTlbr - falseFF - user.js: extensions.BabylonToolbar.admin - falseFF - user.js: extensions.BabylonToolbar_i.babTrack - affID=117023&tt=0313_7FF - user.js: extensions.BabylonToolbar_i.babExt -FF - user.js: extensions.BabylonToolbar_i.srcExt - ssFF - user.js: extensions.BabylonToolbar.autoRvrt - falseFF - user.js: extensions.BabylonToolbar.rvrt - falseFF - user.js: extensions.BabylonToolbar_i.newTab - false.============= SERVICES / DRIVERS ===============.R0 FSProFilter2;FSPro File Filter 2;C:WindowsSystem32driversFSPFltd2.sys [2013-11-20 57648]R1 CFRMD;CFRMD;C:WindowsSystem32driversCFRMD.sys [2013-5-7 37976]R1 HMD;COMODO livePCsupport Hardware Monitor Driver;C:WindowsSystem32drivershmd.sys [2013-10-7 14888]R1 ndisrd;WinpkFilter LightWeight Filter;C:WindowsSystem32driversndisrd.sys [2013-8-5 43088]R1 raddrvv3;raddrvv3;C:WindowsSysWOW64rserver30raddrvv3.sys [2009-10-9 68704]R2 AMD External Events Utility;AMD External Events Utility;C:WindowsSystem32atiesrxx.exe [2013-8-31 239616]R2 Apache2.2;Apache2.2;D:xamppapachebinhttpd.exe [2008-12-10 24636]R2 CLPSLauncher;COMODO LPS Launcher;C:Program Files (x86)Common FilesCOMODOlauncher_service.exe [2013-12-13 70352]R2 DragonUpdater;COMODO Dragon Update Service;C:Program Files (x86)ComodoDragondragon_updater.exe [2013-11-11 2098880]R2 fsproflt2;FSPro Filter Service 2;C:WindowsSysWOW64fsproflt2.exe [2013-11-20 49512]R2 GeekBuddyRSP;GeekBuddyRSP Server;C:Program Files (x86)Common FilesCOMODOGeekBuddyRSP.exe [2013-12-13 2327248]R2 RelevantKnowledge;RelevantKnowledge;C:Program Files (x86)RelevantKnowledgerlservice.exe [2013-12-13 186136]R2 RServer3;Radmin Server V3;C:WindowsSysWOW64rserver30rserver3.exe [2009-10-9 1242504]R2 TeamViewer9;TeamViewer 9;C:Program Files (x86)TeamViewerVersion9TeamViewer_Service.exe [2013-12-20 5341536]R2 UNS;Intel® Management and Security Application User Notification Service;C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe [2013-11-20 2656280]R3 amdkmdag;amdkmdag;C:WindowsSystem32driversatikmdag.sys [2013-8-31 12528640]R3 amdkmdap;amdkmdap;C:WindowsSystem32driversatikmpag.sys [2013-8-31 618496]R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:WindowsSystem32driversAtihdW76.sys [2013-7-5 96256]R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:WindowsSystem32driversEtronHub3.sys [2011-2-8 39936]R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:WindowsSystem32driversEtronXHCI.sys [2011-2-8 64512]R3 MEIx64;Intel® Management Engine Interface;C:WindowsSystem32driversHECIx64.sys [2013-11-20 56344]R3 mirrorv3;mirrorv3;C:WindowsSystem32driversrminiv3.sys [2012-12-18 5632]R3 RTL8167;Realtek 8167 NT Driver;C:WindowsSystem32driversRt64win7.sys [2013-11-20 344680]R3 vvftav303;vvftav303;C:WindowsSystem32driversvvftav303.sys [2013-12-13 308096]R3 ZSMC0303;A4 TECH PC Camera H;C:WindowsSystem32driversusbVM303.sys [2013-12-13 1494656]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe [2012-7-9 104912]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe [2012-7-8 123856]S2 gupdate;Услуга на Google Актуализация (gupdate);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-11-21 116648]S2 hlsm;HL Server Monitor;D:CS 1.6 SERVERSDEATHRUN [FUN] (6132)hlsm.exe --> D:CS 1.6 SERVERSDEATHRUN [FUN] (6132)hlsm.exe [?]S2 LiveUpdateSvc;LiveUpdate;C:Program Files (x86)IObitLiveUpdateLiveUpdate.exe [2013-11-20 2151232]S2 SkypeUpdate;Skype Updater;C:Program Files (x86)SkypeUpdaterUpdater.exe [2013-9-5 171680]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe [2013-11-20 257416]S3 dmvsc;dmvsc;C:WindowsSystem32driversdmvsc.sys [2011-4-12 71168]S3 gupdatem;Услуга на Google Актуализация (gupdatem);C:Program Files (x86)GoogleUpdateGoogleUpdate.exe [2013-11-21 116648]S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:WindowsSystem32ieetwcollector.exe [2013-12-13 111616]S3 MozillaMaintenance;Mozilla Maintenance Service;C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe [2013-11-20 119408]S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:WindowsSystem32driversrdpvideominiport.sys [2013-11-20 19456]S3 Revoflt;Revoflt;C:WindowsSystem32driversrevoflt.sys [2013-11-21 31800]S3 RTCore64;RTCore64;C:Program Files (x86)MSI AfterburnerRTCore64.sys [2013-1-23 13368]S3 Synth3dVsc;Synth3dVsc;C:WindowsSystem32driversSynth3dVsc.sys [2011-4-12 88960]S3 terminpt;Microsoft Remote Desktop Input Driver;C:WindowsSystem32driversterminpt.sys [2013-11-20 29696]S3 TsUsbFlt;TsUsbFlt;C:WindowsSystem32driversTsUsbFlt.sys [2013-11-20 57856]S3 TsUsbGD;Remote Desktop Generic USB Device;C:WindowsSystem32driversTsUsbGD.sys [2013-11-20 30208]S3 WatAdminSvc;Windows Activation Technologies Service;C:WindowsSystem32WatWatAdminSvc.exe [2013-11-20 1255736]S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:Program FilesMicrosoft SQL Server100Sharedsqladhlp.exe [2010-4-3 59744]S4 RsFx0153;RsFx0153 Driver;C:WindowsSystem32driversRsFx0153.sys [2012-6-29 321992]SUnknown tsusbhub;tsusbhub; [x].=============== Created Last 30 ================.2013-12-24 12:30:49 -------- d-----w- C:Program FilesHide Folders 20122013-12-24 10:04:12 10315576 ----a-w- C:ProgramDataMicrosoftWindows DefenderDefinition Updates{9FC35C14-EFDF-4276-8687-A6985F460EBC}mpengine.dll2013-12-24 09:52:46 94208 ----a-w- C:WindowsDIIUnin.exe2013-12-24 09:52:46 2829 ----a-w- C:WindowsDIIUnin.pif2013-12-24 09:51:17 -------- d-----w- C:Program Files (x86)Diablo II2013-12-22 09:30:17 -------- d-----w- C:Program Files (x86)QS2013-12-21 09:49:11 -------- d-----w- C:UsersTheReaverAppDataRoamingComodo2013-12-21 07:51:23 -------- d-----w- C:Program Files (x86)Common FilesCOMODO2013-12-21 07:35:34 -------- d-----w- C:UsersTheReaverAppDataLocalAdTrustMedia2013-12-21 07:34:36 -------- d-----w- C:Program FilesAdTrustMedia2013-12-21 07:34:36 -------- d-----w- C:Program Files (x86)AdTrustMedia2013-12-21 07:34:35 -------- d-----w- C:ProgramDataAdtrustmedia2013-12-21 07:34:26 -------- d-----w- C:ProgramDataCOMODO2013-12-21 07:34:17 -------- d-----w- C:Program FilesCOMODO2013-12-21 07:34:10 -------- d-----w- C:UsersTheReaverAppDataLocalComodo2013-12-21 07:34:07 57096 ----a-w- C:WindowsSystem32certsentry.dll2013-12-21 07:34:07 48392 ----a-w- C:WindowsSysWow64certsentry.dll2013-12-21 07:34:02 -------- d-----w- C:Program Files (x86)Comodo2013-12-21 07:22:57 -------- d-----w- C:ISA Server 2006 SP1 Standard Edition CD2013-12-21 07:12:56 -------- d-----w- C:Program Files (x86)Sygate2013-12-21 07:12:39 -------- d-----w- C:Program Files (x86)Common FilesWise Installation Wizard2013-12-21 07:10:31 -------- d-----w- C:UsersTheReaverAppDataRoamingfirebwall2013-12-21 07:10:03 -------- d-----w- C:Program Files (x86)WinpkFilter2013-12-20 23:31:32 -------- d-----w- C:Program Files (x86)Everything2013-12-20 22:56:59 -------- d-----w- C:Program Files (x86)Anti DDoS Guardian 2.32013-12-20 22:39:34 36256 ----a-w- C:WindowsSystem32driversnblocker.sys2013-12-20 22:39:33 -------- d-----w- C:Program Files (x86)Anti DDoS Guardian 3.12013-12-18 17:56:22 -------- d-----w- C:WindowsCS 1.6 COOL EDiTiON2013-12-14 20:59:00 -------- d-----w- C:Program Files (x86)MSXML 4.02013-12-14 06:06:35 859416 ----a-w- C:WindowsSystem32rlls64.dll2013-12-14 06:06:35 593688 ----a-w- C:WindowsSysWow64rlls.dll2013-12-13 21:10:26 167424 ----a-w- C:Program FilesWindows Media Playerwmplayer.exe2013-12-13 21:10:26 164864 ----a-w- C:Program Files (x86)Windows Media Playerwmplayer.exe2013-12-13 21:10:26 12625920 ----a-w- C:WindowsSystem32wmploc.DLL2013-12-13 21:10:25 12625408 ----a-w- C:WindowsSysWow64wmploc.DLL2013-12-13 20:23:47 -------- d-----w- C:Program FilesCPUID2013-12-13 11:57:55 -------- d-----w- C:UsersTheReaverAppDataRoamingVimisoft Studio2013-12-13 11:57:47 77824 ----a-w- C:WindowsSysWow64vgf.dll2013-12-13 11:57:47 450560 ----a-w- C:WindowsSysWow64newlistview2.dll2013-12-13 11:57:47 -------- d-----w- C:Program Files (x86)Common FilesVimisoft Studio2013-12-13 11:57:30 -------- d-----w- C:Program Files (x86)Vimicro Corporation2013-12-13 11:57:16 -------- d-----w- C:Program Files (x86)IM Magician2013-12-13 11:49:04 -------- d-----w- C:WindowsEffectResources2013-12-12 22:32:08 -------- d-----w- C:Program Files (x86)RelevantKnowledge2013-12-12 22:31:34 -------- d-----w- C:Program Files (x86)Free EXE Lock2013-12-12 22:20:11 -------- d-----w- C:Program Files (x86)ELTIMA Software2013-12-12 10:10:15 -------- d-----w- C:UsersTheReaverAppDataRoamingLolClient2013-12-12 09:28:07 467984 ----a-w- C:WindowsSysWow64d3dx10_39.dll2013-12-12 09:28:07 1493528 ----a-w- C:WindowsSysWow64D3DCompiler_39.dll2013-12-12 09:28:06 3851784 ----a-w- C:WindowsSysWow64D3DX9_39.dll2013-12-12 09:27:55 -------- d-sh--w- C:WindowsSysWow64AI_RecycleBin2013-12-12 09:26:13 -------- d-----w- C:UsersTheReaverAppDataLocalPMB Files2013-12-12 09:26:12 -------- d-----w- C:ProgramDataPMB Files2013-12-12 09:26:09 -------- d-----w- C:Program Files (x86)Pando Networks2013-12-12 09:25:45 -------- d-----w- C:UsersTheReaverAppDataRoamingRiot Games2013-12-11 19:58:08 -------- d-----w- C:WindowsSysWow64directx2013-12-11 19:57:52 -------- d-----w- C:Program Files (x86)MSI Afterburner2013-12-11 11:37:34 -------- d-----w- C:Fraps2013-12-10 08:35:22 -------- d-----w- C:UsersTheReaverAppDataLocalApps2013-12-10 08:34:55 -------- d-----w- C:Program Files (x86)Active Data Recovery Software2013-12-10 08:25:13 -------- d-----w- C:UsersTheReaverAppDataLocalstorage2013-12-08 16:15:05 -------- d-----w- C:UsersTheReaverAppDataLocalMicrosoft_Corporation2013-12-08 16:13:31 57288 ----a-w- C:WindowsSysWow64perf-MSSQL10_50.MSSQLSERVER-sqlagtctr.dll2013-12-08 16:13:30 86984 ----a-w- C:WindowsSystem32perf-MSSQL10_50.MSSQLSERVER-sqlagtctr.dll2013-12-08 16:13:18 88520 ----a-w- C:WindowsSystem32perf-MSSQLSERVER-sqlctr10.52.4000.0.dll2013-12-08 16:13:18 82888 ----a-w- C:WindowsSysWow64perf-MSSQLSERVER-sqlctr10.52.4000.0.dll2013-12-08 16:12:11 -------- d-----w- C:WindowsSystem32RsFx2013-12-08 16:09:22 -------- d-----w- C:UsersTheReaverAppDataLocalMicrosoft Help2013-12-08 16:08:30 -------- d-----w- C:Program Files (x86)Microsoft Synchronization Services2013-12-08 16:08:16 -------- d-----w- C:Program Files (x86)Microsoft SQL Server Compact Edition2013-12-08 16:08:10 -------- d-----w- C:WindowsSysWow6410332013-12-08 16:08:10 -------- d-----w- C:WindowsSystem3210332013-12-08 16:04:43 -------- d-----w- C:WindowsPCHEALTH2013-12-08 16:02:41 -------- d-----w- C:Program FilesMicrosoft SQL Server2013-12-08 15:49:45 -------- d-----w- C:UsersTheReaverAppDataLocalDownloaded Installations2013-12-07 07:05:24 -------- d-----w- C:UsersTheReaverAppDataRoamingSearch Protection2013-12-07 07:05:17 -------- d-----w- C:ProgramDataYTD Video Downloader2013-12-07 07:05:04 -------- d-----w- C:Program Files (x86)GreenTree Applications2013-12-06 16:02:03 -------- d-----w- C:ProgramData{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}2013-12-06 16:02:03 -------- d-----w- C:ProgramData{D76294E6-03B8-4971-AF2E-3F846161A690}2013-12-05 20:05:47 -------- d-----w- C:Program Files (x86)VideoLAN2013-12-05 10:34:33 -------- d-----w- C:Program Files (x86)ASRock Utility2013-11-29 20:03:21 -------- d-----w- C:Program Files (x86)Unlocker2013-11-29 12:44:01 -------- d-----w- C:Program Files (x86)avpbg2013-11-29 12:40:47 -------- d-----w- C:ProgramDataKaspersky Lab2013-11-29 12:16:43 -------- d-----w- C:Program Files (x86)Kaspersky Lab2013-11-29 12:04:19 -------- d-s---w- C:WindowsSysWow64Microsoft2013-11-28 16:43:50 -------- d-----w- C:ProgramDataAMMYY2013-11-27 20:20:17 -------- d-----w- C:Program Files (x86)TeamViewer2013-11-27 18:59:11 -------- d-----w- C:Program Files (x86)Common FilesSteam2013-11-27 18:03:20 -------- d-----w- C:UsersTheReaverAppDataRoamingRadmin2013-11-27 11:13:35 99840 ----a-w- C:WindowsSystem32driversusbccgp.sys2013-11-27 11:13:35 52736 ----a-w- C:WindowsSystem32driversusbehci.sys2013-11-27 11:13:34 7808 ----a-w- C:WindowsSystem32driversusbd.sys2013-11-27 11:13:34 343040 ----a-w- C:WindowsSystem32driversusbhub.sys2013-11-27 11:13:34 325120 ----a-w- C:WindowsSystem32driversusbport.sys2013-11-27 11:13:34 30720 ----a-w- C:WindowsSystem32driversusbuhci.sys2013-11-27 11:13:34 25600 ----a-w- C:WindowsSystem32driversusbohci.sys2013-11-27 09:18:01 140288 ----a-w- C:WindowsSysWow64Comdlg32.ocx2013-11-27 09:18:00 1355776 ----a-w- C:WindowsSysWow64msvbvm50.dll2013-11-27 09:17:57 192569 ----a-w- C:WindowsSysWow64msrpjt40.dll2013-11-27 09:17:42 274489 ----a-w- C:WindowsSysWow64ntwdblib.dll2013-11-27 09:17:39 97552 ----a-w- C:WindowsSysWow64rdocurs.dll2013-11-27 09:17:39 376592 ----a-w- C:WindowsSysWow64msrdo20.dll2013-11-27 09:17:38 32830 ----a-w- C:WindowsSysWow64dbmsshrn.dll2013-11-27 09:17:13 -------- d-----w- C:Program Files (x86)Microsoft SQL Server2013-11-27 09:04:36 306688 ----a-w- C:WindowsIsUninst.exe2013-11-27 08:59:29 -------- d-----w- C:UsersTheReaverAppDataRoamingTeamViewer2013-11-27 08:48:29 -------- d-----w- C:WindowsSysWow64rserver302013-11-27 07:43:42 -------- d-sh--w- C:ProgramDataDSS2013-11-26 19:05:36 -------- d-----w- C:Program Files (x86)Origin Games2013-11-26 19:05:17 -------- d-----w- C:UsersTheReaverAppDataRoamingOrigin2013-11-26 19:05:16 -------- d-----w- C:UsersTheReaverAppDataLocalOrigin2013-11-26 19:03:58 -------- d-----w- C:ProgramDataOrigin2013-11-26 19:03:57 -------- d-----w- C:ProgramDataElectronic Arts2013-11-26 19:03:43 -------- d-----w- C:Program Files (x86)Origin2013-11-26 07:47:40 -------- d-----r- C:Program Files (x86)Skype2013-11-26 06:14:47 -------- d-----w- C:WindowsSystem32MRT.==================== Find3M ====================.2013-12-11 18:21:23 71048 ----a-w- C:WindowsSysWow64FlashPlayerCPLApp.cpl2013-12-11 18:21:23 692616 ----a-w- C:WindowsSysWow64FlashPlayerApp.exe2013-11-26 10:19:07 2724864 ----a-w- C:WindowsSystem32mshtml.tlb2013-11-26 10:18:23 4096 ----a-w- C:WindowsSystem32ieetwcollectorres.dll2013-11-26 09:48:07 66048 ----a-w- C:WindowsSystem32iesetup.dll2013-11-26 09:46:25 48640 ----a-w- C:WindowsSystem32ieetwproxystub.dll2013-11-26 09:23:02 2724864 ----a-w- C:WindowsSysWow64mshtml.tlb2013-11-26 09:18:39 139264 ----a-w- C:WindowsSystem32ieUnatt.exe2013-11-26 09:18:09 111616 ----a-w- C:WindowsSystem32ieetwcollector.exe2013-11-26 09:16:57 708608 ----a-w- C:WindowsSystem32jscript9diag.dll2013-11-26 08:35:02 5769216 ----a-w- C:WindowsSystem32jscript9.dll2013-11-26 08:28:16 553472 ----a-w- C:WindowsSysWow64jscript9diag.dll2013-11-26 08:16:12 4243968 ----a-w- C:WindowsSysWow64jscript9.dll2013-11-26 08:02:16 1995264 ----a-w- C:WindowsSystem32inetcpl.cpl2013-11-26 07:32:06 1928192 ----a-w- C:WindowsSysWow64inetcpl.cpl2013-11-26 07:07:57 2334208 ----a-w- C:WindowsSystem32wininet.dll2013-11-26 06:33:33 1820160 ----a-w- C:WindowsSysWow64wininet.dll2013-11-23 18:26:20 417792 ----a-w- C:WindowsSysWow64WMPhoto.dll2013-11-23 17:47:34 465920 ----a-w- C:WindowsSystem32WMPhoto.dll2013-11-21 11:44:01 447888 ----a-w- C:WindowsSystem32driversaswNdisFlt.sys2013-11-20 17:05:45 197120 ----a-w- C:WindowsSystem32credui.dll2013-11-20 17:05:45 1930752 ----a-w- C:WindowsSystem32authui.dll2013-11-20 17:05:45 190464 ----a-w- C:WindowsSystem32SmartcardCredentialProvider.dll2013-11-20 17:05:45 1796096 ----a-w- C:WindowsSysWow64authui.dll2013-11-20 17:05:45 168960 ----a-w- C:WindowsSysWow64credui.dll2013-11-20 17:05:45 152576 ----a-w- C:WindowsSysWow64SmartcardCredentialProvider.dll2013-11-20 17:03:35 404480 ----a-w- C:WindowsSystem32gdi32.dll2013-11-20 17:03:35 311808 ----a-w- C:WindowsSysWow64gdi32.dll2013-11-20 17:02:43 1474048 ----a-w- C:WindowsSystem32crypt32.dll2013-11-20 17:02:43 1168384 ----a-w- C:WindowsSysWow64crypt32.dll2013-11-20 17:01:48 497152 ----a-w- C:WindowsSystem32driversafd.sys2013-11-20 16:59:21 30720 ----a-w- C:WindowsSystem32cryptdlg.dll2013-11-20 16:59:21 24576 ----a-w- C:WindowsSysWow64cryptdlg.dll2013-11-20 16:58:28 81920 ----a-w- C:WindowsSysWow64davclnt.dll2013-11-20 16:58:28 259584 ----a-w- C:WindowsSystem32WebClnt.dll2013-11-20 16:58:28 205824 ----a-w- C:WindowsSysWow64WebClnt.dll2013-11-20 16:58:28 140800 ----a-w- C:WindowsSystem32driversmrxdav.sys2013-11-20 16:58:28 102400 ----a-w- C:WindowsSystem32davclnt.dll2013-11-20 16:56:50 461312 ----a-w- C:WindowsSystem32scavengeui.dll2013-11-20 16:55:28 109824 ----a-w- C:WindowsSystem32driversUSBAUDIO.sys2013-11-20 16:55:28 100864 ----a-w- C:WindowsSystem32driversusbcir.sys2013-11-20 16:54:46 785624 ----a-w- C:WindowsSystem32driversWdf01000.sys2013-11-20 16:54:00 633856 ----a-w- C:WindowsSystem32comctl32.dll2013-11-20 16:54:00 530432 ----a-w- C:WindowsSysWow64comctl32.dll2013-11-20 16:53:19 76800 ----a-w- C:WindowsSystem32drivershidclass.sys2013-11-20 16:53:19 32896 ----a-w- C:WindowsSystem32drivershidparse.sys2013-11-20 16:52:32 70656 ----a-w- C:WindowsSysWow64fontsub.dll2013-11-20 16:52:32 46080 ----a-w- C:WindowsSystem32atmlib.dll2013-11-20 16:52:32 41472 ----a-w- C:WindowsSystem32lpk.dll2013-11-20 16:52:32 368128 ----a-w- C:WindowsSystem32atmfd.dll2013-11-20 16:52:32 34304 ----a-w- C:WindowsSysWow64atmlib.dll2013-11-20 16:52:32 295424 ----a-w- C:WindowsSysWow64atmfd.dll2013-11-20 16:52:32 25600 ----a-w- C:WindowsSysWow64lpk.dll2013-11-20 16:52:32 14336 ----a-w- C:WindowsSystem32dciman32.dll2013-11-20 16:52:32 10240 ----a-w- C:WindowsSysWow64dciman32.dll2013-11-20 16:52:32 100864 ----a-w- C:WindowsSystem32fontsub.dll2013-11-20 16:51:50 983488 ----a-w- C:WindowsSystem32driversdxgkrnl.sys2013-11-20 16:51:50 265064 ----a-w- C:WindowsSystem32driversdxgmms1.sys2013-11-20 16:51:50 144384 ----a-w- C:WindowsSystem32cdd.dll2013-11-20 16:48:18 124112 ----a-w- C:WindowsSystem32PresentationCFFRasterizerNative_v0300.dll2013-11-20 16:48:18 102608 ----a-w- C:WindowsSysWow64PresentationCFFRasterizerNative_v0300.dll2013-11-20 16:46:51 1887232 ----a-w- C:WindowsSystem32d3d11.dll2013-11-20 16:46:51 1505280 ----a-w- C:WindowsSysWow64d3d11.dll2013-11-20 16:46:05 327168 ----a-w- C:WindowsSystem32mswsock.dll2013-11-20 16:46:05 231424 ----a-w- C:WindowsSysWow64mswsock.dll2013-11-20 16:46:05 1903552 ----a-w- C:WindowsSystem32driverstcpip.sys2013-11-20 16:44:23 62976 ----a-w- C:WindowsSystem32TSWbPrxy.exe2013-11-20 16:41:21 155584 ----a-w- C:WindowsSystem32driversataport.sys2013-11-20 16:40:48 1888768 ----a-w- C:WindowsSystem32WMVDECOD.DLL2013-11-20 16:40:48 1620992 ----a-w- C:WindowsSysWow64WMVDECOD.DLL2013-11-20 16:37:55 663552 ----a-w- C:WindowsSysWow64rpcrt4.dll2013-11-20 16:37:55 1217024 ----a-w- C:WindowsSystem32rpcrt4.dll2013-11-20 16:37:18 288088 ----a-w- C:WindowsSystem32driversFWPKCLNT.SYS2013-11-20 16:36:46 39936 ----a-w- C:WindowsSystem32driverstssecsrv.sys2013-11-20 16:36:08 224256 ----a-w- C:WindowsSystem32wintrust.dll2013-11-20 16:36:08 184320 ----a-w- C:WindowsSystem32cryptsvc.dll2013-11-20 16:36:08 175104 ----a-w- C:WindowsSysWow64wintrust.dll2013-11-20 16:36:08 140288 ----a-w- C:WindowsSysWow64cryptsvc.dll2013-11-20 16:36:08 139776 ----a-w- C:WindowsSystem32cryptnet.dll2013-11-20 16:36:08 103936 ----a-w- C:WindowsSysWow64cryptnet.dll2013-11-20 16:34:58 624128 ----a-w- C:WindowsSystem32qedit.dll2013-11-20 16:34:58 509440 ----a-w- C:WindowsSysWow64qedit.dll2013-11-20 16:29:24 751104 ----a-w- C:WindowsSystem32win32spl.dll2013-11-20 16:29:24 492544 ----a-w- C:WindowsSysWow64win32spl.dll2013-11-20 16:28:45 903168 ----a-w- C:WindowsSysWow64certutil.exe2013-11-20 16:28:45 52224 ----a-w- C:WindowsSystem32certenc.dll2013-11-20 16:28:45 43008 ----a-w- C:WindowsSysWow64certenc.dll2013-11-20 16:28:45 1192448 ----a-w- C:WindowsSystem32certutil.exe2013-11-20 16:26:26 70144 ----a-w- C:WindowsSystem32appinfo.dll2013-11-20 16:26:26 111448 ----a-w- C:WindowsSystem32consent.exe2013-11-20 16:25:51 48640 ----a-w- C:WindowsSystem32wwanprotdim.dll2013-11-20 16:25:51 230400 ----a-w- C:WindowsSystem32wwansvc.dll2013-11-20 16:25:26 474624 ----a-w- C:WindowsapppatchAcSpecfc.dll2013-11-20 16:25:26 350208 ----a-w- C:WindowsapppatchAppPatch64AcLayers.dll2013-11-20 16:25:26 308736 ----a-w- C:WindowsapppatchAppPatch64AcGenral.dll2013-11-20 16:25:26 2176512 ----a-w- C:WindowsapppatchAcGenral.dll2013-11-20 16:25:26 135168 ----a-w- C:WindowsapppatchAppPatch64AcXtrnal.dll2013-11-20 16:25:26 111104 ----a-w- C:WindowsapppatchAppPatch64acspecfc.dll2013-11-20 16:23:47 1656680 ----a-w- C:WindowsSystem32driversntfs.sys2013-11-20 16:22:41 223752 ----a-w- C:WindowsSystem32driversfvevol.sys.============= FINISH: 16:00:33,29 ===============.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-09-30.01).Microsoft Windows 7 UltimateBoot Device: DeviceHarddiskVolume1Install Date: 20.11.2013 г. 17:05:38System Uptime: 25.12.2013 г. 08:00:46 (8 hours ago).Motherboard: ASRock | | H67M-GEProcessor: Intel® Core i5-2400 CPU @ 3.10GHz | CPUSocket | 3101/100mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 100 GiB total, 46,398 GiB free.D: is FIXED (NTFS) - 831 GiB total, 364,807 GiB free.E: is CDROM ().==== Disabled Device Manager Items =============.==== System Restore Points ===================.RP102: 21.12.2013 г. 13:28:20 - Инсталиране на драйверен пакет за устройство: COMODO Мрежова услугаRP103: 24.12.2013 г. 12:03:54 - Windows Update.==== Installed Programs ======================.µTorrentA4 TECH PC Camera HActive@ UNDELETE 7 EnterpriseAdobe Flash Player 11 PluginAdobe Flash Player 9 ActiveXAIDA64 Business v4.00AMD Accelerated Video TranscodingAMD Catalyst Control CenterAMD Catalyst Install ManagerAMD Drag and Drop TranscodingAMD Media Foundation DecodersASRock eXtreme Tuner v0.1.215Catalyst Control Center - BrandingCatalyst Control Center Graphics Previews CommonCatalyst Control Center InstallProxyCatalyst Control Center Localization Allccc-utility64CCC Help Chinese StandardCCC Help Chinese TraditionalCCC Help CzechCCC Help DanishCCC Help DutchCCC Help EnglishCCC Help FinnishCCC Help FrenchCCC Help GermanCCC Help GreekCCC Help HungarianCCC Help ItalianCCC Help JapaneseCCC Help KoreanCCC Help NorwegianCCC Help PolishCCC Help PortugueseCCC Help RussianCCC Help SpanishCCC Help SwedishCCC Help ThaiCCC Help TurkishCCleanerComodo DragonComponents SetupCounter-StrikeCPUID CPU-Z 1.67.1CS 1.6 COOL EDiTiONDaum PotPlayer 1.5.39659 x64 EditionDiablo IIDiablo II - Eastern SunEtron USB3.0 Host ControllerEverything 1.2.1.371EXE Password Protector 1.1.6.214FIFA 13foobar2000 v1.2.9Fraps (remove only)Free EXE Lock 5.4.5GameRangerGeekBuddyGoogle ChromeGoogle Update HelperHotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)IM MagicianInfinityMU SEASON 3Intel® Management Engine ComponentsIObit UninstallerK-Lite Mega Codec Pack 9.8.5League of LegendsMicrosoft .NET Framework 4.5Microsoft Application Error ReportingMicrosoft Report Viewer Redistributable 2008 (KB971119)Microsoft Report Viewer Redistributable 2008 SP1Microsoft SQL Server 2008 R2 (64-bit)Microsoft SQL Server 2008 R2 Native ClientMicrosoft SQL Server 2008 R2 PoliciesMicrosoft SQL Server 2008 R2 RsFx DriverMicrosoft SQL Server 2008 R2 Setup (English)Microsoft SQL Server 2008 Setup Support FilesMicrosoft SQL Server BrowserMicrosoft SQL Server Compact 3.5 SP2 ENUMicrosoft SQL Server Compact 3.5 SP2 Query Tools ENUMicrosoft SQL Server VSS WriterMicrosoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2005 Redistributable (x64)Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727Microsoft Visual Studio Tools for Applications 2.0 - ENUMozilla Firefox 26.0 (x86 bg)Mozilla Maintenance ServiceMSI Afterburner 2.3.1MSXML 4.0 SP2 (KB954430)MSXML 4.0 SP2 (KB973688)NetTools 5.0Notepad++OriginPando Media BoosterPowerISOPrivDogRadmin Server 3.4Realtek Ethernet Controller Driver For Windows 7Realtek High Definition Audio DriverRelevantKnowledgeRevo Uninstaller Pro 3.0.8Search ProtectionSecurity Update for Microsoft .NET Framework 4.5 (KB2737083)Security Update for Microsoft .NET Framework 4.5 (KB2742613)Security Update for Microsoft .NET Framework 4.5 (KB2789648)Security Update for Microsoft .NET Framework 4.5 (KB2833957)Security Update for Microsoft .NET Framework 4.5 (KB2840642v2)Security Update for Microsoft .NET Framework 4.5 (KB2861208)Service Pack 2 for SQL Server 2008 R2 (KB2630458) (64-bit)Skype™ 6.11SQL Server 2008 R2 SP2 Common FilesSQL Server 2008 R2 SP2 Database Engine ServicesSQL Server 2008 R2 SP2 Database Engine SharedSQL Server 2008 R2 SP2 Management StudioSql Server Customer Experience Improvement ProgramSurfing ProtectionTeamViewer 9Ubisoft Game LauncherUpdate for Microsoft .NET Framework 4.5 (KB2750147)Update for Microsoft .NET Framework 4.5 (KB2805221)Update for Microsoft .NET Framework 4.5 (KB2805226)VLC media player 2.1.1WinPcap 3.0WinpkFilter Runtime & ToolsWinRAR 5.00 (64-битова версия)XAMPP 1.7.1YTD Video Downloader 4.7.1.==== Event Viewer Messages From Past Week ========.25.12.2013 г. 08:02:08, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).25.12.2013 г. 08:01:08, Error: Service Control Manager [7000] - The HL Server Monitor service failed to start due to the following error: The system cannot find the file specified.24.12.2013 г. 19:44:51, Error: Service Control Manager [7034] - The Apache2.2 service terminated unexpectedly. It has done this 1 time(s).24.12.2013 г. 18:55:27, Error: Service Control Manager [7034] - The HL Server Monitor service terminated unexpectedly. It has done this 1 time(s).24.12.2013 г. 18:04:43, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).24.12.2013 г. 18:03:54, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SQL Server (MSSQLSERVER) service to connect.24.12.2013 г. 18:03:54, Error: Service Control Manager [7000] - The SQL Server (MSSQLSERVER) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.24.12.2013 г. 10:06:42, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).24.12.2013 г. 10:06:10, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SQL Server (MSSQLSERVER) service to connect.24.12.2013 г. 10:06:10, Error: Service Control Manager [7000] - The SQL Server (MSSQLSERVER) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.24.12.2013 г. 08:55:09, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).24.12.2013 г. 08:54:28, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SQL Server (MSSQLSERVER) service to connect.24.12.2013 г. 08:54:28, Error: Service Control Manager [7000] - The SQL Server (MSSQLSERVER) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.24.12.2013 г. 08:02:09, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).22.12.2013 г. 13:54:34, Error: Service Control Manager [7030] - The HL Server Monitor service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.22.12.2013 г. 11:27:16, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).22.12.2013 г. 08:02:07, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 13:33:48, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 13:23:58, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 13:22:51, Error: Service Control Manager [7003] - The BeeThink IP Blocker Service service depends the following service: NBlocker. This service might not be installed.21.12.2013 г. 12:04:56, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 12:03:44, Error: Service Control Manager [7003] - The BeeThink IP Blocker Service service depends the following service: NBlocker. This service might not be installed.21.12.2013 г. 09:41:48, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 09:40:16, Error: Service Control Manager [7003] - The BeeThink IP Blocker Service service depends the following service: NBlocker. This service might not be installed.21.12.2013 г. 09:37:29, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 2 time(s).21.12.2013 г. 09:37:13, Error: Service Control Manager [7034] - The Advanced SystemCare Service 7 service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 09:36:39, Error: Service Control Manager [7030] - The Advanced SystemCare Service 7 service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.21.12.2013 г. 09:36:18, Error: Service Control Manager [7034] - The AdvancedSystemCareAntivirus service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 09:19:03, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SmcService service.21.12.2013 г. 09:16:56, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 09:16:26, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Teefer wpsdrvnt21.12.2013 г. 09:15:51, Error: Service Control Manager [7003] - The BeeThink IP Blocker Service service depends the following service: NBlocker. This service might not be installed.21.12.2013 г. 09:15:51, Error: Service Control Manager [7000] - The SyGate for NT, wg6n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:15:51, Error: Service Control Manager [7000] - The SyGate for NT, wg5n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:15:51, Error: Service Control Manager [7000] - The SyGate for NT, wg4n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:15:51, Error: Service Control Manager [7000] - The SyGate for NT, wg3n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:15:51, Error: Application Popup [1060] - SystemRootSysWow64Driverswg6n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:15:51, Error: Application Popup [1060] - SystemRootSysWow64Driverswg5n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:15:51, Error: Application Popup [1060] - SystemRootSysWow64Driverswg4n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:15:51, Error: Application Popup [1060] - SystemRootSysWow64Driverswg3n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:15:40, Error: Application Popup [1060] - SystemRootSysWow64DriversTeefer.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:19, Error: Service Control Manager [7000] - The SyGate for NT, wg6n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:13:19, Error: Service Control Manager [7000] - The SyGate for NT, wg5n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:13:19, Error: Application Popup [1060] - SystemRootSysWow64Driverswg6n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:19, Error: Application Popup [1060] - SystemRootSysWow64Driverswg5n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:18, Error: Service Control Manager [7000] - The SyGate for NT, wg4n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:13:18, Error: Application Popup [1060] - SystemRootSysWow64Driverswg4n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:17, Error: Service Control Manager [7000] - The SyGate for NT, wg3n service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:13:17, Error: Application Popup [1060] - SystemRootSysWow64Driverswg3n.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:16, Error: Service Control Manager [7000] - The Teefer for NT service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:13:16, Error: Application Popup [1060] - SystemRootSysWow64DriversTeefer.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:02, Error: Service Control Manager [7000] - The wpsdrvnt service failed to start due to the following error: This driver has been blocked from loading21.12.2013 г. 09:13:02, Error: Service Control Manager [7000] - The Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.21.12.2013 г. 09:13:02, Error: Application Popup [1060] - SystemRootSysWow64driverswpsdrvnt.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.21.12.2013 г. 09:13:00, Error: Service Control Manager [7030] - The Sygate Personal Firewall Pro service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.21.12.2013 г. 08:02:08, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 08:01:03, Error: Service Control Manager [7003] - The BeeThink IP Blocker Service service depends the following service: NBlocker. This service might not be installed.21.12.2013 г. 05:29:58, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.21.12.2013 г. 04:49:33, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).21.12.2013 г. 04:48:29, Error: Service Control Manager [7003] - The BeeThink IP Blocker Service service depends the following service: NBlocker. This service might not be installed.20.12.2013 г. 23:36:55, Error: Service Control Manager [7034] - The Kaspersky Anti-Virus Service service terminated unexpectedly. It has done this 1 time(s).20.12.2013 г. 23:31:21, Error: Service Control Manager [7030] - The Radmin Server V3 service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.20.12.2013 г. 23:25:01, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).20.12.2013 г. 23:19:23, Error: Service Control Manager [7030] - The Radmin Server V3 service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.20.12.2013 г. 23:17:15, Error: Service Control Manager [7030] - The Radmin Server V3 service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.20.12.2013 г. 23:06:03, Error: Service Control Manager [7031] - The Kaspersky Anti-Virus Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Рестартиране на услугата.20.12.2013 г. 21:27:31, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).20.12.2013 г. 21:21:25, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {06622D85-6856-4460-8DE1-A81921B41C4B}. The error: "5" Happened while starting this command: C:WindowsSysWOW64DllHost.exe /Processid:{06622D85-6856-4460-8DE1-A81921B41C4B}20.12.2013 г. 21:14:26, Error: Service Control Manager [7034] - The SQL Server VSS Writer service terminated unexpectedly. It has done this 1 time(s).20.12.2013 г. 21:14:23, Error: Service Control Manager [7034] - The SQL Server (MSSQLSERVER) service terminated unexpectedly. It has done this 1 time(s).20.12.2013 г. 20:36:14, Error: Service Control Manager [7034] - The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).20.12.2013 г. 13:48:24, Error: bowser [8003] - The master browser has received a server announcement from the computer GFDDGF-79E68F5A that believes that it is the master browser for the domain on transport NetBT_Tcpip_{90C7E2AA-A9AE-4207-95B0-24447E8CB857}. The master browser is stopping or an election is being forced.18.12.2013 г. 14:58:22, Error: bowser [8003] - The master browser has received a server announcement from the computer AKY-CCB1B381A4F that believes that it is the master browser for the domain on transport NetBT_Tcpip_{90C7E2AA-A9AE-4207-95B0-24447E8CB857}. The master browser is stopping or an election is being forced..==== End Of File ===========================
×

Информация

Поставихме бисквитки на устройството ви за най-добро потребителско изживяване. Можете да промените настройките си за бисквитки, или в противен случай приемаме, че сте съгласни с нашите условия за ползване.