Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проверка за бацил!?

Featured Replies

  • Автор

ComboFix 10-01-19.08 - Administrator 01.2010 г. 14:57:33.6.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1015.748 [GMT 2:00]

Running from: c:\documents and settings\Administrator\Desktop\Tool.exe

.

((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))

.

2010-01-20 12:36 . 2010-01-20 12:36 0 ----a-w- C:\backup.reg

2010-01-18 12:21 . 2010-01-18 12:21 -------- d-----w- c:\program files\Trend Micro

2010-01-18 12:00 . 2010-01-18 12:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2010-01-18 12:00 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-01-18 12:00 . 2010-01-18 12:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-01-18 12:00 . 2010-01-18 12:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-01-18 12:00 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-01-15 15:10 . 2008-04-14 03:42 176640 ------w- c:\windows\system32\napstat.exe

2010-01-15 15:09 . 2010-01-15 15:09 -------- d-----w- c:\windows\ServicePackFiles

2010-01-15 15:06 . 2007-08-10 18:46 26488 ----a-w- c:\windows\system32\spupdsvc.exe

2010-01-15 06:42 . 2010-01-15 06:42 -------- d-----w- c:\windows\system32\wbem\Repository

2010-01-13 09:07 . 2010-01-15 06:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent

2010-01-06 12:49 . 2002-12-24 19:18 3712 ----a-w- c:\windows\system32\drivers\cfadisk.sys

2009-12-28 09:41 . 2009-12-28 09:41 -------- d-----w- c:\program files\ESET

2009-12-24 09:54 . 2009-12-24 09:54 767328 ----a-w- c:\windows\system32\kdfinj.dll

2009-12-24 09:54 . 2008-10-17 08:50 79104 ----a-w- c:\windows\system32\drivers\Mkd2Nadr.sys

2009-12-24 09:54 . 2008-10-17 08:50 131072 ----a-w- c:\windows\system32\drivers\Mkd2kfNT.sys

2009-12-22 10:38 . 2009-03-04 15:30 709248 ----a-w- c:\windows\system32\drivers\rt2870.sys

2009-12-22 10:38 . 2009-03-04 15:23 221184 ----a-w- c:\windows\system32\RaCoInst.dll

2009-12-22 10:38 . 2009-12-22 10:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Ralink Driver

2009-12-22 10:38 . 2009-03-04 15:30 709248 ----a-w- c:\documents and settings\All Users\Application Data\Ralink Driver\RT2870 Wireless LAN Card\Driver\rt2870.sys

2009-12-22 10:38 . 2009-03-04 15:23 221184 ----a-w- c:\documents and settings\All Users\Application Data\Ralink Driver\RT2870 Wireless LAN Card\Driver\RaCoInst.dll

2009-12-22 10:38 . 2009-03-04 15:23 13931 ----a-w- c:\windows\system32\RaCoInst.dat

2009-12-22 10:38 . 2008-08-06 14:31 528384 ----a-w- c:\documents and settings\All Users\Application Data\Ralink Driver\RT2870 Wireless LAN Card\Driver\RaInst.exe

2009-12-22 10:38 . 2007-05-17 09:17 192512 ----a-w- c:\documents and settings\All Users\Application Data\Ralink Driver\RT2870 Wireless LAN Card\Driver\CoInstaller.dll

2009-12-22 10:38 . 2006-11-02 05:21 319456 ----a-w- c:\documents and settings\All Users\Application Data\Ralink Driver\RT2870 Wireless LAN Card\Driver\difxapi.dll

2009-12-22 10:38 . 2009-12-22 10:38 -------- d-----w- c:\documents and settings\Administrator\Application Data\InstallShield

2009-12-21 14:26 . 2009-12-21 14:26 -------- d-----w- c:\program files\Common Files\Adobe

2009-12-21 14:24 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe

2009-12-21 14:24 . 2009-12-21 14:24 -------- d-----w- c:\program files\Common Files\Adobe AIR

2009-12-21 14:23 . 2009-12-21 14:23 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-01-18 13:43 . 2009-11-20 11:28 -------- d-----w- c:\program files\UltraVNC

2010-01-16 09:54 . 2007-12-16 22:15 64808 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-01-15 15:12 . 2007-10-31 03:46 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-12-22 11:40 . 2009-11-19 11:28 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

2009-12-22 10:38 . 2007-10-31 03:54 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-12-14 11:17 . 2009-12-14 11:17 -------- d-----w- c:\program files\K-Lite Codec Pack

2009-12-13 13:53 . 2009-12-13 13:53 -------- d-----w- c:\program files\CCleaner

2009-12-13 13:23 . 2009-12-07 12:02 -------- d-----w- c:\program files\OpenVPN

2009-12-13 09:24 . 2009-12-13 09:24 411368 ----a-w- c:\windows\system32\deploytk.dll

2009-12-13 09:24 . 2008-04-14 10:21 -------- d-----w- c:\program files\Java

2009-12-13 09:24 . 2009-12-13 09:24 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

2009-12-13 09:22 . 2009-12-13 09:22 79488 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

2009-12-11 09:18 . 2009-11-20 11:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Hamachi

2009-12-09 08:03 . 2009-11-20 08:03 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2009-11-22 06:22 . 2009-11-22 06:22 -------- d-----w- c:\program files\ZyDAS Technology Corporation

2009-11-20 13:26 . 2009-11-20 13:26 25984 ----a-w- c:\windows\system32\drivers\tap0901.sys

2009-11-20 11:23 . 2009-09-23 08:41 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys

2009-11-19 11:36 . 2009-11-18 15:38 376832 ----a-w- c:\windows\system32\AegisI5Installer.exe

2009-11-19 11:29 . 2009-11-19 11:29 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe

2002-12-11 22:00 . 2008-01-22 15:27 6325 ----a-w- c:\program files\BgphXP.inf

.

((((((((((((((((((((((((((((( SnapShot@2010-01-19_12.18.31 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-01-20 12:43 . 2010-01-20 12:43 16384 c:\windows\temp\Perflib_Perfdata_f8.dat

+ 2001-08-23 12:00 . 2010-01-20 12:47 40128 c:\windows\system32\perfc009.dat

- 2001-08-23 12:00 . 2010-01-19 12:13 40128 c:\windows\system32\perfc009.dat

+ 2001-08-23 12:00 . 2010-01-20 12:47 311740 c:\windows\system32\perfh009.dat

- 2001-08-23 12:00 . 2010-01-19 12:13 311740 c:\windows\system32\perfh009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"ShowDeskFix"="shell32" [X]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZDWLan Utility.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk

backup=c:\windows\pss\ZDWLan Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

2009-09-04 10:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-14 03:42 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]

2007-09-20 04:33 61952 ----a-w- c:\windows\system32\HDAShCut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]

2007-01-13 08:47 163840 ----a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]

2007-01-13 08:47 131072 ----a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]

2007-01-13 08:46 135168 ----a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2006-10-11 16:36 16267776 ----a-w- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2009-12-13 09:24 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 cfadisk;CompactFlash Filter Driver;c:\windows\system32\drivers\cfadisk.sys [1/6/2010 2:49 PM 3712]

S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\BRGSp50.sys [8/27/2009 3:09 PM 20608]

S3 CH341SER;CH341SER;c:\windows\system32\drivers\CH341SER.SYS [3/5/2009 12:05 PM 35824]

S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [12/24/2009 11:54 AM 131072]

S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [12/24/2009 11:54 AM 79104]

S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [12/22/2009 12:38 PM 709248]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

uInternet Settings,ProxyServer = proxy.btk.bg:80

uInternet Settings,ProxyOverride = 10.*;<local>

TCP: {1C89E15D-4F3C-4961-B682-D2EAAA6C7EF4} = 192.168.1.1,212.39.90.42

TCP: {24B0A447-301A-4EA0-A32B-041FDF187983} = 192.168.1.1

FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\c705jvq9.default\

.

**************************************************************************

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files:

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1744)

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

.

Completion time: 2010-01-20 15:00:14

ComboFix-quarantined-files.txt 2010-01-20 13:00

ComboFix2.txt 2010-01-20 09:23

ComboFix3.txt 2010-01-19 15:09

ComboFix4.txt 2010-01-19 14:50

ComboFix5.txt 2010-01-20 12:57

Pre-Run: 33 639 194 624 bytes free

Post-Run: 33 602 564 096 bytes free

- - End Of File - - 2A3E3ADB99BE80DE22F18B09FF13A4F9

Супер!

Стъпка 1:

Изтеглете The Avenger (от Swandog46) и го запазете на вашия десктоп. Разархивирайте архива на вашия десктоп, отново.

Стартирайте avenger.exe, копирайте следния скрипт и го поставете в текстовото поле на програмата:

Begin copying here:

Drivers to disable:

avgntflt


Drivers to delete:

avgntflt

Бележка: Този скрипт е създаден специално за този потребител. Ако Вие не сте този потребител, НЕ ползвайте този скрипт, защото ной може да повреди сериозно вашата система.

Уверете се, че Scan for rootkits и Automatically disable any rootkits found имат отметки.

Накрая, изберете Execute и при въпрос от страна на програмата, кликнете върху Yes, при което комюпътър ще се рестартира. След рестартирането, копирайте и поставете съдържанието на лог файла от програмата, намиращ се в C:\avenger.txt в следващия Ви коментар в тази тема.

Стъпка 2:

1) Изтеглете: ESET Online Scanner

2) Стартирайте esetsmartinstaller_enu.exe

3) Сложете отметка на YES, I accept the Terms of Use и изберете Start

4) Скенерът ще започне да изтегля компонентите, които са му необходими.

5) Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:


  • Remove found threats
  • Scan archives
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology

И накрая изберете Start

6) Скенерът ще започне да изтегля последните дефиниции.

7) След, като сканирането завърши изберете Finish.

8) Отидете в:

C:\Program Files\ESET\ESET Online Scanner

Отворете файла log.txt , копирайте съдържанието му и го поставете в следващия си пост тук.

  • Автор

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

No rootkits found!

Error: could not open driver "avgntflt"

Disablement of driver "avgntflt" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\avgntflt" not found!

Deletion of driver "avgntflt" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Completed script processing.

*******************

Finished! Terminate.

ESET

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# IEXPLORE.EXE=7.00.6000.20583 (vista_ldr.070420-1500)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=68ef07d2f9e0724292e0ecbf50b87037

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2009-12-28 09:59:29

# local_time=2009-12-28 11:59:29 (+0200, FLE Standard Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=1797 16775141 100 100 160569 38434380 0 0

# compatibility_mode=8192 67108863 100 0 3855 3855 0 0

# scanned=29404

# found=1

# cleaned=1

# scan_time=828

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\D98B0AAS\kbpgdzw[1].bmp Win32/Conficker.AE worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

# version=7

# IEXPLORE.EXE=7.00.6000.20583 (vista_ldr.070420-1500)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=68ef07d2f9e0724292e0ecbf50b87037

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2010-01-15 07:24:22

# local_time=2010-01-15 09:24:22 (+0200, FLE Standard Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=1797 16775141 100 100 4251 39980374 0 0

# compatibility_mode=8192 67108863 100 0 1549849 1549849 0 0

# scanned=28611

# found=0

# cleaned=0

# scan_time=727

ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=68ef07d2f9e0724292e0ecbf50b87037

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-01-20 03:08:57

# local_time=2010-01-20 05:08:57 (+0200, FLE Standard Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=512 16777215 100 0 184352 184352 0 0

# compatibility_mode=8192 67108863 100 0 2008331 2008331 0 0

# scanned=63438

# found=4

# cleaned=4

# scan_time=2121

C:\Documents and Settings\Administrator\Desktop\ipscan.exe Win32/NetTool.Portscan.C application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\kalinkov\flash01\_my_software\pasword\netpass.exe Win32/NetPass.102 application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\kalinkov\flash02\motorola V360 software\PCCD_Vista_32.zip probably a variant of Win32/Adware.SearchAid application (deleted - quarantined) 00000000000000000000000000000000 C

D:\kalinkov\software\motorola V360 software\PCCD_Vista_32.zip probably a variant of Win32/Adware.SearchAid application (deleted - quarantined) 00000000000000000000000000000000 C

  • Автор

Ами до последно нямаше промяна относно проблемът ми със стартирането на Windows Firewall/ICS service. Но след последното сканиране с ЕСЕТ не съм го рестартирал. Понеже машината е на работа, утре ще го рестартирам и ще видя дали ще тръгне! Благодаря ти за помощта и дано това да е всичко.

  • Автор

Ами и аз се надявах, но УВИ! Може би сме изчистили някаква гадина, но проблемът със сървиса си остава по същия начин, със същата грешки в Event Viewer. Сега: посъветваха ме да обърна внимание на service Routing and Remote Access - при мене беше на Автоматично стартиране - когато му дам "Disable" и след рестарт, service Windows Firewall/Internet Connection Sharing се вдига, но въпреки че в Control Panel/Windows Firewall е на ON, долу в system tray-я ми дава съобщение, че нямам вдигнат Firewall! Незнам какво да го правя - може би ще трябва да си продължа предната тема.

Редактирано от icemans (преглед на промените)

Изтеглете OTL (от OldTimer) и го запазете на вашия десктоп.

Кликнете два пъти върху OTL.exe, за да стартирате програмата.

Сложете отметки преди следните неща:


  • Scan all users
  • Lop check
  • Purity check

Под секцията Extra Registry, изберете Use SafeList

Кликнете на Run Scan и изчакайте да завърши сканирането. (може да отнеме 10-15 минути)

Когато завърши, публикувайте следните два лог файла:

  • OTL.txt (намира се на вашия десктоп)
  • Extras.txt (ще Ви се отвори автоматично)

  • Автор

OTL

OTL logfile created on: 21.1.2010 г. 14:32:35 - Run 1

OTL by OldTimer - Version 3.1.25.3 Folder = C:\Documents and Settings\Administrator\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.11)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

1 015,00 Mb Total Physical Memory | 701,00 Mb Available Physical Memory | 69,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 92,00% Paging File free

Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 40,20 Gb Total Space | 31,24 Gb Free Space | 77,72% Space Free | Partition Type: NTFS

Drive D: | 108,85 Gb Total Space | 100,67 Gb Free Space | 92,48% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: ADSL

Current User Name: Administrator

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.01.21 14:31:52 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

PRC - [2009.12.13 11:24:26 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2008.04.14 05:42:42 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe

PRC - [2008.04.14 05:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007.09.20 06:58:53 | 00,625,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE

PRC - [2005.01.14 09:32:38 | 00,053,248 | ---- | M] () -- C:\WINDOWS\system32\PAStiSvc.exe

========== Modules (SafeList) ==========

MOD - [2010.01.21 14:31:52 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2009.12.13 11:24:26 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)

SRV - [2009.11.20 15:26:26 | 00,036,352 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)

SRV - [2005.01.14 09:32:38 | 00,053,248 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PAStiSvc.exe -- (STI Simulator)

SRV - [2003.07.28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

========== Driver Services (SafeList) ==========

DRV - [2009.11.20 15:26:50 | 00,025,984 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)

DRV - [2009.11.20 13:23:31 | 00,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)

DRV - [2009.03.04 17:30:14 | 00,709,248 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)

DRV - [2008.10.17 10:50:00 | 00,131,072 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt)

DRV - [2008.10.17 10:50:00 | 00,079,104 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr)

DRV - [2008.04.14 00:26:50 | 00,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)

DRV - [2008.04.14 00:15:14 | 00,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)

DRV - [2008.04.13 22:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)

DRV - [2007.09.20 06:33:17 | 00,145,920 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HdAudio.sys -- (HdAudAddService)

DRV - [2007.09.20 06:33:16 | 00,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)

DRV - [2007.01.13 11:33:18 | 05,672,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)

DRV - [2006.10.12 09:52:04 | 04,387,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2006.06.05 00:00:00 | 00,035,824 | ---- | M] (www.winchiphead.com) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CH341SER.SYS -- (CH341SER)

DRV - [2006.05.10 15:00:16 | 00,156,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)

DRV - [2006.04.07 14:19:32 | 00,067,584 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\baspxp32.sys -- (Blfp)

DRV - [2006.03.01 10:24:16 | 00,290,816 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZD1211U.sys -- (ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS)

DRV - [2005.06.08 18:44:20 | 00,020,608 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BRGSp50.sys -- (BRGSp50)

DRV - [2004.10.25 13:40:58 | 00,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)

DRV - [2003.07.16 14:27:40 | 00,043,264 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)

DRV - [2002.12.24 21:18:56 | 00,003,712 | ---- | M] (Hitachi Global Storage Technologies) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\cfadisk.sys -- (cfadisk)

DRV - [2001.08.23 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\S-1-5-21-1779693145-2610261952-1204508424-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\S-1-5-21-1779693145-2610261952-1204508424-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 10.*;<local>

IE - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\S-1-5-21-1779693145-2610261952-1204508424-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.btk.bg:80

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.464

FF - prefs.js..extensions.enabledItems: [email protected]:1.0

FF - prefs.js..network.proxy.ftp: "proxy.btk.bg"

FF - prefs.js..network.proxy.ftp_port: 80

FF - prefs.js..network.proxy.gopher: "proxy.btk.bg"

FF - prefs.js..network.proxy.gopher_port: 80

FF - prefs.js..network.proxy.http: "proxy.btk.bg"

FF - prefs.js..network.proxy.http_port: 80

FF - prefs.js..network.proxy.no_proxies_on: "10.*,localhost,127.0.0.1"

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.socks: "proxy.btk.bg"

FF - prefs.js..network.proxy.socks_port: 80

FF - prefs.js..network.proxy.ssl: "proxy.btk.bg"

FF - prefs.js..network.proxy.ssl_port: 80

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.11.20 10:19:46 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.18 11:32:50 | 00,000,000 | ---D | M]

[2009.07.21 09:27:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions

[2010.01.15 08:42:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\c705jvq9.default\extensions

[2009.11.20 13:16:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\c705jvq9.default\extensions\[email protected]

[2010.01.15 08:42:02 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

[2009.11.03 03:57:59 | 00,001,083 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\911bg.xml

[2009.11.03 03:57:59 | 00,002,442 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\diribg.xml

[2009.11.03 03:57:59 | 00,001,515 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pe-bg.xml

[2009.11.03 03:57:59 | 00,001,857 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\portalbgdict.xml

[2009.11.03 03:57:59 | 00,001,220 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-bg.xml

O1 HOSTS File: ([2010.01.20 11:21:45 | 00,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O4 - HKU\.DEFAULT..\RunOnce: [showDeskFix] File not found

O4 - HKU\S-1-5-18..\RunOnce: [showDeskFix] File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O15 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\..Trusted Ranges: Range1 ([http] in Trusted sites)

O15 - HKU\S-1-5-21-1779693145-2610261952-1204508424-500\..Trusted Ranges: Range2 ([http] in Trusted sites)

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)

O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010.01.15 15:17:30 | 00,000,044 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.01.21 14:31:41 | 00,546,816 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2010.01.20 16:29:49 | 00,000,000 | ---D | C] -- C:\Avenger

[2010.01.20 14:57:03 | 00,000,000 | ---D | C] -- C:\Tool

[2010.01.20 11:20:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp

[2010.01.19 14:15:59 | 00,000,000 | RHSD | C] -- C:\cmdcons

[2010.01.19 14:14:46 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2010.01.19 14:14:45 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2010.01.19 14:14:45 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2010.01.19 14:14:45 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2010.01.19 14:14:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2010.01.19 14:14:13 | 00,000,000 | ---D | C] -- C:\Qoobox

[2010.01.19 13:01:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump

[2010.01.19 11:32:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\New Folder

[2010.01.18 14:21:04 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2010.01.18 14:00:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes

[2010.01.18 14:00:50 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010.01.18 14:00:48 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010.01.18 14:00:48 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010.01.18 14:00:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2010.01.15 17:15:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch

[2010.01.15 17:11:10 | 01,306,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll

[2010.01.15 17:11:10 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6r.dll

[2010.01.15 17:11:09 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpcdll.dll

[2010.01.15 17:11:04 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irbus.sys

[2010.01.15 17:11:04 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll

[2010.01.15 17:11:04 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll

[2010.01.15 17:11:04 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsdupd.exe

[2010.01.15 17:11:03 | 00,377,984 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvaa.dll

[2010.01.15 17:11:03 | 00,229,376 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2cqag.dll

[2010.01.15 17:11:02 | 01,888,992 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3duag.dll

[2010.01.15 17:11:02 | 00,870,784 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3d1ag.dll

[2010.01.15 17:11:02 | 00,650,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3ui.dll

[2010.01.15 17:11:02 | 00,516,768 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ativvaxx.dll

[2010.01.15 17:11:02 | 00,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\azroles.dll

[2010.01.15 17:11:02 | 00,201,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvag.dll

[2010.01.15 17:11:02 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3cfg.dll

[2010.01.15 17:11:02 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3msm.dll

[2010.01.15 17:11:02 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dhcpqec.dll

[2010.01.15 17:11:02 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3gpclnt.dll

[2010.01.15 17:11:02 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsroam.dll

[2010.01.15 17:11:02 | 00,032,768 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativtmxx.dll

[2010.01.15 17:11:02 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3api.dll

[2010.01.15 17:11:02 | 00,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativmvxx.ax

[2010.01.15 17:11:02 | 00,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativdaxx.ax

[2010.01.15 17:11:02 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3dlg.dll

[2010.01.15 17:11:01 | 00,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapp3hst.dll

[2010.01.15 17:11:01 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapphost.dll

[2010.01.15 17:11:01 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappcfg.dll

[2010.01.15 17:11:01 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappgnui.dll

[2010.01.15 17:11:01 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapqec.dll

[2010.01.15 17:11:01 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappprxy.dll

[2010.01.15 17:11:01 | 00,032,285 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\hsfcisp2.dll

[2010.01.15 17:11:01 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapolqec.dll

[2010.01.15 17:11:00 | 00,086,016 | ---- | C] (Conexant) -- C:\WINDOWS\System32\mdmxsdk.dll

[2010.01.15 17:11:00 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\l2gpstore.dll

[2010.01.15 17:10:59 | 04,274,816 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nv4_disp.dll

[2010.01.15 17:10:59 | 01,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\mtxparhd.dll

[2010.01.15 17:10:59 | 00,412,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\photometadatahandler.dll

[2010.01.15 17:10:59 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napmontr.dll

[2010.01.15 17:10:59 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napstat.exe

[2010.01.15 17:10:59 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mssha.dll

[2010.01.15 17:10:59 | 00,144,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\onex.dll

[2010.01.15 17:10:59 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msshavmsg.dll

[2010.01.15 17:10:59 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napipsec.dll

[2010.01.15 17:10:58 | 00,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\s3gnb.dll

[2010.01.15 17:10:58 | 00,286,792 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slextspk.dll

[2010.01.15 17:10:58 | 00,188,508 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slgen.dll

[2010.01.15 17:10:58 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qagent.dll

[2010.01.15 17:10:58 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qutil.dll

[2010.01.15 17:10:58 | 00,073,832 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slcoinst.dll

[2010.01.15 17:10:58 | 00,073,796 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slserv.exe

[2010.01.15 17:10:58 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qcliprov.dll

[2010.01.15 17:10:58 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasqec.dll

[2010.01.15 17:10:58 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slrundll.exe

[2010.01.15 17:10:58 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe

[2010.01.15 17:10:57 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecs.dll

[2010.01.15 17:10:57 | 00,346,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\windowscodecsext.dll

[2010.01.15 17:10:57 | 00,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmphoto.dll

[2010.01.15 17:10:56 | 00,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\slrundll.exe

[2010.01.15 17:10:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting

[2010.01.15 17:10:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en

[2010.01.15 17:10:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits

[2010.01.15 17:09:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles

[2010.01.15 17:07:48 | 00,043,008 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\drivers\amdagp.sys

[2010.01.15 17:07:48 | 00,004,255 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv01nt5.dll

[2010.01.15 17:07:48 | 00,003,967 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv02nt5.dll

[2010.01.15 17:07:48 | 00,003,775 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv11nt5.dll

[2010.01.15 17:07:48 | 00,003,711 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv09nt5.dll

[2010.01.15 17:07:48 | 00,003,647 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv07nt5.dll

[2010.01.15 17:07:48 | 00,003,615 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv05nt5.dll

[2010.01.15 17:07:48 | 00,003,135 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\adv08nt5.dll

[2010.01.15 17:07:47 | 00,701,440 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtag.sys

[2010.01.15 17:07:47 | 00,327,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtaa.sys

[2010.01.15 17:07:47 | 00,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinrvxx.sys

[2010.01.15 17:07:47 | 00,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atintuxx.sys

[2010.01.15 17:07:47 | 00,063,663 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1rvxx.sys

[2010.01.15 17:07:47 | 00,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxsxx.sys

[2010.01.15 17:07:47 | 00,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinbtxx.sys

[2010.01.15 17:07:47 | 00,056,623 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1btxx.sys

[2010.01.15 17:07:47 | 00,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinraxx.sys

[2010.01.15 17:07:47 | 00,036,463 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1tuxx.sys

[2010.01.15 17:07:47 | 00,034,735 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xsxx.sys

[2010.01.15 17:07:47 | 00,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxbxx.sys

[2010.01.15 17:07:47 | 00,030,671 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1raxx.sys

[2010.01.15 17:07:47 | 00,029,455 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xbxx.sys

[2010.01.15 17:07:47 | 00,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinsnxx.sys

[2010.01.15 17:07:47 | 00,026,367 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1snxx.sys

[2010.01.15 17:07:47 | 00,025,471 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv04nt5.dll

[2010.01.15 17:07:47 | 00,021,343 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1ttxx.sys

[2010.01.15 17:07:47 | 00,021,183 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv01nt5.dll

[2010.01.15 17:07:47 | 00,017,279 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv10nt5.dll

[2010.01.15 17:07:47 | 00,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinpdxx.sys

[2010.01.15 17:07:47 | 00,014,143 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv06nt5.dll

[2010.01.15 17:07:47 | 00,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinttxx.sys

[2010.01.15 17:07:47 | 00,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinmdxx.sys

[2010.01.15 17:07:47 | 00,012,047 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1pdxx.sys

[2010.01.15 17:07:47 | 00,011,615 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1mdxx.sys

[2010.01.15 17:07:47 | 00,011,359 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\atv02nt5.dll

[2010.01.15 17:07:46 | 01,041,536 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfdpsp2.sys

[2010.01.15 17:07:46 | 00,685,056 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfcxts2.sys

[2010.01.15 17:07:46 | 00,220,032 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\hsfbs2s2.sys

[2010.01.15 17:07:46 | 00,126,686 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlmnt5.sys

[2010.01.15 17:07:46 | 00,036,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthprint.sys

[2010.01.15 17:07:46 | 00,015,423 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\ch7xxnt5.dll

[2010.01.15 17:07:46 | 00,011,868 | ---- | C] (Conexant) -- C:\WINDOWS\System32\drivers\mdmxsdk.sys

[2010.01.15 17:07:45 | 01,897,408 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nv4_mini.sys

[2010.01.15 17:07:45 | 01,309,184 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlstrm.sys

[2010.01.15 17:07:45 | 00,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\drivers\mtxparhm.sys

[2010.01.15 17:07:45 | 00,180,360 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\ntmtlfax.sys

[2010.01.15 17:07:45 | 00,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\drivers\s3gnbm.sys

[2010.01.15 17:07:45 | 00,129,535 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnt7554.sys

[2010.01.15 17:07:45 | 00,040,960 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\sisagp.sys

[2010.01.15 17:07:45 | 00,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismpx.sys

[2010.01.15 17:07:45 | 00,013,776 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\recagent.sys

[2010.01.15 17:07:45 | 00,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mutohpen.sys

[2010.01.15 17:07:45 | 00,003,901 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\siint5.dll

[2010.01.15 17:07:44 | 00,404,990 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slntamr.sys

[2010.01.15 17:07:44 | 00,095,424 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnthal.sys

[2010.01.15 17:07:44 | 00,025,471 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\watv10nt.sys

[2010.01.15 17:07:44 | 00,022,271 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\watv06nt.sys

[2010.01.15 17:07:44 | 00,013,240 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slwdmsup.sys

[2010.01.15 17:07:44 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023x.sys

[2010.01.15 17:07:44 | 00,011,935 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv11nt.sys

[2010.01.15 17:07:44 | 00,011,871 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv09nt.sys

[2010.01.15 17:07:44 | 00,011,807 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv07nt.sys

[2010.01.15 17:07:44 | 00,011,325 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\vchnt5.dll

[2010.01.15 17:07:44 | 00,011,295 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\drivers\wadv08nt.sys

[2010.01.15 17:07:44 | 00,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbali.sys

[2010.01.15 17:06:23 | 00,026,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe

[2010.01.15 17:04:19 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$

[2010.01.13 11:07:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\uTorrent

[2010.01.06 14:49:39 | 00,003,712 | ---- | C] (Hitachi Global Storage Technologies) -- C:\WINDOWS\System32\drivers\cfadisk.sys

[2009.12.28 11:41:25 | 00,000,000 | ---D | C] -- C:\Program Files\ESET

[2009.12.24 11:54:59 | 00,767,328 | ---- | C] (Kings Information & Network) -- C:\WINDOWS\System32\kdfinj.dll

[2009.12.24 11:54:58 | 00,131,072 | ---- | C] (AhnLab, Inc.) -- C:\WINDOWS\System32\drivers\Mkd2kfNT.sys

[2009.12.24 11:54:58 | 00,079,104 | ---- | C] (AhnLab, Inc.) -- C:\WINDOWS\System32\drivers\Mkd2Nadr.sys

[2009.11.20 13:22:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi

[2009.07.10 13:33:06 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2009.07.10 13:30:10 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[2009.01.19 12:05:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe

[2009.01.19 12:01:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe

[2007.10.31 05:46:35 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2007.10.31 05:46:35 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.01.21 14:31:52 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe

[2010.01.21 14:04:15 | 00,355,944 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010.01.21 14:04:15 | 00,311,740 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010.01.21 14:04:15 | 00,040,128 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010.01.21 14:00:12 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010.01.21 14:00:11 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010.01.21 13:59:37 | 03,825,664 | ---- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT

[2010.01.21 13:59:37 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini

[2010.01.20 16:31:36 | 02,672,312 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\esetsmartinstaller_enu.exe

[2010.01.20 16:28:40 | 00,000,000 | ---- | M] () -- C:\backup.reg

[2010.01.20 14:59:30 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini

[2010.01.20 14:56:10 | 03,830,599 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\Tool.exe

[2010.01.20 14:35:00 | 00,724,952 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\avenger.zip

[2010.01.20 11:21:45 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2010.01.19 14:16:02 | 00,000,281 | RHS- | M] () -- C:\boot.ini

[2010.01.19 11:34:18 | 00,001,717 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk

[2010.01.19 11:33:26 | 00,284,915 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\gmer.zip

[2010.01.18 15:41:06 | 05,858,178 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db

[2010.01.18 14:00:52 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010.01.18 10:25:14 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010.01.16 11:54:03 | 00,064,808 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2010.01.15 17:15:09 | 00,243,128 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010.01.15 17:07:30 | 00,250,048 | RHS- | M] () -- C:\ntldr

[2010.01.15 16:13:06 | 00,000,793 | ---- | M] () -- C:\WINDOWS\win.ini

[2010.01.15 16:13:06 | 00,000,211 | ---- | M] () -- C:\Boot.bak

[2010.01.15 15:17:30 | 00,000,044 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010.01.15 09:11:01 | 00,004,124 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20100115_091057.reg

[2010.01.07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010.01.07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009.12.29 14:30:38 | 00,001,943 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009.12.24 11:54:59 | 00,767,328 | ---- | M] (Kings Information & Network) -- C:\WINDOWS\System32\kdfinj.dll

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.01.20 16:31:36 | 02,672,312 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\esetsmartinstaller_enu.exe

[2010.01.20 14:56:10 | 03,830,599 | R--- | C] () -- C:\Documents and Settings\Administrator\Desktop\Tool.exe

[2010.01.20 14:36:46 | 00,000,000 | ---- | C] () -- C:\backup.reg

[2010.01.20 14:35:15 | 00,731,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\avenger.exe

[2010.01.20 14:34:48 | 00,724,952 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\avenger.zip

[2010.01.19 14:16:02 | 00,000,211 | ---- | C] () -- C:\Boot.bak

[2010.01.19 14:15:59 | 00,260,272 | ---- | C] () -- C:\cmldr

[2010.01.19 14:14:46 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2010.01.19 14:14:45 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2010.01.19 14:14:45 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2010.01.19 14:14:45 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2010.01.19 14:14:45 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2010.01.19 11:33:24 | 00,284,915 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\gmer.zip

[2010.01.18 14:21:04 | 00,001,717 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk

[2010.01.18 14:00:52 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010.01.15 17:07:47 | 00,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod

[2010.01.15 17:07:46 | 00,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty

[2010.01.15 17:07:45 | 00,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img

[2010.01.15 09:10:58 | 00,004,124 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20100115_091057.reg

[2009.12.14 13:17:40 | 00,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2009.08.27 15:09:43 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll

[2009.08.27 15:09:43 | 00,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL

[2008.02.11 17:14:10 | 00,008,192 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2008.01.22 17:27:40 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\kbdBF.dll

[2008.01.22 17:27:40 | 00,006,325 | ---- | C] () -- C:\Program Files\BgphXP.inf

[2007.12.10 01:29:07 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2007.12.10 00:26:39 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2007.11.01 22:54:11 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2007.10.31 05:54:36 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4764.dll

[2007.10.31 05:54:35 | 00,650,608 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll

[2003.01.07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009.11.20 11:51:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IP-TV Player

[2008.12.20 08:33:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Kingston

[2010.01.15 08:41:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\uTorrent

[2009.12.22 12:38:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ralink Driver

========== Purity Check ==========

< End of report >

Extras

OTL Extras logfile created on: 21.1.2010 г. 14:32:35 - Run 1

OTL by OldTimer - Version 3.1.25.3 Folder = C:\Documents and Settings\Administrator\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.11)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'

1 015,00 Mb Total Physical Memory | 701,00 Mb Available Physical Memory | 69,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 92,00% Paging File free

Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 40,20 Gb Total Space | 31,24 Gb Free Space | 77,72% Space Free | Partition Type: NTFS

Drive D: | 108,85 Gb Total Space | 100,67 Gb Free Space | 92,48% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: ADSL

Current User Name: Administrator

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1779693145-2610261952-1204508424-500\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17

"{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = Ralink RT2870 Wireless LAN Card

"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6

"{581CE7EA-A30D-0000-1211-088635773309}" = ZyDAS IEEE 802.11 b+g Wireless LAN - USB

"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com

"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders

"{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom NetXtreme Ethernet Controller

"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR

"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2

"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{FB64BF25-3593-4E4E-AA85-84AEF1D1475F}" = Broadcom Management Programs

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Advanced IP Address Calculator v1.1" = Advanced IP Address Calculator v1.1

"Bulgarian(Phonetic)" = BulgarianPhonetic XP by G. Atanasov

"CCleaner" = CCleaner

"Cisco Networking Academy curriculum_is1" = Cisco Networking Academy curriculum 4.0.0.0

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"ESET Online Scanner" = ESET Online Scanner v3

"HDMI" = Intel® Graphics Media Accelerator Driver

"IP-TV_Player" = IP-TV Player 0.28.1

"KLiteCodecPack_is1" = K-Lite Codec Pack 5.4.4 (Standard)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)

"NVIDIA Drivers" = NVIDIA Drivers

"OpenVPN" = OpenVPN 2.1_rc22

"Packet Tracer 4.11_is1" = Packet Tracer 4.11

"PaperlessPrinter_is1" = PaperlessPrinter version 3.0

"RealVNC_is1" = VNC Free Edition 4.1.2

"SA Dictionary 2005 T2" = SA Dictionary 2005 T2

"Termiserv" = sala's WinXP SP2 Terminal Server Patch

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 29.12.2009 г. 04:33:33 | Computer Name = ADSL | Source = Application Hang | ID = 1002

Description = Hanging application IEXPLORE.EXE, version 7.0.6000.20583, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30.12.2009 г. 17:25:50 | Computer Name = ADSL | Source = Application Error | ID = 1000

Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting

module AcGenral.dll, version 5.1.2600.3163, fault address 0x000116e2.

Error - 13.1.2010 г. 08:22:10 | Computer Name = ADSL | Source = Application Hang | ID = 1002

Description = Hanging application IEXPLORE.EXE, version 7.0.6000.20583, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 15.1.2010 г. 02:43:00 | Computer Name = ADSL | Source = Avira AntiVir | ID = 4110

Description =

Error - 15.1.2010 г. 02:55:11 | Computer Name = ADSL | Source = Avira AntiVir | ID = 4110

Description =

Error - 15.1.2010 г. 02:59:47 | Computer Name = ADSL | Source = Avira AntiVir | ID = 4110

Description =

Error - 19.1.2010 г. 06:20:04 | Computer Name = ADSL | Source = Application Hang | ID = 1002

Description = Hanging application IEXPLORE.EXE, version 7.0.6000.20583, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19.1.2010 г. 08:07:05 | Computer Name = ADSL | Source = Application Hang | ID = 1002

Description = Hanging application IEXPLORE.EXE, version 7.0.6000.20583, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19.1.2010 г. 08:07:59 | Computer Name = ADSL | Source = Application Hang | ID = 1002

Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19.1.2010 г. 08:08:03 | Computer Name = ADSL | Source = Application Hang | ID = 1002

Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]

Error - 20.1.2010 г. 10:30:03 | Computer Name = ADSL | Source = Service Control Manager | ID = 7023

Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated

with the following error: %%2147500037

Error - 20.1.2010 г. 10:30:19 | Computer Name = ADSL | Source = sr | ID = 1

Description = The System Restore filter encountered the unexpected error '0xC0000001'

while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring

the volume.

Error - 21.1.2010 г. 03:28:36 | Computer Name = ADSL | Source = ipnathlp | ID = 32006

Description = The Internet Connection Sharing service could not start because another

process has taken control of the kernel-mode translation module. This may occur

when the Connection Sharing component has been installed in the Routing and Remote

Access Manager. If this is the case, please remove the Connection Sharing component

and restart the Internet Connection Sharing service.

Error - 21.1.2010 г. 03:28:36 | Computer Name = ADSL | Source = Service Control Manager | ID = 7023

Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated

with the following error: %%2147500037

Error - 21.1.2010 г. 04:27:17 | Computer Name = ADSL | Source = Tcpip | ID = 4199

Description = The system detected an address conflict for IP address 192.168.1.2

with the system having network hardware address 00:15:AF:DA:DE:95. Network operations

on this system may be disrupted as a result.

Error - 21.1.2010 г. 04:57:35 | Computer Name = ADSL | Source = Tcpip | ID = 4199

Description = The system detected an address conflict for IP address 192.168.1.2

with the system having network hardware address 00:15:AF:DA:DE:95. Network operations

on this system may be disrupted as a result.

Error - 21.1.2010 г. 05:04:31 | Computer Name = ADSL | Source = Tcpip | ID = 4199

Description = The system detected an address conflict for IP address 192.168.1.2

with the system having network hardware address 00:15:AF:DA:DE:95. Network operations

on this system may be disrupted as a result.

Error - 21.1.2010 г. 08:00:15 | Computer Name = ADSL | Source = ipnathlp | ID = 32006

Description = The Internet Connection Sharing service could not start because another

process has taken control of the kernel-mode translation module. This may occur

when the Connection Sharing component has been installed in the Routing and Remote

Access Manager. If this is the case, please remove the Connection Sharing component

and restart the Internet Connection Sharing service.

Error - 21.1.2010 г. 08:00:15 | Computer Name = ADSL | Source = Service Control Manager | ID = 7023

Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated

with the following error: %%2147500037

Error - 21.1.2010 г. 08:00:36 | Computer Name = ADSL | Source = NetBT | ID = 4307

Description = Initialization failed because the transport refused to open initial

Addresses.

< End of report >

Виждам някои проблеми с svchost, explorer и с правата на приложенията.

Стъпка 1:

Изтеглете => FixPolicies

Запазете го някъде на декстопа.Кликнете два пъти върху файла и изберете Install.Ще се създаде папка с името FixPolicies на десктопа.Отворете я и стартирайте файла Fix_policies.cmd.

Стъпка 2:

Svchost: тук

Explorer: тук

Борбата с Conficker е загубена:clap:Тъкмо си помислиш всичко вече е ок и след 5 дена пак нова зараза.

  • Автор

Maniac, няма ефект за сега!

Изтеглете AVZ Antiviral Toolkit и го запазете на вашия десктоп.

  • Разархивирайте avz4.zip отново на вашия десктоп
  • Влезте в разархивираната папка avz4 и стартирайте avz.exe
  • Стартирайте автоматичното обновление на програмата, кликайки върху бутона avz-update-button.png, който се намира в дясната част на прозореца. Накрая изберете Start.

Бележка: Ако получите съобщение за грешка, изберете алтернативен източник на обновления, последван от кликане на бутона Start

  • Накрая затворете програмата и я стартирайте отново.
  • Изберете File -> Standard scripts и сложете отметка пред Healing/Quarantine and Advanced System Analysis

avz-standardscripts-healing.png

  • Изберете Execute selected scripts, при което ще бъде извършено автоматично сканиране, лекуване и повторно сканиране на системата.
  • Ще бъде генериран лог файл, който ще се намира в директорията на AVZ в папката LOG и ще е с име virusinfo_syscure.zip
  • Най-вероятно ще бъде необходимо рестартиране на системата.

След рестартирането:

  • Стартирайте avz.exe
  • Изберете File -> Standard scripts и сложете отметка пред Изберете File -> Standard scripts и сложете отметка пред Advanced System Analysis

avz-standardscripts.png

  • Изберете Execute selected scripts, при което ще бъде извършено автоматично сканиране, лекуване и повторно сканиране на системата.
  • Ще бъде генериран лог файл, който ще се намира в директорията на AVZ в папката LOG и ще е с име virusinfo_syscheck.zip

Накрая, прикрепете към вашия коментар: virusinfo_syscure.zip и virusinfo_syscheck.zip

  • Автор

На мястото на Healing/Quarantine and Advanced System Analysis пише Advanced System Analysis with malware removal mode enabled.

  • Автор

Maniac да избирам ли "Advanced System Analysis with malware removal mode enabled" ?

Редактирано от icemans (преглед на промените)

  • Автор

Добре, но нямам опция "Healing/Quarantine and Advanced System Analysis", както си описал по-горе?!

  • Автор

Само Advanced System Analysis имам, но нали преди малко ми каза това след рестартирането да не го изпълнявам, а то именно Advanced System Analysis. Преди рестарта си посочил Healing/Quarantine and Advanced System Analysis, но аз на негово място имам Advanced System Analysis with malware removal mode enabled.

По принцип трябва да се генерират два лог файла, а на мен ми трябва само този първия (преди рестартирането). Генерира ли ти първия лог файл?

  • Автор

Сега, може би аз не съм достатъчно ясен, за което ще ме извиниш. Според описанията по-горе, за да извърша първото сканиране, което да ми изведе лог файл, аз трябва да сложа отметка на Healing/Quarantine and Advanced System Analysis - а аз нямам такава опция!!!

  • Автор

Maniac, братле! Благодаря ти, че вземаш нещата присърце, но ще трябва да починем малко, тъй като ще съм 5 дена в отпуск, а компа е в службата! Не ми се искаше точно по средата да спрем, но няма начин - няма да имам достъп! Ще пусна инфо в първия момент, когато имам достъп и направя нещо! Благодаря ти още веднъж.

  • 2 седмици по-късно...
  • Автор

Вече съм на линия! Така сканирах с Avira Rescue CD - продължи 18мин. - alert- 16, renamed - 16. Но след рестарта относно моя проблем нямаше развитие! Направи ми впечатление обаче, че когато пробвах диска на моя компютър ми отне около 2 часа и повече за сканиране, а тука само 18 мин. - дали е редно! Вярно, че моя хард е по-голям, но пък нямам кой знае колко информация на него - по-голямата му част е празна! Както и да е - казвайте какво ще правим от тук нататък!

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.