Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Снощи ме заразиха по скайпа [РЕШЕН]

Featured Replies

Здравейте снощи получих съобщение по скайп след като кликнах на него ми се отвори фаил за сваляне свалих го стартирах го и се заразих вече и моя скайп праща сам съобщения които садаржат вредоносния линк.Това ми е компютара http://valid.canardp...php?id=1333644. ето и какво засече нода-----> 8/6/2010 02:19:36 Защитатата на файловата система в реално време файл C:\ssA1234567890.exe вариант на Win32/Oficla.HZ троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие с нов файл, създаден от приложението: C:\WINDOWS\jusched.exe.

8/6/2010 02:19:36 Защитатата на файловата система в реално време файл C:\Documents and Settings\Ghost\Local Settings\Temporary Internet Files\Content.IE5\8H5ZHKME\decc[1] вариант на Win32/Oficla.HZ троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие с нов файл, създаден от приложението: C:\WINDOWS\jusched.exe.

8/6/2010 02:19:20 HTTP филтър файл http://rs676l33.rapi...39447/decc.html вариант на Win32/Oficla.HZ троянски кон връзката е прекъсната - под карантина GANGOSAN-9708CA\Ghost

8/5/2010 23:32:51 Защитатата на файловата система в реално време файл C:\DOCUME~1\Ghost\LOCALS~1\Temp\11B.tmp вариант на Win32/Oficla.HE троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие при файл, модифициран от приложението: C:\sssA1234567890.exe.

8/5/2010 23:23:07 Защитатата на файловата система в реално време файл C:\DOCUME~1\Ghost\LOCALS~1\Temp\C4.tmp вариант на Win32/Oficla.HE троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие при файл, модифициран от приложението: C:\sssA1234567890.exe. Уж го истри и го сложи под карантина но уви пак ми забива компа за 2 секунди флекс тайпа ми се сменя оф не знам ще си пусна хиренс боот сиди да видим много ме тормози това и със Екстерминате ит пускам 1 скан сега помощ!!!

Редактирано от nologo (преглед на промените)

Към Gangosa: Моля, изпълнявайте инструкциите, дадени от asdfag

Към другите: asdfag има разрешение да дава инструкции по темата, независимо, че не е член на HJT Team. Естествено, всичко е под контрол. Благодаря за разбирането и моля да ни извините за недоразумението. Изключението се отнася само за тази тема.

  • Автор

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Версия на базата от данни: 4397

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

8/5/2010 11:13:17

mbam-log-2010-08-05 (11-13-17).txt

Тип сканиране: Пълно сканиране (C:\|D:\|)

Сканирани обекти: 227592

Изминало време: 28 минута(и), 41 секунда(и)

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 0

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 4

Заразени процеси в паметта:

(Не бяха открити зловредни обекти)

Заразени модули в паметта:

(Не бяха открити зловредни обекти)

Заразени ключове в регистратурата:

(Не бяха открити зловредни обекти)

Заразени стойности в регистратурата:

(Не бяха открити зловредни обекти)

Заразени информационни обекти в регистратурата:

(Не бяха открити зловредни обекти)

Заразени папки:

(Не бяха открити зловредни обекти)

Заразени файлове:

C:\Documents and Settings\Ghost\Local Settings\Temporary Internet Files\Content.IE5\FST0VCSR\d[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Program Files\Driver-Soft\DriverGenius\Crack.exe (Trojan.Bancos) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{AA9F66D1-0F9F-4FAB-9A33-9E67E2E3D0D7}\RP196\A0028081.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

D:\Mirc\MIRC-KEYGEN\mIRC v6.34 6.31Patch.exe (Trojan.Bancos) -> Quarantined and deleted successfully.

иска да ресна сега и после ще пусна dds

  • Автор

DDS (Ver_10-03-17.01) - NTFSx86

Run by Ghost at 1:23:12,50 on петък 08/06/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1014.362 [GMT -7:00]

AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe

c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

C:\Program Files\Uniblue\DiskRescue\UBDiskRescueSrv.exe

C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

C:\WINDOWS\system32\wuauclt.exe

svchost.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Program Files\Unlocker\UnlockerAssistant.exe

C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\USBScan\USBScan.exe

C:\Program Files\Common Files\Corel\Standby\Standby.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Program Files\Internet Download Manager\IDMan.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\Datecs\Flex2K.exe

C:\Program Files\Internet Download Manager\IEMonitor.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\SeaMonkey\seamonkey.exe

C:\Documents and Settings\Ghost\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.bing.com/?pc=AVBR

uStart Page = hxxp://i24search.com

uWindow Title = >>> 'Full Speed' Enabled <<<

uInternet Settings,ProxyServer = http=

BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll

BHO: {2a646672-9c3a-4c28-9a7a-1fb0f63f28b6} - IE 4.x-6.x BHO for Internet Download Accelerator

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL

BHO: Ask Toolbar BHO: {d4027c7f-154a-4066-a1ad-4243d8127440} - Ask Toolbar

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\webscout toolbar\tbcore3.dll

TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} -

TB: IDA Bar: {c70e30c7-140a-4166-a2e8-43557e62b41a} -

TB: WebScout Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\webscout toolbar\tbcore3.dll

uRun: [iDMan] c:\program files\internet download manager\IDMan.exe /onboot

uRun: [swhst] c:\documents and settings\ghost\application data\bc\swhst.exe

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [unlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"

mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"

mRun: [uSBScan.exe] c:\program files\usbscan\USBScan.exe -Hide

mRun: [standby] "c:\program files\common files\corel\standby\Standby.exe" -START

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [bsf] "bsf.exe"

mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\flexty~1.lnk - c:\windows\datecs\Flex2K.exe

uPolicies-explorer: HideClock = 0 (0x0)

uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)

uPolicies-explorer: NoCommonGroups = 0 (0x0)

uPolicies-explorer: NoPrinters = 0 (0x0)

uPolicies-explorer: NoRecentDocsNetHood = 0 (0x0)

uPolicies-explorer: NoChangeAnimation = 0 (0x0)

uPolicies-explorer: NoThemesTab = 0 (0x0)

uPolicies-system: NoSecCpl = 0 (0x0)

uPolicies-system: NoDispAppearancePage = 0 (0x0)

uPolicies-system: NoDispSettingsPage = 0 (0x0)

uPolicies-system: NoVisualStyleChoice = 0 (0x0)

IE: Download ALL with IDA

IE: Download remotely with IDA

IE: Download with IDA

IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105

IE: Свали видео съдържанието на FLV с IDM - c:\program files\internet download manager\IEGetVL.htm

IE: Свали всички линкове с IDM - c:\program files\internet download manager\IEGetAll.htm

IE: Свали с IDM - c:\program files\internet download manager\IEExt.htm

IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}

IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}

IE: {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll

LSP: c:\windows\system32\idmmbc.dll

DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab

DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab

DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: {C343B301-54AB-4781-B657-1DE663E4555B} = 217.79.67.30,217.79.79.79

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL

Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll

Notify: igfxcui - igfxdev.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL

LSA: Authentication Packages = msv1_0 nwprovau

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ghost\applic~1\mozilla\firefox\profiles\6xslnlzt.default\

FF - prefs.js: network.proxy.type - 0

FF - component: c:\documents and settings\ghost\application data\idm\idmmzcc3\components\idmmzcc.dll

FF - component: c:\documents and settings\ghost\application data\mozilla\firefox\profiles\6xslnlzt.default\extensions\[email protected]\components\FFHst.dll

FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-12-18 108792]

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-2-4 96408]

R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2010-2-4 735960]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-8-5 304464]

R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2010-7-5 632792]

R2 pnpcap;Pure Networks Packet Capture Driver;c:\windows\system32\drivers\pnpcap.sys [2010-7-13 23344]

R2 Uniblue DiskRescue;Uniblue DiskRescue;c:\program files\uniblue\diskrescue\UBDiskRescueSrv.exe [2008-9-10 229648]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-8-5 20952]

S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]

S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-7-23 1691480]

S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-7-26 23456]

S3 ExterminateIt;ExterminateIt;c:\windows\system32\drivers\extit.sys [2010-8-5 22016]

S3 H0jf5I;H0jf5I;c:\docume~1\ghost\locals~1\temp\pcwizard\data\pcwizntl.exe -s --> c:\docume~1\ghost\locals~1\temp\pcwizard\data\pcwizntl.exe -s [?]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]

S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]

S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]

S3 UAsaCK;UAsaCK;c:\docume~1\ghost\locals~1\temp\pcwizard\data\pcwizntl.exe -s --> c:\docume~1\ghost\locals~1\temp\pcwizard\data\pcwizntl.exe -s [?]

============== File Associations ===============

.txt=speakingtxtfile

=============== Created Last 30 ================

2010-08-06 10:45:37 0 d-----w- c:\program files\Alex Feinman

2010-08-06 08:10:25 0 d-----w- c:\program files\EASEUS

2010-08-05 17:33:32 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-05 17:33:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-05 17:33:30 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-08-05 17:31:32 22016 ----a-w- c:\windows\system32\drivers\extit.sys

2010-08-05 07:37:54 0 d-----w- c:\docume~1\ghost\applic~1\Capture

2010-08-03 11:30:23 0 d-----w- c:\docume~1\ghost\applic~1\ChessRally 2

2010-08-03 11:29:54 0 d-----w- c:\docume~1\alluse~1\applic~1\ChessRally 2

2010-08-03 11:29:50 83672 ----a-w- c:\windows\system32\CSRAS32.OCX

2010-08-03 11:29:50 73728 ----a-w- c:\windows\system32\ImpulseWindowFlash.ocx

2010-08-03 11:29:50 69632 ----a-w- c:\windows\system32\ImpulseASM.dll

2010-08-03 11:29:50 6114 ----a-w- c:\windows\system32\SHELLLNK.TLB

2010-08-03 11:29:50 42192 ----a-w- c:\windows\system32\hitime32.ocx

2010-08-03 11:29:50 208896 ----a-w- c:\windows\system32\ImpulseMessageHook.ocx

2010-08-03 11:29:50 1536 ----a-w- c:\windows\system32\ISWin32.tlb

2010-08-03 11:29:50 1527808 ----a-w- c:\windows\system32\ImpulseGlobals.dll

2010-08-03 11:29:50 0 d-----w- c:\program files\Ingenuware

2010-08-03 11:28:03 0 d-----w- c:\windows\system32\URTTEMP

2010-08-03 08:57:41 0 d-----w- c:\program files\SopCast

2010-08-03 02:31:52 315347 ----a-w- C:\new_log.html

2010-08-03 02:28:17 212240 ----a-w- c:\windows\system32\Richtx32.ocx

2010-08-02 23:35:13 0 d-----w- c:\program files\VideoLAN

2010-08-02 22:43:31 0 d-----w- c:\program files\Readon Technology

2010-08-02 09:57:57 54156 ---ha-w- c:\windows\QTFont.qfn

2010-08-02 09:57:57 1409 ----a-w- c:\windows\QTFont.for

2010-08-02 08:58:38 0 d-----w- c:\program files\Driver-Soft

2010-08-02 06:04:09 0 d-----w- c:\windows\Downloaded Program Files

2010-08-01 23:15:50 0 d-----w- c:\program files\Driver Cleaner Pro

2010-08-01 21:29:58 0 d-----w- c:\docume~1\ghost\applic~1\Malwarebytes

2010-08-01 21:29:50 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-08-01 12:01:29 0 d-----w- c:\program files\Daihinia

2010-07-27 05:02:22 80416 ----a-w- c:\windows\system32\RtNicProp32.dll

2010-07-27 05:02:22 100896 ----a-w- c:\windows\system32\RTNUninst32.dll

2010-07-27 04:12:08 0 d-----w- c:\program files\Wintoflash

2010-07-26 16:04:37 0 d-----w- c:\program files\Vstplugins

2010-07-26 16:04:32 0 d-----w- c:\program files\Sony

2010-07-26 16:04:08 0 d-----w- c:\program files\Sony Setup

2010-07-26 10:15:52 0 d-----w- c:\program files\Lavalys

2010-07-26 09:48:11 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys

2010-07-26 00:32:37 0 d-----w- c:\docume~1\ghost\applic~1\MozillaControl

2010-07-26 00:31:43 0 d-----w- c:\windows\'Full Speed' Internet Booster + Performance Tests

2010-07-26 00:31:42 0 d-----w- c:\program files\'Full Speed' Internet Booster + Performance Tests

2010-07-25 09:05:33 0 d-----w- c:\program files\SMS Free Sender

2010-07-23 12:33:10 0 d-----w- c:\windows\system32\RTCOM

2010-07-21 10:33:42 0 d-----w- C:\DriveKey

2010-07-21 10:11:42 0 d-----w- C:\WinSetupFromUSB

2010-07-19 12:24:19 0 d-----w- c:\docume~1\alluse~1\applic~1\GoodSync

2010-07-19 12:24:18 0 d-----w- c:\docume~1\ghost\applic~1\GoodSync

2010-07-19 12:17:19 0 d-----w- c:\docume~1\ghost\applic~1\Avant Profiles

2010-07-19 12:17:04 0 d-----w- c:\program files\Avant Browser

2010-07-18 23:49:11 88 --sh--r- c:\docume~1\alluse~1\applic~1\6C1EAF4D49.sys

2010-07-18 23:49:10 5018 --sha-w- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys

2010-07-18 21:47:47 0 d-----w- c:\program files\SmartSound Software

2010-07-18 21:47:46 0 d-----w- c:\docume~1\alluse~1\applic~1\SmartSound Software Inc

2010-07-18 21:47:31 0 d-----w- c:\windows\system32\windows media

2010-07-18 21:47:26 0 d-----w- c:\windows\RegisteredPackages

2010-07-18 21:47:14 0 d-----w- c:\docume~1\alluse~1\applic~1\InterVideo

2010-07-18 21:46:01 0 d-----w- c:\docume~1\alluse~1\applic~1\Corel

2010-07-18 21:42:54 0 d-----w- c:\program files\common files\Protexis

2010-07-18 21:42:11 0 d-----w- c:\program files\common files\Corel

2010-07-18 21:39:58 0 d-----w- c:\program files\Windows Media Components

2010-07-18 21:39:39 0 d-----w- c:\program files\common files\Ulead Systems

2010-07-18 21:39:15 0 d-----w- c:\program files\Corel

2010-07-18 21:37:31 0 d-----w- c:\windows\system32\XPSViewer

2010-07-18 21:36:27 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-07-18 21:36:27 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-07-18 21:36:27 117760 ------w- c:\windows\system32\prntvpt.dll

2010-07-18 21:36:26 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-07-18 21:36:26 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-07-18 21:36:26 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-07-18 21:36:26 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-07-18 11:41:58 0 d-----w- c:\windows\Performance

2010-07-17 12:49:21 0 d-----w- c:\docume~1\ghost\applic~1\RealHideIP

2010-07-17 12:49:21 0 d-----w- c:\docume~1\alluse~1\applic~1\RealHideIP

2010-07-17 10:10:19 0 d-----w- C:\Poker

2010-07-17 05:13:36 0 d-----w- c:\program files\RealHideIP

2010-07-17 00:49:31 0 d-----w- c:\program files\CarbonPoker

2010-07-15 00:07:18 0 d-----w- c:\program files\gps

2010-07-14 23:59:26 0 d-----w- c:\program files\WebEx

2010-07-14 23:59:00 25392 ----a-w- c:\windows\system32\drivers\pnarp.sys

2010-07-14 23:58:57 26672 ----a-w- c:\windows\system32\drivers\purendis.sys

2010-07-14 23:58:51 0 d-----w- c:\program files\common files\Pure Networks Shared

2010-07-14 22:51:37 770048 ----a-w- c:\windows\3D World Map.scr

2010-07-14 22:51:37 0 d-----w- c:\program files\Longgame

2010-07-14 22:28:28 73728 ----a-w- c:\windows\system32\javacpl.cpl

2010-07-14 22:28:28 411368 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-14 05:57:38 23344 ----a-w- c:\windows\system32\drivers\pnpcap.sys

2010-07-14 05:57:36 0 d-----w- c:\program files\Pure Networks

2010-07-14 05:56:21 0 d-----w- c:\docume~1\alluse~1\applic~1\Pure Networks

2010-07-13 21:56:07 0 d-----w- c:\docume~1\ghost\applic~1\YoWindow

2010-07-13 21:55:47 0 d-----w- c:\program files\YoWindow

2010-07-13 02:44:14 0 d-----w- c:\program files\Advanced IP Scanner

2010-07-12 12:11:22 0 d-----w- c:\docume~1\ghost\applic~1\Tao ExDOS

2010-07-12 12:10:31 6912 ---ha-w- c:\windows\system32\drivers\MSdo42H.SYS

2010-07-12 12:10:31 15872 ---ha-w- c:\windows\system32\TaoIMG.lib

2010-07-12 12:10:29 0 d--h--w- C:\~EXDSWAP

2010-07-12 12:09:33 0 d-----w- c:\documents and settings\all users\Tao

2010-07-12 05:36:00 94208 ----a-w- c:\windows\eSellerateControl365.dll

2010-07-12 05:36:00 360580 ----a-w- c:\windows\eSellerateEngine.dll

2010-07-12 00:02:04 0 d-----w- c:\program files\Conduit

2010-07-12 00:01:59 0 d-----w- c:\program files\EasyMP3Downloader

2010-07-11 21:40:39 0 d-----w- c:\docume~1\ghost\applic~1\EasyMP3Downloader

2010-07-11 21:40:39 0 d-----w- c:\docume~1\alluse~1\applic~1\EasyMP3Downloader

2010-07-11 19:51:48 0 d-----w- c:\docume~1\ghost\applic~1\Helios

2010-07-11 18:55:40 0 d-----w- c:\documents and settings\all users\Microsoft

2010-07-11 18:52:27 0 d-----w- c:\program files\Microsoft Analysis Services

2010-07-11 18:50:22 0 d-----w- c:\docume~1\ghost\applic~1\Bc

2010-07-11 12:11:32 0 d-----w- c:\windows\lhsp

2010-07-11 12:11:26 0 d-----w- c:\windows\speech

2010-07-11 12:11:23 0 d-----w- c:\program files\Speaking Notepad

2010-07-10 21:11:18 83 ----a-w- c:\windows\wwp.INI

2010-07-10 11:01:59 68292 ---ha-w- c:\windows\system32\mlfcache.dat

2010-07-10 10:55:16 0 d-----w- c:\docume~1\ghost\applic~1\mIRC

2010-07-09 23:59:15 3255 ----a-w- c:\windows\system32\wbem\Outlook_01cb1fc2bc8f4114.mof

2010-07-09 23:49:57 676224 ----a-w- c:\windows\system32\OGACheckControl.dll

2010-07-09 23:38:47 0 d-----w- c:\windows\SHELLNEW

2010-07-09 23:01:53 0 d-----w- c:\program files\Tao ExDOS

2010-07-08 17:57:35 0 d-----w- C:\team17

2010-07-08 08:53:01 0 d-----w- c:\windows\system32\NtmsData

2010-07-08 07:34:52 0 d-----w- c:\program files\Free ISO Creator

2010-07-08 07:30:23 40960 ----a-w- c:\windows\system32\VBAME.DLL

2010-07-07 20:57:00 61952 ----a-w- c:\windows\svhst.exe

==================== Find3M ====================

2010-07-07 01:27:06 84584 ----a-w- c:\windows\SOUNDMAN.EXE

2010-07-07 01:27:06 359016 ----a-w- c:\windows\vncutil.exe

2010-07-07 01:27:00 1833576 ----a-w- c:\windows\SkyTel.exe

2010-07-07 01:27:00 1489512 ----a-w- c:\windows\RtlUpd.exe

2010-07-07 01:26:54 9721960 ----a-w- c:\windows\RTLCPL.EXE

2010-07-07 01:26:54 6088296 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys

2010-07-07 01:26:48 53864 ----a-w- c:\windows\system32\RtkCoInstXP.dll

2010-07-07 01:26:48 129640 ----a-w- c:\windows\RtkAudioService.exe

2010-07-07 01:26:42 19556968 ----a-w- c:\windows\RTHDCPL.EXE

2010-07-07 01:26:36 2815592 ----a-w- c:\windows\ALCWZRD.EXE

2010-07-07 01:26:36 2180712 ----a-w- c:\windows\MicCal.exe

2010-07-07 01:26:30 64104 ----a-w- c:\windows\ALCMTR.EXE

2010-07-06 18:13:10 234392 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys

2010-07-06 16:38:59 74703 ----a-w- c:\windows\system32\mfc45.dll

2010-06-24 18:13:10 1251944 ----a-w- c:\windows\RtlExUpd.dll

2010-06-22 19:58:26 8 ----a-w- c:\docume~1\ghost\applic~1\pws.dll

2010-06-17 05:10:12 697328 ----a-w- c:\windows\system32\drivers\sptd.sys

2010-06-09 00:30:22 15664 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys

2010-06-09 00:30:22 109360 ----a-w- c:\windows\system32\GEARAspi.dll

2010-06-04 03:38:57 21640 ----a-w- c:\windows\system32\emptyregdb.dat

============= FINISH: 1:23:41,70 ===============

Изпълнете следните стъпки:

Стъпка 1

Пуснете отново MalwareBytes' Anti-Malware и направете бързо сканиране - Quick Scan. Ето как:

• Стартирайте програмата, направете обновяване на дефинициите (Update) и изберете Quick Scan, след това натиснете бутона "Сканиране" (Scan).

• Сканирането ще отнеме малко време, затова моля бъдете търпеливи.

• Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

• Уверете се, че на всички редове има отметки, и кликнете Remove Selected.

• Когато всичко бъде премахнато, логът ще бъде отворен в Notepad. Копирайте лога и го публикувайте в следващия си коментар в темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Стъпка 2

Следвайте следната инструкция за работа със Security Check:

• Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.

• Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.

• Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.

• Копирайте съдържанието с Копирай (Copy) на checkup.txt и с Постави (Paste) го поставете в следващия си коментар.

Редактирано от asdfag (преглед на промените)

  • Автор

хм прекалено дълаг е 2рия файл за това го прикачам Ето и 2рия лог

ЦИТАТ

Стъпка 2

Следвайте следната инструкция за работа със Security Check:

• Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.

• Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.

• Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.

• Копирайте съдържанието с Копирай (Copy) на checkup.txt и с Постави (Paste) го поставете в следващия си коментар.

ОТ КАДЕ ДА ГО ИСТЕГЛЯ

ОК ИЗВИНЯВАЙ сега ми се появи линка за довнлоад

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

8/6/2010 01:50:07

mbam-log-2010-08-06 (01-50-07).txt

Тип сканиране: Бързо сканиране

Сканирани обекти: 144285

Изминало време: 9 минута(и), 51 секунда(и)

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 0

Заразени стойности в регистратурата: 0

Заразени информационни обекти в регистратурата: 0

Заразени папки: 0

Заразени файлове: 0

Заразени процеси в паметта:

(Не бяха открити зловредни обекти)

Заразени модули в паметта:

(Не бяха открити зловредни обекти)

Заразени ключове в регистратурата:

(Не бяха открити зловредни обекти)

Заразени стойности в регистратурата:

(Не бяха открити зловредни обекти)

Заразени информационни обекти в регистратурата:

(Не бяха открити зловредни обекти)

Заразени папки:

(Не бяха открити зловредни обекти)

Заразени файлове:

(Не бяха открити зловредни обекти)

Results of screen317's Security Check version 0.99.5

Windows XP Service Pack 3

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

USB Virus Scan 2.3

Antivirus up to date! (On Access scanning disabled!)

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

DH Driver Cleaner Professional Edition

Java 6 Update 20

Out of date Java installed!

Adobe Flash Player 10.1.53.64

Mozilla Firefox (3.6.8)

````````````````````````````````

Process Check:

objlist.exe by Laurent

Malwarebytes' Anti-Malware mbamservice.exe

Malwarebytes' Anti-Malware mbamgui.exe

````````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

Аз продължавам по темата. По-горе бях написал нещо, но явно хората се дразнят, и то с право.

След малко ще напиша инструкции.

Стъпка 1

Следвайте следната инструкция за работа с OTL:

  • Изтеглете OTL.exe или OTL.scr го запазете на десктопа.
  • Стартирайте файла otlDesktopIcon.png с двукратен клик на мишката.
  • Направете следните настройки:

7518fd045e0fd482.png

  • Под c814d031472c0ac1.png с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):


netsvcs

drivers32 /all

%SYSTEMDRIVE%\*.*

%systemroot%\Fonts\*.com

%systemroot%\Fonts\*.dll

%systemroot%\Fonts\*.ini

%systemroot%\Fonts\*.ini2

%systemroot%\*.scr

%systemroot%\*._sy

%systemroot%\REPAIR\*.bak1

%systemroot%\REPAIR\*.ini

%systemroot%\system32\*.wt

%systemroot%\system32\*.ruy

%systemroot%\system32\*.jpg

%systemroot%\system32\spool\prtprocs\w32x86\*.*

%APPDATA%\Update\*.*

%APPDATA%\Microsoft\*.*

%APPDATA%\Adobe\Update\*.*

%ALLUSERSPROFILE%\Favorites\*.*

%PROGRAMFILES%\*.*

%systemroot%\*. /mp /s

CREATERESTOREPOINT

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\System32\config\*.sav

%systemroot%\system32\user32.dll /md5

%systemroot%\system32\ws2_32.dll /md5

%systemroot%\system32\ws2help.dll /md5

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Натиснете маркираният в синьо бутон: 30rn2na.jpg.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt.
  • Публикувайте или прикачете в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение) логовете от OTL: OTL.Txt, Extras.Txt. Може да качите файловете не rapidshare.com и да дадете линк за изтегляне.

  • Автор

Така го направих давам ви снимка по простата причина че под кустом скан първия скрипт съвпада със този който ми казахте да копирам но от втория не съвпада за това реших да дам и снимка за да съм сигурен

http://prikachi.com/images.php?images/595/2400595T.png

нода току що ми засече 15 атаки и истри някаква снимка имам и десктоп ини файл който е невидим скрит фаил и съдържа това [.ShellClassInfo]

CLSID={645FF040-5081-101B-9F08-00AA002F954E} часа ми се размества постоянно затова не гледайте часа на нода не е верен

8/6/2010 12:27:07 Защитатата на файловата система в реално време файл C:\Documents and Settings\Ghost\Desktop\PIC6777658898-JPG-www.facebook.com.scr IRC/SdBot троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие при опит за достъп до файла от приложението: C:\Documents and Settings\Ghost\desktop\OTL.exe.

8/6/2010 02:19:36 Защитатата на файловата система в реално време файл C:\ssA1234567890.exe вариант на Win32/Oficla.HZ троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие с нов файл, създаден от приложението: C:\WINDOWS\jusched.exe.

8/6/2010 02:19:36 Защитатата на файловата система в реално време файл C:\Documents and Settings\Ghost\Local Settings\Temporary Internet Files\Content.IE5\8H5ZHKME\decc[1] вариант на Win32/Oficla.HZ троянски кон почистен чрез изтриване - под карантина GANGOSAN-9708CA\Ghost Възникна събитие с нов файл, създаден от приложението: C:\WINDOWS\jusched.exe.

8/6/2010 02:19:20 HTTP филтър файл http://rs676l33.rapidshare.com/files/409039447/decc.html вариант на Win32/Oficla.HZ троянски кон връзката е прекъсната - под карантина GANGOSAN-9708CA\Ghost

ОТЛ сканира още

Да, снимките не съвпадат със скрипта, който съм дал. Аз съм дал примерна снимка. Ще изчакам резултатите от сканирането на ОTL.

Благодаря. Ето скрипт за OTL:

Стъпка 1

Деинсталирайте Ask Toolbar, ако се намира в Control Panel -> Add/Remove Programs.

После може да използвате този инструмент за почистване: AutoClean

Стъпка 2

Стартирайте пак OTL.exe и с Copy/ Paste под колонката Custom Scans/Fixes въведете скриптовия текст от цитата по-долу, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта!


:OTL

SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found

DRV - (TfSysMon) -- C:\WINDOWS\System32\drivers\TfSysMon.sys File not found

DRV - (TfNetMon) -- C:\WINDOWS\System32\drivers\TfNetMon.sys File not found

DRV - (TfFsMon) -- C:\WINDOWS\System32\drivers\TfFsMon.sys File not found

O2 - BHO: (no name) - {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} - No CLSID value found.

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - {C70E30C7-140A-4166-A2E8-43557E62B41A} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartmenuLogoff = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinters = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSecCpl = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCpl = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0

O7 - HKU\S-1-5-21-436374069-861567501-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0

O9 - Extra Button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - Reg Error: Value error. File not found

O9 - Extra 'Tools' menuitem : &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - Reg Error: Value error. File not found

O13 - gopher Prefix: missing

O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}  (Reg Error: Value error.)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O32 - AutoRun File - [2010/06/03 20:41:56 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd) - F:\AUTORUN.EXE -- [ CDFS ]

O32 - AutoRun File - [2000/11/09 10:05:38 | 000,000,051 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]

O32 - AutoRun File - [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd) - I:\AUTORUN.EXE -- [ CDFS ]

O32 - AutoRun File - [2000/11/09 10:05:38 | 000,000,051 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]

O33 - MountPoints2\{406b8fbd-80e4-11df-8014-b79bf0d8d1a8}\Shell - "" = AutoRun

O33 - MountPoints2\{406b8fbd-80e4-11df-8014-b79bf0d8d1a8}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{406b8fbd-80e4-11df-8014-b79bf0d8d1a8}\Shell\AutoRun\command - "" = K:\setup.exe -- File not found

O33 - MountPoints2\{c4e485b9-8d1e-11df-acd4-f7f56fae89e5}\Shell - "" = AutoRun

O33 - MountPoints2\{c4e485b9-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{c4e485b9-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE -- [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd)

O33 - MountPoints2\{c4e485bc-8d1e-11df-acd4-f7f56fae89e5}\Shell - "" = AutoRun

O33 - MountPoints2\{c4e485bc-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{c4e485bc-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun\command - "" = I:\AUTORUN.EXE -- [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd)

O34 - HKLM BootExecute: ("autocheck autochk *") -  File not found

@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86

@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8


:Files

C:\WINDOWS\Tasks\at*.job


:Commands

[purity]

[resethosts]

[emptytemp]

[emptyflash]

[Reboot]

След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: 045f5994a44b310e.png

Ще се създаде лог файл. Запишете лог файла, направете ZIP архив и го прикачете към следващия си коментар. Може да го качите на rapidshare.com или подобен сайт.

Стъпка 3

Качете на virustotal този файл:

C:\Documents and Settings\All Users\Application Data\6C1EAF4D49.sys

Сканирайте и дайте линк към резултата.

Много добре!

Сега пусни пак OTL и натисни Quick Scan. Изчакай да завърши сканирането, архивирай и закачи лога с име OTL.txt на rapidshare или подобен сайт.

  • Автор

не съм пипал отметките така го стартирах направо http://prikachi.com/images.php?images/182/2401182G.png

Така готови сме и със този лог http://rapidshare.com/files/411375770/OTL5678uijkhucdn.rar

1. Изтеглете ComboFix от следните миръри: от тук: Download-button3.gif или от тук: Download-button3.gif.

След изтегляне на файла го запишете (бутон Save -> Save as) ComboFix на вашия десктоп, снимка:

030810185350_aaa.jpg

След като изтеглите ComboFix на десктопа, иконката на програмата би трябвало да изглежда така:

030810185426_bbb.jpg

2. Затворете всички работещи приложения или отворени прозорци. Прекратете временно работата на антивирусната програма и на други програми за сигурност, ако има такива. За целта може да прегледате информацията от този линк: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

3. Преименувайте ComboFix.exe на ff1.exe

4. Стартирайте с двоен клик ff1.exe. За целта използвайте YES, за да се съгласите с условията за използване на програмата.

Важно: след като се стартира ComboFix не бива да се движи мишката или да се кликва върху отворения прозорец на програмата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

5. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката, моля да прочетете това: Manually restoring the Internet connection section.

Забележка: При проблеми с ComboFix копирайте (Copy) и поставете (Paste) съдържанието на C:\BUG.txt в следващия си коментар.

6. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad, виж снимката:

030810185514_eee.jpg

Копирайте (Copy) и поставете (Paste) съдържанието на лога в следващия си коментар.

  • Автор

това преди малко

8/6/2010 15:35:56 Защитатата на файловата система в реално време файл C:\System Volume Information\_restore{AA9F66D1-0F9F-4FAB-9A33-9E67E2E3D0D7}\RP196\A0028077.exe IRC/SdBot троянски кон почистен чрез изтриване - под карантина NT AUTHORITY\SYSTEM Възникна събитие при опит за достъп до файла от приложението: C:\WINDOWS\system32\svchost.exe.

За коректна работа на ComboFix трябва да бъде спряна защитата в реално време. За това има инструкция в т.2 от коментар 20 от тази тема.

Това, което се е появило преди малко не е страшно, ще го оправим.

  • Автор

ComboFix 10-08-05.06 - Ghost 08/06/2010 16:20:00.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1014.668 [GMT -7:00]

Running from: c:\documents and settings\Ghost\Desktop\ff1.exe.exe

AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\system32\SHELLLNK.TLB

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_OSPPSVC

-------\Service_osppsvc

((((((((((((((((((((((((( Files Created from 2010-07-07 to 2010-08-07 )))))))))))))))))))))))))))))))

.

2010-08-06 20:54 . 2010-08-06 20:54 -------- d-----w- C:\_OTL

2010-08-06 10:45 . 2010-08-06 10:45 -------- d-----w- c:\program files\Alex Feinman

2010-08-06 08:10 . 2010-08-06 08:27 -------- d-----w- c:\program files\EASEUS

2010-08-05 17:33 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-05 17:33 . 2010-08-05 17:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-08-05 17:33 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-05 17:31 . 2010-08-05 17:31 22016 ----a-w- c:\windows\system32\drivers\extit.sys

2010-08-05 07:37 . 2010-08-05 07:39 -------- d-----w- c:\documents and settings\Ghost\Application Data\Capture

2010-08-04 03:39 . 2010-08-04 03:39 -------- d-----w- c:\program files\microsoft frontpage

2010-08-03 11:30 . 2010-08-04 04:11 -------- d-----w- c:\documents and settings\Ghost\Application Data\ChessRally 2

2010-08-03 11:29 . 2010-08-03 11:34 -------- d-----w- c:\documents and settings\All Users\Application Data\ChessRally 2

2010-08-03 11:29 . 2010-08-03 11:29 -------- d-----w- c:\program files\Ingenuware

2010-08-03 11:29 . 2009-11-07 19:21 1527808 ----a-w- c:\windows\system32\ImpulseGlobals.dll

2010-08-03 11:29 . 2009-02-15 22:19 69632 ----a-w- c:\windows\system32\ImpulseASM.dll

2010-08-03 11:28 . 2010-08-04 05:19 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\ApplicationHistory

2010-08-03 11:28 . 2010-08-03 11:28 -------- d-----w- c:\windows\system32\URTTEMP

2010-08-03 08:57 . 2010-08-03 08:57 -------- d-----w- c:\program files\SopCast

2010-08-02 23:35 . 2010-08-03 11:21 -------- d-----w- c:\documents and settings\Ghost\Application Data\vlc

2010-08-02 23:35 . 2010-08-02 23:35 -------- d-----w- c:\program files\VideoLAN

2010-08-02 23:06 . 2010-08-02 23:14 -------- d-----w- c:\documents and settings\Ghost\Application Data\dvdcss

2010-08-02 22:43 . 2010-08-02 22:43 -------- d-----w- c:\program files\Readon Technology

2010-08-02 10:13 . 2010-08-02 10:16 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Readon_Technology

2010-08-02 08:58 . 2010-08-02 08:58 -------- d-----w- c:\program files\Driver-Soft

2010-08-02 06:04 . 2010-08-02 06:04 -------- d-----w- c:\windows\Downloaded Program Files

2010-08-01 23:15 . 2010-08-01 23:16 -------- d-----w- c:\program files\Driver Cleaner Pro

2010-08-01 21:29 . 2010-08-01 21:29 -------- d-----w- c:\documents and settings\Ghost\Application Data\Malwarebytes

2010-08-01 21:29 . 2010-08-01 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-08-01 12:01 . 2010-08-01 12:01 -------- d-----w- c:\program files\Daihinia

2010-07-27 18:07 . 2010-07-27 18:07 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Threat Expert

2010-07-27 05:02 . 2010-01-12 20:35 100896 ----a-w- c:\windows\system32\RTNUninst32.dll

2010-07-27 05:02 . 2010-01-12 20:35 80416 ----a-w- c:\windows\system32\RtNicProp32.dll

2010-07-27 04:12 . 2010-07-27 04:21 -------- d-----w- c:\program files\Wintoflash

2010-07-26 16:23 . 2010-07-26 16:23 -------- d-----w- c:\documents and settings\Ghost\Application Data\Publish Providers

2010-07-26 16:23 . 2010-07-26 16:23 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Sony

2010-07-26 16:23 . 2010-07-26 16:23 -------- d-----w- c:\documents and settings\Ghost\Application Data\Sony

2010-07-26 16:04 . 2010-07-26 16:04 -------- d-----w- c:\program files\Vstplugins

2010-07-26 16:04 . 2010-07-26 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony

2010-07-26 16:04 . 2010-07-26 16:04 -------- d-----w- c:\program files\Sony

2010-07-26 16:04 . 2010-07-26 16:08 -------- d-----w- c:\program files\Sony Setup

2010-07-26 10:15 . 2010-07-26 10:15 -------- d-----w- c:\program files\Lavalys

2010-07-26 09:48 . 2010-07-26 09:48 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys

2010-07-26 09:48 . 2010-07-26 09:51 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\eSupport.com

2010-07-26 00:32 . 2010-07-26 00:32 -------- d-----w- c:\documents and settings\Ghost\Application Data\MozillaControl

2010-07-26 00:31 . 2010-07-26 00:31 -------- d-----w- c:\windows\'Full Speed' Internet Booster + Performance Tests

2010-07-26 00:31 . 2010-07-28 01:25 -------- d-----w- c:\program files\'Full Speed' Internet Booster + Performance Tests

2010-07-25 09:05 . 2010-07-25 09:05 -------- d-----w- c:\program files\SMS Free Sender

2010-07-23 12:33 . 2010-07-23 12:33 -------- d-----w- c:\windows\system32\RTCOM

2010-07-21 22:53 . 2010-07-21 22:53 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Help

2010-07-21 10:33 . 2010-08-03 07:52 -------- d-----w- C:\DriveKey

2010-07-21 10:11 . 2010-07-28 01:49 -------- d-----w- C:\WinSetupFromUSB

2010-07-20 23:14 . 2010-07-20 23:14 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\PCHealth

2010-07-19 12:24 . 2010-07-19 12:24 -------- d-----w- c:\documents and settings\All Users\Application Data\GoodSync

2010-07-19 12:24 . 2010-07-28 01:25 -------- d-----w- c:\documents and settings\Ghost\Application Data\GoodSync

2010-07-19 12:17 . 2010-07-19 12:17 -------- d-----w- c:\documents and settings\Ghost\Application Data\Avant Profiles

2010-07-19 12:17 . 2010-07-19 12:17 -------- d-----w- c:\program files\Avant Browser

2010-07-18 23:49 . 2010-07-18 23:49 -------- d-----w- c:\documents and settings\Ghost\Application Data\Corel

2010-07-18 21:48 . 2010-07-19 02:27 -------- d-----w- c:\documents and settings\Ghost\Application Data\Ulead Systems

2010-07-18 21:47 . 2010-07-18 21:47 -------- d-----w- c:\program files\SmartSound Software

2010-07-18 21:47 . 2010-07-18 21:48 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc

2010-07-18 21:47 . 2010-07-18 21:47 -------- d-----w- c:\windows\system32\windows media

2010-07-18 21:47 . 2010-07-18 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo

2010-07-18 21:46 . 2010-07-18 21:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel

2010-07-18 21:42 . 2010-07-18 21:42 -------- d-----w- c:\program files\Common Files\Protexis

2010-07-18 21:42 . 2010-07-18 21:42 -------- d-----w- c:\program files\Common Files\Corel

2010-07-18 21:39 . 2010-07-18 21:39 -------- d-----w- c:\program files\Windows Media Components

2010-07-18 21:39 . 2010-07-18 21:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems

2010-07-18 21:39 . 2010-07-18 21:39 -------- d-----w- c:\program files\Common Files\Ulead Systems

2010-07-18 21:39 . 2010-07-18 21:46 -------- d-----w- c:\program files\Corel

2010-07-18 21:37 . 2010-07-18 21:37 -------- d-----w- c:\windows\system32\XPSViewer

2010-07-18 21:37 . 2010-07-18 21:37 -------- d-----w- c:\program files\Reference Assemblies

2010-07-18 21:36 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-07-18 21:36 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2010-07-18 21:36 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-07-18 21:36 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2010-07-18 21:36 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-07-18 21:36 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-07-18 21:36 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-07-18 21:36 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-07-18 21:36 . 2010-07-18 21:36 -------- d-----w- c:\windows\Sun

2010-07-18 20:33 . 2010-07-18 20:55 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\NOS

2010-07-18 11:41 . 2010-07-18 11:41 -------- d-----w- c:\windows\Performance

2010-07-18 11:41 . 2010-07-18 11:41 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Microsoft Corporation

2010-07-17 12:49 . 2010-07-18 05:34 -------- d-----w- c:\documents and settings\All Users\Application Data\RealHideIP

2010-07-17 12:49 . 2010-07-17 12:49 -------- d-----w- c:\documents and settings\Ghost\Application Data\RealHideIP

2010-07-17 10:10 . 2010-07-17 10:10 -------- d-----w- C:\Poker

2010-07-17 05:13 . 2010-07-17 13:21 -------- d-----w- c:\program files\RealHideIP

2010-07-17 00:49 . 2010-07-30 07:08 -------- d-----w- c:\program files\CarbonPoker

2010-07-15 00:07 . 2010-07-15 00:07 -------- d-----w- c:\program files\gps

2010-07-14 23:59 . 2010-07-14 23:59 -------- d-----w- c:\program files\WebEx

2010-07-14 23:59 . 2009-07-07 21:48 25392 ----a-w- c:\windows\system32\drivers\pnarp.sys

2010-07-14 23:58 . 2009-07-07 21:48 26672 ----a-w- c:\windows\system32\drivers\purendis.sys

2010-07-14 23:58 . 2010-07-14 23:58 -------- d-----w- c:\program files\Common Files\Pure Networks Shared

2010-07-14 22:51 . 2010-07-14 22:51 770048 ----a-w- c:\windows\3D World Map.scr

2010-07-14 22:51 . 2010-07-14 22:51 -------- d-----w- c:\program files\Longgame

2010-07-14 22:28 . 2010-08-05 17:12 -------- d-----w- c:\program files\Common Files\Java

2010-07-14 22:28 . 2010-07-14 22:28 411368 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-14 22:28 . 2010-07-14 22:28 -------- d-----w- c:\program files\Java

2010-07-14 05:57 . 2008-12-14 16:20 23344 ----a-w- c:\windows\system32\drivers\pnpcap.sys

2010-07-14 05:57 . 2010-07-14 23:59 -------- d-----w- c:\program files\Pure Networks

2010-07-14 05:56 . 2010-07-14 05:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Pure Networks

2010-07-14 05:12 . 2010-08-06 08:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2010-07-13 21:56 . 2010-07-13 21:57 -------- d-----w- c:\documents and settings\Ghost\Application Data\YoWindow

2010-07-13 21:55 . 2010-07-13 21:56 -------- d-----w- c:\program files\YoWindow

2010-07-13 02:44 . 2010-07-13 02:44 -------- d-----w- c:\program files\Advanced IP Scanner

2010-07-12 12:11 . 2010-07-12 12:25 -------- d-----w- c:\documents and settings\Ghost\Application Data\Tao ExDOS

2010-07-12 12:10 . 2010-07-12 12:10 6912 ---ha-w- c:\windows\system32\drivers\MSdo42H.SYS

2010-07-12 12:10 . 2010-07-28 01:25 -------- d-----w- C:\~EXDSWAP

2010-07-12 12:09 . 2010-07-30 07:10 -------- d-----w- c:\documents and settings\All Users\Tao

2010-07-12 05:36 . 2007-03-05 18:51 360580 ----a-w- c:\windows\eSellerateEngine.dll

2010-07-12 05:36 . 2007-02-23 23:57 94208 ----a-w- c:\windows\eSellerateControl365.dll

2010-07-12 00:02 . 2010-07-12 00:02 -------- d-----w- c:\program files\Conduit

2010-07-12 00:02 . 2010-07-12 00:02 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Conduit

2010-07-12 00:01 . 2010-07-12 00:06 -------- d-----w- c:\program files\EasyMP3Downloader

2010-07-11 21:40 . 2010-07-13 10:06 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader

2010-07-11 21:40 . 2010-07-11 21:40 -------- d-----w- c:\documents and settings\Ghost\Application Data\EasyMP3Downloader

2010-07-11 19:51 . 2010-07-11 19:51 -------- d-----w- c:\documents and settings\Ghost\Application Data\Helios

2010-07-11 18:56 . 2010-07-18 21:37 -------- d-----w- c:\program files\MSBuild

2010-07-11 18:55 . 2010-07-11 18:55 -------- d-----w- c:\program files\Microsoft Sync Framework

2010-07-11 18:55 . 2010-07-11 18:55 -------- d-----w- c:\documents and settings\All Users\Microsoft

2010-07-11 18:52 . 2010-07-11 18:52 -------- d-----w- c:\program files\Microsoft Analysis Services

2010-07-11 18:50 . 2010-07-27 07:43 -------- d-----w- c:\documents and settings\Ghost\Application Data\Bc

2010-07-11 12:11 . 2010-07-11 12:11 -------- d-----w- c:\documents and settings\Ghost\Local Settings\Application Data\Qwerty Studios

2010-07-11 12:11 . 2010-08-03 02:46 -------- d-----w- c:\windows\lhsp

2010-07-11 12:11 . 2010-07-12 05:36 -------- d-----w- c:\windows\speech

2010-07-11 12:11 . 2010-07-25 09:59 -------- d-----w- c:\program files\Speaking Notepad

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-07 02:58 . 2010-06-04 04:32 -------- d-----w- c:\documents and settings\Ghost\Application Data\DMCache

2010-08-06 22:44 . 2010-06-04 00:52 -------- d-----w- c:\documents and settings\Ghost\Application Data\Skype

2010-08-06 21:00 . 2010-06-04 04:13 -------- d-----w- c:\program files\SeaMonkey

2010-08-06 11:45 . 2010-06-04 04:32 -------- d-----w- c:\documents and settings\Ghost\Application Data\IDM

2010-08-06 09:00 . 2010-06-05 18:01 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-08-06 08:32 . 2010-06-05 18:00 -------- d-----w- c:\program files\Common Files\InstallShield

2010-08-06 07:00 . 2010-06-05 03:22 -------- d-----w- c:\program files\PokerStars

2010-08-06 06:56 . 2010-06-10 17:54 -------- d-----w- c:\program files\Absolute Poker

2010-08-06 05:53 . 2010-08-06 05:53 503808 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6801c607-n\msvcp71.dll

2010-08-06 05:53 . 2010-08-06 05:53 499712 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6801c607-n\jmc.dll

2010-08-06 05:53 . 2010-08-06 05:53 348160 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6801c607-n\msvcr71.dll

2010-08-06 05:53 . 2010-08-06 05:53 61440 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-56bfb773-n\decora-sse.dll

2010-08-06 05:53 . 2010-08-06 05:53 12800 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-56bfb773-n\decora-d3d.dll

2010-08-06 05:34 . 2010-06-05 03:28 -------- d-----w- c:\program files\Action Poker

2010-08-06 04:38 . 2010-06-04 04:35 -------- d-----w- c:\documents and settings\Ghost\Application Data\uTorrent

2010-08-05 18:00 . 2010-06-10 21:20 -------- d-----w- c:\documents and settings\Ghost\Application Data\Microgaming

2010-08-05 17:34 . 2010-06-20 01:37 -------- d-----w- c:\program files\Exterminate It!

2010-08-05 06:00 . 2010-06-04 01:06 -------- d-----w- c:\documents and settings\Ghost\Application Data\TeamViewer

2010-08-04 04:11 . 2010-08-03 11:29 45056 ----a-w- c:\documents and settings\All Users\Application Data\ChessRally 2\IngDirectXDetect.dll

2010-08-03 07:58 . 2010-07-05 04:07 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

2010-08-03 02:48 . 2010-07-05 04:07 2605008 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe

2010-08-02 22:16 . 2010-06-05 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer

2010-08-02 22:12 . 2010-06-18 09:13 -------- d-----w- c:\program files\Winamp

2010-08-02 21:03 . 2010-06-04 04:32 -------- d-----w- c:\program files\Internet Download Manager

2010-08-02 10:07 . 2010-06-30 01:24 -------- d-----w- c:\program files\Songbird

2010-08-02 05:59 . 2010-08-02 05:58 3205464 ----a-w- c:\documents and settings\Ghost\Application Data\IDM\idmupdt.exe

2010-07-30 07:13 . 2010-07-30 07:13 22446847 ------w- c:\documents and settings\Ghost\Application Data\PacificPoker\setup.exe

2010-07-28 22:13 . 2010-07-06 04:57 -------- d-----w- c:\program files\Common Files\PC Tools

2010-07-28 02:14 . 2010-06-18 11:26 -------- d-----w- c:\program files\WinUtilities

2010-07-28 01:25 . 2010-06-18 09:55 -------- d-----w- c:\program files\Glary Utilities

2010-07-27 05:02 . 2010-06-10 08:29 -------- d-----w- c:\program files\Realtek

2010-07-27 04:44 . 2010-06-04 05:38 -------- d-----w- c:\program files\Driver Magician

2010-07-26 00:08 . 2010-06-28 00:55 -------- d-----w- c:\program files\BeFaster

2010-07-23 23:55 . 2010-07-18 23:49 5018 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys

2010-07-23 23:55 . 2010-07-18 23:49 5018 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys

2010-07-22 00:49 . 2010-05-01 01:54 272 ----a-w- c:\windows\system32\bsf.reg

2010-07-19 02:12 . 2010-06-04 03:48 83928 ----a-w- c:\documents and settings\Ghost\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-07-19 02:01 . 2010-07-18 23:49 88 --sh--r- c:\documents and settings\All Users\Application Data\6C1EAF4D49.sys

2010-07-19 02:01 . 2010-07-18 23:49 88 --sh--r- c:\documents and settings\All Users\Application Data\6C1EAF4D49.sys

2010-07-15 01:12 . 2010-07-06 00:48 -------- d-----w- c:\program files\Photo Collage Creator

2010-07-14 23:59 . 2010-07-14 05:07 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi

2010-07-14 22:30 . 2010-07-14 22:30 503808 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5997098b-n\msvcp71.dll

2010-07-14 22:30 . 2010-07-14 22:30 499712 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5997098b-n\jmc.dll

2010-07-14 22:30 . 2010-07-14 22:30 348160 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5997098b-n\msvcr71.dll

2010-07-14 22:28 . 2010-07-14 22:28 61440 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-7e446118-n\decora-sse.dll

2010-07-14 22:28 . 2010-07-14 22:28 12800 ----a-w- c:\documents and settings\Ghost\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-7e446118-n\decora-d3d.dll

2010-07-13 03:03 . 2010-06-04 00:56 -------- d-----w- c:\program files\USBScan

2010-07-12 12:54 . 2010-07-06 16:15 -------- d-----w- c:\documents and settings\All Users\Application Data\iolo

2010-07-12 12:54 . 2010-06-05 17:55 -------- d-----w- c:\program files\QuickTime

2010-07-12 12:22 . 2010-06-15 07:52 -------- d-----w- c:\program files\MagicDisc

2010-07-11 19:03 . 2010-07-11 19:02 699904 ----a-w- c:\documents and settings\Ghost\Application Data\Bc\swhst.exe

2010-07-11 18:50 . 2010-07-11 18:50 62976 ----a-w- c:\documents and settings\Ghost\Application Data\Bc\svhst.exe

2010-07-09 17:57 . 2010-07-05 03:43 699392 ----a-w- c:\documents and settings\Ghost\Application Data\Swhst\swhst.exe

2010-07-07 20:57 . 2010-07-07 20:57 61952 ----a-w- c:\windows\svhst.exe

2010-07-07 01:27 . 2010-07-23 12:32 84584 ----a-w- c:\windows\SOUNDMAN.EXE

2010-07-07 01:27 . 2010-07-23 12:32 359016 ----a-w- c:\windows\vncutil.exe

2010-07-07 01:27 . 2010-07-23 12:32 1833576 ----a-w- c:\windows\SkyTel.exe

2010-07-07 01:27 . 2010-07-23 12:32 1489512 ----a-w- c:\windows\RtlUpd.exe

2010-07-07 01:26 . 2010-07-23 12:32 9721960 ----a-w- c:\windows\RTLCPL.EXE

2010-07-07 01:26 . 2010-07-23 12:32 6088296 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys

2010-07-07 01:26 . 2010-07-23 12:32 129640 ----a-w- c:\windows\RtkAudioService.exe

2010-07-07 01:26 . 2010-06-10 08:30 53864 ----a-w- c:\windows\system32\RtkCoInstXP.dll

2010-07-07 01:26 . 2010-07-23 12:32 19556968 ----a-w- c:\windows\RTHDCPL.EXE

2010-07-07 01:26 . 2010-07-23 12:32 2180712 ----a-w- c:\windows\MicCal.exe

2010-07-07 01:26 . 2010-07-23 12:32 2815592 ----a-w- c:\windows\ALCWZRD.EXE

2010-07-07 01:26 . 2010-07-23 12:32 64104 ----a-w- c:\windows\ALCMTR.EXE

2010-07-06 19:52 . 2010-07-06 19:36 -------- d-----w- c:\program files\Unlocker

2010-07-06 19:52 . 2010-07-06 19:48 -------- d-----w- c:\program files\uTorrent Turbo Accelerator

2010-07-06 19:49 . 2010-07-06 19:49 -------- d-----w- c:\documents and settings\Ghost\Application Data\Toolbar4

2010-07-06 19:49 . 2010-07-06 19:49 -------- d-----w- c:\program files\WebScout Toolbar

2010-07-06 18:13 . 2010-06-03 20:29 234392 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys

2010-07-06 16:38 . 2010-07-06 16:38 74703 ----a-w- c:\windows\system32\mfc45.dll

2010-07-06 14:45 . 2010-07-06 14:45 368640 ----a-w- c:\documents and settings\Ghost\Application Data\Mozilla\Firefox\Profiles\6xslnlzt.default\extensions\[email protected]\components\FFHst.dll

2010-07-06 05:04 . 2010-07-06 05:04 -------- d-----w- c:\documents and settings\Ghost\Application Data\Registry Mechanic

2010-07-05 03:43 . 2010-07-04 05:59 -------- d-----w- c:\documents and settings\Ghost\Application Data\Swhst

2010-07-04 06:02 . 2010-07-04 06:00 -------- d-----w- c:\documents and settings\Ghost\Application Data\Internet Download Accelerator

2010-07-04 05:59 . 2010-07-04 05:59 61952 ----a-w- c:\documents and settings\Ghost\Application Data\Swhst\svhst.exe

2010-06-30 01:24 . 2010-06-30 01:24 -------- d-----w- c:\documents and settings\Ghost\Application Data\Songbird2

2010-06-27 23:49 . 2010-06-27 23:49 -------- d-----w- c:\program files\FirefoxPreloader

2010-06-27 19:06 . 2010-06-27 19:06 -------- d-----w- c:\program files\Morphyre

2010-06-26 16:55 . 2010-06-26 16:55 -------- d-----w- c:\program files\B2BPOKER

2010-06-26 10:48 . 2010-06-26 10:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

2010-06-26 06:41 . 2010-06-25 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\NFS Underground

2010-06-26 05:01 . 2010-06-26 05:01 -------- d-----w- c:\program files\Intelore

2010-06-25 21:05 . 2010-06-25 21:05 -------- d-----w- c:\program files\Common Files\DirectX

2010-06-25 20:58 . 2010-06-25 20:58 -------- d-----w- c:\program files\EA GAMES

2010-06-24 20:19 . 2010-06-24 20:19 -------- d-----r- c:\program files\Skype

2010-06-24 19:52 . 2010-06-22 22:52 -------- d-----w- c:\documents and settings\Ghost\Application Data\skypePM

2010-06-24 18:13 . 2010-07-23 12:32 1251944 ----a-w- c:\windows\RtlExUpd.dll

2010-06-22 19:58 . 2010-06-22 19:58 8 ----a-w- c:\documents and settings\Ghost\Application Data\pws.dll

2010-06-22 19:58 . 2010-06-22 19:58 8 ----a-w- c:\documents and settings\Ghost\Application Data\pws.dll

2010-06-22 19:58 . 2010-06-22 19:58 -------- d-----w- c:\program files\Sumra Soft

2010-06-22 01:07 . 2010-06-22 01:04 -------- d-----w- c:\program files\Windows Live Safety Center

2010-06-22 00:32 . 2010-06-22 00:32 23558 ----a-r- c:\documents and settings\Ghost\Application Data\Microsoft\Installer\{83073C45-3003-4671-9A86-243AAADD915A}\_294823.exe

2010-06-22 00:32 . 2010-06-22 00:32 23558 ----a-r- c:\documents and settings\Ghost\Application Data\Microsoft\Installer\{83073C45-3003-4671-9A86-243AAADD915A}\_18be6784.exe

2010-06-22 00:32 . 2010-06-22 00:32 -------- d-----w- c:\program files\Microsoft Calculator Plus

2010-06-20 06:52 . 2010-06-04 04:24 -------- d-----w- c:\documents and settings\Ghost\Application Data\BSplayer PRO

2010-06-18 22:11 . 2010-06-18 22:11 -------- d-----w- c:\documents and settings\Ghost\Application Data\Blitware

2010-06-18 22:11 . 2010-06-18 22:11 -------- d-----w- c:\program files\Driver Robot

2010-06-18 19:10 . 2010-06-18 19:10 -------- d-----w- c:\program files\Common Files\Adobe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

2010-01-16 15:59 561552 ----a-w- c:\progra~1\MICROS~4\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2010-06-10 3220912]

"Swhst"="c:\documents and settings\Ghost\Application Data\Bc\swhst.exe" [2010-07-11 699904]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-01-13 134656]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-01-13 166912]

"Persistence"="c:\windows\system32\igfxpers.exe" [2010-01-13 135680]

"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]

"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]

"USBScan.exe"="c:\program files\USBScan\USBScan.exe" [2009-08-14 1358848]

"Standby"="c:\program files\Common Files\Corel\Standby\Standby.exe" [2009-12-17 105632]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]

"RTHDCPL"="RTHDCPL.EXE" [2010-07-07 19556968]

"bsf"="bsf.exe" [2010-05-05 77824]

"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-02-04 2054360]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2010-6-3 151552]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^Ghost^Start Menu^Programs^Startup^MagicDisc.lnk]

backup=c:\windows\pss\MagicDisc.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ghost^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk]

backup=c:\windows\pss\OneNote 2010 Screen Clipper and Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ghost^Start Menu^Programs^Startup^YoWindow.lnk]

backup=c:\windows\pss\YoWindow.lnkStartup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BeFaster]

2010-05-22 13:00 447488 ----a-w- c:\program files\BeFaster\befaster4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]

2010-01-16 16:54 717696 ----a-w- c:\program files\Microsoft Office\Office14\MSOSYNC.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smp.exe]

2010-07-14 06:18 442664 ----a-w- c:\program files\Pure Networks\Speed Meter Pro\smp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

2010-05-25 16:08 37888 ----a-w- c:\program files\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"d:\\Mirc\\mirc.exe"=

"d:\\Programi\\TeamViewer\\TeamViewer.exe"=

"d:\\Programi\\igri\\Counter-Strike 1.6\\Counter-Strike 1.6\\hl.exe"=

"c:\\Program Files\\EA GAMES\\Need For Speed Underground\\Speed.exe"=

"c:\\Program Files\\B2BPOKER\\24hPoker\\jre\\bin\\javaw.exe"=

"d:\\Programi\\igri\\Worms World Party(XP OK!)\\WWP\\wwp.exe"=

"c:\\Program Files\\Opera\\opera.exe"=

"d:\\Programi\\Mirc.Ircii\\mirc.exe"=

"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=

"c:\\WINDOWS\\Installer\\{1584854C-1513-40EA-96D4-493384D0A3C7}\\_44F622AA395D57B9743A14.exe"=

"c:\\Program Files\\Readon Technology\\Readon TV Movie Radio Player 7.2.0.0\\internettv.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [12/18/2009 15:02 108792]

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2/4/2010 08:37 96408]

R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/4/2010 08:36 735960]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/5/2010 10:33 304464]

R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [7/5/2010 21:57 632792]

R2 pnpcap;Pure Networks Packet Capture Driver;c:\windows\system32\drivers\pnpcap.sys [7/13/2010 22:57 23344]

R2 Uniblue DiskRescue;Uniblue DiskRescue;c:\program files\Uniblue\DiskRescue\UBDiskRescueSrv.exe [9/10/2008 08:22 229648]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/5/2010 10:33 20952]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [7/23/2010 05:32 1691480]

S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/26/2010 02:48 23456]

S3 ExterminateIt;ExterminateIt;c:\windows\system32\drivers\extit.sys [8/5/2010 10:31 22016]

S3 H0jf5I;H0jf5I;c:\docume~1\Ghost\LOCALS~1\Temp\PCWizard\Data\pcwizntl.exe -s --> c:\docume~1\Ghost\LOCALS~1\Temp\PCWizard\Data\pcwizntl.exe -s [?]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [1/21/2010 17:51 30963576]

S3 UAsaCK;UAsaCK;c:\docume~1\Ghost\LOCALS~1\Temp\PCWizard\Data\pcwizntl.exe -s --> c:\docume~1\Ghost\LOCALS~1\Temp\PCWizard\Data\pcwizntl.exe -s [?]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/16/2010 22:10 697328]

.

Contents of the 'Scheduled Tasks' folder

2010-06-18 c:\windows\Tasks\4avdo.job

- c:\program files\WinUtilities\ToolRegistryCleaner.exe [2010-06-18 08:07]

2010-07-31 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-08-07 c:\windows\Tasks\bsf.job

- c:\windows\system32\bsf.exe [2010-05-01 17:35]

2010-08-01 c:\windows\Tasks\Driver Robot.job

- c:\program files\Driver Robot\1.2.0.5\DriverRobot.exe [2010-06-18 16:06]

2010-08-07 c:\windows\Tasks\GlaryInitialize.job

- c:\program files\Glary Utilities\initialize.exe [2010-06-18 18:14]

2010-06-05 c:\windows\Tasks\Uniblue DiskRescue 2009.job

- c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]

2010-08-07 c:\windows\Tasks\User_Feed_Synchronization-{BD35BFC6-6354-4026-839A-A5D9FD413787}.job

- c:\windows\system32\msfeedssync.exe [2007-08-13 11:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://i24search.com

uInternet Settings,ProxyServer = http=

IE: Download ALL with IDA

IE: Download remotely with IDA

IE: Download with IDA

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105

IE: Свали видео съдържанието на FLV с IDM - c:\program files\Internet Download Manager\IEGetVL.htm

IE: Свали всички линкове с IDM - c:\program files\Internet Download Manager\IEGetAll.htm

IE: Свали с IDM - c:\program files\Internet Download Manager\IEExt.htm

LSP: c:\windows\system32\idmmbc.dll

TCP: {C343B301-54AB-4781-B657-1DE663E4555B} = 217.79.67.30,217.79.79.79

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

FF - ProfilePath - c:\documents and settings\Ghost\Application Data\Mozilla\Firefox\Profiles\6xslnlzt.default\

FF - prefs.js: network.proxy.type - 0

FF - component: c:\documents and settings\Ghost\Application Data\IDM\idmmzcc3\components\idmmzcc.dll

FF - component: c:\documents and settings\Ghost\Application Data\Mozilla\Firefox\Profiles\6xslnlzt.default\extensions\[email protected]\components\FFHst.dll

FF - plugin: c:\progra~1\MICROS~4\Office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\MICROS~4\Office14\NPSPWRAP.DLL

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

.

------- File Associations -------

.

.txt=speakingtxtfile

.

- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-DAEMON Tools Pro Agent - c:\program files\DAEMON Tools Pro\DTProAgent.exe

AddRemove-bet365poker - c:\poker\Poker at bet365\_SetupPoker_68e0.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-06 20:03

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-436374069-861567501-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{544BF818-2A62-7801-243F-EB3410AA699B}*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

"jaljmhjpajbmnhlhenni"=hex:61,61,00,00

"kaljmhjpciekjanfbbjbmd"=hex:61,61,00,00

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{55de8176-feec-43b6-b756-94d82d1dfc1a}]

@Denied: (Full) (Everyone)

"Model"=dword:000000d3

"Therad"=dword:00000001

"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,

1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]

@Denied: (Full) (Everyone)

"scansk"=hex(0):2d,ca,c5,b7,4b,41,53,43,f9,0a,34,ab,8f,65,42,d3,22,f0,00,a2,a4,

91,0d,bc,2a,e2,ff,c3,bc,f7,48,98,c0,34,5c,4a,9b,31,92,e3,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(800)

c:\windows\system32\idmmbc.dll

- - - - - - - > 'explorer.exe'(988)

c:\windows\system32\WININET.dll

c:\windows\system32\newdll.dll

c:\program files\Unlocker\UnlockerHook.dll

c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf

c:\progra~1\MICROS~4\Office14\1033\GrooveIntlResource.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\msi.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\Protexis\License Service\PsiService_2.exe

c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

c:\windows\system32\igfxsrvc.exe

c:\windows\RTHDCPL.EXE

c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

c:\windows\system32\wscntfy.exe

c:\program files\Internet Download Manager\IEMonitor.exe

.

**************************************************************************

.

Completion time: 2010-08-06 20:05:13 - machine was rebooted

ComboFix-quarantined-files.txt 2010-08-07 03:04

Pre-Run: 41 277 161 472 bytes free

Post-Run: 41 092 460 544 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - C435098E659D2642FFE6156A725514D0

Стъпка 1

Следвайте следната инструкция за работа с ERUNT (програмата ще направи бекъп на регистрите):

  • Изтеглете програмата ERUNT
  • Инсталирайте и стартирате ERUNT.
  • Изберете папка за съхранение в секцията Backup options, като трябва да бъдат маркирани "System registry", "Current user registry" и "Other open user registries". Натиснете "Ok" и потвърдете създаването на папка. Описание с картинки на ERUNT: тук.

Стъпка 2

Стартирайте пак OTL.exe и с Copy/ Paste под колонката Custom Scans/Fixes въведете скриптовия текст от цитата по-долу, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта!


:OTL

SRV - (UAsaCK) -- C:\DOCUME~1\Ghost\LOCALS~1\Temp\PCWizard\Data\pcwizntl.exe File not found

SRV - (H0jf5I) -- C:\DOCUME~1\Ghost\LOCALS~1\Temp\PCWizard\Data\pcwizntl.exe File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab (Reg Error: Key error.)

O32 - AutoRun File - [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd) - F:\AUTORUN.EXE -- [ CDFS ]

O32 - AutoRun File - [2000/11/09 10:05:38 | 000,000,051 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]

O32 - AutoRun File - [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd) - I:\AUTORUN.EXE -- [ CDFS ]

O32 - AutoRun File - [2000/11/09 10:05:38 | 000,000,051 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]

O33 - MountPoints2\{c4e485b9-8d1e-11df-acd4-f7f56fae89e5}\Shell - "" = AutoRun

O33 - MountPoints2\{c4e485b9-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{c4e485b9-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE -- [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd)

O33 - MountPoints2\{c4e485bc-8d1e-11df-acd4-f7f56fae89e5}\Shell - "" = AutoRun

O33 - MountPoints2\{c4e485bc-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{c4e485bc-8d1e-11df-acd4-f7f56fae89e5}\Shell\AutoRun\command - "" = I:\AUTORUN.EXE -- [2001/01/10 07:48:42 | 000,172,032 | R--- | M] (Team17 Software Ltd)


:Services

jaljmhjpajbmnhlhenni

kaljmhjpciekjanfbbjbmd


:Commands

[purity]

[clearallrestorepoints]

[emptytemp]

[Reboot]

След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено: 045f5994a44b310e.png

Ще се създаде лог файл. Запишете лог файла, направете ZIP архив и го прикачете към следващия си коментар. Може да го качите на rapidshare.com или подобен сайт.

  • Автор

Добър вечер изпълних всичко рестартира се компа излезе лога и заби компа след което чаках 5 минути и се наложи да сресна компа по грубия начин от бутона на компа втория път зареди не искара лог чаках малко и пак по грубия начин рестарт сажалявам но пак ми трябва савет как да ви пратя лога куде е ако го няма как да го създам?

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.