Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Инфектирана система, afd.exe error [РЕШЕН]

Featured Replies

Не виждам активни зарази в системата ви....!Имате ли още проблеми ..?:speak:

  • Отговори 64
  • Прегледи 7,9k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Копирайте текста в карето на notepad и го запазваш с име CFScript.txt на десктопа си: KILLALL:: SecCenter:: AV: ESET Smart Security 3.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C

  • А кои са те..?Не виждам линк..!Или вие си ги измисляте тези стъпки...?Вижте ...от една седмица се опитвам да ви изчистя системата,опитвам се да ви оправя грешките....и най-накрая когато постигнахме не

  • Съжелявам забравих да дам линк за папката Qoobox : Сега пускам mbam.

Публикувани изображения

  • Автор

Момент сега ще проверя, да ви попитам само да включа ли Windows fire wall или да дам опцията, че и сам мога да правя мониторинг на PCто ?

  • Автор

Направиг няколко теста и онзи проблем с изкривяването на картината и звука вече го няма но клипчетата във vbox7 и youtube още ми засичат, преинсталирах флаш плеъра но не се оправи, да неби при някой от фиксовете да сме изтрили някои заразен кодек и от там да идва проблема ?

Копирайте текста в карето на notepad и го запазваш с име CFScript.txt на десктопа си:

KILLALL::

RegNull::
[HKEY_USERS\S-1-5-21-220523388-920026266-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DC984039-3D7D-1F4F-23B3-10F7E48F8E01}*]



След съхранението премести CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

Изтеглете SystemLook и запазете програмата на десктопа.

  • Кликнете два пъти върху SystemLook.exe, за да стартирате програмата.
  • Копирайте съдържанието от цитата по-долу в текстовото поле на програмата:
:regfind
netstats

  • Кликнете на бутона Look, за да започне сканирането.
  • Когато сканирането завърши ще се отвори Notepad с резултата от сканирането. После публикувайте лог файла в следващия си коментар.
  • Автор

ComboFix 11-02-06.02 - Goro 02.2011 г. 22:12:44.15.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1022.669 [GMT 2:00] Running from: c:\documents and settings\Goro.MS-GORO\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Goro.MS-GORO\Desktop\CFScript.txt.txt AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((( Files Created from 2011-01-07 to 2011-02-07 ))))))))))))))))))))))))))))))) . 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\windows\system32\drivers\NSS 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\program files\Norton Security Scan 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Norton 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\program files\NortonInstaller 2011-02-06 22:25 . 2006-10-18 19:05 232448 ----a-w- c:\windows\system32\mp3fhg.acm 2011-02-06 22:25 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll 2011-02-06 22:25 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm 2011-02-06 22:25 . 2010-12-07 18:40 183808 ----a-w- c:\windows\system32\xvidvfw.dll 2011-02-06 22:25 . 2010-12-07 18:22 810496 ----a-w- c:\windows\system32\xvidcore.dll 2011-02-06 22:25 . 2011-01-28 08:00 80896 ----a-w- c:\windows\system32\ff_vfw.dll 2011-02-05 11:48 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-02-05 11:48 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-02-05 11:48 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-02-05 11:48 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-02-05 11:48 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-02-05 11:48 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-02-05 11:48 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-02-05 11:47 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr 2011-02-05 11:47 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe 2011-01-25 13:22 . 2011-01-25 13:22 146 ----a-w- c:\windows\DelMR.bat 2011-01-25 13:07 . 2011-01-25 13:07 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Application Data\Teleca 2011-01-25 12:56 . 2011-01-25 12:56 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Application Data\Sony Ericsson 2011-01-25 12:55 . 2011-01-25 13:22 -------- d-----w- c:\program files\Common Files\Teleca Shared 2011-01-25 12:55 . 2011-01-25 12:55 -------- d-----w- c:\program files\MSXML 6.0 2011-01-24 18:32 . 2011-01-24 18:32 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\bluesoleil 2011-01-24 18:29 . 2011-01-24 18:29 -------- d-----w- c:\program files\Nokia 2011-01-17 19:14 . 2011-01-17 20:50 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Application Data\Mumble 2011-01-17 19:13 . 2011-01-17 19:13 -------- d-----w- c:\program files\Mumble 2011-01-09 12:49 . 2011-01-09 12:55 -------- d-----w- C:\Poker . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-12-20 16:09 . 2010-02-28 12:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-20 16:08 . 2010-02-28 12:22 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-11-11 14:40 . 2008-01-17 08:54 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-11-11 14:40 . 2008-01-17 08:54 103736 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-11-11 01:21 . 2008-01-19 09:31 139152 ----a-w- c:\documents and settings\Goro.MS-GORO\Application Data\PnkBstrK.sys 2010-11-11 01:20 . 2008-11-15 11:26 794408 ----a-w- c:\windows\system32\pbsvc.exe 2009-07-22 18:19 . 2009-07-22 18:19 22285608 ----a-w- c:\program files\SkypeSetup_3.8.0.188.exe 2009-04-10 22:22 . 2009-04-10 22:22 17238008 ----a-w- c:\program files\SystemMechanic.exe 2008-02-03 19:06 . 2008-02-03 19:06 1156096 ----a-w- c:\program files\iview410_setup.exe 2007-08-11 09:00 . 2007-06-24 16:44 543000 ----a-w- c:\program files\TunaticSetup.exe 2007-03-08 19:17 . 2007-03-12 19:51 1077161 ----a-w- c:\program files\TSD_Install.exe 2007-01-14 05:17 . 2007-01-14 05:17 348160 ----a-w- c:\program files\MPUI.exe 2007-01-05 06:04 . 2007-01-05 06:02 11757720 ----a-w- c:\program files\nentenst.exe 2006-11-17 02:27 . 2007-01-05 06:05 229760 ----a-w- c:\program files\main.dll 1999-12-01 06:39 . 2007-01-05 06:05 995384 ----a-w- c:\program files\mfc42u.dll 1999-04-24 05:22 . 2007-01-05 06:05 266293 ----a-w- c:\program files\msvcrt.dll 1999-04-24 05:22 . 2007-01-05 06:05 995383 ----a-w- c:\program files\mfc42.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-05 133104] "Steam"="e:\games\Steam\steam.exe" [2010-11-16 1242448] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320] "DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968] "SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536] "Logitech Utility"="Logi_MwX.Exe" [2003-03-04 19968] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midi1"=s3usrdrv.dll "wave1"=s3usrdrv.dll "midi2"=s3fmdrv.dll "aux1"=s3usrdrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Garena\\Garena.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"= "e:\\GAMES\\Steam\\Steam.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Opera\\opera.exe"= "e:\\GAMES\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"= "e:\\GAMES\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"= "e:\\GAMES\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443 "443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443 "37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674 "37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674 "37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675 "139:TCP"= 139:TCP:@xpsp2res.dll,-22004 "445:TCP"= 445:TCP:@xpsp2res.dll,-22005 "137:UDP"= 137:UDP:@xpsp2res.dll,-22001 "138:UDP"= 138:UDP:@xpsp2res.dll,-22002 "57022:TCP"= 57022:TCP:Pando Media Booster "57022:UDP"= 57022:UDP:Pando Media Booster "8394:TCP"= 8394:TCP:League of Legends Launcher "8394:UDP"= 8394:UDP:League of Legends Launcher "6888:TCP"= 6888:TCP:League of Legends Launcher "6888:UDP"= 6888:UDP:League of Legends Launcher [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings] "RemoteAddresses"= * "Enabled"= 1 (0x1) R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [17.6.2009 г. 14:01 20744] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.4.2007 г. 11:46 682232] R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [08.1.2008 г. 17:03 16896] R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [08.1.2008 г. 17:03 52224] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [05.2.2011 г. 13:48 294608] R1 s3knldrv;s3knldrv;c:\windows\system32\drivers\S3KNLDRV.SYS [22.5.2007 г. 19:39 309184] R1 XGIkp;XGIkp;c:\windows\system32\drivers\xrvkp.sys [08.1.2008 г. 19:23 4480] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05.2.2011 г. 13:48 17744] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [17.7.2008 г. 22:26 2368] R3 N100;Compaq Ethernet or Fast Ethernet NIC Driver;c:\windows\system32\drivers\n100325.sys [08.1.2008 г. 22:31 128000] R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [01.9.2010 г. 22:58 17792] S1 s3knljs;s3knljs;c:\windows\system32\drivers\S3KNLJS.SYS [22.5.2007 г. 19:39 17376] S2 gupdate1c99dec842196aa;Google Update Service (gupdate1c99dec842196aa);c:\program files\Google\Update\GoogleUpdate.exe [06.3.2009 г. 01:45 133104] S3 BS_Flash;BS_Flash;\??\c:\program files\BIOS\BIOS Flash\BS_Flash.sys --> c:\program files\BIOS\BIOS Flash\BS_Flash.sys [?] S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [17.6.2009 г. 14:02 30088] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [21.2.2010 г. 04:26 129024] S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\GORO~2.MS-\LOCALS~1\Temp\GTZ2DBB.tmp --> c:\docume~1\GORO~2.MS-\LOCALS~1\Temp\GTZ2DBB.tmp [?] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?] S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [17.6.2009 г. 14:01 26248] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [02.8.2005 г. 23:10 32512] S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [23.1.2004 г. 15:33 13952] S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [23.1.2004 г. 15:32 28800] S3 RTCore32;RTCore32;c:\program files\RightMark Memory Analyzer\RTCore32.sys [09.3.2010 г. 11:06 4608] S3 XGIGraphics;XGIGraphics;c:\windows\system32\drivers\xgigrp.sys [08.1.2008 г. 19:23 290432] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs uxtuneup . Contents of the 'Scheduled Tasks' folder 2011-02-07 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 12:37] 2011-02-07 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-26 19:55] 2011-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 23:45] 2011-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 23:45] 2011-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-920026266-725345543-1003Core.job - c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-05 16:35] 2011-02-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-920026266-725345543-1003UA.job - c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-05 16:35] 2011-02-07 c:\windows\Tasks\User_Feed_Synchronization-{DABEA9C1-D771-436D-A4EA-9DFF20556F97}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 16:36] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.bing.com/?pc=AVBR uInternet Connection Wizard,ShellNext = iexplore IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {A920F5E5-C246-4587-8D29-420A73DE083F} = 94.155.112.12,94.155.112.13 DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab FF - ProfilePath - c:\documents and settings\Goro.MS-GORO\Application Data\Mozilla\Firefox\Profiles\wkqmrmxm.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.vbox7.com/ FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-02-07 22:25 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\GORO~2.MS-\LOCALS~1\Temp\GTZ2DBB.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\System\ControlSet002\Enum\Root\LEGACY_NETSTATS\0000] @DACL=(02 0000) "Service"="netstats" "Legacy"=dword:00000001 "ConfigFlags"=dword:00000000 "Class"="LegacyDriver" "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}" "DeviceDesc"="netstats" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(980) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2108) c:\windows\system32\msi.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\PnkBstrA.exe c:\windows\System32\TUProgSt.exe c:\windows\SOUNDMAN.EXE c:\windows\Logi_MwX.Exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2011-02-07 22:33:24 - machine was rebooted ComboFix-quarantined-files.txt 2011-02-07 20:33 ComboFix2.txt 2011-02-06 20:41 ComboFix3.txt 2011-02-06 19:15 Pre-Run: 1 803 034 624 bytes free Post-Run: 1 797 472 256 bytes free - - End Of File - - D4EA1A02B96D1509BF86AE419BAA5B7B Ето това е от System Look loga. SystemLook 04.09.10 by jpshortstuff Log created at 22:37 on 07/02/2011 by Goro Administrator - Elevation successful ========== regfind ========== Searching for "netstats" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETSTATS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETSTATS] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETSTATS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETSTATS] -= EOF =-

Копирайте текста в карето на notepad и го запазваш с име CFScript.txt на десктопа си:

KILLALL::

Driver::
NETSTATS

RegLockDel::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETSTATS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETSTATS]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETSTATS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETSTATS]

След съхранението премести CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

ComboFix 11-02-08.02 - Goro 02.2011 г. 2:34.16.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1022.679 [GMT 2:00] Running from: c:\documents and settings\Goro.MS-GORO\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Goro.MS-GORO\Desktop\CFScript.txt.txt AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2011-01-09 to 2011-02-09 ))))))))))))))))))))))))))))))) . 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\windows\system32\drivers\NSS 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\program files\Norton Security Scan 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Norton 2011-02-06 22:33 . 2011-02-06 22:33 -------- d-----w- c:\program files\NortonInstaller 2011-02-06 22:25 . 2006-10-18 19:05 232448 ----a-w- c:\windows\system32\mp3fhg.acm 2011-02-06 22:25 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll 2011-02-06 22:25 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm 2011-02-06 22:25 . 2010-12-07 18:40 183808 ----a-w- c:\windows\system32\xvidvfw.dll 2011-02-06 22:25 . 2010-12-07 18:22 810496 ----a-w- c:\windows\system32\xvidcore.dll 2011-02-06 22:25 . 2011-01-28 08:00 80896 ----a-w- c:\windows\system32\ff_vfw.dll 2011-02-05 11:48 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-02-05 11:48 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-02-05 11:48 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-02-05 11:48 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-02-05 11:48 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-02-05 11:48 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-02-05 11:48 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-02-05 11:47 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr 2011-02-05 11:47 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe 2011-01-25 13:22 . 2011-01-25 13:22 146 ----a-w- c:\windows\DelMR.bat 2011-01-25 13:07 . 2011-01-25 13:07 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Application Data\Teleca 2011-01-25 12:56 . 2011-01-25 12:56 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Application Data\Sony Ericsson 2011-01-25 12:55 . 2011-01-25 13:22 -------- d-----w- c:\program files\Common Files\Teleca Shared 2011-01-25 12:55 . 2011-01-25 12:55 -------- d-----w- c:\program files\MSXML 6.0 2011-01-24 18:32 . 2011-01-24 18:32 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\bluesoleil 2011-01-24 18:29 . 2011-01-24 18:29 -------- d-----w- c:\program files\Nokia 2011-01-17 19:14 . 2011-01-17 20:50 -------- d-----w- c:\documents and settings\Goro.MS-GORO\Application Data\Mumble 2011-01-17 19:13 . 2011-01-17 19:13 -------- d-----w- c:\program files\Mumble . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-12-20 16:09 . 2010-02-28 12:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-20 16:08 . 2010-02-28 12:22 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-11-11 14:40 . 2008-01-17 08:54 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-11-11 14:40 . 2008-01-17 08:54 103736 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-11-11 01:21 . 2008-01-19 09:31 139152 ----a-w- c:\documents and settings\Goro.MS-GORO\Application Data\PnkBstrK.sys 2010-11-11 01:20 . 2008-11-15 11:26 794408 ----a-w- c:\windows\system32\pbsvc.exe 2009-07-22 18:19 . 2009-07-22 18:19 22285608 ----a-w- c:\program files\SkypeSetup_3.8.0.188.exe 2009-04-10 22:22 . 2009-04-10 22:22 17238008 ----a-w- c:\program files\SystemMechanic.exe 2008-02-03 19:06 . 2008-02-03 19:06 1156096 ----a-w- c:\program files\iview410_setup.exe 2007-08-11 09:00 . 2007-06-24 16:44 543000 ----a-w- c:\program files\TunaticSetup.exe 2007-03-08 19:17 . 2007-03-12 19:51 1077161 ----a-w- c:\program files\TSD_Install.exe 2007-01-14 05:17 . 2007-01-14 05:17 348160 ----a-w- c:\program files\MPUI.exe 2007-01-05 06:04 . 2007-01-05 06:02 11757720 ----a-w- c:\program files\nentenst.exe 2006-11-17 02:27 . 2007-01-05 06:05 229760 ----a-w- c:\program files\main.dll 1999-12-01 06:39 . 2007-01-05 06:05 995384 ----a-w- c:\program files\mfc42u.dll 1999-04-24 05:22 . 2007-01-05 06:05 266293 ----a-w- c:\program files\msvcrt.dll 1999-04-24 05:22 . 2007-01-05 06:05 995383 ----a-w- c:\program files\mfc42.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-05 133104] "Steam"="e:\games\Steam\steam.exe" [2010-11-16 1242448] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320] "DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968] "SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536] "Logitech Utility"="Logi_MwX.Exe" [2003-03-04 19968] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midi1"=s3usrdrv.dll "wave1"=s3usrdrv.dll "midi2"=s3fmdrv.dll "aux1"=s3usrdrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Garena\\Garena.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"= "e:\\GAMES\\Steam\\Steam.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Opera\\opera.exe"= "e:\\GAMES\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"= "e:\\GAMES\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"= "e:\\GAMES\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443 "443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443 "37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674 "37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674 "37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675 "139:TCP"= 139:TCP:@xpsp2res.dll,-22004 "445:TCP"= 445:TCP:@xpsp2res.dll,-22005 "137:UDP"= 137:UDP:@xpsp2res.dll,-22001 "138:UDP"= 138:UDP:@xpsp2res.dll,-22002 "57022:TCP"= 57022:TCP:Pando Media Booster "57022:UDP"= 57022:UDP:Pando Media Booster "8394:TCP"= 8394:TCP:League of Legends Launcher "8394:UDP"= 8394:UDP:League of Legends Launcher "6888:TCP"= 6888:TCP:League of Legends Launcher "6888:UDP"= 6888:UDP:League of Legends Launcher [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings] "RemoteAddresses"= * "Enabled"= 1 (0x1) R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [17.6.2009 г. 14:01 20744] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.4.2007 г. 11:46 682232] R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [08.1.2008 г. 17:03 16896] R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [08.1.2008 г. 17:03 52224] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [05.2.2011 г. 13:48 294608] R1 s3knldrv;s3knldrv;c:\windows\system32\drivers\S3KNLDRV.SYS [22.5.2007 г. 19:39 309184] R1 XGIkp;XGIkp;c:\windows\system32\drivers\xrvkp.sys [08.1.2008 г. 19:23 4480] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05.2.2011 г. 13:48 17744] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [17.7.2008 г. 22:26 2368] R3 N100;Compaq Ethernet or Fast Ethernet NIC Driver;c:\windows\system32\drivers\n100325.sys [08.1.2008 г. 22:31 128000] R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [01.9.2010 г. 22:58 17792] S1 s3knljs;s3knljs;c:\windows\system32\drivers\S3KNLJS.SYS [22.5.2007 г. 19:39 17376] S2 gupdate1c99dec842196aa;Google Update Service (gupdate1c99dec842196aa);c:\program files\Google\Update\GoogleUpdate.exe [06.3.2009 г. 01:45 133104] S3 BS_Flash;BS_Flash;\??\c:\program files\BIOS\BIOS Flash\BS_Flash.sys --> c:\program files\BIOS\BIOS Flash\BS_Flash.sys [?] S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [17.6.2009 г. 14:02 30088] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [21.2.2010 г. 04:26 129024] S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\GORO~2.MS-\LOCALS~1\Temp\GTZ2DBB.tmp --> c:\docume~1\GORO~2.MS-\LOCALS~1\Temp\GTZ2DBB.tmp [?] S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\safedrv.sys --> c:\program files\Garena\safedrv.sys [?] S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [17.6.2009 г. 14:01 26248] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [02.8.2005 г. 23:10 32512] S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [23.1.2004 г. 15:33 13952] S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [23.1.2004 г. 15:32 28800] S3 RTCore32;RTCore32;c:\program files\RightMark Memory Analyzer\RTCore32.sys [09.3.2010 г. 11:06 4608] S3 XGIGraphics;XGIGraphics;c:\windows\system32\drivers\xgigrp.sys [08.1.2008 г. 19:23 290432] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs uxtuneup . Contents of the 'Scheduled Tasks' folder 2011-02-09 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 12:37] 2011-02-09 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-26 19:55] 2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 23:45] 2011-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 23:45] 2011-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-920026266-725345543-1003Core.job - c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-05 16:35] 2011-02-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-920026266-725345543-1003UA.job - c:\documents and settings\Goro.MS-GORO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-05 16:35] 2011-02-08 c:\windows\Tasks\User_Feed_Synchronization-{DABEA9C1-D771-436D-A4EA-9DFF20556F97}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 16:36] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.bing.com/?pc=AVBR uInternet Connection Wizard,ShellNext = iexplore IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {A920F5E5-C246-4587-8D29-420A73DE083F} = 94.155.112.12,94.155.112.13 DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab FF - ProfilePath - c:\documents and settings\Goro.MS-GORO\Application Data\Mozilla\Firefox\Profiles\wkqmrmxm.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.vbox7.com/ FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-02-09 02:46 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine] "ImagePath"="\??\c:\docume~1\GORO~2.MS-\LOCALS~1\Temp\GTZ2DBB.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(980) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3776) c:\windows\system32\msi.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\PnkBstrA.exe c:\windows\System32\TUProgSt.exe c:\windows\SOUNDMAN.EXE c:\windows\Logi_MwX.Exe c:\windows\system32\wscntfy.exe c:\windows\ggdrive32.exe c:\documents and settings\Goro.MS-GORO\ms.exe . ************************************************************************** . Completion time: 2011-02-09 02:55:59 - machine was rebooted ComboFix-quarantined-files.txt 2011-02-09 00:55 ComboFix2.txt 2011-02-07 20:33 ComboFix3.txt 2011-02-06 20:41 ComboFix4.txt 2011-02-06 19:15 Pre-Run: 1 697 173 504 bytes free Post-Run: 1 577 439 232 bytes free - - End Of File - - E27A0F510060DEF7BC4F6F3D3ECBFEF3

Перфектно..!Сега мога да кажа с чиста съвест че системата ви е чиста..!Не виждам активни зарази...!:baby:Ако нямате други проблеми и въпроси да пристъпим към деинсталиране на ComboFix така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете OTCleanIt или от тук,стартирайте и натиснете Clean up

  • Автор

Еми какво да ви кажа, наистина в момента е доста по добре но пак от време на време се случва да засече някое клипче, да даде Generic host error или пак да стане онази простотия с изкривяването на звука ( но това в приемливи количества в сравнение с преди). Благодаря ви много за положените усилия да изчистите системата ми. След някакво време ще си сложа Windows 7 и се надявам всички проблеми да изчезнат и както четох в 1 статия за него да увеличи произведителността на машината ми.

Всички тези засичания определено не се дължат на вируси..!Мaркирам случая като РЕШЕН...Ако има проблем пишете...!Лек ден..!:)

  • Автор

Уффф, пак се бъгна скапаният компютър, пак едва зареждам страниците :speak::cool::(

Извинявам се предварително , че пиша тук , ако модераторите сметнат за нужно да изтрият коментара ми . darkman93 , колега вземи разкарай малко програми , то booster-и , mechanic-и ......tweaker-и , може и да се оправи компютъра .

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.