Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

TR/VB.Agent.356352.B - Вирус! - Hijack and MW logs

Featured Replies

Постоянно ми излиза някакъв вирус на име "TR/VB.Agent.356352.B". Сканирах с Авира (пълно сканиране, бързо сканиране и сканиране на "My Documents" и "D:") и винаги е същия вирус!

ПЪРВО ЕТО СНИМКИ ОТ АВИРА - http://prikachi.com/images.php?images/746/2388746j.jpg

http://prikachi.com/images.php?images/754/2388754N.jpg

http://prikachi.com/images.php?images/725/2388725O.jpg

http://prikachi.com/images.php?images/723/2388723G.jpg (ПОСТОЯННО МИ ИЗЛИЗА ТОВА СЪОБЩЕНИЕ ДОКАТО НЕ СПРА АВИРА)

Ето Hijack лога - Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 6:59:20 PM, on 8/2/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\RunDll32.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\VideoLAN\VLC\vlc.exe

C:\Documents and Settings\Linux\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\Winlog\Winlogon.exe

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

O4 - HKCU\..\Run: [HKCU] C:\WINDOWS\system32\Winlog\Winlogon.exe

O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\Winlog\Winlogon.exe

O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\Winlog\Winlogon.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A6A3603C-E70C-4E0A-B4E7-46112A0B0B31}: NameServer = 195.24.90.1

O17 - HKLM\System\CCS\Services\Tcpip\..\{E1AB9185-6C73-4CC5-98D3-3BAC0F0A03F9}: NameServer = 195.24.89.8 195.24.90.1

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--

End of file - 3541 bytes

___________________________________________________________________________

Ето и Malwarebytes лога - Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4381

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

8/2/2010 7:43:20 PM

mbam-log-2010-08-02 (19-43-20).txt

Scan type: Full scan (C:\|D:\|)

Objects scanned: 137296

Time elapsed: 49 minute(s), 43 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 4

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 4

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{xq881j2h-07ya-wrbn-4p25-xn85w68vyevt} (Generic.Bot.H) -> Delete on reboot.

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hkcu (Trojan.VirTool) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\policies (Trojan.VirTool) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hklm (Trojan.VirTool) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\policies (Trojan.VirTool) -> Delete on reboot.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system32\Winlog\Winlogon.exe (Generic.Bot.H) -> Delete on reboot.

C:\Documents and Settings\Linux\Application Data\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.

C:\Documents and Settings\Linux\Desktop\Antivir.lnk (Rogue.Antivir2010) -> Quarantined and deleted successfully.

C:\Documents and Settings\Linux\Local Settings\Temp\XxX.xXx (Malware.Trace) -> Quarantined and deleted successfully.

ЕТО И СНИМКА ОТ ВИРУСИТЕ, КОИТО МИ ОТКРИ МАЛВАРЕБАЙТС - http://prikachi.com/images.php?images/168/2389168J.jpg

дадох "Remove Selected" сега ми иска рестарт и ще рестартирам!!!

Сега като ги изтрих ще имам ли проблеми с вируси или всичко се изтри???

Моля помогнете!

Благодаря!

Привет, nbs!

Ето какво следва:

Стъпка 1

  • Стартирайте отново MalwareBytes' Anti-Malware (MBAM), направете обновяване на дефинициите (Update) и изберете Quick Scan, след това натиснете бутона Scan (Сканиране).
  • Сканирането ще отнеме малко време, затова моля бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
  • Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Стъпка 2

Следвайте следната инструкция за работа с Security Check:

  • Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.
  • Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.
  • Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.
  • Копирайте съдържанието с Копирай (Copy) на checkup.txt и с Постави (Paste) го поставете в следващия си коментар.

Стъпка 3

Следвайте следната инструкция за работа с DDS:

  • Изтеглете DDS: от bleepingcomputer.
  • След изтегляне на файла го запишете (бутон Save -> Save as) DDS на вашия десктоп, снимка:
    2exprgh.jpg
  • След като изтеглите DDS на десктопа, иконката на програмата би трябвало да изглежда така: rvwlll.jpg
  • Прекратете временно работата на всички скрипт блокиращи приложения, ако има такива или разрешете изпълнението на dds.scr. След това стартирайте DDS с двоен клик на иконката, като потвърдите с Run.
  • След приключване на работата на DDS копирайте с Copy текста от двата файлови лога, които ще се появят в Notepad: DDS.txt и Attach.txt и ги запазете (бутон Save -> Save as) на десктопа. После прикачете двата лога към следващия си коментар по темата (погледнете опцията "прикачени файлове", когато публикувате мнение).

  • Автор

Мисля, че Малваребайтс премахна всичко в момента направих пак едно бързо сканиране с Авира и по чудо този път не ми откри никакви вируси и т.н. :whist: И сега не ми излиза онова прозорче.

ЕТО ЛОГА ОТ "Security Check"(checkup.txt) - Results of screen317's Security Check version 0.99.5

Windows XP Service Pack 2

Out of date service pack!!

Internet Explorer 6 Out of date!

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

Avira AntiVir Personal - Free Antivirus

Antivirus out of date!

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Adobe Flash Player 10.0.45.2

Mozilla Firefox (3.6.8)

````````````````````````````````

Process Check:

objlist.exe by Laurent

Malwarebytes' Anti-Malware mbam.exe

Avira Antivir avgnt.exe

Avira Antivir avguard.exe

````````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

____________________________________________________________________________

Ето лога от БЪРЗОТО СКАНИРАНЕ С МАЛВАРЕБАЙТС - Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4381

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

8/2/2010 8:57:17 PM

mbam-log-2010-08-02 (20-57-17).txt

Scan type: Quick scan

Objects scanned: 119320

Time elapsed: 49 minute(s), 35 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

_________________________________________________________________________

Ето лога и от DDS.txt - DDS (Ver_10-03-17.01) - NTFSx86

Run by Linux at 20:58:11.29 on Mon 08/02/2010

Internet Explorer: 6.0.2900.2180

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.60 [GMT 3:00]

AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\RunDll32.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\vssvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\Documents and Settings\Linux\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /install

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: {A6A3603C-E70C-4E0A-B4E7-46112A0B0B31} = 195.24.90.1

TCP: {E1AB9185-6C73-4CC5-98D3-3BAC0F0A03F9} = 195.24.89.8 195.24.90.1

SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\linux\applic~1\mozilla\firefox\profiles\ngmbqi4t.default\

FF - prefs.js: browser.startup.homepage - google.com

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-5-13 11608]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-5-13 135336]

R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-5-13 267432]

R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-5-13 60936]

R3 PAC7311;VGA SoC PC-Camer@;c:\windows\system32\drivers\PA707UCM.SYS [2005-2-16 144768]

S3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\drivers\SIVX32.sys [2010-8-1 67264]

=============== Created Last 30 ================

2010-08-02 15:46:48 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-02 15:46:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-02 15:46:37 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-08-02 08:46:33 1583 ----a-w- c:\windows\system0.ini

2010-08-02 08:46:32 713728 ----a-w- c:\windows\system32\opengl30.dll

2010-08-02 08:07:25 58403 ----a-w- c:\docume~1\linux\applic~1\SQLite3.dll

2010-08-01 18:28:42 67264 ----a-w- c:\windows\system32\drivers\SIVX32.sys

2010-07-14 08:10:26 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com

2010-07-14 05:55:03 0 d-----w- c:\docume~1\linux\applic~1\Malwarebytes

2010-07-14 05:54:46 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-07-13 18:09:23 0 d-----w- c:\windows\system32\NtmsData

==================== Find3M ====================

2010-05-13 19:08:59 32768 ----a-w- c:\windows\system32\udaprop.dll

2010-05-13 19:08:59 118784 ----a-w- c:\windows\system32\cmuda.dll

2010-05-13 19:08:58 28672 ----a-w- c:\windows\system32\cmirmdrv.dll

2010-05-13 19:08:58 233472 ----a-w- c:\windows\system32\cmirmdrv.exe

2010-05-13 19:08:57 712704 ----a-w- c:\windows\system32\Audio3D.dll

2010-05-13 19:08:57 712704 ----a-w- c:\windows\system32\a3d.dll

2010-05-13 18:31:55 21640 ----a-w- c:\windows\system32\emptyregdb.dat

============= FINISH: 20:59:11.51 ===============

ЕТО И ЛОГА ОТ Attach.txt - UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 5/13/2010 9:41:01 PM

System Uptime: 8/2/2010 7:50:15 PM (1 hours ago)

Motherboard: | | nVidia-nForce

Processor: AMD Athlon XP | Socket A | 1243/100mhz

==== Disk Partitions =========================

A: is Removable

C: is FIXED (NTFS) - 10 GiB total, 4.98 GiB free.

D: is FIXED (NTFS) - 29 GiB total, 26.08 GiB free.

E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: NVIDIA nForce MCP Networking Controller

Device ID: PCI\VEN_10DE&DEV_0066&SUBSYS_1B311019&REV_A1\3&13C0B0C5&0&20

Manufacturer: Nvidia

Name: NVIDIA nForce MCP Networking Controller

PNP Device ID: PCI\VEN_10DE&DEV_0066&SUBSYS_1B311019&REV_A1\3&13C0B0C5&0&20

Service: NVENET

==== System Restore Points ===================

RP3: 7/15/2010 5:09:37 PM - System Checkpoint

RP4: 7/16/2010 5:48:19 PM - System Checkpoint

RP5: 7/26/2010 7:21:54 PM - System Checkpoint

RP6: 7/28/2010 12:22:35 PM - System Checkpoint

RP7: 7/29/2010 9:04:19 PM - System Checkpoint

RP8: 8/2/2010 11:59:56 AM - Removed Steam

RP9: 8/2/2010 12:02:04 PM - Installed Steam

==== Installed Programs ======================

µTorrent

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Avira AntiVir Personal - Free Antivirus

C-Media WDM Audio Driver

Counter-Strike

Counter-Strike: Condition Zero

Malwarebytes' Anti-Malware

Microsoft Application Error Reporting

Microsoft Choice Guard

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

mIRC

Mozilla Firefox (3.6.8)

MSVCRT

NVIDIA Drivers

NVIDIA nForce Drivers

PC VGA Camer@

Segoe UI

Skype™ 4.2

SopCast 3.2.9

Steam

VLC media player 1.1.2

WebFldrs XP

Winamp

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live Messenger

Windows Media Format Runtime

WinZip 14.5

==== Event Viewer Messages From Past Week ========

8/2/2010 5:46:26 PM, error: Service Control Manager [7031] - The Avira AntiVir Guard service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

8/2/2010 11:38:28 AM, error: DCOM [10009] - DCOM was unable to communicate with the computer L using any of the configured protocols.

7/27/2010 4:17:54 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.

==== End Of File ===========================

Имам ли някакви повреди/опасности на PC-то, сигурен съм, че можете да ми дадете точен и 100% верен отговор!

Редактирано от nbs (преглед на промените)

Преди да продължим имам няколко въпроса:

1. Каква е причината да използвате Service Pack 2 за Windows XP? Преди около месец Windows XP SP2 беше спрян от поддръжка. Много отдавна има Service Pack 3 за Windows XP. Рискувате много от гледна точка на сигурността, защото нямате възможност да обновявате системата си с необходимите кръпки...

2. Сега има ли проблем с обновяването на Avira? Пробвайте да обновите програмата и пишете дали има резултат.

  • Автор

Нищо не разбирам под обновяването, но в момента Авира не ми прави никви проблеми и не ми дава ония вирус... Тотално изчезна май... :whist:

А да попитам от каде се трие Хижак, защото не видях в Add/Remove programs(control panel), а ми показа че се инстална някаде в C:, а не намерих нищо там за Хижак...??? Всичко изтрих само Хижак не мога да намеря, за да я изтрия...

Моля за помощ!

Би трябвало HijackThis да се намира ето тук:

C:\Documents and Settings\Linux\My Documents\HijackThis.exe

Опитайте да изтриете файла.

Сега има ли някакви други проблеми с Windows?

  • Автор

Аз от там изтрих едно имаше червено човече с лупа... Ако е само това цялата програмата, значи всичко е ок!

Обаче тази сутрин след като пуснах компютъра, забелязах, че е доста ама доста бавен и като погледнах процесите там имаше един процес дето се вдига до 150,000 К и дори в момента пиша трудно, до сега нямах такъв проблем и съм сигурен, че това е от вируса! Като спра този процес компютъра леко се оправя, но ми изчезват часовника и спира интернета. Качил снимка, обаче там е до 95,000 К, защото не снимах когато се вдигна до 150,000 К

http://prikachi.com/images.php?images/994/2390994m.jpg

Постоянно отдолу ми показва това (ВЕЧЕ НЕ ГО ПОКАЗВА) - http://prikachi.com/images.php?images/992/2390992u.jpg

Не разбирам ето това какво е - http://prikachi.com/images.php?images/12/2391012c.jpg (ПРЕДИ НЯМАХ ТАКЪВ ПРОЦЕС) !!!

СЕГА ТОЗИ СЪЩИЯ ПРОЦЕС ДЕТО СЕ ВДИГАШЕ ДО 150,000 седи на около 25,000-65 000 K(90 000 К)!

ПРЕДИ МАЛКО МИ ИЗЛЕЗЕ ТОВА - http://prikachi.com/images.php?images/29/2391029v.jpg - БЕЗ ДА ДОКОСНА НИЩО!!!

ЯВНО ТОВА Е ТОЗИ ПРОЦЕС... update

Редактирано от nbs (преглед на промените)

Зададох един въпрос в коментар 4 от темата, на който все още нямам отговор. В момента аз нямам понятие дали използвате нелицензиран (пиратски) Windows XP, на който никога не са включвани обновявания (Update). Явно наистина нямате никакво понятие какво представляват сервизните пакети и Update (Обновяване) за операционната система Windows. Изчакайте Windows да се обнови, рестартирайте и пишете дали има проблеми. Ако имате някакви зарази, които са открити от Avira, пишете.

За "Virtual memory minimum too low" можете да погледнете тази тема.

Моля да престанете да пишете с главни букви! Съобразявайте се с правилата на форума. Прочетете ето това:

2.1 Писането на български език с кирилица е задължително. Теми и съобщения, написани на латиница, само с главни букви или със заместени символи вместо Ч-4, Ш-6 и т.н. се изтриват без предупреждение.

Редактирано от nologo (преглед на промените)

  • Автор

Еми виж сега, аз до сега такъв проблем нямах, този вирус го изчистих и тази сутрин като пуснах компютъра беше толкова бавен (и сега е така, трудно пиша :@) явно проблема е от вируса и има нещо останало или не знам... Или е от уиндолс-а??? Преди малко качих снимка на упдейта, рестартирах комп-а, Авира не ми откри никакви вируси, но комп-а продалжава да си зарежда много и е доста бавен! Гледам в процесите този процес дето се вдигаше до 150,000 К сега седи на 25,000-30 000 К и мисля, че това е нормалното, но има друг процес "wuauclt.exe" не знам за какво, но до сега май не беше толкова (30,000 К). Може и това да е нормално, не знам. Ей сега ще направя едно сканиране с Avira на "My Documents", за да видя дали пак ще хвани този вирус с това име или нещо друго... :)

Процесите в момента, мисля че са нормализирани, но компютъра си е все така бавен. Аз съм сигурен, че това е от този проклет вирус и още има някакви остатъци!

Редактирано от nbs (преглед на промените)

Следвайте следните стъпки за работа с ComboFix:

1. Изтеглете ComboFix от следните миръри: от BleepingComputer или от ForoSpyware.

След изтегляне на файла го запишете (бутон Save -> Save as) ComboFix на вашия десктоп, снимка:

2exprgh.jpg

След като изтеглите ComboFix на десктопа, иконката на програмата би трябвало да изглежда така:

29eqjuq.jpg

2. Затворете всички работещи приложения или отворени прозорци. Прекратете временно работата на антивирусната програма и на други програми за сигурност, ако има такива. За целта може да прегледате информацията от този линк: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs.

3. Преименувайте ComboFix.exe на ff2.exe

4. Стартирайте с двоен клик ff2.exe. За целта използвайте YES, за да се съгласите с условията за използване на програмата. Важно: след като се стартира ComboFix не бива да се движи мишката или да се кликва върху отворения прозорец на програмата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

5. След като приключи сканирането на регистрите (Windows Registry) ComboFix ще провери дали има инсталирана Windows Recovery Console.

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console, виж снимката:

33wr6us.jpg

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

m9lvnk.jpg

6. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката, моля да прочетете това: Manually restoring the Internet connection section.

Забележка: При проблеми с ComboFix копирайте (Copy) и поставете (Paste) съдържанието на C:\BUG.txt в следващия си коментар.

7. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad, виж снимката:

157m978.jpg

Копирайте (Copy) и поставете (Paste) съдържанието на лога в следващия си коментар.

  • Автор

ComboFix 10-08-02.03 - Linux 08/03/2010 11:59:27.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.120 [GMT 3:00]

Running from: c:\documents and settings\Linux\Desktop\ff2.exe.exe

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Linux\Application Data\SQLite3.dll

.

((((((((((((((((((((((((( Files Created from 2010-07-03 to 2010-08-03 )))))))))))))))))))))))))))))))

.

2010-08-03 06:15 . 2010-08-03 06:15 -------- d-----w- c:\program files\MSXML 4.0

2010-08-02 21:49 . 2008-07-09 07:38 26488 ----a-w- c:\windows\system32\spupdsvc.exe

2010-08-02 21:49 . 2010-08-03 08:01 -------- d--h--w- c:\windows\$hf_mig$

2010-08-02 13:00 . 2010-08-02 13:03 -------- d-----w- c:\documents and settings\Linux\Application Data\vlc

2010-08-02 09:25 . 2009-02-06 17:22 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe

2010-08-02 09:25 . 2009-02-06 17:24 2180480 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe

2010-08-02 09:25 . 2009-02-06 16:49 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe

2010-08-02 09:25 . 2009-02-06 16:49 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe

2010-08-02 09:12 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

2010-08-02 08:46 . 2004-08-04 12:00 713728 ----a-w- c:\windows\system32\opengl30.dll

2010-08-01 18:28 . 2010-07-14 04:40 67264 ----a-w- c:\windows\system32\drivers\SIVX32.sys

2010-07-27 19:09 . 2010-07-27 19:09 -------- d-----w- c:\documents and settings\Linux\Application Data\dvdcss

2010-07-14 12:14 . 2010-07-14 12:14 -------- d-----w- c:\documents and settings\Linux\Application Data\Media Player Classic

2010-07-14 08:10 . 2010-07-14 08:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-07-14 05:55 . 2010-07-14 05:55 -------- d-----w- c:\documents and settings\Linux\Application Data\Malwarebytes

2010-07-14 05:54 . 2010-07-14 05:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-07-13 18:09 . 2010-08-03 08:27 -------- d-----w- c:\windows\system32\NtmsData

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-03 06:32 . 2010-05-13 19:39 -------- d-----w- c:\documents and settings\Linux\Application Data\Skype

2010-08-02 14:00 . 2010-08-02 14:01 1364347 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aescript.dll

2010-08-02 14:00 . 2010-08-02 14:01 106868 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aevdf.dll

2010-08-02 14:00 . 2010-08-02 14:01 471414 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aepack.dll

2010-08-02 14:00 . 2010-08-02 14:01 2830711 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aeheur.dll

2010-08-02 14:00 . 2010-08-02 14:01 393589 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aegen.dll

2010-08-02 12:59 . 2010-05-13 19:41 -------- d-----w- c:\program files\VideoLAN

2010-08-02 09:07 . 2010-05-13 19:30 -------- d-----w- c:\documents and settings\Linux\Application Data\uTorrent

2010-08-02 08:33 . 2010-05-13 18:45 13304 ----a-w- c:\documents and settings\Linux\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-07-28 20:25 . 2010-08-02 14:01 614772 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aerdl.dll

2010-07-28 20:25 . 2010-08-02 14:01 201081 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aeoffice.dll

2010-07-28 20:25 . 2010-08-02 14:01 242039 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aehelp.dll

2010-07-28 20:25 . 2010-08-02 14:01 192887 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aecore.dll

2010-07-22 10:50 . 2010-05-14 07:39 -------- d-----w- c:\documents and settings\Linux\Application Data\mIRC

2010-07-22 10:46 . 2010-05-14 07:39 -------- d---a-w- c:\program files\mIRC

2010-06-14 14:30 . 2010-05-13 18:32 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-05-14 08:19 . 2010-05-13 18:35 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2010-05-13 19:59 . 2010-08-02 14:01 254324 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aesbx.dll

2010-05-13 19:59 . 2010-08-02 14:01 127347 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aescn.dll

2010-05-13 19:59 . 2010-08-02 14:01 393588 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aeemu.dll

2010-05-13 19:59 . 2010-08-02 14:01 53618 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\VALIDATION\aebb.dll

2010-05-13 19:51 . 2010-05-13 19:51 721904 ----a-w- c:\windows\system32\drivers\sptd.sys

2010-05-13 19:08 . 2003-11-06 12:59 755392 ----a-w- c:\windows\system32\drivers\cmuda.sys

2010-05-13 19:08 . 2003-11-03 17:22 118784 ----a-w- c:\windows\system32\cmuda.dll

2010-05-13 19:08 . 2003-04-24 10:29 32768 ----a-w- c:\windows\system32\udaprop.dll

2010-05-13 19:08 . 2003-08-20 15:46 233472 ----a-w- c:\windows\system32\cmirmdrv.exe

2010-05-13 19:08 . 2003-02-18 15:26 28672 ----a-w- c:\windows\system32\cmirmdrv.dll

2010-05-13 19:08 . 2001-11-23 09:08 712704 ----a-w- c:\windows\system32\Audio3D.dll

2010-05-13 19:08 . 2001-11-23 09:08 712704 ----a-w- c:\windows\system32\a3d.dll

2010-05-13 18:55 . 2010-05-13 18:55 0 ----a-w- c:\windows\nsreg.dat

2010-05-13 18:31 . 2010-05-13 18:31 21640 ----a-w- c:\windows\system32\emptyregdb.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]

"nwiz"="nwiz.exe" [2008-05-03 1630208]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Documents and Settings\\Linux\\My Documents\\blubVolley\\blubVolley.exe"=

"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\SopCast\\SopCast.exe"=

"d:\\Games\\Steam\\Steam.exe"=

"d:\\Games\\Steam\\steamapps\\nbs_levent\\condition zero\\hl.exe"=

"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"d:\\Games\\Steam\\steamapps\\nbs_levent\\counter-strike\\hl.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/13/2010 10:57 PM 135336]

R3 PAC7311;VGA SoC PC-Camer@;c:\windows\system32\drivers\PA707UCM.SYS [2/16/2005 9:15 AM 144768]

S3 SIVDRIVER;SIV Kernel Driver;c:\windows\system32\drivers\SIVX32.sys [8/1/2010 9:28 PM 67264]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/13/2010 10:51 PM 721904]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://google.com/

TCP: {A6A3603C-E70C-4E0A-B4E7-46112A0B0B31} = 195.24.90.1

TCP: {E1AB9185-6C73-4CC5-98D3-3BAC0F0A03F9} = 195.24.89.8 195.24.90.1

FF - ProfilePath - c:\documents and settings\Linux\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\

FF - prefs.js: browser.startup.homepage - google.com

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-03 12:04

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2010-08-03 12:06:53

ComboFix-quarantined-files.txt 2010-08-03 09:06

Pre-Run: 5,644,034,048 bytes free

Post-Run: 5,614,030,848 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 05247AABDD5D85BE4EA05084EC7E9381

Не знам дали ще ти помогне, но ми изписа това когато зареждаше - Deleting files: c:\documents and settings\Linux\Application Data\SQLite3.dll

Сега мога ли да изтрия тази програма??? Защото го направих! :rolleyes:

Ето сега мисля, че положението се нормализира, гледам процесите и ония процес дето беше 150,000 К сега е 5,000 К и това ме зарадва!

Това пак ли е от тази програма - http://prikachi.com/images.php?images/358/2391358D.jpg - защото не помня дали имах нещо такова в Адд/Ремоув ???

Редактирано от nbs (преглед на промените)

Това е някакъв WDM драйвер нa C-Media. Вижте дали има в проблеми с хардуера в Device Manager.

Нека все пак да направим една проверка, която става доста лесно:

Следвайте следната инструкция за работа с RKUnHooker:

  • Изтеглете този файл на десктопа.
  • Стартирайте RKUnhookerLE.exe, отидете на Report и маркирайте Drivers, Stealth Code, Files и Code Hooks. Демаркирайте останалите и натиснете ОК. Снимка:
    1eb6cc90177042cd.png
  • Изчакайте програмата да завърши работа. След това кликнете на File, после Save Report. Запазете (Save as) файла с име report.txt на десктопа. Прикачете го в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение).

  • Автор

Това пак ли е от тази програма - http://prikachi.com/images.php?images/358/2391358D.jpg - защото не помня дали имах нещо такова в Адд/Ремоув (От тегленията на ComboFix и т.н.)??? (Не получих отговор на това)

Редактирано от nbs (преглед на промените)

ComboFix няма как да инсталира драйвер на C-Media. Може ли да прочетете внимателно това, което съм написал по-горе за Device Manager? Имате ли представа какъв хардуер използвате? Инсталирани ли са всички драйвери? Има ли проблем (въпросителни или ?) в Device Manager?

  • Автор

Пич толкова малко разбирам от компютри, че дори не знам за какво ми говориш. Всичко свързано с комп-а го оправя брата, така че няма смисъл да ме питаш, значи няма да го трия това на снимката! Сега чакам сканирането от тази програма дето ми даде, но не става толкова бързо както си казал :ph34r:.

***

Ето сега Авира без да правя нищо, хвана нещо като вирус, ето снимка - http://prikachi.com/images.php?images/404/2391404n.jpg - Чистя едното идва другото, какво по дяволите да правя вече не знам...

Ето още си седи е така тази програма - http://prikachi.com/images.php?images/410/2391410v.jpg

nologo, колко още ще чакам??? От както ти ми каза го направих и още чакам да сканира C:, ако изобщо сканира??? В момента е още така както на снимката, дето съм дал :rolleyes:

Редактирано от nbs (преглед на промените)

По принцип този скан с RKUnHooker става бързо. Виж дали програмата не е спряла да работи (Not responding) в Task Manager. Aко работи - имай търпение, изчакай още малко.

  • Автор

Да, работи и преди малко започна зареждане на C:

Но не ми отговори на това, защо отново Авира ми откри вирус??? Виж предната снимка на коментара ми

Редактирано от nbs (преглед на промените)

  • Автор

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows XP

Version 5.1.2600 (Service Pack 2)

Number of processors #1

==============================================

>Drivers

==============================================

0xF8C2B000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 6557696 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 175.16 )

0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 6111232 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 175.16 )

0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2180480 bytes (Microsoft Corporation, NT Kernel & System)

0x804D7000 PnpManager 2180480 bytes

0x804D7000 RAW 2180480 bytes

0x804D7000 WMIxWDM 2180480 bytes

0xBF800000 Win32k 1839104 bytes

0xBF800000 C:\WINDOWS\System32\win32k.sys 1839104 bytes (Microsoft Corporation, Multi-User Win32 Driver)

0xF92B3000 C:\WINDOWS\system32\drivers\cmuda.sys 757760 bytes (C-Media Inc, C-Media Audio WDM Driver)

0xF98A0000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)

0xF77FE000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0xF78E3000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver)

0xF6D2D000 C:\WINDOWS\system32\DRIVERS\srv.sys 339968 bytes (Microsoft Corporation, Server driver)

0xF69CA000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)

0xF8B5E000 C:\WINDOWS\system32\DRIVERS\update.sys 212992 bytes (Microsoft Corporation, Update Driver)

0xF8B92000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 200704 bytes (Microsoft Corporation, Microsoft RDP Device redirector)

0xF99E3000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)

0xF6E98000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0xF9873000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)

0xF786D000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 180224 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0xF6798000 C:\WINDOWS\system32\drivers\kmixer.sys 172032 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)

0xF78BB000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)

0xF998D000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)

0xF776F000 C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS 147456 bytes (PixArt Imaging Inc., PA707UCM)

0xF928F000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0xF926C000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)

0xF936C000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0xF7899000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0xF77BB000 C:\WINDOWS\system32\DRIVERS\avipbb.sys 139264 bytes (Avira GmbH, Avira Driver for Security Enhancement)

0xF77DD000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator)

0x806EC000 ACPI_HAL 131968 bytes

0x806EC000 C:\WINDOWS\system32\hal.dll 131968 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0xF9956000 fltMgr.sys 126976 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0xF99B3000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)

0xF9858000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0xF9975000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)

0xF7757000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes

0xF992D000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0xF8BD4000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0xF73B7000 C:\WINDOWS\system32\DRIVERS\avgntflt.sys 86016 bytes (Avira GmbH, Avira Minifilter Driver)

0xF7082000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)

0xF8C03000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)

0xF8C17000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)

0xF793B000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)

0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)

0xF9944000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)

0xF99D2000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)

0xF8BC3000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)

0xF9C82000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)

0xF9B72000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)

0xF9B32000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0xF9B62000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)

0xF7227000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)

0xF9C02000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)

0xF9B52000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0xF9A72000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)

0xF9B82000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)

0xF9B92000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0xF9A52000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)

0xF9BB2000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0xF9C72000 C:\WINDOWS\system32\DRIVERS\STREAM.SYS 49152 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0)

0xF9B42000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)

0xF9A42000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)

0xF9BA2000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0xF9B22000 C:\WINDOWS\system32\DRIVERS\amdk7.sys 40960 bytes (Microsoft Corporation, Processor Device Driver)

0xF9BF2000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)

0xF9A82000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0xF9BE2000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)

0xF9A62000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)

0xF9C42000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver)

0xF9CA2000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library)

0xF9A32000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver)

0xF9BC2000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)

0xF9C32000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)

0xF7357000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0xF9C52000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xF9CFA000 C:\DOCUME~1\Linux\LOCALS~1\Temp\catchme.sys 32768 bytes

0xF9D8A000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)

0xF9DAA000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)

0xF9D2A000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver)

0xF9D72000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0xF9CB2000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0xF9D1A000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0xF9D52000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)

0xF9CF2000 C:\DOCUME~1\Linux\LOCALS~1\Temp\mbr.sys 24576 bytes

0xF9D32000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)

0xF9D22000 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 24576 bytes (Realtek Semiconductor Corporation, Realtek RTL8139 NDIS 5.0 Driver)

0xF9D92000 C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 24576 bytes (Avira GmbH, AVIRA SnapShot Driver)

0xF9D7A000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0xF9D62000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver)

0xF9D82000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)

0xF9CC2000 nv_agp.sys 20480 bytes (NVIDIA Corporation, NVIDIA nForce AGP Filter)

0xF9CBA000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)

0xF9D42000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)

0xF9D4A000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)

0xF9D3A000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)

0xF9D12000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver)

0xF9DBA000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)

0xF9EC6000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver)

0xF9EF2000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)

0xF73D0000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)

0xF9ED2000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)

0xF9E42000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)

0xF8B46000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)

0xF9EC2000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)

0xF9ED6000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0xF93B3000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0xF9F52000 C:\Program Files\Avira\AntiVir Desktop\avgio.sys 8192 bytes (Avira GmbH, Avira AntiVir Support for Minifilter)

0xF9F4A000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)

0xF9F36000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)

0xF9F5A000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes

0xF9F48000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)

0xF9F32000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0xF9F4C000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)

0xF9FBE000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver)

0xF9FA6000 C:\WINDOWS\system32\Drivers\PROCEXP113.SYS 8192 bytes

0xF9F4E000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)

0xF9F44000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0xF9F46000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)

0xF9F34000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0xFA059000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)

0xFA01A000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)

0xFA133000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)

0xF9FFA000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)

==============================================

>Stealth

==============================================

==============================================

>Files

==============================================

!-->[Hidden] C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\LOGFILES\AVSCAN-20100803-124248-9D8E5801.LOG

!-->[Hidden] C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\REPORTS\4935dba7.avl

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\0094E3F2d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\02B35F36d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\061A2CD1d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\06D33B4Ed01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\07E77B6Bd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\08DE3DCCd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\09001498d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\0B6F0ACEd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\109813E0d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\1462A9CFd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\1689B2A5d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\1EC5E551d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\22B7FDB4d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\2597C10Dd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\286B9B2Fd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\2CEB4CA8d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\3118850Dd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\362F04FDd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\3775B5A6d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\3EC5A807d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\421B77ADd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\4A443B1Fd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\4B1BE828d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\4EAF6466d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\51E7BA5Dd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\534AF584d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\59D982C6d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\5C61C63Dd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\63A300B2d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\65B0BDDAd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\692CE752d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\6D198F6Cd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\6D53AAA4d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\6E0EC829d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\704E2C00d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\72421098d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\77969484d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\825A5D42d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\84A0FE74d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\8B3B02F4d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\910A0FC3d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\942595DCd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\94A5B3F8d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\9700A3D4d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\9A4A39C1d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\9ABC9207d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\A2F50D20d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\A4CE71DAd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\A55B0AA0d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\AA010E9Dd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\AC7FEFE3d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\AC982D44d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\BA6F6D58d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\BA8FD208d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\BBB48141d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\BE8FD281d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\BEA08340d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\CA45B4B7d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\D0F48D63d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\D5505997d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\DAB2F3DBd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\DCA6F4DCd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\DFB6E248d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\E14CE592d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\E29A88A7d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\E45C8223d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\E6A0BA59d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\E87EB4D1d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\E90A862Ad01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\EEDA1333d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\EF5A4389d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\EF5D8399d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\EF92746Fd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\F58585A1d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\F90750B1d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\FB4AA5EDd01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\FD0006D4d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\FD709233d01

!-->[Hidden] C:\Documents and Settings\Linux\Local Settings\Application Data\Mozilla\Firefox\Profiles\ngmbqi4t.default\Cache\FE21F489d01

!-->[Hidden] C:\RECYCLER\S-1-5-21-789336058-1972579041-682003330-1003\Dc10.JPG

==============================================

>Hooks

==============================================

ntoskrnl.exe+0x00004AA2, Type: Inline - RelativeJump 0x804DBAA2-->804DBAA9 [ntoskrnl.exe]

ntoskrnl.exe-->ExAllocatePool, Type: Inline - RelativeJump 0x8050ED8E-->F7357525 [Normandy.SYS]

ntoskrnl.exe-->ExAllocatePoolWithTag, Type: Inline - RelativeJump 0x8054ABC4-->F7357555 [Normandy.SYS]

ntoskrnl.exe-->IofCallDriver, Type: Address change 0x80552980-->F9CFCF84 [catchme.sys]

ntoskrnl.exe-->KeDelayExecutionThread, Type: Inline - RelativeJump 0x804DBF09-->F7357584 [Normandy.SYS]

ntoskrnl.exe-->NtSystemDebugControl, Type: Inline - RelativeJump 0x806484A7-->F735774B [Normandy.SYS]

[2224]firefox.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [firefox.exe]

[2692]plugin-container.exe-->user32.dll-->TrackPopupMenu, Type: Inline - RelativeJump 0x77D94F16-->00000000 [xul.dll]

[3532]RKUnhookerLE.EXE-->kernel32.dll-->CreateRemoteThread, Type: Inline - RelativeJump 0x7C810626-->00000000 [RKUnhookerLE.EXE]

[3532]RKUnhookerLE.EXE-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [RKUnhookerLE.EXE]

Какво да цъкна сега - http://prikachi.com/images.php?images/547/2391547c.jpg - ??? (Дадох "Затвори")

Редактирано от nbs (преглед на промените)

Да, Close. Следва:

Следвайте следната инструкция за работа с OTL:

  • Изтеглете OTL.exe (или OTL.scr) и го запазете на десктопа.
  • Стартирайте файла otlDesktopIcon.png с двукратен клик на мишката.
  • Направете следните настройки:

33wm6o2.jpg

  • Под "Custom Scans/Fixes" с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):


netsvcs

drivers32 /all

%SYSTEMDRIVE%\*.*

%systemroot%\Fonts\*.com

%systemroot%\Fonts\*.dll

%systemroot%\Fonts\*.ini

%systemroot%\Fonts\*.ini2

%systemroot%\*.scr

%systemroot%\*._sy

%systemroot%\REPAIR\*.bak1

%systemroot%\REPAIR\*.ini

%systemroot%\system32\*.wt

%systemroot%\system32\*.ruy

%systemroot%\system32\*.jpg

%systemroot%\system32\spool\prtprocs\w32x86\*.*

%APPDATA%\Update\*.*

%APPDATA%\Microsoft\*.*

%APPDATA%\Adobe\Update\*.*

%ALLUSERSPROFILE%\Favorites\*.*

%PROGRAMFILES%\*.*

%systemroot%\*. /mp /s

CREATERESTOREPOINT

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\System32\config\*.sav

%systemroot%\system32\user32.dll /md5

%systemroot%\system32\ws2_32.dll /md5

%systemroot%\system32\ws2help.dll /md5

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Натиснете маркираният в синьо бутон: 30rn2na.jpg.
  • Имайте търпение и изчакайте програмата да свърши сканирането. След като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt.
  • Прикачете в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение) логовете от OTL: OTL.Txt, Extras.Txt.

По-горе пуснах скрипт, който се намира в полето, което е очертано в коментара. Трябва да маркираш текста, да го копираш (Copy) и след това да го поставиш (Paste) под надписа Custom Scans/Fixes. Под този надпис има едно празно поле. На снимката по-горе е показано как става. Но не прави нищо, няма никакъв смисъл.

Виждам, че не може да се справиш с повечето инструкции по темата. Съжалявам, в този случай не мога да помогна.

Приятен ден и успех!

P.S. Деинсталирай OTL, ето как:

Стартирай OTL.exe още веднъж и натисни бутона CleanUp!

35hfp21.jpg

При дeинсталацията на OTL ще бъдат почистени инструменти и файлове, които използвахме в темата. Ще последва рестарт на Windows. След това може да деинсталираш (ако има такива програми) или направо да изтриеш останалите файлове и инструменти, ако има остатъци.

Редактирано от nologo (преглед на промените)

  • Автор

не разбрах сега, имам ли вируси или нЕ?

Нямаш вируси. Но имаш проблеми с други зарази. Ако се стегнеш и четеш внимателно какво пише в инструкциите, после няма да имаш проблем да ги изпълниш. Може да ми напишеш лично съобщение при проблем с някоя инструкция, за да не пълним темата с глупости.

Гост
Тази тема е заключена за нови отговори.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.