Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Вирyс [РЕШЕН]

Featured Replies

Здравейте. Имам следния проблем в дял D имах папки със снимки, музика, филми и разни други които изчезнаха но неса изтрити защото Malwarebytes' Anti-Malware сканира информацияра в тях. Някой знае ли как да се справя с проблема? Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5128 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 11/17/2010 7:16:38 PM mbam-log-2010-11-17 (19-16-38).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 174803 Time elapsed: 12 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 8 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 13 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\b39o.dll (Adware.Rugo) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\bho.msnplayer (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{d94d57b6-ea37-46a9-bbc4-8a2872e1d5ce} (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{c350ff9e-710b-4895-981c-9151a0c9244e} (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b1108084-aa13-4723-abaf-09d533aa6aae} (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b1108084-aa13-4723-abaf-09d533aa6aae} (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b1108084-aa13-4723-abaf-09d533aa6aae} (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bho.msnplayer.1 (Adware.Rugo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{86aefbe8-763f-0647-899c-a93278894599} (Trojan.Agent) -> Delete on reboot. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\Application Data\t (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad\da8b0920d2 (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\b39o.dll (Adware.Rugo) -> Delete on reboot. C:\WINDOWS\440u.bmp (Extension.Mismatch) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\cml1.tmp (Adware.BHO) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\a1521.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\b1521.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\k1521.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\p1521.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\r1521.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad\361-TVC.lz (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad\da8b0920d2\800-600.swf (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad\da8b0920d2\blank.gif (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad\da8b0920d2\click.js (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\t\ad\da8b0920d2\index.htm (Trojan.Agent) -> Quarantined and deleted successfully.

Редактирано от nologo (преглед на промените)

  • Отговори 70
  • Прегледи 8,1k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • готово ето файловете

  • Да, възможно е. Досега не сме използвали всички средства за почистването на заразите. Надявам се, че ще успеем.

  • Благодаря за проявеното търпение. Дава ми следната грешка Cannot import C:\Documents and Settings\Lugosss\Desktop\RecycleRestore\RecycleRestore.reg: Not all data was successfuly written to the registr

  • Автор

И още нещо да добавя постоянно ми излиза този прозорец

  • Автор

Какво да направя да ми обърнете малко внимание ?

Какво да направя да ми обърнете малко внимание ?

Изчакай от HJT не са 24 часа на разположение.

  • Автор

Изчакай от HJT не са 24 часа на разположение.

Ок мерси

Какво да направя да ми обърнете малко внимание ?

Не си изпълнил стъпка 4 от темата, която ти посочиха вчера в една друга твоя тема, която ще заключа сега. Очаквам да сканираш с DDS и да прикачиш логовете (DDS.txt и Attach.txt) в следващия си коментар.
  • Автор

Не си изпълнил стъпка 4 от темата, която ти посочиха вчера в една друга твоя тема, която ще заключа сега. Очаквам да сканираш с DDS и да прикачиш логовете (DDS.txt и Attach.txt) в следващия си коментар.

надявам се този път да съм направил всичко както трябва

Хм, доста си загазил. Като начало деинсталирай Kaspersky, защото използваш стара версия. След това ще трябва да продължим с ComboFix, eто инструкция:

Следвайте следните стъпки за работа с ComboFix:

1. Изтеглете ComboFix от следния мирър: BleepingComputer.

След изтегляне на файла го запишете (бутон Save -> Save as) ComboFix на вашия десктоп, снимка:

Публикувано изображение

След като изтеглите ComboFix на десктопа, иконката на програмата би трябвало да изглежда така:

Публикувано изображение

2. Затворете всички работещи приложения или отворени прозорци. Прекратете временно работата на антивирусната програма и на други програми за сигурност, ако има такива.

3. Стартирайте с двоен клик ComboFix.exe (ако не се стартира, преименувайте файла на lugos.exe и опитайте пак). За целта използвайте YES, за да се съгласите с условията за използване на програмата. Важно: след като се стартира ComboFix не бива да се движи мишката или да се кликва върху отворения прозорец на програмата. Просто търпеливо оставете ComboFix да си свърши работата, без да използвате компютъра за други цели.

4. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката, моля да прочетете това: Manually restoring the Internet connection section.

5. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad, виж снимката:

Публикувано изображение

Копирайте (Copy) и поставете (Paste) съдържанието на лога в следващия си коментар.

  • Автор

Здравeйте отново. В момента съm на работа и не съм на моя компютър. Само искам да кажа че, в дял С имам инсталиран само Mozilla Firefox ,а Kaspersky деинсталирах преди да пусна логовете: mbam-log-2010-11-17 (23-55-24) DDS Attach Кото се прибера в нас ще продължа с инструкциите които ми пратихте за ComboFix. Благодаря ви за отделеното време.

  • Автор

Излезе ми тази грешка и се рестартира

Сега отворете Notepad.exe и с copy/paste въведете следната информация:

Killall::

File::

c:\windows\system32\taofx19.dll

c:\documents and settings\All Users\Start Menu\Programs\Startup\EIM.vbe

c:\documents and settings\All Users\Start Menu\Programs\Startup\va0aa8cbe5bd.exe

c:\windows\system32\322d.exe

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AEDB5938-D4DF-4C0F-BC87-A7D9C2F259B0}]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"_nltide_2"=-

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\Program Files\\0aa8cbe5\\fia\\a8cbe5cduec.exe"=-

Запазете файла с име CFScript и го провлачете и пуснете в Combofix, както е показано на снимката:

Публикувано изображение

Забележка: По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си коментар.

  • Автор

Ето го лог файла Папките ми в дял D вече се виждат само че тези преди ги нямаше: ghos, RECYCLER, MSOCache, msdownld.tmp, My Documents

Редактирано от Lugos (преглед на промените)

Това е добре. Сега следва:

Стъпка 1

  • Изтеглете CFCollect от тук тук и го поставете на десктопа.
  • Стартирайте CFCollect, като за целта трябва да имате включен Интернет. След стартирането натиснете OK и се убедете, че CFCollect работи и изпращането на файлове е успешно.

Стъпка 2

Знам много добре, че имаш инсталиран SP3 за Windows XP. Нужни са малко поправки на системни файлове. За това изтегли и инсталирай Windows XP Service Pack 3 от тук.

Напиши в следващия си коментар, когато станеш готов с това, което написах в този коментар.

  • Автор

Излиза ми тази грешка. И тези сайтове пак са се показали на декстопа.

Пробвай ето това:

Изтеглете FixPolicies и го запазете на декстопа. Кликнете два пъти върху файла и изберете Install. Ще се създаде папка с името FixPolicies на десктопа. Отворете я и стартирайте файла Fix_policies.cmd.

  • Автор

Стартирах Fix_policies.cmd. Сега да пробвам да старирам пак CFCollect ли ?

  • Автор

Готово. След инсталацията на Windows XP Service Pack 3 трябва ли да рестартирам ?

Да. След рестарта ще ми трябва лог от OTL, ето как става:

Следвайте следната инструкция за работа с OTL:

  • Изтеглете OTL.exe или OTL.scr го запазете на десктопа.
  • Стартирайте файла Публикувано изображение с двукратен клик на мишката.
  • Направете следните настройки:
Публикувано изображение

  • Под Публикувано изображение с Copy/ Paste въведете изцяло следната текстова информация (само това, което е поставено в карето):
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
tcpip.sys
sfcfiles.dll
/md5stop
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90
  • Натиснете маркираният в синьо бутон: Публикувано изображение.
  • Като приключи проверката, ще се създадат два файла - OTL.Txt и Extras.Txt. Прикачете тези два файла в следващия си коментар (погледнете опцията "прикачени файлове", когато публикувате мнение).

Брей, проклети китайски гадини. Ето какво следва:

Стъпка 1

Стартирайте пак OTL.exe и с Copy/ Paste под колонката Custom Scans/Fixes въведете скриптовия текст от текстовото поле по-долу, като не забравяте да копирате скрипта 1 към 1, както и двете точки преди първия ред на скрипта!

:OTL
PRC - C:\Program Files\Common Files\Microsoft Shared\explorer.exe ()
MOD - C:\Program Files\Common Files\ips888.dll ()
SRV - (MSDTC) -- File not found
DRV - (DMusic) -- C:\WINDOWS\system32\drivers\kpscc.sys ()
IE - HKU\S-1-5-21-1202660629-57989841-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.3322.com/
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TSPS.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1202660629-57989841-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O27 - HKLM IFEO\~.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360rp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360rpt.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360Safe.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360safebox.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360sd.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360sdrun.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\360tray.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\799d.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\adam.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AgentSvr.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AntiU.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AoYun.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\appdllman.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AppSvc32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ArSwp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ArSwp2.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ArSwp3.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AST.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\atpup.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\auto.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AutoRun.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\autoruns.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\av.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AvastU3.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\avconsol.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\avgrssvc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AvMonitor.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\avp.com: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\avp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\AvU3Launcher.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\CCenter.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ccSvcHst.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\cross.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Discovery.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\DSMain.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\EGHOST.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\FileDsty.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\filmst.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\FTCleanerShell.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\FYFireWall.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ghost.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\guangd.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\HijackThis.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\IceSword.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\iparmo.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Iparmor.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\irsetup.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\isPwdSvc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\jisu.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kabaload.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KaScrScn.SCR: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KASMain.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KASTask.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KAV32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KAVDX.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KAVPF.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KAVPFW.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KAVSetup.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kavstart.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kernelwind32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KISLnchr.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kissvc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KMailMon.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KMFilter.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KPFW32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KPFW32X.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KPfwSvc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KRegEx.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KRepair.com: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KsLoader.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KSWebShield.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KVCenter.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KvDetect.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KvfwMcl.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KVMonXP.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KVMonXP_1.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kvol.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kvolself.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KvReport.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KVScan.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KVSrvXP.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KVStub.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kvupload.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kvwsc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KvXP.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KvXP_1.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KWatch.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KWatch9x.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KWatchX.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KWSMain.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\kwstray.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\KWSUpd.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\loaddll.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\logogo.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\MagicSet.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\mcconsol.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\mmqczj.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\mmsk.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Navapsvc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Navapw32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\NAVSetup.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\niu.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\nod32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\nod32krn.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\nod32kui.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\NPFMntor.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\pagefile.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\pagefile.pif: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\pfserver.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\PFW.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\PFWLiveUpdate.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\qheart.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QHSET.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQDoctor.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQDoctorMain.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQDoctorRtp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQKav.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQPCMgr.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQPCRTP.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQPCSmashFile.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQPCTray.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\QQSC.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\qsetup.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Ras.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Rav.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ravcopy.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RavMon.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RavMonD.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RavStub.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RavTask.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RegClean.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\rfwcfg.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\rfwmain.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\rfwProxy.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\rfwsrv.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RsAgent.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Rsaupd.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\rsnetsvr.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\RsTray.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\rstrui.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\runiep.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\safeboxTray.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\safelive.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\scan32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ScanFrm.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\ScanU3.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\SDGames.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\SelfUpdate.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\servet.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\shcfg32.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\SmartUp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\sos.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\SREng.EXE: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\SREngPS.EXE: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\stormii.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\sxgame.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\symlcsvc.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\SysSafe.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\tmp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\TNT.Exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\TrojanDetector.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Trojanwall.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\TrojDie.kxp: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\TxoMoU.Exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UFO.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UIHost.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UmxAgent.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UmxAttachment.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UmxCfg.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UmxFwHlp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UmxPol.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\upiea.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\UpLive.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\USBCleaner.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\vsstat.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\wbapp.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\webscanx.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\WoptiClean.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\Wsyscheck.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\XDelBox.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\XP.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\zhudongfangyu.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\zjb.exe: Debugger - ntsd -d (Microsoft Corporation)
O27 - HKLM IFEO\zxsweep.exe: Debugger - ntsd -d (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
[2010/11/18 21:34:50 | 000,000,087 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ÌÔ±¦¹ºÎïA.url
[2010/11/18 21:34:50 | 000,000,077 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ãâ·ÑµçÓ°C.url
[2010/11/18 21:34:50 | 000,000,077 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\¸Ä±äÄãµÄÒ»Éú.url
[2010/11/17 06:56:30 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\053
[2010/11/17 05:16:02 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\dd63b
[2010/11/17 04:46:01 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\d0d
[2010/11/17 04:16:00 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\b39
[2010/11/17 03:45:59 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\9890
[2010/11/17 03:15:58 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\63b8
[2010/11/17 02:45:57 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\3b8
[2010/11/17 02:15:56 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\314a
[2010/11/17 01:45:55 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\14a2bb
[2010/11/17 01:15:53 | 000,000,068 | ---- | C] () -- C:\WINDOWS\System32\0dd6
[2010/11/16 23:23:55 | 000,212,992 | R--- | C] () -- C:\WINDOWS\b44d.exe
[2010/11/16 23:23:55 | 000,172,032 | R--- | C] () -- C:\WINDOWS\cb4d.flv
[2010/11/16 23:23:55 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2010/11/16 23:23:39 | 000,184,539 | ---- | C] () -- C:\WINDOWS\System32\msn280.exe
[2010/11/16 23:39:10 | 000,000,483 | ---- | C] () -- C:\WINDOWS\-12-8-5039.lnk
[2010/11/17 07:05:09 | 000,002,112 | -HS- | M] () -- C:\WINDOWS\system32\drivers\kpscc.sys
:files
recycler /alldrives
ipconfig /flushdns /c
:commands
[purity]
[resethosts]
[emptytemp]
[emptyflash]
[Reboot]
След като въведете скрипта от по-горе натиснете бутона, маркиран в червено: Публикувано изображение

След завършване на работата ОТL ще рестартира Windows. След това ще се създаде лог файл. Копирайте и поставете този файл в следващия си коментар.

Стъпка 2

Направете проверка със Sophos Anti-Rootkit. Eто как: изтеглете Sophos Anti-Rootkit от тук (иска се регистрация), стартирайте sarsfx.exe и го пуснете да сканира (Start scan). Когато сканирането завърши, пуснете Windows Explorer и отидете в папка %temp%. Там трябва да има файл с име sarscan.log. Публикувайте или го прикачете към следващия си коментар.

  • Автор

Пуснал съм Sophos Anti-Rootkit да сканира. Но след това нз какво да правя смисъл незнам каде се намира %temp%

Редактирано от Lugos (преглед на промените)

Първо трябва да пуснеш OTL със скрипта, който дадох в стъпка 1. Не се правят настройки на OTL и след въвеждане на скрипта от текстовото поле се натиска Run Fix.

След това следва Sophos Anti-Rootkit. Просто въведи в лентата на Windows Explorer %temp% и ще отидеш в папката.

  • Автор

пуснах OTL със скрипта и със тези настройки снимката е най - отдолу

ето и лога само неми стана ясно дали трябва да е с тези настроики или като стартирам OTL да не барам нищо по него

All processes killed

========== OTL ==========

No active process named explorer.exe was found!

Service MSDTC stopped successfully!

Service MSDTC deleted successfully!

File File not found not found.

Service DMusic stopped successfully!

Service DMusic deleted successfully!

C:\WINDOWS\system32\drivers\kpscc.sys moved successfully.

HKU\S-1-5-21-1202660629-57989841-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!

File move failed. C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TSPS.lnk scheduled to be moved on reboot.

Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.

Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.

Registry key HKEY_USERS\S-1-5-21-1202660629-57989841-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~.exe\ deleted successfully.

C:\WINDOWS\System32\ntsd.exe moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360sd.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360sdrun.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\799d.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiU.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AoYun.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appdllman.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp2.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp3.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atpup.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRun.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\av.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastU3.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvU3Launcher.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cross.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discovery.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DSMain.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filmst.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ghost.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guangd.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\irsetup.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jisu.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavstart.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernelwind32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kissvc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPfwSvc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.com\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KSWebShield.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWSMain.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kwstray.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWSUpd.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logogo.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSetup.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\niu.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfserver.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qheart.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctorMain.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctorRtp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQPCMgr.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQPCRTP.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQPCSmashFile.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQPCTray.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQSC.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qsetup.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravcopy.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwmain.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsnetsvr.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsTray.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScanFrm.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScanU3.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDGames.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SelfUpdate.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servet.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.EXE\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREngPS.EXE\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stormii.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sxgame.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tmp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TNT.Exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TxoMoU.Exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UFO.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upiea.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wbapp.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Wsyscheck.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XDelBox.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XP.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zhudongfangyu.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zjb.exe\ deleted successfully.

File ntsd -d not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe\ deleted successfully.

File ntsd -d not found.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.

C:\Documents and Settings\All Users\Desktop\ÌÔ±¦¹ºÎïA.url moved successfully.

C:\Documents and Settings\All Users\Desktop\Ãâ·ÑµçÓ°C.url moved successfully.

C:\Documents and Settings\All Users\Desktop\¸Ä±äÄãµÄÒ»Éú.url moved successfully.

C:\WINDOWS\system32\053 moved successfully.

C:\WINDOWS\system32\dd63b moved successfully.

C:\WINDOWS\system32\d0d moved successfully.

C:\WINDOWS\system32\b39 moved successfully.

C:\WINDOWS\system32\9890 moved successfully.

C:\WINDOWS\system32\63b8 moved successfully.

C:\WINDOWS\system32\3b8 moved successfully.

C:\WINDOWS\system32\314a moved successfully.

C:\WINDOWS\system32\14a2bb moved successfully.

C:\WINDOWS\system32\0dd6 moved successfully.

C:\WINDOWS\b44d.exe moved successfully.

C:\WINDOWS\cb4d.flv moved successfully.

C:\WINDOWS\libem.INI moved successfully.

C:\WINDOWS\System32\msn280.exe moved successfully.

C:\WINDOWS\-12-8-5039.lnk moved successfully.

File C:\WINDOWS\system32\drivers\kpscc.sys not found.

========== FILES ==========

C:\RECYCLER\S-1-5-21-1202660629-57989841-1801674531-1003 folder moved successfully.

C:\RECYCLER folder moved successfully.

D:\RECYCLER\S-1-5-21-861567501-682003330-1417001333-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-73586283-448539723-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-507921405-1844237615-1801674531-500 folder moved successfully.

D:\RECYCLER\S-1-5-21-507921405-1844237615-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-329068152-562591055-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-299502267-1229272821-839522115-1006 folder moved successfully.

D:\RECYCLER\S-1-5-21-299502267-1229272821-839522115-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-220523388-1614895754-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1715567821-963894560-725345543-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1454471165-1972579041-725345543-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1229272821-113007714-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1202660629-57989841-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1202660629-1275210071-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1177238915-838170752-1801674531-1003 folder moved successfully.

D:\RECYCLER\S-1-5-21-1085031214-299502267-1417001333-1003 folder moved successfully.

D:\RECYCLER\$hf_mig$ folder moved successfully.

D:\RECYCLER folder moved successfully.

< ipconfig /flushdns /c >

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

C:\Documents and Settings\Lugosss\Desktop\cmd.bat deleted successfully.

C:\Documents and Settings\Lugosss\Desktop\cmd.txt deleted successfully.

========== COMMANDS ==========

HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32902 bytes

->Flash cache emptied: 601 bytes

User: Lugosss

->Temp folder emptied: 587497 bytes

->Temporary Internet Files folder emptied: 113560 bytes

->FireFox cache emptied: 6432040 bytes

->Flash cache emptied: 1727 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 2421613 bytes

%systemroot%\System32 .tmp files removed: 2577 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 17379 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 9.00 mb

[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

->Flash cache emptied: 0 bytes

User: Lugosss

->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

OTL by OldTimer - Version 3.2.17.3 log created on 11182010_235906

Files\Folders moved on Reboot...

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TSPS.lnk moved successfully.

Registry entries deleted on Reboot...

Редактирано от Lugos (преглед на промените)

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.