Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Как да изтрия Windows Rescue Center [ РЕШЕН]

Featured Replies

Здравейте вчера лаптопа ми попадна в клопката на тази програма.Помислих си че наистина има вирус и натиснах ОК да я инсталирам (много тъпо).

Сега не мога да използвам лаптопа пълноценно постоянно ми се показват фалшиви съобщения за грешки,не мога да влизам в програмите или ако вляза излизам след 1-2 минути.Опитах да рестартирам системата с 2-3 дена назад,но след 4-5 часово чакане (да затвори мрежовите връзки) се отказах.

Моля ви кажете ми как да я махна защото лаптопа ми трябва...

Благодаря предварително

П.С. Ето как изглежда програмата (снимката не е моя)

Публикувано изображение

Здравейте...!:)Windows Rescue Center е типична фалшива анти-спайуер Rogue програма...!:)

Стъпка 1:

Изтеглете rkill.com Download Link и го запазете на десктопа си.С тази програма ще се опитаме да спрем всички процеси на защитния ви софтуер - временно.Кликнете два пъти върху иконката и чакате търпеливо.Ако антивирусната ви засече rkill като инфекция не трябва да се притеснявате..нормално е .Това е фалшив сигнал.

Едно условие имаме само - не рестартирайте компютъра си защото спрените процеси ще стартират отново..!

Стъпка 2:

Изтеглете Shell.reg Download Link и го запазете на десктопа си.Старирате с двоен клик и потвърждавате когато Windows ви пита дали искате данните да бъдат обединени, моля, изчакайте я да го направи.

Стъпка 3:

  • Изтеглете Malwarebytes' Anti-Malware Free от тук
  • Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.
  • Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.
  • Ако има намерени обновявания, тя ще ги изтегли и инсталира.
  • Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.
  • Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.
  • Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.
  • Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.
  • Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.
Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

  • Автор

аз не мога да изтегля програми от лаптопа не мога да отворя браузера видях друг начин http://trojan-killer.net/how-to-delete-windows-resque-center-fake-removal-guide/?lang=bg#more-3027 но като отворя папка WINDOWS на юзера вместо да ми се отвори папката с файловете-и заразения файл,ми се отваря празна папка какво да направя имам и друг проблем не мога да намеря папката application data

Рестартирайте компюютъра си и РАЗРЕШЕТЕ на фалшивата програма да направи сканирането....естествено това което ще засече програмата е абсолютно невярно.След като завърши сканирането натиснете Fix Errors....След това затворете програмата - X.След затваряне на програмата, вашия Desktop ще се зареди нормално. Опитайте се да направите стъпките от горния ми пост...!!!

Поздрави..!:)

  • Автор

ок ще направя тези стъпки и ще пиша пак не мога да отворя файловете кажете ми моля ви какво да правя

  • Автор

благодарение на ицотонев мисля че успях да се справя с вируса ето и лога Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Версия на базата от данни: 6774 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 05.6.2011 г. 03:10:05 mbam-log-2011-06-05 (03-10-05).txt Тип сканиране: Пълно сканиране (C:\|D:\|E:\|F:\|) Сканирани обекти: 208395 Изминало време: 1 час(а), 2 минута(и), 11 секунда(и) Заразени процеси в паметта: 0 Заразени модули в паметта: 0 Заразени ключове в регистратурата: 3 Заразени стойности в регистратурата: 0 Заразени информационни обекти в регистратурата: 4 Заразени папки: 1 Заразени файлове: 121 Заразени процеси в паметта: (Не бяха открити зловредни обекти) Заразени модули в паметта: (Не бяха открити зловредни обекти) Заразени ключове в регистратурата: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\MADOWN (Worm.Magania) -> Quarantined and deleted successfully. Заразени стойности в регистратурата: (Не бяха открити зловредни обекти) Заразени информационни обекти в регистратурата: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Заразени папки: c:\RECYCLER\s-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Quarantined and deleted successfully. Заразени файлове: c:\9d6tpg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\09lf.exe (Worm.Taterf) -> Quarantined and deleted successfully. c:\1hqup.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\1j038ki.exe (Trojan.PWS) -> Quarantined and deleted successfully. c:\2id9.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\2u923g01.exe (Worm.Taterf) -> Quarantined and deleted successfully. c:\31lyx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\3exi.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\62.exe (Worm.Taterf) -> Quarantined and deleted successfully. c:\8xcrbho6.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\9d6resf.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\g6jk.exe (Worm.Magania) -> Quarantined and deleted successfully. c:\ggb6w.exe (Trojan.Onlinegames) -> Quarantined and deleted successfully. c:\h0.exe (Trojan.GamesThief) -> Quarantined and deleted successfully. c:\i8gcgmg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\imghyva6.exe (Trojan.PWS) -> Quarantined and deleted successfully. c:\io3yalc.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\jeo3ky.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\jofk1wf.exe (Trojan.GamesThief) -> Quarantined and deleted successfully. c:\k1d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\k8jc.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\krwyrv0d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\kyme.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\lpl.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\mbdm.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\mbvd.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\mk28sp.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\mvmdh.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\o1o.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\p3vwxx.exe (Worm.Taterf) -> Quarantined and deleted successfully. c:\pcxis.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\9fo3ar0j.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\9rfpp.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\awb3ryk.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\c2e.exe (Spyware.OnLineGames) -> Quarantined and deleted successfully. c:\e9naq.exe (Spyware.OnLineGames) -> Quarantined and deleted successfully. c:\f2kmj.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\fk.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\q3kku.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\r3q63rok.exe (Trojan.GamesThief) -> Quarantined and deleted successfully. c:\r3x0k.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\rxf.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\s1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\sywyrl0q.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\tgt.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\vi8f.exe (Worm.Tartef) -> Quarantined and deleted successfully. c:\wisf1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\x3xh.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\xjb3.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\xmor.exe (Spyware.Password) -> Quarantined and deleted successfully. c:\program files\Stardock\object desktop\iconpackager\builder.icl (Trojan.Agent) -> Quarantined and deleted successfully. c:\program files\Stardock\object desktop\windowblinds\PATCH.exe (PUP.Riskware.Tool.CK) -> Quarantined and deleted successfully. c:\program files\wondershare\dvd slideshow builder\wondershare.dvd.slideshow.builder.3.1.0.x-patch.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\application data\microsoft\gfrvhr.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\nodqq0.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\nodqq1.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\dsoqq0.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\dsoqq1.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\apiqq1.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\temporary directory 1 for wondershare.dvd.slideshow.builder.3.1.0.x.patch-snd.zip\wondershare.dvd.slideshow.builder.3.1.0.x-patch.exe (PUP.Hacktool.Patcher) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\my documents\skin\iconpackager enhanced v3.0 (stardock) universal keygen.exe (Riskware.Tool.CK) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\my documents\skin\winblinds5.5\PATCH.exe (PUP.Riskware.Tool.CK) -> Quarantined and deleted successfully. d:\09lf.exe (Worm.Taterf) -> Quarantined and deleted successfully. d:\1hqup.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\1j038ki.exe (Trojan.PWS) -> Quarantined and deleted successfully. d:\2id9.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\2u923g01.exe (Worm.Taterf) -> Quarantined and deleted successfully. d:\31lyx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\c2e.exe (Spyware.OnLineGames) -> Quarantined and deleted successfully. d:\e9naq.exe (Spyware.OnLineGames) -> Quarantined and deleted successfully. d:\f2kmj.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\fk.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\g6jk.exe (Worm.Magania) -> Quarantined and deleted successfully. d:\ggb6w.exe (Trojan.Onlinegames) -> Quarantined and deleted successfully. d:\o1o.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\p3vwxx.exe (Worm.Taterf) -> Quarantined and deleted successfully. d:\pcxis.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\q3kku.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\r3q63rok.exe (Trojan.GamesThief) -> Quarantined and deleted successfully. d:\r3x0k.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\rxf.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\s1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\62.exe (Worm.Taterf) -> Quarantined and deleted successfully. d:\8xcrbho6.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\9d6resf.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\9d6tpg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\9fo3ar0j.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\9rfpp.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\io3yalc.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\jeo3ky.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\jofk1wf.exe (Trojan.GamesThief) -> Quarantined and deleted successfully. d:\k1d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\k8jc.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\krwyrv0d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\kyme.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\lpl.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\mbdm.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\mbvd.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\mk28sp.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\mvmdh.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\sywyrl0q.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\tgt.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\3exi.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\awb3ryk.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\h0.exe (Trojan.GamesThief) -> Quarantined and deleted successfully. d:\vi8f.exe (Worm.Tartef) -> Quarantined and deleted successfully. d:\wisf1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\x3xh.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\xjb3.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\xmor.exe (Spyware.Password) -> Quarantined and deleted successfully. d:\y.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\i8gcgmg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. d:\imghyva6.exe (Trojan.PWS) -> Quarantined and deleted successfully. d:\guitar pro 5.2\guitar pro 5.2\guitar pro 5.2\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. c:\9qqigqwf.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\9xf8.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\yqq8eqil.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\utt272.tmp.exe (Trojan.Pakes) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\cvasds0.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\documents and settings\Plamen\local settings\Temp\cvasds1.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. c:\RECYCLER\s-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.

  • Автор

не ! вече мога ли да махам rKill и shell.reg и освен това тея файлове заразените да ги изтрия ли от карантината

Искам да провяеря дали всичко е наред..за целта:

  • Изтеглете DDS: от BleepingComputer.
  • След изтегляне на файла го запишете (бутон Save => Save as) DDS на вашия десктоп, снимка:

    Публикувано изображение

  • След като изтеглите DDS на десктопа, иконката на програмата би трябвало да изглежда така: Публикувано изображение
  • Прекратете временно работата на всички скрипт блокиращи приложения, ако има такива или разрешете изпълнението на dds.scr. След това стартирайте DDS с двоен клик на иконката, като потвърдите с Run.
  • След приключване на работата на DDS копирайте с Copy текста от двата файлови лога, които ще се появят в Notepad: DDS.txt и Attach.txt и ги запазете (бутон Save => Save as) на десктопа си.
  • Копирайте и поставете съдържанието на DDS.txt и Attach.txt във вашата тема. Моля, не ги прикачвайте!

не ! вече мога ли да махам rKill и shell.reg

Изтрийте ги спокойно...За сега си оставете МБАМ.....всъщност ви препоръчвам да си я оставите на компютъра и периодично да я обновявате и сканирате с нея...поне веднъж в седмицата...!:)

  • Автор

ето Attach . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-03.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 29.9.2007 г. 15:30:32 System Uptime: 05.6.2011 г. 03:52:59 (1 hours ago) . Motherboard: FUJITSU SIEMENS | | AMILO PRO V2055 Processor: Intel® Celeron® M CPU 410 @ 1.46GHz | mPGA 479M | 1462/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 20 GiB total, 4,027 GiB free. D: is FIXED (NTFS) - 36 GiB total, 2,947 GiB free. E: is CDROM () F: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP510: 30.4.2011 г. 11:24:09 - System Checkpoint RP511: 30.4.2011 г. 12:22:50 - Removed Opera 11.01. RP512: 02.5.2011 г. 12:20:13 - System Checkpoint RP513: 05.5.2011 г. 02:42:30 - System Checkpoint RP514: 06.5.2011 г. 02:57:55 - System Checkpoint RP515: 08.5.2011 г. 02:30:27 - System Checkpoint RP516: 10.5.2011 г. 02:20:07 - System Checkpoint RP517: 11.5.2011 г. 02:26:36 - System Checkpoint RP518: 12.5.2011 г. 23:11:15 - System Checkpoint RP519: 14.5.2011 г. 07:46:14 - System Checkpoint RP520: 20.5.2011 г. 14:48:15 - System Checkpoint RP521: 22.5.2011 г. 03:46:34 - System Checkpoint RP522: 23.5.2011 г. 04:09:31 - System Checkpoint RP523: 24.5.2011 г. 14:35:42 - System Checkpoint RP524: 26.5.2011 г. 00:43:00 - System Checkpoint RP525: 27.5.2011 г. 08:20:56 - System Checkpoint RP526: 29.5.2011 г. 03:06:52 - System Checkpoint RP527: 30.5.2011 г. 22:00:18 - System Checkpoint RP528: 01.6.2011 г. 00:14:37 - System Checkpoint RP529: 02.6.2011 г. 01:19:44 - System Checkpoint RP530: 03.6.2011 г. 02:01:21 - System Checkpoint RP531: 04.6.2011 г. 03:59:33 - Операция за възстановяване RP532: 04.6.2011 г. 06:20:45 - Операция за възстановяване RP533: 04.6.2011 г. 06:30:05 - Операция за възстановяване RP534: 04.6.2011 г. 09:48:36 - Операция за възстановяване RP535: 04.6.2011 г. 12:06:55 - Операция за възстановяване RP536: 05.6.2011 г. 03:00:23 - Software Distribution Service 3.0 . ==== Installed Programs ====================== . ACE Mega CoDecS Pack ADMINRD_INSTALL_CLIENT_2008 AdminRD_Install_server Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0.9 Brother HL-5350DN Brother MFL-Pro Suite BS.Player FREE Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX Canon G.726 WMP-Decoder Canon MovieEdit Task for ZoomBrowser EX Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX CDex extraction audio Chicken Invaders: Revenge of the Yolk (Christmas Edition) v3.20 Compatibility Pack for the 2007 Office system CP_Package_Variety1 CP_Package_Variety2 CP_Package_Variety3 Critical Update for Windows Media Player 11 (KB959772) DAEMON Tools Toolbar eBay Icon FlexType 2K GOM Player Google Chrome Google Update Helper Google чµјя Guitar Pro 5.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) IconPackager J2SE Runtime Environment 5.0 Update 7 Java 6 Update 17 Malwarebytes' Anti-Malware, Іµрсёя 1.51.0.1200 MathPlayer Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Motorola SM56 Speakerphone Modem Mozilla Firefox (3.6.3) MyPhoneExplorer Nero Suite Opera 11.11 Oxford Picture Dictionary uninstall Panda Antivirus 2008 PaperPort Power Tab Editor 1.7 PowerDVD Realtek AC'97 Audio Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Skype Toolbars Skype™ 5.3 The Rosetta Stone Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB975364) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Service VIA Rhine-Family Fast Ethernet Adapter VIA/S3G Display Driver WebFldrs XP Winamp (remove only) WindowBlinds Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Wondershare DVD Slideshow Builder 3.1.0 ррхёІ°тѕр WinRAR рґјёЅПрѕ µTorrent . ==== Event Viewer Messages From Past Week ======== . 31.5.2011 і. 22:02:04, error: Dhcp [1002] - The IP address lease 192.168.1.102 for the Network Card with network address 00140B015053 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 31.5.2011 і. 02:49:31, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 00140B015053 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 29.5.2011 і. 23:17:30, error: Dhcp [1002] - The IP address lease 192.168.1.107 for the Network Card with network address 00140B015053 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 05.6.2011 і. 03:53:36, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 05.6.2011 і. 01:14:04, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:13:58, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:13:45, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:13:26, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:05:18, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:04:16, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:04:13, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 01:04:03, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:31:38, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:31:36, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:31:18, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:31:18, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:21:38, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:20:59, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:20:57, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 05.6.2011 і. 00:20:51, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:11:55, error: EventLog [6004] - A driver packet received from the I/O subsystem was invalid. The data is the packet. 04.6.2011 і. 12:11:31, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:10:39, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:10:29, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:10:27, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:05:24, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:05:23, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:05:04, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 12:04:59, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 09:47:39, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 09:47:32, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 09:47:24, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 09:47:17, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 06:30:08, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 04.6.2011 і. 06:28:57, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 04.6.2011 і. 06:28:39, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 04.6.2011 і. 06:27:28, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ShldDrv sptd Tcpip Tcpip6 WS2IFSL 04.6.2011 і. 06:27:28, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 06:27:28, error: Service Control Manager [7001] - The IPv6 Helper Service service depends on the Microsoft IPv6 Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 06:27:28, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 06:27:28, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 06:27:28, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 06:26:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 04.6.2011 і. 06:26:34, error: sptd [4] - Driver detected an internal error in its data structures for . 04.6.2011 і. 06:19:42, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 06:19:33, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 06:18:52, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 06:18:50, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 03:59:36, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 04.6.2011 і. 03:58:21, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 04.6.2011 і. 03:55:55, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ShldDrv sptd Tcpip Tcpip6 WS2IFSL 04.6.2011 і. 03:55:55, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 03:55:55, error: Service Control Manager [7001] - The IPv6 Helper Service service depends on the Microsoft IPv6 Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 03:55:55, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 03:55:55, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 03:55:55, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 04.6.2011 і. 03:55:17, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 04.6.2011 і. 03:55:01, error: sptd [4] - Driver detected an internal error in its data structures for . 04.6.2011 і. 02:59:26, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:59:16, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:59:15, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:59:09, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:53:17, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:53:11, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:53:07, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:52:45, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:43:09, error: EventLog [6004] - A driver packet received from the I/O subsystem was invalid. The data is the packet. 04.6.2011 і. 02:35:45, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:35:12, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:35:00, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:34:55, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:31:38, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:31:24, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:22:31, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:22:27, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:22:27, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 04.6.2011 і. 02:22:27, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). 01.6.2011 і. 21:56:01, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 00140B015053 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== ето го и другия файл . DDS (Ver_2011-06-03.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Run by Plamen at 4:17:28 on 2011-06-05 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.446.141 [GMT -7:00] . AV: Panda Antivirus 2008 *Enabled/Updated* {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Brother\ControlCenter2\brctrcen.exe C:\Program Files\Brownie\BrstsWnd.exe C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\Brownie\brpjp04a.exe C:\WINDOWS\Datecs\Flex2K.exe C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe C:\Program Files\Opera\opera.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Skype\Phone\Skype.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://start.drp.su/ uInternet Connection Wizard,ShellNext = iexplore BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun mRun: [VTTimer] VTTimer.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\windows\system32\qttask.exe" -atboottime mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe" mRun: [APVXDWIN] "c:\program files\panda security\panda antivirus 2008\APVXDWIN.EXE" /s mRun: [sSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe mRun: [indexSearch] c:\program files\scansoft\paperport\IndexSearch.exe mRun: [setDefPrt] c:\program files\brother\brmfl05c\BrStDvPt.exe mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [brStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [sMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe dRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\flexty~1.lnk - c:\windows\datecs\Flex2K.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0) IE: Е&кспортирай в Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: c:\program files\panda security\panda antivirus 2008\pavlsp.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{71CB3FC6-B3E4-4354-B6D6-41C797DBAD86} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{97148B2C-AE2F-4FF7-A7B2-BA3AB6CF4E1E} : DhcpNameServer = 192.168.1.1 Filter: application/xhtml+xml - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - c:\program files\design science\mathplayer\MathMLMimer.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avldr - avldr.dll Notify: WBSrv - c:\progra~1\stardock\object~1\window~1\wbsrv.dll AppInit_DLLs: wbsys.dll SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\windows\system32\iprepair.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 nwprovau . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\plamen\application data\mozilla\firefox\profiles\shjj6g3k.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - DAEMON Search FF - prefs.js: browser.startup.homepage - hxxp://my.daemon-search.com/startpage|http://start.drp.su/ FF - component: c:\documents and settings\plamen\application data\mozilla\firefox\profiles\shjj6g3k.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\FFExternalAlert.dll FF - component: c:\documents and settings\plamen\application data\mozilla\firefox\profiles\shjj6g3k.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.dll FF - component: c:\documents and settings\plamen\application data\mozilla\firefox\profiles\shjj6g3k.default\extensions\[email protected]\components\DTToolbarFF.dll FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - plugin: c:\program files\ace mega codecs pack\systems\realmedia\browser\plugins\nppl3260.dll FF - plugin: c:\program files\ace mega codecs pack\systems\realmedia\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: DAEMON Tools Toolbar: [email protected] - %profile%\extensions\[email protected] FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: BS Player Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [email protected] - c:\program files\java\jre6\lib\deploy\jqs\ff . ============= SERVICES / DRIVERS =============== . R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [2009-1-30 38968] R2 pavdrv;pavdrv;c:\windows\system32\drivers\pavdrv51.sys [2009-1-30 83896] R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [2009-1-30 178872] R3 EKBfltr;ENE Keyboard Controller;c:\windows\system32\drivers\EKBfltr.sys [2005-1-14 5504] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-13 136176] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-6-6 13224] S3 gupdatem;Ус»уі° Ѕ° Google рєту°»ё·°цёя (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-7-13 136176] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-6-5 39984] . =============== Created Last 30 ================ . 2011-06-05 08:42:05 -------- d-----w- c:\documents and settings\plamen\application data\Malwarebytes 2011-06-05 08:42:00 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-06-05 08:41:57 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2011-06-05 08:41:53 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-06-05 08:41:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-05-21 09:08:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . ==================== Find3M ==================== . 2011-04-26 07:36:11 0 ----a-w- c:\windows\system32\ConduitEngine.tmp 2011-03-12 21:27:01 691696 ----a-w- c:\windows\system32\drivers\sptd.sys . ============= FINISH: 4:20:03,32 ===============

Изтеглете ComboFix от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.

Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs

  • Стартирайте Combo-Fix.com и следвайте инструкциите.

Бележка: ComboFix ще се стартира без инсталирана Recovery Console.

  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.

  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.

Работата на ComboFix, може да отнеме до 20-30 минути, за да завърши, моля имайте търпение.

Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

Всъщност остави за сега това сканиране....!!!

Само ти препоръчвам да си ъпдейтнеш Java™ 6 Update 17 с новта Version 6 Update 25,освен това махни от компютъра си недоразумението FlexType 2K...кирилизирай си системата като си избереш някои от тези варианти.

Adobe Reader - също - с Adobe Reader X (10.0.1)

А относно последното сканиране с Комбофикс - има все още съмнителни файлове в системата ви....!!!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.