Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Maniac - моля за помощ на поредната жертва на Skype вируса [РЕШЕН]

Featured Replies

  • Автор

Такаааа

1. CombiFixa се инсталира, тръгна да инсталира и Recovery Console но тъй като не хвана интернет продължи и без нея.

2. На следващия етап засече Rootkit Activity и рестартна машината

3. Направи си всички stages и пак рестартира.

4. Изрева, че не може да намери Win32\Combofix.sys или нещо подобно и каза да не мърдам докато не генерира репорт.

Ето го и него:

ComboFix 10-01-13.0C - Administrator 01.2010 г. 18:23:34.3.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.511.295 [GMT 2:00]

Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

((((((((((((((((((((((((( Files Created from 2009-12-14 to 2010-01-14 )))))))))))))))))))))))))))))))

.

2010-01-14 15:47 . 2010-01-14 15:47 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe

2010-01-14 15:47 . 2010-01-14 15:47 -------- d-----w- c:\program files\TrendMicro

2010-01-14 15:46 . 2010-01-14 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Panda Security

2010-01-14 15:46 . 2010-01-14 15:46 -------- d-----w- c:\program files\Panda USB Vaccine

2010-01-11 20:04 . 2009-03-30 07:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys

2010-01-11 20:04 . 2009-02-13 09:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

2010-01-11 20:04 . 2009-02-13 09:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2010-01-11 20:04 . 2010-01-11 20:04 -------- d-----w- c:\program files\Avira

2010-01-11 20:04 . 2010-01-11 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira

2010-01-11 19:54 . 2010-01-11 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

2010-01-11 19:43 . 2010-01-11 19:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2010-01-11 19:43 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-01-11 19:43 . 2010-01-11 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-01-11 19:43 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-01-11 09:36 . 2010-01-11 09:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2010-01-06 18:13 . 2010-01-11 19:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-01-06 18:04 . 2010-01-11 13:06 -------- d-----w- C:\_OTL

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-01-13 16:21 . 2005-01-14 02:26 -------- d-----w- c:\program files\Broadcom

2010-01-13 15:26 . 2005-04-29 08:01 70320 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-01-11 19:41 . 2005-01-14 02:25 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-01-11 18:07 . 2005-04-20 12:07 -------- d-----w- c:\program files\WinISO

2010-01-11 18:07 . 2005-06-22 07:01 -------- d-----w- c:\program files\Microsoft.NET

2010-01-11 18:06 . 2005-03-23 18:34 -------- d-----w- c:\program files\Microsoft SQL Server

2010-01-11 18:05 . 2005-06-22 07:01 -------- d-----w- c:\program files\Microsoft ActiveSync

2010-01-11 18:05 . 2005-01-14 02:11 -------- d-----w- c:\program files\microsoft frontpage

2010-01-11 18:04 . 2005-01-14 02:20 -------- d-----w- c:\program files\Java

2010-01-11 18:04 . 2007-07-20 13:35 -------- d-----w- c:\program files\SA Dictionary 2005 T2

2010-01-11 18:04 . 2005-03-24 08:02 -------- d-----w- c:\program files\Satellite Forms EE Redist

2010-01-11 18:04 . 2005-03-26 09:45 -------- d-----w- c:\program files\SA

2010-01-11 18:04 . 2005-03-23 09:00 -------- d-----w- c:\program files\Program Shortcuts

2010-01-11 18:04 . 2006-11-15 01:01 -------- d-----w- c:\program files\MSXML 4.0

2010-01-11 18:04 . 2009-04-06 07:06 -------- d-----w- c:\program files\HP

2010-01-11 18:03 . 2006-04-14 06:24 -------- d-----w- c:\program files\Hewlett-Packard

2010-01-11 18:03 . 2005-03-23 17:49 -------- d-----w- c:\program files\D-Tools

2010-01-11 18:03 . 2005-06-03 14:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-01-11 18:03 . 2005-01-14 02:29 -------- d-----w- c:\program files\Compaq

2010-01-11 18:03 . 2005-01-14 02:28 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-01-11 18:03 . 2009-11-16 11:20 -------- d-----w- c:\program files\Common Files\Skype

2010-01-11 18:03 . 2009-03-30 06:54 -------- d-----w- c:\program files\Common Files\Softwin

2010-01-11 18:03 . 2005-03-24 08:02 -------- d-----w- c:\program files\Common Files\Satellite Forms EE

2010-01-11 18:03 . 2005-06-28 13:55 -------- d-----w- c:\program files\Common Files\PCSuite

2010-01-11 18:03 . 2005-06-28 13:55 -------- d-----w- c:\program files\Common Files\Nokia

2010-01-11 18:02 . 2006-11-01 11:05 -------- d-----w- c:\program files\Common Files\Lectra

2010-01-11 18:02 . 2005-01-14 02:20 -------- d-----w- c:\program files\Common Files\Java

2010-01-11 18:02 . 2005-01-14 02:25 -------- d-----w- c:\program files\Common Files\InstallShield

2010-01-11 18:02 . 2005-06-03 15:24 -------- d-----w- c:\program files\Common Files\Ahead

2010-01-11 18:02 . 2005-03-31 07:41 -------- d-----w- c:\program files\Common Files\Adobe

2010-01-11 18:02 . 2005-05-03 10:06 -------- d-----w- c:\program files\Citrix

2010-01-11 18:02 . 2005-03-30 08:23 -------- d-----w- c:\program files\ATI Technologies

2010-01-11 18:01 . 2005-01-14 02:27 -------- d-----w- c:\program files\HPQ

2010-01-11 18:01 . 2005-01-14 02:25 -------- d-----w- c:\program files\Analog Devices

2010-01-11 17:34 . 2007-09-23 09:10 -------- d-----w- c:\documents and settings\plovdiv\Application Data\Symantec

2010-01-11 17:34 . 2007-09-23 09:11 -------- d-----w- c:\documents and settings\plovdiv\Application Data\PC Suite

2010-01-11 17:34 . 2007-09-23 09:11 -------- d-----w- c:\documents and settings\plovdiv\Application Data\Hamachi

2010-01-11 17:34 . 2005-06-04 07:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems

2010-01-11 17:34 . 2005-01-14 02:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec

2010-01-11 17:33 . 2009-04-06 07:06 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY

2010-01-11 17:33 . 2006-04-14 07:44 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems

2010-01-11 17:28 . 2006-01-28 10:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Talkback

2010-01-11 17:28 . 2005-01-14 02:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec

2010-01-11 17:28 . 2005-11-01 14:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\SolidDocuments

2010-01-11 17:27 . 2005-08-19 15:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype

2010-01-11 17:27 . 2005-06-28 14:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia

2010-01-11 17:27 . 2005-06-28 13:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite

2010-01-11 17:27 . 2009-01-12 16:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Netscape

2010-01-11 17:26 . 2005-03-24 07:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\Microsoft Web Folders

2010-01-11 17:26 . 2009-04-06 07:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Hewlett-Packard

2010-01-11 17:26 . 2005-05-03 10:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\ICAClient

2010-01-11 17:26 . 2009-01-12 16:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Citrix

2009-11-16 11:21 . 2009-11-16 11:21 48 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-11-14 13:06 . 2009-11-14 13:06 59992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe

2005-08-16 14:04 . 2006-04-18 09:44 35840 -c--a-w- c:\program files\winbox.exe

2005-09-15 15:26 . 2006-01-28 10:13 94208 ----a-w- c:\program files\mozilla firefox\components\BrandRes.dll

2005-09-15 15:26 . 2006-01-28 10:13 150912 ----a-w- c:\program files\mozilla firefox\components\fullsoft.dll

2005-09-15 15:26 . 2006-01-28 10:13 41573 ----a-w- c:\program files\mozilla firefox\components\jar50.dll

2005-09-15 15:26 . 2006-01-28 10:13 48223 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll

2005-09-15 15:26 . 2006-01-28 10:13 8813 ----a-w- c:\program files\mozilla firefox\components\qfaservices.dll

2005-09-15 15:26 . 2006-01-28 10:13 160871 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll

2008-03-13 15:04 . 2008-03-13 15:04 27976 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll

2008-03-13 15:04 . 2008-03-13 15:04 125848 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll

2008-03-13 15:04 . 2008-03-13 15:04 46408 ----a-w- c:\program files\mozilla firefox\plugins\atmccli.dll

2008-03-13 15:04 . 2008-03-13 15:04 98712 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll

2007-08-06 09:07 . 2009-01-08 07:15 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll

2007-07-18 11:54 . 2009-01-08 07:15 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]

"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 0 (0x0)

"EnableInstallerDetection"= 0 (0x0)

"EnableSecureUIAPaths"= 0 (0x0)

"EnableVirtualization"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Hamachi (2).lnk]

path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\Hamachi (2).lnk

backup=c:\windows\pss\Hamachi (2).lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Skype.lnk]

path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\Skype.lnk

backup=c:\windows\pss\Skype.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk

backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hamachi.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hamachi.lnk

backup=c:\windows\pss\hamachi.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP LaserJet Director.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP LaserJet Director.lnk

backup=c:\windows\pss\HP LaserJet Director.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]

2009-09-24 14:11 2356088 ----a-w- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]

2004-08-12 18:10 339968 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]

2003-10-02 00:20 81920 ----a-w- c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP AutoIndexer]

2002-04-22 09:57 90112 ----a-w- c:\program files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP SchedIndexer]

2002-04-22 09:56 94208 ----a-w- c:\program files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 08:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetRefresh]

2003-11-20 18:01 525824 ----a-w- c:\program files\Compaq\SetRefresh\SetRefresh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]

2003-07-30 17:08 143360 ----a-w- c:\program files\Analog Devices\SoundMAX\SMTray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Palm\\HOTSYNC.EXE"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 pnpshark;pnpshark;c:\windows\system32\drivers\pnpshark.sys [02.10.2003 г. 03:16 119552]

R0 st3shark;st3shark;c:\windows\system32\drivers\st3shark.sys [27.9.2003 г. 14:37 5504]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11.1.2010 г. 22:04 108289]

S3 MA-660;Mobile Action MA-660 USB Infrared Adapter;c:\windows\system32\drivers\MA-660.sys [28.6.2005 г. 13:58 27136]

.

Contents of the 'Scheduled Tasks' folder

2010-01-14 c:\windows\Tasks\PandaUSBVaccine.job

- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2010-01-14 14:45]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.lectra.com/

mStart Page = hxxp://go.compaq.com/1Q00CDT/0409/bl7.asp

mSearch Bar = hxxp://go.compaq.com/1Q00CDT/0409/bl8.asp

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

Trusted Zone: lectra.com\gateway

DPF: {2E687AA8-B276-4910-BBFB-4E412F685379} - hxxp://shamal.eu.lectra.com/WebsiteViewerRoot/WebsiteViewer.cab

DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} - hxxps://gateway.lectra.com/lectra/cds/CGC/en/CSGProxy.cab

FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xhwszpi8.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://mirofashion.com/home.htm

FF - component: c:\program files\Mozilla Firefox\components\qfaservices.dll

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("backups.number_of_prefs_copies", 1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.link.open_newwindow.ui", 3); // prefs UI version

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");

c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.disable_window_open_feature.status", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("advanced.always_load_images", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.protocol-handler.external.help", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.connect.timeout", 30); // in seconds

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.request.timeout", 120); // in seconds

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN_show_punycode", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.image.imageBehavior", 0); // 0-Accept, 1-dontAcceptForeign, 2-dontUse

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.cookieBehavior", 3); // 0-Accept, 1-dontAcceptForeign, 2-dontUse, 3-p3p

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.id", "{ec8030f7-c20a-464f-9b0e-13a3a9e97384}");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.version",

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.extensions.version", "1.0");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.build_id",

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.autoUpdateEnabled", true); // Whether or not background app updates

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.url", "chrome://mozapps/locale/update/update.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.updatesAvailable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.lastUpdateDate", 0); // UTC offset when last App update was

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.performed", false); // Whether or not an update has been

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.autoUpdateEnabled", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.autoUpdate", false); // Automatically download and install

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.interval", 604800000); // Check for updates to Extensions and

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.lastUpdateDate", 0); // UTC offset when last Extension/Theme

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.severity.threshold", 5);// The number of pending Extension/Theme

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.count", 0); // The number of extension/theme/etc

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("update.interval", 3600000); // Check each of the above intervals

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("update.showSlidingNotification", true); // Windows-only slide-up taskbar

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("update.severity", 0);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("general.useragent.vendor", "Firefox");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("general.useragent.vendorSub",

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.update.resetHomepage", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.startup.homepage_override.1", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.turbo.enabled", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://browser/content/searchconfig.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://browser/content/searchconfig.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("update_notifications.enabled", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("update_notifications.provider.0.frequency", 7); // number of days

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.xul.error_pages.enabled", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("pfs.datasource.url", "chrome://mozapps/locale/plugins/plugins.properties");

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-fpvjmafnv - bxppeevpjgzylokccrric.exe

HKLM-Run-mtwhhs - bxppeevpjgzylokccrric.exe

HKLM-Run-qdmdjaitescs - c:\docume~1\TEMP\LOCALS~1\Temp\bxppeevpjgzylokccrric.exe

HKLM-Explorer_Run-oxcpreip - ypcxhcodskysaypc.exe

HKLM-Explorer_Run-bhjts - c:\docume~1\TEMP\LOCALS~1\Temp\ypcxhcodskysaypc.exe

MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe

MSConfigStartUp-BDMCon - c:\progra~1\Softwin\BITDEF~1\bdmcon.exe

MSConfigStartUp-BDNewsAgent - c:\progra~1\Softwin\BITDEF~1\bdnagent.exe

MSConfigStartUp-BDOESRV - c:\program files\Softwin\BitDefender8\\bdoesrv.exe

MSConfigStartUp-BDSwitchAgent - c:\program files\Softwin\BitDefender8\\bdswitch.exe

MSConfigStartUp-Google Update - c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

MSConfigStartUp-LogMeIn GUI - c:\program files\LogMeIn\x86\LogMeInSystray.exe

MSConfigStartUp-Orb - c:\program files\Winamp Remote\bin\OrbTray.exe

MSConfigStartUp-PrnStatusMX - c:\program files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe

MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe

MSConfigStartUp-WinampAgent - c:\program files\Winamp\wianmpa.exe

AddRemove-Adobe PageMaker 7.0 - c:\program files\Adobe\PageMaker 7.0\Uninst.isu

AddRemove-Adobe Photoshop 7.0 - c:\program files\Adobe\Photoshop 7.0\Uninst.isu

AddRemove-Bullzip PDF Printer_is1 - c:\program files\Bullzip\PDF Printer\unins000.exe

AddRemove-Gaberoff Koral German Dictionary 1.01 - c:\progra~1\GABERO~1\GABERO~1.0\UNWISE.EXE

AddRemove-GPL Ghostscript Lite_is1 - c:\program files\Bullzip\PDF Printer\gs\unins000.exe

AddRemove-Hamachi - c:\program files\Hamachi\uninstall.exe

AddRemove-Nero - Burning Rom!UninstallKey - c:\program files\Ahead\nero\uninstall\UNNERO.exe

AddRemove-RealVNC_is1 - c:\program files\RealVNC\VNC4\unins000.exe

AddRemove-SCREEN2EXE_is1 - c:\program files\SCREEN2EXE\unins000.exe

AddRemove-WinRAR archiver - c:\program files\WinRAR\uninstall.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-01-14 18:31

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82F75550]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf8539fc3

\Driver\ACPI -> ACPI.sys @ 0xf84accb8

\Driver\atapi -> 0x82f75550

IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Broadcom NetXtreme Gigabit Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xf8314ba0

PacketIndicateHandler -> NDIS.sys @ 0xf8303a0b

SendHandler -> NDIS.sys @ 0xf8317b31

Warning: possible MBR rootkit infection !

user & kernel MBR OK

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(772)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\Ati2evxx.exe

c:\program files\Avira\AntiVir Desktop\avguard.exe

c:\windows\system32\crypserv.exe

c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

c:\program files\Analog Devices\SoundMAX\SMAgent.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\Ati2evxx.exe

c:\program files\Panda USB Vaccine\USBVaccine.exe

c:\windows\system32\wscntfy.exe

c:\progra~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE

c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE

.

**************************************************************************

.

Completion time: 2010-01-14 18:36:45 - machine was rebooted

ComboFix-quarantined-files.txt 2010-01-14 16:36

Pre-Run: 59 334 676 480 bytes free

Post-Run: 59 369 304 064 bytes free

- - End Of File - - 6EA24ECAFE8F40D658A4BB38246A42CA

СТЪПКА 1

Изтеглете TDSSKiller и го разархивирайте на вашия десктоп.

Сега отворете Notepad.exe и въведете:

@ECHO OFF

START /WAIT TDSSKILLER.exe -l Logit.txt -v

START Logit.txt

del %0

Запазете файла с име - fix.bat

Трябва да изглежда ето така - batchfileimage.jpg

Стартирайте го и публикувайте лог файла.

СТЪПКА 2

Моля, изтеглете mbr.exe и го запазете C:\ . (Важно е да го направите!).

  • Отворете Start -> Run и напишете: cmd /c mbr.exe -t >log.txt&start log.txt
  • Потвърдете с клавишния бутон Enter
  • Излезте от Command Prompt

Публикувайте лог файла.

...

СТЪПКА 2

Моля, изтеглете mbr.exe и го запазете C:\ . (Важно е да го направите!).

  • Отворете Start -> Run и напишете: cmd /c mbr.exe -t >log.txt&start log.txt
  • Потвърдете с клавишния бутон Enter
  • Излезте от Command Prompt

Публикувайте лог файла.

Един ред от кода трябва малко да се пипне, защото така няма как да проработи:

cmd /c mbr.exe -t >log.txt&start log.txt

да стане:

cmd /c C:\mbr.exe -t >log.txt&start log.txt

Извинявам се за забележката, но предполагам, че е грешка от разсеяност.

Prompt-а, стартиран от Start -> Run -> cmd отива в pwd на текущият потребител.

Няма да споря, но бих попитал какво ще накара промпта да смени директорията с C:\?

Най-лесно е да се пробва!

ПС: Важна забележка е да се знае, че ако имате инсталирана и друга, различна от Win ОС, програмата ще ви посъветва:

Use "Recovery Console" command "fixmbr" to clear infection !

Това би затрило стартирането на други OS! Предупреждавам, за да няма изненадани.

Prompt-а, стартиран от Start -> Run -> cmd отива в pwd на текущият потребител.

Няма да споря, но бих попитал какво ще накара промпта да смени директорията с C:\?

Най-лесно е да се пробва!

ПС: Важна забележка е да се знае, че ако имате инсталирана и друга, различна от Win ОС, програмата ще ви посъветва:

Use "Recovery Console" command "fixmbr" to clear infection !

Това би затрило стартирането на други OS! Предупреждавам, за да няма изненадани.

Наистина не спорете. Командата е правилна и съм я използвам неведнъж:

http://forum.avira.com/wbb/index.php?page=Thread&postID=882515#post882515

Мога да разчитам логове на MBR.exe, но благодаря за включването.

В случая след използването на TDSSkiller не очаквам да видя в лога "Use "Recovery Console" command "fixmbr" to clear infection !".

Очаквам да бъдет деактиривани драйверите на Daemon Tools и да видя съобщение от рода на:

device: opened successfully

user: MBR read successfully

called modules: >>UNKNOWN [0x........]<<

kernel: MBR read successfully

user & kernel MBR OK

  • Автор

Здравейте с малко закъснение, но от време на време се налага и да хапва човек :lol6:

Доверявам се безрезервно на г-н Петков и ето двата лога:

За жалост вторият действително завърши с :

Use "Recovery Console" command "fixmbr" to clear infection !

Само да информирам, че втора ОС нямам на този комп.

Имам вече един Image.tib на машината с Acronis и backup на важните файлове. Мога да направя още един, ако трябва да се пуска fixmbr и каквото става да става вече sad.gif

Само да вмъкна и че от форума по моделистика, който си чета От време на време един колега беше предложил същото решение: Нов вирус Chudo

22:50:15:890 3776 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25

22:50:15:890 3776 ================================================================================

22:50:15:890 3776 SystemInfo:

22:50:15:890 3776 OS Version: 5.1.2600 ServicePack: 2.0

22:50:15:890 3776 Product type: Workstation

22:50:15:890 3776 ComputerName: HP24

22:50:15:890 3776 UserName: Administrator

22:50:15:890 3776 Windows directory: C:\windows

22:50:15:890 3776 Processor architecture: Intel x86

22:50:15:890 3776 Number of processors: 2

22:50:15:890 3776 Page size: 0x1000

22:50:15:890 3776 Boot type: Normal boot

22:50:15:890 3776 ================================================================================

22:50:15:890 3776 UnloadDriverW: NtUnloadDriver error 2

22:50:15:890 3776 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2

22:50:15:890 3776 MyNtCreateFileW: NtCreateFile(\??\C:\windows\system32\drivers\klmd.sys) returned status 00000000

22:50:15:937 3776 UtilityInit: KLMD drop and load success

22:50:15:937 3776 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)

22:50:15:937 3776 UtilityInit: KLMD open success

22:50:15:937 3776 UtilityInit: Initialize success

22:50:15:937 3776

22:50:15:937 3776 Scanning Services ...

22:50:15:937 3776 CreateRegParser: Registry parser init started

22:50:15:937 3776 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127

22:50:15:937 3776 CreateRegParser: DisableWow64Redirection error

22:50:15:937 3776 wfopen_ex: Trying to open file C:\windows\system32\config\system

22:50:15:937 3776 MyNtCreateFileW: NtCreateFile(\??\C:\windows\system32\config\system) returned status C0000043

22:50:15:937 3776 wfopen_ex: MyNtCreateFileW error 32 (C0000043)

22:50:15:937 3776 wfopen_ex: Trying to KLMD file open

22:50:15:937 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\config\system

22:50:15:937 3776 wfopen_ex: File opened ok (Flags 2)

22:50:15:937 3776 CreateRegParser: HIVE_ADAPTER(C:\windows\system32\config\system) init success: 9C4888

22:50:15:937 3776 wfopen_ex: Trying to open file C:\windows\system32\config\software

22:50:15:937 3776 MyNtCreateFileW: NtCreateFile(\??\C:\windows\system32\config\software) returned status C0000043

22:50:15:937 3776 wfopen_ex: MyNtCreateFileW error 32 (C0000043)

22:50:15:937 3776 wfopen_ex: Trying to KLMD file open

22:50:15:937 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\config\software

22:50:15:937 3776 wfopen_ex: File opened ok (Flags 2)

22:50:15:937 3776 CreateRegParser: HIVE_ADAPTER(C:\windows\system32\config\software) init success: 9C4930

22:50:15:937 3776 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127

22:50:15:937 3776 CreateRegParser: EnableWow64Redirection error

22:50:15:937 3776 CreateRegParser: RegParser init completed

22:50:16:468 3776 GetAdvancedServicesInfo: Raw services enum returned 350 services

22:50:16:468 3776 fclose_ex: Trying to close file C:\windows\system32\config\system

22:50:16:468 3776 fclose_ex: Trying to close file C:\windows\system32\config\software

22:50:16:468 3776

22:50:16:468 3776 Scanning Kernel memory ...

22:50:16:468 3776 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk

22:50:16:468 3776 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 82F5BB80

22:50:16:468 3776 DetectCureTDL3: KLMD_GetDeviceObjectList returned 6 DevObjects

22:50:16:468 3776

22:50:16:468 3776 DetectCureTDL3: DEVICE_OBJECT: 829106E0

22:50:16:468 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 829106E0

22:50:16:468 3776 KLMD_ReadMem: Trying to ReadMemory 0x829106E0[0x38]

22:50:16:468 3776 DetectCureTDL3: DRIVER_OBJECT: 82F5BB80

22:50:16:468 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F5BB80[0xA8]

22:50:16:468 3776 KLMD_ReadMem: Trying to ReadMemory 0xE1009210[0x18]

22:50:16:468 3776 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

22:50:16:468 3776 DetectCureTDL3: IrpHandler (0) addr: F853BC30

22:50:16:468 3776 DetectCureTDL3: IrpHandler (1) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (2) addr: F853BC30

22:50:16:468 3776 DetectCureTDL3: IrpHandler (3) addr: F8535D9B

22:50:16:468 3776 DetectCureTDL3: IrpHandler (4) addr: F8535D9B

22:50:16:468 3776 DetectCureTDL3: IrpHandler (5) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (6) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (7) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (8) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (9) addr: F8536366

22:50:16:468 3776 DetectCureTDL3: IrpHandler (10) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (11) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (12) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (13) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (14) addr: F853644D

22:50:16:468 3776 DetectCureTDL3: IrpHandler (15) addr: F8539FC3

22:50:16:468 3776 DetectCureTDL3: IrpHandler (16) addr: F8536366

22:50:16:468 3776 DetectCureTDL3: IrpHandler (17) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (18) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (19) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (20) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (21) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (22) addr: F8537EF3

22:50:16:468 3776 DetectCureTDL3: IrpHandler (23) addr: F853CA24

22:50:16:468 3776 DetectCureTDL3: IrpHandler (24) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (25) addr: 804F9709

22:50:16:468 3776 DetectCureTDL3: IrpHandler (26) addr: 804F9709

22:50:16:468 3776 TDL3_FileDetect: Processing driver: Disk

22:50:16:468 3776 TDL3_FileDetect: Processing driver file: C:\windows\system32\DRIVERS\disk.sys

22:50:16:468 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\DRIVERS\disk.sys

22:50:16:484 3776 TDL3_FileDetect: C:\windows\system32\DRIVERS\disk.sys - Verdict: Clean

22:50:16:484 3776

22:50:16:484 3776 DetectCureTDL3: DEVICE_OBJECT: 82677AB8

22:50:16:484 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82677AB8

22:50:16:484 3776 DetectCureTDL3: DEVICE_OBJECT: 8287D920

22:50:16:484 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8287D920

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x8287D920[0x38]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT: 82E84A60

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82E84A60[0xA8]

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0xE12A8188[0x1E]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

22:50:16:484 3776 DetectCureTDL3: IrpHandler (0) addr: F8842218

22:50:16:484 3776 DetectCureTDL3: IrpHandler (1) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (2) addr: F8842218

22:50:16:484 3776 DetectCureTDL3: IrpHandler (3) addr: F884223C

22:50:16:484 3776 DetectCureTDL3: IrpHandler (4) addr: F884223C

22:50:16:484 3776 DetectCureTDL3: IrpHandler (5) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (6) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (7) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (8) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (9) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (10) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (11) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (12) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (13) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (14) addr: F8842180

22:50:16:484 3776 DetectCureTDL3: IrpHandler (15) addr: F883D9E6

22:50:16:484 3776 DetectCureTDL3: IrpHandler (16) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (17) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (18) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (19) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (20) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (21) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (22) addr: F88415F0

22:50:16:484 3776 DetectCureTDL3: IrpHandler (23) addr: F883FA6E

22:50:16:484 3776 DetectCureTDL3: IrpHandler (24) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (25) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (26) addr: 804F9709

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0xF883EF26[0x400]

22:50:16:484 3776 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

22:50:16:484 3776 TDL3_FileDetect: Processing driver: USBSTOR

22:50:16:484 3776 TDL3_FileDetect: Processing driver file: C:\windows\system32\DRIVERS\USBSTOR.SYS

22:50:16:484 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\DRIVERS\USBSTOR.SYS

22:50:16:484 3776 TDL3_FileDetect: C:\windows\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean

22:50:16:484 3776

22:50:16:484 3776 DetectCureTDL3: DEVICE_OBJECT: 82620418

22:50:16:484 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82620418

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82620418[0x38]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT: 82F5BB80

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F5BB80[0xA8]

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0xE1009210[0x18]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

22:50:16:484 3776 DetectCureTDL3: IrpHandler (0) addr: F853BC30

22:50:16:484 3776 DetectCureTDL3: IrpHandler (1) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (2) addr: F853BC30

22:50:16:484 3776 DetectCureTDL3: IrpHandler (3) addr: F8535D9B

22:50:16:484 3776 DetectCureTDL3: IrpHandler (4) addr: F8535D9B

22:50:16:484 3776 DetectCureTDL3: IrpHandler (5) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (6) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (7) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (8) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (9) addr: F8536366

22:50:16:484 3776 DetectCureTDL3: IrpHandler (10) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (11) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (12) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (13) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (14) addr: F853644D

22:50:16:484 3776 DetectCureTDL3: IrpHandler (15) addr: F8539FC3

22:50:16:484 3776 DetectCureTDL3: IrpHandler (16) addr: F8536366

22:50:16:484 3776 DetectCureTDL3: IrpHandler (17) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (18) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (19) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (20) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (21) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (22) addr: F8537EF3

22:50:16:484 3776 DetectCureTDL3: IrpHandler (23) addr: F853CA24

22:50:16:484 3776 DetectCureTDL3: IrpHandler (24) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (25) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (26) addr: 804F9709

22:50:16:484 3776 TDL3_FileDetect: Processing driver: Disk

22:50:16:484 3776 TDL3_FileDetect: Processing driver file: C:\windows\system32\DRIVERS\disk.sys

22:50:16:484 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\DRIVERS\disk.sys

22:50:16:484 3776 TDL3_FileDetect: C:\windows\system32\DRIVERS\disk.sys - Verdict: Clean

22:50:16:484 3776

22:50:16:484 3776 DetectCureTDL3: DEVICE_OBJECT: 82659AB8

22:50:16:484 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82659AB8

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82659AB8[0x38]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT: 82F5BB80

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F5BB80[0xA8]

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0xE1009210[0x18]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

22:50:16:484 3776 DetectCureTDL3: IrpHandler (0) addr: F853BC30

22:50:16:484 3776 DetectCureTDL3: IrpHandler (1) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (2) addr: F853BC30

22:50:16:484 3776 DetectCureTDL3: IrpHandler (3) addr: F8535D9B

22:50:16:484 3776 DetectCureTDL3: IrpHandler (4) addr: F8535D9B

22:50:16:484 3776 DetectCureTDL3: IrpHandler (5) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (6) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (7) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (8) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (9) addr: F8536366

22:50:16:484 3776 DetectCureTDL3: IrpHandler (10) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (11) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (12) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (13) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (14) addr: F853644D

22:50:16:484 3776 DetectCureTDL3: IrpHandler (15) addr: F8539FC3

22:50:16:484 3776 DetectCureTDL3: IrpHandler (16) addr: F8536366

22:50:16:484 3776 DetectCureTDL3: IrpHandler (17) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (18) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (19) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (20) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (21) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (22) addr: F8537EF3

22:50:16:484 3776 DetectCureTDL3: IrpHandler (23) addr: F853CA24

22:50:16:484 3776 DetectCureTDL3: IrpHandler (24) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (25) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (26) addr: 804F9709

22:50:16:484 3776 TDL3_FileDetect: Processing driver: Disk

22:50:16:484 3776 TDL3_FileDetect: Processing driver file: C:\windows\system32\DRIVERS\disk.sys

22:50:16:484 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\DRIVERS\disk.sys

22:50:16:484 3776 TDL3_FileDetect: C:\windows\system32\DRIVERS\disk.sys - Verdict: Clean

22:50:16:484 3776

22:50:16:484 3776 DetectCureTDL3: DEVICE_OBJECT: 82FD22F0

22:50:16:484 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82FD22F0

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82FD22F0[0x38]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT: 82F5BB80

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F5BB80[0xA8]

22:50:16:484 3776 KLMD_ReadMem: Trying to ReadMemory 0xE1009210[0x18]

22:50:16:484 3776 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

22:50:16:484 3776 DetectCureTDL3: IrpHandler (0) addr: F853BC30

22:50:16:484 3776 DetectCureTDL3: IrpHandler (1) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (2) addr: F853BC30

22:50:16:484 3776 DetectCureTDL3: IrpHandler (3) addr: F8535D9B

22:50:16:484 3776 DetectCureTDL3: IrpHandler (4) addr: F8535D9B

22:50:16:484 3776 DetectCureTDL3: IrpHandler (5) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (6) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (7) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (8) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (9) addr: F8536366

22:50:16:484 3776 DetectCureTDL3: IrpHandler (10) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (11) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (12) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (13) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (14) addr: F853644D

22:50:16:484 3776 DetectCureTDL3: IrpHandler (15) addr: F8539FC3

22:50:16:484 3776 DetectCureTDL3: IrpHandler (16) addr: F8536366

22:50:16:484 3776 DetectCureTDL3: IrpHandler (17) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (18) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (19) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (20) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (21) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (22) addr: F8537EF3

22:50:16:484 3776 DetectCureTDL3: IrpHandler (23) addr: F853CA24

22:50:16:484 3776 DetectCureTDL3: IrpHandler (24) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (25) addr: 804F9709

22:50:16:484 3776 DetectCureTDL3: IrpHandler (26) addr: 804F9709

22:50:16:484 3776 TDL3_FileDetect: Processing driver: Disk

22:50:16:484 3776 TDL3_FileDetect: Processing driver file: C:\windows\system32\DRIVERS\disk.sys

22:50:16:484 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\DRIVERS\disk.sys

22:50:16:500 3776 TDL3_FileDetect: C:\windows\system32\DRIVERS\disk.sys - Verdict: Clean

22:50:16:500 3776

22:50:16:500 3776 DetectCureTDL3: DEVICE_OBJECT: 82F74AB8

22:50:16:500 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F74AB8

22:50:16:500 3776 DetectCureTDL3: DEVICE_OBJECT: 82F409E8

22:50:16:500 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F409E8

22:50:16:500 3776 DetectCureTDL3: DEVICE_OBJECT: 82F3F940

22:50:16:500 3776 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F3F940

22:50:16:500 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F3F940[0x38]

22:50:16:500 3776 DetectCureTDL3: DRIVER_OBJECT: 82F42030

22:50:16:500 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F42030[0xA8]

22:50:16:500 3776 KLMD_ReadMem: Trying to ReadMemory 0xE1864680[0x1A]

22:50:16:500 3776 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi

22:50:16:500 3776 DetectCureTDL3: IrpHandler (0) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (1) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (2) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (3) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (4) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (5) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (6) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (7) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (8) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (9) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (10) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (11) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (12) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (13) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (14) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (15) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (16) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (17) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (18) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (19) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (20) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (21) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (22) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (23) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (24) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (25) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: IrpHandler (26) addr: 82F75550

22:50:16:500 3776 DetectCureTDL3: All IRP handlers pointed to one addr: 82F75550

22:50:16:500 3776 KLMD_ReadMem: Trying to ReadMemory 0x82F75550[0x400]

22:50:16:500 3776 TDL3_IrpHookDetect: CheckParameters: 0, 0, 0, 0, 0, 0

22:50:16:500 3776 KLMD_ReadMem: Trying to ReadMemory 0xF84217C6[0x400]

22:50:16:500 3776 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

22:50:16:500 3776 TDL3_FileDetect: Processing driver: atapi

22:50:16:500 3776 TDL3_FileDetect: Processing driver file: C:\windows\system32\DRIVERS\atapi.sys

22:50:16:500 3776 KLMD_CreateFileW: Trying to open file C:\windows\system32\DRIVERS\atapi.sys

22:50:16:500 3776 TDL3_FileDetect: C:\windows\system32\DRIVERS\atapi.sys - Verdict: Clean

22:50:16:500 3776

22:50:16:500 3776 Completed

22:50:16:500 3776

22:50:16:500 3776 Results:

22:50:16:500 3776 Memory objects infected / cured / cured on reboot: 0 / 0 / 0

22:50:16:500 3776 Registry objects infected / cured / cured on reboot: 0 / 0 / 0

22:50:16:500 3776 File objects infected / cured / cured on reboot: 0 / 0 / 0

22:50:16:500 3776

22:50:16:500 3776 MyNtCreateFileW: NtCreateFile(\??\C:\windows\system32\drivers\klmd.sys) returned status 00000000

22:50:16:500 3776 UtilityDeinit: KLMD(ARK) unloaded successfully

--------------------------------------------------------------------------------------

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82F75550]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\atapi -> 0x82f75550

Warning: possible MBR rootkit infection !

user & kernel MBR OK

Use "Recovery Console" command "fixmbr" to clear infection !

Редактирано от mannesmann (преглед на промените)

  • Автор

Ухаааа ... деинсталирах Daemon Tools, RESTART и ето го новия лог:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys

kernel: MBR read successfully

user & kernel MBR OK

Има ли надежда !? ... да вадя ли бирата !? :cool:

За жалост интернета още го няма :(

Софтуера ми клиент, който се опитва да се вържи към SQL Servera дава следната грешка:

:6[Microsoft][ODBC SQL Server Driver][TCP/IP Sockets]Specified SQL server not found.:11001

[Microsoft][ODBC SQL Server Driver][TCP/IP Sockets]ConnectionOpen (Connect()).

Това е редовната грешка като сървъра му е дръпната мрежата, но интересното е, че успявам да го пингна и него на 192.168.29.200 Болната машина е на 192.168.29.101 :nono:

Забелязах и че при опит да се updatne Avira дава следното:

Scan for updates ...

Transmited: започна да върти някви Кабайти

Remaining: пак върти някви кабайти

... и тъкмо ми светнаха очите и хоп update.exe encountered a problem and need to close.

Същото става и с Malwarebytes като се опитам да го ъпдейтна!

Редактирано от mannesmann (преглед на промените)

Надежда винаги има. :cool:

Изтеглете нова версия на OTL.exe

Направете следните настройки:

f1a78i.jpg

Под секцията "Custom Scans/Fixes" с copy/paste въведете следната информация:

netsvcs

msconfig

safebootminimal

safebootnetwork

activex

drivers32

%SYSTEMDRIVE%\*.*

/md5start

eventlog.dll

scecli.dll

netlogon.dll

cngaudit.dll

sceclt.dll

ntelogon.dll

logevent.dll

iaStor.sys

nvstor.sys

atapi.sys

IdeChnDr.sys

viasraid.sys

AGP440.sys

vaxscsi.sys

nvatabus.sys

viamraid.sys

nvata.sys

nvgts.sys

iastorv.sys

ViPrt.sys

eNetHook.dll

ahcix86.sys

KR10N.sys

nvstor32.sys

ahcix86s.sys

nvrd32.sys

/md5stop

%systemroot%\*. /mp /s

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%PROGRAMFILES%\*.

%userprofile%\Desktop\*.*

%userprofile%\Desktop\*.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

Натиснете бутона Run Scan.

Публикувайте резултатите.

  • Автор

Пу д**ба и късмета си д**ба ... жената е на 50 метра от мен в бар Мармалад в Пловдив и слуша концерта на Белослава, а аз сканирам за вируси и умирам от жажда :cool:

Ето го и лога ...

OTL logfile created on: 15.1.2010 г. 00:33:05 - Run 2

OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Administrator\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

511,00 Mb Total Physical Memory | 309,00 Mb Available Physical Memory | 60,00% Memory free

1,00 Gb Paging File | 1,00 Gb Available in Paging File | 83,00% Paging File free

Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files

Drive C: | 74,52 Gb Total Space | 55,29 Gb Free Space | 74,19% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: HP24

Current User Name: Administrator

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\Panda USB Vaccine\USBVaccine.exe (Panda Security)

PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

PRC - C:\WINDOWS\system32\ati2evxx.exe ()

PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)

PRC - C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)

PRC - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe (Nokia.)

PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)

PRC - C:\WINDOWS\system32\Crypserv.exe ()

========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (WinVNC4) -- File not found

SRV - (RetroLauncher) -- File not found

SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

SRV - (ATI Smart) -- C:\WINDOWS\system32\ati2sgag.exe ()

SRV - (Ati HotKey Poller) -- C:\WINDOWS\system32\ati2evxx.exe ()

SRV - (Irmon) -- C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)

SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

SRV - (SoundMAX Agent Service (default)) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)

SRV - (Crypkey License) -- C:\windows\System32\Crypserv.exe ()

========== Driver Services (SafeList) ==========

DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)

DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)

DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)

DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)

DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)

DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)

DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (PxHelp20) -- C:\windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)

DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)

DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)

DRV - (slabser) -- C:\WINDOWS\system32\drivers\slabser.sys (MCCI)

DRV - (slabbus) USB Cable DCU-11 driver (WDM) -- C:\WINDOWS\system32\drivers\slabbus.sys (MCCI)

DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)

DRV - (wceusbsh) -- C:\WINDOWS\system32\drivers\wceusbsh.sys (Microsoft Corporation)

DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)

DRV - (iAimFP4) -- C:\WINDOWS\system32\drivers\wVchNTxx.sys (Intel® Corporation)

DRV - (iAimFP3) -- C:\WINDOWS\system32\drivers\wSiINTxx.sys (Intel® Corporation)

DRV - (iAimTV5) -- C:\WINDOWS\system32\drivers\wATV10nt.sys (Intel® Corporation)

DRV - (iAimTV4) -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys (Intel® Corporation)

DRV - (iAimTV6) -- C:\WINDOWS\system32\drivers\wATV06nt.sys (Intel® Corporation)

DRV - (iAimTV3) -- C:\WINDOWS\system32\drivers\wATV04nt.sys (Intel® Corporation)

DRV - (iAimTV1) -- C:\WINDOWS\system32\drivers\wATV02NT.sys (Intel® Corporation)

DRV - (iAimTV0) -- C:\WINDOWS\system32\drivers\wATV01nt.sys (Intel® Corporation)

DRV - (iAimFP7) -- C:\WINDOWS\system32\drivers\wADV09NT.sys (Intel® Corporation)

DRV - (iAimFP5) -- C:\WINDOWS\system32\drivers\wADV07nt.sys (Intel® Corporation)

DRV - (iAimFP6) -- C:\WINDOWS\system32\drivers\wADV08NT.sys (Intel® Corporation)

DRV - (i81x) -- C:\WINDOWS\system32\drivers\i81xnt5.sys (Intel® Corporation)

DRV - (iAimFP0) -- C:\WINDOWS\system32\drivers\wADV01nt.sys (Intel® Corporation)

DRV - (iAimFP1) -- C:\WINDOWS\system32\drivers\wADV02NT.sys (Intel® Corporation)

DRV - (iAimFP2) -- C:\WINDOWS\system32\drivers\wADV05NT.sys (Intel® Corporation)

DRV - (EIO) -- C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)

DRV - (smwdm) -- C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)

DRV - (Blfp) -- C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)

DRV - (aeaudio) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)

DRV - (MA-660) -- C:\WINDOWS\system32\drivers\MA-660.sys (Mobile Action Tech. Inc.)

DRV - (adpu320) -- C:\windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)

DRV - (Symmpi) -- C:\windows\system32\DRIVERS\symmpi.sys (LSI Logic)

DRV - (sym_u3) -- C:\windows\system32\DRIVERS\sym_u3.sys (LSI Logic)

DRV - (sym_hi) -- C:\windows\system32\DRIVERS\sym_hi.sys (LSI Logic)

DRV - (symc8xx) -- C:\windows\system32\DRIVERS\symc8xx.sys (LSI Logic)

DRV - (symc810) -- C:\windows\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)

DRV - (SONYPVU1) Sony USB Filter Driver (SONYPVU1) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)

DRV - (ac97intc) Intel® 82801 Audio Driver Install Service (WDM) -- C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)

DRV - (E100B) Intel® -- C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)

DRV - (Sentinel) -- C:\windows\System32\Drivers\SENTINEL.SYS ()

DRV - (NetworkX) -- C:\windows\system32\ckldrv.sys ()

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.compaq.com/1Q00CDT/0409/bl7.asp

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1073245545-1349789880-22627367-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.lectra.com/

IE - HKU\S-1-5-21-1073245545-1349789880-22627367-500\S-1-5-21-1073245545-1349789880-22627367-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.startup.homepage: "http://mirofashion.com/home.htm"

FF - HKLM\software\mozilla\Mozilla Firefox 1.0.6\Extensions\\Components: C:\Program Files\Mozilla Firefox\Components [2010.01.11 20:04:35 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 1.0.6\Extensions\\Plugins: C:\Program Files\Mozilla Firefox\Plugins [2010.01.11 20:04:38 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 1.0.7\Extensions\\Components: C:\Program Files\Mozilla Firefox\Components [2010.01.11 20:04:35 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 1.0.7\Extensions\\Plugins: C:\Program Files\Mozilla Firefox\Plugins [2010.01.11 20:04:38 | 00,000,000 | ---D | M]

[2010.01.11 19:26:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xhwszpi8.default\extensions

[2010.01.11 19:26:59 | 00,000,000 | ---D | M] (Firefox (default)) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xhwszpi8.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2010.01.11 20:04:37 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2010.01.11 18:26:23 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions

[2010.01.11 20:04:36 | 00,000,000 | ---D | M] (Firefox (default)) -- C:\Program Files\Mozilla Firefox\defaults\profile\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2005.09.15 17:26:00 | 00,094,208 | ---- | M] () -- C:\Program Files\Mozilla Firefox\components\BrandRes.dll

[2005.09.15 17:26:00 | 00,150,912 | ---- | M] (Full Circle Software, Inc.) -- C:\Program Files\Mozilla Firefox\components\fullsoft.dll

[2005.09.15 17:26:00 | 00,041,573 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jar50.dll

[2005.09.15 17:26:00 | 00,048,223 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jsd3250.dll

[2005.09.15 17:26:00 | 00,008,813 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\qfaservices.dll

[2005.09.15 17:26:00 | 00,160,871 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\xpinstal.dll

[2008.03.13 17:04:15 | 00,027,976 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll

[2008.03.13 17:04:15 | 00,125,848 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll

[2008.03.13 17:04:41 | 00,046,408 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\atmccli.dll

[2008.03.13 17:04:47 | 00,098,712 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll

[2008.03.13 17:04:13 | 00,060,824 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll

[2009.02.19 11:38:00 | 02,633,728 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npRACtrl.dll

[2007.08.06 11:07:00 | 00,008,784 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ractrlkeyhook.dll

[2007.07.18 13:54:00 | 00,245,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\unicows.dll

[2005.09.15 17:26:00 | 00,000,680 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.png

[2005.09.15 17:26:00 | 00,000,735 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.src

[2005.09.15 17:26:00 | 00,000,356 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.png

[2005.09.15 17:26:00 | 00,000,976 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.src

[2005.09.15 17:26:00 | 00,000,557 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dictionary.png

[2005.09.15 17:26:00 | 00,000,692 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dictionary.src

[2005.09.15 17:26:00 | 00,000,210 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.gif

[2005.09.15 17:26:00 | 00,001,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.src

[2005.09.15 17:26:00 | 00,001,076 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.gif

[2010.01.05 14:38:10 | 00,000,750 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.src

[2005.09.15 17:26:00 | 00,000,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.gif

[2005.09.15 17:26:00 | 00,001,098 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.src

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)

O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\windows\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1073245545-1349789880-22627367-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1073245545-1349789880-22627367-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-1073245545-1349789880-22627367-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\S-1-5-21-1073245545-1349789880-22627367-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-1073245545-1349789880-22627367-500_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-21-1073245545-1349789880-22627367-500\..Trusted Domains: lectra.com ([gateway] https in Trusted sites)

O15 - HKU\S-1-5-21-1073245545-1349789880-22627367-500\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} https://gateway.lectra.com/lectra/cds/ICAWEB/default/ica32/ica32t.exe (Citrix ICA Client)

O16 - DPF: {2E687AA8-B276-4910-BBFB-4E412F685379} http://shamal.eu.lectra.com/WebsiteViewerRoot/WebsiteViewer.cab (CWebsiteViewer Object)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_03)

O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} http://community.webshots.com/html/WSPhotoUploader.CAB (Webshots Photo Uploader)

O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_03)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://lectra-eu.webex.com/client/T26L/webex/ieatgpc.cab (GpcContainer Class)

O16 - DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} https://gateway.lectra.com/lectra/cds/CGC/en/CSGProxy.cab (Gateway Client for MetaFrame)

O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\windows\System32\ati2evxx.dll ()

O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\windows\System32\igfxsrvc.dll (Intel Corporation)

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found

NetSvcs: Ias - C:\WINDOWS\system32\ias [2010.01.11 19:49:25 | 00,000,000 | ---D | M]

NetSvcs: Iprip - File not found

NetSvcs: Irmon - C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Hamachi (2).lnk - C:\PROGRA~1\Hamachi\hamachi.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Skype.lnk - C:\PROGRA~1\Skype\Phone\Skype.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk - C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\acrotray.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hamachi.lnk - C:\PROGRA~1\Hamachi\hamachi.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP LaserJet Director.lnk - C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe - ()

MsConfig - StartUpReg: AdobeUpdater - hkey= - key= - C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)

MsConfig - StartUpReg: ATIPTA - hkey= - key= - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)

MsConfig - StartUpReg: DAEMON Tools-1033 - hkey= - key= - C:\Program Files\D-Tools\daemon.exe File not found

MsConfig - StartUpReg: HP AutoIndexer - hkey= - key= - C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe (Hewlett-Packard)

MsConfig - StartUpReg: HP SchedIndexer - hkey= - key= - C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe (Hewlett-Packard)

MsConfig - StartUpReg: MSMSGS - hkey= - key= - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - File not found

MsConfig - StartUpReg: SetRefresh - hkey= - key= - C:\Program Files\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)

MsConfig - StartUpReg: Smapp - hkey= - key= - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)

MsConfig - State: "system.ini" - 0

MsConfig - State: "win.ini" - 0

MsConfig - State: "bootini" - 0

MsConfig - State: "services" - 0

MsConfig - State: "startup" - 2

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: sermouse.sys - Driver

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vga.sys - Driver

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: sermouse.sys - Driver

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: vga.sys - Driver

SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)

ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)

ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4

ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation

ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java

ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack

ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe

ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)

ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring

ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow

ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx

ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help

ActiveX: {4b218e3e-bc98-4770-93d3-2731b9329278} - %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes

ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6

ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW

ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools

ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements

ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player

ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access

ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework

ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders

ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll

ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe

ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

ActiveX: {8D1D0E9A-C799-4D28-9E29-0061D1E66E43} - Microsoft .NET Framework 1.1 Hotfix (KB928366)

ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding

ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -

ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts

ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework

ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler

ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1

ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player

ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help

ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface

ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP

ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

Drivers32: MIDI1 - C:\windows\System32\Syncor11.dll (SoundMAX)

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.sl_anet - C:\windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)

Drivers32: msacm.trspch - C:\windows\System32\tssoft32.acm (DSP GROUP, INC.)

Drivers32: SENTINEL - C:\windows\System32\SNTI386.DLL ()

Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)

Drivers32: VIDC.MP42 - C:\windows\System32\MPG4C32.DLL (Microsoft Corporation)

Drivers32: vidc.MP43 - C:\windows\System32\MPG4C32.DLL (Microsoft Corporation)

Drivers32: VIDC.MPG4 - C:\windows\System32\MPG4C32.DLL (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2010.01.15 00:31:41 | 00,544,256 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2010.01.14 22:47:45 | 00,000,000 | -HSD | C] -- C:\RECYCLER

[2010.01.14 18:36:47 | 00,000,000 | ---D | C] -- C:\windows\temp

[2010.01.14 18:19:38 | 00,212,480 | ---- | C] (SteelWerX) -- C:\windows\SWXCACLS.exe

[2010.01.14 18:19:38 | 00,161,792 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe

[2010.01.14 18:19:38 | 00,136,704 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe

[2010.01.14 18:19:38 | 00,031,232 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe

[2010.01.14 18:19:21 | 00,000,000 | ---D | C] -- C:\Qoobox

[2010.01.14 17:47:03 | 00,000,000 | ---D | C] -- C:\Program Files\TrendMicro

[2010.01.14 17:46:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Panda Security

[2010.01.14 17:46:26 | 00,000,000 | ---D | C] -- C:\Program Files\Panda USB Vaccine

[2010.01.13 08:44:14 | 00,176,392 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe

[2010.01.11 22:04:59 | 00,096,104 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avipbb.sys

[2010.01.11 22:04:59 | 00,056,816 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avgntflt.sys

[2010.01.11 22:04:59 | 00,045,416 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avgntdd.sys

[2010.01.11 22:04:59 | 00,022,360 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\avgntmgr.sys

[2010.01.11 22:04:58 | 00,028,520 | ---- | C] (Avira GmbH) -- C:\windows\System32\drivers\ssmdrv.sys

[2010.01.11 22:04:58 | 00,000,000 | ---D | C] -- C:\Program Files\Avira

[2010.01.11 22:04:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira

[2010.01.11 21:54:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files

[2010.01.11 21:43:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes

[2010.01.11 21:43:37 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2010.01.11 21:43:34 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2010.01.11 21:43:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2010.01.11 19:34:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2010.01.11 18:26:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2010.01.11 11:36:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

[2010.01.06 20:13:15 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010.01.06 20:04:25 | 00,000,000 | ---D | C] -- C:\_OTL

[2010.01.06 18:55:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\FixPolicies

[2010.01.06 17:41:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\LSPFix

[2010.01.06 12:44:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2010.01.06 12:44:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[2010.01.06 12:29:52 | 00,000,000 | RHSD | C] -- C:\cmdcons

[2010.01.06 12:27:13 | 00,000,000 | ---D | C] -- C:\windows\ERDNT

[2005.03.30 10:23:28 | 00,151,552 | R--- | C] ( ) -- C:\windows\System32\ATIDEMGR.dll

========== Files - Modified Within 30 Days ==========

[2010.01.15 00:31:00 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2010.01.15 00:21:19 | 00,000,540 | ---- | M] () -- C:\windows\tasks\PandaUSBVaccine.job

[2010.01.15 00:20:51 | 00,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT

[2010.01.15 00:20:40 | 00,002,048 | --S- | M] () -- C:\windows\bootstat.dat

[2010.01.15 00:20:33 | 53,635,0720 | -HS- | M] () -- C:\hiberfil.sys

[2010.01.15 00:19:56 | 08,388,608 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT

[2010.01.15 00:19:56 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini

[2010.01.14 22:57:15 | 00,000,754 | ---- | M] () -- C:\windows\WORDPAD.INI

[2010.01.14 22:40:30 | 00,152,401 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip

[2010.01.14 22:40:08 | 00,077,312 | ---- | M] () -- C:\mbr.exe

[2010.01.14 18:31:52 | 00,000,227 | ---- | M] () -- C:\windows\system.ini

[2010.01.14 18:31:19 | 00,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts

[2010.01.14 18:16:50 | 03,824,871 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

[2010.01.14 17:47:03 | 00,001,998 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk

[2010.01.14 17:28:22 | 01,401,344 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.msi

[2010.01.13 17:26:07 | 00,070,320 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2010.01.13 17:21:25 | 00,056,816 | ---- | M] (Avira GmbH) -- C:\windows\System32\drivers\avgntflt.sys

[2010.01.13 17:14:02 | 00,001,158 | ---- | M] () -- C:\windows\System32\wpa.dbl

[2010.01.13 08:44:14 | 00,176,392 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe

[2010.01.11 22:05:42 | 00,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk

[2010.01.11 21:51:53 | 00,313,968 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT

[2010.01.11 21:43:39 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010.01.07 16:32:16 | 00,000,280 | -H-- | M] () -- C:\windows\System32\dfdjekhhhkjohqsqwrxuuux.bud

[2010.01.07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2010.01.07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2010.01.06 21:11:03 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\dfdjekhhhkjohqsqwrxuuux.bud

[2010.01.06 20:48:22 | 00,004,248 | -H-- | M] () -- C:\windows\System32\qdmdjaitescswqdmdjaitescswqdmdjait.scs

[2010.01.06 20:48:22 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\qdmdjaitescswqdmdjaitescswqdmdjait.scs

[2010.01.06 15:03:08 | 00,000,750 | ---- | M] () -- C:\windows\Plexis.ini

[2010.01.06 14:51:11 | 00,001,034 | ---- | M] () -- C:\windows\win.ini

[2010.01.05 15:20:00 | 00,057,856 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\SPRAVKI MIROTEX 2009.xls

[2010.01.04 12:18:14 | 00,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk

[2009.12.29 13:07:13 | 00,751,104 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (2).doc

[2009.12.28 09:34:47 | 00,113,152 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ИМПОРТ гладачно.xls

[2009.12.28 09:34:11 | 00,112,128 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Протокол шивачно.xls

[2009.12.28 09:33:39 | 00,125,440 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Протокол кроялна.xls

[2009.12.23 13:42:21 | 00,565,248 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document.doc

[2009.12.21 09:54:17 | 00,112,128 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ЕКСПОРТ гладачно.xls

========== Files Created - No Company Name ==========

[2010.01.14 22:53:37 | 00,077,312 | ---- | C] () -- C:\mbr.exe

[2010.01.14 22:46:26 | 00,152,401 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip

[2010.01.14 18:19:38 | 00,261,632 | ---- | C] () -- C:\windows\PEV.exe

[2010.01.14 18:19:38 | 00,098,816 | ---- | C] () -- C:\windows\sed.exe

[2010.01.14 18:19:38 | 00,080,412 | ---- | C] () -- C:\windows\grep.exe

[2010.01.14 18:19:38 | 00,077,312 | ---- | C] () -- C:\windows\MBR.exe

[2010.01.14 18:19:38 | 00,068,096 | ---- | C] () -- C:\windows\zip.exe

[2010.01.14 18:18:38 | 03,824,871 | R--- | C] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

[2010.01.14 17:47:03 | 00,001,998 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk

[2010.01.14 17:46:53 | 01,401,344 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.msi

[2010.01.14 17:46:28 | 00,000,540 | ---- | C] () -- C:\windows\tasks\PandaUSBVaccine.job

[2010.01.11 22:05:42 | 00,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk

[2010.01.11 21:43:39 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010.01.11 21:06:22 | 53,635,0720 | -HS- | C] () -- C:\hiberfil.sys

[2010.01.06 20:48:22 | 00,004,248 | -H-- | C] () -- C:\windows\System32\qdmdjaitescswqdmdjaitescswqdmdjait.scs

[2010.01.06 20:48:22 | 00,004,248 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\qdmdjaitescswqdmdjaitescswqdmdjait.scs

[2010.01.06 20:48:22 | 00,000,280 | -H-- | C] () -- C:\windows\System32\dfdjekhhhkjohqsqwrxuuux.bud

[2010.01.06 20:48:22 | 00,000,280 | -H-- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\dfdjekhhhkjohqsqwrxuuux.bud

[2010.01.06 12:30:04 | 00,000,211 | ---- | C] () -- C:\Boot.bak

[2010.01.06 12:29:57 | 00,260,272 | ---- | C] () -- C:\cmldr

[2009.12.29 13:05:46 | 00,751,104 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (2).doc

[2009.12.23 13:39:29 | 00,565,248 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document.doc

[2007.11.27 10:33:21 | 00,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat

[2007.11.02 12:11:32 | 00,159,744 | ---- | C] () -- C:\windows\System32\hppatusg01.dll

[2007.08.06 12:07:30 | 00,008,520 | ---- | C] () -- C:\windows\System32\ractrlkeyhook.dll

[2006.05.18 16:21:06 | 00,000,049 | ---- | C] () -- C:\windows\NeroDigital.ini

[2006.04.18 11:44:48 | 00,035,840 | ---- | C] () -- C:\Program Files\winbox.exe

[2006.04.14 08:26:07 | 00,000,174 | ---- | C] () -- C:\windows\hpbafd.ini

[2006.04.14 08:25:23 | 00,000,033 | ---- | C] () -- C:\windows\hppLangChoice.ini

[2006.04.14 08:25:22 | 00,343,040 | R--- | C] () -- C:\windows\System32\lffpx7.dll

[2006.04.14 08:25:22 | 00,116,736 | R--- | C] () -- C:\windows\System32\lfkodak.dll

[2006.04.14 08:24:54 | 00,094,274 | ---- | C] () -- C:\windows\System32\HPBHealr.dll

[2006.04.14 08:24:54 | 00,049,152 | ---- | C] () -- C:\windows\System32\usbinst32.dll

[2005.11.01 16:10:56 | 00,000,116 | ---- | C] () -- C:\windows\ConverterCore.INI

[2005.10.08 16:48:21 | 00,000,026 | ---- | C] () -- C:\windows\lvdbed.INI

[2005.06.28 16:06:32 | 00,000,000 | ---- | C] () -- C:\windows\nokiacontentcopier.INI

[2005.06.11 23:21:16 | 00,157,696 | ---- | C] () -- C:\windows\System32\unrar.dll

[2005.06.11 23:21:12 | 00,019,968 | ---- | C] () -- C:\windows\System32\cpuinf32.dll

[2005.06.04 10:53:25 | 00,000,030 | ---- | C] () -- C:\windows\Iedit.INI

[2005.04.18 09:03:45 | 00,000,156 | ---- | C] () -- C:\windows\Kpcms.ini

[2005.04.18 09:03:23 | 00,210,944 | ---- | C] () -- C:\windows\System32\Msvcrt10.dll

[2005.04.11 15:23:37 | 00,000,754 | ---- | C] () -- C:\windows\WORDPAD.INI

[2005.04.01 16:20:42 | 00,080,896 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2005.03.26 11:40:30 | 00,000,000 | ---- | C] () -- C:\windows\PROTOCOL.INI

[2005.03.24 09:30:22 | 00,065,536 | ---- | C] () -- C:\windows\System32\MSRTEDIT.DLL

[2005.03.23 18:53:29 | 00,000,750 | ---- | C] () -- C:\windows\Plexis.ini

[2005.03.23 18:45:59 | 00,000,623 | ---- | C] () -- C:\windows\ODBC.INI

[2005.03.23 17:28:05 | 00,000,087 | ---- | C] () -- C:\windows\printstn.INI

[2005.03.23 17:03:42 | 00,000,069 | ---- | C] () -- C:\windows\Crypkey.ini

[2005.03.23 17:03:39 | 00,020,768 | ---- | C] () -- C:\windows\System32\Ckldrv.sys

[2005.03.23 17:03:39 | 00,018,432 | ---- | C] () -- C:\windows\Setup_ck.dll

[2005.03.23 17:03:24 | 00,064,512 | ---- | C] () -- C:\windows\System32\drivers\SENTINEL.SYS

[2005.03.23 17:03:24 | 00,039,424 | ---- | C] () -- C:\windows\System32\SNTI386.DLL

[2005.03.23 17:03:24 | 00,017,408 | ---- | C] () -- C:\windows\System32\RNBOVDD.DLL

[2005.01.14 04:33:21 | 00,000,061 | ---- | C] () -- C:\windows\smscfg.ini

[2005.01.14 04:25:41 | 00,000,044 | ---- | C] () -- C:\windows\System32\msssc.dll

[2004.08.12 16:10:50 | 00,086,016 | ---- | C] () -- C:\windows\System32\ati2evxx.dll

[2004.08.04 10:00:00 | 00,081,920 | ---- | C] () -- C:\windows\System32\ieencode.dll

[2003.01.07 15:05:08 | 00,002,695 | ---- | C] () -- C:\windows\System32\OUTLPERF.INI

[2002.05.08 11:12:22 | 00,000,715 | ---- | C] () -- C:\windows\System32\oeminfo.ini

[2002.03.21 14:39:02 | 00,073,728 | ---- | C] () -- C:\windows\System32\UNACEV2.DLL

[2001.09.05 17:13:54 | 00,139,776 | ---- | C] () -- C:\windows\System32\UserEdit.dll

========== LOP Check ==========

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ACD Systems

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Bullzip

[2010.01.11 19:26:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Citrix

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Datalayer

[2010.01.11 19:26:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ICAClient

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Marvell

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mikrotik

[2010.01.11 19:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Netscape

[2010.01.11 19:27:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Nokia

[2010.01.11 19:27:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PC Suite

[2010.01.11 19:28:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SolidDocuments

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Ulead Systems

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\webex

[2010.01.11 19:33:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn

[2010.01.14 17:46:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Panda Security

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Retrospect

[2010.01.11 19:34:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems

[2010.01.11 19:34:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\plovdiv\Application Data\PC Suite

[2010.01.15 00:21:19 | 00,000,540 | ---- | M] () -- C:\windows\Tasks\PandaUSBVaccine.job

========== Purity Check ==========

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2008.08.15 17:14:17 | 00,001,024 | ---- | M] () -- C:\.rnd

[2005.06.21 16:43:54 | 00,018,556 | ---- | M] () -- C:\000726.mdl

[2007.09.12 14:10:56 | 07,897,890 | ---- | M] () -- C:\1117.jpg

[2006.03.16 18:47:00 | 00,122,943 | ---- | M] () -- C:\16.03.jpg

[2006.02.03 16:54:34 | 00,037,545 | ---- | M] () -- C:\A Golden.jpg

[2006.02.03 17:04:32 | 02,173,023 | ---- | M] () -- C:\A Tihomirova.jpg

[2007.04.23 23:04:42 | 33,093,214 | ---- | M] () -- C:\A3 Project.cdr

[2007.03.07 18:00:16 | 00,150,600 | ---- | M] () -- C:\AAAA.JPG

[2005.10.12 14:44:41 | 00,071,704 | ---- | M] () -- C:\Asset Manager.jpg

[2007.07.06 08:55:14 | 00,000,750 | ---- | M] () -- C:\atlog.txt

[2006.05.30 16:29:13 | 05,794,376 | ---- | M] () -- C:\Baba.tif

[2006.05.30 16:30:49 | 01,863,437 | ---- | M] () -- C:\Baba2.tif

[2005.06.24 16:03:34 | 00,271,360 | ---- | M] () -- C:\backup Contacts.pst

[2005.06.28 15:52:59 | 24,787,4560 | ---- | M] () -- C:\backup.pst

[2008.12.18 15:49:01 | 00,000,239 | ---- | M] () -- C:\Barcod2.txt

[2008.12.18 15:49:01 | 00,000,239 | ---- | M] () -- C:\Barcodes.txt

[2007.05.08 20:10:05 | 00,035,328 | ---- | M] () -- C:\BESTaTIGUNG.doc

[2005.04.14 12:32:31 | 00,080,273 | ---- | M] () -- C:\BGDoc1dis.QRP

[2005.04.14 15:40:50 | 00,046,626 | ---- | M] () -- C:\BGDoc1kyr4.QRP

[2005.04.20 08:55:08 | 00,065,823 | ---- | M] () -- C:\BGDocF52.QRP

[2006.10.03 10:30:03 | 00,071,407 | ---- | M] () -- C:\bmw.jpg

[2009.10.26 11:31:49 | 00,000,211 | ---- | M] () -- C:\Boot.bak

[2006.01.28 15:17:53 | 00,028,689 | ---- | M] () -- C:\Boss.jpg

[2009.01.13 12:31:38 | 03,064,832 | ---- | M] () -- C:\Celendar 24.02.2006.pst

[2007.04.04 08:47:39 | 00,038,400 | ---- | M] () -- C:\City Express Дневник.xls

[2004.08.03 23:00:00 | 00,260,272 | ---- | M] () -- C:\cmldr

[2004.08.26 19:07:54 | 00,413,845 | ---- | M] () -- C:\COBIAS10.136

[2010.01.14 18:36:45 | 00,025,755 | ---- | M] () -- C:\ComboFix.txt

[2005.12.15 17:56:47 | 00,525,312 | ---- | M] () -- C:\Contacts.pst

[2009.06.10 13:50:32 | 00,459,264 | ---- | M] () -- C:\Declaracia.doc

[2006.01.11 12:58:52 | 00,001,056 | ---- | M] () -- C:\DN_BasicMARK_9-18A6F32C Unlimited.lic

[2006.11.24 09:27:19 | 00,000,687 | ---- | M] () -- C:\Document.rtf

[2007.03.13 17:17:41 | 00,032,734 | ---- | M] () -- C:\Dogovor za Prodajba na marka.rtf

[2007.08.31 16:15:04 | 00,050,176 | ---- | M] () -- C:\dogzaem.doc

[2005.04.13 18:46:01 | 00,012,916 | ---- | M] () -- C:\EAN13.TTF

[2010.01.15 00:21:09 | 00,002,288 | ---- | M] () -- C:\error.log

[2007.03.19 12:12:18 | 00,045,056 | ---- | M] () -- C:\ERTRAGSVORSCHAU.doc

[2009.07.01 11:57:37 | 00,018,432 | ---- | M] () -- C:\EVN Electro Razpredelenie 6.2009.xls

[2009.03.16 15:44:48 | 00,015,751 | ---- | M] () -- C:\Export13.02varnal_ДВ_.txt

[2009.03.03 15:32:37 | 00,010,807 | ---- | M] () -- C:\Export260209var2_ДВ_.txt

[2009.04.10 12:59:32 | 00,013,526 | ---- | M] () -- C:\Exports10.04pld_.txt

[2009.04.13 15:18:55 | 00,010,689 | ---- | M] () -- C:\Exports13.04pld_.txt

[2009.03.03 15:33:28 | 00,017,454 | ---- | M] () -- C:\Exports250209var_ДВ_.txt

[2009.03.03 15:32:12 | 00,019,317 | ---- | M] () -- C:\Exports260209var_ДВ_.txt

[2009.04.29 14:46:44 | 00,020,974 | ---- | M] () -- C:\Exports27.04.var_.txt

[2008.12.01 10:16:45 | 00,010,729 | ---- | M] () -- C:\Exports27.10l_ДВ_.txt

[2007.09.14 15:26:25 | 00,028,512 | ---- | M] () -- C:\ExportsPlovdiv_1409_.txt

[2005.10.03 14:36:20 | 00,021,824 | ---- | M] () -- C:\EXPORTStbl898_Codes.xml

[2005.10.17 09:15:01 | 00,088,407 | ---- | M] () -- C:\EXPORTSTran_171005.txt

[2009.03.03 15:35:19 | 00,019,317 | ---- | M] () -- C:\Exportsvar26_2_ДВ_.txt

[2006.06.12 16:12:23 | 00,161,408 | ---- | M] () -- C:\ExportsVarna_12.06.06_19.txt

[2009.02.26 11:20:42 | 00,063,012 | ---- | M] () -- C:\Exports_novi_1_ДВ_.txt

[2009.02.26 11:21:09 | 00,008,926 | ---- | M] () -- C:\Exports_novi_2_ДВ_.txt

[2009.02.26 11:22:04 | 00,017,427 | ---- | M] () -- C:\Exports_novi_3_ДВ_.txt

[2006.06.06 10:32:01 | 00,132,422 | ---- | M] () -- C:\ExportVarna_10_02.06.2006.txt

[2005.05.31 13:12:16 | 00,049,664 | ---- | M] () -- C:\Forma Zajavka Magazini AV.xls

[2006.12.21 13:27:34 | 00,019,456 | ---- | M] () -- C:\FROHE Weihnachten.doc

[2005.12.20 11:56:45 | 00,019,456 | ---- | M] () -- C:\Hello Christian.doc

[2010.01.15 00:20:33 | 53,635,0720 | -HS- | M] () -- C:\hiberfil.sys

[2006.07.28 13:35:48 | 01,414,042 | ---- | M] () -- C:\IMG_0143.jpg

[2006.07.28 13:36:34 | 01,815,290 | ---- | M] () -- C:\IMG_0144.jpg

[2006.07.28 13:37:03 | 01,666,038 | ---- | M] () -- C:\IMG_0145.jpg

[2006.07.28 13:37:55 | 02,144,872 | ---- | M] () -- C:\IMG_0146.jpg

[2007.04.24 15:17:35 | 01,071,570 | ---- | M] () -- C:\IMG_4445.jpg

[2008.07.08 16:49:49 | 00,000,140 | ---- | M] () -- C:\installationstep1.log

[2006.11.01 13:06:02 | 00,001,004 | ---- | M] () -- C:\installJustPrintV2R1.log

[2005.03.23 17:01:41 | 00,000,000 | RHS- | M] () -- C:\IO.SYS

[2006.11.06 15:06:00 | 00,001,033 | ---- | M] () -- C:\Irnaco_dn_Markpro_9-2A46447C_unlimited.lic

[2006.11.06 15:06:00 | 00,001,034 | ---- | M] () -- C:\Irnaco_MDmodepro_9-002FFD13_unlimited.lic

[2006.11.06 15:06:00 | 00,001,031 | ---- | M] () -- C:\Irnaco_Md_mode_9-32154995_unlimited.lic

[2005.08.19 12:47:34 | 00,001,333 | ---- | M] () -- C:\Lizenz 1.txt

[2006.01.11 12:50:41 | 00,167,531 | ---- | M] () -- C:\magazin 6.jpg

[2006.01.11 12:13:18 | 01,457,152 | ---- | M] () -- C:\maildoc82053.doc

[2006.01.11 12:20:08 | 00,287,894 | ---- | M] () -- C:\maildoc82053.pdf

[2006.01.11 12:15:49 | 01,032,192 | ---- | M] () -- C:\maildoc82054.doc

[2006.01.11 12:18:09 | 00,240,218 | ---- | M] () -- C:\maildoc82054.pdf

[2006.01.11 12:17:31 | 01,608,192 | ---- | M] () -- C:\maildoc82055.doc

[2006.01.11 12:19:39 | 00,307,908 | ---- | M] () -- C:\maildoc82055.pdf

[2006.01.11 12:19:03 | 01,251,328 | ---- | M] () -- C:\maildoc82056.doc

[2006.01.11 12:17:29 | 00,253,919 | ---- | M] () -- C:\maildoc82056.pdf

[2006.01.11 12:19:36 | 01,054,208 | ---- | M] () -- C:\maildoc82057.doc

[2006.01.11 12:18:32 | 00,248,726 | ---- | M] () -- C:\maildoc82057.pdf

[2010.01.14 22:40:08 | 00,077,312 | ---- | M] () -- C:\mbr.exe

[2005.09.28 19:04:38 | 00,138,957 | ---- | M] () -- C:\Ministerstwo na kulturata 2 Pages.jpg

[2006.11.23 13:23:00 | 00,245,943 | R--- | M] () -- C:\Miro.JPG

[2006.02.03 15:58:00 | 00,019,434 | R--- | M] () -- C:\Mirotex_Feb06A.Petrov_all_CAD_19May06.lic

[2008.12.15 17:30:34 | 00,062,231 | ---- | M] () -- C:\Mirro_kadastara _ 1.pdf

[2006.11.24 16:18:19 | 00,051,180 | ---- | M] () -- C:\MOni Petrov DXf.mdl

[2005.03.23 17:01:41 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS

[2006.02.03 17:05:18 | 00,157,697 | ---- | M] () -- C:\mvstcdxx.lst

[2004.08.04 10:00:00 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2004.08.04 10:00:00 | 00,250,032 | RHS- | M] () -- C:\ntldr

[2006.11.09 13:01:23 | 00,024,112 | ---- | M] () -- C:\NV180002P07.mdl

[2006.12.08 13:37:00 | 00,022,501 | ---- | M] () -- C:\NV315021P07-2.mdl

[2006.12.08 12:44:00 | 00,022,501 | ---- | M] () -- C:\NV315021P07.mdl

[2007.10.30 08:15:47 | 00,000,000 | ---- | M] () -- C:\OrbPVR.db

[2008.11.18 08:39:00 | 00,007,837 | ---- | M] () -- C:\Orders_171108_171108.txt

[2005.07.25 08:58:38 | 00,000,062 | ---- | M] () -- C:\Packet.bak

[2008.10.01 11:12:19 | 00,135,717 | ---- | M] () -- C:\Page10.jpg

[2008.10.01 11:16:14 | 00,173,324 | ---- | M] () -- C:\Page10.pdf

[2008.10.01 11:17:46 | 00,058,579 | ---- | M] () -- C:\Page10_2.jpg

[2008.10.01 11:18:52 | 00,075,964 | ---- | M] () -- C:\Page10_2.pdf

[2008.10.01 11:20:31 | 00,045,825 | ---- | M] () -- C:\Page10_3.jpg

[2008.10.01 11:21:33 | 00,059,934 | ---- | M] () -- C:\Page10_3.pdf

[2008.10.01 11:27:11 | 00,092,034 | ---- | M] () -- C:\Page10_4.jpg

[2008.10.01 11:28:05 | 00,126,772 | ---- | M] () -- C:\Page10_4.pdf

[2008.10.01 11:29:44 | 00,095,515 | ---- | M] () -- C:\Page10_5.jpg

[2008.10.01 11:31:09 | 00,131,973 | ---- | M] () -- C:\Page10_5.pdf

[2010.01.15 00:20:31 | 79,272,3456 | -HS- | M] () -- C:\pagefile.sys

[2005.10.07 11:37:34 | 00,809,352 | ---- | M] () -- C:\Payment Order Visplay.jpg

[2005.10.07 13:27:14 | 00,306,956 | ---- | M] () -- C:\PaymentOrder Visplay.jpg

[2006.01.12 09:19:08 | 00,001,840 | ---- | M] () -- C:\PhotoImpact 8 (2).lnk

[2006.08.14 15:51:48 | 00,028,160 | ---- | M] () -- C:\PLATOVE PO KODOVE.xls

[2006.04.18 11:18:18 | 00,034,816 | ---- | M] () -- C:\Plovdiv 17 04 2006.xls

[2005.10.07 11:34:01 | 00,324,835 | ---- | M] () -- C:\Proforma 000123 Antoan Vill.jpg

[2005.10.07 13:44:20 | 00,091,651 | ---- | M] () -- C:\Proforma 123 Antoan Vill - Lectra.jpg

[2005.08.16 10:36:19 | 00,024,064 | ---- | M] () -- C:\Remont.doc

[2006.08.15 13:29:42 | 00,186,880 | ---- | M] () -- C:\Revizia Mirotex.xls

[2008.08.27 07:50:00 | 00,011,202 | ---- | M] () -- C:\Sale_260808.txt

[2006.09.20 09:25:04 | 00,007,862 | ---- | M] () -- C:\Sale_30.07.2006.txt

[2006.02.24 09:03:50 | 00,000,136 | ---- | M] () -- C:\SerialSync.txt

[2008.03.24 13:48:24 | 00,029,184 | ---- | M] () -- C:\SkicaViza Arial.doc

[2008.03.24 13:48:13 | 00,028,672 | ---- | M] () -- C:\Skiza Visa 3.doc

[2006.09.20 09:48:59 | 00,000,000 | ---- | M] () -- C:\sql.log

[2005.09.29 14:30:07 | 00,417,476 | ---- | M] () -- C:\Swift ComputerLife.jpg

[2005.10.10 08:56:40 | 00,148,162 | ---- | M] () -- C:\SWIFT Visplay.jpg

[2006.11.17 15:39:28 | 00,034,068 | ---- | M] () -- C:\TM541 new.mdl

[2006.12.01 14:24:00 | 00,040,161 | ---- | M] () -- C:\TM597013P07.mdl

[2005.08.24 10:06:31 | 00,041,311 | ---- | M] () -- C:\Transaktion types.JPG

[2005.09.28 19:04:57 | 00,076,417 | ---- | M] () -- C:\Udostowerenie.jpg

[2005.12.19 12:20:31 | 00,076,278 | ---- | M] () -- C:\Untitled - 1.jpg

[2006.02.03 16:46:31 | 00,091,187 | ---- | M] () -- C:\Untitled-1.psd

[2008.06.26 15:00:23 | 00,000,016 | ---- | M] () -- C:\UsageTrack.txt

[2006.04.18 11:17:27 | 00,270,848 | ---- | M] () -- C:\Varna 17 04 2006.xls

[2005.08.23 16:17:34 | 00,082,580 | ---- | M] () -- C:\Varna1.jpg

[2006.10.30 17:18:56 | 00,046,080 | ---- | M] () -- C:\VASSETO.XLS

[2006.02.13 13:20:33 | 00,118,784 | ---- | M] () -- C:\Zusammenfassung Lektra.xls

[2007.12.03 11:35:08 | 00,026,112 | ---- | M] () -- C:\До Кмета на Централен 29.11.2007.doc

[2006.11.28 22:22:09 | 00,135,680 | ---- | M] () -- C:\Справка шивачки Октомври.xls

< MD5 for: AGP440.SYS >

[2004.08.04 15:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys

[2004.08.04 10:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys

[2008.04.13 20:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys

< MD5 for: ATAPI.SYS >

[2004.08.04 15:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys

[2004.08.04 10:00:00 | 18,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys

[2008.04.13 20:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys

[2004.08.04 08:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys

[2004.08.04 08:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys

[2004.08.04 08:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

[2004.08.04 02:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

[2004.08.04 08:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >

[2008.04.14 02:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll

[2004.08.04 10:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll

[2004.08.04 10:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >

[2008.04.14 02:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll

[2004.08.04 10:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll

[2004.08.04 10:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >

[2004.08.04 10:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll

[2004.08.04 10:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll

[2008.04.14 02:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %PROGRAMFILES%\*. >

[2010.01.11 20:01:59 | 00,000,000 | ---D | M] -- C:\Program Files\Analog Devices

[2010.01.11 20:02:01 | 00,000,000 | ---D | M] -- C:\Program Files\ATI Technologies

[2010.01.11 22:04:58 | 00,000,000 | ---D | M] -- C:\Program Files\Avira

[2010.01.13 18:21:47 | 00,000,000 | ---D | M] -- C:\Program Files\Broadcom

[2010.01.11 20:02:06 | 00,000,000 | ---D | M] -- C:\Program Files\Citrix

[2010.01.14 18:27:32 | 00,000,000 | ---D | M] -- C:\Program Files\Common Files

[2010.01.11 20:03:53 | 00,000,000 | ---D | M] -- C:\Program Files\Compaq

[2010.01.11 20:03:54 | 00,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications

[2010.01.11 20:03:55 | 00,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard

[2010.01.11 20:04:29 | 00,000,000 | ---D | M] -- C:\Program Files\HP

[2010.01.11 20:01:59 | 00,000,000 | ---D | M] -- C:\Program Files\HPQ

[2010.01.11 21:41:11 | 00,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information

[2010.01.06 12:44:47 | 00,000,000 | ---D | M] -- C:\Program Files\Internet Explorer

[2010.01.11 20:04:57 | 00,000,000 | ---D | M] -- C:\Program Files\Java

[2010.01.11 21:43:39 | 00,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010.01.11 20:05:28 | 00,000,000 | ---D | M] -- C:\Program Files\Messenger

[2010.01.11 20:05:29 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync

[2010.01.11 20:05:29 | 00,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage

[2010.01.11 20:05:29 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Office

[2010.01.11 20:06:33 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server

[2010.01.11 20:07:10 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio

[2010.01.11 20:07:22 | 00,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET

[2010.01.11 20:07:22 | 00,000,000 | ---D | M] -- C:\Program Files\Movie Maker

[2010.01.11 20:04:31 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox

[2010.01.11 20:04:42 | 00,000,000 | ---D | M] -- C:\Program Files\MSN

[2010.01.11 20:04:43 | 00,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone

[2010.01.11 20:04:44 | 00,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0

[2010.01.11 20:04:44 | 00,000,000 | ---D | M] -- C:\Program Files\NetMeeting

[2010.01.11 20:04:45 | 00,000,000 | ---D | M] -- C:\Program Files\Online Services

[2010.01.11 20:04:45 | 00,000,000 | ---D | M] -- C:\Program Files\Outlook Express

[2010.01.14 17:46:27 | 00,000,000 | ---D | M] -- C:\Program Files\Panda USB Vaccine

[2010.01.11 20:04:45 | 00,000,000 | ---D | M] -- C:\Program Files\Program Shortcuts

[2010.01.11 20:04:46 | 00,000,000 | ---D | M] -- C:\Program Files\SA

[2010.01.11 20:04:47 | 00,000,000 | ---D | M] -- C:\Program Files\SA Dictionary 2005 T2

[2010.01.11 20:04:47 | 00,000,000 | ---D | M] -- C:\Program Files\Satellite Forms EE Redist

[2010.01.14 17:47:03 | 00,000,000 | ---D | M] -- C:\Program Files\TrendMicro

[2010.01.11 20:01:59 | 00,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information

[2010.01.11 20:07:25 | 00,000,000 | ---D | M] -- C:\Program Files\Windows Media Player

[2010.01.11 20:07:31 | 00,000,000 | ---D | M] -- C:\Program Files\Windows NT

[2010.01.11 20:07:32 | 00,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate

[2010.01.11 20:07:33 | 00,000,000 | ---D | M] -- C:\Program Files\WinISO

[2010.01.11 20:07:34 | 00,000,000 | ---D | M] -- C:\Program Files\WinZip

[2010.01.11 20:07:35 | 00,000,000 | ---D | M] -- C:\Program Files\xerox

< %userprofile%\Desktop\*.* >

[2009.05.13 09:34:27 | 00,075,470 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\..__ Register.BG __.pdf

[2009.04.09 13:35:14 | 00,150,440 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\40000000037 - MOD MARI - 31.03.2009.pdf

[2009.04.09 13:59:16 | 00,149,119 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\40000000038 TPK Saglasie - 01.04.2009.pdf

[2009.09.16 10:24:50 | 00,100,067 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\6_.jpg

[2009.11.25 12:41:31 | 00,955,219 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Badj Roma Fondation 90x60 - Italiano FINAL Corel11.pdf

[2009.03.31 14:33:02 | 00,163,840 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\bank transfer MIRO.doc

[2009.03.31 14:33:10 | 00,163,840 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\bank transfer2 MIRO.doc

[2009.05.13 08:32:00 | 00,065,528 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Bulbank Online 13.05.2009.pdf

[2009.11.10 11:04:23 | 00,030,900 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\christian-dior-prolet-2010-modna-kolekcia-20.jpg

[2009.04.22 16:45:56 | 00,098,304 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\City Express Дневник.xls

[2010.01.14 18:16:50 | 03,824,871 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

[2010.01.14 18:37:17 | 00,025,755 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\CombofixLog.txt

[2009.06.10 13:49:00 | 00,354,374 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Declaracia Page1.jpg

[2009.06.10 13:49:29 | 00,081,166 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Declaracia Page2.jpg

[2009.06.10 13:50:32 | 00,459,264 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Declaracia.doc

[2009.04.29 15:17:36 | 00,018,432 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\dima.xls

[2005.06.22 09:09:19 | 00,000,824 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\EMAIL.lnk

[2008.11.12 12:22:43 | 00,758,648 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\Desktop\EPAClient.exe

[2009.12.01 15:18:08 | 00,002,258 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\eula.txt

[2009.07.08 09:20:36 | 01,574,868 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Exportirane na kodove.exe

[2009.06.25 09:16:53 | 00,000,700 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Finansovi Otcheti Rumi 2008.xls.lnk

[2009.06.17 12:09:36 | 00,000,676 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Hamachi (2).lnk

[2006.03.17 17:30:29 | 00,000,676 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Hamachi.lnk

[2010.01.14 17:47:03 | 00,001,998 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk

[2010.01.14 17:48:58 | 00,005,770 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\hijackthis.log

[2010.01.14 17:28:22 | 01,401,344 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.msi

[2009.07.08 09:08:59 | 01,545,062 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Importirane na prodajbi v PLEXIS.exe

[2009.07.08 08:53:34 | 01,548,687 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Importirane na zajavki v PLEXIS.exe

[2009.07.08 08:45:00 | 01,425,156 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Importirane ot EMAIL.exe

[2007.07.23 09:10:01 | 00,001,655 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Internet.lnk

[2005.03.24 13:09:24 | 00,001,343 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\LabelView 5.2.lnk

[2009.01.18 10:27:27 | 00,788,480 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Lectra Team and office.ppt

[2010.01.14 22:56:59 | 00,000,453 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\log.txt

[2010.01.14 22:50:16 | 00,041,696 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Logit.txt

[2006.07.05 16:12:00 | 00,186,880 | ---- | M] (CEXX.ORG) -- C:\Documents and Settings\Administrator\Desktop\LSPFix.exe

[2006.07.06 00:25:18 | 00,005,733 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\lspfix.txt

[2010.01.11 21:50:53 | 00,001,194 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\mbam-log-2010-01-11 (21-50-06).txt

[2010.01.14 17:43:33 | 00,000,849 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\mbam-log-2010-01-14 (17-43-33).txt

[2010.01.14 23:58:35 | 00,000,286 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\MBRlog2.txt

[2009.08.27 12:32:59 | 00,002,471 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Microsoft Excel.lnk

[2009.09.09 17:06:39 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Microsoft Word.lnk

[2005.04.07 10:30:10 | 00,000,673 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\mOrders.lnk

[2005.04.07 10:30:10 | 00,000,668 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\mStock.lnk

[2007.08.24 09:23:41 | 00,001,493 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\My Dokuments.lnk

[2009.12.29 13:07:13 | 00,751,104 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document (2).doc

[2009.12.23 13:42:21 | 00,565,248 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\New Microsoft Word Document.doc

[2008.11.21 13:46:04 | 00,024,576 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Order 66 Mirotex Bulgaria for rumi.xls

[2009.07.08 09:14:19 | 00,606,999 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Otchet Prodajbi.exe

[2009.01.18 12:36:40 | 29,503,580 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Otec Paisii Project.cdr

[2009.01.18 12:35:23 | 39,578,468 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Otec Paisii Sgrada.pdf

[2010.01.15 00:31:00 | 00,544,256 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2010.01.15 00:29:48 | 00,000,746 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\OTL.txt

[2005.03.23 19:09:09 | 00,001,288 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Palm Desktop.lnk

[2009.02.02 18:55:23 | 00,785,920 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Pismo Ministerstvo na Kulturata.doc

[2006.02.10 08:41:15 | 00,000,601 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\PLEXIS.lnk

[2009.01.18 10:25:21 | 03,096,975 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Presentation Bulgaria Version 2.pdf

[2009.01.18 10:33:56 | 04,816,896 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Presentation Bulgaria Version 3.ppt

[2005.04.13 16:24:00 | 00,000,773 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\repbi11.exe.lnk

[2009.02.09 08:56:10 | 00,052,224 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Revisionen protokol Varna 02.11.2008 - 10.01.2009.xls

[2009.02.11 10:12:57 | 00,057,344 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Revisionen protokol Varna 11.01.2009 - 08.02.2009.xls

[2006.02.10 08:41:15 | 00,000,613 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\S-M-L-XL.lnk

[2008.09.10 16:47:56 | 00,000,736 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Skype.lnk

[2010.01.05 15:20:00 | 00,057,856 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\SPRAVKI MIROTEX 2009.xls

[2010.01.15 00:15:07 | 00,000,170 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\SQL Server.txt

[2009.05.18 11:20:44 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\sql.log

[2010.01.13 08:44:14 | 00,176,392 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe

[2010.01.14 22:40:30 | 00,152,401 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\tdsskiller.zip

[2008.03.19 09:50:24 | 00,287,744 | -HS- | M] () -- C:\Documents and Settings\Administrator\Desktop\Thumbs.db

[2009.12.10 11:09:27 | 00,028,589 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\velvet-12.jpg

[2009.11.25 12:41:21 | 00,723,100 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Vititka Roma Fondation 90x60 - Italiano FINAL Corel11 Badjove.cdr

[2006.12.18 16:18:13 | 00,000,730 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\VNC Viewer 4.lnk

[2009.11.25 12:03:11 | 00,454,017 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\winmail.dat

[2008.12.23 11:12:39 | 00,858,582 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\[Fw- Lectra Offer Upgrde - HEROS ROUSSE ].eml

[2009.05.13 09:41:22 | 00,053,663 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\_476D61696C202D20D0E5E3E8F1F2FAF02EC1C33A20CFEEF2E2FAF0E6E4E5EDE8E520E7E020EFEBE0F9E0EDE5202F2052656769737465722E42473A20502E2E2E_.pdf

[2009.12.21 09:54:17 | 00,112,128 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ЕКСПОРТ гладачно.xls

[2009.12.28 09:34:47 | 00,113,152 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ИМПОРТ гладачно.xls

[2009.05.08 08:15:14 | 00,016,896 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ОБОРОТИ МАГАЗИНИ.xls

[2009.12.28 09:33:39 | 00,125,440 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Протокол кроялна.xls

[2009.12.28 09:34:11 | 00,112,128 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Протокол шивачно.xls

[2009.04.30 10:59:15 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\разценки общи.xls

[2008.12.16 10:16:51 | 00,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\РЕВю.doc

[2009.09.08 10:02:53 | 00,019,456 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\СПИСЪК НА ИЗЛИЗАНЕ.doc

< %userprofile%\Desktop\*. >

[2008.02.28 11:50:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Desktop\FixPolicies

[2010.01.11 18:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Desktop\Indian Rose

[2010.01.14 22:46:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Desktop\LSPFix

[2010.01.11 19:28:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Desktop\Pictures

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2008-10-25 12:37:37

========== Alternate Data Streams ==========

@Alternate Data Stream - 68 bytes -> C:\Program Files\Messenger\msmsgs.exe:KAVICHS

@Alternate Data Stream - 36 bytes -> C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys:KAVICHS

@Alternate Data Stream - 36 bytes -> C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys:KAVICHS

< End of report >

Редактирано от mannesmann (преглед на промените)

Стартирай OTL.exe и под "Customs Scans/Fixes" с copy/paste въведи това:

:OTL

SRV - (WinVNC4) -- File not found

SRV - (RetroLauncher) -- File not found

MsConfig - StartUpFolder: C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Hamachi (2).lnk - C:\PROGRA~1\Hamachi\hamachi.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Skype.lnk - C:\PROGRA~1\Skype\Phone\Skype.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk - C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\acrotray.exe - File not found

MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hamachi.lnk - C:\PROGRA~1\Hamachi\hamachi.exe - File not found

MsConfig - StartUpReg: DAEMON Tools-1033 - hkey= - key= - C:\Program Files\D-Tools\daemon.exe File not found

MsConfig - StartUpReg: NeroFilterCheck - hkey= - key= - File not found

[2010.01.07 16:32:16 | 00,000,280 | -H-- | M] () -- C:\windows\System32\dfdjekhhhkjohqsqwrxuuux.bud

[2010.01.06 21:11:03 | 00,000,280 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\dfdjekhhhkjohqsqwrxuuux.bud

[2010.01.06 20:48:22 | 00,004,248 | -H-- | M] () -- C:\windows\System32\qdmdjaitescswqdmdjaitescswqdmdjait.scs

[2010.01.06 20:48:22 | 00,004,248 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\qdmdjaitescswqdmdjaitescswqdmdjait.scs

@Alternate Data Stream - 68 bytes -> C:\Program Files\Messenger\msmsgs.exe:KAVICHS

@Alternate Data Stream - 36 bytes -> C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys:KAVICHS

@Alternate Data Stream - 36 bytes -> C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys:KAVICHS

:files

C:\RECYCLER

:Commands

[purity]

[emptytemp]

[Reboot]

Натисни Run Fix.

След рестарта, стартирай програмката LSPFix.exe и направи една снимка.

Публикувай я в следващия си пост. :P

  • Автор

Ok ето го лога от ОТЛ след рестарта и снимката от LSPFix:

All processes killed

========== OTL ==========

Service WinVNC4 stopped successfully!

Service WinVNC4 deleted successfully!

File File not found not found.

Service RetroLauncher stopped successfully!

Service RetroLauncher deleted successfully!

File File not found not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Hamachi (2).lnk\ deleted successfully.

C:\WINDOWS\pss\Hamachi (2).lnkStartup moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Skype.lnk\ deleted successfully.

C:\WINDOWS\pss\Skype.lnkStartup moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk\ deleted successfully.

C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpFolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hamachi.lnk\ deleted successfully.

C:\WINDOWS\pss\hamachi.lnkCommon Startup moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\DAEMON Tools-1033\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\NeroFilterCheck\ deleted successfully.

C:\WINDOWS\system32\dfdjekhhhkjohqsqwrxuuux.bud moved successfully.

C:\Documents and Settings\Administrator\Local Settings\Application Data\dfdjekhhhkjohqsqwrxuuux.bud moved successfully.

C:\WINDOWS\system32\qdmdjaitescswqdmdjaitescswqdmdjait.scs moved successfully.

C:\Documents and Settings\Administrator\Local Settings\Application Data\qdmdjaitescswqdmdjaitescswqdmdjait.scs moved successfully.

ADS C:\Program Files\Messenger\msmsgs.exe:KAVICHS deleted successfully.

ADS C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys:KAVICHS deleted successfully.

ADS C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys:KAVICHS deleted successfully.

========== FILES ==========

C:\RECYCLER\S-1-5-21-1073245545-1349789880-22627367-500 folder moved successfully.

C:\RECYCLER folder moved successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32902 bytes

->Java cache emptied: 0 bytes

->Google Chrome cache emptied: 0 bytes

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: plovdiv

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 0,00 mb

OTL by OldTimer - Version 3.1.24.0 log created on 01152010_011224

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

post-258002-1263511135,64_thumb.jpg

Предполагам още има проблеми с интернета или ?

Би трябвало вече системата да е чиста, но за интернета се сещам само за тези инструменти:

http://www.kaldata.com/forums/index.php?showtopic=39592

След стартиране, те ще занулят настройките за интернета. (настройките трябва да се въведат наново ръчно).

Да се надяваме, че това ще помогне...

  • Автор

YESSS MASTER ... РАБОТИ !!! :P

Наистина всичко беше наред, но интернет още нямаше. След като FIXнах мрежата с winsockfix и рестартирах всички връзки се възстановиха. Антивирусната се ъпдейтна веднага, клиента се връзва към SQL servera и си дудукат без проблем . Термотрансферния ми принтер си печата етикети, лазерния принтер си печата протоколи и PALM скенера също си разтовари успешно данните през болния компютър към сървъра.

Бооооже мили не вярвах, че ще стане наистина. Бозата беше пълна и от първия работен ден на новата година бях изпаднал в депресия направо. Сега имам един куп протоколи да въведа в базата данни, но сърцето ми направо пеее

За първи път от 9 нощи ще спя спокойно. Утре преди да буутне му пускам веднага един имидж с Акрониса и се надявам ако се стигне някога до подобна ситуация да сме по-подготвени.

ОГРОМНО БЛАГОДАРЯ, ЧЕ НЕ МЕ ИЗОСТАВИХТЕ В КАЛТА

Често пътувам до София и ще се радвам много да се запознаем лично и да почерпя за безкористната помощ, която ми оказахте!

Свалям Ви шапка за това, което правите в този форум!

:speak::wors: :wors: :wors: :wors: :wors::wors:

Радвам се, че всичко е наред. Вие се справихте отлично. Чудесно е, че импровизирахте със спасителните дискове на Kaspersky и Avira (дискове които доста потребители като PhrozenCrew и vasilevsa честичко препоръчват и ние по принцип също с колегата като последни усилия на надежда). Честно казано и аз се измъчих, защото по принцип този бацил се чисти по-лесно. Незнам защо при вас се бяха закучили така нещата. Но лека по лека всичко си дойде на мястото. Сега ако искате можете да преинсталирате някои приграми премахнати по време на почистването (стига да ги използвате):

- Daemon Tools както и тези премахнати от Combofix (или по-скоро премахнати техните деинсталатори или ги махна от списъка със зареждащите с Windows програми) и може и те да се преинсталират при желание.

- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe

MSConfigStartUp-BDMCon - c:\progra~1\Softwin\BITDEF~1\bdmcon.exe

MSConfigStartUp-BDNewsAgent - c:\progra~1\Softwin\BITDEF~1\bdnagent.exe

MSConfigStartUp-BDOESRV - c:\program files\Softwin\BitDefender8\\bdoesrv.exe

MSConfigStartUp-BDSwitchAgent - c:\program files\Softwin\BitDefender8\\bdswitch.exe

MSConfigStartUp-Google Update - c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

MSConfigStartUp-LogMeIn GUI - c:\program files\LogMeIn\x86\LogMeInSystray.exe

MSConfigStartUp-Orb - c:\program files\Winamp Remote\bin\OrbTray.exe

MSConfigStartUp-PrnStatusMX - c:\program files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe

MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe

MSConfigStartUp-WinampAgent - c:\program files\Winamp\wianmpa.exe

AddRemove-Adobe PageMaker 7.0 - c:\program files\Adobe\PageMaker 7.0\Uninst.isu

AddRemove-Adobe Photoshop 7.0 - c:\program files\Adobe\Photoshop 7.0\Uninst.isu

AddRemove-Bullzip PDF Printer_is1 - c:\program files\Bullzip\PDF Printer\unins000.exe

AddRemove-Gaberoff Koral German Dictionary 1.01 - c:\progra~1\GABERO~1\GABERO~1.0\UNWISE.EXE

AddRemove-GPL Ghostscript Lite_is1 - c:\program files\Bullzip\PDF Printer\gs\unins000.exe

AddRemove-Hamachi - c:\program files\Hamachi\uninstall.exe

AddRemove-Nero - Burning Rom!UninstallKey - c:\program files\Ahead\nero\uninstall\UNNERO.exe

AddRemove-RealVNC_is1 - c:\program files\RealVNC\VNC4\unins000.exe

AddRemove-SCREEN2EXE_is1 - c:\program files\SCREEN2EXE\unins000.exe

AddRemove-WinRAR archiver - c:\program files\WinRAR\uninstall.exe

Болднах тези които ми се сториха по-важни.

Деинсталирайте Combofix => Start => Run => въведете Combofix /Uninstall => (има празно място между Combofix и /Uninstall) => Enter => това ще стартира и ще деинсталира Combofix. Ще затрие и файловете асоциирани с този инструмент, както и папката C:\Qoobox - карантината на Combofix.

Стартирайте OTL.exe => натиснете Cleanup! бутона => за да изтриете някои от използваните от нас програми. Това ще изтрие и папката C:\_OTL => карантинната папка на OTL.exe.

35hfp21.jpg

След това изтрийте всички други инструменти за които се сетите, от тези които сме използвали.

По време на преинсталацията на Skype => Не инсталирайте есктрите. Ето как да стане това:

1. Преинсталирайте Скайп без "добавките":

(описанието е взето от Night_Raven)

Деинсталирай Skype и го инсталирай без диспечера на на екстрите. Те позволяват на Skype да ползва разни допълнения - детектори на лъжата, допълнения за настроения и всякакви други шарении. Инсталацията на екстрите води и до инсталиране на SkypePM.exe, който се вижда в Task Manager и някои хора се чудят какво е, защото понякога гълта доста памет. Именно с тези екстри се инсталира и Skype4COM протокола, чрез който тази гадинка и всичкия спам, който циркулира в Skype, се разпространява. Традиционния метод е следния: даден потребител е залъган да изтегли и стартира дадена програма, която обещава да добави икони/да разбие парола/нещо друго. Тази програма обаче не е нищо повече от скрипт (VBS в повечето случаи), който не прави нищо от обещаното, а използва споменатия по-горе протокол да се разпрати на всички абонати в списъка.

Ако този протокол го няма, дори и да се стартира подобен спам-скрипт, той няма да може да разпрати нищо.

Ето графична илюстрация как да НЕ се инсталират екстрите:

z5pvs.png

2zgx8gp.png

2. Не стартирайте съмнителни файлове получени по Скайп (дори от познати в контакт листата) без преди това да сте ги проверила с антивирусната си програма или на адрес:

http://www.virustotal.com

За финал преди да направите IMIGE-a, можете да обновите Malwarebytes и антивирусната си програма и да направите финални проверки.

Не забравяйте да изтриете и файловете от карантините на антивирусната програма и на Malwarebytes.

И на мен ми олекна, че проблема се реши. Лека вечер ! :P

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.