Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Може би РС то се зарази,Kaspersky не иска да го острани.

Featured Replies

Денес KIS 2011 светна в червено и получих следното съобщение

Публикувано изображение

Възможно ли е самия Авант браузер, да е заразен?

Ползвателите на Кашперски знаят, че има бутон за автоматичен фикс, който при мен и в този случай не работи.

Наскоро инсталирах антивирусната и има ли друг начин за дезинфекция?

Редактирано от mihnev_sz
Заглавието (преглед на промените)

  • Автор

Благодаря за отговора.

Стъпка 3 Malwarebytes' Anti-Malware Free не откри нищо подозрително.

DDS файла го копирам защото системата не позволява да се прикачи.

DDS (Ver_10-03-17.01) - NTFSx86

Run by pmsacks at 20:06:16,81 on ўв 31.08.2010 Ј.

Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_03

Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1251.359.1033.18.2037.823 [GMT 3:00]

AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}

SP: Sunbelt VIPRE *disabled* (Outdated) {9817B764-AE4E-4B29-AEE7-725B7A50BD48}

============== Running Processes ===============

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k secsvcs

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\Apoint\Apoint.exe

C:\Program Files\Sony\VAIO Care\VAIOCareService.exe

C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe

C:\Windows\VM_STI.EXE

C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

C:\Windows\WindowsMobile\wmdSync.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

C:\Windows\ehome\ehtray.exe

c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\ehome\ehmsas.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\system32\svchost.exe -k iissvcs

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\WUDFHost.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\system32\iashost.exe

C:\Program Files\Sony\VAIO Care\VCsystray.exe

C:\Windows\System32\mobsync.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\svchost.exe -k WindowsMobile

C:\Windows\System32\alg.exe

C:\Program Files\Apoint\ApMsgFwd.exe

C:\Program Files\Apoint\Apntex.exe

C:\Windows\system32\conime.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\Avant Browser\avant.exe

C:\Program Files\Avant Browser\avantab.exe

C:\Program Files\Avant Browser\avantab.exe

C:\Program Files\Avant Browser\avantab.exe

C:\Users\pmsacks\Desktop\Software2\HiJackThis_v2.exe

C:\Program Files\Avant Browser\avantab.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Users\pmsacks\Desktop\dds.scr

C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank

mStart Page = about:blank

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll

BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2011\ievkbd.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll

uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun

uRun: [iSUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler

uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe

mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

mRun: [Apoint] c:\program files\apoint\Apoint.exe

mRun: [iSBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [bigDogPath] c:\windows\VM_STI.EXE Philips SPC 200NC PC Camera

mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe"

mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm

IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm

IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2011\ie_banner_deny.htm

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000

IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagead/preview/en/preview.html

IE: {85d1f590-48f4-11d9-9669-0800200c9a66}

IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

Notify: igfxcui - igfxdev.dll

Notify: klogon - c:\windows\system32\klogon.dll

Notify: VESWinlogon - VESWinlogon.dll

AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-6-30 130936]

R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2010-4-22 22104]

R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464]

R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2010-3-23 202928]

R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe [2010-7-1 357096]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-1-15 47640]

R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2008-9-12 69168]

R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-7-18 38224]

R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2008-2-24 807424]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\system32\drivers\ADM851X.sys [2007-7-10 26190]

S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-29 21504]

S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-5-13 27192]

S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]

=============== Created Last 30 ================

2010-08-19 06:28:00 2402801469 ----a-w- c:\users\pmsacks\Alex pic House travels.rar

2010-08-16 18:15:59 0 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor

2010-08-15 07:42:56 302080 ----a-w- c:\windows\system32\drivers\srv.sys

2010-08-15 07:42:56 144896 ----a-w- c:\windows\system32\drivers\srv2.sys

2010-08-15 07:40:21 1248768 ----a-w- c:\windows\system32\msxml3.dll

2010-08-15 07:32:33 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys

2010-08-09 13:19:14 0 d-----w- c:\users\pmsacks\appdata\roaming\CometNetwork

==================== Find3M ====================

2010-08-29 06:58:25 319456 ----a-w- c:\windows\DIFxAPI.dll

2010-07-29 15:21:17 113933 ----a-w- c:\windows\system32\drivers\klin.dat

2010-07-29 15:21:16 97549 ----a-w- c:\windows\system32\drivers\klick.dat

2010-07-24 19:26:18 86016 ----a-w- c:\windows\inf\infpub.dat

2010-07-24 19:26:18 143360 ----a-w- c:\windows\inf\infstrng.dat

2010-07-24 19:26:18 143360 ----a-w- c:\windows\inf\infstor.dat

2010-07-21 12:37:10 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-01 18:35:12 228024 ----a-w- c:\windows\system32\klogon.dll

2010-06-03 02:41:44 3600384 ----a-w- c:\windows\system32\GPhotos.scr

2009-12-29 20:02:32 665600 ----a-w- c:\windows\inf\drvindex.dat

2009-08-29 04:14:58 174 --sha-w- c:\program files\desktop.ini

2007-08-27 14:14:38 10342366 ----a-w- c:\program files\Windows6.0-KB938979-x86.msu

2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat

2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat

2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat

2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat

2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat

2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat

2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat

2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat

2010-05-31 19:17:44 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat

2010-05-31 19:17:44 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat

2010-05-31 19:17:44 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat

2009-08-23 04:32:54 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

2009-12-30 15:25:20 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

============= FINISH: 20:10:46,11 ===============

Позволих си да направя и проверка с hijackthis и лилагал лог файла.

mbam-log-2010-08-31 (23-06-31).txt

Attach.txt

Редактирано от ALEXONE™ (преглед на промените)

Версията на MBAM е стара:

4324

Стъпка 1

Моля обновете (update) МВАМ и направете Quick Scan. След като сканирането приключи ще ви се отвори техтов документ. Копирайте съдържанието и го публикувайте със следващият си пост.

Стъпка 2

Следвайте следната инструкция за работа със Security Check:

• Изтеглете Security Check (автор: screen317) от Публикувано изображениеили от Публикувано изображение

и го запишете на десктопа.

• Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.

• Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.

• Копирайте съдържанието с Копирай (Copy) на checkup.txt и с Постави (Paste) го поставете в следващия си коментар.

Стъпка 3

Следвайте следната инструкция за работа с OTL:

• Изтеглете програмата от тук Публикувано изображение и я запазете на десктопа.

• Стартирайте файла Публикувано изображениес двукратен клик на мишката.

• Направете следните настройки които са очертани в червено:

Публикувано изображение

• Под "Custom Scans/Fixes" с Copy/ Paste въведете следната информация от цитата по-долу:

netsvcs
drivers32 /all
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\*.scr
%systemroot%\*._sy
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.wt
%systemroot%\system32\*.ruy
%systemroot%\system32\*.jpg
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%APPDATA%\Update\*.*
%APPDATA%\Microsoft\*.*
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%PROGRAMFILES%\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
%systemroot%\system32\ws2help.dll /md5
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

• Натиснете маркираният в синьо бутон:

Публикувано изображение

• Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Прикачете двата файла в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение).

  • Автор

Извинявам се за пропуска, ето новия, ъпдейтнат лог.

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4521

Windows 6.0.6002 Service Pack 2

Internet Explorer 8.0.6001.18928

1.9.2010 г. 14:09:19

mbam-log-2010-09-01 (14-09-19).txt

Scan type: Quick scan

Objects scanned: 142974

Time elapsed: 39 minute(s), 11 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Стъпка 2

Results of screen317's Security Check version 0.99.5

Windows Vista Service Pack 2 (UAC is enabled)

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Disabled!

Kaspersky Internet Security 2011

Antivirus out of date! (On Access scanning disabled!)

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Java 6 Update 21

Adobe Flash Player 10.0.22.87

Adobe Reader 8.1.2

Out of date Adobe Reader installed!

````````````````````````````````

Process Check:

objlist.exe by Laurent

Windows Defender MSASCui.exe

Windows Defender MSASCui.exe

windows defender MpCmdRun.exe

Kaspersky Lab Kaspersky Internet Security 2011 avp.exe

````````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

От шота е видно, че едната отметка липсва при мен, а заяо идея си нямам.

Публикувано изображение

това са логовете:

OTL logfile created on: 1.9.2010 г. 14:54:06 - Run 4

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\pmsacks\Desktop

Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18928)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: d.M.yyyy 'г.'

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free

4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 105,18 Gb Total Space | 39,33 Gb Free Space | 37,39% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: PMSACKS-PC

Current User Name: pmsacks

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\pmsacks\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)

PRC - C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation)

PRC - C:\Program Files\Sony\VAIO Care\VAIOCareService.exe (Sony Corporation)

PRC - C:\Windows\explorer.exe (Microsoft Corporation)

PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)

PRC - c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)

PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

PRC - c:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)

PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation)

PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)

PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)

PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)

PRC - C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.)

PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)

PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)

PRC - C:\Windows\VM_STI.EXE (BIGDOG)

========== Modules (SafeList) ==========

MOD - C:\Users\pmsacks\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)

MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)

SRV - (WAS) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)

SRV - (W3SVC) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)

SRV - (WPFFontCache_v0400) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)

SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)

SRV - (FontCache) -- C:\Windows\System32\FntCache.dll (Microsoft Corporation)

SRV - (SampleCollector) Intel® -- C:\Program Files\Sony\VAIO Care\collsvc.exe (Intel Corporation)

SRV - (MSSQLServerADHelper100) -- c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE (Microsoft Corporation)

SRV - (sdCoreService) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)

SRV - (AppHostSvc) -- C:\Windows\System32\inetsrv\apphostsvc.dll (Microsoft Corporation)

SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)

SRV - (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS) -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE (Microsoft Corporation)

SRV - (sdAuxService) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)

SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)

SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (MEMSWEEP2) -- C:\Windows\System32\D700.tmp File not found

DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)

DRV - (kl2) -- C:\Windows\System32\drivers\kl2.sys (Kaspersky Lab ZAO)

DRV - (KL1) -- C:\Windows\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO)

DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab ZAO)

DRV - (Revoflt) -- C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)

DRV - (LMIRfsClientNP) -- C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)

DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)

DRV - (motmodem) -- C:\Windows\System32\drivers\motmodem.sys (Motorola)

DRV - (LMIRfsDriver) -- C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)

DRV - (NuidFltr) -- C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)

DRV - (usbaudio) USB Audio Driver (WDM) -- C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)

DRV - (winusb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)

DRV - (PCTCore) -- C:\Windows\system32\drivers\PCTCore.sys (PC Tools)

DRV - (RsFx0103) -- C:\Windows\System32\drivers\RsFx0103.sys (Microsoft Corporation)

DRV - (SBRE) -- C:\Windows\System32\drivers\SBREDrv.sys (Sunbelt Software)

DRV - (sbtis) -- C:\Windows\System32\drivers\sbtis.sys (Sunbelt Software)

DRV - (sbapifs) -- C:\Windows\System32\drivers\sbapifs.sys (Sunbelt Software)

DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)

DRV - (vncmirror) -- C:\Windows\System32\drivers\vncmirror.sys (RealVNC Ltd.)

DRV - (ti21sony) -- C:\Windows\System32\drivers\ti21sony.sys (Texas Instruments)

DRV - (Cdralw2k) -- C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)

DRV - (Cdr4_xp) -- C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)

DRV - (SNC) -- C:\Windows\System32\drivers\SonyNC.sys (Sony Corporation)

DRV - (yukonwlh) -- C:\Windows\System32\drivers\yk60x86.sys (Marvell)

DRV - (igfx) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)

DRV - (ialm) -- C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)

DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)

DRV - (ql2300) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)

DRV - (adp94xx) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)

DRV - (elxstor) -- C:\Windows\system32\drivers\elxstor.sys (Emulex)

DRV - (adpahci) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)

DRV - (uliahci) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)

DRV - (iaStorV) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)

DRV - (adpu320) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)

DRV - (ulsata2) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)

DRV - (vsmraid) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)

DRV - (ql40xx) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)

DRV - (UlSata) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)

DRV - (adpu160m) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)

DRV - (nvraid) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)

DRV - (nfrd960) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)

DRV - (iirsp) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)

DRV - (SiSRaid4) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)

DRV - (nvstor) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)

DRV - (aic78xx) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)

DRV - (arcsas) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)

DRV - (LSI_SCSI) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)

DRV - (SiSRaid2) -- C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)

DRV - (HpCISSs) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)

DRV - (arc) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)

DRV - (iteraid) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)

DRV - (iteatapi) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)

DRV - (LSI_SAS) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)

DRV - (Symc8xx) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)

DRV - (LSI_FC) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)

DRV - (Sym_u3) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)

DRV - (Mraid35x) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)

DRV - (Sym_hi) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)

DRV - (megasas) -- C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)

DRV - (viaide) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)

DRV - (cmdide) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)

DRV - (aliide) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)

DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)

DRV - (BrUsbSer) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)

DRV - (BrFiltUp) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)

DRV - (BrFiltLo) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)

DRV - (BrSerWdm) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)

DRV - (BrUsbMdm) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)

DRV - (HSF_DPV) -- C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)

DRV - (HSFHWAZL) -- C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)

DRV - (winachsf) -- C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)

DRV - (ntrigdigi) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)

DRV - (E1G60) Intel® -- C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)

DRV - (wanatw) WAN Miniport (ATW) -- C:\Windows\System32\drivers\wanatw4.sys (America Online, Inc.)

DRV - (DMICall) -- C:\Windows\System32\drivers\DMICall.sys (Sony Corporation)

DRV - (WimFltr) -- C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)

DRV - (ADM851X) -- C:\Windows\System32\drivers\ADM851X.sys (DAVICOM Semiconductor, Inc. )

DRV - (QCMerced) -- C:\Windows\System32\drivers\lvcm.sys ()

DRV - (LVUSBSta) -- C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.)

DRV - (ZSMC301b) -- C:\Windows\System32\drivers\usbVM31b.sys (VM)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-203263742-2692646269-238311384-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data over 100 bytes]

IE - HKU\S-1-5-21-203263742-2692646269-238311384-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-203263742-2692646269-238311384-1005\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1

IE - HKU\S-1-5-21-203263742-2692646269-238311384-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"

FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="

FF - prefs.js..extensions.enabledItems: [email protected]:1.0.13966

FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009.06.13 07:02:05 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2010.07.24 22:25:26 | 000,000,000 | ---D | M]

[2009.06.14 11:10:18 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Mozilla\Extensions

[2009.06.14 11:24:45 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Mozilla\Firefox\Profiles\w74jbost.default\extensions

[2009.06.14 11:24:44 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\pmsacks\AppData\Roaming\Mozilla\Firefox\Profiles\w74jbost.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

O1 HOSTS File: ([2010.07.22 09:27:07 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)

O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)

O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)

O4 - HKLM..\Run: [avp] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)

O4 - HKLM..\Run: [bigDogPath] C:\Windows\VM_STI.EXE (BIGDOG)

O4 - HKLM..\Run: [iSBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)

O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-203263742-2692646269-238311384-1005..\Run: [iSUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)

O4 - HKU\S-1-5-21-203263742-2692646269-238311384-1005..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-203263742-2692646269-238311384-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-203263742-2692646269-238311384-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-203263742-2692646269-238311384-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()

O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - Reg Error: Value error. File not found

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)

O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 91.193.156.4 91.193.156.5

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO)

O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)

O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)

O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)

O24 - Desktop WallPaper: C:\Users\pmsacks\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp

O24 - Desktop BackupWallPaper: C:\Users\pmsacks\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006.09.19 00:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.08.23 16:04:17 | 000,000,000 | ---D | C] -- C:\Users\pmsacks\Desktop\New Folder

[2010.08.16 21:18:38 | 000,000,000 | ---D | C] -- C:\Users\pmsacks\AppData\Local\Microsoft Corporation

[2010.08.16 21:15:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Windows 7 Upgrade Advisor

[2010.08.10 13:29:02 | 000,000,000 | ---D | C] -- C:\Users\pmsacks\Desktop\IPB_2.3.6__Arslan178.info

[2010.08.09 16:19:14 | 000,000,000 | ---D | C] -- C:\Users\pmsacks\AppData\Roaming\CometNetwork

[2010.08.09 16:19:14 | 000,000,000 | ---D | C] -- C:\Users\pmsacks\AppData\Local\CometNetwork

========== Files - Modified Within 30 Days ==========

[2010.09.01 15:13:07 | 000,000,422 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{B6C1BFDC-B045-40A2-9D0B-976C849B0355}.job

[2010.09.01 14:53:40 | 007,188,480 | ---- | M] () -- C:\Users\pmsacks\NTUSER.DAT

[2010.09.01 14:36:38 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

[2010.09.01 14:36:38 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

[2010.09.01 14:33:09 | 000,869,051 | ---- | M] () -- C:\Users\pmsacks\Desktop\SecurityCheck.exe

[2010.09.01 10:36:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2010.08.31 20:05:36 | 000,525,824 | ---- | M] () -- C:\Users\pmsacks\Desktop\dds.scr

[2010.08.31 16:03:14 | 000,857,910 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI

[2010.08.31 16:03:14 | 000,707,582 | ---- | M] () -- C:\Windows\System32\perfh009.dat

[2010.08.31 16:03:14 | 000,143,486 | ---- | M] () -- C:\Windows\System32\perfc009.dat

[2010.08.31 15:56:30 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl

[2010.08.31 15:56:12 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2010.08.31 15:53:53 | 000,065,536 | -HS- | M] () -- C:\Users\pmsacks\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf

[2010.08.31 15:53:52 | 000,524,288 | -HS- | M] () -- C:\Users\pmsacks\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms

[2010.08.31 15:52:35 | 003,771,194 | -H-- | M] () -- C:\Users\pmsacks\AppData\Local\IconCache.db

[2010.08.31 09:34:21 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Windows 7 Upgrade Advisor.lnk

[2010.08.27 22:13:11 | 000,174,799 | ---- | M] () -- C:\Users\pmsacks\Desktop\9252838-lg.jpg

[2010.08.26 22:59:48 | 000,055,296 | ---- | M] () -- C:\Users\pmsacks\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010.08.19 10:41:04 | 2402,801,469 | ---- | M] () -- C:\Users\pmsacks\Alex pic House travels.rar

[2010.08.17 00:59:04 | 000,099,367 | ---- | M] () -- C:\test.xml

[2010.08.02 21:03:51 | 000,043,370 | ---- | M] () -- C:\Users\pmsacks\Desktop\Untitled.jpg

========== Files Created - No Company Name ==========

[2010.09.01 14:33:05 | 000,869,051 | ---- | C] () -- C:\Users\pmsacks\Desktop\SecurityCheck.exe

[2010.08.31 20:05:04 | 000,525,824 | ---- | C] () -- C:\Users\pmsacks\Desktop\dds.scr

[2010.08.27 22:14:49 | 000,174,799 | ---- | C] () -- C:\Users\pmsacks\Desktop\9252838-lg.jpg

[2010.08.26 23:16:32 | 000,063,467 | ---- | C] () -- C:\Users\pmsacks\Desktop\Case.39.2009.DvDScR.XviD-ExtraScene RG.srt

[2010.08.19 09:28:00 | 2402,801,469 | ---- | C] () -- C:\Users\pmsacks\Alex pic House travels.rar

[2010.08.16 21:16:01 | 000,001,984 | ---- | C] () -- C:\Users\Public\Desktop\Windows 7 Upgrade Advisor.lnk

[2010.08.02 21:03:50 | 000,043,370 | ---- | C] () -- C:\Users\pmsacks\Desktop\Untitled.jpg

[2009.10.07 19:28:45 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll

[2009.05.14 15:29:30 | 000,008,520 | ---- | C] () -- C:\Windows\System32\ractrlkeyhook.dll

[2008.02.24 19:56:18 | 000,077,824 | ---- | C] () -- C:\Windows\System32\hccutils.dll

[2008.02.24 19:56:18 | 000,061,440 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll

[2008.02.24 19:56:18 | 000,053,248 | ---- | C] () -- C:\Windows\System32\oemdspif.dll

[2008.02.24 19:56:17 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1151.dll

[2007.11.07 16:07:02 | 000,000,221 | ---- | C] () -- C:\Windows\NCLogConfig.ini

[2007.07.11 16:30:39 | 001,317,152 | ---- | C] () -- C:\Windows\System32\drivers\lvcm.sys

[2007.07.11 16:30:39 | 000,009,255 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini

[2007.05.08 12:59:20 | 000,532,480 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Sony.dll

[2007.02.24 21:59:14 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI

[2006.11.02 15:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll

[2006.11.02 10:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010.06.13 08:00:55 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Auslogics

[2010.08.26 22:47:59 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\BSplayer

[2009.10.29 16:10:03 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\BSplayer Pro

[2010.08.09 16:19:14 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\CometNetwork

[2010.03.28 15:25:56 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Facebook

[2009.10.23 17:35:48 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\GHISLER

[2009.06.15 16:32:07 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\ICAClient

[2008.10.01 12:01:35 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Image Zone Express

[2010.01.19 14:50:58 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Notepad++

[2007.07.06 15:14:13 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\PeerNetworking

[2007.08.01 12:45:39 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Printer Info Cache

[2007.08.23 14:46:54 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\SmartDraw

[2010.06.17 15:59:24 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\Tific

[2010.05.13 14:01:34 | 000,000,000 | ---D | M] -- C:\Users\pmsacks\AppData\Roaming\uTorrent

[2010.08.31 15:54:24 | 000,032,566 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

[2010.09.01 15:13:07 | 000,000,422 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{B6C1BFDC-B045-40A2-9D0B-976C849B0355}.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:DFC5A2B2

@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:63238B95

< End of report >

Extras.txt

OTL Extras logfile created on: 1.9.2010 г. 14:54:06 - Run 4

OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\pmsacks\Desktop

Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18928)

Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: d.M.yyyy 'г.'

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 51,00% Memory free

4,00 Gb Paging File | 3,00 Gb Available in Paging File | 69,00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files

Drive C: | 105,18 Gb Total Space | 39,33 Gb Free Space | 37,39% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: PMSACKS-PC

Current User Name: pmsacks

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe File not found

[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)

htmlfile [edit] -- Reg Error: Key error.

https [open] -- Reg Error: Key error.

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

"VistaSp1" = Reg Error: Unknown registry data type -- File not found

"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{03DECCAD-65A3-4609-9DFA-98EB29E47F73}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{079E0414-2312-4A68-A3B3-AECDA4C43A88}" = rport=2869 | protocol=6 | dir=out | app=system |

"{085F3C34-D909-471B-9C73-7ED3F01E4DEE}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{095AD5DB-FAA4-4493-87EE-4778E83098D3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{19F111F3-12AA-4D73-9D88-7E5C9E15CFB7}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{21904915-5C5C-4738-98CC-3AF89CBC6707}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{274AA65F-FB7B-45A5-9663-E9DF0600A302}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{2D3F01CF-62F8-43CF-B5BB-8D8A81D4393D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{3244F6BC-736B-4187-87B3-F5335D9F492B}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{324AAF92-8C7E-412D-AC83-9A219036BF4B}" = lport=2869 | protocol=6 | dir=in | app=system |

"{34344FC6-DF68-4F9A-90D4-88791A9F7FF1}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{414E29C3-9667-439F-9F82-0DB8F77E5F5A}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{48DBFC4C-E95D-4C4F-926E-10587FA2FB5D}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{522BE19E-7E16-4C40-979F-FD1A3A670F7A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{53F1DC3A-99EF-4955-977F-98E03B98D7C8}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{57416AC4-4FA5-4125-B5ED-53A74B39CE70}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

"{6408674B-36A5-491C-90C0-331E34865560}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{771E2179-1CB1-4610-89C6-A6DB475763B4}" = lport=2869 | protocol=6 | dir=in | app=system |

"{80FF1206-BABB-49CB-8932-FCEBC20D7976}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{8519C654-A1D7-4867-B6F3-E0C7B1E1BE2A}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |

"{8F0D5643-F826-40E6-9E63-8AA3476D8DAC}" = lport=10243 | protocol=6 | dir=in | app=system |

"{8FFED2E9-799F-4385-AFF7-FFD26F9931C7}" = rport=10243 | protocol=6 | dir=out | app=system |

"{9A18527A-696B-46EC-B74C-427361671779}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{A946AFA8-8232-45DE-9DC1-5FF33BBB7DEA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{AAEF747A-1A2E-46E4-919A-769EEB2DDB39}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{B1841EA4-01F0-48A8-ADB4-1CD50149B973}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{B3DFCC0D-32AA-4E02-BDFE-8D5D501381BD}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=%systemroot%\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe |

"{CD6E1FCA-36D6-4EBD-BA71-43BD99E9740D}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{D9467B3B-8B7E-4697-98BD-B50C2E89D6AF}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |

"{D9CCC334-DA89-4175-9271-A280C0CFD777}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{DA5CAFA5-7216-4B98-9416-17AB9F6AABE0}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{DB061537-CD71-4433-B38A-311E8BEA0966}" = lport=12345 | protocol=6 | dir=in | name=motorola helper |

"{DB0CF38F-23CE-43FC-82FE-748585B5F5CE}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |

"{FB76E796-E261-4DE4-B107-FD059BE354B8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{FCADD9B3-7B70-4EAC-BE71-E3164A06254D}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{16A25056-97B0-4059-A76B-DFB7071B4282}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{29F678CB-361A-4173-A84D-61F724145299}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{2FB12362-12C7-4446-9B07-1F92B140DE1B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{386E9F76-6387-441F-8290-E5B6381999B8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{39521C5D-1B27-40BC-84E4-F08955481084}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{43C7CA55-C732-47BD-8993-21A73C0E6577}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{4EC60089-5F11-4C08-9E2D-82560FF40632}" = protocol=6 | dir=out | app=system |

"{5C7E6F89-7468-4D54-9449-5AB6D230F10F}" = protocol=58 | dir=in | [email protected],-148 |

"{6539706F-57C6-45E2-B924-FA32A6F03114}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{8AD14E41-E0E9-4B9D-945B-1457B68ABFE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{910093B9-BD97-40FE-9CB8-3522833C639B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{9DE7A48A-EA23-44A6-B1FD-7BBB26DF0CCB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{B8301703-4B40-4B78-B8D2-B4B5DF02F5BE}" = dir=in | app=c:\program files\skype\phone\skype.exe |

"{D4996661-332F-45E0-912A-8853B6C4A5B2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{F8CC9AE2-CDBA-4B11-A425-0BA7B0A949F5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{FC9745F2-AA26-4015-AB07-7153FD2B7D17}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |

"TCP Query User{51D2EB8F-7702-4415-9460-22021CA698A2}C:\program files\totalcmd\totalcmd.exe" = protocol=6 | dir=in | app=c:\program files\totalcmd\totalcmd.exe |

"TCP Query User{8532E55A-E11B-4D99-A57A-B53955709A3C}C:\program files\totalcmd\totalcmd.exe" = protocol=6 | dir=in | app=c:\program files\totalcmd\totalcmd.exe |

"TCP Query User{CA62ECEE-A6BA-4B8F-A1A1-551FAF749028}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |

"TCP Query User{D7A2C7AE-78EE-404E-A1AA-0490006326A4}C:\program files\bitcomet\bitcomet.exe" = protocol=6 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |

"TCP Query User{DCE64B30-5C34-49F9-8992-8D01071EE94A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

"UDP Query User{0DE63AA8-9B6D-47BB-B326-95E40297CD43}C:\program files\totalcmd\totalcmd.exe" = protocol=17 | dir=in | app=c:\program files\totalcmd\totalcmd.exe |

"UDP Query User{46665569-9109-4C34-9D7B-AEBC13A07449}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |

"UDP Query User{4F419DDE-EE59-4468-B5D8-CD0191029755}C:\program files\bitcomet\bitcomet.exe" = protocol=17 | dir=in | app=c:\program files\bitcomet\bitcomet.exe |

"UDP Query User{7E839C9D-BB0D-42FC-8C74-380E479268E5}C:\program files\totalcmd\totalcmd.exe" = protocol=17 | dir=in | app=c:\program files\totalcmd\totalcmd.exe |

"UDP Query User{BA0570CF-E618-4ACF-8AFE-4C827FC170BA}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up

"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK

"{223A0070-C924-48E3-AEB6-2E06CC835CC0}" = VAIO Care

"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java 6 Update 21

"{27B6D024-FD7E-4A88-BC17-5AFBE33EC072}" = Microsoft F# Runtime for Silvelight 4

"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility

"{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}" = VAIO Care

"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile

"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2

"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{558358E5-E4F3-4374-BA1D-26FF39EF87D9}" = Microsoft Silverlight 4 Tools for Visual Studio 2010

"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites

"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011

"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.2.3

"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works

"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{801B0DA3-A3FF-46CC-B97F-D76D510AF5AE}" = Microsoft Silverlight 4 SDK

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8BCD7AE7-F713-4D50-BAB9-7839B9386870}" = ImageShack Uploader 2.2.0

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007

"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector

"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO

"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable

"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor

"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2

"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2

"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel

"7-Zip" = 7-Zip 9.13 beta

"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Adobe Shockwave Player" = Adobe Shockwave Player 11.5

"AvantBrowser" = Avant Browser (remove only)

"BitComet" = BitComet 1.05

"BSPlayerf" = BS.Player FREE

"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09

"CometBird (3.6.8)" = CometBird (3.6.8)

"HDMI" = Intel® Graphics Media Accelerator Driver

"HijackThis" = HijackThis 2.0.0

"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0

"Notepad++" = Notepad++

"OpenMu Season3 Episode 1" = OpenMu Season3 Episode 1

"Picasa 3" = Picasa 3

"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.4

"Spyware Doctor" = Spyware Doctor 6.1

"STANDARDR" = Microsoft Office Standard 2007

"Totalcmd" = Total Commander (Remove or Repair)

"ViewpointMediaPlayer" = Viewpoint Media Player

"Winamp" = Winamp

"WinRAR archiver" = WinRAR archiver

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-203263742-2692646269-238311384-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Facebook Plug-In" = Facebook Plug-In

"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]

Error - 14.8.2010 г. 08:30:34 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4,

faulting module avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4, exception

code 0xc00000fd, fault offset 0x0010f3df, process id 0x1110, application start time

0x01cb3ba4034ea480.

Error - 18.8.2010 г. 06:34:30 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application svchost.exe_Schedule, version 6.0.6001.18000,

time stamp 0x47918b89, faulting module ntdll.dll, version 6.0.6002.18005, time

stamp 0x49e03821, exception code 0xc0000374, fault offset 0x000afaf8, process id

0x4f4, application start time 0x01cb3e97ac968a4e.

Error - 18.8.2010 г. 07:40:40 | Computer Name = pmsacks-PC | Source = Application Hang | ID = 1002

Description = The program avant.exe version 11.8.0.3 stopped interacting with Windows

and was closed. To see if more information about the problem is available, check

the problem history in the Problem Reports and Solutions control panel. Process

ID: 1284 Start Time: 01cb3ec981d937d6 Termination Time: 49

Error - 18.8.2010 г. 16:40:23 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4,

faulting module avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4, exception

code 0xc00000fd, fault offset 0x0010f3df, process id 0xae0, application start time

0x01cb3efa5c50b3d0.

Error - 19.8.2010 г. 09:40:21 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4,

faulting module avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4, exception

code 0xc0000005, fault offset 0x0010f3c0, process id 0x8e0, application start time

0x01cb3f7f5da8c850.

Error - 25.8.2010 г. 13:49:14 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4,

faulting module avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4, exception

code 0xc00000fd, fault offset 0x0010f3df, process id 0x12fc, application start time

0x01cb4473e6b41bfd.

Error - 25.8.2010 г. 14:26:30 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4,

faulting module avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4, exception

code 0xc0000005, fault offset 0x0010f3b3, process id 0x374, application start time

0x01cb44548310d94d.

Error - 28.8.2010 г. 08:52:38 | Computer Name = pmsacks-PC | Source = Application Error | ID = 1000

Description = Faulting application avantab.exe, version 11.8.0.3, time stamp 0x4c1f3bb4,

faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code

0xc0000005, fault offset 0x00000000, process id 0x14bc, application start time 0x01cb46afc3292dc5.

Error - 30.8.2010 г. 04:05:48 | Computer Name = pmsacks-PC | Source = EventSystem | ID = 4609

Description =

Error - 31.8.2010 г. 05:37:56 | Computer Name = pmsacks-PC | Source = EventSystem | ID = 4609

Description =

[ Media Center Events ]

Error - 30.10.2009 г. 03:54:13 | Computer Name = pmsacks-PC | Source = MCUpdate | ID = 0

Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]

Error - 31.8.2010 г. 02:27:52 | Computer Name = pmsacks-PC | Source = Service Control Manager | ID = 7000

Description =

Error - 31.8.2010 г. 02:29:36 | Computer Name = pmsacks-PC | Source = Service Control Manager | ID = 7022

Description =

Error - 31.8.2010 г. 02:29:46 | Computer Name = pmsacks-PC | Source = DCOM | ID = 10005

Description =

Error - 31.8.2010 г. 02:30:38 | Computer Name = pmsacks-PC | Source = Service Control Manager | ID = 7001

Description =

Error - 31.8.2010 г. 08:52:44 | Computer Name = pmsacks-PC | Source = DCOM | ID = 10010

Description =

Error - 31.8.2010 г. 08:57:33 | Computer Name = pmsacks-PC | Source = Service Control Manager | ID = 7000

Description =

Error - 31.8.2010 г. 08:58:24 | Computer Name = pmsacks-PC | Source = Service Control Manager | ID = 7022

Description =

Error - 1.9.2010 г. 03:36:39 | Computer Name = pmsacks-PC | Source = Service Control Manager | ID = 7011

Description =

Error - 1.9.2010 г. 03:36:51 | Computer Name = pmsacks-PC | Source = ipnathlp | ID = 31004

Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This

may indicate that the system is low on virtual memory, or that the memory manager

has encountered an internal error.

Error - 1.9.2010 г. 03:37:06 | Computer Name = pmsacks-PC | Source = ipnathlp | ID = 31004

Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This

may indicate that the system is low on virtual memory, or that the memory manager

has encountered an internal error.

< End of report >

Отметката липсва, защото сте с 32-битова система.

Стъпка 1

Стартирайте пак OTL.exe и с Copy/ Paste под колонката Custom Scans/Fixes въведете скриптовия текст от цитата по-долу, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта!

:OTL
DRV - (MEMSWEEP2) -- C:\Windows\System32\D700.tmp File not found
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:63238B95

:Reg
[-HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe File not found

[-HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe File not found

:Commands
[purity]
[resethosts]
[emptytemp]
[Reboot]

След като въведете скрипта от цитата по-горе натиснете бутона, маркиран в червено:

Публикувано изображение

Ще се създаде лог файл. Копирайте и поставете този файл в следващия си коментар.

Стъпка 2

Следвайте следната инструкция за работа с RKUnHooker:

  • Изтеглете този файл на десктопа.
  • Стартирайте RKUnhookerLE.exe, отидете на Report и маркирайте Drivers, Stealth Code, Files и Code Hooks. Демаркирайте останалите и натиснете ОК. Снимка:

    Публикувано изображение

  • Изчакайте програмата да завърши работа. След това кликнете на File, после Save Report. Запазете (Save as) файла с име report.txt на десктопа. Прикачете го в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение).
  • Автор

каква да направя, да разреша ли на кашперски това?

Публикувано изображение

Стъпка 1

резултата е следния

Публикувано изображение

По време на сканиранията е желателно програмите за защита да се изключват. Разрешете изпълнението. Сега имате ли други проблеми ? Ще изчакам лога от RKUnHook. А при стъпка 1 появи ли ви се техтов файл ?

  • Автор

Преди сканирането получих следните съобщения.

Публикувано изображение

Публикувано изображение

Ето го и лога от скана.

RkU Version: 3.8.388.590, Type LE (SR2)

==============================================

OS Name: Windows Vista

Version 6.0.6002 (Service Pack 2)

Number of processors #2

==============================================

>Drivers

==============================================

0x8F40C000 C:\Windows\system32\DRIVERS\igdkmd32.sys 7008256 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)

0x8520F000 C:\Windows\system32\DRIVERS\kl1.sys 5382144 bytes (Kaspersky Lab ZAO, Kaspersky Unified Driver)

0x8421C000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)

0x8421C000 PnpManager 3903488 bytes

0x8421C000 RAW 3903488 bytes

0x8421C000 WMIxWDM 3903488 bytes

0x9AC40000 Win32k 2109440 bytes

0x9AC40000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver)

0x8AC0C000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver)

0x8A805000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)

0x90206000 C:\Windows\system32\DRIVERS\VSTDPV3.SYS 1064960 bytes (Conexant Systems, Inc., HSF_DP driver)

0x8AA04000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)

0x8F002000 C:\Windows\system32\DRIVERS\athr.sys 946176 bytes (Atheros Communications, Inc., Atheros Extensible Wireless LAN device driver)

0x804DF000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)

0xB0E0D000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)

0x8FC01000 C:\Windows\system32\drivers\ti21sony.sys 823296 bytes (Texas Instruments, ti21sony.sys)

0x9030A000 C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 733184 bytes (Conexant Systems, Inc., HSF_CNXT driver)

0x908E5000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)

0x8FABB000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel)

0x8FB68000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)

0x90407000 C:\Windows\system32\DRIVERS\klif.sys 540672 bytes (Kaspersky Lab, Klif Mini-Filter [fre_wlh_x86])

0x85731000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)

0x80740000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)

0x80415000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)

0xADC05000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)

0xADD75000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)

0x80610000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)

0x90567000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)

0x857BA000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)

0x8049E000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)

0x8FD97000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)

0x8ABAB000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver)

0x8F0F4000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)

0x9080E000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)

0x807B1000 C:\Windows\system32\DRIVERS\VSTAZL3.SYS 245760 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)

0x8A93B000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)

0xADCFD000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)

0x8AD1C000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)

0x8AB76000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)

0x8AB18000 C:\Windows\system32\DRIVERS\yk60x86.sys 212992 bytes (Marvell, NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller)

0x845D5000 ACPI_HAL 208896 bytes

0x845D5000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)

0x806D2000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)

0x905AF000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)

0x90537000 C:\Windows\system32\drivers\sbtis.sys 196608 bytes (Sunbelt Software, Sunbelt TDI Inspection System)

0x8FD68000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)

0x8066F000 C:\Windows\system32\DRIVERS\pcmcia.sys 184320 bytes (Microsoft Corporation, PCMCIA Bus Driver)

0x8A976000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))

0x8A910000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)

0x8AB4C000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)

0x909A5000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)

0x8FCEF000 C:\Windows\system32\DRIVERS\Apfiltr.sys 163840 bytes (Alps Electric Co., Ltd., Alps Touch Pad Driver)

0x8AD6C000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)

0x805C7000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)

0xADD4E000 C:\Windows\System32\DRIVERS\srv2.sys 159744 bytes (Microsoft Corporation, Smb 2.0 Server driver)

0xB0F28000 C:\Windows\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)

0x8A9A3000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)

0x8F16A000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))

0x80714000 C:\Windows\system32\drivers\PCTCore.sys 143360 bytes (PC Tools, PC Tools KDS Core Driver)

0x8ADA4000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)

0xADCBD000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)

0x8FD46000 C:\Windows\system32\DRIVERS\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)

0xADCDE000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)

0x806B4000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)

0xADC72000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)

0x8AAEE000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)

0x908A5000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)

0xADC8F000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)

0x8FD2C000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)

0xADD36000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)

0x90855000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)

0x8FDE3000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)

0xB0F4E000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)

0x905E1000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)

0x90507000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)

0xADCA8000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)

0x8F1B0000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)

0x904A4000 C:\Windows\system32\drivers\SBREdrv.sys 86016 bytes (Sunbelt Software, Anti-Rootkit Engine)

0xB0F01000 C:\Windows\system32\DRIVERS\WUDFRd.sys 86016 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Reflector)

0x8F19C000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)

0x90523000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)

0x8FCD1000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)

0x909D9000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)

0x903D8000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)

0xB0F16000 C:\Windows\system32\DRIVERS\WUDFPf.sys 73728 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)

0x8AD93000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)

0x8F1EE000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)

0x80485000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)

0x80704000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)

0x90995000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)

0x8069C000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)

0x8F141000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)

0x908C0000 C:\Windows\system32\DRIVERS\sbapifs.sys 65536 bytes (Sunbelt Software, Sunbelt ActiveProtection Filter)

0x8F1C5000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)

0x8AB09000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)

0x90896000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)

0x8AD5D000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)

0x805EE000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)

0x8F18D000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)

0x8F132000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)

0x80601000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)

0x8F151000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)

0x9AE80000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)

0x903CA000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)

0x904F0000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)

0x80661000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)

0x9086C000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)

0x903BD000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)

0x8F1E1000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)

0x857AD000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)

0xB0EF5000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)

0x904C9000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)

0x8FB5C000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)

0x90879000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes

0x8FCE4000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)

0x8FD20000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)

0x904E5000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)

0x8F15F000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)

0x8FDD8000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)

0x8ADEE000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)

0x8F0E9000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)

0x80400000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)

0x9088C000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)

0xADDDB000 C:\Windows\system32\drivers\LMIRfsDriver.sys 40960 bytes (LogMeIn, Inc., LogMeIn Rfs Drivemap Driver)

0x8F1D7000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)

0x909CF000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)

0x9084A000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)

0xB0EEB000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)

0x8ADC5000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)

0x9048D000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)

0x8FD17000 C:\Windows\system32\DRIVERS\klmouflt.sys 36864 bytes (Kaspersky Lab, KLMOUFLT Mouse Device Filter [fre_wlh_x86])

0xB0F86000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)

0x80737000 C:\Windows\System32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)

0x904FE000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)

0x9AE60000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)

0x8AC00000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)

0x85200000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)

0x806AC000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)

0x80496000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)

0x90884000 C:\Windows\System32\Drivers\dump_atapi.sys 32768 bytes

0x905F7000 C:\Windows\system32\DRIVERS\klim6.sys 32768 bytes (Kaspersky Lab ZAO, Kaspersky Lab Intermediate Network Driver)

0x805BF000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)

0x904D5000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)

0x904DD000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)

0x8AD55000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)

0x9049D000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)

0x904C2000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)

0x8065A000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)

0x8040E000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)

0x90496000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)

0x8FCCA000 C:\Windows\System32\Drivers\SonyNC.sys 28672 bytes (Sony Corporation, Sony Firmware Extension Parser driver)

0x9051D000 C:\Windows\system32\DRIVERS\kl2.sys 24576 bytes (Kaspersky Lab ZAO, Kaspersky Unified Driver)

0x8FDFA000 C:\Windows\system32\DRIVERS\wanatw4.sys 24576 bytes (America Online, Inc., Wan Miniport (ATW))

0x8ADF9000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)

0x85209000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)

0x8F1D5000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)

0x9048B000 C:\Windows\System32\Drivers\Cdr4_xp.SYS 4096 bytes (Sonic Solutions, CDR4 CD and DVD Place Holder Driver (see PxHelp))

0x9048C000 C:\Windows\System32\Drivers\Cdralw2k.SYS 4096 bytes (Sonic Solutions, CDRAL Place Holder Driver (see PxHelp))

0x90854000 C:\Windows\system32\DRIVERS\DMICall.sys 4096 bytes (Sony Corporation, Windows 2000 DMI Call Kernel Driver)

0x8FD45000 C:\Windows\system32\DRIVERS\lmimirr.sys 4096 bytes (LogMeIn, Inc., LogMeIn Mirror Miniport Driver)

0x8FD67000 C:\Windows\system32\DRIVERS\vncmirror.sys 4096 bytes (RealVNC Ltd., VNC Mirror Miniport)

==============================================

>Stealth

==============================================

==============================================

>Files

==============================================

==============================================

>Hooks

==============================================

ntkrnlpa.exe+0x000A87AA, Type: Inline - RelativeJump 0x842C47AA-->842C47B1 [ntkrnlpa.exe]

ntkrnlpa.exe+0x000ACC14, Type: Inline - RelativeJump 0x842C8C14-->842C8C5E [ntkrnlpa.exe]

ntkrnlpa.exe+0x000ACCB4, Type: Inline - RelativeJump 0x842C8CB4-->842C8CFE [ntkrnlpa.exe]

ntkrnlpa.exe+0x000ACD40, Type: Inline - RelativeJump 0x842C8D40-->842C8D8A [ntkrnlpa.exe]

ntkrnlpa.exe+0x000ACE47, Type: Inline - RelativeJump 0x842C8E47-->842C8E04 [ntkrnlpa.exe]

[2148]ybrowser.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x76919725-->00000000 [ybrowser.exe]

[2148]ybrowser.exe-->wininet.dll-->HttpSendRequestW, Type: Inline - RelativeJump 0x762CFABE-->00000000 [ybrowser.exe]

[2148]ybrowser.exe-->wininet.dll-->InternetSetCookieExW, Type: Inline - RelativeJump 0x762E5F85-->00000000 [ybrowser.exe]

[3568]ybrowser.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x76919725-->00000000 [ybrowser.exe]

[3568]ybrowser.exe-->wininet.dll-->HttpSendRequestW, Type: Inline - RelativeJump 0x762CFABE-->00000000 [ybrowser.exe]

[3568]ybrowser.exe-->wininet.dll-->InternetSetCookieExW, Type: Inline - RelativeJump 0x762E5F85-->00000000 [ybrowser.exe]

Системата не ми позволява, да прикачвам файлове затова ги копирам дирекно тук в темата.

  • Автор
http://www.virustotal.com/file-scan/report.html?id=3ecde27186e8ebc7a6a6b7ee66ee5de84ddbd44e2df90ea7acadd4a747fa3117-1283358995 http://www.virustotal.com/file-scan/report.html?id=135dd05678c8997b45982d77298dbdd98061c9d4fe43d77866846012eb061a04-1283359189 avantab.exe такъв файл няна в директорията C:\Program Files\Avant Browser Между другото преди няколко часа ъпдейтнах авант браузера до последна версия.
  • Автор

Да кашперски не може да реши проблема, и мисля, че той се задълбочава.

Публикувано изображение

След рестарт се появи и това

Публикувано изображение

Ами как няма да ви се показват такива съобщения като използвате trial reset за Kaspersky! Аз не виждам други проблеми.

Стъпка 3

Деинсталирайте OTL. Ето как:

Стартирайте OTL.exe още веднъж и натиснете бутона CleanUp!

Публикувано изображение

При дeинсталацията на OTL ще бъдат почистени някои инструменти и файлове, които използвахме досега. Ще последва рестарт на Windows.

  • Автор

Какво разбирате под trial reset за Kaspersky!?

  • Автор

Тоест решение на проблема е нов Кашперки или друга антивирусна така ли? Кода за KIS 2011 до колкото зная е промоционален и ми беше предоставен от потребител на форума.

Редактирано от ALEXONE™ (преглед на промените)

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.