Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с компютър/вирус! [РЕШЕН]

Featured Replies

Та значи имам следния проблем...когато си пусна компютъра и едвам зацепи (не винаги зацепва - след като ми зареди уиндоуса и стигне вече на декстопа нали ...премигва,премигва и ми изгасва монитора,сякаш заспива и нищо не може да се направи освен рестарт) интернета ми работи в началото,но след известно време изчезва смисъл спира .. сканирах,трих некви вируси със аваст и mallwarebytes' и нищо все същото.След рестарт тръгва пак нали ако зацепи от първия път известно време има интернет и пак изчезва.Доста често се случва докато правя нещо по компютъра дори не свързано с интернет да зацепи и да се налага да го рестартирам.До вчера цялото старт меню не ми функционираше от време на време,но това се оправи ..незнам как сигурно от многото сканирания и т.н. Също така не ми отваря почти никой официален сайт за антивирусна програма.

Незнам дали всичко е в следствие от вирусите или поради причината,че машината вече ми е стара.

Наскоро преинсталирах .. мога пак но няма как да си форматирам всички дялове на хард дисковете на този етап тъй като нямам къде да си кача информацията която искам да запазя,та за това ако има някакво друго решение на въпроса ще се радвам ако ми помогнете!

Това е лога от Malwarebytes' Anti-Malware които този път не откри нищо:

Malwarebytes' Anti-Malware 1.44

Database version: 3510

Windows 5.1.2600 Service Pack 3

Internet Explorer 6.0.2900.5512

28.4.2010 г. 20:57:34

mbam-log-2010-04-28 (20-57-34).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)

Objects scanned: 169527

Time elapsed: 49 minute(s), 8 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Ето и от HijackThis :

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 21:00:15, on 28.4.2010 г.

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\D-Tools\daemon.exe

C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\WINDOWS\system32\msiexec.exe

C:\HJT\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.bg/

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: BlueSoleil.lnk = ?

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{F869851E-6F02-4A9D-901D-AC45CC3372BE}: NameServer = 88.203.163.1 91.134.0.43

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--

End of file - 4089 bytes

Редактирано от nologo (преглед на промените)

Моля, следвайте това, което е написано по-долу, стъпка по стъпка:

Стъпка 1

Следвайте следната инструкция за работа с TFC (програмата ще премахне ненужните временни файлове):

  • Изтеглете TFC (Temp File Cleaner) от тук и го запишете на десктопа
  • Стартирайте TFC.exe
  • Имайте търпение и изчакайте програмата да завърши работата си
  • Ако е необходимо, потвърдете с OK за рестартиране на Windows

Стъпка 2

Следвайте следната инструкция за работа с OTL:

  • Изтеглете OTL.exe и го запазете на десктопа.
  • Стартирайте файла otlDesktopIcon.png с двукратен клик на мишката.
  • Направете следните настройки:

33wm6o2.jpg

  • Под "Custom Scans/Fixes" с Copy/ Paste въведете следната информация от цитата по-долу:

netsvcs

msconfig

safebootminimal

safebootnetwork

activex

drivers32

%SYSTEMDRIVE%\*.exe

%systemroot%\*. /mp /s

%ALLUSERSPROFILE%\Application Data\*.

%ALLUSERSPROFILE%\Application Data\*.exe /s

%APPDATA%\*.

%APPDATA%\*.exe /s

/md5start

eventlog.dll

scecli.dll

netlogon.dll

cngaudit.dll

sceclt.dll

ntelogon.dll

logevent.dll

iaStor.sys

nvstor.sys

atapi.sys

beep.sys

IdeChnDr.sys

viasraid.sys

AGP440.sys

vaxscsi.sys

nvatabus.sys

viamraid.sys

nvata.sys

nvgts.sys

iastorv.sys

ViPrt.sys

eNetHook.dll

ahcix86.sys

ahcix86s.sys

KR10N.sys

nvstor32.sys

nvrd32.sys

explorer.exe

svchost.exe

userinit.exe

symmpi.sys

qmgr.dll

ws2_32.dll

proquota.exe

imm32.dll

kernel32.dll

ndis.sys

autochk.exe

spoolsv.exe

xmlprov.dll

ntmssvc.dll

mswsock.dll

ntfs.sys

tcpip.sys

termsrv.dll

sfcfiles.dll

st3shark.sys

srsvc.dll

adp3132.sys

mv61xx.sys

/md5stop

CREATERESTOREPOINT

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\system32\drivers\*.sys /lockedfiles

%systemroot%\System32\config\*.sav

%systemroot%\system32\drivers\*.sys /90

  • Натиснете маркираният в синьо бутон: 30rn2na.jpg.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt.

Стъпка 3

Прикачете в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение):

  • Логовете от OTL: OTL.Txt, Extras.Txt

Съжалявам, ще трябва да направите още едно пълно сканиране с Malwarebytes' Anti-Malware (MBAM). При предишното сканиране не сте обновили (update) програмата. За нас е важно да знаем как работят последните дефиниции на MBAM.

Ето как ще трябва да сканирате с MBAM:

  • Стартирайте програмата, направете обновяване (update) и изберете Perform Full Scan.
  • След това кликнете на Scan. Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете Remove Selected.
  • Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. копирайте съдържанието му и го поставете в следващия си коментар.

След това ще дам скрипт за OTL.

  • Автор
Malwarebytes' Anti-Malware 1.45

www.malwarebytes.org

Database version: 4051

Windows 5.1.2600 Service Pack 3

Internet Explorer 6.0.2900.5512

29.4.2010 г. 19:29:21

mbam-log-2010-04-29 (19-29-21).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|)

Objects scanned: 166971

Time elapsed: 43 minute(s), 51 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vqfyhga (Worm.Conficker) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system32\jdtoke.dll (Worm.Conficker) -> Delete on reboot.

E:\System Volume Information\_restore{AF9803F5-B2B0-4092-AF79-1C4451A1C14E}\RP482\A0369839.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.

и като му дадох рестарт зацепи от третото включване.

Добре. Сега ще може ли още един лог на OTL:

  • Стартирайте файла otlDesktopIcon.png с двукратен клик на мишката.
  • Направете следните настройки:

33wm6o2.jpg

  • Под "Custom Scans/Fixes" с Copy/ Paste въведете следната информация от цитата по-долу:

netsvcs

msconfig

safebootminimal

safebootnetwork

activex

drivers32

%SYSTEMDRIVE%\*.*

/md5start

jdtoke.dll

/md5stop

%systemroot%\*. /mp /s

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%PROGRAMFILES%\*.

%userprofile%\Desktop\*.*

%userprofile%\Desktop\*.

  • Натиснете маркираният в синьо бутон: 30rn2na.jpg.
  • Като приключи проверката, публикувайте лог файла OTL.Txt или го прикачете към следващия си коментар.

Благодаря за логовете. Ще е добре да пуснете още един лог, този път от DDS, за да видя какво остана за чистене. За заразата Conficker ще трябват още малко усилия. Ето какво следва.

Следвайте следната инструкция за работа с DDS:

  • Изтеглете DDS: от bleepingcomputer.
  • След изтегляне на файла го запишете (бутон Save -> Save as) DDS на вашия десктоп, снимка:
    2exprgh.jpg
  • След като изтеглите DDS на десктопа, иконката на програмата би трябвало да изглежда така: rvwlll.jpg
  • Прекратете временно работата на всички скрипт блокиращи приложения, ако има такива или разрешете изпълнението на dds.scr. След това стартирайте DDS с двоен клик на иконката, като потвърдите с Run.
  • След приключване на работата на DDS копирайте с Copy текста от двата файлови лога, които ще се появят в Notepad: DDS.txt и Attach.txt. После използвайте Paste и поставете двата лога в следващия си коментар по темата. Също така запазете двата файла (бутон Save -> Save as) на десктопа.

  • Автор

DDS (Ver_10-03-17.01) - NTFSx86

Run by BASS at 5:02:02,03 on 01.05.2010 Ј.

Internet Explorer: 6.0.2900.5512

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.180 [GMT 3:00]

AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\D-Tools\daemon.exe

C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\BASS\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.bg/

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

mRun: [soundMan] SOUNDMAN.EXE

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /install

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [DAEMON Tools-1033] "c:\program files\d-tools\daemon.exe" -lang 1033

mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueso~1.lnk - c:\program files\ivt corporation\bluesoleil\BlueSoleil.exe

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: {F869851E-6F02-4A9D-901D-AC45CC3372BE} = 88.203.163.1 91.134.0.43

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\bass\applic~1\mozilla\firefox\profiles\0ri83a1v.default\

FF - prefs.js: browser.startup.homepage - hxxp://hmsu.org/

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2010-4-10 155136]

R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2010-4-10 5248]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-28 162768]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-28 19024]

R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-28 40384]

R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-28 40384]

R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-28 40384]

S0 ddegnro;ddegnro;c:\windows\system32\drivers\fnce.sys --> c:\windows\system32\drivers\fnce.sys [?]

=============== Created Last 30 ================

2010-04-29 17:29:35 0 d-----w- C:\_OTL

2010-04-29 15:42:44 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 15:42:41 20824 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-04-29 15:42:41 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-04-28 17:10:55 0 d-----w- C:\HJT

2010-04-28 06:09:25 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software

2010-04-28 06:08:46 0 d-----w- c:\docume~1\bass\applic~1\Malwarebytes

2010-04-28 06:08:40 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-04-27 19:30:07 7680 ----a-w- c:\windows\system32\kbdBPKL.dll

2010-04-27 17:51:49 0 d-----r- c:\program files\Skype

2010-04-27 17:42:13 0 d-----w- c:\program files\uTorrent

2010-04-27 17:40:38 0 d-----w- c:\docume~1\bass\applic~1\uTorrent

2010-04-27 17:34:19 0 d-----w- c:\docume~1\bass\applic~1\BSplayer

2010-04-27 17:22:50 71168 ----a-w- c:\windows\system32\drivers\Rtlnicxp.sys

2010-04-27 16:44:06 0 d-----w- c:\windows\system32\NtmsData

2010-04-27 16:28:17 0 d-s---w- c:\documents and settings\bass\UserData

2010-04-27 16:21:37 0 d-----w- C:\Medion

2010-04-27 16:12:59 0 d-----w- c:\windows\OPTIONS

2010-04-27 05:36:05 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys

2010-04-27 05:36:05 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys

2010-04-27 05:34:49 28672 ----a-w- c:\windows\system32\drivers\vidcap.ax

2010-04-27 05:34:48 53760 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll

2010-04-27 05:34:46 91136 ----a-w- c:\windows\system32\drivers\kswdmcap.ax

2010-04-27 05:34:46 61952 ----a-w- c:\windows\system32\drivers\kstvtune.ax

2010-04-27 05:34:46 43008 ----a-w- c:\windows\system32\drivers\ksxbar.ax

2010-04-27 05:34:17 208 ----a-r- c:\windows\system32\drivers\vssver.scc

2010-04-27 05:33:22 0 d-----w- c:\program files\IVT Corporation

2010-04-23 12:25:51 0 d-----w- c:\program files\Xilisoft

2010-04-21 05:10:19 376 ----a-w- c:\windows\ODBC.INI

2010-04-21 05:09:25 0 d-----w- c:\program files\Microsoft ActiveSync

2010-04-21 05:08:49 0 d-----w- c:\windows\SHELLNEW

2010-04-10 14:04:32 368640 ----a-w- c:\windows\system32\ReWire.dll

2010-04-10 14:04:32 233472 ----a-w- c:\windows\system32\REX Shared Library.dll

2010-04-10 13:54:11 0 d-----w- c:\docume~1\alluse~1\applic~1\Propellerhead Software

2010-04-10 13:54:09 0 d-----w- c:\docume~1\bass\applic~1\Propellerhead Software

2010-04-10 13:53:17 0 d-----w- C:\Propellerhead

2010-04-10 13:50:20 5248 ----a-w- c:\windows\system32\drivers\d347prt.sys

2010-04-10 13:50:20 155136 ----a-w- c:\windows\system32\drivers\d347bus.sys

2010-04-10 13:50:19 0 d-----w- c:\program files\D-Tools

2010-04-10 13:49:55 0 d-----w- c:\windows\Downloaded Installations

2010-04-06 14:47:45 0 d-----w- c:\program files\VirtualDJ

2010-04-06 06:43:15 88566 ----a-w- c:\windows\system32\nvapps.xml

2010-04-06 06:43:05 27136 ----a-r- c:\windows\system32\nvcod.dll

2010-04-06 06:43:03 225280 ----a-r- c:\windows\system32\nvnt4cpl.dll

2010-04-06 06:43:02 49152 ----a-r- c:\windows\system32\nvmctray.dll

2010-04-06 06:43:02 35328 ----a-r- c:\windows\system32\nvwddi.dll

2010-04-06 06:42:54 5058560 ----a-r- c:\windows\system32\nvcpl.dll

2010-04-06 06:42:53 3551232 ----a-r- c:\windows\system32\nvoglnt.dll

2010-04-06 06:42:52 81920 ----a-r- c:\windows\system32\nvsvc32.exe

2010-04-06 06:42:50 4246528 ----a-w- c:\windows\system32\nv4_disp.dll

2010-04-06 06:42:50 1550043 ----a-w- c:\windows\system32\drivers\nv4_mini.sys

2010-04-06 06:42:49 552960 ----a-r- c:\windows\system32\nviewimg.dll

2010-04-06 06:42:49 131072 ----a-r- c:\windows\system32\nvinstnt.dll

2010-04-06 06:41:49 208896 ----a-w- c:\windows\system32\NVUNINST.EXE

2010-04-06 06:41:26 0 d-----w- C:\NVIDIA

2010-04-06 00:03:29 4444 ----a-w- c:\windows\system32\pid.PNF

2010-04-05 23:49:38 0 d-----w- c:\program files\common files\ODBC

2010-04-05 23:49:32 0 d-----w- c:\program files\common files\SpeechEngines

2010-04-05 23:48:08 0 d-----r- c:\documents and settings\all users\Documents

2010-04-05 23:19:36 0 d-----w- c:\program files\AC3Filter

2010-04-05 23:11:39 0 d-----w- c:\docume~1\bass\applic~1\BSplayer Pro

2010-04-05 23:11:30 0 d-----w- c:\program files\Webteh

2010-04-05 23:05:15 0 d-----w- c:\program files\K-Lite Codec Pack

2010-04-05 22:08:50 0 d-----w- c:\program files\Realtek Sound Manager

2010-04-05 22:08:48 0 d-----w- c:\program files\AvRack

2010-04-05 21:50:14 0 d-----w- c:\program files\Gigabyte

2010-04-05 21:18:05 0 d-sh--w- c:\documents and settings\all users\DRM

2010-04-05 21:17:00 0 d--h--w- c:\program files\WindowsUpdate

2010-04-05 21:15:21 0 d-----w- c:\program files\common files\MSSoap

2010-04-05 21:11:03 0 d-----w- c:\program files\Online Services

2010-04-05 21:10:35 0 d-----w- c:\program files\Messenger

2010-04-05 21:10:31 0 d-----w- c:\program files\MSN Gaming Zone

2010-04-05 21:09:25 0 d-----w- c:\program files\Windows NT

==================== Find3M ====================

2010-04-05 21:12:56 21640 ----a-w- c:\windows\system32\emptyregdb.dat

2010-03-14 18:00:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll

2010-02-10 17:13:48 165376 ----a-w- c:\windows\system32\unrar.dll

============= FINISH: 5:02:36,10 ===============

Тва беше ддс а ето го и Attach file-а :

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 06.4.2010 г. 00:25:50

System Uptime: 29.4.2010 г. 20:54:09 (33 hours ago)

Motherboard: Gigabyte Technology Co., Ltd. | | 8IPE1000-G/L

Processor: Intel® Celeron® CPU 2.60GHz | Socket 478 | 2625/100mhz

==== Disk Partitions =========================

A: is Removable

C: is FIXED (NTFS) - 20 GiB total, 0,628 GiB free.

D: is FIXED (NTFS) - 55 GiB total, 0,685 GiB free.

E: is FIXED (NTFS) - 59 GiB total, 1,814 GiB free.

F: is FIXED (NTFS) - 53 GiB total, 0,943 GiB free.

G: is CDROM ()

H: is CDROM (UDF)

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: Bluetooth PAN Network Adapter

Device ID: ROOT\NET\0000

Manufacturer: IVT Corporation

Name: Bluetooth PAN Network Adapter

PNP Device ID: ROOT\NET\0000

Service: BT

==== System Restore Points ===================

RP9: 28.4.2010 г. 20:54:20 - avast! Free Antivirus Setup

RP10: 28.4.2010 г. 20:59:49 - Installed HiJackThis

RP11: 28.4.2010 г. 21:26:28 - System Checkpoint

RP12: 29.4.2010 г. 00:09:51 - OTL Restore Point

RP13: 30.4.2010 г. 04:42:49 - System Checkpoint

==== Installed Programs ======================

µTorrent

AC3Filter (remove only)

Adobe Acrobat 5.0

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

avast! Free Antivirus

BlueSoleil

BS.Player FREE

Bulgarian Phonetic Keyboard Layout

DAEMON Tools

Enable S3 for USB Device

HiJackThis

Hotfix for Windows XP (KB942288-v3)

Hotfix for Windows XP (KB970653-v3)

K-Lite Codec Pack 5.8.3 (Full)

Malwarebytes' Anti-Malware

Microsoft Office Professional Edition 2003

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Mozilla Firefox (3.6.3)

NVIDIA Drivers

Realtek AC'97 Audio

REALTEK Gigabit and Fast Ethernet NIC Driver

Reason 4.0

RTLSetup

Security Update for Windows XP (KB950760)

Security Update for Windows XP (KB956391)

Security Update for Windows XP (KB960715)

Security Update for Windows XP (KB969898)

Security Update for Windows XP (KB973346)

Skype™ 4.2

Update for Windows XP (KB898461)

Update for Windows XP (KB943729)

Virtual DJ - Atomix Productions

WebFldrs XP

Winamp

WinRAR archiver

==== Event Viewer Messages From Past Week ========

29.4.2010 г. 18:37:37, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 17:23:02, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 15:47:29, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 14:28:36, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 13:36:55, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 13:05:29, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 08:08:11, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 00:05:18, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 00:02:15, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).

29.4.2010 г. 00:02:15, error: Service Control Manager [7034] - The BlueSoleil Hid Service service terminated unexpectedly. It has done this 1 time(s).

29.4.2010 г. 00:00:48, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

29.4.2010 г. 00:00:35, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

29.4.2010 г. 00:00:34, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

29.4.2010 г. 00:00:34, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 20:54:18, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000098' while processing the file 'Skype.lnk' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

28.4.2010 г. 19:37:44, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 19:37:32, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 19:37:30, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 19:37:29, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 18:18:31, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 18:18:21, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 18:18:18, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 17:37:21, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.

28.4.2010 г. 16:44:23, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 16:44:23, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Print Spooler service to connect.

28.4.2010 г. 16:44:23, error: Service Control Manager [7000] - The Print Spooler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

28.4.2010 г. 16:44:14, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 16:44:13, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 16:06:17, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000098' while processing the file 'Skype.lnk' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

28.4.2010 г. 15:40:32, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 15:25:42, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IntelIde

28.4.2010 г. 15:25:42, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 15:25:32, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 15:25:29, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 10:04:50, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 09:34:49, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 09:19:56, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 09:19:49, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 09:19:47, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 08:28:47, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 08:27:59, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 08:27:56, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 08:27:55, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 01:01:38, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 01:01:25, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 01:01:25, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

28.4.2010 г. 01:01:25, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

28.4.2010 г. 00:04:01, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 23:59:56, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 23:59:52, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 23:59:51, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 22:14:00, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 22:13:39, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 22:13:36, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 22:13:35, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 21:24:51, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 21:24:51, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 21:24:51, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 20:27:42, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 20:27:41, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 20:27:40, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 20:15:52, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 20:08:21, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 19:17:13, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 18:50:22, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 12:36:28, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 09:15:30, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 09:00:30, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

27.4.2010 г. 08:51:45, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 08:50:00, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 08:50:00, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.

27.4.2010 г. 08:44:55, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

27.4.2010 г. 08:36:02, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

26.4.2010 г. 14:38:30, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

25.4.2010 г. 12:49:50, error: Service Control Manager [7023] - The Microsoft Security service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

25.4.2010 г. 12:49:50, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.

25.4.2010 г. 12:49:50, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.

25.4.2010 г. 12:49:50, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

==== End Of File ===========================

Редактирано от m1reca (преглед на промените)

Сега ще ми трябва и един лог от RootRepeal. Затова следвайте следната инструкция за работа с RootRepeal:

  • Изтеглете ZIP архив на RootRepeal, ето два миръра:geekstogo или psikotick
  • Разархивирайте RootRepeal.zip на вашия десктоп, стартирайте RootRepeal.exe и направете следните настройки:
  • Кликнете на таба Report в долната част на прозореца.
  • Кликнете на бутона Scan
  • Сложете отметки пред следното:


  • Drivers

  • Files

  • Processes

  • SSDT

  • Stealth Objects

  • Hidden Services

  • Shadow SSDT

  • Кликнете на бутона OK
  • На следващия диалогов прозорец, сложете отметки преди всички дялове (C:\ , D:\ ....)
  • Кликнете на OK, за да започне процеса на сканиране

Забележка: Процеса на сканиране може да отнеме време. Моля,
не стартирайте
никакви програми, докато програмата сканира.

  • Когато сканирането завърши успешно ще се появи бутона Save Report
  • Кликнете върху Save Report и запишете лог файла на вашия десктоп, с име RootRepeal.txt
  • Отворете File, след което Exit, за да затворите програмата.
  • Копирайте и поставете съдържанието на RootRepeal.txt в следващия си коментар.

  • Автор

ROOTREPEAL © AD, 2007-2009

==================================================

Scan Start Time: 2010/05/01 13:48

Program Version: Version 1.3.5.0

Windows Version: Windows XP SP3

==================================================

Drivers

-------------------

Name:

Image Path:

Address: 0xF8792000 Size: 98304 File Visible: No Signed: -

Status: -

Name:

Image Path:

Address: 0x00000000 Size: 0 File Visible: No Signed: -

Status: -

Name: dump_atapi.sys

Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys

Address: 0xF6D4D000 Size: 98304 File Visible: No Signed: -

Status: -

Name: dump_WMILIB.SYS

Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Address: 0xF8D97000 Size: 8192 File Visible: No Signed: -

Status: -

Hidden/Locked Files

-------------------

Path: C:\hiberfil.sys

Status: Locked to the Windows API!

SSDT

-------------------

#: 025 Function Name: NtClose

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46c08

#: 041 Function Name: NtCreateKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46ac4

#: 045 Function Name: NtCreatePagingFile

Status: Hooked by "d347bus.sys" at address 0xf882fa20

#: 063 Function Name: NtDeleteKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e47078

#: 065 Function Name: NtDeleteValueKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46fa2

#: 068 Function Name: NtDuplicateObject

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e4669a

#: 071 Function Name: NtEnumerateKey

Status: Hooked by "d347bus.sys" at address 0xf88302a8

#: 073 Function Name: NtEnumerateValueKey

Status: Hooked by "d347bus.sys" at address 0xf883b910

#: 119 Function Name: NtOpenKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46b9e

#: 122 Function Name: NtOpenProcess

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e465da

#: 128 Function Name: NtOpenThread

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e4663e

#: 160 Function Name: NtQueryKey

Status: Hooked by "d347bus.sys" at address 0xf88302c8

#: 177 Function Name: NtQueryValueKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46cbe

#: 192 Function Name: NtRenameKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e47146

#: 204 Function Name: NtRestoreKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46c7e

#: 241 Function Name: NtSetSystemPowerState

Status: Hooked by "d347bus.sys" at address 0xf883b0b0

#: 247 Function Name: NtSetValueKey

Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf6e46dfe

Stealth Objects

-------------------

Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]

Process: System Address: 0x8335ae10 Size: 11

Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]

Process: System Address: 0x8304f348 Size: 11

Object: Hidden Code [Driver: Udfsȅఉ瑎捦܉@考, IRP_MJ_READ]

Process: System Address: 0x83196538 Size: 11

Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_READ]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]

Process: System Address: 0x83245b88 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]

Process: System Address: 0x82fd7918 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_CREATE]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_CREATE_NAMED_PIPE]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_CLOSE]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_READ]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_WRITE]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_INFORMATION]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_INFORMATION]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_EA]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_EA]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_FLUSH_BUFFERS]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_VOLUME_INFORMATION]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_VOLUME_INFORMATION]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_DIRECTORY_CONTROL]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_FILE_SYSTEM_CONTROL]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_DEVICE_CONTROL]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_INTERNAL_DEVICE_CONTROL]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SHUTDOWN]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_LOCK_CONTROL]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_CLEANUP]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_CREATE_MAILSLOT]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_SECURITY]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_SECURITY]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_POWER]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SYSTEM_CONTROL]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_DEVICE_CHANGE]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_QUERY_QUOTA]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_SET_QUOTA]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: d347prt, IRP_MJ_PNP]

Process: System Address: 0x82f55f00 Size: 99

Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]

Process: System Address: 0x830191c0 Size: 11

Object: Hidden Code [Driver: Srv, IRP_MJ_READ]

Process: System Address: 0x82450948 Size: 11

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]

Process: System Address: 0x82f81480 Size: 11

Object: Hidden Code [Driver: Npfsȅే浍瑓苿q, IRP_MJ_READ]

Process: System Address: 0x82f33138 Size: 11

Object: Hidden Code [Driver: Msfsȅ瑎捦ȁఄ䵃䥖ꈨ褉붉檁, IRP_MJ_READ]

Process: System Address: 0x82fb9658 Size: 11

Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]

Process: System Address: 0x831a1188 Size: 11

Object: Hidden Code [Driver: Ma, IRP_MJ_READ]

Process: System Address: 0x82f4a1b0 Size: 11

==EOF==

Стартирайте пак OTL.exe и с Copy/ Paste под колонката Custom Scans/Fixes въведете скриптовия текст от цитата по-долу, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди OTL!

:OTL

O4 - HKLM..\Run: [KernelFaultCheck] File not found

O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe File not found

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O32 - AutoRun File - [2010.04.06 00:20:57 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2007.08.10 18:52:56 | 000,106,496 | RH-- | M] () - H:\Autorun.exe -- [ UDF ]

O32 - AutoRun File - [2007.08.08 11:11:43 | 000,000,050 | RH-- | M] () - H:\Autorun.inf -- [ UDF ]

O32 - AutoRun File - [2007.08.10 19:24:29 | 000,000,414 | RH-- | M] () - H:\autorun.ini -- [ UDF ]

O33 - MountPoints2\{0299fb1c-4108-11df-b59b-a216427dcbd3}\Shell - "" = AutoRun

O33 - MountPoints2\{0299fb1c-4108-11df-b59b-a216427dcbd3}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{3af792c1-418a-11df-b5a1-91d8982ff9d7}\Shell\AutoRun\command - "" = wscript.exe jargon.vbs

O33 - MountPoints2\{3af792c1-418a-11df-b5a1-91d8982ff9d7}\Shell\Open\Command - "" = wscript.exe jargon.vbs

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

:services

ddegnro

:files

c:\windows\system32\drivers\fnce.sys

:reg

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]

""=""%1" %*"

:commands

[purity]

[emptytemp]

[resethosts]

[Reboot]

След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: Run Fix. Ще се създаде лог файл. Копирайте лог файла и поставете съдържанието му в следващия си коментар.

  • Автор
All processes killed

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\WinampAgent deleted successfully.

Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

C:\WINDOWS\Downloaded Program Files\gp.inf not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

C:\AUTOEXEC.BAT moved successfully.

File move failed. H:\Autorun.exe scheduled to be moved on reboot.

File move failed. H:\Autorun.inf scheduled to be moved on reboot.

File move failed. H:\autorun.ini scheduled to be moved on reboot.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0299fb1c-4108-11df-b59b-a216427dcbd3}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0299fb1c-4108-11df-b59b-a216427dcbd3}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0299fb1c-4108-11df-b59b-a216427dcbd3}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0299fb1c-4108-11df-b59b-a216427dcbd3}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3af792c1-418a-11df-b5a1-91d8982ff9d7}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3af792c1-418a-11df-b5a1-91d8982ff9d7}\ not found.

File wscript.exe jargon.vbs not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3af792c1-418a-11df-b5a1-91d8982ff9d7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3af792c1-418a-11df-b5a1-91d8982ff9d7}\ not found.

File wscript.exe jargon.vbs not found.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.

========== SERVICES/DRIVERS ==========

Service ddegnro stopped successfully!

Service ddegnro deleted successfully!

========== FILES ==========

File\Folder c:\windows\system32\drivers\fnce.sys not found.

========== REGISTRY ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: BASS

->Temp folder emptied: 394990 bytes

->Temporary Internet Files folder emptied: 235582 bytes

->FireFox cache emptied: 84626149 bytes

->Flash cache emptied: 2348 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 81,00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

OTL by OldTimer - Version 3.2.3.0 log created on 05012010_183419

Files\Folders moved on Reboot...

File move failed. H:\Autorun.exe scheduled to be moved on reboot.

File move failed. H:\Autorun.inf scheduled to be moved on reboot.

File move failed. H:\autorun.ini scheduled to be moved on reboot.

File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Ето какво следва:

Стъпка 1

Препоръки:

  • Mоже да инсталирате KB971029. Този ъпдейт ще ограничи AutoRun възможностите в диалога AutoPlay само за CD и DVD.
  • Може да използвате Panda USB Vaccine. Ако сте решили да я използвате, просто стартирайте програмата и натиснете бутона Vaccinate Computer.

Стъпка 2

Следвайте следната инструкция за проверка с ESET Online Scanner:

  • Изтеглете: ESET Online Scanner
  • Стартирайте esetsmartinstaller_enu.exe
  • Сложете отметка на YES, I accept the Terms of Use и изберете Start
  • Скенерът ще започне да изтегля компонентите, които са му необходими.
  • Уверете се, че има отметки на следните редове, включително и тези от менюто Advanced Settings:

  • Remove found threats

  • Scan archives

  • Scan for potentially unwanted applications

  • Scan for potentially unsafe applications

  • Enable Anti-Stealth technology

  • Накрая изберете Start
  • Скенерът ще започне да изтегля последните дефиниции.
  • След, като сканирането завърши, изберете Finish.
  • Отидете в: C:\Program Files\ESET\ESET Online Scanner и отворете файла log.txt. Копирайте съдържанието му и го поставете в следващия си коментар.

  • Автор
ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=d2c05fa34f5bf84d83920c57eb7081e7

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-05-02 11:08:15

# local_time=2010-05-02 02:08:15 (+0200, FLE Daylight Time)

# country="Bulgaria"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=768 16777175 100 0 357819 357819 0 0

# compatibility_mode=8192 67108863 100 0 173 173 0 0

# scanned=67345

# found=0

# cleaned=0

# scan_time=5710

Много добре! Сега ето какво препоръчвам:

Стъпка 1

  • Както написах по-горе - използвайте Panda USB Vaccine и ваксинирайте компютъра (Vaccinate computer).
  • Така ще се спре Autorun/Autoplay, който е един от начините на разпространение на червея Conficker. При използване на флашка ще се наложи да я отваряте ръчно през My Computer, защото менюто няма да се появи.

Стъпка 2

  • Отворете Start -> run -> напишете -> services.msc -> намерете от списъка -> Server -> двукратен клик -> Stop -> и от Startup type -> посочете -> Disabled.
  • Така ще се спре вторият начин за разпространение на червея, но със спирането на тази услуга няма да можете да използвате споделените (shared) принтери в мрежата.

Стъпка 2

Стъпка 3

  • Изпълнете следната инструкция за почистване и имунизиране на USB флаш памети.

P.S. Ако решите и изпълните всички препоръки, моля да коментирате какво е състоянието на Windows и как се сържи системата.

  • Автор

Ами направих всичко което ми казахте и препоръчахте.

Не съм сядал за дълго на компютъра,но проблемите за които писах мисля,че са решени.Уиндоуса се държи нормално на пръв поглед.Не "хвърчи" така да се каже,но кято цяло съм доволен и благодаря!Ако имате още някакви препоръки с удоволствие бих ги изпълнил.Виждам,че си разбирате от работата и пак ви благодаря! :)

И аз благодаря за точното спазване на всички инструкции. Сега ще маркирам проблема като приключен, като добавя [РЕШЕН] в заглавието на темата.

Сега вече може да деинсталирате OTL. Ето как: стартирайте OTL.exe още веднъж и натиснете бутона CleanUp!

35hfp21.jpg

При дeинсталацията на OTL ще бъдат почистени инструменти и работни папки, които използвахме в темата.

Успех!

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.