Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

win32 rootkit.kryptik.af trojan [РЕШЕН]

Featured Replies

Здравейте,

четвъртък вечерта ( 25 02 2010 ) антивирусната ми (nod32) алармира за наличието на троянски кон. алармира за около 10 файла със съобщение че ги вкарва под карантина. няколко часа по късно установих че вируса е изпратил моите юзернаме и парола за фтп достъп към сайт който подържам и беше инсталирал кодове в source на някои файлове на сървъра. оправих това сканирах отново този път не излезе нищо, инсталирах и spyware doctor който откри около 20 проблема и ги поправи. преди малко обаче антивирусната отново сигнализира за наличието на win32 rootkit.kryptik.af trojan във файлове в директория system32. системата работи тромаво, при процесите имам един svhost който заема на 100% процесора. това мога да дам като информация, логовете ще пусна във следващия си пост

Редактирано от poslushen (преглед на промените)

*. Временно спрете защитата на антивирусната си програма!.

*. Изтеглете Combofix.

*. Запазете го на на декстопа.

*. Стартирайте инструмента с двукратен клик на мишката.

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

  • Автор

Логовете от Malwarebytes и HijackThis:

Malwarebytes' Anti-Malware 1.44

Database version: 3799

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

27.2.2010 г. 05:14:07

mbam-log-2010-02-27 (05-14-07).txt

Scan type: Full Scan (C:\|D:\|)

Objects scanned: 203241

Time elapsed: 33 minute(s), 15 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 3

Folders Infected: 0

Files Infected: 4

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Documents and Settings\Adrian\Start Menu\Programs\Startup\winesm32.exe (Worm.KoobFace) -> Delete on reboot.

C:\Documents and Settings\Adrian\Favorites\Free Porn Sex Porno - a group of young one have a sex party.url (Rogue.Link) -> Quarantined and deleted successfully.

C:\Documents and Settings\Adrian\Favorites\Free Porn Sex Porno - Cute girl with Rodney Moore does anal and receives facial.url (Rogue.Link) -> Quarantined and deleted successfully.

C:\Documents and Settings\Adrian\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.

--------------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 05:22:58, on 27.2.2010 г.

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\Eset\nod32kui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Spyware Doctor\swdoctor.exe

C:\Program Files\Rainlendar\Rainlendar.exe

C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe

C:\Program Files\Microsoft LifeCam\MSCamS32.exe

C:\Program Files\Eset\nod32krn.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

C:\Program Files\Spyware Doctor\sdhelp.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\HJT\kaldata.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: (no name) - - (no file)

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211800259437

O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll

O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.68.31.137/activex/AMC.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{C969EE38-2110-4871-8507-43738E67EC08}: NameServer = 212.25.58.229 212.25.58.2

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: XAMPP Service (XAMPP) - Unknown owner - c:\xampp\service.exe (file missing)

--

End of file - 6638 bytes

----------------------------------------------------------------------------------------------------------------

От инструкциите не разбрах дали да избера FIX CHEKED на HijackThis затова извличам само лог-а. Ако е нужно ще повторя сканирането и ще поправя грешките които дава.

От инструкциите не разбрах дали да избера FIX CHEKED на HijackThis затова извличам само лог-а. Ако е нужно ще повторя сканирането и ще поправя грешките които дава.

Нищо не натискайте в HijackThis без да сме ви дали някакви допълнителни инструкции !

Също така очаквам от вас лог от Combofix. (вижте предишния ми пост).

  • Автор

ComboFix 10-02-26.01 - Adrian 02.2010 г. 5:43.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.447.165 [GMT 2:00]

Running from: c:\documents and settings\Adrian\Desktop\ComboFix.exe

AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

.

((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))

.

2010-02-27 03:21 . 2010-02-27 03:22 -------- d-----w- C:\HJT

2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\Adrian\Application Data\Malwarebytes

2010-02-27 02:38 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-27 02:38 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-02-27 00:09 . 2005-12-13 13:18 50048 ----a-w- c:\windows\system32\drivers\ikhlayer.sys

2010-02-27 00:08 . 2010-02-27 01:16 -------- d-----w- c:\program files\Spyware Doctor

2010-02-27 00:08 . 2010-02-27 00:08 -------- d-----w- c:\documents and settings\Adrian\Application Data\PC Tools

2010-02-26 21:55 . 2010-02-26 23:51 -------- d-----w- c:\windows\BDOSCAN8

2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\Adrian\PrivacIE

2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2010-02-26 16:14 . 2010-02-26 16:14 -------- d-sh--w- c:\documents and settings\Adrian\IETldCache

2010-02-26 16:05 . 2010-02-26 16:05 -------- dc-h--w- c:\windows\ie8

2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys

2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys

2010-02-26 04:22 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys

2010-02-26 04:22 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys

2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys

2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\Changer.sys

2010-02-26 03:09 . 2010-02-26 03:10 5515984 ----a-w- c:\documents and settings\Adrian\Application Data\TVU Networks\AutoUpgrade\TVUPlayer2.5.2.1.exe

2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\program files\Photodex

2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Photodex

2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\Adrian\Application Data\Photodex

2010-02-11 19:25 . 2010-02-26 22:29 -------- d-----w- c:\program files\PokerStars

2010-02-07 12:56 . 2010-02-27 01:55 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-02-05 20:22 . 2008-03-05 14:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll

2010-02-05 20:22 . 2008-03-05 14:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll

2010-02-05 20:22 . 2008-03-05 14:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll

2010-02-05 20:22 . 2008-03-05 13:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll

2010-02-05 20:22 . 2008-02-05 21:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll

2010-02-05 20:22 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll

2010-01-30 17:21 . 2010-02-27 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton

2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec

2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller

2010-01-30 14:20 . 2010-01-30 14:24 -------- d-----w- c:\windows\system32\Adobe

2010-01-29 17:06 . 2010-02-06 23:35 -------- d-----w- c:\program files\Videos

2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\documents and settings\Adrian\Application Data\FastStone

2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\program files\FastStone Capture

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-27 02:26 . 2010-02-27 02:26 16 ----a-w- c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat

2010-02-27 02:22 . 2009-02-07 00:35 -------- d-----w- c:\program files\Pazera_Free_FLV_to_AVI_Converter

2010-02-27 01:23 . 2009-07-03 06:47 -------- d-----w- c:\documents and settings\Adrian\Application Data\FileZilla

2010-02-26 16:01 . 2010-02-26 16:01 8 ----a-w- c:\documents and settings\NetworkService\Application Data\rbuwzv.dat

2010-02-26 12:40 . 2008-10-29 18:30 14 ----a-w- c:\windows\popcinfo.dat

2010-02-26 04:20 . 2010-02-26 04:20 12 ----a-w- c:\documents and settings\LocalService\Application Data\rbuwzv.dat

2010-02-25 21:52 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\skypePM

2010-02-23 16:51 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\Skype

2010-02-11 19:23 . 2010-01-21 22:10 -------- d-----w- c:\program files\PokerStars.NET

2010-01-21 19:01 . 2008-05-23 16:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\documents and settings\Adrian\Application Data\Media Player Classic

2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\program files\K-Lite Codec Pack

2010-01-18 13:41 . 2010-01-18 13:00 -------- d-----w- c:\program files\ACE Mega CoDecS Pack

2010-01-18 13:41 . 2010-02-27 01:12 831 ----a-w- c:\windows\system.tmp

2010-01-18 12:51 . 2010-01-18 12:07 -------- d-----w- c:\program files\BSR Screen Recorder 4

2010-01-18 12:13 . 2010-01-18 12:07 2048 ----a-w- c:\windows\system32\Tr_sttool.dat

2009-12-29 06:38 . 2009-12-29 06:33 -------- d-----w- c:\program files\TGIANT

2009-12-22 14:56 . 2008-05-23 14:46 38664 ----a-w- c:\documents and settings\Adrian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-10-02 19:40 . 2009-10-02 19:33 120566929 ----a-w- c:\program files\Championship Manager 01-02.rar

2008-07-31 16:59 . 2008-06-03 20:20 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll

2008-07-31 16:59 . 2008-06-03 20:20 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll

2008-07-31 16:59 . 2008-06-03 20:20 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll

2005-05-13 15:12 . 2005-05-13 15:12 217073 --sha-r- c:\windows\meta4.exe

2005-10-24 09:13 . 2005-10-24 09:13 66560 --sha-r- c:\windows\MOTA113.exe

2005-10-13 19:27 . 2005-10-13 19:27 422400 --sha-r- c:\windows\x2.64.exe

2005-10-07 17:14 . 2005-10-07 17:14 308224 --sha-r- c:\windows\system32\avisynth.dll

2005-07-14 10:31 . 2005-07-14 10:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll

2005-06-26 13:32 . 2005-06-26 13:32 616448 --sha-r- c:\windows\system32\cygwin1.dll

2005-06-21 20:37 . 2005-06-21 20:37 45568 --sha-r- c:\windows\system32\cygz.dll

2004-01-24 22:00 . 2004-01-24 22:00 70656 --sha-r- c:\windows\system32\i420vfw.dll

2006-04-27 08:24 . 2006-04-27 08:24 2945024 --sha-r- c:\windows\system32\Smab.dll

2005-02-28 11:16 . 2005-02-28 11:16 240128 --sha-r- c:\windows\system32\x.264.exe

2004-01-24 22:00 . 2004-01-24 22:00 217088 --sha-r- c:\windows\system32\yv12vfw.dll

.

------- Sigcheck -------

[-] 2008-05-22 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-12-13 1976544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]

"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-05-24 950664]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]

"nwiz"="nwiz.exe" [2006-10-22 1622016]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-12-13 1976544]

c:\documents and settings\Adrian\Start Menu\Programs\Startup\

Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2008-5-23 118784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-6 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"

"VX1000"=c:\windows\vVX1000.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"21362:TCP"= 21362:TCP:BitComet 21362 TCP

"21362:UDP"= 21362:UDP:BitComet 21362 UDP

R2 XAMPP;XAMPP Service;c:\xampp\service.exe [x]

R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]

S0 d346bus;d346bus;c:\windows\system32\DRIVERS\d346bus.sys [2004-03-12 156800]

S0 d346prt;d346prt;c:\windows\System32\Drivers\d346prt.sys [2004-03-12 5248]

S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-05-24 15424]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

.

Contents of the 'Scheduled Tasks' folder

2010-02-26 c:\windows\Tasks\1-Click Maintenance.job

- c:\program files\TuneUp Utilities 2007en\SystemOptimizer.exe [2007-04-26 19:51]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe

LSP: c:\windows\system32\imon.dll

TCP: {C969EE38-2110-4871-8507-43738E67EC08} = 212.25.58.229 212.25.58.2

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://193.68.31.137/activex/AMC.cab

DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab

.

- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

AddRemove-HijackThis - c:\hjt\HijackThis.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-27 05:54

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]

"ImagePath"="\??\c:\docume~1\Adrian\LOCALS~1\Temp\mc21.tmp"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(648)

c:\windows\system32\imon.dll

- - - - - - - > 'explorer.exe'(1788)

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Completion time: 2010-02-27 05:57:22

ComboFix-quarantined-files.txt 2010-02-27 03:57

Pre-Run: 2 827 997 184 bytes free

Post-Run: 4 655 624 192 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - D5E4C859C16C4D0DACB57E4F3ED1B4B9

Определено някои от програмите с които сте почиствали (NOD32 или Spyware Doctor) явно са се справили с рууткита.

Все пак има някои остатъци в лог файла които е добре да премахнем:

*. Отворете notepad.exe и с copy/paste въведете следната информация:


http://www.kaldata.com/forums/index.php?showtopic=150464


KILLALL::

Collect::

c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat

c:\documents and settings\NetworkService\Application Data\rbuwzv.dat

c:\windows\popcinfo.dat

c:\documents and settings\LocalService\Application Data\rbuwzv.dat

c:\windows\system.tmp

SRPeek::

c:\windows\system32\sfcfiles.dll

Registry::

NetSvc::

sysrst::

Запазете файла с име CFScript и го провлачете и пуснете в Combofix (както е показано на картинката отдолу).

cfscript10uc2.gif

*. По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

*. Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си пост.

  • Автор

да, и натоварването от svhost на процесора изчезна, ето лога:

ComboFix 10-02-26.01 - Adrian 02.2010 г. 6:24.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.447.200 [GMT 2:00]

Running from: c:\documents and settings\Adrian\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\Adrian\Desktop\CFScript.txt

AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

* Resident AV is active

file zipped: c:\documents and settings\LocalService\Application Data\rbuwzv.dat

file zipped: c:\documents and settings\NetworkService\Application Data\rbuwzv.dat

file zipped: c:\windows\popcinfo.dat

file zipped: c:\windows\system.tmp

file zipped: c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat

.

The following files were disabled during the run:

c:\progra~1\SPYWAR~1\Tools\swpg.dat

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\LocalService\Application Data\rbuwzv.dat

c:\documents and settings\NetworkService\Application Data\rbuwzv.dat

c:\windows\popcinfo.dat

c:\windows\system.tmp

c:\windows\system32\config\systemprofile\Application Data\rbuwzv.dat

.

((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))

.

2010-02-27 03:21 . 2010-02-27 03:22 -------- d-----w- C:\HJT

2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\Adrian\Application Data\Malwarebytes

2010-02-27 02:38 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-27 02:38 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-27 02:38 . 2010-02-27 02:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-02-27 00:09 . 2005-12-13 13:18 50048 ----a-w- c:\windows\system32\drivers\ikhlayer.sys

2010-02-27 00:08 . 2010-02-27 01:16 -------- d-----w- c:\program files\Spyware Doctor

2010-02-27 00:08 . 2010-02-27 00:08 -------- d-----w- c:\documents and settings\Adrian\Application Data\PC Tools

2010-02-26 21:55 . 2010-02-26 23:51 -------- d-----w- c:\windows\BDOSCAN8

2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\Adrian\PrivacIE

2010-02-26 16:15 . 2010-02-26 16:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2010-02-26 16:14 . 2010-02-26 16:14 -------- d-sh--w- c:\documents and settings\Adrian\IETldCache

2010-02-26 16:05 . 2010-02-26 16:05 -------- dc-h--w- c:\windows\ie8

2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys

2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys

2010-02-26 04:22 . 2004-08-03 20:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys

2010-02-26 04:22 . 2004-08-03 20:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys

2010-02-26 04:22 . 2004-08-03 21:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys

2010-02-26 04:22 . 2004-08-03 21:00 8192 ----a-w- c:\windows\system32\drivers\Changer.sys

2010-02-26 03:09 . 2010-02-26 03:10 5515984 ----a-w- c:\documents and settings\Adrian\Application Data\TVU Networks\AutoUpgrade\TVUPlayer2.5.2.1.exe

2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\program files\Photodex

2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Photodex

2010-02-26 02:46 . 2010-02-26 02:46 -------- d-----w- c:\documents and settings\Adrian\Application Data\Photodex

2010-02-11 19:25 . 2010-02-26 22:29 -------- d-----w- c:\program files\PokerStars

2010-02-07 12:56 . 2010-02-27 01:55 -------- d-----w- c:\program files\Common Files\Symantec Shared

2010-02-05 20:22 . 2008-03-05 14:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll

2010-02-05 20:22 . 2008-03-05 14:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll

2010-02-05 20:22 . 2008-03-05 14:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll

2010-02-05 20:22 . 2008-03-05 13:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll

2010-02-05 20:22 . 2008-02-05 21:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll

2010-02-05 20:22 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll

2010-01-30 17:21 . 2010-02-27 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton

2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec

2010-01-30 17:21 . 2010-01-30 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller

2010-01-30 14:20 . 2010-01-30 14:24 -------- d-----w- c:\windows\system32\Adobe

2010-01-29 17:06 . 2010-02-06 23:35 -------- d-----w- c:\program files\Videos

2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\documents and settings\Adrian\Application Data\FastStone

2010-01-29 16:37 . 2010-01-29 16:37 -------- d-----w- c:\program files\FastStone Capture

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-27 04:31 . 2010-02-27 04:31 827 ----a-w- c:\windows\system.tmp

2010-02-27 02:22 . 2009-02-07 00:35 -------- d-----w- c:\program files\Pazera_Free_FLV_to_AVI_Converter

2010-02-27 01:23 . 2009-07-03 06:47 -------- d-----w- c:\documents and settings\Adrian\Application Data\FileZilla

2010-02-25 21:52 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\skypePM

2010-02-23 16:51 . 2008-05-23 16:55 -------- d-----w- c:\documents and settings\Adrian\Application Data\Skype

2010-02-11 19:23 . 2010-01-21 22:10 -------- d-----w- c:\program files\PokerStars.NET

2010-01-21 19:01 . 2008-05-23 16:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\documents and settings\Adrian\Application Data\Media Player Classic

2010-01-18 13:42 . 2010-01-18 13:42 -------- d-----w- c:\program files\K-Lite Codec Pack

2010-01-18 13:41 . 2010-01-18 13:00 -------- d-----w- c:\program files\ACE Mega CoDecS Pack

2010-01-18 12:51 . 2010-01-18 12:07 -------- d-----w- c:\program files\BSR Screen Recorder 4

2010-01-18 12:13 . 2010-01-18 12:07 2048 ----a-w- c:\windows\system32\Tr_sttool.dat

2009-12-29 06:38 . 2009-12-29 06:33 -------- d-----w- c:\program files\TGIANT

2009-12-22 14:56 . 2008-05-23 14:46 38664 ----a-w- c:\documents and settings\Adrian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-10-02 19:40 . 2009-10-02 19:33 120566929 ----a-w- c:\program files\Championship Manager 01-02.rar

2008-07-31 16:59 . 2008-06-03 20:20 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll

2008-07-31 16:59 . 2008-06-03 20:20 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll

2008-07-31 16:59 . 2008-06-03 20:20 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll

2005-05-13 15:12 . 2005-05-13 15:12 217073 --sha-r- c:\windows\meta4.exe

2005-10-24 09:13 . 2005-10-24 09:13 66560 --sha-r- c:\windows\MOTA113.exe

2005-10-13 19:27 . 2005-10-13 19:27 422400 --sha-r- c:\windows\x2.64.exe

2005-10-07 17:14 . 2005-10-07 17:14 308224 --sha-r- c:\windows\system32\avisynth.dll

2005-07-14 10:31 . 2005-07-14 10:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll

2005-06-26 13:32 . 2005-06-26 13:32 616448 --sha-r- c:\windows\system32\cygwin1.dll

2005-06-21 20:37 . 2005-06-21 20:37 45568 --sha-r- c:\windows\system32\cygz.dll

2004-01-24 22:00 . 2004-01-24 22:00 70656 --sha-r- c:\windows\system32\i420vfw.dll

2006-04-27 08:24 . 2006-04-27 08:24 2945024 --sha-r- c:\windows\system32\Smab.dll

2005-02-28 11:16 . 2005-02-28 11:16 240128 --sha-r- c:\windows\system32\x.264.exe

2004-01-24 22:00 . 2004-01-24 22:00 217088 --sha-r- c:\windows\system32\yv12vfw.dll

.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

------- Sigcheck -------

[-] 2008-05-22 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\12c762eb1b4771c079de44\admparse.dll

08.03.2009 г. 04:32 72704 \RP2\A0000097.dll

c:\12c762eb1b4771c079de44\advpack.dll

08.03.2009 г. 04:32 128512 \RP2\A0000096.dll

c:\12c762eb1b4771c079de44\browseui.dll

07.01.2009 г. 18:20 1022976 \RP2\A0000095.dll

c:\12c762eb1b4771c079de44\corpol.dll

08.03.2009 г. 04:33 18944 \RP2\A0000094.dll

c:\12c762eb1b4771c079de44\dxtmsft.dll

08.03.2009 г. 04:31 348160 \RP2\A0000093.dll

c:\12c762eb1b4771c079de44\dxtrans.dll

08.03.2009 г. 04:31 216064 \RP2\A0000092.dll

c:\12c762eb1b4771c079de44\extexport.exe

08.03.2009 г. 04:35 144384 \RP2\A0000043.exe

c:\12c762eb1b4771c079de44\hmmapi.dll

08.03.2009 г. 04:24 68608 \RP2\A0000091.dll

c:\12c762eb1b4771c079de44\icardie.dll

08.03.2009 г. 04:31 59904 \RP2\A0000090.dll

c:\12c762eb1b4771c079de44\ie4uinit.exe

08.03.2009 г. 04:32 173056 \RP2\A0000042.exe

c:\12c762eb1b4771c079de44\ieakeng.dll

08.03.2009 г. 04:33 125952 \RP2\A0000089.dll

c:\12c762eb1b4771c079de44\ieaksie.dll

08.03.2009 г. 04:33 229376 \RP2\A0000088.dll

c:\12c762eb1b4771c079de44\ieakui.dll

08.03.2009 г. 04:32 163840 \RP2\A0000087.dll

c:\12c762eb1b4771c079de44\ieapfltr.dll

08.03.2009 г. 04:11 445952 \RP2\A0000086.dll

c:\12c762eb1b4771c079de44\iecompat.dll

08.03.2009 г. 04:35 2048 \RP2\A0000085.dll

c:\12c762eb1b4771c079de44\iedkcs32.dll

08.03.2009 г. 14:09 391536 \RP2\A0000084.dll

c:\12c762eb1b4771c079de44\iedvtool.dll

08.03.2009 г. 04:35 742912 \RP2\A0000083.dll

c:\12c762eb1b4771c079de44\ieframe.dll

08.03.2009 г. 04:39 11063808 \RP2\A0000082.dll

c:\12c762eb1b4771c079de44\iepeers.dll

08.03.2009 г. 04:31 183808 \RP2\A0000081.dll

c:\12c762eb1b4771c079de44\ieproxy.dll

08.03.2009 г. 04:33 246784 \RP2\A0000080.dll

c:\12c762eb1b4771c079de44\iernonce.dll

08.03.2009 г. 04:32 55808 \RP2\A0000079.dll

c:\12c762eb1b4771c079de44\iertutil.dll

08.03.2009 г. 04:32 1985024 \RP2\A0000078.dll

c:\12c762eb1b4771c079de44\iesetup.dll

08.03.2009 г. 04:32 71680 \RP2\A0000077.dll

c:\12c762eb1b4771c079de44\ieudinit.exe

08.03.2009 г. 04:32 36864 \RP2\A0000041.exe

c:\12c762eb1b4771c079de44\ieui.dll

08.03.2009 г. 04:22 164352 \RP2\A0000076.dll

c:\12c762eb1b4771c079de44\iexplore.exe

08.03.2009 г. 14:09 638816 \RP2\A0000040.exe

c:\12c762eb1b4771c079de44\imgutil.dll

08.03.2009 г. 04:31 34816 \RP2\A0000075.dll

c:\12c762eb1b4771c079de44\inseng.dll

08.03.2009 г. 04:32 94720 \RP2\A0000074.dll

c:\12c762eb1b4771c079de44\jscript.dll

08.03.2009 г. 04:33 726528 \RP2\A0000073.dll

c:\12c762eb1b4771c079de44\jsdbgui.dll

08.03.2009 г. 04:35 521216 \RP2\A0000072.dll

c:\12c762eb1b4771c079de44\jsdebuggeride.dll

08.03.2009 г. 04:35 121344 \RP2\A0000071.dll

c:\12c762eb1b4771c079de44\jsprofilercore.dll

08.03.2009 г. 04:35 118272 \RP2\A0000070.dll

c:\12c762eb1b4771c079de44\jsprofilerui.dll

08.03.2009 г. 04:35 233984 \RP2\A0000069.dll

c:\12c762eb1b4771c079de44\jsproxy.dll

08.03.2009 г. 04:33 25600 \RP2\A0000068.dll

c:\12c762eb1b4771c079de44\licmgr10.dll

08.03.2009 г. 04:34 43008 \RP2\A0000067.dll

c:\12c762eb1b4771c079de44\msdbg2.dll

07.01.2009 г. 18:20 265720 \RP2\A0000066.dll

c:\12c762eb1b4771c079de44\msfeeds.dll

08.03.2009 г. 04:32 594432 \RP2\A0000065.dll

c:\12c762eb1b4771c079de44\msfeedsbs.dll

08.03.2009 г. 04:31 55296 \RP2\A0000064.dll

c:\12c762eb1b4771c079de44\msfeedssync.exe

08.03.2009 г. 04:31 13312 \RP2\A0000039.exe

c:\12c762eb1b4771c079de44\mshta.exe

08.03.2009 г. 04:31 45568 \RP2\A0000038.exe

c:\12c762eb1b4771c079de44\mshtml.dll

08.03.2009 г. 04:41 5937152 \RP2\A0000063.dll

c:\12c762eb1b4771c079de44\mshtmled.dll

08.03.2009 г. 04:31 66560 \RP2\A0000062.dll

c:\12c762eb1b4771c079de44\mshtmler.dll

08.03.2009 г. 04:31 48128 \RP2\A0000061.dll

c:\12c762eb1b4771c079de44\msls31.dll

08.03.2009 г. 04:22 156160 \RP2\A0000060.dll

c:\12c762eb1b4771c079de44\msrating.dll

08.03.2009 г. 04:34 193536 \RP2\A0000059.dll

c:\12c762eb1b4771c079de44\mstime.dll

08.03.2009 г. 04:32 611840 \RP2\A0000058.dll

c:\12c762eb1b4771c079de44\occache.dll

08.03.2009 г. 04:34 109568 \RP2\A0000057.dll

c:\12c762eb1b4771c079de44\pdm.dll

07.01.2009 г. 18:20 355832 \RP2\A0000056.dll

c:\12c762eb1b4771c079de44\pngfilt.dll

08.03.2009 г. 04:31 46592 \RP2\A0000055.dll

c:\12c762eb1b4771c079de44\shdocvw.dll

07.01.2009 г. 18:20 1497088 \RP2\A0000054.dll

c:\12c762eb1b4771c079de44\shlwapi.dll

07.01.2009 г. 18:20 474112 \RP2\A0000053.dll

c:\12c762eb1b4771c079de44\spmsg.dll

07.01.2009 г. 18:20 16928 \RP2\A0000052.dll

c:\12c762eb1b4771c079de44\spuninst.exe

07.01.2009 г. 18:20 231456 \RP2\A0000037.exe

c:\12c762eb1b4771c079de44\spupdsvc.exe

07.01.2009 г. 18:21 26144 \RP2\A0000036.exe

c:\12c762eb1b4771c079de44\sqmapi.dll

07.01.2009 г. 18:20 134144 \RP2\A0000051.dll

c:\12c762eb1b4771c079de44\support\idndl.dll

07.01.2009 г. 18:20 26112 \RP2\A0000024.dll

c:\12c762eb1b4771c079de44\support\nlsdl.dll

07.01.2009 г. 18:20 24576 \RP2\A0000023.dll

c:\12c762eb1b4771c079de44\support\normaliz.dll

07.01.2009 г. 18:20 23552 \RP2\A0000022.dll

c:\12c762eb1b4771c079de44\support\xmllite.dll

07.01.2009 г. 18:21 121856 \RP2\A0000021.dll

c:\12c762eb1b4771c079de44\update\iecustom.dll

08.03.2009 г. 14:23 58464 \RP2\A0000019.dll

c:\12c762eb1b4771c079de44\update\iesetup.exe

08.03.2009 г. 14:23 1113696 \RP2\A0000016.exe

c:\12c762eb1b4771c079de44\update\sqmapi.dll

08.03.2009 г. 14:23 141408 \RP2\A0000018.dll

c:\12c762eb1b4771c079de44\update\update.exe

07.01.2009 г. 18:21 755744 \RP2\A0000015.exe

c:\12c762eb1b4771c079de44\update\updspapi.dll

07.01.2009 г. 18:21 382496 \RP2\A0000017.dll

c:\12c762eb1b4771c079de44\url.dll

08.03.2009 г. 04:34 105984 \RP2\A0000050.dll

c:\12c762eb1b4771c079de44\urlmon.dll

08.03.2009 г. 04:34 1206784 \RP2\A0000049.dll

c:\12c762eb1b4771c079de44\vbscript.dll

08.03.2009 г. 04:33 420352 \RP2\A0000048.dll

c:\12c762eb1b4771c079de44\vgx.dll

08.03.2009 г. 04:33 759296 \RP2\A0000047.dll

c:\12c762eb1b4771c079de44\webcheck.dll

08.03.2009 г. 04:34 236544 \RP2\A0000046.dll

c:\12c762eb1b4771c079de44\winfxdocobj.exe

08.03.2009 г. 04:34 208384 \RP2\A0000035.exe

c:\12c762eb1b4771c079de44\wininet.dll

08.03.2009 г. 04:34 914944 \RP2\A0000045.dll

c:\12c762eb1b4771c079de44\xpshims.dll

08.03.2009 г. 04:33 12288 \RP2\A0000044.dll

c:\32788r22fwjfw\SF.exe

10.06.2006 г. 14:42 49152 \RP3\A0000785.exe

c:\avenger\winesm32.exe

04.08.2004 г. 00:56 29184 \RP3\A0000776.exe

c:\documents and settings\Adrian\Application Data\Sun\Java\jre1.6.0_10\lzma.dll

19.11.2008 г. 00:42 152576 \RP2\A0000218.dll

C:\ie4uinit.exe

13.08.2007 г. 17:39 54784 \RP2\A0000107.exe

c:\program files\Ahead\CoverDesigner\CoverDes.exe

01.02.2005 г. 12:31 2412544 \RP3\A0000434.exe

c:\program files\Ahead\ImageDrive\idriveinst.dll

02.03.2004 г. 15:37 90112 \RP3\A0000521.dll

c:\program files\Ahead\ImageDrive\ImageDrive.exe

30.11.2004 г. 11:31 893016 \RP3\A0000523.exe

c:\program files\Ahead\ImageDrive\imagedrv.dll

02.03.2004 г. 15:37 118784 \RP3\A0000524.dll

c:\program files\Ahead\Nero BackItUp\BackItUp.exe

10.02.2005 г. 17:36 5734400 \RP3\A0000435.exe

c:\program files\Ahead\Nero BackItUp\NBJ.exe

10.02.2005 г. 16:00 1937408 \RP3\A0000436.exe

c:\program files\Ahead\Nero BackItUp\NBR.exe

10.02.2005 г. 16:01 1159168 \RP3\A0000437.exe

c:\program files\Ahead\Nero SoundTrax\SoundTrax.exe

01.02.2005 г. 12:54 1830999 \RP3\A0000519.exe

c:\program files\Ahead\Nero StartSmart\NeroStartSmart.exe

21.01.2005 г. 18:12 4714582 \RP3\A0000438.exe

c:\program files\Ahead\Nero Toolkit\CDSpeed.exe

09.02.2005 г. 22:25 1220608 \RP3\A0000509.exe

c:\program files\Ahead\Nero Toolkit\DriveSpeed.exe

18.12.2004 г. 22:01 593920 \RP3\A0000510.exe

c:\program files\Ahead\Nero Toolkit\hwinfo.exe

10.03.2003 г. 11:10 11568 \RP3\A0000512.exe

c:\program files\Ahead\Nero Toolkit\InfoTool.exe

19.01.2005 г. 16:01 524288 \RP3\A0000511.exe

c:\program files\Ahead\Nero Wave Editor\DXEnum.exe

01.02.2005 г. 12:49 122980 \RP3\A0000513.exe

c:\program files\Ahead\Nero Wave Editor\waveedit.dll

01.02.2005 г. 12:53 1802332 \RP3\A0000514.dll

c:\program files\Ahead\Nero Wave Editor\WaveEdit.exe

01.02.2005 г. 12:49 118877 \RP3\A0000515.exe

c:\program files\Ahead\Nero\AudioPluginMgr.dll

01.02.2005 г. 10:53 106578 \RP3\A0000452.dll

c:\program files\Ahead\Nero\CDCopy.dll

11.03.2005 г. 14:52 208967 \RP3\A0000453.dll

c:\program files\Ahead\Nero\cdr100.dll

11.03.2005 г. 14:48 233546 \RP3\A0000454.dll

c:\program files\Ahead\Nero\cdr50s.dll

11.03.2005 г. 14:48 245831 \RP3\A0000455.dll

c:\program files\Ahead\Nero\CDROM.dll

11.03.2005 г. 14:48 258118 \RP3\A0000456.dll

c:\program files\Ahead\Nero\cdu920.dll

11.03.2005 г. 14:48 278599 \RP3\A0000457.dll

c:\program files\Ahead\Nero\cr2200cs.dll

11.03.2005 г. 14:48 237641 \RP3\A0000458.dll

c:\program files\Ahead\Nero\Drweb32.dll

01.10.2003 г. 13:02 627200 \RP3\A0000460.dll

c:\program files\Ahead\Nero\DVDREALLOC.dll

01.10.2003 г. 13:02 102400 \RP3\A0000461.dll

c:\program files\Ahead\Nero\Dws114x.dll

11.03.2005 г. 14:48 229448 \RP3\A0000462.dll

c:\program files\Ahead\Nero\em2v.dll

16.02.2005 г. 09:55 176128 \RP3\A0000459.dll

c:\program files\Ahead\Nero\Equalize.dll

11.03.2005 г. 14:52 110671 \RP3\A0000463.dll

c:\program files\Ahead\Nero\FATImporter.dll

11.03.2005 г. 15:18 184396 \RP3\A0000464.dll

c:\program files\Ahead\Nero\GENCUSH.dll

11.03.2005 г. 14:53 77896 \RP3\A0000465.dll

c:\program files\Ahead\Nero\Generatr.dll

11.03.2005 г. 14:50 77903 \RP3\A0000466.dll

c:\program files\Ahead\Nero\GenFAT.dll

11.03.2005 г. 14:57 176202 \RP3\A0000467.dll

c:\program files\Ahead\Nero\geniso.dll

11.03.2005 г. 14:50 225354 \RP3\A0000468.dll

c:\program files\Ahead\Nero\GenPCHy.dll

11.03.2005 г. 14:51 233544 \RP3\A0000469.dll

c:\program files\Ahead\Nero\GenUDF.dll

11.03.2005 г. 14:51 311370 \RP3\A0000470.dll

c:\program files\Ahead\Nero\image.dll

11.03.2005 г. 14:48 135238 \RP3\A0000471.dll

c:\program files\Ahead\Nero\ImageGen.dll

11.03.2005 г. 14:50 106569 \RP3\A0000472.dll

c:\program files\Ahead\Nero\ims.dll

11.03.2005 г. 14:49 241732 \RP3\A0000473.dll

c:\program files\Ahead\Nero\ISOFS.dll

11.03.2005 г. 14:49 196678 \RP3\A0000474.dll

c:\program files\Ahead\Nero\KARAOKE.dll

01.10.2003 г. 13:02 28160 \RP3\A0000475.dll

c:\program files\Ahead\Nero\mfc42.DLL

23.08.2001 г. 12:00 995383 \RP3\A0000446.DLL

c:\program files\Ahead\Nero\MMC.dll

11.03.2005 г. 14:49 696388 \RP3\A0000476.dll

c:\program files\Ahead\Nero\MPGEnc.dll

01.10.2003 г. 13:02 139264 \RP3\A0000477.dll

c:\program files\Ahead\Nero\msvcrt.dll

04.05.2001 г. 10:05 290869 \RP3\A0000447.dll

c:\program files\Ahead\Nero\NeEm2a.dll

16.02.2005 г. 09:55 274432 \RP3\A0000486.dll

c:\program files\Ahead\Nero\NeHDBlkAccess.dll

11.03.2005 г. 15:01 102492 \RP3\A0000478.dll

c:\program files\Ahead\Nero\NeMP3Dmo.dll

11.03.2005 г. 15:18 471113 \RP3\A0000479.dll

c:\program files\Ahead\Nero\NeMP3Hlp.dll

11.03.2005 г. 14:52 81998 \RP3\A0000480.dll

c:\program files\Ahead\Nero\nero.exe

11.03.2005 г. 15:18 15376454 \RP3\A0000448.exe

c:\program files\Ahead\Nero\neroAPI.dll

11.03.2005 г. 15:23 3211340 \RP3\A0000481.dll

c:\program files\Ahead\Nero\NeroCmd.exe

29.10.2004 г. 08:11 151552 \RP3\A0000449.exe

c:\program files\Ahead\Nero\NeroCom.dll

19.10.2004 г. 15:06 372736 \RP3\A0000482.dll

c:\program files\Ahead\Nero\neroDB.dll

11.03.2005 г. 14:52 249930 \RP3\A0000483.dll

c:\program files\Ahead\Nero\neroErr.dll

11.03.2005 г. 14:46 282696 \RP3\A0000484.dll

c:\program files\Ahead\Nero\NeroMediaCon.dll

16.02.2005 г. 09:55 630784 \RP3\A0000485.dll

c:\program files\Ahead\Nero\NeroNet.dll

01.09.2004 г. 16:17 323584 \RP3\A0000487.dll

c:\program files\Ahead\Nero\neroscsi.dll

11.03.2005 г. 14:47 159817 \RP3\A0000488.dll

c:\program files\Ahead\Nero\neRSDB.dll

11.03.2005 г. 14:53 102478 \RP3\A0000489.dll

c:\program files\Ahead\Nero\NetRecorder.dll

11.03.2005 г. 14:57 200788 \RP3\A0000490.dll

c:\program files\Ahead\Nero\NeVCDEngine.dll

11.03.2005 г. 14:52 159826 \RP3\A0000491.dll

c:\program files\Ahead\Nero\newtrf.dll

11.03.2005 г. 14:47 270407 \RP3\A0000492.dll

c:\program files\Ahead\Nero\NRESTORE.EXE

14.05.2004 г. 13:56 257820 \RP3\A0000451.EXE

c:\program files\Ahead\Nero\READHD16.dll

01.10.2003 г. 13:02 5120 \RP3\A0000493.dll

c:\program files\Ahead\Nero\ReadHD32.dll

01.10.2003 г. 13:02 23040 \RP3\A0000494.dll

c:\program files\Ahead\Nero\ro1420c.dll

11.03.2005 г. 14:49 237640 \RP3\A0000495.dll

c:\program files\Ahead\Nero\SHORTCUT.DLL

16.02.2005 г. 15:16 725062 \RP3\A0000536.DLL

c:\program files\Ahead\Nero\TMPVImporter.dll

11.03.2005 г. 15:19 90202 \RP3\A0000496.dll

c:\program files\Ahead\Nero\UDFImporter.dll

11.03.2005 г. 15:00 491604 \RP3\A0000497.dll

c:\program files\Ahead\Nero\Uninstall\UNNero.exe

17.02.2005 г. 11:21 2682880 \RP3\A0000507.exe

c:\program files\Ahead\Nero\VCDMenu.dll

11.03.2005 г. 14:54 155724 \RP3\A0000498.dll

c:\program files\Ahead\Nero\VMPEGEnc.dll

11.03.2005 г. 15:01 155726 \RP3\A0000499.dll

c:\program files\Ahead\Nero\VMPEGEncNDX.dll

01.10.2003 г. 13:02 364544 \RP3\A0000500.dll

c:\program files\Ahead\Nero\WNASPI32.DLL

26.10.2004 г. 16:35 164112 \RP3\A0000506.DLL

c:\program files\Ahead\WMPBurn\NeroBurnPlugin.dll

08.01.2004 г. 15:17 331776 \RP3\A0000440.dll

c:\program files\Ahead\WMPBurn\WMPBurn.exe

08.01.2004 г. 15:19 1265664 \RP3\A0000439.exe

c:\program files\BitComet\Downloads\Photodex.ProShow.Gold.v4.1.2711.Incl.Keymaker-CORE\Keygen\CORE10k.EXE

26.02.2010 г. 04:44 137728 \RP2\A0000211.EXE

c:\program files\BitComet\Downloads\Photodex.ProShow.Gold.v4.1.2711.Incl.Keymaker-CORE\Keygen\keygen.exe

26.02.2010 г. 04:44 126464 \RP2\A0000212.exe

c:\program files\BitComet\Downloads\Photodex.ProShow.Gold.v4.1.2711.Incl.Keymaker-CORE\psgold_41_2711.exe

26.02.2010 г. 04:44 19644248 \RP2\A0000213.exe

c:\program files\Common Files\Ahead\AudioPlugins\Aac.dll

26.01.2005 г. 10:38 1990656 \RP3\A0000424.dll

c:\program files\Common Files\Ahead\AudioPlugins\aacenc32.dll

16.02.2005 г. 09:51 978944 \RP3\A0000425.dll

c:\program files\Common Files\Ahead\AudioPlugins\Aiff.dll

01.02.2005 г. 10:51 73813 \RP3\A0000404.dll

c:\program files\Common Files\Ahead\AudioPlugins\DefConvertor.dll

01.02.2005 г. 10:51 57445 \RP3\A0000405.dll

c:\program files\Common Files\Ahead\AudioPlugins\lame_enc.dll

17.02.2004 г. 10:20 208896 \RP3\A0000445.dll

c:\program files\Common Files\Ahead\AudioPlugins\mp3PP.dll

01.02.2005 г. 10:51 536664 \RP3\A0000441.dll

c:\program files\Common Files\Ahead\AudioPlugins\mp3PRO.dll

01.02.2005 г. 10:52 1433689 \RP3\A0000442.dll

c:\program files\Common Files\Ahead\AudioPlugins\mp3PRO_dmo.dll

01.02.2005 г. 10:52 94305 \RP3\A0000443.dll

c:\program files\Common Files\Ahead\AudioPlugins\mp3PRO_hlp.dll

01.02.2005 г. 10:52 86118 \RP3\A0000444.dll

c:\program files\Common Files\Ahead\AudioPlugins\msa.dll

01.02.2005 г. 10:51 234496 \RP3\A0000406.dll

c:\program files\Common Files\Ahead\AudioPlugins\ogg.dll

01.02.2005 г. 10:52 1589336 \RP3\A0000431.dll

c:\program files\Common Files\Ahead\AudioPlugins\Vqf.dll

01.02.2005 г. 10:51 82003 \RP3\A0000407.dll

c:\program files\Common Files\Ahead\AudioPlugins\VqfDecLib.dll

01.02.2005 г. 10:51 667648 \RP3\A0000408.dll

c:\program files\Common Files\Ahead\AudioPlugins\VqfEncLib.dll

01.02.2005 г. 10:51 827392 \RP3\A0000409.dll

c:\program files\Common Files\Ahead\AudioPlugins\VqfEncLib1.dll

01.02.2005 г. 10:51 221184 \RP3\A0000410.dll

c:\program files\Common Files\Ahead\AudioPlugins\wav.dll

01.02.2005 г. 10:53 98387 \RP3\A0000411.dll

c:\program files\Common Files\Ahead\DSFilter\aacplus.dll

16.02.2005 г. 09:54 303104 \RP3\A0000428.dll

c:\program files\Common Files\Ahead\DSFilter\NeAMR.dll

16.02.2005 г. 09:54 372736 \RP3\A0000422.dll

c:\program files\Common Files\Ahead\Lib\AdvrCntr.dll

11.03.2005 г. 15:28 1454158 \RP3\A0000429.dll

c:\program files\Common Files\Ahead\Lib\apreg.dll

21.01.2005 г. 18:12 528461 \RP3\A0000420.dll

c:\program files\Common Files\Ahead\Lib\DriveLocker.dll

08.12.2004 г. 19:58 139264 \RP3\A0000412.dll

c:\program files\Common Files\Ahead\Lib\NeroCBUI.dll

24.08.2004 г. 06:58 1097728 \RP3\A0000413.dll

c:\program files\Common Files\Ahead\Lib\NeroIPP.dll

16.02.2005 г. 09:55 1097728 \RP3\A0000430.dll

08.03.2009 г. 04:33 759296 c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll

13.08.2007 г. 17:54 765952 \RP2\A0000143.dll

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\CCERASER.DLL

18.01.2010 г. 18:22 2747440 \RP3\A0000537.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\ECMSVR32.DLL

18.01.2010 г. 18:22 259440 \RP3\A0000538.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\EECTRL.SYS

18.01.2010 г. 18:22 371248 \RP3\A0000539.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\ERASER.SYS

18.01.2010 г. 18:22 102448 \RP3\A0000541.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVENG.SYS

16.02.2010 г. 11:00 84912 \RP3\A0000542.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVENG32.DLL

18.01.2010 г. 18:22 177520 \RP3\A0000543.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVEX15.SYS

16.02.2010 г. 11:00 1324720 \RP3\A0000544.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20100223.004\NAVEX32A.DLL

18.01.2010 г. 18:22 1647984 \RP3\A0000545.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\cceraser.dll

18.01.2010 г. 18:22 2747440 \RP3\A0000551.dll

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ecmsvr32.dll

18.01.2010 г. 18:22 259440 \RP3\A0000552.dll

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\eeCtrl.sys

18.01.2010 г. 18:22 371248 \RP3\A0000553.sys

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\ERASER.sys

18.01.2010 г. 18:22 102448 \RP3\A0000555.sys

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\NAVENG.SYS

16.02.2010 г. 11:00 84912 \RP3\A0000556.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\naveng32.dll

18.01.2010 г. 18:22 177520 \RP3\A0000557.dll

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\NAVEX15.SYS

16.02.2010 г. 11:00 1324720 \RP3\A0000558.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub\navex32a.dll

18.01.2010 г. 18:22 1647984 \RP3\A0000559.dll

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\CCERASER.DLL

18.01.2010 г. 18:22 2747440 \RP3\A0000565.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\ECMSVR32.DLL

18.01.2010 г. 18:22 259440 \RP3\A0000566.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\EECTRL.SYS

18.01.2010 г. 18:22 371248 \RP3\A0000567.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\ERASER.SYS

18.01.2010 г. 18:22 102448 \RP3\A0000569.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\hub.scr

18.01.2010 г. 18:22 750 \RP3\A0000570.scr

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVENG.SYS

18.01.2010 г. 18:22 84912 \RP3\A0000571.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVENG32.DLL

18.01.2010 г. 18:22 177520 \RP3\A0000572.DLL

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVEX15.SYS

18.01.2010 г. 18:22 1323568 \RP3\A0000573.SYS

c:\program files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp3062.tmp\NAVEX32A.DLL

18.01.2010 г. 18:22 1647984 \RP3\A0000574.DLL

c:\program files\Conduit\Community Alerts\Alert.dll

29.12.2009 г. 15:32 520728 \RP3\A0000676.dll

c:\program files\Forklift Truck Simulator 2009\CEGUIBase.dll

10.12.2008 г. 17:18 1683456 \RP2\A0000262.dll

c:\program files\Forklift Truck Simulator 2009\CEGUIExpatParser.dll

10.12.2008 г. 17:25 114688 \RP2\A0000261.dll

c:\program files\Forklift Truck Simulator 2009\CEGUIFalagardWRBase.dll

10.12.2008 г. 17:28 131072 \RP2\A0000260.dll

c:\program files\Forklift Truck Simulator 2009\dbghelp.dll

04.12.2007 г. 00:50 986112 \RP2\A0000259.dll

c:\program files\Forklift Truck Simulator 2009\DirectX9GUIRenderer.dll

10.12.2008 г. 17:25 253952 \RP2\A0000258.dll

c:\program files\Forklift Truck Simulator 2009\Forklift Truck Simulator 2009.exe

01.05.2009 г. 17:52 1175552 \RP2\A0000257.exe

c:\program files\Forklift Truck Simulator 2009\Microsoft DirectX\dxwebsetup.exe

16.03.2009 г. 22:23 301384 \RP2\A0000254.exe

c:\program files\Forklift Truck Simulator 2009\msvcp71.dll

18.03.2003 г. 23:14 499712 \RP2\A0000256.dll

c:\program files\Forklift Truck Simulator 2009\msvcr71.dll

21.02.2003 г. 05:42 348160 \RP2\A0000255.dll

08.03.2009 г. 04:24 68608 c:\program files\Internet Explorer\hmmapi.dll

13.08.2007 г. 17:18 60416 \RP2\A0000139.dll

08.03.2009 г. 04:33 246784 c:\program files\Internet Explorer\ieproxy.dll

13.08.2007 г. 17:54 287744 \RP2\A0000140.dll

08.03.2009 г. 14:09 638816 c:\program files\Internet Explorer\iexplore.exe

13.08.2007 г. 17:43 622080 \RP2\A0000141.exe

c:\program files\Java\jre6\bin\msvcr71.dll

19.11.2008 г. 00:43 348160 \RP3\A0000269.dll

c:\program files\MillBar\MillBarToolbarHelper.exe

02.06.2009 г. 10:12 38424 \RP3\A0000391.exe

c:\program files\MillBar\tbMill.dll

31.12.2009 г. 11:53 2349080 \RP3\A0000393.dll

c:\program files\MillBar\UNWISE.EXE

26.07.2002 г. 17:02 153088 \RP3\A0000394.EXE

c:\program files\Norton Security Scan\Engine\2.7.0.52\BilBDRes.dll

01.02.2010 г. 11:54 578936 \RP3\A0000582.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ccL80U.dll

30.01.2010 г. 19:21 522088 \RP3\A0000583.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ccScanw.dll

30.01.2010 г. 19:21 328552 \RP3\A0000584.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ccVrTrst.dll

30.01.2010 г. 19:21 80744 \RP3\A0000585.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\dec_abi.dll

30.01.2010 г. 19:21 2102624 \RP3\A0000586.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\DefUtDCD.dll

30.01.2010 г. 19:21 677240 \RP3\A0000587.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\diLueCbk.dll

30.01.2010 г. 19:21 65904 \RP3\A0000588.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ecmldr32.dll

30.01.2010 г. 19:21 54640 \RP3\A0000589.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\HeartBt.dll

30.01.2010 г. 19:21 95608 \RP3\A0000590.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\msl.dll

30.01.2010 г. 19:21 321152 \RP3\A0000592.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\msvcp80.dll

30.01.2010 г. 19:21 548864 \RP3\A0000593.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\msvcr80.dll

30.01.2010 г. 19:21 626688 \RP3\A0000594.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\Nss.exe

23.02.2010 г. 13:12 606072 \RP3\A0000595.exe

c:\program files\Norton Security Scan\Engine\2.7.0.52\patch25d.dll

30.01.2010 г. 19:21 40320 \RP3\A0000596.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\PrdDtRes.dll

23.02.2010 г. 13:12 35704 \RP3\A0000597.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\RptCdRes.dll

22.02.2010 г. 22:22 128376 \RP3\A0000598.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\SAUpdt.dll

30.01.2010 г. 19:21 898424 \RP3\A0000599.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ScanCore.dll

23.02.2010 г. 13:12 1098616 \RP3\A0000600.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ScanRes.dll

22.02.2010 г. 22:10 932216 \RP3\A0000601.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\ScanText.dll

22.02.2010 г. 22:10 31096 \RP3\A0000602.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\SKUCfg.dll

23.02.2010 г. 18:31 12664 \RP3\A0000603.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\SKURes.dll

23.02.2010 г. 18:31 451960 \RP3\A0000604.dll

c:\program files\Norton Security Scan\Engine\2.7.0.52\symbos.exe

22.02.2010 г. 22:22 382328 \RP3\A0000605.exe

c:\program files\Norton Security Scan\Engine\2.7.0.52\SymHTML.dll

30.01.2010 г. 19:21 1657688 \RP3\A0000606.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\ccL80U.dll

30.01.2010 г. 19:21 523624 \RP3\A0000610.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\ccSet.dll

30.01.2010 г. 19:21 254824 \RP3\A0000611.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Engine.dll

30.01.2010 г. 19:21 1328160 \RP3\A0000612.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\InstStub.exe

30.01.2010 г. 19:21 634760 \RP3\A0000613.exe

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\InstUI.dll

30.01.2010 г. 19:21 2261536 \RP3\A0000614.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Lue.dll

30.01.2010 г. 19:21 935776 \RP3\A0000615.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Microsoft.VC80.CRT\msvcm80.dll

30.01.2010 г. 19:21 479232 \RP3\A0000617.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Microsoft.VC80.CRT\msvcp80.dll

30.01.2010 г. 19:21 548864 \RP3\A0000618.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\Microsoft.VC80.CRT\msvcr80.dll

30.01.2010 г. 19:21 626688 \RP3\A0000619.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\ProdCbk.dll

30.01.2010 г. 19:21 189816 \RP3\A0000620.dll

c:\program files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\2.7.0.52\SKUCfg.dll

30.01.2010 г. 19:21 12152 \RP3\A0000621.dll

c:\program files\SMAC\SMAC.exe

24.03.2004 г. 21:16 258048 \RP3\A0000622.exe

c:\program files\SMAC\UNWISE.EXE

26.07.2002 г. 17:02 153088 \RP3\A0000627.EXE

27.02.2010 г. 02:11 1281712 c:\program files\Spyware Doctor\update.exe

09.01.2006 г. 09:19 1281784 \RP2\A0000235.exe

c:\program files\Webcam and Screen Recorder\mfc42.dll

04.08.2004 г. 00:56 1028096 \RP3\A0000670.dll

c:\program files\Webcam and Screen Recorder\MFC71.dll

19.03.2003 г. 12:19 1060864 \RP3\A0000671.dll

c:\program files\Webcam and Screen Recorder\msvcp71.dll

27.08.2003 г. 14:43 499712 \RP3\A0000672.dll

c:\program files\Webcam and Screen Recorder\msvcr71.dll

21.02.2003 г. 19:42 348160 \RP3\A0000673.dll

c:\program files\Webcam and Screen Recorder\msvcrt.dll

04.08.2004 г. 00:56 343040 \RP3\A0000674.dll

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\AskInstallChecker.exe

18.12.2008 г. 13:22 54664 \RP3\A0000675.exe

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\askSBarSetup-4.1.0.5.exe

23.12.2008 г. 11:48 867544 \RP3\A0000638.exe

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\asr30.dll

01.12.2009 г. 17:54 231424 \RP3\A0000636.dll

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\AutoScreenRecorder.exe

01.12.2009 г. 18:00 4656640 \RP3\A0000637.exe

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\gdiplus.dll

15.04.2008 г. 10:47 1724416 \RP3\A0000635.dll

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\KillAutoScreenRecorder.exe

18.06.2009 г. 17:38 110978 \RP3\A0000633.exe

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\Remove AutoScreenRecorder 3 Free from Startup.reg

23.02.2009 г. 17:22 115 \RP3\A0000634.reg

c:\program files\Wisdom-soft AutoScreenRecorder 3 Free\UNWISE.EXE

28.09.2001 г. 16:00 164864 \RP3\A0000643.EXE

c:\sportskeeping\SportsKeeping.exe

26.07.2009 г. 22:11 8650752 \RP3\A0000628.exe

c:\sportskeeping\Uninstal.exe

22.08.2009 г. 20:45 50037 \RP3\A0000632.exe

c:\windows\_001232_.tmp.dll

08.03.2009 г. 14:23 47422 \RP2\A0000004.dll

c:\windows\ie7\spuninst\_001237_.tmp.dll

06.09.2006 г. 16:43 213216 \RP2\A0000006.dll

c:\windows\system32\_001231_.tmp.dll

16.10.2006 г. 15:10 14640 \RP2\A0000002.dll

c:\windows\system32\_001238_.tmp.dll

13.08.2007 г. 17:45 78336 \RP2\A0000007.dll

08.03.2009 г. 04:32 72704 c:\windows\system32\admparse.dll

13.08.2007 г. 17:39 71680 \RP2\A0000144.dll

08.03.2009 г. 04:32 128512 c:\windows\system32\advpack.dll

13.08.2007 г. 17:39 123904 \RP2\A0000145.dll

08.03.2009 г. 04:33 18944 c:\windows\system32\corpol.dll

13.08.2007 г. 17:42 17408 \RP2\A0000146.dll

c:\windows\system32\dllcache\_001233_.tmp.dll

13.08.2007 г. 17:45 78336 \RP2\A0000005.dll

08.03.2009 г. 04:32 72704 c:\windows\system32\dllcache\admparse.dll

13.08.2007 г. 17:39 71680 \RP2\A0000101.dll

08.03.2009 г. 04:32 128512 c:\windows\system32\dllcache\advpack.dll

13.08.2007 г. 17:39 123904 \RP2\A0000102.dll

03.08.2004 г. 21:39 142464 c:\windows\system32\dllcache\aec.sys

03.08.2004 г. 21:39 142464 \RP3\A0000695.sys

03.08.2004 г. 23:05 14336 c:\windows\system32\dllcache\asyncmac.sys

03.08.2004 г. 23:05 14336 \RP3\A0000698.sys

03.08.2004 г. 22:58 59904 c:\windows\system32\dllcache\atmarpc.sys

03.08.2004 г. 22:58 59904 \RP3\A0000699.sys

03.08.2004 г. 22:10 17024 c:\windows\system32\dllcache\ccdecode.sys

03.08.2004 г. 22:10 17024 \RP3\A0000701.sys

23.08.2001 г. 14:00 18688 c:\windows\system32\dllcache\cdaudio.sys

23.08.2001 г. 14:00 18688 \RP3\A0000703.sys

03.08.2004 г. 23:00 8192 c:\windows\system32\dllcache\changer.sys

03.08.2004 г. 23:00 8192 \RP3\A0000707.sys

08.03.2009 г. 04:33 18944 c:\windows\system32\dllcache\corpol.dll

13.08.2007 г. 17:42 17408 \RP2\A0000103.dll

03.08.2004 г. 22:07 52864 c:\windows\system32\dllcache\dmusic.sys

03.08.2004 г. 22:07 52864 \RP3\A0000709.sys

03.08.2004 г. 22:07 2944 c:\windows\system32\dllcache\drmkaud.sys

03.08.2004 г. 22:07 2944 \RP3\A0000710.sys

08.03.2009 г. 04:31 348160 c:\windows\system32\dllcache\dxtmsft.dll

13.08.2007 г. 17:35 346624 \RP2\A0000104.dll

08.03.2009 г. 04:31 216064 c:\windows\system32\dllcache\dxtrans.dll

13.08.2007 г. 17:35 214528 \RP2\A0000105.dll

03.08.2004 г. 22:59 20480 c:\windows\system32\dllcache\flpydisk.sys

03.08.2004 г. 22:59 20480 \RP3\A0000712.sys

08.03.2009 г. 04:24 68608 c:\windows\system32\dllcache\hmmapi.dll

13.08.2007 г. 17:18 60416 \RP2\A0000106.dll

03.08.2004 г. 23:14 52736 c:\windows\system32\dllcache\i8042prt.sys

03.08.2004 г. 23:14 52736 \RP3\A0000713.sys

08.03.2009 г. 04:32 173056 c:\windows\system32\dllcache\ie4uinit.exe

13.08.2007 г. 17:39 54784 \RP2\A0000107.exe

08.03.2009 г. 04:33 125952 c:\windows\system32\dllcache\ieakeng.dll

13.08.2007 г. 17:39 152064 \RP2\A0000108.dll

08.03.2009 г. 04:33 229376 c:\windows\system32\dllcache\ieaksie.dll

13.08.2007 г. 17:39 229376 \RP2\A0000109.dll

08.03.2009 г. 04:32 163840 c:\windows\system32\dllcache\ieakui.dll

13.08.2007 г. 16:56 161792 \RP2\A0000110.dll

08.03.2009 г. 14:09 391536 c:\windows\system32\dllcache\iedkcs32.dll

13.08.2007 г. 17:39 382976 \RP2\A0000111.dll

08.03.2009 г. 04:31 183808 c:\windows\system32\dllcache\iepeers.dll

13.08.2007 г. 17:54 191488 \RP2\A0000112.dll

08.03.2009 г. 04:32 55808 c:\windows\system32\dllcache\iernonce.dll

13.08.2007 г. 17:39 43008 \RP2\A0000113.dll

08.03.2009 г. 04:32 71680 c:\windows\system32\dllcache\iesetup.dll

13.08.2007 г. 17:39 55296 \RP2\A0000114.dll

08.03.2009 г. 14:09 638816 c:\windows\system32\dllcache\iexplore.exe

13.08.2007 г. 17:43 622080 \RP2\A0000115.exe

03.08.2004 г. 23:00 41856 c:\windows\system32\dllcache\imapi.sys

03.08.2004 г. 23:00 41856 \RP3\A0000715.sys

08.03.2009 г. 04:31 34816 c:\windows\system32\dllcache\imgutil.dll

13.08.2007 г. 17:36 36352 \RP2\A0000116.dll

08.03.2009 г. 04:32 94720 c:\windows\system32\dllcache\inseng.dll

13.08.2007 г. 17:39 92672 \RP2\A0000118.dll

03.08.2004 г. 23:00 29056 c:\windows\system32\dllcache\ip6fw.sys

03.08.2004 г. 23:00 29056 \RP3\A0000716.sys

23.08.2001 г. 14:00 32896 c:\windows\system32\dllcache\ipfltdrv.sys

23.08.2001 г. 14:00 32896 \RP3\A0000718.sys

03.08.2004 г. 23:04 20992 c:\windows\system32\dllcache\ipinip.sys

03.08.2004 г. 23:04 20992 \RP3\A0000719.sys

03.08.2004 г. 23:00 11264 c:\windows\system32\dllcache\irenum.sys

03.08.2004 г. 23:00 11264 \RP3\A0000722.sys

08.03.2009 г. 04:33 726528 c:\windows\system32\dllcache\jscript.dll

17.05.2006 г. 10:43 465864 \RP2\A0000119.dll

08.03.2009 г. 04:33 25600 c:\windows\system32\dllcache\jsproxy.dll

13.08.2007 г. 17:54 27136 \RP2\A0000120.dll

03.08.2004 г. 22:59 34688 c:\windows\system32\dllcache\lbrtfdc.sys

03.08.2004 г. 22:59 34688 \RP3\A0000724.sys

08.03.2009 г. 04:34 43008 c:\windows\system32\dllcache\licmgr10.dll

13.08.2007 г. 17:44 40960 \RP2\A0000121.dll

04.08.2004 г. 01:05 30080 c:\windows\system32\dllcache\modem.sys

04.08.2004 г. 01:05 30080 \RP3\A0000726.sys

08.03.2009 г. 04:31 45568 c:\windows\system32\dllcache\mshta.exe

13.08.2007 г. 17:32 45568 \RP2\A0000122.exe

08.03.2009 г. 04:41 5937152 c:\windows\system32\dllcache\mshtml.dll

13.08.2007 г. 17:54 3578368 \RP2\A0000123.dll

08.03.2009 г. 04:31 66560 c:\windows\system32\dllcache\mshtmled.dll

13.08.2007 г. 17:54 475648 \RP2\A0000125.dll

08.03.2009 г. 04:31 48128 c:\windows\system32\dllcache\mshtmler.dll

13.08.2007 г. 17:01 48128 \RP2\A0000126.dll

03.08.2004 г. 21:58 7552 c:\windows\system32\dllcache\mskssrv.sys

03.08.2004 г. 21:58 7552 \RP3\A0000728.sys

08.03.2009 г. 04:22 156160 c:\windows\system32\dllcache\msls31.dll

13.08.2007 г. 17:54 156160 \RP2\A0000127.dll

03.08.2004 г. 21:58 5376 c:\windows\system32\dllcache\mspclock.sys

03.08.2004 г. 21:58 5376 \RP3\A0000734.sys

03.08.2004 г. 21:58 4992 c:\windows\system32\dllcache\mspqm.sys

03.08.2004 г. 21:58 4992 \RP3\A0000736.sys

08.03.2009 г. 04:34 193536 c:\windows\system32\dllcache\msrating.dll

13.08.2007 г. 17:44 192000 \RP2\A0000128.dll

03.08.2004 г. 21:58 5504 c:\windows\system32\dllcache\mstee.sys

03.08.2004 г. 21:58 5504 \RP3\A0000738.sys

08.03.2009 г. 04:32 611840 c:\windows\system32\dllcache\mstime.dll

13.08.2007 г. 17:54 670720 \RP2\A0000129.dll

03.08.2004 г. 22:10 85376 c:\windows\system32\dllcache\nabtsfec.sys

03.08.2004 г. 22:10 85376 \RP3\A0000739.sys

03.08.2004 г. 22:10 10880 c:\windows\system32\dllcache\ndisip.sys

03.08.2004 г. 22:10 10880 \RP3\A0000740.sys

03.08.2004 г. 22:59 40320 c:\windows\system32\dllcache\nmnt.sys

03.08.2004 г. 22:59 40320 \RP3\A0000741.sys

23.08.2001 г. 14:00 12416 c:\windows\system32\dllcache\nwlnkflt.sys

23.08.2001 г. 14:00 12416 \RP3\A0000743.sys

23.08.2001 г. 14:00 32512 c:\windows\system32\dllcache\nwlnkfwd.sys

23.08.2001 г. 14:00 32512 \RP3\A0000745.sys

08.03.2009 г. 04:34 109568 c:\windows\system32\dllcache\occache.dll

13.08.2007 г. 17:44 101376 \RP2\A0000130.dll

08.03.2009 г. 04:31 46592 c:\windows\system32\dllcache\pngfilt.dll

13.08.2007 г. 17:36 44544 \RP2\A0000131.dll

04.08.2004 г. 01:01 139400 c:\windows\system32\dllcache\rdpwd.sys

04.08.2004 г. 01:01 139400 \RP3\A0000755.sys

03.08.2004 г. 22:59 11392 c:\windows\system32\dllcache\sfloppy.sys

03.08.2004 г. 22:59 11392 \RP3\A0000756.sys

03.08.2004 г. 22:10 11136 c:\windows\system32\dllcache\slip.sys

03.08.2004 г. 22:10 11136 \RP3\A0000758.sys

03.08.2004 г. 22:07 6400 c:\windows\system32\dllcache\splitter.sys

03.08.2004 г. 22:07 6400 \RP3\A0000760.sys

03.08.2004 г. 22:10 15360 c:\windows\system32\dllcache\streamip.sys

03.08.2004 г. 22:10 15360 \RP3\A0000761.sys

17.08.2001 г. 13:00 54272 c:\windows\system32\dllcache\swmidi.sys

17.08.2001 г. 13:00 54272 \RP3\A0000763.sys

04.08.2004 г. 01:01 12040 c:\windows\system32\dllcache\tdpipe.sys

04.08.2004 г. 01:01 12040 \RP3\A0000764.sys

04.08.2004 г. 01:01 21896 c:\windows\system32\dllcache\tdtcp.sys

04.08.2004 г. 01:01 21896 \RP3\A0000765.sys

08.03.2009 г. 04:34 105984 c:\windows\system32\dllcache\url.dll

13.08.2007 г. 17:44 105984 \RP2\A0000133.dll

08.03.2009 г. 04:34 1206784 c:\windows\system32\dllcache\urlmon.dll

13.08.2007 г. 17:54 1162240 \RP2\A0000134.dll

03.08.2004 г. 22:07 59264 c:\windows\system32\dllcache\usbaudio.sys

03.08.2004 г. 22:07 59264 \RP3\A0000768.sys

03.08.2004 г. 22:08 25600 c:\windows\system32\dllcache\usbser.sys

03.08.2004 г. 22:08 25600 \RP3\A0000769.sys

03.08.2004 г. 22:08 26496 c:\windows\system32\dllcache\usbstor.sys

03.08.2004 г. 22:08 26496 \RP3\A0000771.sys

08.03.2009 г. 04:33 420352 c:\windows\system32\dllcache\vbscript.dll

09.08.2004 г. 20:27 438272 \RP2\A0000135.dll

08.03.2009 г. 04:33 759296 c:\windows\system32\dllcache\VGX.dll

13.08.2007 г. 17:54 765952 \RP2\A0000136.dll

08.03.2009 г. 04:34 236544 c:\windows\system32\dllcache\webcheck.dll

13.08.2007 г. 17:54 231424 \RP2\A0000137.dll

08.03.2009 г. 04:34 914944 c:\windows\system32\dllcache\wininet.dll

13.08.2007 г. 17:54 818688 \RP2\A0000138.dll

03.08.2004 г. 22:10 19328 c:\windows\system32\dllcache\wstcodec.sys

03.08.2004 г. 22:10 19328 \RP3\A0000772.sys

03.08.2004 г. 21:39 142464 c:\windows\system32\drivers\aec.sys

03.08.2004 г. 21:39 142464 \RP3\A0000687.sys

03.08.2004 г. 23:05 14336 c:\windows\system32\drivers\asyncmac.sys

03.08.2004 г. 23:05 14336 \RP3\A0000688.sys

03.08.2004 г. 22:58 59904 c:\windows\system32\drivers\atmarpc.sys

03.08.2004 г. 22:58 59904 \RP3\A0000689.sys

07.05.2008 г. 06:38 17536 c:\windows\system32\drivers\ccdcmb.sys

07.05.2008 г. 06:38 17536 \RP3\A0000729.sys

07.05.2008 г. 06:38 20864 c:\windows\system32\drivers\ccdcmbo.sys

07.05.2008 г. 06:38 20864 \RP3\A0000730.sys

03.08.2004 г. 22:10 17024 c:\windows\system32\drivers\ccdecode.sys

03.08.2004 г. 22:10 17024 \RP3\A0000690.sys

23.08.2001 г. 14:00 18688 c:\windows\system32\drivers\Cdaudio.sys

23.08.2001 г. 14:00 18688 \RP3\A0000691.sys

03.08.2004 г. 23:00 8192 c:\windows\system32\drivers\Changer.sys

03.08.2004 г. 23:00 8192 \RP3\A0000692.sys

03.08.2004 г. 22:07 52864 c:\windows\system32\drivers\dmusic.sys

03.08.2004 г. 22:07 52864 \RP3\A0000693.sys

03.08.2004 г. 22:07 2944 c:\windows\system32\drivers\drmkaud.sys

03.08.2004 г. 22:07 2944 \RP3\A0000694.sys

03.08.2004 г. 22:59 20480 c:\windows\system32\drivers\Flpydisk.sys

03.08.2004 г. 22:59 20480 \RP3\A0000696.sys

03.08.2004 г. 23:14 52736 c:\windows\system32\drivers\i8042prt.sys

03.08.2004 г. 23:14 52736 \RP3\A0000697.sys

c:\windows\system32\drivers\imagedrv.sys

02.03.2004 г. 15:37 5504 \RP3\A0000525.sys

c:\windows\system32\drivers\imagesrv.sys

02.03.2004 г. 15:37 125184 \RP3\A0000526.sys

03.08.2004 г. 23:00 41856 c:\windows\system32\drivers\imapi.sys

03.08.2004 г. 23:00 41856 \RP3\A0000700.sys

03.08.2004 г. 23:00 29056 c:\windows\system32\drivers\ip6fw.sys

03.08.2004 г. 23:00 29056 \RP3\A0000702.sys

23.08.2001 г. 14:00 32896 c:\windows\system32\drivers\ipfltdrv.sys

23.08.2001 г. 14:00 32896 \RP3\A0000704.sys

03.08.2004 г. 23:04 20992 c:\windows\system32\drivers\ipinip.sys

03.08.2004 г. 23:04 20992 \RP3\A0000705.sys

03.08.2004 г. 23:00 11264 c:\windows\system32\drivers\irenum.sys

03.08.2004 г. 23:00 11264 \RP3\A0000706.sys

03.08.2004 г. 22:59 34688 c:\windows\system32\drivers\lbrtfdc.sys

03.08.2004 г. 22:59 34688 \RP3\A0000708.sys

04.08.2004 г. 01:05 30080 c:\windows\system32\drivers\Modem.sys

04.08.2004 г. 01:05 30080 \RP3\A0000711.sys

03.08.2004 г. 21:58 7552 c:\windows\system32\drivers\mskssrv.sys

03.08.2004 г. 21:58 7552 \RP3\A0000714.sys

03.08.2004 г. 21:58 5376 c:\windows\system32\drivers\mspclock.sys

03.08.2004 г. 21:58 5376 \RP3\A0000717.sys

03.08.2004 г. 21:58 4992 c:\windows\system32\drivers\mspqm.sys

03.08.2004 г. 21:58 4992 \RP3\A0000720.sys

03.08.2004 г. 21:58 5504 c:\windows\system32\drivers\mstee.sys

03.08.2004 г. 21:58 5504 \RP3\A0000721.sys

03.08.2004 г. 22:10 85376 c:\windows\system32\drivers\nabtsfec.sys

03.08.2004 г. 22:10 85376 \RP3\A0000723.sys

03.08.2004 г. 22:10 10880 c:\windows\system32\drivers\ndisip.sys

03.08.2004 г. 22:10 10880 \RP3\A0000725.sys

03.08.2004 г. 22:59 40320 c:\windows\system32\drivers\nmnt.sys

03.08.2004 г. 22:59 40320 \RP3\A0000727.sys

06.11.2007 г. 22:22 34064 c:\windows\system32\drivers\npf.sys

06.11.2007 г. 22:22 34064 \RP3\A0000731.sys

27.11.2006 г. 15:33 58368 c:\windows\system32\drivers\nvenetfd.sys

27.11.2006 г. 15:33 58368 \RP3\A0000732.sys

23.08.2001 г. 14:00 12416 c:\windows\system32\drivers\nwlnkflt.sys

23.08.2001 г. 14:00 12416 \RP3\A0000733.sys

23.08.2001 г. 14:00 32512 c:\windows\system32\drivers\nwlnkfwd.sys

23.08.2001 г. 14:00 32512 \RP3\A0000735.sys

17.09.2007 г. 14:53 21632 c:\windows\system32\drivers\pccsmcfd.sys

17.09.2007 г. 14:53 21632 \RP3\A0000737.sys

04.08.2004 г. 01:01 139400 c:\windows\system32\drivers\RDPWD.sys

04.08.2004 г. 01:01 139400 \RP3\A0000742.sys

03.08.2004 г. 22:59 11392 c:\windows\system32\drivers\Sfloppy.sys

03.08.2004 г. 22:59 11392 \RP3\A0000744.sys

03.08.2004 г. 22:10 11136 c:\windows\system32\drivers\slip.sys

03.08.2004 г. 22:10 11136 \RP3\A0000746.sys

03.08.2004 г. 22:07 6400 c:\windows\system32\drivers\splitter.sys

03.08.2004 г. 22:07 6400 \RP3\A0000747.sys

03.08.2004 г. 22:10 15360 c:\windows\system32\drivers\streamip.sys

03.08.2004 г. 22:10 15360 \RP3\A0000748.sys

17.08.2001 г. 13:00 54272 c:\windows\system32\drivers\swmidi.sys

17.08.2001 г. 13:00 54272 \RP3\A0000749.sys

04.08.2004 г. 01:01 12040 c:\windows\system32\drivers\TDPIPE.sys

04.08.2004 г. 01:01 12040 \RP3\A0000750.sys

04.08.2004 г. 01:01 21896 c:\windows\system32\drivers\TDTCP.sys

04.08.2004 г. 01:01 21896 \RP3\A0000751.sys

03.08.2004 г. 22:07 59264 c:\windows\system32\drivers\usbaudio.sys

03.08.2004 г. 22:07 59264 \RP3\A0000753.sys

03.08.2004 г. 22:08 25600 c:\windows\system32\drivers\usbser.sys

03.08.2004 г. 22:08 25600 \RP3\A0000754.sys

06.06.2008 г. 08:24 8064 c:\windows\system32\drivers\usbser_lowerflt.sys

06.06.2008 г. 08:24 8064 \RP3\A0000752.sys

07.05.2008 г. 06:38 8064 c:\windows\system32\drivers\usbser_lowerfltj.sys

07.05.2008 г. 06:38 8064 \RP3\A0000757.sys

03.08.2004 г. 22:08 26496 c:\windows\system32\drivers\usbstor.sys

03.08.2004 г. 22:08 26496 \RP3\A0000759.sys

06.12.2006 г. 01:39 1963680 c:\windows\system32\drivers\vx1000.sys

06.12.2006 г. 01:39 1963680 \RP3\A0000762.sys

02.11.2006 г. 06:22 492000 c:\windows\system32\drivers\wdf01000.sys

02.11.2006 г. 06:22 492000 \RP3\A0000766.sys

03.08.2004 г. 22:10 19328 c:\windows\system32\drivers\wstcodec.sys

03.08.2004 г. 22:10 19328 \RP3\A0000767.sys

15.09.2006 г. 21:30 82688 c:\windows\system32\drivers\wudfrd.sys

15.09.2006 г. 21:30 82688 \RP3\A0000770.sys

c:\windows\system32\drivers\xcybys.sys

27.02.2010 г. 05:15 54016 \RP3\A0000775.sys

08.03.2009 г. 04:31 348160 c:\windows\system32\dxtmsft.dll

13.08.2007 г. 17:35 346624 \RP2\A0000147.dll

08.03.2009 г. 04:31 216064 c:\windows\system32\dxtrans.dll

13.08.2007 г. 17:35 214528 \RP2\A0000148.dll

08.03.2009 г. 04:31 59904 c:\windows\system32\icardie.dll

13.08.2007 г. 17:36 61952 \RP2\A0000149.dll

08.03.2009 г. 04:32 173056 c:\windows\system32\ie4uinit.exe

13.08.2007 г. 17:39 54784 \RP2\A0000150.exe

08.03.2009 г. 04:33 125952 c:\windows\system32\ieakeng.dll

13.08.2007 г. 17:39 152064 \RP2\A0000151.dll

08.03.2009 г. 04:33 229376 c:\windows\system32\ieaksie.dll

13.08.2007 г. 17:39 229376 \RP2\A0000152.dll

08.03.2009 г. 04:32 163840 c:\windows\system32\ieakui.dll

13.08.2007 г. 16:56 161792 \RP2\A0000153.dll

08.03.2009 г. 04:11 445952 c:\windows\system32\ieapfltr.dll

11.07.2007 г. 11:27 383488 \RP2\A0000154.dll

08.03.2009 г. 14:09 391536 c:\windows\system32\iedkcs32.dll

13.08.2007 г. 17:39 382976 \RP2\A0000155.dll

08.03.2009 г. 04:39 11063808 c:\windows\system32\ieframe.dll

13.08.2007 г. 17:54 6049280 \RP2\A0000156.dll

08.03.2009 г. 04:31 183808 c:\windows\system32\iepeers.dll

13.08.2007 г. 17:54 191488 \RP2\A0000157.dll

08.03.2009 г. 04:32 55808 c:\windows\system32\iernonce.dll

13.08.2007 г. 17:39 43008 \RP2\A0000158.dll

08.03.2009 г. 04:32 1985024 c:\windows\system32\iertutil.dll

13.08.2007 г. 17:34 266752 \RP2\A0000159.dll

08.03.2009 г. 04:32 71680 c:\windows\system32\iesetup.dll

13.08.2007 г. 17:39 55296 \RP2\A0000160.dll

08.03.2009 г. 04:22 164352 c:\windows\system32\ieui.dll

13.08.2007 г. 17:54 180736 \RP2\A0000161.dll

c:\windows\system32\ImagX7.dll

26.07.2004 г. 15:16 1568768 \RP3\A0000416.dll

c:\windows\system32\ImagXpr7.dll

26.07.2004 г. 15:16 476320 \RP3\A0000417.dll

c:\windows\system32\ImagXR7.dll

26.07.2004 г. 15:16 262144 \RP3\A0000418.dll

c:\windows\system32\ImagXRA7.dll

26.07.2004 г. 15:16 471040 \RP3\A0000419.dll

08.03.2009 г. 04:31 34816 c:\windows\system32\imgutil.dll

13.08.2007 г. 17:36 36352 \RP2\A0000163.dll

08.03.2009 г. 04:32 94720 c:\windows\system32\inseng.dll

13.08.2007 г. 17:39 92672 \RP2\A0000165.dll

c:\windows\system32\java.exe

19.11.2008 г. 00:43 144792 \RP3\A0000265.exe

c:\windows\system32\javaw.exe

19.11.2008 г. 00:43 144792 \RP3\A0000266.exe

c:\windows\system32\javaws.exe

19.11.2008 г. 00:43 148888 \RP3\A0000267.exe

08.03.2009 г. 04:33 726528 c:\windows\system32\jscript.dll

17.05.2006 г. 10:43 465864 \RP2\A0000166.dll

08.03.2009 г. 04:33 25600 c:\windows\system32\jsproxy.dll

13.08.2007 г. 17:54 27136 \RP2\A0000167.dll

08.03.2009 г. 04:34 43008 c:\windows\system32\licmgr10.dll

13.08.2007 г. 17:44 40960 \RP2\A0000168.dll

08.03.2009 г. 04:32 594432 c:\windows\system32\msfeeds.dll

13.08.2007 г. 17:54 458752 \RP2\A0000169.dll

08.03.2009 г. 04:31 55296 c:\windows\system32\msfeedsbs.dll

13.08.2007 г. 17:54 50688 \RP2\A0000170.dll

08.03.2009 г. 04:31 13312 c:\windows\system32\msfeedssync.exe

13.08.2007 г. 17:36 12288 \RP2\A0000171.exe

08.03.2009 г. 04:31 45568 c:\windows\system32\mshta.exe

13.08.2007 г. 17:32 45568 \RP2\A0000172.exe

08.03.2009 г. 04:41 5937152 c:\windows\system32\mshtml.dll

13.08.2007 г. 17:54 3578368 \RP2\A0000173.dll

08.03.2009 г. 04:31 66560 c:\windows\system32\mshtmled.dll

13.08.2007 г. 17:54 475648 \RP2\A0000175.dll

08.03.2009 г. 04:31 48128 c:\windows\system32\mshtmler.dll

13.08.2007 г. 17:01 48128 \RP2\A0000176.dll

08.03.2009 г. 04:22 156160 c:\windows\system32\msls31.dll

13.08.2007 г. 17:54 156160 \RP2\A0000177.dll

08.03.2009 г. 04:34 193536 c:\windows\system32\msrating.dll

13.08.2007 г. 17:44 192000 \RP2\A0000178.dll

08.03.2009 г. 04:32 611840 c:\windows\system32\mstime.dll

13.08.2007 г. 17:54 670720 \RP2\A0000179.dll

c:\windows\system32\NeroCheck.exe

09.07.2001 г. 09:50 155648 \RP3\A0000403.exe

07.01.2009 г. 18:20 23552 c:\windows\system32\normaliz.dll

29.06.2006 г. 07:05 23552 \RP2\A0000100.dll

08.03.2009 г. 04:34 109568 c:\windows\system32\occache.dll

13.08.2007 г. 17:44 101376 \RP2\A0000180.dll

08.03.2009 г. 04:31 46592 c:\windows\system32\pngfilt.dll

13.08.2007 г. 17:36 44544 \RP2\A0000181.dll

c:\windows\system32\TwnLib20.dll

26.06.2000 г. 09:45 106496 \RP3\A0000433.dll

08.03.2009 г. 04:34 105984 c:\windows\system32\url.dll

13.08.2007 г. 17:44 105984 \RP2\A0000183.dll

08.03.2009 г. 04:34 1206784 c:\windows\system32\urlmon.dll

13.08.2007 г. 17:54 1162240 \RP2\A0000184.dll

08.03.2009 г. 04:33 420352 c:\windows\system32\vbscript.dll

\RP2\A0000185."

09.08.2004 г. 20:27 438272 \RP2\A0000185.dll

08.03.2009 г. 04:34 236544 c:\windows\system32\webcheck.dll

13.08.2007 г. 17:54 231424 \RP2\A0000186.dll

08.03.2009 г. 04:34 208384 c:\windows\system32\WinFXDocObj.exe

13.08.2007 г. 17:45 206336 \RP2\A0000187.exe

08.03.2009 г. 04:34 914944 c:\windows\system32\wininet.dll

13.08.2007 г. 17:54 818688 \RP2\A0000188.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Spyware Doctor"="c:\progra~1\SPYWAR~1\swdoctor.exe" [2005-12-13 1976544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]

"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-05-24 950664]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]

"nwiz"="nwiz.exe" [2006-10-22 1622016]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-12-13 1976544]

c:\documents and settings\Adrian\Start Menu\Programs\Startup\

Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2008-5-23 118784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-10-6 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe"

"VX1000"=c:\windows\vVX1000.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"21362:TCP"= 21362:TCP:BitComet 21362 TCP

"21362:UDP"= 21362:UDP:BitComet 21362 UDP

R2 XAMPP;XAMPP Service;c:\xampp\service.exe [x]

R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]

S0 d346bus;d346bus;c:\windows\system32\DRIVERS\d346bus.sys [2004-03-12 156800]

S0 d346prt;d346prt;c:\windows\System32\Drivers\d346prt.sys [2004-03-12 5248]

S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-05-24 15424]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

.

Contents of the 'Scheduled Tasks' folder

2010-02-26 c:\windows\Tasks\1-Click Maintenance.job

- c:\program files\TuneUp Utilities 2007en\SystemOptimizer.exe [2007-04-26 19:51]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe

LSP: c:\windows\system32\imon.dll

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://193.68.31.137/activex/AMC.cab

DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-27 06:32

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]

"ImagePath"="\??\c:\docume~1\Adrian\LOCALS~1\Temp\mc22.tmp"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(588)

c:\progra~1\SPYWAR~1\Tools\swpg.dat

- - - - - - - > 'lsass.exe'(644)

c:\progra~1\SPYWAR~1\Tools\swpg.dat

c:\windows\system32\imon.dll

- - - - - - - > 'explorer.exe'(1280)

c:\progra~1\SPYWAR~1\Tools\swpg.dat

c:\windows\system32\msi.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\IEFRAME.dll

c:\windows\system32\WPDShServiceObj.dll

c:\program files\Nokia\Nokia PC Suite 7\phonebrowser.dll

c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL

c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr

c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

- - - - - - - > 'csrss.exe'(564)

c:\progra~1\SPYWAR~1\Tools\swpg.dat

.

------------------------ Other Running Processes ------------------------

.

c:\windows\RTHDCPL.EXE

c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe

c:\program files\Microsoft LifeCam\MSCamS32.exe

c:\program files\Eset\nod32krn.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Photodex\ProShowGold\ScsiAccess.exe

c:\program files\Spyware Doctor\sdhelp.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2010-02-27 06:35:48 - machine was rebooted

ComboFix-quarantined-files.txt 2010-02-27 04:35

ComboFix2.txt 2010-02-27 03:57

Pre-Run: 4 683 071 488 bytes free

Post-Run: 4 652 834 816 bytes free

- - End Of File - - 4F5983E2BFF186A3376514FFA4F258C7

СТЪПКА 1

Желателно е да изключите временно System Restore, защото изтритите бацили са си все още там. Предполагам рууткита е бил този:

c:\windows\system32\drivers\xcybys.sys

27.02.2010 г. 05:15 54016 \RP3\A0000775.sys

Сега спрете => System Restore => десен бутон на My Computer => Properties => System restore => сложете отметка пред Turn off System restore on all drives => натиснете Apply.

СТЪПКА 2

Сега пробвайте да изтеглите и да преинсталирате Service Pack 3 за Windows XP за да се възстанови този файл с чисто копие:

[-] 2008-05-22 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

А и системата да стане по-сигурна.

Рестартирайте машината като го направите.

СТЪПКА 3

След това изтрийте вашата версия на Combofix.exe и изтеглете нова оттук.

Стартирайте файла и следвайте инструкциите.

Публикувайте лог файла в следващия си пост.

  • Автор

изпълних инструкциите ето лога:

прикачвам файла защото:

Коментарът ви е прекалено дълъг. Моля върнете се и го съкратете

log.txt

СТЪПКА 1

Лог файла изглежда добре.

Моля, архивирайте папката C:\Qoobox и я качете на този адрес:

http://www.rapidshare.de

Публикувайте линк за download за да я изтеглим.

Деинсталирайте Combofix.

Start => Run => въведете Combofix /Uninstall => (има празно място между Combofix и /Uninstall) => Enter => това ще стартира и ще деинсталира Combofix. Ще затрие и файловете асоциирани с този инструмент, както и папката C:\Qoobox - карантината на Combofix.

СТЪПКА 2

Желателно е да спрете и Autorun функцията на Windows като мярка за превенция на бъдещи проблеми с тази зараза.

Това можете да направите най-лесно с помощта на този инструмент:

Panda USB Vaccine

(Изтеглете и стартирайте приложението и натиснете Vaccinate computer).

СТЪПКА 3

Обновете NOD32 и направете пълна проверка на системата.

Публикувайте резултатите.

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.