Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

проблем със зареждане на windows

Featured Replies

  • Автор
' date='06 декември 2009 - 17:06 ' timestamp='1260111995' post='1574890']

1. Да направим една проверка с този инструмент. download100s.gif

Също така публикувайте и новия лог файл от MBAM.

Инсталаторите също трябва да се изтеглят наново (забравил съм да го спомена), защото именно те най-вероятно също са увредени. Така че изтеглете въпросните програми наново и тогава ги преинсталирайте.

2. Възможно е да е и заради драйверите...така че да пробваме първо с тяхното обновяване.

3. Трябва ни модела на видеокартата. По-добре направете един screenshot на информацията от GPU-Z и я публикувайте.

Ако неуспеем да го преборим е много вероятно да сте се заразили от новите и адски бъгави версии на тези файлови инфектори при които решението е само едно - пълен формат на всички дялове, преинсталация на чисто и изтегляне на всички необходими програми и и игри наново. И занапред използване на качествена и обновена антивирусна, Операционна Система с инсталирани всички налични кръпки, браузър различен от I.E. - най-добре Firefox с добавката NoScript или Opera, избягване на съмнителни сайтове и използване на безплатни програми без нуждата от пачване, кракване и т.н.

Malwarebytes' Anti-Malware 1.42

Версия на базата от данни: 3303

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

12/5/2009 6:31:27 PM

mbam-log-2009-12-05 (18-31-27).txt

Тип сканиране: Пълно сканиране (C:\|D:\|E:\|)

Сканирани обекти: 214335

Изминало време: 1 hour(s), 20 minute(s), 24 second(s)

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 8

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 0

Заразени процеси в паметта:

(Не бяха открити заплахи)

Заразени модули в паметта:

(Не бяха открити заплахи)

Заразени ключове в регистратурата:

HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Заразени стойности в регистратурата:

(Не бяха открити заплахи)

Заразени информационни обекти в регистратурата:

(Не бяха открити заплахи)

Заразени папки:

(Не бяха открити заплахи)

Заразени файлове:

(Не бяха открити заплахи)

  • Отговори 59
  • Прегледи 10,5k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Имате файлов инфектор - parite. Ако не е от най-бъгавите му версии ше се опитаме да оправим нещата. За всеки случай си пригответе инсталационен диск на Операционната Система. Изтеглете програмата

Ако ще правим нещо да го правим като хората. :speak:

Къде са останалите резултати. Имам чувството, че не изпълнявате всички инструкции от постовете...

  • Автор
' date='06 декември 2009 - 21:54 ' timestamp='1260129298' post='1575118']

Ако ще правим нещо да го правим като хората. :)

Къде са останалите резултати. Имам чувството, че не изпълнявате всички инструкции от постовете...

е извинявам се ама съм на работа.....другите неща преди утре няма как да ги пратя....а и как се правеше скриин,че все с програма съм правила преди,а сега нямам такава

е извинявам се ама съм на работа.....другите неща преди утре няма как да ги пратя....а и как се правеше скриин,че все с програма съм правила преди,а сега нямам такава

Няма проблеми.

А иначе не е необходимо да използвате програма за целта. Вижте тази тема:

http://www.kaldata.com/forums/index.php?showtopic=59060

Поздрави :yanim:

  • Автор
' date='07 декември 2009 - 02:20 ' timestamp='1260145214' post='1575248']

Няма проблеми.

А иначе не е необходимо да използвате програма за целта. Вижте тази тема:

http://www.kaldata.com/forums/index.php?showtopic=59060

Поздрави ;)

12/6/2009, 11:05:34 AM

Memory scanning started...

No virus body found in memory.

Memory scanning finished (30.2s).

----------

Files scanning started...

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\call256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\callmember256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat1024.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat16384.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat2048.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat4096.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat512.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chat8192.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmember256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg1024.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg16384.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg2048.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg32768.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg4096.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg512.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\chatmsg8192.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\contactgroup256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\index2.dat... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\profile32768.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\sms256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\transfer1024.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\transfer256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\transfer512.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\user1024.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\user16384.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\user256.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\user32768.dbb... file could not be scanned!

C:\Documents and Settings\Administrator\Application Data\Skype\sweet_gabs88\user4096.dbb... file could not be scanned!

C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpSfc.bin... file could not be scanned!

C:\WINDOWS\system32\CatRoot2\edb.log... file could not be scanned!

C:\WINDOWS\system32\CatRoot2\tmp.edb... file could not be scanned!

C:\WINDOWS\temp\TMP0000000BB3F59AE663F1F303... file could not be scanned!

No virus body found.

Files scanning finished (100953 files, 0 infected, 3512.2s).

Drives scanned: C: D:

----------

Колкото до скрииншота,като натисна тоя бутон нищо не става, а и програмата paint също не я намирам където е показано...а също така и няма никакви показатели който да излизат от Gpu-z , сигурен ли си че не искаш от другата програма там излизат доста неща

Редактирано от bg_fenka (преглед на промените)

Добре, да видим какво ще покаже другата програма.

Стартирайте Hwinfo32 => и отидете до Video Adapter и препишете информацията за => Video Card и Video Chipset.

  • Автор
' date='07 декември 2009 - 15:12 ' timestamp='1260191561' post='1575562']

Добре, да видим какво ще покаже другата програма.

Стартирайте Hwinfo32 => и отидете до Video Adapter и препишете информацията за => Video Card и Video Chipset.

video chipset : Via/S3 UniChrome Pro video memory :64 mbytes of SDRAM

video card : Via/S3 UniChrome Pro Integrated

video bus : AGP 8X

video ramdac:internal

video bios version:unknown

performance:processor clock:200,5 Mhz

А има ли някакъв начин да си видя примерно на 1 място кое колко памет ми заема,примерно песни еди колко си,програми еди колко си и т.н...или някоя друга програма за чистене подобна на Ccleaner щото тя почна да ми чисти съвсем малко памет и като гледам 4-5 клипчета и вече пак е пълна, а със сканирането й сканира известно време и се затваря.Това е след като я инсталирах на ново.Иначе от другите програми които инсталирах наново повечето са ок вече, но има и някой дето пак не са съвсем наред...и най-странното е че клипчета и песни от компа продължават да не се отварят,а уж иснталирах на ново плейъра.

Редактирано от bg_fenka (преглед на промените)

video chipset : Via/S3 UniChrome Pro video memory :64 mbytes of SDRAM

video card : Via/S3 UniChrome Pro Integrated

video bus : AGP 8X

video ramdac:internal

video bios version:unknown

performance:processor clock:200,5 Mhz

А има ли някакъв начин да си видя примерно на 1 място кое колко памет ми заема,примерно песни еди колко си,програми еди колко си и т.н...или някоя друга програма за чистене подобна на Ccleaner щото тя почна да ми чисти съвсем малко памет и като гледам 4-5 клипчета и вече пак е пълна, а със сканирането й сканира известно време и се затваря.Това е след като я инсталирах на ново.Иначе от другите програми които инсталирах наново повечето са ок вече, но има и някой дето пак не са съвсем наред...и най-странното е че клипчета и песни от компа продължават да не се отварят,а уж иснталирах на ново плейъра.

За тези интегрирани драйвери ще имам нужда от информация и за дъното:

От същата програма се придвижете до секцията "Motherboard" => и от полето вдясно препишете информацията за Motherboard Model и Motherboard Chipset.

Най-добре би било, ако разполагате с диск с драйвери за дъното, но ако компютъра е прекалено стар се съмнявам да имате такъв.

Да, има програма с която бихте могли да разгледате кое, колко място заема. Тази е доста удобна и безплатна за целта =>

http://www.jam-software.com/treesize_free/TreeSizeSetup.exe

Вие сте инсталирала плеъра наново, но изтеглихте ли го наново от интернет или използвахте този, който вече е бил свален на компютъра ви.

Поради сериозността на заразата бих искал да направим още няколко проверки:

Kaspersky Online Scanner

Изтеглете Kaspersky Online Scanner (Работи само с Firefox и Internet Explorer):

1) Нужно е да приемете лицензното споразумение, за да извършите сканиране на вашата система, така че изберете Accept

2) Проявете търпение, докато Kaspersky Online Scanner се изтегли, инсталира и обнови дефинициите си.

3) Когато процеса приключи успешно, изберете Settings и махнете отметката на Uncheck Mail databases

4) Под Scan, кликнете на My Computer

5) С това се дава старт на сканирането.

6) Когато сканирането завърши, кликнете на View scan report, а след това на бутона Save Report As... . Запазете файла на вашия десктоп. Накрая публикувайте лога в следващия Ви коментар в тази тема.

Eset Online Scanner

1) Изтеглете: ESET Online Scanner

2) Стартирайте esetsmartinstaller_enu.exe

3) Сложете отметка на YES, I accept the Terms of Use и изберете Start

4) Скенерът ще започне да изтегля компонентите, които са му необходими.

5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:


  • Remove found threats
  • Scan archives
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology

И накрая изберете Start

6) Скенерът ще започне да изтегля последните дефиниции.

7) След, като сканирането завърши изберете Finish.

8) Отидете в:

C:\Program Files\ESET\ESET Online Scanner

Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си пост тук.

Изтеглете OTL (от OldTimer) и го запазете на вашия десктоп.

Кликнете два пъти върху OTL.exe, за да стартирате програмата.

Сложете отметки преди следните неща:


  • Scan all users
  • Lop check
  • Purity check

Под секцията Extra Registry, изберете Use SafeList

Кликнете на Run Scan и изчакайте да завърши сканирането. (може да отнеме 10-15 минути)

Когато завърши, публикувайте следните два лог файла:

  • OTL.txt (намира се на вашия десктоп)
  • Extras.txt (ще Ви се отвори автоматично)

  • Автор
' date='08 декември 2009 - 02:42 ' timestamp='1260232927' post='1576028']

За тези интегрирани драйвери ще имам нужда от информация и за дъното:

От същата програма се придвижете до секцията "Motherboard" => и от полето вдясно препишете информацията за Motherboard Model и Motherboard Chipset.

Най-добре би било, ако разполагате с диск с драйвери за дъното, но ако компютъра е прекалено стар се съмнявам да имате такъв.

Да, има програма с която бихте могли да разгледате кое, колко място заема. Тази е доста удобна и безплатна за целта =>

http://www.jam-software.com/treesize_free/TreeSizeSetup.exe

Вие сте инсталирала плеъра наново, но изтеглихте ли го наново от интернет или използвахте този, който вече е бил свален на компютъра ви.

Поради сериозността на заразата бих искал да направим още няколко проверки:

Kaspersky Online Scanner

Изтеглете Kaspersky Online Scanner (Работи само с Firefox и Internet Explorer):

1) Нужно е да приемете лицензното споразумение, за да извършите сканиране на вашата система, така че изберете Accept

2) Проявете търпение, докато Kaspersky Online Scanner се изтегли, инсталира и обнови дефинициите си.

3) Когато процеса приключи успешно, изберете Settings и махнете отметката на Uncheck Mail databases

4) Под Scan, кликнете на My Computer

5) С това се дава старт на сканирането.

6) Когато сканирането завърши, кликнете на View scan report, а след това на бутона Save Report As... . Запазете файла на вашия десктоп. Накрая публикувайте лога в следващия Ви коментар в тази тема.

Eset Online Scanner

1) Изтеглете: ESET Online Scanner

2) Стартирайте esetsmartinstaller_enu.exe

3) Сложете отметка на YES, I accept the Terms of Use и изберете Start

4) Скенерът ще започне да изтегля компонентите, които са му необходими.

5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:


  • Remove found threats
  • Scan archives
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology

И накрая изберете Start

6) Скенерът ще започне да изтегля последните дефиниции.

7) След, като сканирането завърши изберете Finish.

8) Отидете в:

C:\Program Files\ESET\ESET Online Scanner

Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си пост тук.

Изтеглете OTL (от OldTimer) и го запазете на вашия десктоп.

Кликнете два пъти върху OTL.exe, за да стартирате програмата.

Сложете отметки преди следните неща:


  • Scan all users
  • Lop check
  • Purity check

Под секцията Extra Registry, изберете Use SafeList

Кликнете на Run Scan и изчакайте да завърши сканирането. (може да отнеме 10-15 минути)

Когато завърши, публикувайте следните два лог файла:

  • OTL.txt (намира се на вашия десктоп)
  • Extras.txt (ще Ви се отвори автоматично)

Съжалявам че толко време не писах ,но покрай 8-и декември си взех малко по-голяма почивчица и нямах достъп до "болния" комп. Касперски 3-4 пъти ми забива на около 30-40 %, от другите неща ето логовете :

ESETSmartInstaller@High as downloader log:

all ok

ESETSmartInstaller@High as downloader log:

all ok

esets_scanner_update returned -1 esets_gle=53251

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=ea4374d602df4042957eb5567e510bc5

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2009-12-12 04:56:17

# local_time=2009-12-12 06:56:17 (+0200, FLE Standard Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=768 16777215 100 0 0 0 0 0

# compatibility_mode=1536 16777215 100 0 0 0 0 0

# compatibility_mode=2048 16777215 100 0 85096416 85096416 0 0

# compatibility_mode=5891 16776533 100 100 0 15240334 0 0

# compatibility_mode=8192 67108863 100 0 25434 25434 0 0

# scanned=101201

# found=1

# cleaned=1

# scan_time=9756

D:\Program Files\BitComet\Downloads\UEFA Champions League 2006-2007-Razor19111\UEFA_CL0607.iso probably a variant of Win32/Agent trojan (deleted) 00000000000000000000000000000000 C

OTL logfile created on: 12/12/2009 5:34:35 PM - Run 1

OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Administrator\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000402 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.48 Mb Total Physical Memory | 162.94 Mb Available Physical Memory | 36.49% Memory free

1.23 Gb Paging File | 0.19 Gb Available in Paging File | 15.40% Paging File free

Paging file location(s): c:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19.53 Gb Total Space | 2.88 Gb Free Space | 14.72% Space Free | Partition Type: NTFS

Drive D: | 54.99 Gb Total Space | 29.71 Gb Free Space | 54.04% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: HRISTO-28670FBF

Current User Name: Administrator

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/12/12 17:33:29 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

PRC - [2009/09/13 18:52:50 | 01,048,392 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe

PRC - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe

PRC - [2008/10/26 02:18:36 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2008/09/30 13:06:50 | 00,485,208 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

PRC - [2008/08/11 16:46:50 | 21,741,864 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe

PRC - [2008/08/11 16:46:50 | 00,076,744 | R--- | M] (Skype Technologies) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe

PRC - [2008/04/14 05:42:42 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe

PRC - [2008/04/14 05:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/08/13 17:43:56 | 00,622,080 | -HS- | M] (Microsoft Corporation) -- C:\Program Files\internet explorer\iexplore.exe

PRC - [2006/06/19 12:37:30 | 00,262,144 | ---- | M] () -- C:\WINDOWS\tsnp2std.exe

PRC - [2006/04/11 10:06:30 | 00,353,754 | R--- | M] (S3 Graphics Co., Ltd.) -- C:\WINDOWS\system32\VTTrayp.exe

PRC - [2006/02/24 11:58:14 | 00,868,352 | R--- | M] (Sony Ericsson Mobile Communications AB) -- D:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

PRC - [2005/10/26 16:17:24 | 00,159,744 | R--- | M] (Sony Ericsson Mobile Communications AB) -- D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

PRC - [2005/08/10 07:54:34 | 00,385,024 | R--- | M] (Teleca Software Solutions) -- C:\Program Files\Common Files\Teleca Shared\Generic.exe

PRC - [2005/06/08 16:45:04 | 00,278,528 | ---- | M] (Teleca Software Solutions AB) -- C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

PRC - [2005/03/07 21:33:28 | 00,230,868 | ---- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\VTTimer.exe

PRC - [2003/02/25 07:52:00 | 00,303,104 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\LEXBCES.EXE

PRC - [2003/02/25 07:50:00 | 00,174,592 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\LEXPPS.EXE

PRC - [2002/05/19 09:24:00 | 00,095,232 | ---- | M] () -- D:\Program Files\Datecs\FlexType 2K\FType2K.exe

========== Modules (SafeList) ==========

MOD - [2009/12/12 17:33:29 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

MOD - [2002/04/23 00:17:06 | 00,045,056 | ---- | M] () -- C:\WINDOWS\system32\newdll.dll

========== Win32 Services (SafeList) ==========

SRV - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)

SRV - [2008/10/26 02:18:36 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)

SRV - [2008/04/14 05:41:56 | 00,028,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\irmon.dll -- (Irmon)

SRV - [2008/03/13 14:36:32 | 00,102,704 | ---- | M] () [On_Demand | Stopped] -- D:\Program Files\Hide My IP 2008\SecureSrv.exe -- (SecureSrv)

SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

SRV - [2005/04/03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)

SRV - [2003/02/25 07:52:00 | 00,303,104 | ---- | M] (Lexmark International, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LEXBCES.EXE -- (LexBceS)

========== Driver Services (SafeList) ==========

DRV - [2009/07/16 15:22:10 | 00,019,064 | ---- | M] (REALiX) [Kernel | System | Running] -- D:\Program Files\HWiNFO32\HWiNFO32.SYS -- (HWiNFO32)

DRV - [2009/06/18 18:48:04 | 00,142,832 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)

DRV - [2009/04/28 22:20:06 | 00,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)

DRV - [2009/01/02 23:04:11 | 00,002,368 | ---- | M] (AntiCracking) [Kernel | Auto | Running] -- C:\WINDOWS\system32\SVKP.sys -- (SVKP)

DRV - [2008/04/13 22:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)

DRV - [2007/02/09 18:21:08 | 00,008,413 | ---- | M] (RealNetworks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mcstrm.sys -- (MCSTRM)

DRV - [2006/11/15 16:08:08 | 00,103,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cam1690.sys -- (CAM1690)

DRV - [2006/04/13 07:04:38 | 00,252,416 | R--- | M] (Copyright © VIA/S3 Graphics Co, Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vtmini.sys -- (viagfx)

DRV - [2005/11/22 08:44:22 | 03,804,416 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)

DRV - [2005/06/03 13:47:06 | 00,079,488 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750obex.sys -- (k750obex)

DRV - [2005/06/03 13:47:04 | 00,081,728 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mgmt.sys -- (k750mgmt)

DRV - [2005/06/03 13:47:00 | 00,089,872 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mdm.sys -- (k750mdm)

DRV - [2005/06/03 13:46:58 | 00,006,576 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mdfl.sys -- (k750mdfl)

DRV - [2005/06/03 13:46:52 | 00,055,216 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)

DRV - [2004/08/04 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)

DRV - [2004/04/15 04:57:20 | 00,042,496 | R--- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fetnd5b.sys -- (FETNDISB)

DRV - [2004/03/08 11:55:50 | 00,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)

DRV - [2003/06/16 05:05:40 | 00,369,920 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio) VIA AC'97 Audio Controller (WDM)

DRV - [2003/05/27 16:45:06 | 00,003,351 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vsp.sys -- (Vsp)

DRV - [2001/09/17 13:40:12 | 00,091,792 | R--- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97) VIA Audio Driver (WDM)

DRV - [2001/08/17 13:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-448539723-2077806209-682003330-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search

IE - HKU\S-1-5-21-448539723-2077806209-682003330-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7

IE - HKU\S-1-5-21-448539723-2077806209-682003330-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.lulin-net.com/

IE - HKU\S-1-5-21-448539723-2077806209-682003330-500\S-1-5-21-448539723-2077806209-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)

O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

O3 - HKU\S-1-5-21-448539723-2077806209-682003330-500\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.

O3 - HKU\S-1-5-21-448539723-2077806209-682003330-500\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)

O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe (Apple Inc.)

O4 - HKLM..\Run: [sony Ericsson PC Suite] D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe (Sony Ericsson Mobile Communications AB)

O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe ()

O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)

O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)

O4 - HKU\S-1-5-21-448539723-2077806209-682003330-500..\Run: [skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk = D:\Program Files\Datecs\FlexType 2K\FType2K.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-448539723-2077806209-682003330-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-448539723-2077806209-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-448539723-2077806209-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-448539723-2077806209-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\S-1-5-21-448539723-2077806209-682003330-500_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: Е&кспортирай в Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_10.dll (Sun Microsystems, Inc.)

O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)

O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 77.78.128.66 77.78.128.67

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: GinaDLL - (ginamsi.dll) - C:\WINDOWS\System32\ginamsi.dll ()

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006/12/23 13:33:30 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/12 17:33:20 | 00,538,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2009/12/12 17:26:24 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent

[2009/12/11 23:13:17 | 00,000,000 | ---D | C] -- C:\Program Files\Veetle

[2009/12/08 14:38:30 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\eSellerate

[2009/12/08 14:38:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\docXConverter logs

[2009/12/08 14:19:55 | 00,000,000 | ---D | C] -- C:\Program Files\MSECache

[2009/12/08 13:51:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sony Ericsson

[2009/12/08 13:51:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Teleca

[2009/12/07 12:25:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\JAM Software

[2009/12/05 16:24:58 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2009/12/05 16:24:51 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009/12/05 15:58:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Winamp

[2009/12/05 05:40:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch

[2009/12/05 05:33:57 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6r.dll

[2009/12/05 05:33:57 | 00,000,000 | ---D | C] -- C:\Program Files\Messenger

[2009/12/05 05:33:56 | 01,306,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll

[2009/12/05 05:33:56 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpcdll.dll

[2009/12/05 05:33:43 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irbus.sys

[2009/12/05 05:33:43 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll

[2009/12/05 05:33:43 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsdupd.exe

[2009/12/05 05:33:42 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll

[2009/12/05 05:33:38 | 00,377,984 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvaa.dll

[2009/12/05 05:33:38 | 00,229,376 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2cqag.dll

[2009/12/05 05:33:38 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aaclient.dll

[2009/12/05 05:33:37 | 01,888,992 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3duag.dll

[2009/12/05 05:33:37 | 00,870,784 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3d1ag.dll

[2009/12/05 05:33:37 | 00,516,768 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ativvaxx.dll

[2009/12/05 05:33:37 | 00,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\azroles.dll

[2009/12/05 05:33:37 | 00,201,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvag.dll

[2009/12/05 05:33:37 | 00,032,768 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativtmxx.dll

[2009/12/05 05:33:37 | 00,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativmvxx.ax

[2009/12/05 05:33:37 | 00,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativdaxx.ax

[2009/12/05 05:33:36 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx4.dll

[2009/12/05 05:33:35 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3cfg.dll

[2009/12/05 05:33:35 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3msm.dll

[2009/12/05 05:33:35 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dhcpqec.dll

[2009/12/05 05:33:35 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3gpclnt.dll

[2009/12/05 05:33:35 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsroam.dll

[2009/12/05 05:33:35 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3api.dll

[2009/12/05 05:33:35 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3dlg.dll

[2009/12/05 05:33:34 | 00,650,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3ui.dll

[2009/12/05 05:33:34 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapp3hst.dll

[2009/12/05 05:33:34 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapphost.dll

[2009/12/05 05:33:34 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappcfg.dll

[2009/12/05 05:33:34 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappgnui.dll

[2009/12/05 05:33:34 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapolqec.dll

[2009/12/05 05:33:33 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapqec.dll

[2009/12/05 05:33:33 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappprxy.dll

[2009/12/05 05:33:32 | 00,032,285 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\hsfcisp2.dll

[2009/12/05 05:33:31 | 00,338,432 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\ir41_qcx.dll

[2009/12/05 05:33:31 | 00,120,320 | ---- | C] (Intel Corporation.) -- C:\WINDOWS\System32\ir41_qc.dll

[2009/12/05 05:33:30 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdiultn.dll

[2009/12/05 05:33:30 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbhc.dll

[2009/12/05 05:33:29 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\l2gpstore.dll

[2009/12/05 05:33:29 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpash.dll

[2009/12/05 05:33:29 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnepr.dll

[2009/12/05 05:33:28 | 00,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcex.dll

[2009/12/05 05:33:28 | 00,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\microsoft.managementconsole.dll

[2009/12/05 05:33:28 | 00,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcfxcommon.dll

[2009/12/05 05:33:28 | 00,086,016 | ---- | C] (Conexant) -- C:\WINDOWS\System32\mdmxsdk.dll

[2009/12/05 05:33:28 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcperf.exe

[2009/12/05 05:33:27 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mssha.dll

[2009/12/05 05:33:27 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msshavmsg.dll

[2009/12/05 05:33:26 | 04,274,816 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nv4_disp.dll

[2009/12/05 05:33:26 | 01,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\mtxparhd.dll

[2009/12/05 05:33:26 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napmontr.dll

[2009/12/05 05:33:26 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napstat.exe

[2009/12/05 05:33:26 | 00,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\onex.dll

[2009/12/05 05:33:26 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napipsec.dll

[2009/12/05 05:33:24 | 00,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\s3gnb.dll

[2009/12/05 05:33:24 | 00,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rhttpaa.dll

[2009/12/05 05:33:24 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qagent.dll

[2009/12/05 05:33:24 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qutil.dll

[2009/12/05 05:33:24 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qcliprov.dll

[2009/12/05 05:33:24 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasqec.dll

[2009/12/05 05:33:23 | 00,286,792 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slextspk.dll

[2009/12/05 05:33:23 | 00,188,508 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slgen.dll

[2009/12/05 05:33:23 | 00,073,832 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slcoinst.dll

[2009/12/05 05:33:23 | 00,073,796 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slserv.exe

[2009/12/05 05:33:23 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slrundll.exe

[2009/12/05 05:33:23 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe

[2009/12/05 05:33:22 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsgqec.dll

[2009/12/05 05:33:21 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlanapi.dll

[2009/12/05 05:33:19 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\slrundll.exe

[2009/12/05 05:33:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting

[2009/12/05 05:33:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas

[2009/12/05 05:33:13 | 00,000,000 | ---D | C] -- C:\Program Files\msn

[2009/12/05 05:33:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en

[2009/12/05 05:33:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits

[2009/12/05 05:28:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles

[2009/12/05 05:25:35 | 00,056,623 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1btxx.sys

[2009/12/05 05:25:35 | 00,004,255 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv01nt5.dll

[2009/12/05 05:25:35 | 00,003,967 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv02nt5.dll

[2009/12/05 05:25:35 | 00,003,775 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv11nt5.dll

[2009/12/05 05:25:35 | 00,003,711 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv09nt5.dll

[2009/12/05 05:25:35 | 00,003,647 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv07nt5.dll

[2009/12/05 05:25:35 | 00,003,615 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv05nt5.dll

[2009/12/05 05:25:35 | 00,003,135 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv08nt5.dll

[2009/12/05 05:25:34 | 00,701,440 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtag.sys

[2009/12/05 05:25:34 | 00,327,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtaa.sys

[2009/12/05 05:25:34 | 00,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinrvxx.sys

[2009/12/05 05:25:34 | 00,063,663 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1rvxx.sys

[2009/12/05 05:25:34 | 00,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinbtxx.sys

[2009/12/05 05:25:34 | 00,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinraxx.sys

[2009/12/05 05:25:34 | 00,036,463 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1tuxx.sys

[2009/12/05 05:25:34 | 00,034,735 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xsxx.sys

[2009/12/05 05:25:34 | 00,030,671 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1raxx.sys

[2009/12/05 05:25:34 | 00,029,455 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xbxx.sys

[2009/12/05 05:25:34 | 00,026,367 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1snxx.sys

[2009/12/05 05:25:34 | 00,021,343 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1ttxx.sys

[2009/12/05 05:25:34 | 00,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinpdxx.sys

[2009/12/05 05:25:34 | 00,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinmdxx.sys

[2009/12/05 05:25:34 | 00,012,047 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1pdxx.sys

[2009/12/05 05:25:34 | 00,011,615 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1mdxx.sys

[2009/12/05 05:25:33 | 00,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atintuxx.sys

[2009/12/05 05:25:33 | 00,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxsxx.sys

[2009/12/05 05:25:33 | 00,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxbxx.sys

[2009/12/05 05:25:33 | 00,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinsnxx.sys

[2009/12/05 05:25:33 | 00,025,471 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv04nt5.dll

[2009/12/05 05:25:33 | 00,021,183 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv01nt5.dll

[2009/12/05 05:25:33 | 00,017,279 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv10nt5.dll

[2009/12/05 05:25:33 | 00,014,143 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv06nt5.dll

[2009/12/05 05:25:33 | 00,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinttxx.sys

[2009/12/05 05:25:33 | 00,011,359 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv02nt5.dll

[2009/12/05 05:25:32 | 00,144,384 | ---- | C] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\System32\drivers\hdaudbus.sys

[2009/12/05 05:25:32 | 00,036,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthprint.sys

[2009/12/05 05:25:32 | 00,015,423 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\ch7xxnt5.dll

[2009/12/05 05:25:31 | 01,041,536 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfdpsp2.sys

[2009/12/05 05:25:31 | 00,685,056 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfcxts2.sys

[2009/12/05 05:25:31 | 00,220,032 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfbs2s2.sys

[2009/12/05 05:25:31 | 00,011,868 | ---- | C] (Conexant) -- C:\WINDOWS\System32\drivers\mdmxsdk.sys

[2009/12/05 05:25:30 | 01,897,408 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nv4_mini.sys

[2009/12/05 05:25:30 | 01,309,184 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlstrm.sys

[2009/12/05 05:25:30 | 00,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\drivers\mtxparhm.sys

[2009/12/05 05:25:30 | 00,180,360 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\ntmtlfax.sys

[2009/12/05 05:25:30 | 00,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\drivers\s3gnbm.sys

[2009/12/05 05:25:30 | 00,126,686 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlmnt5.sys

[2009/12/05 05:25:30 | 00,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismpx.sys

[2009/12/05 05:25:30 | 00,013,776 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\recagent.sys

[2009/12/05 05:25:30 | 00,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mutohpen.sys

[2009/12/05 05:25:29 | 00,404,990 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slntamr.sys

[2009/12/05 05:25:29 | 00,129,535 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnt7554.sys

[2009/12/05 05:25:29 | 00,095,424 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnthal.sys

[2009/12/05 05:25:29 | 00,013,240 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slwdmsup.sys

[2009/12/05 05:25:29 | 00,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbali.sys

[2009/12/05 05:25:29 | 00,003,901 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\siint5.dll

[2009/12/05 05:25:28 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023x.sys

[2009/12/05 05:25:28 | 00,011,807 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv07nt.sys

[2009/12/05 05:25:28 | 00,011,325 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\vchnt5.dll

[2009/12/05 05:25:28 | 00,011,295 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv08nt.sys

[2009/12/05 05:25:27 | 00,025,471 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\watv10nt.sys

[2009/12/05 05:25:27 | 00,022,271 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\watv06nt.sys

[2009/12/05 05:25:27 | 00,011,935 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv11nt.sys

[2009/12/05 05:25:27 | 00,011,871 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv09nt.sys

[2009/12/05 04:48:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\New Folder

[2009/12/05 02:11:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2009/12/05 02:10:05 | 00,195,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe

[2009/12/05 02:07:04 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials

[2009/12/04 23:33:55 | 00,000,000 | -HSD | C] -- C:\RECYCLER

[2009/12/04 22:21:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp

[2009/12/04 22:11:22 | 00,000,000 | RHSD | C] -- C:\cmdcons

[2009/12/01 12:22:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData

[2009/12/01 04:21:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Apple Computer

[2009/11/20 02:13:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Foxit

[2008/06/25 13:16:56 | 00,147,456 | ---- | C] ( ) -- C:\WINDOWS\rsnp2std.dll

[2008/06/25 13:16:56 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll

[2007/06/10 22:57:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help

[2007/06/10 22:57:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help

[2007/04/19 07:32:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2007/04/19 07:32:37 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[2007/04/19 07:32:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google

[2007/04/19 07:32:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Google

[2006/12/27 18:29:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[7 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]

[6 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]

[4 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

[14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[14 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2009/12/12 17:33:29 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2009/12/12 17:32:40 | 00,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job

[2009/12/12 13:51:44 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/12/12 13:51:30 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/12/12 13:51:28 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/12/12 12:38:17 | 13,369,344 | ---- | M] () -- C:\Documents and Settings\Administrator\ntuser.dat

[2009/12/12 12:38:17 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini

[2009/12/12 01:52:55 | 00,002,257 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2009/12/12 01:27:14 | 00,062,024 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\svv4.jpg

[2009/12/10 00:02:16 | 00,206,336 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\spss.doc

[2009/12/09 23:59:18 | 00,214,016 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\12345.doc

[2009/12/09 23:33:50 | 00,101,888 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\strat.doc

[2009/12/09 01:13:13 | 00,720,897 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\why.mp3

[2009/12/09 01:07:37 | 14,151,680 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Didko.mp3

[2009/12/09 00:48:16 | 12,200,064 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Maya_Simantov_-_Why_(Maya's_Version_LG_Edit).mp3

[2009/12/08 22:05:41 | 00,729,972 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\analis2.zip

[2009/12/08 19:24:30 | 00,126,976 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\2chast.doc

[2009/12/08 16:27:07 | 00,459,109 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Corruption research design.pdf

[2009/12/08 16:26:00 | 00,504,249 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ukazania referrati SPSS 2008.pdf

[2009/12/08 15:08:34 | 00,021,504 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\2chast.doc

[2009/12/08 15:01:30 | 00,010,568 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\docXConverter.ini

[2009/12/08 14:58:36 | 00,000,140 | -H-- | M] () -- C:\Documents and Settings\Administrator\Application Data\brara1985.sys

[2009/12/08 14:45:39 | 00,289,975 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\част_2.rtf

[2009/12/08 13:52:23 | 00,001,760 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Sony Ericsson PC Suite.lnk

[2009/12/08 13:46:51 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn

[2009/12/08 13:46:51 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for

[2009/12/08 13:39:07 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrator\Desktop\~$ferat_2_4ast.doc

[2009/12/08 13:38:50 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrator\Desktop\~$unss.doc

[2009/12/08 13:19:16 | 00,033,792 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\225663_pomagalo_com.doc

[2009/12/08 13:16:45 | 02,382,336 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\107448_pomagalo_com.doc

[2009/12/08 12:57:39 | 00,025,456 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT

[2009/12/08 12:57:17 | 01,229,824 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\193486_pomagalo_com.doc

[2009/12/08 12:52:09 | 00,099,840 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\203099_pomagalo_com.doc

[2009/12/08 12:40:55 | 00,156,160 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\1767_pomagalo_com.doc

[2009/12/08 12:32:37 | 00,116,224 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\referat_2_4ast.doc

[2009/12/08 11:37:15 | 00,001,593 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2009/12/07 12:24:44 | 00,000,724 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\TreeSize Free.lnk

[2009/12/07 11:17:56 | 00,000,126 | ---- | M] () -- C:\WINDOWS\S3.uns

[2009/12/06 17:16:39 | 05,784,600 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\BISOLLINI - Greshnata nota.mp3

[2009/12/05 16:08:52 | 00,001,195 | ---- | M] () -- C:\WINDOWS\win.ini

[2009/12/05 16:08:52 | 00,000,320 | RHS- | M] () -- C:\boot.ini

[2009/12/05 16:08:52 | 00,000,264 | ---- | M] () -- C:\WINDOWS\system.ini

[2009/12/05 15:59:06 | 00,000,566 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk

[2009/12/05 15:47:32 | 00,000,593 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk

[2009/12/05 05:42:34 | 00,432,664 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2009/12/05 05:42:34 | 00,067,428 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2009/12/05 05:41:47 | 00,025,456 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2009/12/05 05:40:06 | 00,149,992 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2009/12/05 05:25:02 | 00,250,048 | RHS- | M] () -- C:\ntldr

[2009/12/05 02:07:06 | 00,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk

[2009/12/04 23:23:47 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2009/12/03 22:56:05 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\setup_XP.ini

[2009/12/03 16:14:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2009/12/03 16:13:56 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009/12/02 09:25:35 | 00,000,000 | -H-- | M] () -- C:\Documents and Settings\Administrator\My Documents\Default.rdp

[2009/12/01 04:21:52 | 00,001,755 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

[2009/11/30 23:22:28 | 00,156,672 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/11/19 04:18:33 | 00,170,496 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\unss.doc

[2009/11/18 21:23:05 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrator\Desktop\~$8243_pomagalo_com.doc

[2009/11/18 18:07:56 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrator\Desktop\~$4697_pomagalo_com.doc

[2009/11/18 16:57:32 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrator\Desktop\~$9362_pomagalo_com.doc

[7 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]

[6 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]

[4 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

[14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[14 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/12 01:27:43 | 00,062,024 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\svv4.jpg

[2009/12/10 00:00:44 | 00,206,336 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\spss.doc

[2009/12/09 01:13:12 | 00,720,897 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\why.mp3

[2009/12/09 01:07:36 | 14,151,680 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Didko.mp3

[2009/12/09 00:48:12 | 12,200,064 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Maya_Simantov_-_Why_(Maya's_Version_LG_Edit).mp3

[2009/12/08 22:21:47 | 00,214,016 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\12345.doc

[2009/12/08 22:05:40 | 00,729,972 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\analis2.zip

[2009/12/08 21:31:24 | 00,101,888 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\strat.doc

[2009/12/08 16:27:04 | 00,459,109 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Corruption research design.pdf

[2009/12/08 16:25:58 | 00,504,249 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ukazania referrati SPSS 2008.pdf

[2009/12/08 15:09:47 | 00,126,976 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\2chast.doc

[2009/12/08 15:08:34 | 00,021,504 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\2chast.doc

[2009/12/08 14:45:38 | 00,289,975 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\част_2.rtf

[2009/12/08 14:38:30 | 00,000,140 | -H-- | C] () -- C:\Documents and Settings\Administrator\Application Data\brara1985.sys

[2009/12/08 14:38:21 | 00,010,568 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\docXConverter.ini

[2009/12/08 13:52:23 | 00,001,760 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Sony Ericsson PC Suite.lnk

[2009/12/08 13:46:40 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn

[2009/12/08 13:46:40 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for

[2009/12/08 13:39:07 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrator\Desktop\~$ferat_2_4ast.doc

[2009/12/08 13:38:50 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrator\Desktop\~$unss.doc

[2009/12/08 13:19:15 | 00,033,792 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\225663_pomagalo_com.doc

[2009/12/08 13:16:42 | 02,382,336 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\107448_pomagalo_com.doc

[2009/12/08 12:57:16 | 01,229,824 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\193486_pomagalo_com.doc

[2009/12/08 12:52:06 | 00,099,840 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\203099_pomagalo_com.doc

[2009/12/08 12:40:54 | 00,156,160 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\1767_pomagalo_com.doc

[2009/12/08 12:32:35 | 00,116,224 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\referat_2_4ast.doc

[2009/12/08 11:37:15 | 00,001,593 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2009/12/07 12:24:44 | 00,000,724 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\TreeSize Free.lnk

[2009/12/06 17:16:34 | 05,784,600 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\BISOLLINI - Greshnata nota.mp3

[2009/12/05 15:59:06 | 00,000,566 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk

[2009/12/05 15:47:32 | 00,000,593 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk

[2009/12/05 05:25:33 | 00,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod

[2009/12/05 05:25:32 | 00,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty

[2009/12/05 05:25:30 | 00,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img

[2009/12/05 02:13:45 | 00,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job

[2009/12/05 02:07:06 | 00,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk

[2009/12/03 22:56:05 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\setup_XP.ini

[2009/12/03 17:41:58 | 13,369,344 | ---- | C] () -- C:\Documents and Settings\Administrator\ntuser.dat

[2009/12/02 09:25:35 | 00,000,000 | -H-- | C] () -- C:\Documents and Settings\Administrator\My Documents\Default.rdp

[2009/12/01 23:15:22 | 00,000,126 | ---- | C] () -- C:\WINDOWS\S3.uns

[2009/11/18 21:23:05 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrator\Desktop\~$8243_pomagalo_com.doc

[2009/11/18 18:07:56 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrator\Desktop\~$4697_pomagalo_com.doc

[2009/11/18 16:52:19 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrator\Desktop\~$9362_pomagalo_com.doc

[2009/11/18 16:50:55 | 00,170,496 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\unss.doc

[2009/09/24 18:10:10 | 00,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Home

[2009/09/24 18:10:10 | 00,000,268 | RH-- | C] () -- C:\Documents and Settings\Administrator\Application Data\Halftone

[2009/09/24 18:10:10 | 00,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT

[2009/09/24 18:10:10 | 00,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Hybrid Morph

[2009/06/06 08:21:09 | 00,157,184 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2009/05/06 23:07:29 | 00,888,832 | ---- | C] () -- C:\WINDOWS\System32\securenet.dll

[2008/12/15 17:33:01 | 00,084,632 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2008/11/02 14:23:19 | 00,000,761 | ---- | C] () -- C:\WINDOWS\MTConfig.INI

[2008/06/25 13:16:58 | 00,024,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncamd.sys

[2008/06/25 13:16:58 | 00,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini

[2008/06/25 13:16:57 | 10,305,280 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys

[2008/04/25 15:40:07 | 00,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI

[2008/03/08 20:32:52 | 00,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat

[2007/11/06 01:23:13 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\Days5.ini

[2007/10/16 22:02:53 | 00,064,981 | ---- | C] () -- C:\WINDOWS\System32\sysdatcth32.dll

[2007/07/28 14:12:31 | 00,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

[2007/06/24 00:16:20 | 00,000,039 | ---- | C] () -- C:\WINDOWS\winprefs.ini

[2007/05/10 03:21:10 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\cwsmaf40.dll

[2007/05/10 03:21:09 | 00,511,488 | ---- | C] () -- C:\WINDOWS\System32\cwmdtl50a.dll

[2007/02/13 22:56:17 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\newdll.dll

[2007/02/13 20:31:59 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2007/02/09 10:40:57 | 00,847,872 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2007/02/09 10:40:57 | 00,151,552 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2007/02/09 10:40:55 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll

[2007/02/09 10:40:55 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2007/02/09 10:26:08 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\UnAudioNT.dll

[2007/02/09 10:26:08 | 00,003,351 | ---- | C] () -- C:\WINDOWS\System32\drivers\vsp.sys

[2007/01/28 20:22:46 | 00,000,253 | ---- | C] () -- C:\WINDOWS\LEXSTAT.INI

[2007/01/28 20:18:52 | 00,000,508 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2007/01/13 14:39:55 | 00,156,672 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2006/12/27 12:14:44 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\ginamsi.dll

[2006/11/15 16:08:08 | 00,103,936 | ---- | C] () -- C:\WINDOWS\System32\drivers\cam1690.sys

[2006/11/07 18:45:22 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\cam1690.dll

[2006/11/07 15:39:14 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\cam1690m.dll

[2006/11/06 19:01:12 | 00,004,039 | ---- | C] () -- C:\WINDOWS\cam1690.ini

[2006/03/06 09:41:02 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\AMV_DecDLL.dll

[2004/09/16 12:26:40 | 00,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS

[2004/09/16 12:26:40 | 00,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS

[2003/05/12 22:57:47 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini

[2002/10/16 00:54:04 | 00,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2002/05/16 01:38:40 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll

[2002/05/04 15:19:00 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\avisynthEx.dll

[2002/04/19 16:23:26 | 00,106,137 | ---- | C] () -- C:\WINDOWS\System32\libpostproc.dll

[2002/04/19 15:51:04 | 00,211,760 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll

[2001/06/22 13:06:02 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\MPEG2DEC.dll

========== LOP Check ==========

[2008/03/23 17:07:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\######

[2008/05/01 16:27:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\DAEMON Tools

[2009/11/20 02:13:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Foxit

[2007/06/07 15:35:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GanymedeNet

[2009/01/18 22:54:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Hide IP NG

[2006/12/31 18:26:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ICAClient

[2009/12/07 12:25:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\JAM Software

[2008/05/28 18:54:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\JustVoip

[2008/03/23 18:17:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech

[2008/06/20 18:52:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\LowRateVoip

[2007/03/02 19:53:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Miranda

[2007/03/02 20:00:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MSNInstaller

[2009/10/22 14:02:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Nikon

[2009/05/04 14:51:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\OLYMPUS

[2007/02/17 01:41:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Ringjacker

[2007/11/08 20:01:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Sony

[2009/06/22 23:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TeamViewer

[2007/07/31 15:53:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Teleca

[2009/11/07 17:22:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Thinstall

[2009/02/22 02:33:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\WNR

[2008/03/03 05:57:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem

[2009/09/24 18:10:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp

[2009/09/24 18:10:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon

[2009/12/08 13:52:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca

[2007/03/12 15:28:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2009/09/24 18:10:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15

[2009/05/05 23:49:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WNR

[2009/12/12 17:32:40 | 00,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0295CBF7

< End of report >

OTL Extras logfile created on: 12/12/2009 5:34:35 PM - Run 1

OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Administrator\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000402 | Country: United States | Language: ENU | Date Format: M/d/yyyy

446.48 Mb Total Physical Memory | 162.94 Mb Available Physical Memory | 36.49% Memory free

1.23 Gb Paging File | 0.19 Gb Available in Paging File | 15.40% Paging File free

Paging file location(s): c:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19.53 Gb Total Space | 2.88 Gb Free Space | 14.72% Space Free | Partition Type: NTFS

Drive D: | 54.99 Gb Total Space | 29.71 Gb Free Space | 54.04% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: HRISTO-28670FBF

Current User Name: Administrator

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.chm [@ = chm.file] -- "%SYSTEMROOT%\hh.exe" %1

.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe"

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0 -- File not found

"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Disabled:BitComet - a BitTorrent Client -- (www.BitComet.com)

"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)

"D:\Program Files\Skype\Phone\Skype.exe" = D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0

"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform

"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader

"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java 6 Update 10

"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1

"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5

"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1

"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials

"{5A438E06-0BB3-4C5F-0085-B14F1F4077E6}" = FIFA 07

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8

"{6E65247F-58F9-41CA-BE69-0316F7907170}" = Disc2Phone

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{75438C0E-9925-412E-AD85-D0E71C6CE2ED}" = 1.3Mega USB2.0 PC Cam

"{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}" = MP3 Player Utilities 4.09

"{90110402-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional

"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-0045-0409-0000-0000000FF1CE}" = Microsoft Expression Web 2 MUI (English)

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{940E5F97-1FD4-4B6E-8FD9-804691ACB8D7}" = JPEG USB Video Camera Driver v0.81

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware

"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable

"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1

"{B947EFD7-D033-49E2-B837-F43C9D73AD4A}" = Tsunami-Filter-Pack Mini

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C5ADA65A-7828-4D85-B071-ECC52B51F794}" = Sony Ericsson PC Suite 1.20.173

"{C72EA659-13C2-49A8-0083-920B373E887B}" = UEFA Champions League 2006-2007

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center

"{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4

"{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime

"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer

"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Shockwave Player" = Adobe Shockwave Player

"BitComet" = BitComet 0.60

"BSPlayer1" = BSPlayer

"CCleaner" = CCleaner

"Citrix ICA Client" = Citrix ICA Client

"Cliprex Cdivx Player" = Cliprex Cdivx Player

"Cliprex DS DVD Player" = Cliprex DS DVD Player

"Elecard MPEG2 Decoder Package" = Elecard MPEG2 Decoder Package 2.0

"ESET Online Scanner" = ESET Online Scanner v3

"FlexType 2K" = FlexType 2K

"FormatFactory" = FormatFactory 2.00

"HWiNFO32_is1" = HWiNFO32 Version 3.30

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager

"IZArc 3.4.1.6_is1" = IZArc 3.4.1.6

"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.46

"Lexmark Z600 Series" = Lexmark Z600 Series

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5

"Microsoft Security Essentials" = Microsoft Security Essentials

"Mp3 Knife_is1" = Mp3 Knife 3.2

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"My Global Search Uninstall" = My Global Search Bar

"NimoCorp" = Nimo Codecs Pack v5.0 (Remove Only)

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"SA Dictionary 2004 Datacenter" = SA Dictionary 2004 Datacenter

"SA Dictionary 2005 T2" = SA Dictionary 2005 T2

"SecureDoc" = SecureDoc

"TreeSize Free_is1" = TreeSize Free V2.3.3

"Veetle TV" = Veetle TV 0.9.15

"VIA Audio Driver Setup Program" = VIA Audio Driver Setup Program

"VIA/S3G UniChrome Family Win2K/XP/Server2003 Display" = VIA/S3G Display Driver 6.14.10.0297

"VobSub" = VobSub v2.23 (Remove Only)

"WebClicker" = HeadStrong WebClicker v2.56

"WIC" = Windows Imaging Component

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinRAR archiver" = WinRAR archiver

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 12/8/2009 1:31:42 PM | Computer Name = HRISTO-28670FBF | Source = Application Hang | ID = 1002

Description = Hanging application Skype.exe, version 3.8.0.154, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 12/9/2009 11:31:06 AM | Computer Name = HRISTO-28670FBF | Source = MPSampleSubmission | ID = 5000

Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4

2.0.6212.0, P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),

P8 NIL, P9 NIL, P10 NIL.

Error - 12/10/2009 4:14:29 PM | Computer Name = HRISTO-28670FBF | Source = MPSampleSubmission | ID = 5000

Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4

2.0.6212.0, P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),

P8 NIL, P9 NIL, P10 NIL.

Error - 12/11/2009 7:52:47 PM | Computer Name = HRISTO-28670FBF | Source = Application Hang | ID = 1002

Description = Hanging application Skype.exe, version 3.8.0.154, hang module hungapp,

version 0.0.0.0, hang address 0x00000000.

Error - 12/11/2009 8:00:56 PM | Computer Name = HRISTO-28670FBF | Source = MPSampleSubmission | ID = 5000

Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4

2.0.6212.0, P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),

P8 NIL, P9 NIL, P10 NIL.

Error - 12/12/2009 12:47:28 AM | Computer Name = HRISTO-28670FBF | Source = ESENT | ID = 482

Description = svchost (1120) An attempt to write to the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"

at offset 0 (0x0000000000000000) for 4096 (0x00001000) bytes failed with system

error 112 (0x00000070): "There is not enough space on the disk. ". The write operation

will fail with error -1808 (0xfffff8f0). If this error persists then the file

may be damaged and may need to be restored from a previous backup.

Error - 12/12/2009 12:47:29 AM | Computer Name = HRISTO-28670FBF | Source = ESENT | ID = 439

Description = Catalog Database (1120) Unable to write a shadowed header for file

C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb. Error

-1808.

Error - 12/12/2009 12:47:29 AM | Computer Name = HRISTO-28670FBF | Source = ESENT | ID = 470

Description = Catalog Database (1120) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb

is partially attached. Attachment stage: 1. Error: -1808.

Error - 12/12/2009 11:28:45 AM | Computer Name = HRISTO-28670FBF | Source = MPSampleSubmission | ID = 5000

Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4

2.0.6212.0, P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),

P8 NIL, P9 NIL, P10 NIL.

Error - 12/12/2009 11:33:57 AM | Computer Name = HRISTO-28670FBF | Source = MPSampleSubmission | ID = 5000

Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4

2.0.6212.0, P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),

P8 NIL, P9 NIL, P10 NIL.

[ System Events ]

Error - 12/11/2009 8:00:55 PM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 1.71.538.0 Update Source: %%859 Update Stage:

%%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current

Engine Version: Previous Engine Version: 1.1.5302.0 Error code: 0x80070424 Error

description: The specified service does not exist as an installed service.

Error - 12/12/2009 7:51:42 AM | Computer Name = HRISTO-28670FBF | Source = Service Control Manager | ID = 7023

Description = The Microsoft Antimalware Service service terminated with the following

error: %%2147944102

Error - 12/12/2009 11:27:38 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2004

Description = %%861 has encountered an error trying to load signatures and will

attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824

Error

Code: 0x8050800c Error description: An unexpected problem occurred. Install any

available updates, and then try to start the program again. For information on installing

updates, see Help and Support. Signature version: 1.71.760.0;1.71.760.0 Engine version:

1.1.5302.0

Error - 12/12/2009 11:27:38 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2004

Description = %%861 has encountered an error trying to load signatures and will

attempt reverting back to a known-good set of signatures. Signatures Attempted: %%825

Error

Code: 0x80070070 Error description: There is not enough space on the disk. Signature

version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0

Error - 12/12/2009 11:28:43 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%852

Source

Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current

Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070424 Error description:

The specified service does not exist as an installed service.

Error - 12/12/2009 11:28:57 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%853

Source

Path: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=0.0.0.0&avdelta=0.0.0.0&asdelta=0.0.0.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE

Signature

Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:

Previous Engine Version: 0.0.0.0 Error code: 0x80070070 Error description: There

is not enough space on the disk.

Error - 12/12/2009 11:28:57 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%853

Source

Path: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=0.0.0.0&avdelta=0.0.0.0&asdelta=0.0.0.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE

Signature

Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:

Previous Engine Version: 0.0.0.0 Error code: 0x80070070 Error description: There

is not enough space on the disk.

Error - 12/12/2009 11:28:57 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%853

Source

Path: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=0.0.0.0&avdelta=0.0.0.0&asdelta=0.0.0.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE

Signature

Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:

Previous Engine Version: 0.0.0.0 Error code: 0x80070070 Error description: There

is not enough space on the disk.

Error - 12/12/2009 11:28:57 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%853

Source

Path: http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=0.0.0.0&avdelta=0.0.0.0&asdelta=0.0.0.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE

Signature

Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:

Previous Engine Version: 0.0.0.0 Error code: 0x80070070 Error description: There

is not enough space on the disk.

Error - 12/12/2009 11:33:57 AM | Computer Name = HRISTO-28670FBF | Source = Microsoft Antimalware | ID = 2001

Description = %%861 has encountered an error trying to update signatures. New Signature

Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%852

Source

Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current

Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070424 Error description:

The specified service does not exist as an installed service.

< End of report >

Ето инфото и за драйверите ;)

motherboard model: MSI MS-7222 motherboard chipset : VIA P4M800 Pro/CE + VT8237®

Здравейте,

Би трябвало драйверите за видеокартата да са това.

Пробвайте да ги изтеглите, инсталирате и да рестартирате машината. Вижте как е положението и има ли промяна.

Изтеглете OTL.exe и го запазете на десктопа.

Стартирай файла otlDesktopIcon.png с двукратен клик на мишката и copy/paste под колонката "Custom Scans/Fixes" въведете това:

:OTL

O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

O3 - HKU\S-1-5-21-448539723-2077806209-682003330-500\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.

O3 - HKU\S-1-5-21-448539723-2077806209-682003330-500\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.

O4 - HKLM..\Run: [] File not found

:files

C:\RECYCLER

C:\WINDOWS\System32\sysdatcth32.dll

:Commands

[purity]

[emptytemp]

[Reboot]

Натиснете бутона runFixbutton.png

Ще се създаде лог файл. Копирайте го в следващия си пост.

Обновете дефинициите на Malwarebytes' Anti-Malware 1.42 и направете нова бърза проверка.

Публикувайте резултатите от нея.

  • Автор

При драйвърите няма никаква промяна, все така си е.След като го направих това с OTL на десктопа се появиха няколко бледи иконки главно на неща от word който са изтрити преди време или поне от десктопа ги бях изтрила.А между другото от няколко дена, не всеки път, но понякога при вкл на компа той почва супер много да шуми, все едно е трактор :mad: след около 5 мин се оправя и си става нормално шумен.

All processes killed

========== OTL ==========

Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.

Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.

Registry value HKEY_USERS\S-1-5-21-448539723-2077806209-682003330-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.

Registry value HKEY_USERS\S-1-5-21-448539723-2077806209-682003330-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.

========== FILES ==========

C:\RECYCLER\S-1-5-21-448539723-2077806209-682003330-500\Dc1\UChromeP folder moved successfully.

C:\RECYCLER\S-1-5-21-448539723-2077806209-682003330-500\Dc1 folder moved successfully.

C:\RECYCLER\S-1-5-21-448539723-2077806209-682003330-500 folder moved successfully.

C:\RECYCLER folder moved successfully.

C:\WINDOWS\System32\sysdatcth32.dll moved successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator

->Temp folder emptied: 346144637 bytes

->Temporary Internet Files folder emptied: 213059750 bytes

->Java cache emptied: 0 bytes

User: All Users

User: bear

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 78991 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

User: LocalService

->Temp folder emptied: 16384 bytes

->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService

->Temp folder emptied: 171462 bytes

->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 4306477 bytes

%systemroot%\System32 .tmp files removed: 13517759 bytes

Windows Temp folder emptied: 185420 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 550.82 mb

OTL by OldTimer - Version 3.1.17.0 log created on 12142009_034354

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Да пробваме, няколко неща:

1. Заредете в Safe Mode (при рестартиране на компютъра припомпвайте бутона F8 и от списъка селектирайте Safe Mode).

Вижте дали там се появява проблема с черния екран при зареждане (Log-on).

2. Ако го няма, значи е възможно калпав драйвер, скрит зловреден процес (макар аз вече да не откривам такива) или нещо друго да спъва работата на Операционната Система.

И тук ще ми трябват отново няколко лог файла:

Изтеглете Autoruns:

1) стартирайте програмата;

2) изберете Options -> Hide Microsoft and Windows Entries и Verify Code Signatures

3) меню File -> Refresh (или F5)

4) изчакайте сканирането да завърши

4) меню File -> Save -> (от падащото меню запазете файла с разширение *.TXT а не *.ARN).

5) копирайте съдържанието на лога в следващия си пост

Също така, отворете Notepad и с Copy/Paste въведете:

CMD /C Net Start >"%Userprofile%\Desktop\Log.txt"

Запазете файла с име check.bat и го стартирайте.

Публикувайте лог файла в следващия си пост.

И за финал изтеглете HijackThis.

Стартирайте програмата и от Open The Misc Tools section => и изберете Generate StartupList log => Публикувайте го в следващия си коментар.

И пак от HijackThis => Open The Misc Tools section => Open Uninstall Manager => Save List => Публикувайте лог файла в следващия си коментар.

  • Автор

Лога от МBAM,а тия неща по-късно през деня, че умрях за сън :mad:

Malwarebytes' Anti-Malware 1.42

Версия на базата от данни: 3362

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

12/14/2009 5:30:36 AM

mbam-log-2009-12-14 (05-30-36).txt

Тип сканиране: Пълно сканиране (C:\|D:\|E:\|)

Сканирани обекти: 209988

Изминало време: 1 hour(s), 14 minute(s), 14 second(s)

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 0

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 0

Заразени процеси в паметта:

(Не бяха открити заплахи)

Заразени модули в паметта:

(Не бяха открити заплахи)

Заразени ключове в регистратурата:

(Не бяха открити заплахи)

Заразени стойности в регистратурата:

(Не бяха открити заплахи)

Заразени информационни обекти в регистратурата:

(Не бяха открити заплахи)

Заразени папки:

(Не бяха открити заплахи)

Заразени файлове:

(Не бяха открити заплахи)

  • Автор

При safe mode го няма това с черния екран,пробвах и при другото копие на windows или както се нарича там където се избира кой да се стартира и там също не се появява черен екран,а и резолюцията там си е нормална и не се сменя това в скобите й от 32 на 8...само че на това копие нямам инсталирано почти нищо :P

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" ""

+ "Adobe Reader Speed Launcher" "Adobe Acrobat SpeedLauncher" "(Verified) Adobe Systems, Incorporated" "d:\program files\adobe\reader 9.0\reader\reader_sl.exe"

+ "Nikon Transfer Monitor" "Nikon Transfer Monitor" "(Verified) NIKON CORPORATION" "c:\program files\common files\nikon\monitor\nkmonitor.exe"

+ "QuickTime Task" "QuickTime Task" "(Not verified) Apple Inc." "c:\program files\k-lite codec pack\quicktime\qttask.exe"

+ "Sony Ericsson PC Suite" "Application Launcher" "(Not verified) Sony Ericsson Mobile Communications AB" "d:\program files\sony ericsson\mobile2\application launcher\application launcher.exe"

+ "tsnp2std" "tsnp2std Microsoft " "" "c:\windows\tsnp2std.exe"

"C:\Documents and Settings\All Users\Start Menu\Programs\Startup" "" "" ""

+ "FlexType 2K.lnk" "" "" "d:\program files\datecs\flextype 2k\ftype2k.exe"

"HKCU\Software\Microsoft\Windows\CurrentVersion\Run" "" "" ""

+ "Skype" "Skype" "(Verified) Skype Technologies SA" "c:\program files\skype\phone\skype.exe"

"HKLM\SOFTWARE\Classes\Protocols\Handler" "" "" ""

+ "cdo" "Microsoft SharePoint Portal Server Object Model" "(Not verified) Microsoft Corporation" "c:\program files\common files\microsoft shared\web folders\pkmcdo.dll"

+ "skype4com" "Skype for COM API" "(Verified) Skype Technologies SA" "c:\program files\common files\skype\skype4com.dll"

"HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components" "" "" ""

+ "0" "" "" "File not found: About:Home"

"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" ""

+ "IE7 Uninstall Stub" "IE Per User Active Setup Uninstall Utility" "(Not verified) Microsoft Corporation" "c:\windows\system32\ieudinit.exe"

"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" ""

+ "IZArcCM" "" "" "c:\program files\izarc\izarccm.dll"

+ "SecureDocMenu" "SecureDoc" "(Not verified) msi" "c:\program files\msi\securedoc\secdoc.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers" "" "" ""

+ "MBAMShlExt" "Malwarebytes' Anti-Malware" "(Verified) Malwarebytes Corporation" "d:\program files\malwarebytes' anti-malware\mbamext.dll"

"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers" "" "" ""

+ "IZArcCM" "" "" "c:\program files\izarc\izarccm.dll"

+ "SecureDocMenu" "SecureDoc" "(Not Verified) msi" "c:\program files\msi\securedoc\secdoc.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\Directory\Shellex\DragDropHandlers" "" "" ""

+ "A5110426-177D-4e08-AB3F-785F10B4439C" "File Manager interface" "(Not verified) Sony Ericsson Mobile Communications AB" "d:\program files\sony ericsson\mobile2\file manager\fmgrgui.dll"

+ "IZArcCM" "" "" "c:\program files\izarc\izarccm.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Classes\Folder\Shellex\ColumnHandlers" "" "" ""

+ "PDF Shell Extension" "PDF Shell Extension" "(Verified) Adobe Systems, Incorporated" "c:\program files\common files\adobe\acrobat\activex\pdfshell.dll"

"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" ""

+ "MBAMShlExt" "Malwarebytes' Anti-Malware" "(Verified) Malwarebytes Corporation" "d:\program files\malwarebytes' anti-malware\mbamext.dll"

+ "WinRAR" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" "" "" ""

+ "Display Panning CPL Extension" "" "" "File not found: deskpan.dll"

+ "HyperTerminal Icon Ext" "" "" "File not found: C:\WINDOWS\system32\hticons.dll"

+ "IZArc DragDrop Menu" "" "" "c:\program files\izarc\izarccm.dll"

+ "IZArc Shell Context Menu" "" "" "c:\program files\izarc\izarccm.dll"

+ "SecureDoc" "SecureDoc" "(Not Verified) msi" "c:\program files\msi\securedoc\secdoc.dll"

+ "Sony Ericsson File Manager" "File Manager interface" "(Not Verified) Sony Ericsson Mobile Communications AB" "d:\program files\sony ericsson\mobile2\file manager\fmgrgui.dll"

+ "WinRAR shell extension" "" "" "c:\program files\winrar\rarext.dll"

"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" ""

+ "Adobe PDF Link Helper" "Adobe PDF Helper for Internet Explorer" "(Verified) Adobe Systems, Incorporated" "c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll"

+ "Java Plug-In 2 SSV Helper" "Java Platform SE binary" "(Not verified) Sun Microsystems, Inc." "c:\program files\java\jre6\bin\jp2ssv.dll"

+ "JQSIEStartDetectorImpl Class" "Java Quick Starter binary" "(Not verified) Sun Microsystems, Inc." "c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll"

+ "Skype add-on (mastermind)" "Skype add-on for IE" "(Verified) Skype Technologies SA" "c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll"

+ "SSVHelper Class" "Java Platform SE binary" "(Verified) Sun Microsystems, Inc." "c:\program files\java\jre6\bin\ssv.dll"

"HKLM\System\CurrentControlSet\Services" "" "" ""

+ "aspnet_state" "Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start." "(Not verified) Microsoft Corporation" "c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe"

+ "clr_optimization_v2.0.50727_32" "Microsoft .NET Framework NGEN" "(Not verified) Microsoft Corporation" "c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe"

+ "IDriverT" "Provides support for the Running Object Table for InstallShield Drivers" "(Not verified) Macrovision Corporation" "c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe"

+ "idsvc" "Securely enables the creation, management, and disclosure of digital identities." "(Not verified) Microsoft Corporation" "c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe"

+ "JavaQuickStarterService" "Prefetches JRE files for faster startup of Java applets and applications" "(Verified) Sun Microsystems, Inc." "c:\program files\java\jre6\bin\jqs.exe"

+ "ose" "Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports." "(Not verified) Microsoft Corporation" "c:\program files\common files\microsoft shared\source engine\ose.exe"

+ "SecureSrv" "ProxySrv Module" "" "d:\program files\hide my ip 2008\securesrv.exe"

+ "WMPNetworkSvc" "Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play" "(Not verified) Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe"

"HKLM\System\CurrentControlSet\Services" "" "" ""

+ "bdfdll" "" "" "File not found: C:\Program Files\Softwin\BitDefender9\bdfdll.sys"

+ "CAM1690" "USB Camera Driver" "" "c:\windows\system32\drivers\cam1690.sys"

+ "catchme" "" "" "File not found: C:\ComboFix\catchme.sys"

+ "cdrbsdrv" "CD-ROM Filter Driver for Windows2000/xp" "(Not verified) B.H.A Corporation" "c:\windows\system32\drivers\cdrbsdrv.sys"

+ "Changer" "" "" "File not found: C:\WINDOWS\System32\Drivers\Changer.sys"

+ "dtscsi" "" "" "File not found: C:\WINDOWS\System32\Drivers\dtscsi.sys"

+ "FETNDIS" "" "" "File not found: system32\DRIVERS\fetnd5.sys"

+ "GMSIPCI" "" "" "File not found: E:\INSTALL\GMSIPCI.SYS"

+ "HWiNFO32" "HWiNFO32 Kernel Driver" "(Verified) REALiX" "d:\program files\hwinfo32\hwinfo32.sys"

+ "i2omgmt" "" "" "File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys"

+ "lbrtfdc" "" "" "File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys"

+ "MCSTRM" "RealNetworks Virtual Path Manager®" "(Not verified) RealNetworks, Inc." "c:\windows\system32\drivers\mcstrm.sys"

+ "PCIDump" "" "" "File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys"

+ "Pcouffin" "" "" "File not found: System32\Drivers\Pcouffin.sys"

+ "PDCOMP" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys"

+ "PDFRAME" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys"

+ "PDRELI" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys"

+ "PDRFRAME" "" "" "File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys"

+ "PxHelp20" "Px Engine Device Driver for Windows 2000/XP" "(Verified) Sonic Solutions" "c:\windows\system32\drivers\pxhelp20.sys"

+ "rootrepeal" "" "" "File not found: C:\WINDOWS\system32\drivers\rootrepeal.sys"

+ "STAC97" "VIA VT82C686A Audio Driver (WDM)" "(Not verified) SigmaTel, Inc." "c:\windows\system32\drivers\stac97.sys"

+ "SVKP" "SVKP driver for NT" "(Not verified) AntiCracking" "c:\windows\system32\svkp.sys"

+ "SysProtDrv.sys" "" "" "File not found: C:\Documents and Settings\Administrator\Desktop\SysProt\SysProt\SysProtDrv.sys"

+ "VIAudio" "VIA AC'97 Enhanced Audio WDM Driver " "(Not verified) VIA Technologies, Inc." "c:\windows\system32\drivers\viaudios.sys"

+ "Vsp" "" "" "c:\windows\system32\drivers\vsp.sys"

+ "WDICA" "" "" "File not found: C:\WINDOWS\System32\Drivers\WDICA.sys"

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""

+ "msacm.ac3acm" "AC-3 ACM Codec" "(Not verified) fccHandler" "c:\windows\system32\ac3acm.acm"

+ "msacm.divxa32" "DivX;-) Audio Codec" "(Not verified) Hacked With Joy !" "c:\windows\system32\divxa32.acm"

+ "msacm.l3fhg" "MPEG Audio Layer-3 Codec for MSACM" "(Not verified) Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\mp3fhg.acm"

+ "VIDC.3iv2" "3ivx D4 4.5.1 Pro Video for Windows Codec" "(Not verified) 3ivx.com" "c:\windows\system32\3ivxvfwcodec.dll"

+ "VIDC.DIV3" "DivX ;-) MPEG-4 Video Codec " "(Not verified) Hacked with Joy !" "c:\windows\system32\divxc32.dll"

+ "VIDC.DIV4" "DivX ;-) MPEG-4 Video Codec " "(Not verified) Hacked with Joy ! " "c:\windows\system32\divxc32f.dll"

+ "vidc.DIVX" "DivX® Codec for Windows" "(Not verified) DivXNetworks, Inc." "c:\windows\system32\divx.dll"

+ "VIDC.FFDS" "" "" "c:\windows\system32\ff_vfw.dll"

+ "VIDC.MJPG" "PICVideo Motion JPEG Compressor" "(Not verified) Pegasus Imaging Corporation" "c:\windows\system32\pvmjpg21.dll"

+ "vidc.MP42" "Microsoft MPEG-4 Video Codec" "(Not Verified) Microsoft Corporation" "c:\windows\system32\mpg4c32.dll"

+ "vidc.MP43" "Microsoft MPEG-4 Video Codec" "(Not Verified) Microsoft Corporation" "c:\windows\system32\mpg4c32.dll"

+ "vidc.MPG4" "Microsoft MPEG-4 Video Codec" "(Not verified) Microsoft Corporation" "c:\windows\system32\mpg4c32.dll"

+ "VIDC.VP31" "On2_VP3 Version 3.2.6.1 Decoder Tune" "(Not verified) On2.com" "c:\windows\system32\vp31vfw.dll"

+ "VIDC.VP60" "VP6 VIDEO FOR WINDOWS CODEC " "(Not verified) On2.com" "c:\windows\system32\vp6vfw.dll"

+ "VIDC.VP61" "VP6 VIDEO FOR WINDOWS CODEC " "(Not Verified) On2.com" "c:\windows\system32\vp6vfw.dll"

+ "VIDC.VP62" "VP6 VIDEO FOR WINDOWS CODEC " "(Not Verified) On2.com" "c:\windows\system32\vp6vfw.dll"

+ "VIDC.VP70" "VP70 VIDEO FOR WINDOWS CODEC " "(Not verified) On2.com" "c:\windows\system32\vp7vfw.dll"

+ "VIDC.wmv3" "Windows Media Video 9 VCM" "(Not verified) Microsoft Corporation" "c:\windows\system32\wmv9vcm.dll"

+ "VIDC.XVID" "" "" "c:\windows\system32\xvidvfw.dll"

"HKLM\Software\Classes\Filter" "" "" ""

+ "Elecard MPEG2 Demultiplexer" "Elecard MPEG 2 Demultiplexor" "(Not verified) Elecard Ltd." "c:\program files\common files\elecard\mpeg2dmx.ax"

+ "Elecard MPEG2 Video Decoder" "Elecard MPEG2 Video Decoder" "(Not verified) Moonlight Cordless Ltd." "c:\program files\common files\elecard\mpgdec.ax"

+ "Elecard PVA Demultiplexer" "Elecard MPEG2 Demultiplexer Streaming Version" "(Not verified) Moonlight Cordless" "c:\program files\common files\elecard\pva_dmx.ax"

"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" ""

+ "AC3 Prologic Decoder " "AC3AUDI" "(Not verified) Kristal Studi" "c:\windows\system32\ac3audio.ax"

+ "AC3 XForm audio filter" "MPEG Audio Codec (Sample)" "(Not verified) MyCompanyName" "c:\windows\system32\mpgaudio.ax"

+ "AC3Filter" "ac3filter" "" "c:\program files\k-lite codec pack\filters\ac3filter.ax"

+ "CoreFLAC Audio Decoder" "CoreFLAC Audio Decoder & Source DirectShow Filter" "(Not Verified) -" "c:\program files\k-lite codec pack\filters\coreflacdecoder.ax"

+ "CoreFLAC Audio Source" "CoreFLAC Audio Decoder & Source DirectShow Filter" "(Not verified) -" "c:\program files\k-lite codec pack\filters\coreflacdecoder.ax"

+ "CoreVorbis Audio Decoder" "CoreVorbis" "(Not verified) -" "c:\program files\k-lite codec pack\filters\corevorbis.ax"

+ "DivX Decoder Filter" "DivX Decoder Filter" "(Not verified) DivXNetworks, Inc." "c:\windows\system32\divxdec.ax"

+ "DivX MPEG-4 DVD Video Decompressor " "DivX MPEG-4 DVD Video Decompressor " "(Not verified) Hacked With Joy ! " "c:\windows\system32\divx_c32.ax"

+ "Elecard Audio Null" "Elecard PIM2 Null Filter" "(Not verified) MyCompanyName" "c:\program files\common files\elecard\pim2null.ax"

+ "Elecard MPEG2 Demultiplexer" "Elecard MPEG 2 Demultiplexor" "(Not Verified) Elecard Ltd." "c:\program files\common files\elecard\mpeg2dmx.ax"

+ "Elecard MPEG2 Video Decoder" "Elecard MPEG2 Video Decoder" "(Not Verified) Moonlight Cordless Ltd." "c:\program files\common files\elecard\mpgdec.ax"

+ "Elecard PVA Demultiplexer" "Elecard MPEG2 Demultiplexer Streaming Version" "(Not Verified) Moonlight Cordless" "c:\program files\common files\elecard\pva_dmx.ax"

+ "ffdshow Audio Decoder" "DirectShow and VFW video and audio decoding/encoding/processing filter" "" "d:\program files\freetime\formatfactory\ffmodules\filters\ffdshow\ffdshow.ax"

+ "ffdshow Audio Processor" "DirectShow and VFW video and audio decoding/encoding/processing filter" "" "d:\program files\freetime\formatfactory\ffmodules\filters\ffdshow\ffdshow.ax"

+ "ffdshow raw video filter" "DirectShow and VFW video and audio decoding/encoding/processing filter" "" "d:\program files\freetime\formatfactory\ffmodules\filters\ffdshow\ffdshow.ax"

+ "ffdshow subtitles filter" "DirectShow and VFW video and audio decoding/encoding/processing filter" "" "d:\program files\freetime\formatfactory\ffmodules\filters\ffdshow\ffdshow.ax"

+ "ffdshow Video Decoder" "DirectShow and VFW video and audio decoding/encoding/processing filter" "" "d:\program files\freetime\formatfactory\ffmodules\filters\ffdshow\ffdshow.ax"

+ "File Source (Monkey Audio)" "" "" "c:\program files\k-lite codec pack\filters\monkeysource.ax"

+ "File Source Filter For Preview" "" "" "File not found: C:\Program Files\BitSpirit\Codec\dxFilter.ax"

+ "FLV Source" "FLV Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\flvsplitter.ax"

+ "FLV Splitter" "FLV Splitter" "(Not verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\flvsplitter.ax"

+ "FLV4 Video Decoder" "FLV Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\flvsplitter.ax"

+ "Haali Matroska Muxer" "" "" "c:\program files\k-lite codec pack\filters\haali\splitter.ax"

+ "Haali Media Splitter" "" "" "c:\program files\k-lite codec pack\filters\haali\splitter.ax"

+ "I-Media AVI Renderer" "" "(Not verified) MyCompanyName" "c:\windows\system32\avi_renderer.ax"

+ "MainConcept (Nikon) MPEG Audio Decoder" "MPEG Video and Audio Decoder" "(Not verified) MainConcept AG (Nikon)" "c:\program files\common files\nikon\mpeg\nikondsmpeg.ax"

+ "MainConcept (Nikon) MPEG Encoder" "MPEG Encoder and Muxer" "(Not verified) MainConcept AG (Nikon)" "c:\program files\common files\nikon\mpeg\nikonesmpeg.ax"

+ "MainConcept (Nikon) MPEG Video Decoder" "MPEG Video and Audio Decoder" "(Not Verified) MainConcept AG (Nikon)" "c:\program files\common files\nikon\mpeg\nikondsmpeg.ax"

+ "Moonlight NicePheratu" "Moonlight Divx Decoder" "(Not verified) Moonlight Cordless Ltd." "c:\program files\common files\elecard\minidivx.ax"

+ "Moonlight Odio Dekoda" "Moonlight Odio Dekoda" "(Not verified) Moonlight Cordless Ltd." "c:\program files\common files\elecard\mlcom.ax"

+ "MPC - Avi Source" "Avi Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\avisplitter.ax"

+ "MPC - Avi Splitter" "Avi Splitter" "(Not verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\avisplitter.ax"

+ "MPC - Matroska Source" "Matroska Splitter" "(Not verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\matroskasplitter.ax"

+ "MPC - Matroska Splitter" "Matroska Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\matroskasplitter.ax"

+ "MPC - MP4 Source" "MP4 Splitter" "(Not verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\mp4splitter.ax"

+ "MPC - MP4 Splitter" "MP4 Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\mp4splitter.ax"

+ "MPC - Mpeg Source (Gabest)" "Mpeg Splitter" "(Not verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\mpegsplitter.ax"

+ "MPC - Mpeg Splitter (Gabest)" "Mpeg Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\mpegsplitter.ax"

+ "MPC - MPEG4 Video Source" "MP4 Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\mp4splitter.ax"

+ "MPC - MPEG4 Video Splitter" "MP4 Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\mp4splitter.ax"

+ "MPEG Layer-3 Decoder" "MPEG Layer-3 Audio Decoder" "(Not verified) Fraunhofer Institut Integrierte Schaltungen IIS" "c:\program files\k-lite codec pack\filters\l3codecx.ax"

+ "muvee Music Analyser" "Music Analyser Filter for muvee autoProducer" "(Not verified) muvee Technologies Pte Ltd" "c:\program files\common files\muvee technologies\030625\mvmanalyse.ax"

+ "muvee WAV Encoder" "mvWavEncoder Filter (Sample)" "(Not verified) Microsoft Corporation" "c:\program files\common files\muvee technologies\030625\mvwavenc.ax"

+ "PIXELA MPEG2-Splitter(IMX)" "" "" "File not found: C:\Program Files\PIXELA\ImageMixer\ImxPsSpl.ax"

+ "QTSrc" "" "" "File not found: C:\Program Files\Allok MP3 to AMR Converter\QuickTime.dll"

+ "QuickTime Source Filter" "QuickTimeSource Module" "" "c:\program files\common files\muvee technologies\030625\quicktimesource.dll"

+ "RadLight MPC DirectShow Filter" "RLMPCDec" "(Not verified) RadLight" "c:\program files\k-lite codec pack\filters\mpcdec.ax"

+ "RealAudio Decoder" "RealMedia Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\realmediasplitter.ax"

+ "RealMedia Source" "RealMedia Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\realmediasplitter.ax"

+ "RealMedia Splitter" "RealMedia Splitter" "(Not Verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\realmediasplitter.ax"

+ "RealVideo Decoder" "RealMedia Splitter" "(Not verified) Gabest" "d:\program files\freetime\formatfactory\ffmodules\filters\realmediasplitter.ax"

+ "ShoutcastSource" "Shoutcast Source Filter" "(Not verified) Gabest" "c:\program files\k-lite codec pack\filters\shoutcastsource.ax"

+ "Subtitle Source" "DirectVobSub" "(Not verified) Gabest" "c:\windows\system32\dvobsub.ax"

+ "Switcher-In-Place" "MM Switcher" "(Not verified) Morgan Multimedia" "c:\windows\system32\mmswitch.ax"

+ "T" "VP6 Decompression Filter" "(Not verified) On2.com Inc." "c:\program files\k-lite codec pack\filters\vp6dec.ax"

+ "T" "VP7 Decompression Filter" "(Not verified) On2.com Inc." "c:\program files\k-lite codec pack\filters\vp7dec.ax"

+ "WavPack Audio Decoder" "WavPack Audio DirectShow Decoder" "(Not verified) -" "c:\program files\k-lite codec pack\filters\wavpackdsdecoder.ax"

+ "WavPack Audio Splitter" "WavPack Audio DirectShow Splitter" "(Not verified) -" "c:\program files\k-lite codec pack\filters\wavpackdssplitter.ax"

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL" "" "" ""

+ "ginamsi.dll" "" "" "c:\windows\system32\ginamsi.dll"

These Windows services are started:

Application Layer Gateway Service

COM+ Event System

CryptSvc

DCOM Server Process Launcher

DHCP Client

Distributed Link Tracking Client

DNS Client

Error Reporting Service

Event Log

Fast User Switching Compatibility

Help and Support

Infrared Monitor

IPSEC Services

Java Quick Starter

LexBce Server

Logical Disk Manager

Microsoft Antimalware Service

Network Connections

Network Location Awareness (NLA)

Plug and Play

Print Spooler

Protected Storage

Remote Access Connection Manager

Remote Procedure Call (RPC)

Remote Registry

Secondary Logon

Security Accounts Manager

Security Center

Server

Shell Hardware Detection

System Event Notification

System Restore Service

Task Scheduler

TCP/IP NetBIOS Helper

Telephony

Terminal Services

Themes

WebClient

Windows Audio

Windows Firewall/Internet Connection Sharing (ICS)

Windows Image Acquisition (WIA)

Windows Management Instrumentation

Windows Time

Wireless Zero Configuration

Workstation

The command completed successfully.

1.3Mega USB2.0 PC Cam

Adobe Flash Player 10 ActiveX

Adobe Reader 9.1

Adobe Shockwave Player

ArcSoft Panorama Maker 4

BitComet 0.60

BSPlayer

CCleaner

Citrix ICA Client

Cliprex Cdivx Player

Cliprex DS DVD Player

Compatibility Pack for the 2007 Office system

Disc2Phone

EA SPORTS online 2007

Elecard MPEG2 Decoder Package 2.0

ESET Online Scanner v3

FIFA 07

File Uploader

FlexType 2K

FormatFactory 2.00

HeadStrong WebClicker v2.56

HijackThis 2.0.2

HWiNFO32 Version 3.30

IZArc 3.4.1.6

Java 6 Update 10

Java 6 Update 7

Java SE Runtime Environment 6 Update 1

JPEG USB Video Camera Driver v0.81

K-Lite Mega Codec Pack 1.46

Lexmark Z600 Series

Malwarebytes' Anti-Malware

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 1

Microsoft .NET Framework 3.5

Microsoft .NET Framework 3.5

Microsoft Antimalware

Microsoft Compression Client Pack 1.0 for Windows XP

Microsoft Expression Web 2 MUI (English)

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft National Language Support Downlevel APIs

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office XP Professional

Microsoft Security Essentials

Microsoft Security Essentials

Microsoft User-Mode Driver Framework Feature Pack 1.0

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

Mp3 Knife 3.2

MP3 Player Utilities 4.09

MSXML 6.0 Parser (KB927977)

My Global Search Bar

Nikon Message Center

Nikon Transfer

Nimo Codecs Pack v5.0 (Remove Only)

OpenOffice.org Installer 1.0

QuickTime

Realtek AC'97 Audio

SA Dictionary 2004 Datacenter

SA Dictionary 2005 T2

SecureDoc

Security Update for Windows Media Player 9 (KB911565)

Security Update for Windows Media Player 9 (KB917734)

Skype™ 3.8

Sony Ericsson PC Suite 1.20.173

TreeSize Free V2.3.3

Tsunami-Filter-Pack Mini

UEFA Champions League 2006-2007

Veetle TV 0.9.15

VIA Audio Driver Setup Program

VIA Platform Device Manager

VIA/S3G Display Driver 6.14.10.0380

VobSub v2.23 (Remove Only)

Winamp

Windows Imaging Component

Windows Media Format 11 runtime

Windows Media Format 11 runtime

Windows Media Player 11

Windows Media Player 11

Windows XP Service Pack 3

WinRAR archiver

StartupList report, 12/14/2009, 6:15:19 PM

StartupList version: 1.52.2

Started from : D:\Program Files\Trend Micro\HijackThis\HijackThis.EXE

Detected: Windows XP SP3 (WinNT 5.01.2600)

Detected: Internet Explorer v7.00 (7.00.5730.0013)

* Using default options

==================================================

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Microsoft Security Essentials\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\tsnp2std.exe

C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

C:\Program Files\Microsoft Security Essentials\msseces.exe

D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

C:\Program Files\Skype\Phone\Skype.exe

D:\Program Files\Datecs\FlexType 2K\FType2K.exe

C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Common Files\Teleca Shared\Generic.exe

D:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe

C:\Program Files\Skype\Plugin Manager\SkypePM.exe

D:\GOM Player Portable.exe

C:\Program Files\internet explorer\iexplore.exe

D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:

[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]

FlexType 2K.lnk = D:\Program Files\Datecs\FlexType 2K\FType2K.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

VTTimer = VTTimer.exe

VTTrayp = VTtrayp.exe

tsnp2std = C:\WINDOWS\tsnp2std.exe

Nikon Transfer Monitor = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

MSSE = "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide

Adobe Reader Speed Launcher = "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

QuickTime Task = "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime

Sony Ericsson PC Suite = "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

--------------------------------------------------

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Skype = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

--------------------------------------------------

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]

=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*

SCRNSAVE.EXE=*INI section not found*

drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe

SCRNSAVE.EXE=*Registry value not found*

drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*

HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Enumerating Browser Helper Objects:

AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}

Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll - {22BF413B-C6D2-4d91-82A9-A0F997BA588C}

(no name) - C:\Program Files\Java\jre6\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}

JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

--------------------------------------------------

Enumerating Task Scheduler jobs:

MP Scheduled Scan.job

--------------------------------------------------

Enumerating Download Program Files:

[shockwave Flash Object]

InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx

CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

[{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]

CODEBASE = http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll

CDBurn: C:\WINDOWS\system32\SHELL32.dll

WebCheck: C:\WINDOWS\system32\webcheck.dll

SysTray: C:\WINDOWS\system32\stobject.dll

WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

--------------------------------------------------

End of report, 5,872 bytes

Report generated in 0.141 seconds

Command line options:

/verbose - to add additional info on each section

/complete - to include empty sections and unsuspicious data

/full - to include several rarely-important sections

/force9x - to include Win9x-only startups even if running on WinNT

/forcent - to include WinNT-only startups even if running on Win9x

/forceall - to include all Win9x and WinNT startups, regardless of platform

/history - to list version history only

Редактирано от bg_fenka (преглед на промените)

СТЪПКА 1

Стартирайте AutoRuns и от списъка с обектите махнете отметките пред следните редове:

+ "bdfdll" "" "" "File not found: C:\Program Files\Softwin\BitDefender9\bdfdll.sys"

+ "catchme" "" "" "File not found: C:\ComboFix\catchme.sys"

+ "dtscsi" "" "" "File not found: C:\WINDOWS\System32\Drivers\dtscsi.sys"

+ "rootrepeal" "" "" "File not found: C:\WINDOWS\system32\drivers\rootrepeal.sys"

+ "SVKP" "SVKP driver for NT" "(Not verified) AntiCracking" "c:\windows\system32\svkp.sys"

+ "SysProtDrv.sys" "" "" "File not found: C:\Documents and Settings\Administrator\Desktop\SysProt\SysProt\SysProtDrv.sys"

СТЪПКА 2

Стартирайте Notepad.exe и с copy/paste въведете:

On Error Resume Next

Set WshShell = WScript.CreateObject("WScript.Shell")

WshShell.RegDelete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL"

Message = "Your Windows Logon Screen is restored" & vbCR & vbCR

Message = Message & "You may need to log off/log on, or" & vbCR

Message = Message & "restart for the change to take effect."

X = MsgBox(Message, vbOKOnly, "Done")

Set WshShell = Nothing

Запазете файла с име fix.vbs и го стартирайте.

Потвърдете с YES за въпроса. (ако се появи такъв).

Изтеглете този инструмент.

Разархивирайте го и го стартирайте.

Рестартирайте машината.

Вижте дали има някаква промяна с черния прозорец.

  • Автор
' date='17 декември 2009 - 02:26 ' timestamp='1261009604' post='1583531']

СТЪПКА 1

Стартирайте AutoRuns и от списъка с обектите махнете отметките пред следните редове:

СТЪПКА 2

Стартирайте Notepad.exe и с copy/paste въведете:

Запазете файла с име fix.vbs и го стартирайте.

Потвърдете с YES за въпроса. (ако се появи такъв).

Изтеглете този инструмент.

Разархивирайте го и го стартирайте.

Рестартирайте машината.

Вижте дали има някаква промяна с черния прозорец.

Е ок де,ама като рестартирах и ми после ми дава да избирам лог..стария ми го няма,а излизат някви други които явно са правени, но който и да избера мн от нещата дето бяха на десктопа липсват..а има някви които не съм виждала от мн време и мислех че са изтрити.А на всичкото отгоре от xp май преминах на уиндоус 7, без въобще да ме попита.Иначе черния екран така го няма,ама как да си върна нещата от преди на десктопа

Е ок де,ама като рестартирах и ми после ми дава да избирам лог..стария ми го няма,а излизат някви други които явно са правени, но който и да избера мн от нещата дето бяха на десктопа липсват..а има някви които не съм виждала от мн време и мислех че са изтрити.А на всичкото отгоре от xp май преминах на уиндоус 7, без въобще да ме попита.Иначе черния екран така го няма,ама как да си върна нещата от преди на десктопа

Нещо не можах да ви разбера.

Какъв лог ви дава да избирате ?

И как така с един скрипт сте принали на изцяло нова Операционна Система - може ли по-подробно описание и една снимка на това което ви дава да изибрате и състоянието на десктопа.

  • Автор

Aми дано това клипчевъпреки не мн доброто си качество да те ориентира: http://4storing.com/shyvhj/952ee4c70c5cd7f971311f060a0ca480.html

В началото тия неща дето излизат за user name явно са използвани на компа от брат ми повечето,а 1-2 и от мен, но отдавна.Този юзър който е използван почти през цялото време ( administrator) обаче сега го няма в този списък.А от другите който и да избера на десктопа са само програми и някви стари картинки.Освен това положението е още по-лошо защото и в папките my pictures, my music и т.н. няма нищо с тези юзъри.А стартовото меню дето се показва не е ли това на windows 7, а не на xp ?

Не това, определено не е Windows 7, а си е Windows XP.

Странно, защото това го даваха като лечение на премигвашия черен екран...е добре го излекуваха.

Но акаунта (administrator) не би трябвало да е изтрит.

Пробвайте с десен бутон на My Computer => Manage => Local users and groups => users => вижте какво е положението.

Присъства ли там Administrator акаунта ?

  • Автор
' date='19 декември 2009 - 17:00 ' timestamp='1261234847' post='1585496']

Не това, определено не е Windows 7, а си е Windows XP.

Странно, защото това го даваха като лечение на премигвашия черен екран...е добре го излекуваха.

Но акаунта (administrator) не би трябвало да е изтрит.

Пробвайте с десен бутон на My Computer => Manage => Local users and groups => users => вижте какво е положението.

Присъства ли там Administrator акаунта ?

Да,там го има...но в началото на пускане на компа както се вижда и от клипчето го няма :)

Да,там го има...но в началото на пускане на компа както се вижда и от клипчето го няма :)

Стартирайте го и вижте дали има отметка пред "Account is disabled" и я махнете.

Потвърдете с Apply.

2dt5dva.jpg

Рестартирайте машината и вижте дали ще се появи сега.

Налага ми се да изляза, но съм попитал още хора и ще се опитаме да излезем от тази неприятна ситуация.

  • Автор
' date='19 декември 2009 - 19:48 ' timestamp='1261244909' post='1585615']

Стартирайте го и вижте дали има отметка пред "Account is disabled" и я махнете.

Потвърдете с Apply.

2dt5dva.jpg

Рестартирайте машината и вижте дали ще се появи сега.

Налага ми се да изляза, но съм попитал още хора и ще се опитаме да излезем от тази неприятна ситуация.

Ами нямаше отметка пред това :cool:

Въведете от Start => Run => control userpasswords2 => и вижте дали присъства в списъка.

Ако не пробвайте да го добавите с бутона ADD => въведете Administrator

  • Автор
' date='19 декември 2009 - 22:50 ' timestamp='1261255840' post='1585768']

Въведете от Start => Run => control userpasswords2 => и вижте дали присъства в списъка.

Ако не пробвайте да го добавите с бутона ADD => въведете Administrator

Има го, не се наложи да го добавям,но при пускане на pc-to продължава да го няма

Има го, не се наложи да го добавям,но при пускане на pc-to продължава да го няма

Пробвайте да изкарате скрития Administrator акаунт при зареждане с клавишната комбинация ALT+TAB.

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.