Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Бавна и лесно натоварваща се система [РЕШЕН]

Featured Replies

  • Автор

Готово ComboFix 11-01-11.01 - my computer 01.2011 г. 14:17:59.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1022.656 [GMT 2:00] Running from: c:\documents and settings\my computer\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\my computer\Desktop\CFScript.txt AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FW: ESET Personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_SAVROAM -------\Service_SavRoam ((((((((((((((((((((((((( Files Created from 2010-12-12 to 2011-01-12 ))))))))))))))))))))))))))))))) . 2011-01-10 19:40 . 2011-01-10 19:40 13312 ----a-w- c:\windows\system32\drivers\vdi4ndaz.sys 2011-01-09 11:02 . 2011-01-10 12:24 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\ApplicationHistory 2011-01-08 14:20 . 2011-01-08 14:21 -------- d-----w- c:\documents and settings\my computer\Application Data\Skype 2011-01-08 10:32 . 2011-01-08 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files 2011-01-08 09:47 . 2011-01-08 09:47 4341408 ----a-w- C:\PMBInstSafe.exe 2011-01-08 09:05 . 2011-01-08 09:05 -------- d-----w- c:\program files\Pando Networks 2011-01-08 08:58 . 2011-01-08 08:58 1910152 ----a-w- C:\lotrostandard.exe 2011-01-07 17:50 . 2008-11-10 09:41 32656 ----a-w- c:\windows\system32\msonpmon.dll 2011-01-07 17:50 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll 2011-01-07 17:47 . 2011-01-07 17:57 -------- d-----w- c:\program files\Microsoft Works 2011-01-07 17:46 . 2011-01-07 17:46 -------- d-----w- c:\program files\Microsoft.NET 2011-01-07 17:43 . 2011-01-07 17:43 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2011-01-07 17:42 . 2011-01-07 17:53 -------- d-----w- c:\windows\SHELLNEW 2011-01-07 17:42 . 2011-01-07 17:42 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\Microsoft Help 2011-01-07 17:42 . 2011-01-07 18:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2011-01-07 17:41 . 2011-01-07 17:41 -------- d-----r- C:\MSOCache 2011-01-07 14:19 . 2011-01-07 14:19 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\Chromium 2011-01-07 13:58 . 2011-01-07 13:58 -------- d-----w- C:\FSDownloader 2011-01-07 13:19 . 2011-01-07 13:19 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2011-01-06 18:29 . 2011-01-06 18:29 -------- d-----w- c:\documents and settings\my computer\Application Data\ESET 2011-01-06 18:28 . 2011-01-06 18:28 -------- d-----w- c:\program files\ESET 2011-01-06 18:28 . 2011-01-06 18:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2011-01-06 12:59 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-06 12:59 . 2011-01-06 12:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-01-06 12:59 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-01-04 17:07 . 2011-01-04 17:07 -------- d-----w- c:\windows\system32\wbem\Repository 2011-01-04 17:05 . 2011-01-04 17:05 -------- d-----w- c:\documents and settings\my computer\Application Data\Malwarebytes 2011-01-04 15:43 . 2011-01-04 15:50 97859 ----a-w- c:\windows\system32\drivers\klick.dat 2011-01-04 15:43 . 2011-01-04 15:50 114243 ----a-w- c:\windows\system32\drivers\klin.dat 2011-01-04 15:28 . 2011-01-04 17:06 -------- d-----w- c:\program files\Kaspersky Lab 2011-01-03 20:30 . 2011-01-06 12:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-01-02 13:20 . 2011-01-02 13:20 -------- d-----w- c:\documents and settings\my computer\Application Data\FastStone 2011-01-02 13:20 . 2011-01-02 13:20 -------- d-----w- c:\program files\FastStone Capture 2011-01-01 11:56 . 2011-01-01 11:58 -------- d-----w- c:\program files\Windows Live Safety Center 2011-01-01 11:21 . 2011-01-01 11:21 -------- d-----w- c:\documents and settings\my computer\Application Data\PeaZip 2010-12-31 17:17 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\LocalService\Application Data\VMware 2010-12-31 11:02 . 2009-07-16 14:32 139264 ----a-w- c:\windows\NeoUninstall.exe 2010-12-31 11:02 . 2010-12-31 11:02 -------- d-----w- c:\program files\Neoact 2010-12-28 09:50 . 2011-01-02 20:16 -------- d-----w- c:\program files\ZD Soft 2010-12-28 09:21 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\VMware 2010-12-28 09:21 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\my computer\Application Data\VMware 2010-12-27 14:07 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware 2010-12-26 20:01 . 2010-12-31 17:16 -------- d-----w- c:\documents and settings\my computer\Application Data\QuickScan 2010-12-26 12:31 . 2010-12-26 12:31 -------- d-----w- C:\blubVolley_1.1h 2010-12-25 21:09 . 2010-12-25 22:25 -------- d-----w- c:\program files\TuneUp 2010-12-25 19:10 . 2010-12-25 19:10 -------- d-----w- c:\program files\Xenocode 2010-12-25 19:05 . 2010-12-25 19:05 -------- d-----w- c:\documents and settings\my computer\Application Data\TuneUp Software 2010-12-25 19:05 . 2010-12-25 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software 2010-12-25 19:05 . 2010-12-25 19:05 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} 2010-12-25 18:42 . 2010-12-25 18:43 -------- d-----w- c:\program files\Unlocker 2010-12-25 18:34 . 2010-12-25 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Ashampoo 2010-12-25 18:26 . 2011-01-12 08:50 -------- d-----w- c:\documents and settings\my computer\Application Data\BitComet 2010-12-25 18:26 . 2010-12-25 18:26 -------- d-----w- c:\program files\BitComet 2010-12-25 12:56 . 2010-12-25 19:15 -------- d-----w- c:\program files\Microsoft Silverlight 2010-12-24 11:52 . 2010-12-24 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Backup 2010-12-15 10:56 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr 2010-12-15 10:54 . 2010-12-15 10:54 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2010-12-15 10:47 . 2010-05-06 10:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2010-12-15 10:47 . 2010-05-06 10:41 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2010-12-15 10:47 . 2010-05-06 10:41 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-12-15 10:47 . 2010-05-06 10:41 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2010-12-15 10:47 . 2010-05-06 10:41 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2010-12-15 10:47 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll 2010-12-15 10:47 . 2010-05-06 10:41 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll 2010-12-14 16:57 . 2010-12-14 17:07 -------- d-----w- c:\documents and settings\my computer\Application Data\GetRightToGo 2010-12-14 12:05 . 2010-12-14 12:05 -------- d-sh--w- c:\documents and settings\my computer\IECompatCache 2010-12-14 12:04 . 2010-12-14 12:04 -------- d-sh--w- c:\documents and settings\my computer\PrivacIE 2010-12-14 11:59 . 2010-12-14 11:59 -------- d-sh--w- c:\documents and settings\my computer\IETldCache 2010-12-14 11:56 . 2010-12-14 11:57 -------- dc-h--w- c:\windows\ie8 2010-12-13 21:08 . 2010-12-13 21:08 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2010-12-13 21:03 . 2010-12-13 21:03 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\Secunia PSI 2010-12-13 21:03 . 2010-12-13 21:03 -------- d-----w- c:\program files\Secunia 2010-12-13 14:41 . 2008-02-26 11:59 294912 -c----w- c:\windows\system32\dllcache\msctf.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-26 08:10 . 2010-11-08 19:03 841912 ----a-w- c:\windows\system32\drivers\ESLWireACD.sys 2010-11-20 09:29 . 2009-04-29 09:06 214592 ----a-w- c:\windows\system32\PnkBstrB.xtr 2010-11-20 09:29 . 2008-11-19 14:54 214592 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-11-20 09:13 . 2008-11-19 14:54 138968 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-11-14 15:50 . 2010-11-14 15:50 180224 ----a-w- c:\windows\system32\WinVd32.sys 2010-11-14 15:50 . 2010-11-14 15:50 7680 ----a-w- c:\windows\system32\WinFLsrv.exe 2010-11-12 16:53 . 2010-07-02 12:33 472808 ----a-w- c:\windows\system32\deployJava1.dll 2010-11-12 14:34 . 2010-12-12 07:08 73728 ----a-w- c:\windows\system32\javacpl.cpl . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\steam\steam.exe" [2010-11-17 1242448] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "BitComet"="c:\program files\BitComet\BitComet.exe" [2010-12-08 10811696] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-12-27 405736] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2006-01-11 577536] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-11-04 2219184] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544] c:\documents and settings\my computer\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoRecentDocsNetHood"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoRecentDocsNetHood"= 1 (0x1) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Secunia PSI Tray.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk backup=c:\windows\pss\Secunia PSI Tray.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadStudio] 2009-07-09 02:15 156312 ----a-w- c:\program files\Conceiva\DownloadStudio\DownloadStudioScheduleMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl] 2010-12-27 16:57 405736 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2009-09-02 13:27 25623336 ----a-w- c:\program files\Skype\App\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] 2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ccEvtMgr"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Steam\\Steam.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "d:\\FIFA Online\\NFE.exe"= "d:\\PES 2010\\pes2010.exe"= "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"= "c:\\Program Files\\SopCast\\SopCast.exe"= "d:\\Football Manager 2011\\fm.exe"= "c:\\Program Files\\TeamViewer\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\TeamViewer_Service.exe"= "c:\\Program Files\\BitComet\\BitComet.exe"= "c:\\Documents and Settings\\my computer\\temp\\TeamViewer\\Version5\\TeamViewer.exe"= "c:\\Program Files\\Steam\\steamapps\\aditeam\\counter-strike\\hl.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "I:0\\Program Files\\Skype\\App\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Skype\\App\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "7715:TCP"= 7715:TCP:BitComet 7715 TCP "7715:UDP"= 7715:UDP:BitComet 7715 UDP "25766:TCP"= 25766:TCP:BitComet 25766 TCP "25766:UDP"= 25766:UDP:BitComet 25766 UDP "13226:TCP"= 13226:TCP:BitComet 13226 TCP "13226:UDP"= 13226:UDP:BitComet 13226 UDP "58976:TCP"= 58976:TCP:Pando Media Booster "58976:UDP"= 58976:UDP:Pando Media Booster "57019:TCP"= 57019:TCP:Pando Media Booster "57019:UDP"= 57019:UDP:Pando Media Booster "58348:TCP"= 58348:TCP:Pando Media Booster "58348:UDP"= 58348:UDP:Pando Media Booster "58281:TCP"= 58281:TCP:Pando Media Booster "58281:UDP"= 58281:UDP:Pando Media Booster "56094:TCP"= 56094:TCP:Pando Media Booster "56094:UDP"= 56094:UDP:Pando Media Booster "57109:TCP"= 57109:TCP:Pando Media Booster "57109:UDP"= 57109:UDP:Pando Media Booster R0 Copystar;Copystar;c:\windows\system32\drivers\copystar.sys [01.6.2002 г. 16:37 82400] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.11.2008 г. 13:45 691696] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29.7.2010 г. 12:31 115008] R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [04.11.2010 г. 17:15 810144] R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [14.11.2010 г. 17:50 17984] S1 1004731;1004731;c:\windows\system32\drivers\1004731.sys [24.10.2008 г. 11:14 0] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.4.2010 г. 11:16 136176] S3 ESLvnic1;ESLvnic Virtual Network 32 Bit;c:\windows\system32\drivers\ESLvnic.sys [07.1.2010 г. 20:03 24504] . Contents of the 'Scheduled Tasks' folder 2010-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb701a8c28a288.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-27 09:16] 2010-12-21 c:\windows\Tasks\User_Feed_Synchronization-{15058668-FA9F-4B0F-9A86-FF39016A2C51}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 02:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.bg/ uSearchAssistant = hxxp://www.google.com/ie IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: &Експортиране към Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {49493689-EEF9-43FF-B091-379EFAC23048} = 212.50.10.50 212.50.10.51 FF - ProfilePath - c:\documents and settings\my computer\Application Data\Mozilla\Firefox\Profiles\d10klczq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1424611&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3} FF - Ext: Ghostery: [email protected] - %profile%\extensions\[email protected] FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-01-12 14:24 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\system32\sys_drv.dat 6024 bytes c:\windows\system32\sys_drv_2.dat 5020 bytes c:\windows\system32\WinFLdrv.sys 17984 bytes executable scan completed successfully hidden files: 3 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1202660629-1965331169-839522115-1003\Software\G*e*n*i*e*"!\FM Genie Scout 10] "GameDir"="" "ShortlistDir"="" "ScreenshotsDir"="" "SaveDir"="" "HistoryDir"="c:\\Documents and Settings\\my computer\\Desktop\\fm_genie_scout_10_v1_11_b116\\FM Genie Scout 10\\History Points" "LangDB"="d:\\Football Manager 2010\\data\\db\\1000\\lang_db.dat" "LastSaveGame"="d:\\My Documents\\Sports Interactive\\Football Manager 2010\\games\\Internazionale.fm" "Language"="English" "LoadLangDB"=dword:00000001 "CompressHistoryPoints"=dword:00000000 "HighlightedAttributes"=dword:00000000 "MinCondition"=dword:00000050 "GraphStep"=dword:00000000 "SkinName"="Steklo Black" "LastUpdateCheck"=dword:00009de4 "HighQualityGUI"=dword:00000001 "AutomaticallyUpdateCheck"=dword:00000001 "AdvancedGeneration"=dword:00000000 "TranslateStaffSkills"=dword:00000001 "TranslatePlayerSkills"=dword:00000001 "TranslatePositions"=dword:00000001 "ShowHistory"=dword:00000001 "Version"=dword:00000074 "UniqueID"="44-8270-E43F" "Currency"=dword:00000056 "UseProxy"=dword:00000000 "ProxyHost"="" "ProxyPort"="" "UseAuthentication"=dword:00000000 "UserName"="" "UserPassword"="" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40401deb-2441-4352-9053-850e9e4d2924}] @Denied: (Full) (Everyone) "Model"=dword:000000dc "Therad"=dword:00000001 "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d, df,1c,2f,3b,8a,0a,32,11,89,01,b5,82,e4,d4,1d,80,1e,ff,6e,54,b9,fb,be,b9,9c,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):e0,54,4f,ea,ec,7e,3f,2e,ea,8a,68,00,23,31,58,03,32,26,bf,a0,39, 5d,c0,50,23,00,0b,ae,15,4e,b4,1c,f8,12,c9,7f,51,a3,b3,9d,00,00,00,00,00,00,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @DACL=(02 0010) @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @DACL=(02 0010) @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @DACL=(02 0010) @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\software\Classes\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}] @Denied: (1) (LocalSystem) @Denied: (1) (Administrators) "class"="364802367dbb37fe6bc8177d63b13aa2507554a5" [HKEY_LOCAL_MACHINE\software\Microsoft\TelnetServer\1.0\ReadConfig] @DACL=(02 0000) "Defaults"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(672) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3400) c:\windows\system32\WININET.dll c:\program files\Unlocker\UnlockerHook.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\Sandboxie\SbieSvc.exe c:\windows\system32\Ati2evxx.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\PnkBstrA.exe c:\windows\SOUNDMAN.EXE c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe . ************************************************************************** . Completion time: 2011-01-12 14:28:24 - machine was rebooted ComboFix-quarantined-files.txt 2011-01-12 12:28 ComboFix2.txt 2011-01-12 07:53 Pre-Run: 2 085 253 120 bytes free Post-Run: 2 088 804 352 bytes free - - End Of File - - 353A6332D9D12D0C259AB811D9876BC8

gmer.txt

Запазете текста в карето във файл cleanup.bat и го поставете там където се намира gmer.exe

gmer.exe -del service WinFLdrv
gmer.exe -del file "C:\WINDOWS\system32\sys_drv.dat"
gmer.exe -del file "C:\WINDOWS\system32\sys_drv_2.dat"
gmer.exe -del file "C:\WINDOWS\system32\WinFLdrv.sys"
gmer.exe -del file "C:\Documents and Settings\my computer\Application Data\systemfl.$dk"
gmer.exe -reboot

Стартирате с двоен клик съхранения пакетен файл cleanup.bat.

Внимание!!! Компютъра ви ще се рестартира!!!

Изгответе нов лог с Gmer....!:biggrin:

Перфектно..!Още малко и приключваме..!:yanim:

Копирайте текста в карето на notepad и го запазваш с име CFScript.txt на десктопа си:

KILLALL::

file:
c:\documents and settings\my computer\Local Settings\Application Data\Secunia PSI
c:\program files\Secunia
c:\documents and settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
c:\windows\pss\Secunia PSI Tray.lnkCommon Startup

registry::
[-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Secunia PSI Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
backup=c:\windows\pss\Secunia PSI Tray.lnkCommon Startup

След съхранението премести CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

ComboFix 11-01-11.01 - my computer 01.2011 г. 17:08:56.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1022.555 [GMT 2:00] Running from: c:\documents and settings\my computer\Desktop\Security Utilities\ComboFix.exe Command switches used :: c:\documents and settings\my computer\Desktop\Security Utilities\CFScript.txt AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FW: ESET Personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0} . ((((((((((((((((((((((((( Files Created from 2010-12-12 to 2011-01-12 ))))))))))))))))))))))))))))))) . 2011-01-10 19:40 . 2011-01-10 19:40 13312 ----a-w- c:\windows\system32\drivers\vdi4ndaz.sys 2011-01-09 11:02 . 2011-01-10 12:24 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\ApplicationHistory 2011-01-08 14:20 . 2011-01-08 14:21 -------- d-----w- c:\documents and settings\my computer\Application Data\Skype 2011-01-08 10:32 . 2011-01-08 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files 2011-01-08 09:47 . 2011-01-08 09:47 4341408 ----a-w- C:\PMBInstSafe.exe 2011-01-08 09:05 . 2011-01-08 09:05 -------- d-----w- c:\program files\Pando Networks 2011-01-08 08:58 . 2011-01-08 08:58 1910152 ----a-w- C:\lotrostandard.exe 2011-01-07 17:50 . 2008-11-10 09:41 32656 ----a-w- c:\windows\system32\msonpmon.dll 2011-01-07 17:50 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll 2011-01-07 17:47 . 2011-01-07 17:57 -------- d-----w- c:\program files\Microsoft Works 2011-01-07 17:46 . 2011-01-07 17:46 -------- d-----w- c:\program files\Microsoft.NET 2011-01-07 17:43 . 2011-01-07 17:43 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2011-01-07 17:42 . 2011-01-07 17:53 -------- d-----w- c:\windows\SHELLNEW 2011-01-07 17:42 . 2011-01-07 17:42 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\Microsoft Help 2011-01-07 17:42 . 2011-01-07 18:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2011-01-07 17:41 . 2011-01-07 17:41 -------- d-----r- C:\MSOCache 2011-01-07 14:19 . 2011-01-07 14:19 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\Chromium 2011-01-07 13:58 . 2011-01-07 13:58 -------- d-----w- C:\FSDownloader 2011-01-07 13:19 . 2011-01-07 13:19 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2011-01-06 18:29 . 2011-01-06 18:29 -------- d-----w- c:\documents and settings\my computer\Application Data\ESET 2011-01-06 18:28 . 2011-01-06 18:28 -------- d-----w- c:\program files\ESET 2011-01-06 18:28 . 2011-01-06 18:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2011-01-06 12:59 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-06 12:59 . 2011-01-06 12:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-01-06 12:59 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-01-04 17:07 . 2011-01-04 17:07 -------- d-----w- c:\windows\system32\wbem\Repository 2011-01-04 17:05 . 2011-01-04 17:05 -------- d-----w- c:\documents and settings\my computer\Application Data\Malwarebytes 2011-01-04 15:43 . 2011-01-04 15:50 97859 ----a-w- c:\windows\system32\drivers\klick.dat 2011-01-04 15:43 . 2011-01-04 15:50 114243 ----a-w- c:\windows\system32\drivers\klin.dat 2011-01-03 20:30 . 2011-01-06 12:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-01-02 13:20 . 2011-01-02 13:20 -------- d-----w- c:\documents and settings\my computer\Application Data\FastStone 2011-01-02 13:20 . 2011-01-02 13:20 -------- d-----w- c:\program files\FastStone Capture 2011-01-01 11:56 . 2011-01-01 11:58 -------- d-----w- c:\program files\Windows Live Safety Center 2011-01-01 11:21 . 2011-01-01 11:21 -------- d-----w- c:\documents and settings\my computer\Application Data\PeaZip 2010-12-31 17:17 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\LocalService\Application Data\VMware 2010-12-31 11:02 . 2009-07-16 14:32 139264 ----a-w- c:\windows\NeoUninstall.exe 2010-12-31 11:02 . 2010-12-31 11:02 -------- d-----w- c:\program files\Neoact 2010-12-28 09:50 . 2011-01-02 20:16 -------- d-----w- c:\program files\ZD Soft 2010-12-28 09:21 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\VMware 2010-12-28 09:21 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\my computer\Application Data\VMware 2010-12-27 14:07 . 2010-12-31 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware 2010-12-26 20:01 . 2010-12-31 17:16 -------- d-----w- c:\documents and settings\my computer\Application Data\QuickScan 2010-12-26 12:31 . 2010-12-26 12:31 -------- d-----w- C:\blubVolley_1.1h 2010-12-25 21:09 . 2010-12-25 22:25 -------- d-----w- c:\program files\TuneUp 2010-12-25 19:05 . 2010-12-25 19:05 -------- d-----w- c:\documents and settings\my computer\Application Data\TuneUp Software 2010-12-25 19:05 . 2010-12-25 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software 2010-12-25 19:05 . 2010-12-25 19:05 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} 2010-12-25 18:42 . 2010-12-25 18:43 -------- d-----w- c:\program files\Unlocker 2010-12-25 18:34 . 2010-12-25 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Ashampoo 2010-12-25 18:26 . 2011-01-12 14:27 -------- d-----w- c:\documents and settings\my computer\Application Data\BitComet 2010-12-25 18:26 . 2010-12-25 18:26 -------- d-----w- c:\program files\BitComet 2010-12-25 12:56 . 2010-12-25 19:15 -------- d-----w- c:\program files\Microsoft Silverlight 2010-12-24 11:52 . 2010-12-24 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Backup 2010-12-15 10:56 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr 2010-12-15 10:54 . 2010-12-15 10:54 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2010-12-15 10:47 . 2010-05-06 10:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2010-12-15 10:47 . 2010-05-06 10:41 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2010-12-15 10:47 . 2010-05-06 10:41 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-12-15 10:47 . 2010-05-06 10:41 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2010-12-15 10:47 . 2010-05-06 10:41 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2010-12-15 10:47 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll 2010-12-15 10:47 . 2010-05-06 10:41 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll 2010-12-14 16:57 . 2010-12-14 17:07 -------- d-----w- c:\documents and settings\my computer\Application Data\GetRightToGo 2010-12-14 12:05 . 2010-12-14 12:05 -------- d-sh--w- c:\documents and settings\my computer\IECompatCache 2010-12-14 12:04 . 2010-12-14 12:04 -------- d-sh--w- c:\documents and settings\my computer\PrivacIE 2010-12-14 11:59 . 2010-12-14 11:59 -------- d-sh--w- c:\documents and settings\my computer\IETldCache 2010-12-14 11:56 . 2010-12-14 11:57 -------- dc-h--w- c:\windows\ie8 2010-12-13 21:08 . 2010-12-13 21:08 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2010-12-13 21:03 . 2010-12-13 21:03 -------- d-----w- c:\documents and settings\my computer\Local Settings\Application Data\Secunia PSI 2010-12-13 21:03 . 2010-12-13 21:03 -------- d-----w- c:\program files\Secunia . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-26 08:10 . 2010-11-08 19:03 841912 ----a-w- c:\windows\system32\drivers\ESLWireACD.sys 2010-11-20 09:29 . 2009-04-29 09:06 214592 ----a-w- c:\windows\system32\PnkBstrB.xtr 2010-11-20 09:29 . 2008-11-19 14:54 214592 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-11-20 09:13 . 2008-11-19 14:54 138968 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-11-14 15:50 . 2010-11-14 15:50 180224 ----a-w- c:\windows\system32\WinVd32.sys 2010-11-14 15:50 . 2010-11-14 15:50 7680 ----a-w- c:\windows\system32\WinFLsrv.exe 2010-11-12 16:53 . 2010-07-02 12:33 472808 ----a-w- c:\windows\system32\deployJava1.dll 2010-11-12 14:34 . 2010-12-12 07:08 73728 ----a-w- c:\windows\system32\javacpl.cpl . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\steam\steam.exe" [2010-11-17 1242448] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "BitComet"="c:\program files\BitComet\BitComet.exe" [2010-12-08 10811696] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-12-27 405736] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2006-01-11 577536] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-11-04 2219184] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544] c:\documents and settings\my computer\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoRecentDocsNetHood"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoRecentDocsNetHood"= 1 (0x1) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadStudio] 2009-07-09 02:15 156312 ----a-w- c:\program files\Conceiva\DownloadStudio\DownloadStudioScheduleMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl] 2010-12-27 16:57 405736 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2009-09-02 13:27 25623336 ----a-w- c:\program files\Skype\App\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] 2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ccEvtMgr"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Steam\\Steam.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Xfire\\Xfire.exe"= "d:\\FIFA Online\\NFE.exe"= "d:\\PES 2010\\pes2010.exe"= "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"= "c:\\Program Files\\SopCast\\SopCast.exe"= "d:\\Football Manager 2011\\fm.exe"= "c:\\Program Files\\TeamViewer\\TeamViewer.exe"= "c:\\Program Files\\TeamViewer\\TeamViewer_Service.exe"= "c:\\Program Files\\BitComet\\BitComet.exe"= "c:\\Documents and Settings\\my computer\\temp\\TeamViewer\\Version5\\TeamViewer.exe"= "c:\\Program Files\\Steam\\steamapps\\aditeam\\counter-strike\\hl.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "I:0\\Program Files\\Skype\\App\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Skype\\App\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "7715:TCP"= 7715:TCP:BitComet 7715 TCP "7715:UDP"= 7715:UDP:BitComet 7715 UDP "25766:TCP"= 25766:TCP:BitComet 25766 TCP "25766:UDP"= 25766:UDP:BitComet 25766 UDP "13226:TCP"= 13226:TCP:BitComet 13226 TCP "13226:UDP"= 13226:UDP:BitComet 13226 UDP "58976:TCP"= 58976:TCP:Pando Media Booster "58976:UDP"= 58976:UDP:Pando Media Booster "57019:TCP"= 57019:TCP:Pando Media Booster "57019:UDP"= 57019:UDP:Pando Media Booster "58348:TCP"= 58348:TCP:Pando Media Booster "58348:UDP"= 58348:UDP:Pando Media Booster "58281:TCP"= 58281:TCP:Pando Media Booster "58281:UDP"= 58281:UDP:Pando Media Booster "56094:TCP"= 56094:TCP:Pando Media Booster "56094:UDP"= 56094:UDP:Pando Media Booster "57109:TCP"= 57109:TCP:Pando Media Booster "57109:UDP"= 57109:UDP:Pando Media Booster R0 Copystar;Copystar;c:\windows\system32\drivers\copystar.sys [01.6.2002 г. 16:37 82400] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.11.2008 г. 13:45 691696] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29.7.2010 г. 12:31 115008] R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [04.11.2010 г. 17:15 810144] S1 1004731;1004731;c:\windows\system32\drivers\1004731.sys [24.10.2008 г. 11:14 0] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.4.2010 г. 11:16 136176] S3 ESLvnic1;ESLvnic Virtual Network 32 Bit;c:\windows\system32\drivers\ESLvnic.sys [07.1.2010 г. 20:03 24504] . Contents of the 'Scheduled Tasks' folder 2010-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb701a8c28a288.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-27 09:16] 2010-12-21 c:\windows\Tasks\User_Feed_Synchronization-{15058668-FA9F-4B0F-9A86-FF39016A2C51}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 02:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.bg/ uSearchAssistant = hxxp://www.google.com/ie IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: &Експортиране към Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {49493689-EEF9-43FF-B091-379EFAC23048} = 212.50.10.50 212.50.10.51 FF - ProfilePath - c:\documents and settings\my computer\Application Data\Mozilla\Firefox\Profiles\d10klczq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1424611&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: BetterPrivacy: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} - %profile%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3} FF - Ext: Ghostery: [email protected] - %profile%\extensions\[email protected] FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232} FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-01-12 17:15 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1202660629-1965331169-839522115-1003\Software\G*e*n*i*e*"!\FM Genie Scout 10] "GameDir"="" "ShortlistDir"="" "ScreenshotsDir"="" "SaveDir"="" "HistoryDir"="c:\\Documents and Settings\\my computer\\Desktop\\fm_genie_scout_10_v1_11_b116\\FM Genie Scout 10\\History Points" "LangDB"="d:\\Football Manager 2010\\data\\db\\1000\\lang_db.dat" "LastSaveGame"="d:\\My Documents\\Sports Interactive\\Football Manager 2010\\games\\Internazionale.fm" "Language"="English" "LoadLangDB"=dword:00000001 "CompressHistoryPoints"=dword:00000000 "HighlightedAttributes"=dword:00000000 "MinCondition"=dword:00000050 "GraphStep"=dword:00000000 "SkinName"="Steklo Black" "LastUpdateCheck"=dword:00009de4 "HighQualityGUI"=dword:00000001 "AutomaticallyUpdateCheck"=dword:00000001 "AdvancedGeneration"=dword:00000000 "TranslateStaffSkills"=dword:00000001 "TranslatePlayerSkills"=dword:00000001 "TranslatePositions"=dword:00000001 "ShowHistory"=dword:00000001 "Version"=dword:00000074 "UniqueID"="44-8270-E43F" "Currency"=dword:00000056 "UseProxy"=dword:00000000 "ProxyHost"="" "ProxyPort"="" "UseAuthentication"=dword:00000000 "UserName"="" "UserPassword"="" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40401deb-2441-4352-9053-850e9e4d2924}] @Denied: (Full) (Everyone) "Model"=dword:000000dc "Therad"=dword:00000001 "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d, df,1c,2f,3b,8a,0a,32,11,89,01,b5,82,e4,d4,1d,80,1e,ff,6e,54,b9,fb,be,b9,9c,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):e0,54,4f,ea,ec,7e,3f,2e,ea,8a,68,00,23,31,58,03,32,26,bf,a0,39, 5d,c0,50,23,00,0b,ae,15,4e,b4,1c,f8,12,c9,7f,51,a3,b3,9d,00,00,00,00,00,00,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @DACL=(02 0010) @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @DACL=(02 0010) @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @DACL=(02 0010) @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\software\Classes\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}] @Denied: (1) (LocalSystem) @Denied: (1) (Administrators) "class"="364802367dbb37fe6bc8177d63b13aa2507554a5" [HKEY_LOCAL_MACHINE\software\Microsoft\TelnetServer\1.0\ReadConfig] @DACL=(02 0000) "Defaults"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(668) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3364) c:\windows\system32\WININET.dll c:\program files\Unlocker\UnlockerHook.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\Sandboxie\SbieSvc.exe c:\windows\system32\Ati2evxx.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\PnkBstrA.exe c:\windows\SOUNDMAN.EXE c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe . ************************************************************************** . Completion time: 2011-01-12 17:19:43 - machine was rebooted ComboFix-quarantined-files.txt 2011-01-12 15:19 ComboFix2.txt 2011-01-12 12:28 ComboFix3.txt 2011-01-12 07:53 Pre-Run: 2 175 897 600 bytes free Post-Run: 2 166 722 560 bytes free - - End Of File - - 716F35534EDE35C2EA728C7A38CDB4E1

Така...сега вече мисля че всичко е наред.....!

Деинсталирайте ComboFix така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете OTCleanIt или от тук,стартирайте и натиснете Clean up

АВЗ деинсталирайте така:

Стартирате програмата.

Файл ==> Стандартни скрипти ==>Поставяте отметка на 6 - ти стандартен скрипт :

Публикувано изображение

Натискате бутона за да изпълните скрипта....!

Всичко останало изтривате ръчно....!:)

Остана само едно нещо : Инсталирането на Service Pack 3

Основния проблем при вас беше рооткит + остатъци от антивирусен софтуер и някои програми...Мисля че пооправихме нещата..!

Вие как чуствате системата си...Наблюдавате ли проблеми..?

  • Автор

Всичко е готово

Няколко въпроса:

Как да направя да се виждат файловите разширения?

Да ми препоръчате някоя security програма, или да остана с ESS и съответно какви бяха процедурите които направихме.....

Благодаря много!

Това е последното, после може да я заключвате.

Еdit: Добре я чувствам, и като цяло е по - живнала.

Редактирано от herolanok (преглед на промените)

Как да направя да се виждат файловите разширения?

Control Panel ==> Folder options == > View ==.> махате отметката от '' Hide extensions for known file types''

  • Автор

Control Panel ==> Folder options == > View ==.> махате отметката от '' Hide extensions for known file types''

С това се оправих.

А за другата част от поста ми? :)

ESET е добра антивирусна но има едно условие...да не е изтеглена от някъде и крактната съответно....предполагам разбирате какво искам да кажа...?!?А това какво направихме съм ви описъл в пост 31..!:)

  • Автор

ESET е добра антивирусна но има едно условие...да не е изтеглена от някъде и крактната съответно....предполагам разбирате какво искам да кажа...?!?А това какво направихме съм ви описъл в пост 31..!:)

Платена е, а в момента е TRIAL но ако го препоръчвате силно - го купувам. :clap:

Е ,не ме карайте да си казвам личните предпочитания защото веднага ще кажат ''реклама''....но ще ви кажа че вече доста години аз си купувам едногодишния лиценз за програмата която харесвам и съм напълно спокоен в това отношение...!А вие сами ще решите....затова са TRIAL -те ,да пробвате и вземете решение дали да закупите лиценз или да изберете друг вариант..!:)

  • Автор

Добре. Оставам със ESS, пък ако има нещо - пак ще се видим :)

Благодаря и може да заключвате темата.

РЕШЕН

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.