Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Възможно ли е да съм жертва на зловреден софтуер?

Featured Replies

  • Автор

Eto такива проблеми прави Аваст! и немога да го подкарам никак :

http://prikachi.com/images.php?files/1169455O.jpg

http://prikachi.com/images.php?files/1169457X.jpg

  • Автор

Под сейф мод стартирах ЕСЕТ и не откри нищо, но дори и така Аваст! не стартира ! Да неби да се е объркало нещо след КомбоФикс ? Немога да намеря лог файла на ЕСЕТ от последното сканиране, в неговата папка го няма (стои си предпоследното, което съм публикувал) !

  • Автор

Malwarebytes' Anti-Malware 1.41

Версия на базата от данни: 3188

Windows 5.1.2600 Service Pack 3

11/18/2009 1:54:10 AM

mbam-log-2009-11-18 (01-54-10).txt

Тип сканиране: Пълно сканиране (A:\|C:\|D:\|E:\|)

Сканирани обекти: 141850

Изминало време: 20 minute(s), 33 second(s)

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 0

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 0

Заразени процеси в паметта:

(Не бяха открити заплахи)

Заразени модули в паметта:

(Не бяха открити заплахи)

Заразени ключове в регистратурата:

(Не бяха открити заплахи)

Заразени стойности в регистратурата:

(Не бяха открити заплахи)

Заразени информационни обекти в регистратурата:

(Не бяха открити заплахи)

Заразени папки:

(Не бяха открити заплахи)

Заразени файлове:

(Не бяха открити заплахи)

  • Автор

Ето ги лог. файловете на ОТЛ, но не станаха както пишете за 10-15 мин., а за няма и 1-2 мин. казвам го ако има значение .(1.OTL; 2.EXTRAS)

1.OTL :

OTL logfile created on: 11/18/2009 3:03:52 PM - Run 1

OTL by OldTimer - Version 3.1.6.0 Folder = C:\Documents and Settings\Venci\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.23 Mb Total Physical Memory | 545.89 Mb Available Physical Memory | 56.91% Memory free

2.26 Gb Paging File | 1.81 Gb Available in Paging File | 79.93% Paging File free

Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19.07 Gb Total Space | 11.64 Gb Free Space | 61.00% Space Free | Partition Type: NTFS

Drive D: | 129.97 Gb Total Space | 99.42 Gb Free Space | 76.49% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: MYHOMEEE-6K294O

Current User Name: Venci

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/11/17 22:01:41 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

PRC - [2009/10/19 15:50:14 | 00,832,296 | ---- | M] (Opera Software) -- C:\Program Files\Opera-2\opera.exe

PRC - [2009/10/02 09:59:08 | 01,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe

PRC - [2009/10/02 09:59:08 | 01,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe

PRC - [2009/09/15 12:56:48 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe

PRC - [2009/09/15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe

PRC - [2009/09/15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

PRC - [2009/09/15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

PRC - [2009/09/15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

PRC - [2009/06/10 07:28:50 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe

PRC - [2008/04/14 02:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe

PRC - [2008/04/14 02:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2006/12/02 22:30:30 | 00,438,272 | ---- | M] (Lorenzi Davide (hexagora.com)) -- C:\Program Files\PerfMon3x\PerfMon.exe

PRC - [2006/10/09 16:32:10 | 00,020,480 | ---- | M] () -- C:\WINDOWS\CameraFixer.exe

PRC - [2006/09/19 08:07:28 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2006/09/19 08:07:28 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2006/04/17 09:34:42 | 16,143,872 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe

PRC - [2005/01/28 22:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe

========== Modules (SafeList) ==========

MOD - [2009/11/17 22:01:41 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

MOD - [2009/09/15 12:55:49 | 00,139,264 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll

MOD - [2008/04/14 02:12:51 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

MOD - [2008/04/14 02:11:53 | 00,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll

========== Win32 Services (SafeList) ==========

SRV - [2009/10/02 09:59:08 | 01,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free)

SRV - [2009/09/15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)

SRV - [2009/09/15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)

SRV - [2009/09/15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)

SRV - [2009/09/15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)

SRV - [2009/06/10 07:28:50 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)

SRV - [2009/04/28 09:06:06 | 01,195,008 | ---- | M] (Agnitum Ltd.) -- C:\Program Files\Agnitum\Outpost Firewall\acs.exe -- (acssrv)

SRV - [2008/04/14 02:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll -- (helpsvc)

SRV - [2005/01/28 22:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf)

SRV - [2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

========== Driver Services (SafeList) ==========

DRV - [2009/10/19 18:56:22 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)

DRV - [2009/09/15 12:56:14 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2009/09/15 12:55:30 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)

DRV - [2009/09/15 12:55:19 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2009/09/15 12:54:30 | 00,052,368 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2009/09/15 12:54:21 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2009/09/15 12:53:24 | 00,027,408 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2009/09/15 12:40:44 | 00,201,504 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)

DRV - [2009/06/10 05:03:00 | 08,087,712 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)

DRV - [2009/04/06 10:37:12 | 00,704,384 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\drivers\SandBox.sys -- (SandBox)

DRV - [2009/02/18 16:30:56 | 00,031,128 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\drivers\afw.sys -- (afw)

DRV - [2009/02/10 15:15:42 | 00,257,432 | ---- | M] (Agnitum Ltd.) -- C:\WINDOWS\system32\drivers\afwcore.sys -- (afwcore)

DRV - [2008/04/13 20:45:29 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)

DRV - [2008/04/13 18:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)

DRV - [2008/04/13 18:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)

DRV - [2007/03/27 17:19:36 | 10,252,544 | ---- | M] (Sonix Co. Ltd.) -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3)

DRV - [2006/05/10 20:27:00 | 00,036,864 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)

DRV - [2006/04/17 10:31:26 | 04,262,912 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService)

DRV - [2005/07/29 11:11:04 | 00,012,928 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)

DRV - [2005/07/29 11:11:02 | 00,034,048 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)

DRV - [2001/08/23 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

IE - HKU\S-1-5-21-842925246-1532298954-725345543-1003\S-1-5-21-842925246-1532298954-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5

FF - HKLM\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/11/17 15:55:11 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/11/17 15:55:11 | 00,000,000 | ---D | M]

[2009/07/11 16:07:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Mozilla\Extensions

[2009/07/11 16:07:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009/07/11 16:07:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Mozilla\Firefox\Profiles\n5zx7pvv.default\extensions

[2009/07/11 16:07:20 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2009/11/17 15:55:06 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009/11/17 15:55:06 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll

[2009/11/17 15:55:06 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll

[2009/11/17 15:55:08 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll

[2003/07/14 21:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL

[2009/06/24 14:31:54 | 00,001,083 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\911bg.xml

[2009/06/24 14:31:54 | 00,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml

[2009/06/24 14:31:54 | 00,002,442 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\diribg.xml

[2009/06/24 14:31:54 | 00,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml

[2009/06/24 14:31:54 | 00,001,515 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pe-bg.xml

[2009/06/24 14:31:54 | 00,001,857 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\portalbgdict.xml

[2009/06/24 14:31:54 | 00,001,220 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-bg.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.

O3 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe ()

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()

O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)

O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()

O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()

O4 - HKU\S-1-5-21-842925246-1532298954-725345543-1003..\Run: [PerfMon] C:\Program Files\PerfMon3x\PerfMon.exe (Lorenzi Davide (hexagora.com))

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1244737704576 (WUWebControl Class)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009/06/12 02:49:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - File not found

O35 - comfile [open] -- "%1" %* File not found

O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/11/18 14:56:40 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Venci\Recent

[2009/11/17 22:01:41 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

[2009/11/17 11:19:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

[2009/11/15 16:14:23 | 00,000,000 | RHSD | C] -- C:\cmdcons

[2009/11/15 16:11:24 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2009/11/15 16:11:24 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2009/11/15 16:11:24 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2009/11/15 16:11:24 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2009/11/15 16:10:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2009/11/15 16:10:10 | 00,000,000 | ---D | C] -- C:\Tool

[2009/11/15 15:20:00 | 00,000,000 | ---D | C] -- C:\Qoobox

[2009/11/15 09:48:33 | 00,000,000 | ---D | C] -- C:\Program Files\ESET

[2009/11/14 22:34:29 | 00,000,000 | ---D | C] -- C:\HJT

[2009/11/14 17:50:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Venci\Application Data\vlc

[2009/11/02 11:49:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun

[2009/10/25 15:08:46 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy

[2009/10/24 16:22:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Venci\Desktop\narachnik po kachestvoto

[2009/10/20 16:02:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Venci\My Documents\GomPlayer

[2009/10/19 19:05:43 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mdimon.dll

[2009/10/19 19:04:42 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET

[2009/10/19 19:04:36 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync

[2009/10/19 19:04:00 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER

[2009/10/19 19:03:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW

[2009/10/19 19:03:27 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office

[2009/07/12 14:54:12 | 00,147,456 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll

[2009/07/12 14:54:12 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll

[2009/07/12 14:54:12 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/11/18 14:56:27 | 04,194,304 | -H-- | M] () -- C:\Documents and Settings\Venci\NTUSER.DAT

[2009/11/18 11:19:37 | 00,108,544 | ---- | M] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/11/18 11:17:38 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2009/11/18 10:31:39 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/11/18 10:31:28 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/11/18 10:31:24 | 00,039,326 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml

[2009/11/18 10:31:16 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/11/18 02:07:01 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Venci\ntuser.ini

[2009/11/18 02:06:45 | 03,766,208 | -H-- | M] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\IconCache.db

[2009/11/17 22:01:41 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

[2009/11/17 19:43:00 | 00,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2009/11/17 16:02:18 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk

[2009/11/17 16:01:14 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/11/17 12:17:04 | 00,189,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009/11/16 23:19:25 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini

[2009/11/16 18:55:12 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2009/11/15 16:14:33 | 00,000,281 | RHS- | M] () -- C:\boot.ini

[2009/11/14 17:48:20 | 00,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk

[2009/11/14 01:47:57 | 00,260,608 | ---- | M] () -- C:\WINDOWS\PEV.exe

[2009/10/28 20:40:14 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\Venci\Desktop\rezume.doc

[2009/10/28 17:42:41 | 00,000,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk

[2009/10/27 11:21:09 | 00,718,496 | ---- | M] () -- C:\Documents and Settings\Venci\My Documents\openSUSE-11.1-GNOME-LiveCD-i686.iso

[2009/10/25 15:10:28 | 00,000,406 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol

[2009/10/25 07:39:39 | 00,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009/10/25 07:39:39 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2009/10/25 07:39:39 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2009/10/25 06:11:34 | 00,077,312 | ---- | M] () -- C:\WINDOWS\MBR.exe

[2009/10/22 19:41:49 | 00,581,120 | ---- | M] () -- C:\Documents and Settings\Venci\Desktop\Технически университет Габрово.doc

[2009/10/22 16:52:16 | 00,022,016 | ---- | M] () -- C:\Documents and Settings\Venci\Desktop\Задание.doc

[2009/10/21 06:08:54 | 03,598,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll

[2009/10/21 06:08:54 | 03,598,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll

[2009/10/19 19:08:06 | 00,042,944 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT

[2009/10/19 19:05:56 | 00,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI

[2009/10/19 19:05:24 | 00,000,812 | ---- | M] () -- C:\WINDOWS\win.ini

[2009/10/19 18:56:22 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/11/17 16:02:18 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk

[2009/11/17 16:01:14 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/11/15 16:14:32 | 00,000,211 | ---- | C] () -- C:\Boot.bak

[2009/11/15 16:14:25 | 00,260,272 | ---- | C] () -- C:\cmldr

[2009/11/15 16:11:24 | 00,260,608 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2009/11/15 16:11:24 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2009/11/15 16:11:24 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2009/11/15 16:11:24 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2009/11/15 16:11:24 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2009/11/14 17:48:20 | 00,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk

[2009/10/28 19:51:03 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\Venci\Desktop\rezume.doc

[2009/10/27 11:21:09 | 00,718,496 | ---- | C] () -- C:\Documents and Settings\Venci\My Documents\openSUSE-11.1-GNOME-LiveCD-i686.iso

[2009/10/25 15:10:27 | 00,000,406 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol

[2009/10/22 16:41:00 | 00,022,016 | ---- | C] () -- C:\Documents and Settings\Venci\Desktop\Задание.doc

[2009/10/21 17:32:47 | 00,581,120 | ---- | C] () -- C:\Documents and Settings\Venci\Desktop\Технически университет Габрово.doc

[2009/10/19 19:08:06 | 00,042,944 | ---- | C] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT

[2009/10/19 19:05:56 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009/10/19 18:56:22 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009/07/12 14:54:14 | 00,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini

[2009/06/14 03:12:26 | 00,108,544 | ---- | C] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/06/12 17:25:05 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2009/06/12 05:52:53 | 00,013,104 | ---- | C] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2009/06/12 03:09:59 | 03,766,208 | -H-- | C] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\IconCache.db

[2009/06/12 03:08:02 | 00,004,925 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini

[2009/06/12 03:08:01 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

[2009/06/12 02:55:57 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Venci\Application Data\desktop.ini

[2009/06/11 19:38:10 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

[2009/06/10 07:29:34 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll

[2009/06/10 07:29:34 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll

[2009/06/10 07:29:34 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll

[2009/06/10 07:29:32 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll

[2005/10/10 15:49:00 | 00,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll

[2005/10/10 15:49:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll

[2003/01/07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

[2001/08/23 14:00:00 | 00,000,812 | ---- | C] () -- C:\WINDOWS\win.ini

[2001/08/23 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

========== LOP Check ==========

[2009/09/03 11:28:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agnitum

[2009/06/18 08:33:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo

[2009/06/29 16:45:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\12Voip

[2009/06/18 08:33:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Ashampoo

[2009/09/03 11:25:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\CheckPoint

[2009/06/24 20:00:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Foxit

[2009/07/19 12:00:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\JustVoip

[2009/10/16 12:11:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Opera

[2009/06/24 20:49:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Runiter

[2009/11/18 10:59:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\uTorrent

[2001/08/23 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini

[2009/11/18 10:31:28 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

2.EXTRAS :

OTL Extras logfile created on: 11/18/2009 3:03:52 PM - Run 1

OTL by OldTimer - Version 3.1.6.0 Folder = C:\Documents and Settings\Venci\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.23 Mb Total Physical Memory | 545.89 Mb Available Physical Memory | 56.91% Memory free

2.26 Gb Paging File | 1.81 Gb Available in Paging File | 79.93% Paging File free

Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19.07 Gb Total Space | 11.64 Gb Free Space | 61.00% Space Free | Partition Type: NTFS

Drive D: | 129.97 Gb Total Space | 99.42 Gb Free Space | 76.49% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: MYHOMEEE-6K294O

Current User Name: Venci

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.chm [@ = chm.file] -- "%SYSTEMROOT%\hh.exe" %1

.html [@ = Opera.HTML] -- C:\Program Files\Opera-2\Opera.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %* File not found

chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 File not found

cmdfile [open] -- "%1" %* File not found

comfile [open] -- "%1" %* File not found

exefile [open] -- "%1" %* File not found

htmlfile [edit] -- Reg Error: Key error.

htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Program Files\Opera-2\opera.exe" (Opera Software)

piffile [open] -- "%1" %* File not found

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1" File not found

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S File not found

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe" = C:\Program Files\JustVoip.com\JustVoip\JustVoip.exe:*:Enabled:JustVoip -- (JustVoip)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{4B296228-DF7C-43EA-8DED-76027355B219}" = Opera 10.01

"{63E949F6-03BC-5C40-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT.Policy (x86) WinSXS MSM

"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003

"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{ADA45687-0976-4EF0-A062-EDEE1366CFCA}" = Bulgarian (Phonetic)

"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1

"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC CAM-168

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"9E140F48C9836B9B78539C08FB2B17146BDB3F65" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0)

"AC3Filter" = AC3Filter (remove only)

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Agnitum Outpost Firewall_is1" = Outpost Firewall 2009

"Ashampoo Burning Studio 8_is1" = Ashampoo Burning Studio 8.02

"Ashampoo WinOptimizer 4_is1" = Ashampoo WinOptimizer 4.51

"a-squared Free_is1" = a-squared Free 4.5

"avast!" = avast! Antivirus

"CCleaner" = CCleaner (remove only)

"ESET Online Scanner" = ESET Online Scanner v3

"Foxit Reader" = Foxit Reader

"GOM Player" = GOM Player

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"JustVoip_is1" = JustVoip

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)

"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"NVIDIA Drivers" = NVIDIA Drivers

"Performance Monitor 3.x_is1" = Performance Monitor 3.x

"Smart Math Calculator_is1" = Smart Math Calculator 2.1

"VLC media player" = VLC media player 1.0.3

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format Runtime

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinRAR archiver" = WinRAR archiver

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-842925246-1532298954-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]

Error - 11/3/2009 6:48:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:49:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:50:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:51:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:52:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:53:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:54:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/3/2009 6:55:18 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

D:\Download\bgb_diamond_kitty.wmv failed, 00000084.

Error - 11/17/2009 8:50:49 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

http://ftp.belnet.be/packages/slackware/slackware-11.0-iso/slackware-11.0-install-d1.iso

failed, 00000084.

Error - 11/17/2009 8:51:54 AM | Computer Name = MYHOMEEE-6K294O | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

http://ftp.lip6.fr/pub/linux/distributions/slackware/slackware-11.0-iso/slackware-11.0-install-d1.iso

failed, 00000084.

[ Application Events ]

Error - 8/16/2009 6:43:29 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Hang | ID = 1002

Description = Hanging application ashDisp.exe, version 4.8.1335.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 8/16/2009 6:44:05 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Hang | ID = 1002

Description = Hanging application ashDisp.exe, version 4.8.1335.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 8/16/2009 6:44:11 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Hang | ID = 1002

Description = Hanging application ashDisp.exe, version 4.8.1335.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 8/16/2009 6:44:41 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Hang | ID = 1002

Description = Hanging application ashDisp.exe, version 4.8.1335.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 8/16/2009 6:44:41 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Hang | ID = 1002

Description = Hanging application ashDisp.exe, version 4.8.1335.0, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 8/25/2009 2:40:42 PM | Computer Name = MYHOMEEE-6K294O | Source = Application Error | ID = 1000

Description = Faulting application opera.exe, version 10.0.1699.0, faulting module

wmvcore.dll, version 10.0.0.4066, fault address 0x000ce7d3.

Error - 8/30/2009 10:43:15 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x042e1cd8.

Error - 9/6/2009 5:03:03 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x036d1cd8.

Error - 9/6/2009 5:03:26 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Error | ID = 1001

Description = Fault bucket 318575181.

Error - 9/7/2009 10:16:33 AM | Computer Name = MYHOMEEE-6K294O | Source = Application Error | ID = 1000

Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting

module unknown, version 0.0.0.0, fault address 0x032e1cd8.

[ System Events ]

Error - 11/17/2009 9:59:55 AM | Computer Name = MYHOMEEE-6K294O | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

Aavmker4 AFD AmdK8 aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SandBox Tcpip

Error - 11/17/2009 10:01:16 AM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service netman with

arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 11/17/2009 10:01:21 AM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service wuauserv with

arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 11/17/2009 12:21:29 PM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 11/17/2009 12:23:38 PM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 11/17/2009 12:24:59 PM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 11/17/2009 12:25:34 PM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 11/17/2009 12:26:09 PM | Computer Name = MYHOMEEE-6K294O | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

Aavmker4 AmdK8 aswSP Fips SandBox

Error - 11/17/2009 1:00:32 PM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service StiSvc with

arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 11/17/2009 1:01:40 PM | Computer Name = MYHOMEEE-6K294O | Source = DCOM | ID = 10005

Description = DCOM got error "%1084" attempting to start the service EventSystem

with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

< End of report >

Редактирано от slav.bg (преглед на промените)

Стъпка 1:

Изтеглете SREng от тук и го запишете на вашия десктоп.

  • Разархивирайте sreng2.zip на вашия десктоп и ще се появи папка, наречена sreng2
  • Отворете папката sreng2 и кликнете два пъти върху SREngLdr.exe, за да стартирате програмата
  • От панела в ляво, изберете System Repair
  • Кликнете на File Association
  • Сложете отметки пред всички редове, чиито статус е Error
  • Накрая изберете Repair

SystemRepair_FileAssocs.gif

Стъпка 2:

  • Стартирайте OTL.exe
  • Под Custom Scans/Fixes поставете следния скрипт:

:OTL

O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.

O3 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-842925246-1532298954-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (*) - File not found


:files

C:\WINDOWS\system32\drivers\klif.sys


:Commands

[purity]

[emptytemp]

[Reboot]

  • След това, кликнете върху бутона Run Fix
  • Търпеливо изчакайте, докато програмата приключи своята работа. След, като нейната работа приключи, компютърът Ви ще се рестартира.

След рестартирането на компютъра, стартирайте отново OTL.exe и кликнете върху бутона Quick Scan. Накрая ще бъде генериран лог файл, който е необходимо да копирате и публикувате в следващия Ви коментар в тази тема.

Добавете и информация за това как се държи системата, след всички тези опити за коригиране на проблема.

  • Автор

сЛЕД Боот-а веднага след рестарта от OTL излезна следния лог.

All processes killed

========== OTL ==========

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ not found.

Registry value HKEY_USERS\S-1-5-21-842925246-1532298954-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}\ not found.

Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-21-842925246-1532298954-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.

Registry key HKEY_USERS\S-1-5-21-842925246-1532298954-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:* deleted successfully.

========== FILES ==========

C:\WINDOWS\system32\drivers\klif.sys moved successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

User: Venci

->Temp folder emptied: 1088322 bytes

->Temporary Internet Files folder emptied: 32902 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 42951541 bytes

->Opera cache emptied: 1766741 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 1200001 bytes

%systemroot%\System32 .tmp files removed: 2577 bytes

Windows Temp folder emptied: 49635 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 57931 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 45.00 mb

OTL by OldTimer - Version 3.1.6.0 log created on 11182009_162139

Files\Folders moved on Reboot...

File\Folder C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!

C:\WINDOWS\temp\Perflib_Perfdata_718.dat moved successfully.

Registry entries deleted on Reboot...

След това направих бързо сканиране с ОТЛ и излезна следния лог.

OTL logfile created on: 11/18/2009 4:25:03 PM - Run 2

OTL by OldTimer - Version 3.1.6.0 Folder = C:\Documents and Settings\Venci\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.23 Mb Total Physical Memory | 586.79 Mb Available Physical Memory | 61.17% Memory free

2.26 Gb Paging File | 1.92 Gb Available in Paging File | 85.15% Paging File free

Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19.07 Gb Total Space | 11.67 Gb Free Space | 61.17% Space Free | Partition Type: NTFS

Drive D: | 129.97 Gb Total Space | 99.42 Gb Free Space | 76.49% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: MYHOMEEE-6K294O

Current User Name: Venci

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 14 Days

Output = Standard

Quick Scan

========== Processes (SafeList) ==========

PRC - [2009/11/17 22:01:41 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

PRC - [2009/10/02 09:59:08 | 01,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe

PRC - [2009/10/02 09:59:08 | 01,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe

PRC - [2009/09/15 12:56:48 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe

PRC - [2009/09/15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe

PRC - [2009/09/15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

PRC - [2009/09/15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

PRC - [2009/09/15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

PRC - [2009/06/10 07:28:50 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe

PRC - [2008/04/14 02:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe

PRC - [2008/04/14 02:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2006/12/02 22:30:30 | 00,438,272 | ---- | M] (Lorenzi Davide (hexagora.com)) -- C:\Program Files\PerfMon3x\PerfMon.exe

PRC - [2006/10/09 16:32:10 | 00,020,480 | ---- | M] () -- C:\WINDOWS\CameraFixer.exe

PRC - [2006/09/19 08:07:28 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2006/09/19 08:07:28 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2006/04/17 09:34:42 | 16,143,872 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe

PRC - [2005/01/28 22:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe

========== Modules (SafeList) ==========

MOD - [2009/11/17 22:01:41 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

MOD - [2009/09/15 12:55:49 | 00,139,264 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll

MOD - [2008/04/14 02:12:51 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

MOD - [2008/04/14 02:11:53 | 00,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll

========== Win32 Services (SafeList) ==========

SRV - [2009/10/02 09:59:08 | 01,858,144 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free)

SRV - [2009/09/15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)

SRV - [2009/09/15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)

SRV - [2009/09/15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)

SRV - [2009/09/15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)

SRV - [2009/06/10 07:28:50 | 00,168,004 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)

SRV - [2009/04/28 09:06:06 | 01,195,008 | ---- | M] (Agnitum Ltd.) -- C:\Program Files\Agnitum\Outpost Firewall\acs.exe -- (acssrv)

SRV - [2008/04/14 02:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll -- (helpsvc)

SRV - [2005/01/28 22:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf)

SRV - [2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5

FF - HKLM\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/11/17 15:55:11 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/11/17 15:55:11 | 00,000,000 | ---D | M]

[2009/07/11 16:07:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Mozilla\Extensions

[2009/07/11 16:07:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009/07/11 16:07:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Mozilla\Firefox\Profiles\n5zx7pvv.default\extensions

[2009/07/11 16:07:20 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2009/11/17 15:55:06 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009/11/17 15:55:06 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll

[2009/11/17 15:55:06 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll

[2009/11/17 15:55:08 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll

[2003/07/14 21:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL

[2009/06/24 14:31:54 | 00,001,083 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\911bg.xml

[2009/06/24 14:31:54 | 00,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml

[2009/06/24 14:31:54 | 00,002,442 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\diribg.xml

[2009/06/24 14:31:54 | 00,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml

[2009/06/24 14:31:54 | 00,001,515 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pe-bg.xml

[2009/06/24 14:31:54 | 00,001,857 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\portalbgdict.xml

[2009/06/24 14:31:54 | 00,001,220 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-bg.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe ()

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()

O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)

O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()

O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()

O4 - HKCU..\Run: [PerfMon] C:\Program Files\PerfMon3x\PerfMon.exe (Lorenzi Davide (hexagora.com))

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1244737704576 (WUWebControl Class)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O24 - Desktop Components:0 (My Current Home Page) - About:Home

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009/06/12 02:49:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O35 - comfile [open] -- "%1" %* File not found

O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 14 Days ==========

[2009/11/18 16:21:39 | 00,000,000 | ---D | C] -- C:\_OTL

[2009/11/18 16:17:49 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Venci\Recent

[2009/11/18 16:12:37 | 02,224,128 | ---- | C] (Smallfrogs Studio) -- C:\Documents and Settings\Venci\Desktop\SREngLdr.EXE

[2009/11/18 16:12:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Venci\Desktop\Upload

[2009/11/17 22:01:41 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

[2009/11/17 11:19:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

[2009/11/15 16:14:23 | 00,000,000 | RHSD | C] -- C:\cmdcons

[2009/11/15 16:11:24 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2009/11/15 16:11:24 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2009/11/15 16:11:24 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2009/11/15 16:11:24 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2009/11/15 16:10:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2009/11/15 16:10:10 | 00,000,000 | ---D | C] -- C:\Tool

[2009/11/15 15:20:00 | 00,000,000 | ---D | C] -- C:\Qoobox

[2009/11/15 09:48:33 | 00,000,000 | ---D | C] -- C:\Program Files\ESET

[2009/11/14 22:34:29 | 00,000,000 | ---D | C] -- C:\HJT

[2009/11/14 17:50:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Venci\Application Data\vlc

[2009/07/12 14:54:12 | 00,147,456 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll

[2009/07/12 14:54:12 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll

[2009/07/12 14:54:12 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll

========== Files - Modified Within 14 Days ==========

[2009/11/18 16:23:13 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/11/18 16:22:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/11/18 16:22:58 | 00,039,326 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml

[2009/11/18 16:22:49 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/11/18 16:22:06 | 04,194,304 | -H-- | M] () -- C:\Documents and Settings\Venci\NTUSER.DAT

[2009/11/18 16:22:06 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Venci\ntuser.ini

[2009/11/18 16:11:41 | 00,868,323 | ---- | M] () -- C:\Documents and Settings\Venci\Desktop\sreng2.zip

[2009/11/18 11:19:37 | 00,108,544 | ---- | M] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/11/18 11:17:38 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2009/11/18 02:06:45 | 03,766,208 | -H-- | M] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\IconCache.db

[2009/11/17 22:01:41 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Venci\Desktop\OTL.exe

[2009/11/17 19:43:00 | 00,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2009/11/17 16:02:18 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk

[2009/11/17 16:01:14 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/11/17 12:17:04 | 00,189,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009/11/16 23:19:25 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini

[2009/11/16 18:55:12 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2009/11/15 16:14:33 | 00,000,281 | RHS- | M] () -- C:\boot.ini

[2009/11/14 17:48:20 | 00,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk

[2009/11/14 01:47:57 | 00,260,608 | ---- | M] () -- C:\WINDOWS\PEV.exe

========== Files Created - No Company Name ==========

[2009/11/18 16:12:37 | 00,035,952 | ---- | C] () -- C:\Documents and Settings\Venci\Desktop\releasenotes_cht.htm

[2009/11/18 16:12:37 | 00,032,326 | ---- | C] () -- C:\Documents and Settings\Venci\Desktop\releasenotes_chs.htm

[2009/11/18 16:11:37 | 00,868,323 | ---- | C] () -- C:\Documents and Settings\Venci\Desktop\sreng2.zip

[2009/11/17 16:02:18 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk

[2009/11/17 16:01:14 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/11/15 16:14:32 | 00,000,211 | ---- | C] () -- C:\Boot.bak

[2009/11/15 16:14:25 | 00,260,272 | ---- | C] () -- C:\cmldr

[2009/11/15 16:11:24 | 00,260,608 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2009/11/15 16:11:24 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2009/11/15 16:11:24 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2009/11/15 16:11:24 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2009/11/15 16:11:24 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2009/11/14 17:48:20 | 00,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk

[2009/10/19 19:05:56 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009/10/19 18:56:22 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009/07/12 14:54:14 | 00,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini

[2009/06/14 03:12:26 | 00,108,544 | ---- | C] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/06/12 17:25:05 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2009/06/12 05:52:53 | 00,013,104 | ---- | C] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2009/06/12 03:09:59 | 03,766,208 | -H-- | C] () -- C:\Documents and Settings\Venci\Local Settings\Application Data\IconCache.db

[2009/06/12 03:08:02 | 00,004,925 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini

[2009/06/12 03:08:01 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

[2009/06/12 02:55:57 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Venci\Application Data\desktop.ini

[2009/06/11 19:38:10 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini

[2009/06/10 07:29:34 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll

[2009/06/10 07:29:34 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll

[2009/06/10 07:29:34 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll

[2009/06/10 07:29:32 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll

[2005/10/10 15:49:00 | 00,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll

[2005/10/10 15:49:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll

[2003/01/07 14:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

[2001/08/23 14:00:00 | 00,000,812 | ---- | C] () -- C:\WINDOWS\win.ini

[2001/08/23 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

========== LOP Check ==========

[2009/09/03 11:28:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agnitum

[2009/06/18 08:33:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo

[2009/06/29 16:45:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\12Voip

[2009/06/18 08:33:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Ashampoo

[2009/09/03 11:25:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\CheckPoint

[2009/06/24 20:00:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Foxit

[2009/07/19 12:00:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\JustVoip

[2009/10/16 12:11:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Opera

[2009/06/24 20:49:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\Runiter

[2009/11/18 10:59:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Venci\Application Data\uTorrent

[2001/08/23 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini

[2009/11/18 16:22:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

  • Автор

Ами единствено товаренето на процесора спря иначе пак си има цикличен данлоуд от 20-30 кбита на около 50 секунди. Явно Аваста сме го омазали и не се стартира, не мога и да го поправя ! Явно ще трябва да го деинсталирам и наново да го инсталирам.

Опитайте следното:

Стъпка 1:

Деинсталирайте Avast и Outpost Firewall.

Стъпка 2:

Оптимизирайте вашия Windows:

http://www.eset.bg/forum/viewtopic.php?f=6&t=549&sid=93df6d8b7ebbdb5816a14d627cc3f516

Стъпка 3:

Изтеглете, инсталирайте, ръчно обновете и сканирайте с Avast:

http://www.kaldata.com/comments.php?id=49885&catid=1&highlight=avast

Накрая ми пишете как е сега.

  • Автор

Здравейте, след преинсталация и ръчно обновяване на АВАСТ! той поиска да се извърши предстартова проверка! По време на проверката беше открит заразен файл, прилагам лог. файла :

11/19/2009 12:51

Proveriava vsichki lokalni diskove

File C:\WINDOWS\$NtServicePackUninstall$\wextract.exe e zarazen ot Win32:Trojan-gen, Premesten v Kletkata

Broi provereni papki: 2762

Broi provereni failove: 39723

Broi zarazeni failove: 1

Има ли някакво подобрение?

Изтеглете AVZ Antiviral Toolkit и го запазете на вашия десктоп.

  • Разархивирайте avz4.zip отново на вашия десктоп
  • Влезте в разархивираната папка avz4 и стартирайте avz.exe
  • Стартирайте автоматичното обновление на програмата, кликайки върху бутона avz-update-button.png, който се намира в дясната част на прозореца. Накрая изберете Start.

Бележка: Ако получите съобщение за грешка, изберете алтернативен източник на обновления, последван от кликане на бутона Start

  • Накрая затворете програмата и я стартирайте отново.
  • Изберете File -> Standard scripts и сложете отметка пред Healing/Quarantine and Advanced System Analysis

avz-standardscripts-healing.png

  • Изберете Execute selected scripts, при което ще бъде извършено автоматично сканиране, лекуване и повторно сканиране на системата.
  • Ще бъде генериран лог файл, който ще се намира в директорията на AVZ в папката LOG и ще е с име virusinfo_syscure.zip
  • Най-вероятно ще бъде необходимо рестартиране на системата.

След рестартирането:

  • Стартирайте avz.exe
  • Изберете File -> Standard scripts и сложете отметка пред Изберете File -> Standard scripts и сложете отметка пред

avz-standardscripts.png

  • Изберете Execute selected scripts, при което ще бъде извършено автоматично сканиране, лекуване и повторно сканиране на системата.
  • Ще бъде генериран лог файл, който ще се намира в директорията на AVZ в папката LOG и ще е с име virusinfo_syscheck.zip

Накрая, прикрепете към вашия коментар: virusinfo_syscure.zip и virusinfo_syscheck.zip

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.