Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Зарезена ОС "your system has been hacked" [РЕШЕН]

Featured Replies

Изтеглете DDS от тук.

Запазете го на десктопа и го стартирайте.

  • Когато DDS приключи успешно анализа на системата ще отвори два лог файла.


  1. DDS.txt
  2. Attach.txt

  • Запазете ги на десктопа и след това ги публикувай в следващия си пост.

  • Отговори 65
  • Прегледи 9,8k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Няма проблеми. Дано да се получи само с sfc /scannow или само с поправителна преинсталация, а не НОВА преинсталация. Успех и ни дръжте в течение. Поздрави

  • Да и аз забелязах, в лога на DDS, че System File Protection се е опитал да възстанови някои пачнати версии на файловете които не минават проверката за цифров подпис на Microsoft. (изключвам uxtheme.dl

  • Здравей Ще анализирам това нещо: http://www.download.bg/index.php?cls=forum&mtd=thread&t=130287&q=%F5%E0%EA%20%E7%E0%20%F1%EA%E0%E9%EF Мисля, че от него идва надписа "Your S

  • Автор

Тези логове са от чистият акаунт :biggrin: Ако трябва ще направя логове и от "заразеният"/"счупения" акаунт :biggrin:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-11-24.02)

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 01.1.2006 г. 03:03:37

System Uptime: 26.11.2009 г. 16:20:45 (0 hours ago)

Motherboard: | | P4M800CE-8237

Processor: Intel® Celeron® CPU 2.26GHz | Socket 775 | 2271/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 10 GiB total, 3,964 GiB free.

D: is FIXED (NTFS) - 65 GiB total, 21,277 GiB free.

E: is CDROM ()

J: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 26.11.2009 г. 11:36:47 - System Checkpoint

RP2: 26.11.2009 г. 11:47:04 - Avira AntiVir Personal - 26.11.2009 г. 11:46

RP3: 26.11.2009 г. 12:05:35 - Avira AntiVir Personal - 26.11.2009 г. 12:05

RP4: 26.11.2009 г. 16:29:23 - Installed WinXP Manager

RP5: 26.11.2009 г. 16:31:08 - Installed WinXP Manager

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Adobe Shockwave Player

ArcSoft VideoImpression 2

Army Men RTS

Avira AntiVir Personal - Free Antivirus

BitComet 0.81

BSPlayer

BulgarianPhonetic XP by G. Atanasov

DTS+AC3 Filter

GOM Player

Hamachi 1.0.2.2

HijackThis 2.0.2

Hotfix for Windows XP (KB976098-v2)

ICCup Launcher

Malwarebytes' Anti-Malware

Mario Forever 4.0

Microsoft .NET Framework 1.1

Microsoft .NET Framework 2.0

Microsoft Base Smart Card Cryptographic Service Provider Package

Microsoft Compression Client Pack 1.0 for Windows XP

Microsoft Office Professional Edition 2003

Microsoft User-Mode Driver Framework Feature Pack 1.0

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft XML Parser

Mozilla Firefox (3.5.5)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Nero 8 Micro v8.3.2.1

neroxml

Norton Security Scan

Picasa 3

Platform

Realtek AC'97 Audio

Security Update for Microsoft .NET Framework 2.0 (KB917283)

Security Update for Windows Internet Explorer 7 (KB938127-v2)

Security Update for Windows Internet Explorer 7 (KB953838)

Security Update for Windows Internet Explorer 7 (KB958215)

Security Update for Windows Internet Explorer 7 (KB960714)

Security Update for Windows Internet Explorer 7 (KB974455)

Security Update for Windows Internet Explorer 8 (KB971961)

Security Update for Windows Internet Explorer 8 (KB974455)

Security Update for Windows Media Player (KB954155)

Security Update for Windows Media Player (KB968816)

Security Update for Windows Media Player (KB973540)

Security Update for Windows Media Player 11 (KB954154)

Security Update for Windows XP (KB923561)

Security Update for Windows XP (KB923789)

Security Update for Windows XP (KB941569)

Security Update for Windows XP (KB952004)

Security Update for Windows XP (KB953839)

Security Update for Windows XP (KB956391)

Security Update for Windows XP (KB956572)

Security Update for Windows XP (KB956744)

Security Update for Windows XP (KB956844)

Security Update for Windows XP (KB958687)

Security Update for Windows XP (KB958869)

Security Update for Windows XP (KB959426)

Security Update for Windows XP (KB960225)

Security Update for Windows XP (KB960803)

Security Update for Windows XP (KB960859)

Security Update for Windows XP (KB961371-v2)

Security Update for Windows XP (KB961501)

Security Update for Windows XP (KB969059)

Security Update for Windows XP (KB969947)

Security Update for Windows XP (KB970238)

Security Update for Windows XP (KB971486)

Security Update for Windows XP (KB971557)

Security Update for Windows XP (KB971633)

Security Update for Windows XP (KB971657)

Security Update for Windows XP (KB971961)

Security Update for Windows XP (KB973354)

Security Update for Windows XP (KB973507)

Security Update for Windows XP (KB973525)

Security Update for Windows XP (KB973869)

Security Update for Windows XP (KB974112)

Security Update for Windows XP (KB974571)

Security Update for Windows XP (KB975025)

Security Update for Windows XP (KB975467)

Skype™ 3.8

Trust R-Series Mouse

Trust WB-1400T Webcam

Update for Microsoft Windows (KB971513)

Update for Windows Internet Explorer 8 (KB975364)

Update for Windows Internet Explorer 8 (KB976749)

Update for Windows XP (KB898461)

Update for Windows XP (KB967715)

Update for Windows XP (KB968389)

Update for Windows XP (KB973687)

Update for Windows XP (KB973815)

VCRedistSetup

VIA Platform Device Manager

VIA Rhine-Family Fast Ethernet Adapter

VIA/S3G Display Driver

VNC Free Edition 4.1.2

WebFldrs XP

Windows Genuine Advantage Notifications (KB905474)

Windows Genuine Advantage Validation Tool (KB892130)

Windows Internet Explorer 8

Windows Media Format 11 runtime

Windows Media Player 11

Windows PowerShell 1.0

Windows PowerShell 1.0 MUI pack

WinRAR archiver

WinXP Manager

==== Event Viewer Messages From Past Week ========

26.11.2009 г. 12:02:56, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

26.11.2009 г. 12:01:09, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

26.11.2009 г. 12:01:04, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

26.11.2009 г. 11:59:32, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

26.11.2009 г. 11:59:19, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

26.11.2009 г. 11:57:01, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BIOS Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

26.11.2009 г. 11:57:01, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.

26.11.2009 г. 11:57:01, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.

26.11.2009 г. 11:57:01, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

26.11.2009 г. 11:57:01, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

26.11.2009 г. 11:56:13, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

26.11.2009 г. 11:56:04, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

26.11.2009 г. 11:56:02, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

26.11.2009 г. 11:56:01, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

26.11.2009 г. 04:42:22, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 840db558, parameter3 840db6cc, parameter4 805fb07e.

26.11.2009 г. 04:13:59, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 04:13:59, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 04:13:59, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 04:13:59, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 03:24:55, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 03:24:55, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 03:24:55, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 03:24:55, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 02:55:24, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 02:55:24, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 02:55:24, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 02:55:24, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 02:07:25, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\cmd.exe could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.

26.11.2009 г. 02:02:32, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 02:02:32, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 01:40:34, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

26.11.2009 г. 01:40:34, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 18:17:27, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 18:17:27, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 18:17:27, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 18:17:27, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 18:15:13, error: stealth_2 [4] -

25.11.2009 г. 18:15:13, error: stealth_2 [11] -

25.11.2009 г. 03:26:48, error: Service Control Manager [7001] - The AVG Free8 E-mail Scanner service depends on the AVG Free8 WatchDog service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

25.11.2009 г. 03:25:13, error: stealth_2 [4] -

25.11.2009 г. 03:25:13, error: stealth_2 [11] -

25.11.2009 г. 00:54:14, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:51:54, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:44:03, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the AVG Free8 WatchDog service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

25.11.2009 г. 00:44:03, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

25.11.2009 г. 00:36:51, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:36:50, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:35:09, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.

25.11.2009 г. 00:34:07, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\windows\system32\uxtheme.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.

25.11.2009 г. 00:34:07, information: Windows File Protection [64004] - The protected system file c:\windows\system32\uxtheme.dll could not be restored to its original, valid version. The file version of the bad file is 6.0.2900.5512 The specific error code is 0x800b0100 [No signature was present in the subject. ].

25.11.2009 г. 00:33:51, information: Windows File Protection [64004] - The protected system file c:\windows\system32\sfc_os.dll could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x800b0100 [No signature was present in the subject. ].

25.11.2009 г. 00:33:48, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\windows\system32\sfc_os.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.

25.11.2009 г. 00:32:11, information: Windows File Protection [64016] - Windows File Protection file scan was started.

25.11.2009 г. 00:32:01, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.

25.11.2009 г. 00:30:29, information: Windows File Protection [64004] - The protected system file c:\windows\system32\uxtheme.dll could not be restored to its original, valid version. The file version of the bad file is 6.0.2900.5512 The specific error code is 0x800b0100 [No signature was present in the subject. ].

25.11.2009 г. 00:30:28, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\windows\system32\uxtheme.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.

25.11.2009 г. 00:30:10, information: Windows File Protection [64005] - The protected system file c:\windows\system32\sfc_os.dll was not restored to its original, valid version because the Windows File Protection restoration process was cancelled by user interaction, user name is Administrator. The file version of the bad file is 5.1.2600.5512.

25.11.2009 г. 00:25:24, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\windows\system32\sfc_os.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.

25.11.2009 г. 00:23:43, information: Windows File Protection [64016] - Windows File Protection file scan was started.

25.11.2009 г. 00:23:11, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

25.11.2009 г. 00:23:05, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 00:23:01, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 00:22:55, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

25.11.2009 г. 00:21:06, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:21:04, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:18:39, error: Service Control Manager [7034] - The Keyboard And Mouse Communication Service service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 00:18:33, error: Service Control Manager [7034] - The STI Simulator service terminated unexpectedly. It has done this 1 time(s).

25.11.2009 г. 00:15:56, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

25.11.2009 г. 00:15:56, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 19:35:05, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 19:35:02, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 18:18:24, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 18:03:24, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 18:03:21, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 18:00:07, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 18:00:04, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 17:55:01, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 17:54:58, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 13:21:46, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 13:21:40, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 01:23:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

23.11.2009 г. 01:23:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

22.11.2009 г. 14:30:07, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

22.11.2009 г. 14:30:05, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

22.11.2009 г. 01:55:22, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

22.11.2009 г. 01:55:22, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

20.11.2009 г. 13:21:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

20.11.2009 г. 13:21:25, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

19.11.2009 г. 13:31:52, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

19.11.2009 г. 13:31:29, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

19.11.2009 г. 13:31:21, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

19.11.2009 г. 04:09:43, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

19.11.2009 г. 04:09:43, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

==== End Of File ===========================

DDS (Ver_09-11-24.02) - NTFSx86

Run by t at 16:33:27,32 on 26.11.2009 Ј.

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.446.162 [GMT 4,5:30]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

D:\Program Files\Trust\Trust R-Series Mouse\KMWDSrv.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\msiexec.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\t\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.bg/

uInternet Connection Wizard,ShellNext = hxxp://www.avg.com/ww.special-uninstallation-feedback-appf?lic=OEZSRUUtVkRDU1QtSkRORFotQkFCUEEtUzhFQkctUDdLSzQ"&"inst=NzktMTI4NTg2MTMwLVQxNy1YTCsx"&"prod=50"&"ver=8.5.420

BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [VTTimer] VTTimer.exe

mRun: [VTTrayp] VTtrayp.exe

mRun: [soundMan] SOUNDMAN.EXE

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259197504125

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\t\applic~1\mozilla\firefox\profiles\mfpbz7w6.default\

FF - plugin: c:\program files\picasa2\npPicasa2.dll

FF - plugin: c:\program files\picasa2\npPicasa3.dll

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-1-5 13696]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-11-26 108289]

R2 KMWDSERVICE;Keyboard And Mouse Communication Service;d:\program files\trust\trust r-series mouse\KMWDSrv.exe [2007-6-9 208896]

R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\drivers\RMSPPPOE.SYS [2009-1-5 31152]

S3 cpuz131;cpuz131;\??\c:\docume~1\neli\locals~1\temp\cpuz131\cpuz_x32.sys --> c:\docume~1\neli\locals~1\temp\cpuz131\cpuz_x32.sys [?]

S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.sys [2005-2-24 162176]

=============== Created Last 30 ================

2009-11-26 12:01:09 0 d-----w- c:\program files\Yamicsoft

2009-11-26 11:49:26 0 d-----w- c:\docume~1\t\applic~1\Malwarebytes

2009-11-26 11:49:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-11-26 11:49:16 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-11-26 11:49:16 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-11-26 11:49:16 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2009-11-26 07:36:37 0 d-----w- c:\program files\Avira

2009-11-26 07:36:37 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira

2009-11-26 01:04:41 0 d-sh--w- c:\documents and settings\t\IECompatCache

2009-11-26 01:04:20 0 d-sh--w- c:\documents and settings\t\PrivacIE

2009-11-26 01:03:08 0 d-sh--w- c:\documents and settings\t\IETldCache

2009-11-26 00:56:42 0 d-----w- c:\program files\MSXML 4.0

2009-11-26 00:54:33 92160 ------w- c:\windows\system32\dllcache\iecompat.dll

2009-11-26 00:54:13 0 d-----w- c:\windows\ie8updates

2009-11-26 00:53:56 12800 ------w- c:\windows\system32\dllcache\xpshims.dll

2009-11-26 00:53:55 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll

2009-11-26 00:52:28 0 dc-h--w- c:\windows\ie8

2009-11-26 00:45:34 0 d-----w- c:\windows\system32\URTTEMP

2009-11-26 00:44:55 1447424 ------w- c:\windows\system32\dllcache\msxml6.dll

2009-11-26 00:44:55 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll

2009-11-26 00:43:12 153088 ------w- c:\windows\system32\dllcache\triedit.dll

2009-11-26 00:42:31 1315328 ------w- c:\windows\system32\dllcache\msoe.dll

2009-11-26 00:42:27 128512 ------w- c:\windows\system32\dllcache\dhtmled.ocx

2009-11-26 00:39:21 0 d-----w- c:\windows\system32\PreInstall

2009-11-26 00:25:07 0 d-----w- c:\windows\system32\SoftwareDistribution

2009-11-25 23:40:19 0 d--h--w- c:\windows\PIF

2009-11-25 22:04:58 0 d-----w- c:\windows\system32\CatRoot2

2009-11-25 21:57:40 50620 ----a-w- c:\windows\system32\command.com

2009-11-25 21:57:40 389120 ----a-w- c:\windows\system32\dllcache\cmd.exe

2009-11-25 21:57:40 389120 ----a-w- c:\windows\system32\cmd.exe

2009-11-25 07:15:43 174 ----a-w- c:\windows\wininit.ini

2009-11-24 23:44:12 0 d--h--w- c:\windows\system32\GroupPolicy

2009-11-24 23:42:04 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2009-11-24 23:22:33 0 d-----w- c:\windows\pss

2009-11-24 22:55:13 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys

2009-11-24 22:55:13 96512 ------w- c:\windows\system32\drivers\atapi.sys

2009-11-24 22:54:29 0 d-sha-r- C:\cmdcons

2009-11-23 13:24:40 0 d-----w- c:\windows\system32\wbem\snmp

2009-11-23 13:24:39 0 d-----w- c:\windows\system32\xircom

2009-11-13 17:32:09 20 ----a-w- c:\windows\mafosav.INI

2009-11-13 16:29:37 0 d-----w- C:\Downloads

==================== Find3M ====================

2009-11-26 00:11:36 1614848 ----a-w- c:\windows\system32\dllcache\sfcfiles.dll

2009-11-26 00:11:36 1614848 ------w- c:\windows\system32\sfcfiles.dll

2009-10-22 09:19:04 5939712 ------w- c:\windows\system32\dllcache\mshtml.dll

2009-10-08 10:27:02 611328 ------w- c:\windows\system32\uiautomationcore.dll

2009-10-08 10:27:00 220160 ----a-w- c:\windows\system32\oleacc.dll

2009-10-08 10:27:00 220160 ------w- c:\windows\system32\dllcache\oleacc.dll

2009-10-08 10:26:56 20480 ----a-w- c:\windows\system32\oleaccrc.dll

2009-10-08 10:26:56 20480 ------w- c:\windows\system32\dllcache\oleaccrc.dll

2009-09-11 14:13:26 136704 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-11 14:13:26 136704 ------w- c:\windows\system32\dllcache\msv1_0.dll

2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-09-04 21:03:36 58880 ------w- c:\windows\system32\dllcache\msasn1.dll

2009-08-29 08:08:21 916480 ------w- c:\windows\system32\wininet.dll

2009-08-29 08:08:21 916480 ------w- c:\windows\system32\dllcache\wininet.dll

2009-08-29 08:08:21 1208832 ------w- c:\windows\system32\dllcache\urlmon.dll

2009-08-29 08:08:20 206848 ------w- c:\windows\system32\dllcache\occache.dll

2009-08-29 08:08:18 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll

2009-08-29 08:08:18 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll

2009-08-29 08:08:18 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll

2009-08-29 08:08:18 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll

2009-08-29 08:08:17 184320 ------w- c:\windows\system32\dllcache\iepeers.dll

2009-08-29 08:08:16 11069440 ------w- c:\windows\system32\dllcache\ieframe.dll

2009-08-29 08:08:13 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll

2009-08-29 07:36:24 78336 ------w- c:\windows\system32\ieencode.dll

2009-08-29 07:36:24 78336 ------w- c:\windows\system32\dllcache\ieencode.dll

2009-08-29 07:36:24 133120 ------w- c:\windows\system32\dllcache\extmgr.dll

2005-12-31 22:35:13 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012006010120060102\index.dat

============= FINISH: 16:34:08,71 ===============

Стига с този чист. Сега оправяме заразения акаунт. :biggrin:

Логовете и инструментите искам да се стартират вече оттам. :biggrin:

Колкото за Avira, проверете настройките на услугите.

Start => Run => Sevices.msc => Avira Antivir Guard => двукратен клик => натиснете => "Start" и от падащото меню на "Startup type" => сложете "Automatic"

Ако е пусната, значи просто самата икона на интерфейса не се отваря => и трябва да се добави този процес от папката на Avira в стартиращите обекти (avgnt.exe)

2hfkjcw.jpg

Стартирайте Registry Editor => Start => Run => regedit => намерете следния ключ =>

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

и направете в десния панел нова стойност New => String Value.

Стартирайте я и в полето Value name напишете avgnt, а в полето value data въведете стойността, която води до файла avgnt.exe

При мен изглежда така: "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min

При вас може би ще е така "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

6yd25g.jpg

  • Автор

ОК да правя ли логове(DDS) - да ги публикувам ли?

Reg fix-a не работи под заразения акаунт - "Error accessing the registry."

Winxp Manager vers.6.0.7 няма такава опция като тая която ми казахте да следвам :biggrin:

Сега започвам да работя по следващите стъпки, благодаря!

ОК да правя ли логове(DDS) - да ги публикувам ли?

Reg fix-a не работи под заразения акаунт - "Error accessing the registry."

Winxp Manager vers.6.0.7 няма такава опция като тая която ми казахте да следвам :biggrin:

Сега започвам да работя по следващите стъпки, благодаря!

Не, не правете нови логове.

Пробвайте да асоциирате *.reg файловете с regedit.

Десен бутон на reg файла, който изтеглихте преди малко => Open With => Browse => посочете файла в папка C:\Windows\regedit.exe => сложете отметка пред "Always use selected program to open this kind of file" => натиснете O.K.

След това пробвайте да стартирате файла отново.

Искам да деинсталирате всичко от Norton и AVG.

След това изтеглете и почистете след тях с тези неща:

Norton Security Scan

ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exe

AVG Free8

http://download.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe

Какво стана с AVIRA => в лога на DDS изцяло липсваше процеса на Avira Guard модула.

  • Автор
' date='26 ноември 2009 - 16:42 ' timestamp='1259246549' post='1567446']

Стига с този чист. Сега оправяме заразения акаунт. :biggrin:

Логовете и инструментите искам да се стартират вече оттам. :biggrin:

Колкото за Avira, проверете настройките на услугите.

Start => Run => Sevices.msc => Avira Antivir Guard => двукратен клик => натиснете => "Start" и от падащото меню на "Startup type" => сложете "Automatic"

Ако е пусната, значи просто самата икона на интерфейса не се отваря => и трябва да се добави този процес от папката на Avira в стартиращите обекти (avgnt.exe)

2hfkjcw.jpg

Стартирайте Registry Editor => Start => Run => regedit => намерете следния ключ =>

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

и направете в десния панел нова стойност New => String Value.

Стартирайте я и в полето Value name напишете avgnt, а в полето value data въведете стойността, която води до файла avgnt.exe

При мен изглежда така: "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min

При вас може би ще е така "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

6yd25g.jpg

1. Пишеше "Started" и "Automatic" - без да пипам и да променям каквото и да е :)

2. Този регистър си съществува и не съм правил и тука нищо - само проверка :D

avirra.th.jpg

' date='26 ноември 2009 - 17:13 ' timestamp='1259248388' post='1567466']

Не, не правете нови логове.

Пробвайте да асоциирате *.reg файловете с regedit.

Десен бутон на reg файла, който изтеглихте преди малко => Open With => Browse => посочете файла в папка C:\Windows\regedit.exe => сложете отметка пред "Always use selected program to open this kind of file" => натиснете O.K.

След това пробвайте да стартирате файла отново.

Искам да деинсталирате всичко от Norton и AVG.

След това изтеглете и почистете след тях с тези неща:

Norton Security Scan

ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exe

AVG Free8

http://download.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe

Какво стана с AVIRA => в лога на DDS изцяло липсваше процеса на Avira Guard модула.

Пак същата грешка за регистъра не става по никакъв начин :(

Сега ще ги изчиста тези остатъци от АВ софтуер :)

Редактирано от teodor192 (преглед на промените)

Значи акаунта е доста поразен...няма смисъл да се мъчим да го възстановяваме.

По-добре направете нов (ако в момента използвате вградения акаунт - Administrator в самия Windows).

А другия може да се изтрие. Ще трябва обаче да правите доста настройки по системата отначало.

Друг вариант е да се направи Repair Install на Windows като цяло, защото има доста проблеми с редица важни услуги в Event Viewer лог файла от DDS.

С REPAIR INSTALL-a, ще се възстановят файловете, които липсват или са повредени и ще се запазят поне повечето ви настройки и инсталирани програми. Да, сигурно някои програми ще се наложи да ги преинсталирате отново, но е трудно да се предскаже кои ще са те.

Заредете от диска с Windows XP, но не натискайте "R", а натиснете "Enter"

1101192207-8.gif

Там вече по-стандартната процедура натиснете "F8" за да се съгласите с лицензионното споразумение.

След като се появи това меню тук натиснете "R"

1101192215-9.gif

Продължете все едно правите стандартна преинсталация...

  • Автор

ОМГ, може ли да предложа и аз нещо и ако го удобрите ще го правя, ако ли не - Repair Install :biggrin:

Махам заразения акаунт правя един нов след това Sfc /scannow & check disk и съм в джаза? По този начин няма ли да поправя файловете и няма да имам нужда от реинстал на повечето софтуер.

ОМГ, може ли да предложа и аз нещо и ако го удобрите ще го правя, ако ли не - Repair Install :biggrin:

Махам заразения акаунт правя един нов след това Sfc /scannow & check disk и съм в джаза? По този начин няма ли да поправя файловете и няма да имам нужда от реинстал на повечето софтуер.

Само че, последния лог от DDS, бе именно от незаразения акаунт. И там не ми харесаха грешките в услугите.

И второ, за да работи коректно sfc /scannow се изискват някои условия:

http://www.kaldata.com/forums/index.php?showtopic=137543&view=findpost&p=1525847

Мпжете да пробвате, ако имате време. Нищо не губите. Винаги след това ако не стане може да се опита с Repair Install.

Лично аз в логовете не намирам индикация на зловреден софтуер, но май зловредния код е оставил доста поражения, защото опитахме доста неща.

Ако всичко работи коректно под новия акаунт, мисля, че системата е чистичка. Ако вече и там има някои "забрани" значи ще има нещо което мъти водата.

Аз обаче съм оптимистично настроен, защото досега всички инструменти стартираха под ADMIN акаунта. Другия едва скоро го направихме достъпен, но явно не е напълно.

  • Автор
' date='26 ноември 2009 - 17:34 ' timestamp='1259249675' post='1567487']

Само че, последния лог от DDS, бе именно от незаразения акаунт. И там не ми харесаха грешките в услугите.

И второ, за да работи коректно sfc /scannow се изискват някои условия:

http://www.kaldata.com/forums/index.php?showtopic=137543&view=findpost&p=1525847

Мпжете да пробвате, ако имате време. Нищо не губите. Винаги след това ако не стане може да се опита с Repair Install.

Лично аз в логовете не намирам индикация на зловреден софтуер, но май зловредния код е оставил доста поражения, защото опитахме доста неща.

Ако всичко работи коректно под новия акаунт, мисля, че системата е чистичка. Ако вече и там има някои "забрани" значи ще има нещо което мъти водата.

Аз обаче съм оптимистично настроен, защото досега всички инструменти стартираха под ADMIN акаунта. Другия едва скоро го направихме достъпен, но явно не е напълно.

Благодаря от сърце за помощта която ми указахте! :biggrin:

Ще пробвам както споменах и ако не стане така ще има Поправяне/Фреш инстал :biggrin:

Няма проблеми. Дано да се получи само с sfc /scannow или само с поправителна преинсталация, а не НОВА преинсталация.

Успех и ни дръжте в течение.

Поздрави ;)

  • Автор

Възстановяването премина горе-долу успешно, но имаше случаи в който искаше оригинално сд Xp sp3, за да възстанови *.dll файл при положение, че бях сложил точно това от което е инсталирана ОС( xp sp3 + повечето ъпдейти). След това му пуснах chkdsk (автоматично оправяне на на файловата система + проверка за бад сектори). Според мен с новият акаунт системата се държи нормално и не правих реинстал/фреш инстал ;)

@B-boy[styLe], благодаря много за помощта която получих!

Възстановяването премина горе-долу успешно, но имаше случаи в който искаше оригинално сд Xp sp3, за да възстанови *.dll файл при положение, че бях сложил точно това от което е инсталирана ОС( xp sp3 + повечето ъпдейти). След това му пуснах chkdsk (автоматично оправяне на на файловата система + проверка за бад сектори). Според мен с новият акаунт системата се държи нормално и не правих реинстал/фреш инстал ;)

@B-boy[styLe], благодаря много за помощта която получих!

Да и аз забелязах, в лога на DDS, че System File Protection се е опитал да възстанови някои пачнати версии на файловете които не минават проверката за цифров подпис на Microsoft. (изключвам uxtheme.dll, който трябва да се пачне за да се инсталират допълнителни теми за Windows).

Можете да пробвате да преинсталирате Service Pack 3 и да инсталирате всички критични актуализации.

За финал направете една оптимизация на машината:

http://www.kaldata.com/forums/index.php?showtopic=22755

Безопасно сърфиране и кажете на вашия приятел да не "цъка на всичко що види из нета". :clap:

Поздрави ! :clap:

  • Автор

Безопасно сърфиране и кажете на вашия приятел да не "цъка на всичко що види из нета". :black eye:

Поздрави ! :boxing8:

Задължително :lol6:

Здравей

Ще анализирам това нещо:

http://www.download.bg/index.php?cls=forum&mtd=thread&t=130287&q=%F5%E0%EA%20%E7%E0%20%F1%EA%E0%E9%EF

Мисля, че от него идва надписа "Your System Has Been Hacked"

Специално за да го сваля се набутах 2.40 :black eye:

Много нагли бат скриптове има и затова внимавайте какво стартирате.

Маркирам проблема като решен.

Защо не каза да ти го сваля ? ;)

Който иска нещо от http://www.download.bg/, да ми пише. Аз ще ви ги свалям.

A и аз го имам ехе-то , което прави мизерии. ;)

Редактирано от palavata_tanq (преглед на промените)

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.