Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

DDS.txt и Attach.txt [РЕШЕН]

Featured Replies

здравеите от 1 седмица исталирам деуцталирам чета трия,дано да мойете да ми помогнете...

ето и фаиловете

attach

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-06-23.01)

.

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 6/14/2011 4:39:52 PM

System Uptime: 8/9/2011 11:59:43 PM (2 hours ago)

.

Motherboard: ASUSTeK Computer INC. | | P5N-E SLI

Processor: Intel Pentium III Xeon processor | Socket 775 | 2499/200mhz

.

==== Disk Partitions =========================

.

A: is Removable

C: is FIXED (NTFS) - 128 GiB total, 91.997 GiB free.

D: is CDROM ()

E: is CDROM ()

F: is FIXED (NTFS) - 571 GiB total, 552.24 GiB free.

G: is CDROM ()

.

==== Disabled Device Manager Items =============

.

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}

Description: PCI Device

Device ID: PCI\VEN_197B&DEV_2360&SUBSYS_82081043&REV_02\4&268339C6&0&0038

Manufacturer:

Name: PCI Device

PNP Device ID: PCI\VEN_197B&DEV_2360&SUBSYS_82081043&REV_02\4&268339C6&0&0038

Service:

.

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: Realtek RTL8139 Family PCI Fast Ethernet NIC

Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\4&DC268A3&0&3080

Manufacturer: Realtek

Name: Realtek RTL8139 Family PCI Fast Ethernet NIC

PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\4&DC268A3&0&3080

Service: rtl8139

.

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: Realtek RTL8139 Family PCI Fast Ethernet NIC

Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\4&DC268A3&0&3880

Manufacturer: Realtek

Name: Realtek RTL8139 Family PCI Fast Ethernet NIC #2

PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\4&DC268A3&0&3880

Service: rtl8139

.

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: 1394 Net Adapter

Device ID: V1394\NIC1394\124754E1E8C00

Manufacturer: Microsoft

Name: 1394 Net Adapter

PNP Device ID: V1394\NIC1394\124754E1E8C00

Service: NIC1394

.

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}

Description:

Device ID: ACPI\ATK0110\1010110

Manufacturer:

Name:

PNP Device ID: ACPI\ATK0110\1010110

Service:

.

==== System Restore Points ===================

.

No restore point in system.

.

==== Installed Programs ======================

.

Пакет обеспечения совместимости для выпуска 2007 системы Microsoft Office

24hPoker

4Donk Live

888poker

A?oeaaoi? WinRAR

ActionPoker.com

Adobe AIR

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Adobe Shockwave Player 11.6

AirPlus XtremeG DWL-G122

AKPokerClub

AMD APP SDK Runtime

ANIO Service

ANIWZCS2 Service

ArcSoft PhotoStudio 5.5

ATI Catalyst Install Manager

AVG 2011

Betfair Poker JPC 1.0.0

Betfred Poker

BFL_FIFA_10

BitComet 1.28

Bluff Room

Bodog Poker

Bulgarian (New Phonetic)

Canon CanoScan Toolbox 4.9

Canon LBP6000/LBP6018

Canon ScanGear Starter

CANYON USB PC Camera

CarbonPoker

Casino at bet365

Catalyst Control Center

Catalyst Control Center - Branding

Catalyst Control Center Graphics Previews Common

Catalyst Control Center InstallProxy

ccc-utility

CCC Help English

Codec Pack - All In 1 6.0.3.0

ComeOn Poker

Conduit Engine

Cool Hand Poker

Cristal Poker

DAEMON Tools Pro

Download Updater (AOL LLC)

FIFA 10

FoxTab PDF Converter

Full Tilt Poker

Google Chrome

Google Earth Plug-in

Google Toolbar for Internet Explorer

Google Update Helper

HiJackThis

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

Hotfix for Windows XP (KB954550-v5)

Hotfix for Windows XP (KB961118)

Hotfix for Windows XP (KB974841-v2)

Intertops Poker

Java Auto Updater

Java 6 Update 26

Jetbull Poker

Launch Manager

Malwarebytes' Anti-Malware version 1.51.1.1800

Manual CanoScan LiDE 25

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Security Update (KB2416447)

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft Application Error Reporting

Microsoft Fix it Center

Microsoft IntelliType Pro 8.0

Microsoft Office Professional Edition 2003

Microsoft Silverlight

Microsoft Tool Web Package : INSTALER.EXE

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

MPEG2 Codec(libmpeg2/mad)

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP3 Parser

MSXML 4.0 SP3 Parser (KB973685)

myBet Poker

Nero Suite

NordicBet

NVIDIA Drivers

NVIDIA Performance

NVIDIA System Monitor

NVIDIA System Update

OmniPage SE 2.0

ParetoLogic PC Health Advisor

PKR

PMB

Poker Heaven

Pokernet

Pokerplex24

PokerStars

PokerStars.net

PokerTime

Realtek HDMI Audio Driver for ATI

Realtek High Definition Audio Driver

Redbet

Redbet Poker

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)

Security Update for Windows Internet Explorer 8 (KB2510531)

Security Update for Windows Internet Explorer 8 (KB2530548)

Security Update for Windows Internet Explorer 8 (KB2544521)

Security Update for Windows Internet Explorer 8 (KB982381)

Security Update for Windows XP (KB2124261)

Security Update for Windows XP (KB2290570)

Security Update for Windows XP (KB946648)

Security Update for Windows XP (KB954459)

Security Update for Windows XP (KB970483)

Security Update for Windows XP (KB976323)

Skype Toolbars

Skype™ 5.3

Smoking Aces Poker

SweetIM for Messenger 3.4

SweetIM Toolbar for Internet Explorer 4.1

swMSM

The Gaming Club

Unibet

Uniblue DriverScanner

Uniblue RegistryBooster

Uniblue SpeedUpMyPC

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Windows Internet Explorer 8 (KB2447568)

WebFldrs XP

WIDCOMM Bluetooth Software

Winamp

Winamp Detector Plug-in

Windows Internet Explorer 8

Windows Media Format 11 runtime

Windows Media Player 11

Windows PowerShell 1.0

YogaPoker

.

==== Event Viewer Messages From Past Week ========

.

8/8/2011 6:54:15 AM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\NVIDIA Corporation\NVIDIA System Monitor\MFC80.DLL. Reference error message: The operation completed successfully. .

8/8/2011 4:14:08 PM, error: smtpsvc [1004] - Virtual server 1 was unable to register itself and the local delivery sink with the event binding database. Server events and local delivery will not function properly for this virtual server.

8/8/2011 4:14:08 PM, error: smtpsvc [1002] - Server events initialization failed for virtual server 1. Server events may not be called for this virtual server.

8/6/2011 8:06:08 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgtdix sptd

8/6/2011 8:05:53 AM, error: Service Control Manager [7000] - The PMBDeviceInfoProvider service failed to start due to the following error: The system cannot find the path specified.

8/6/2011 8:05:53 AM, error: Service Control Manager [7000] - The Java Quick Starter service failed to start due to the following error: The system cannot find the path specified.

8/6/2011 8:05:53 AM, error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the path specified.

8/6/2011 8:05:53 AM, error: Service Control Manager [7000] - The Bluetooth Service service failed to start due to the following error: The system cannot find the path specified.

8/6/2011 8:05:53 AM, error: Service Control Manager [7000] - The Ati HotKey Poller service failed to start due to the following error: The system cannot find the file specified.

8/6/2011 8:05:25 AM, error: Microsoft Antimalware [3002] -

8/6/2011 6:03:41 PM, error: SideBySide [59] - Generate Activation Context failed for F:\Program Files\Bodog Poker\BPGame.exe. Reference error message: The operation completed successfully. .

8/6/2011 6:03:41 PM, error: SideBySide [58] - Syntax error in manifest or policy file "F:\Program Files\Bodog Poker\Microsoft.VC80.MFC.MANIFEST" on line 4.

8/6/2011 6:03:41 PM, error: SideBySide [34] - Component identity found in manifest does not match the identity of the component requested

8/6/2011 12:43:05 AM, error: Service Control Manager [7034] - The Pokernet service terminated unexpectedly. It has done this 1 time(s).

8/6/2011 12:42:17 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

8/6/2011 12:41:59 AM, error: Service Control Manager [7022] - The Pokernet service hung on starting.

8/6/2011 12:18:05 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB973685).

8/6/2011 12:04:08 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Office 2003 Service Pack 3 (SP3).

8/6/2011 10:43:49 AM, error: Service Control Manager [7028] - The Cfg Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.

8/6/2011 10:31:30 AM, error: Service Control Manager [7000] - The AVG TDI Driver service failed to start due to the following error: The system cannot find the file specified.

8/6/2011 10:04:12 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 002401A70262. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

8/6/2011 1:32:49 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the 6to4 service.

8/5/2011 9:58:15 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Pokernet service to connect.

8/5/2011 9:58:15 PM, error: Service Control Manager [7000] - The Pokernet service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

8/5/2011 5:54:47 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .

8/5/2011 5:54:47 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\PacificPoker\bin\casinopoker\bin\Microsoft.VC80.MFC\MFC80.DLL. Reference error message: The operation completed successfully. .

8/5/2011 5:54:47 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.

8/5/2011 4:51:20 PM, error: Service Control Manager [7000] - The Microsoft Antimalware Service service failed to start due to the following error: The system cannot find the path specified.

8/4/2011 7:44:20 PM, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.

8/4/2011 7:44:01 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

8/4/2011 10:21:29 PM, error: Service Control Manager [7000] - The Microsoft Antimalware Service service failed to start due to the following error: Access is denied.

8/4/2011 10:21:29 PM, error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: Access is denied.

8/4/2011 10:21:29 PM, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the path specified.

8/4/2011 10:21:29 PM, error: Service Control Manager [7000] - The AVG Firewall service failed to start due to the following error: The system cannot find the path specified.

8/4/2011 1:29:01 PM, error: Service Control Manager [7000] - The PMBDeviceInfoProvider service failed to start due to the following error: The system cannot find the file specified.

8/4/2011 1:29:01 PM, error: Service Control Manager [7000] - The Java Quick Starter service failed to start due to the following error: The system cannot find the file specified.

8/4/2011 1:29:01 PM, error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the file specified.

8/4/2011 1:29:01 PM, error: Service Control Manager [7000] - The Bluetooth Service service failed to start due to the following error: The system cannot find the file specified.

8/4/2011 1:29:01 PM, error: Service Control Manager [7000] - The AVG WatchDog service failed to start due to the following error: The system cannot find the file specified.

8/4/2011 1:29:01 PM, error: Service Control Manager [7000] - The AVG Firewall service failed to start due to the following error: The system cannot find the file specified.

8/3/2011 3:15:28 PM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found.

.

==== End Of File ===========================

dds

.

DDS (Ver_2011-06-23.01) - NTFSx86

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26

Run by Karina at 1:29:14 on 2011-08-10

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.684 [GMT 3:00]

.

AV: AVG Internet Security 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FW: AVG Firewall *Disabled*

.

============== Running Processes ===============

.

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe

C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe

C:\Program Files\AVG\AVG10\avgfws.exe

C:\Program Files\AVG\AVG10\avgwdsvc.exe

svchost.exe

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe

C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe

C:\Program Files\AVG\AVG10\avgam.exe

C:\Program Files\D-Link\AirPlus XtremeG DWL-G122\AirGCFG.exe

svchost.exe

C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\VMSnap23.exe

C:\WINDOWS\Domino.exe

C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNAP2RPK.EXE

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNABCSWK.EXE

C:\Program Files\SweetIM\Messenger\SweetIM.exe

C:\Program Files\AVG\AVG10\avgtray.exe

C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE

C:\Program Files\Microsoft IntelliType Pro\itype.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\DAEMON Tools Pro\DTAgent.exe

C:\Program Files\Uniblue\DriverScanner\driverscanner.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\WINDOWS\system32\wuauclt.exe

C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE

C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\PROGRA~1\AVG\AVG10\avgrsx.exe

C:\Program Files\AVG\AVG10\avgcsrvx.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\PokerStars\PokerStars.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe

F:\Program Files\PKR\pokerapp.exe

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Karina\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\rundll32.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.bg/

uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll

uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {eee6c35d-6118-11dc-9c72-001320c79847} -

mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll

BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - Conduit Engine

BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.5.4.11.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll

BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: SkypeIEPluginBHO: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - Skype Browser Helper

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: SWEETIE: {eee6c35c-6118-11dc-9c72-001320c79847} - SweetIM Toolbar Helper

TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} -

TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} -

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun

uRun: [speedUpMyPC] "c:\program files\uniblue\speedupmypc\launcher.exe" delay 20000

uRun: [DriverScanner] "c:\program files\uniblue\driverscanner\launcher.exe" delay 20000

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [D-Link AirPlus XtremeG DWL-G122] c:\program files\d-link\airplus xtremeg dwl-g122\AirGCFG.exe

mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe

mRun: [iSUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [Alcmtr] ALCMTR.EXE

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [bigDogPath323VMSnap] c:\windows\VMSnap23.exe

mRun: [bigDogPath323Domino] c:\windows\Domino.exe

mRun: [OpwareSE2] "c:\program files\scansoft\omnipagese2.0\OpwareSE2.exe"

mRun: [CNAP2 Launcher] c:\windows\system32\spool\drivers\w32x86\3\CNAP2LAK.EXE

mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe

mRun: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"

mRun: [sweetIM] c:\program files\sweetim\messenger\SweetIM.exe

mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe

mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE

mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"

mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe

IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm

IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html

IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe

IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm

IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.5.4.11.dll/206

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - f:\program files\bodog poker\BPGame.exe

IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5}

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL

LSP: mswsock.dll

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204

DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1307653455827

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1307735326077

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{1ABDE162-AD25-4932-9D13-2B87B9846ED3} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{837E32BB-6C6D-43C2-9A81-4F093718FDF8} : DhcpNameServer = 192.168.1.1

Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll

Notify: AtiExtEvent - Ati2evxx.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

LSA: Authentication Packages = msv1_0 nwprovau

.

============= SERVICES / DRIVERS ===============

.

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]

R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]

R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]

R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]

R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-8-1 233024]

R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2011-3-9 2708024]

R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752]

R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]

R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [2011-8-4 45696]

R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2011-8-8 101392]

R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432]

R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480]

R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]

R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]

R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248]

R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [2011-8-4 56960]

R3 vmfilter323;323 filter service, Normal;c:\windows\system32\drivers\vmfilter323.sys [2011-6-15 476672]

R3 ZSMC326;CANYON USB PC Camera;c:\windows\system32\drivers\usbvm323.sys [2011-6-15 260224]

S1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys --> c:\windows\system32\drivers\avgtdix.sys [?]

S2 Guard.Mail.ru;Guard.Mail.ru; [x]

S2 gupdate;Google Update Service (gupdate); [x]

S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider; [x]

S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-8-1 1025352]

S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432]

S3 gupdatem;Google Update Service (gupdatem); [x]

S3 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]

S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-8-10 41272]

.

=============== Created Last 30 ================

.

2011-08-09 22:04:26 -------- d-----w- c:\documents and settings\karina\application data\Malwarebytes

2011-08-09 22:04:15 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-08-09 22:04:14 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-08-09 22:04:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-08-09 22:04:14 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes

2011-08-09 21:51:09 388096 ----a-r- c:\documents and settings\karina\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe

2011-08-09 21:51:08 -------- d-----w- c:\program files\Trend Micro

2011-08-09 21:10:16 15872 ----a-w- c:\windows\system32\drivers\HpqKbFiltr.sys

2011-08-09 21:10:16 1419232 ----a-w- c:\windows\system32\drivers\wdfcoinstaller01005.dll

2011-08-09 20:56:08 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll

2011-08-09 20:55:42 19569 ----a-w- c:\windows\000004_.tmp

2011-08-08 21:42:05 -------- d-----w- c:\program files\Winamp Detect

2011-08-08 16:40:54 -------- d-----w- c:\program files\Intertops Poker

2011-08-08 13:24:53 19569 ----a-w- c:\windows\000003_.tmp

2011-08-08 13:13:46 -------- d-----w- c:\windows\IIS Temporary Compressed Files

2011-08-08 13:13:34 -------- d-----w- c:\windows\system32\Cache

2011-08-08 13:06:03 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll

2011-08-08 13:06:03 9216 -c--a-w- c:\windows\system32\dllcache\iwrps.dll

2011-08-08 13:06:02 73728 -c--a-w- c:\windows\system32\dllcache\w3ext.dll

2011-08-08 13:06:02 16896 -c--a-w- c:\windows\system32\dllcache\status.dll

2011-08-08 13:06:01 53248 -c--a-w- c:\windows\system32\dllcache\nextlink.dll

2011-08-08 13:06:01 31744 -c--a-w- c:\windows\system32\dllcache\pagecnt.dll

2011-08-08 13:06:01 26624 -c--a-w- c:\windows\system32\dllcache\mdsync.dll

2011-08-08 13:06:01 20992 -c--a-w- c:\windows\system32\dllcache\permchk.dll

2011-08-08 13:06:00 7168 -c--a-w- c:\windows\system32\dllcache\isapips.dll

2011-08-08 12:59:43 -------- d-----w- c:\windows\system32\URTTEMP

2011-08-08 11:12:59 4002 ----a-w- c:\windows\system32\tmp.reg

2011-08-08 10:36:18 4445184 ----a-w- c:\windows\system32\msi.dll

2011-08-08 10:36:18 332800 ----a-w- c:\windows\system32\msihnd.dll

2011-08-08 04:21:28 -------- d-----w- c:\program files\Microsoft IntelliType Pro

2011-08-08 04:16:59 -------- d-----w- c:\program files\Launch Manager

2011-08-08 04:16:41 5120 ----a-w- c:\windows\system32\FILTRCOI.DLL

2011-08-08 04:16:41 49152 ----a-w- c:\windows\system32\QtBtLib.dll

2011-08-08 04:16:41 16896 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS

2011-08-08 04:16:41 147456 ----a-w- c:\windows\UNINST32.EXE

2011-08-07 23:28:24 101392 ----a-w- c:\windows\system32\drivers\AtihdXP3.sys

2011-08-07 23:12:56 -------- d-----w- c:\documents and settings\karina\local settings\application data\NVIDIA Corporation

2011-08-07 23:12:32 -------- d-----w- c:\program files\NVIDIA Corporation

2011-08-07 23:11:52 -------- d-----w- C:\NVIDIA

2011-08-07 23:04:08 485920 ----a-w- c:\windows\system32\nvunrm.exe

2011-08-07 23:04:05 888320 ----a-w- c:\windows\system32\NEW16.tmp

2011-08-07 23:04:05 888320 ----a-w- c:\windows\system32\fdco1ins.dll

2011-08-07 23:04:05 888320 ----a-w- c:\windows\system32\fdco1.dll

2011-08-07 23:04:05 66688 ----a-w- c:\windows\system32\drivers\NVENETFD.sys

2011-08-07 23:04:05 207872 ----a-w- c:\windows\system32\drivers\nvnrm.sys

2011-08-07 23:04:05 151552 ----a-w- c:\windows\system32\nvconrm.dll

2011-08-07 23:04:05 13824 ----a-w- c:\windows\system32\drivers\nvnetbus.sys

2011-08-07 23:04:05 11264 ----a-w- c:\windows\system32\NEW10.tmp

2011-08-07 23:04:05 11264 ----a-w- c:\windows\system32\bdco1ins.dll

2011-08-07 23:04:05 11264 ----a-w- c:\windows\system32\bdco1.dll

2011-08-07 22:33:51 600680 ----a-w- c:\windows\system32\nvuninst.exe

2011-08-07 22:33:47 485920 ----a-w- c:\windows\system32\nvusmb.exe

2011-08-07 22:33:47 155648 ----a-w- c:\windows\system32\NVCOSMB.DLL

2011-08-07 22:33:06 55912 ----a-w- c:\windows\system32\RHCoInstXP.dll

2011-08-07 22:33:06 4090920 ----a-w- c:\windows\system32\drivers\RtKHDMI.sys

2011-08-07 22:33:06 1489440 ----a-w- c:\windows\RtaUpd.exe

2011-08-07 13:46:51 -------- d-----w- c:\program files\EA Sports

2011-08-07 13:30:05 -------- d-----w- c:\documents and settings\karina\local settings\application data\Identities

2011-08-06 07:46:53 -------- d-----w- c:\documents and settings\karina\application data\VeniceLobby.895DF36AEBDDDC40895175E41D084FB613D0A6E4.1

2011-08-06 07:45:29 -------- d-----w- c:\program files\4DonkLive

2011-08-06 07:37:16 81920 ------w- c:\windows\system32\ieencode.dll

2011-08-06 07:36:55 19569 ----a-w- c:\windows\000002_.tmp

2011-08-06 07:27:05 -------- d-----w- c:\program files\Resource Kit

2011-08-06 06:53:13 -------- d-----w- c:\windows\system32\Logfiles

2011-08-06 06:53:13 -------- d-----w- C:\Inetpub

2011-08-05 23:23:24 -------- d-----w- c:\windows\system32\Adobe

2011-08-05 22:31:18 18944 ----a-w- c:\windows\system32\simptcp.dll

2011-08-05 21:58:45 -------- d-----w- c:\documents and settings\karina\local settings\application data\ApplicationHistory

2011-08-05 20:43:11 -------- d-----w- c:\documents and settings\karina\local settings\application data\FixItCenter

2011-08-05 20:35:16 -------- d-----w- c:\windows\MATS

2011-08-05 20:35:16 -------- d-----w- c:\program files\Microsoft Fix it Center

2011-08-05 20:34:15 -------- d-----w- c:\documents and settings\karina\application data\ElevatedDiagnostics

2011-08-05 19:33:05 -------- d-----w- c:\documents and settings\all users\application data\Pokernet

2011-08-05 19:11:56 -------- d-----w- c:\windows\system32\XPSViewer

2011-08-05 19:11:38 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

2011-08-05 19:11:28 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2011-08-05 19:11:28 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2011-08-05 19:11:28 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2011-08-05 19:11:28 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2011-08-05 19:11:28 575488 ------w- c:\windows\system32\xpsshhdr.dll

2011-08-05 19:11:28 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2011-08-05 19:11:28 1676288 ------w- c:\windows\system32\xpssvcs.dll

2011-08-05 19:11:28 117760 ------w- c:\windows\system32\prntvpt.dll

2011-08-05 18:53:13 -------- dc-h--w- c:\windows\ie8

2011-08-05 18:11:53 274288 ----a-w- c:\windows\system32\mucltui.dll

2011-08-05 18:11:53 16736 ----a-w- c:\windows\system32\mucltui.dll.mui

2011-08-05 11:22:44 -------- d-----w- c:\documents and settings\all users\application data\SpeedyPC

2011-08-05 10:59:23 -------- d-----w- c:\documents and settings\all users\application data\AVG Security Toolbar

2011-08-04 16:19:34 -------- d-----w- c:\documents and settings\karina\local settings\application data\PCHealth

2011-08-04 16:02:25 56960 ----a-w- c:\windows\system32\drivers\ousb2hub.sys

2011-08-04 16:02:25 45696 ----a-w- c:\windows\system32\drivers\ousbehci.sys

2011-08-04 15:03:33 -------- d-----w- c:\documents and settings\karina\application data\Uniblue

2011-08-04 15:03:25 -------- dc-h--w- c:\documents and settings\all users\application data\{DE8EABB5-1C85-4410-A68D-79BD8A4518F4}

2011-08-04 15:03:25 -------- d-----w- c:\program files\Uniblue

2011-08-04 15:02:32 -------- dc-h--w- c:\documents and settings\all users\application data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}

2011-08-04 14:59:34 -------- d-----w- c:\program files\Babylon

2011-08-04 14:59:20 -------- d-----w- c:\documents and settings\karina\local settings\application data\Media Get LLC

2011-08-04 14:59:09 -------- d-----w- c:\documents and settings\karina\local settings\application data\MediaGet2

2011-08-04 13:52:57 -------- d-----w- c:\documents and settings\karina\local settings\application data\PackageAware

2011-08-04 10:39:34 -------- d-----w- c:\program files\BluffRoom

2011-08-03 13:29:16 -------- d-----w- c:\windows\system32\wbem\repository\FS

2011-08-03 13:29:16 -------- d-----w- c:\windows\system32\wbem\Repository

2011-08-03 12:59:59 1327320 ------w- c:\program files\msn\msncorefiles\install\msnsusii.exe

2011-08-03 12:57:20 35328 ----a-w- c:\windows\system32\iprip.dll

2011-08-03 11:36:23 222080 ------w- c:\windows\system32\MpSigStub.exe

2011-08-02 17:32:20 -------- d-----w- c:\program files\SecurityXploded

2011-08-02 15:10:52 -------- d-----w- C:\Casino

2011-08-02 14:51:31 -------- d-----w- c:\documents and settings\karina\local settings\application data\CPN

2011-08-02 14:45:55 -------- d--h--r- C:\AHCache

2011-08-02 12:25:36 -------- d-----w- c:\program files\PokerStars.NET

2011-08-02 11:26:23 -------- d-----w- c:\program files\common files\ParetoLogic

2011-08-02 11:26:22 -------- d-----w- c:\program files\ParetoLogic

2011-08-02 11:26:22 -------- d-----w- c:\documents and settings\all users\application data\ParetoLogic

2011-08-01 14:46:57 233024 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys

2011-08-01 14:46:49 -------- d-----w- c:\program files\DAEMON Tools Pro

2011-08-01 14:46:10 -------- d-----w- c:\documents and settings\karina\application data\DAEMON Tools Pro

2011-08-01 14:46:10 -------- d-----w- c:\documents and settings\all users\application data\DAEMON Tools Pro

2011-08-01 12:52:05 -------- d-----w- c:\windows\system32\drivers\AVG

2011-08-01 12:51:42 -------- d-----w- c:\program files\AVG

2011-07-30 13:10:33 1060864 ----a-w- c:\windows\system32\MFC71.dll

2011-07-30 12:09:12 -------- d-----w- c:\program files\NirSoft

2011-07-30 12:02:58 -------- d--h--w- c:\windows\system32\GroupPolicy

2011-07-30 06:15:17 -------- d-----w- c:\windows\system32\appmgmt

2011-07-29 18:39:58 -------- d-----w- c:\program files\Conduit

2011-07-29 18:38:51 -------- d-----w- c:\program files\MpcStar

2011-07-29 15:15:00 -------- d-----w- c:\documents and settings\karina\application data\AVG

2011-07-26 17:21:11 -------- d-----w- c:\program files\Bodog Poker

2011-07-26 17:17:30 -------- d-----w- c:\documents and settings\karina\local settings\application data\P5

2011-07-26 17:17:28 -------- d-----w- C:\Betfair JPC

2011-07-25 14:06:14 -------- d-----w- c:\program files\Cake Poker

2011-07-23 15:32:30 -------- d-----w- c:\program files\Windows Media Connect 2(2)

2011-07-20 11:45:48 -------- d-----w- c:\documents and settings\karina\application data\MRA

2011-07-20 07:56:26 -------- d-----w- c:\program files\Mail.Ru

2011-07-13 13:14:47 -------- d-----w- c:\documents and settings\karina\application data\LuckyAcePoker.com

2011-07-13 13:14:41 -------- d-----w- c:\program files\LuckyAcePoker.com

.

==================== Find3M ====================

.

2011-08-07 22:49:52 991264 ----a-w- c:\windows\system32\drivers\btkrnl.sys

2011-07-30 13:06:20 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-07-08 04:12:46 7023104 ----a-w- c:\windows\system32\drivers\ati2mtag.sys

2011-07-08 04:09:28 311296 ----a-w- c:\windows\system32\atiiiexx.dll

2011-07-08 03:45:16 57344 ----a-w- c:\windows\system32\aticalrt.dll

2011-07-08 03:45:06 53248 ----a-w- c:\windows\system32\aticalcl.dll

2011-07-08 03:42:12 5111808 ----a-w- c:\windows\system32\aticaldd.dll

2011-07-08 03:38:30 17989632 ----a-w- c:\windows\system32\atioglxx.dll

2011-07-08 03:23:10 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll

2011-07-08 03:22:08 302592 ----a-w- c:\windows\system32\ati2dvag.dll

2011-07-08 03:21:34 4091648 ----a-w- c:\windows\system32\ati3duag.dll

2011-07-08 03:15:26 956160 ----a-w- c:\windows\system32\ativvamv.dll

2011-07-08 03:05:16 212992 ----a-w- c:\windows\system32\atipdlxx.dll

2011-07-08 03:05:04 155648 ----a-w- c:\windows\system32\Oemdspif.dll

2011-07-08 03:04:56 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe

2011-07-08 03:04:48 43520 ----a-w- c:\windows\system32\ati2edxx.dll

2011-07-08 03:04:36 188416 ----a-w- c:\windows\system32\ati2evxx.dll

2011-07-08 03:03:20 643072 ----a-w- c:\windows\system32\ati2evxx.exe

2011-07-08 03:03:12 3155072 ----a-w- c:\windows\system32\ativvaxx.dll

2011-07-08 03:01:58 53248 ----a-w- c:\windows\system32\ATIDDC.DLL

2011-07-08 03:00:38 151552 ----a-w- c:\windows\system32\atiapfxx.exe

2011-07-08 02:56:52 651264 ----a-w- c:\windows\system32\atikvmag.dll

2011-07-08 02:53:32 507904 ----a-w- c:\windows\system32\atiok3x2.dll

2011-07-08 02:53:14 208896 ----a-w- c:\windows\system32\atiadlxx.dll

2011-07-08 02:52:54 17408 ----a-w- c:\windows\system32\atitvo32.dll

2011-07-08 02:47:44 868352 ----a-w- c:\windows\system32\ati2cqag.dll

2011-07-08 02:46:38 64512 ----a-w- c:\windows\system32\atimpc32.dll

2011-07-08 02:46:38 64512 ----a-w- c:\windows\system32\amdpcom32.dll

2011-07-08 02:46:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2011-06-26 17:17:20 0 ----a-w- c:\windows\system32\ConduitEngine.tmp

2011-06-24 13:37:44 0 ----a-w- c:\windows\ativpsrm.bin

2011-06-14 16:53:22 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-06-14 16:53:21 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-06-13 19:09:22 65328 ----a-w- c:\windows\apppatch\matsshim.dll

2011-06-10 19:34:18 737280 ----a-w- c:\windows\iun6002.exe

2011-06-02 14:07:35 1867904 ----a-w- c:\windows\system32\win32k.sys

2011-06-02 14:07:35 1867904 ----a-w- c:\windows\system32\win32k(2).sys

2011-05-25 03:14:06 4059328 ----a-w- c:\windows\system32\ati3duag(6).dll

2011-05-25 03:14:06 4059328 ----a-w- c:\windows\system32\ati3duag(5).dll

2011-05-25 03:14:06 4059328 ----a-w- c:\windows\system32\ati3duag(4).dll

2011-05-25 03:14:06 4059328 ----a-w- c:\windows\system32\ati3duag(3).dll

2011-05-25 03:14:06 4059328 ----a-w- c:\windows\system32\ati3duag(2).dll

2011-05-25 03:05:18 503808 ----a-w- c:\windows\system32\atiok3x2(6).dll

2011-05-25 03:05:18 503808 ----a-w- c:\windows\system32\atiok3x2(5).dll

2011-05-25 03:05:18 503808 ----a-w- c:\windows\system32\atiok3x2(4).dll

2011-05-25 03:05:18 503808 ----a-w- c:\windows\system32\atiok3x2(3).dll

2011-05-25 03:05:18 503808 ----a-w- c:\windows\system32\atiok3x2(2).dll

2011-05-25 02:55:58 302592 ----a-w- c:\windows\system32\ati2dvag(6).dll

2011-05-25 02:55:58 302592 ----a-w- c:\windows\system32\ati2dvag(5).dll

2011-05-25 02:55:58 302592 ----a-w- c:\windows\system32\ati2dvag(4).dll

2011-05-25 02:55:58 302592 ----a-w- c:\windows\system32\ati2dvag(3).dll

2011-05-25 02:55:58 302592 ----a-w- c:\windows\system32\ati2dvag(2).dll

2011-05-25 02:54:56 3152384 ----a-w- c:\windows\system32\ativvaxx(6).dll

2011-05-25 02:54:56 3152384 ----a-w- c:\windows\system32\ativvaxx(5).dll

2011-05-25 02:54:56 3152384 ----a-w- c:\windows\system32\ativvaxx(4).dll

2011-05-25 02:54:56 3152384 ----a-w- c:\windows\system32\ativvaxx(3).dll

2011-05-25 02:54:56 3152384 ----a-w- c:\windows\system32\ativvaxx(2).dll

2011-05-25 02:39:28 212992 ----a-w- c:\windows\system32\atipdlxx(6).dll

2011-05-25 02:39:28 212992 ----a-w- c:\windows\system32\atipdlxx(5).dll

2011-05-25 02:39:28 212992 ----a-w- c:\windows\system32\atipdlxx(4).dll

2011-05-25 02:39:28 212992 ----a-w- c:\windows\system32\atipdlxx(3).dll

2011-05-25 02:39:28 212992 ----a-w- c:\windows\system32\atipdlxx(2).dll

2011-05-25 02:39:00 43520 ----a-w- c:\windows\system32\ati2edxx(6).dll

2011-05-25 02:39:00 43520 ----a-w- c:\windows\system32\ati2edxx(5).dll

2011-05-25 02:39:00 43520 ----a-w- c:\windows\system32\ati2edxx(4).dll

2011-05-25 02:39:00 43520 ----a-w- c:\windows\system32\ati2edxx(3).dll

2011-05-25 02:39:00 43520 ----a-w- c:\windows\system32\ati2edxx(2).dll

2011-05-25 02:38:50 188416 ----a-w- c:\windows\system32\ati2evxx(6).dll

2011-05-25 02:38:50 188416 ----a-w- c:\windows\system32\ati2evxx(5).dll

2011-05-25 02:38:50 188416 ----a-w- c:\windows\system32\ati2evxx(4).dll

2011-05-25 02:38:50 188416 ----a-w- c:\windows\system32\ati2evxx(3).dll

2011-05-25 02:38:50 188416 ----a-w- c:\windows\system32\ati2evxx(2).dll

2011-05-25 02:37:34 643072 ----a-w- c:\windows\system32\ati2evxx(6).exe

2011-05-25 02:37:34 643072 ----a-w- c:\windows\system32\ati2evxx(5).exe

2011-05-25 02:37:34 643072 ----a-w- c:\windows\system32\ati2evxx(4).exe

2011-05-25 02:37:34 643072 ----a-w- c:\windows\system32\ati2evxx(3).exe

2011-05-25 02:37:34 643072 ----a-w- c:\windows\system32\ati2evxx(2).exe

2011-05-25 02:31:28 651264 ----a-w- c:\windows\system32\atikvmag(6).dll

2011-05-25 02:31:28 651264 ----a-w- c:\windows\system32\atikvmag(5).dll

2011-05-25 02:31:28 651264 ----a-w- c:\windows\system32\atikvmag(4).dll

2011-05-25 02:31:28 651264 ----a-w- c:\windows\system32\atikvmag(3).dll

2011-05-25 02:31:28 651264 ----a-w- c:\windows\system32\atikvmag(2).dll

2011-05-25 02:27:52 200704 ----a-w- c:\windows\system32\atiadlxx(6).dll

2011-05-25 02:27:52 200704 ----a-w- c:\windows\system32\atiadlxx(5).dll

2011-05-25 02:27:52 200704 ----a-w- c:\windows\system32\atiadlxx(4).dll

2011-05-25 02:27:52 200704 ----a-w- c:\windows\system32\atiadlxx(3).dll

2011-05-25 02:27:52 200704 ----a-w- c:\windows\system32\atiadlxx(2).dll

2011-05-25 02:22:34 856064 ----a-w- c:\windows\system32\ati2cqag(6).dll

2011-05-25 02:22:34 856064 ----a-w- c:\windows\system32\ati2cqag(5).dll

2011-05-25 02:22:34 856064 ----a-w- c:\windows\system32\ati2cqag(4).dll

2011-05-25 02:22:34 856064 ----a-w- c:\windows\system32\ati2cqag(3).dll

2011-05-25 02:22:34 856064 ----a-w- c:\windows\system32\ati2cqag(2).dll

.

============= FINISH: 1:29:45.92 ===============

aко триабва да ги извада от днес сутринта само кажете.

Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C:\ както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.
=======================================================================================

* Изтеглете Malwarebytes' Anti-Malware или от тук

* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.

* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.

* Ако има намерени обновявания, тя ще ги изтегли и инсталира.

* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.

* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.

* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

  • Автор

здравей мерси за бурзите съвети искам да те попитам aswMBR вече 10мин работи:Д Смисал ще ми изпише ли че сцанирането е завуршило?

  • Автор

ето го и aswMBR лог фаила

aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software

Run date: 2011-08-10 14:04:28

-----------------------------

14:04:28.953 OS Version: Windows 5.1.2600 Service Pack 3

14:04:28.953 Number of processors: 2 586 0x1706

14:04:28.953 ComputerName: COMPUTER UserName: Karina

14:04:29.734 Initialize success

14:06:32.265 AVAST engine defs: 11081000

14:06:52.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0

14:06:52.937 Disk 0 Vendor: SAMSUNG_ 1AA0 Size: 715404MB BusType: 3

14:06:52.937 Device \Driver\nvgts -> DriverStartIo SCSIPORT.SYS b9ecb40e

14:06:52.937 Disk 0 MBR read successfully

14:06:52.937 Disk 0 MBR scan

14:06:52.953 Disk 0 Windows XP default MBR code

14:06:52.953 Disk 0 scanning sectors +1465143120

14:06:53.000 Disk 0 scanning C:\WINDOWS\system32\drivers

14:07:02.531 Service scanning

14:07:02.750 Service .avgldx86 \* **LOCKED** 123

14:07:03.406 Modules scanning

14:07:05.250 Module: C:\WINDOWS\system32\ntdll.dll **SUSPICIOUS**

14:07:05.250 Disk 0 trace - called modules:

14:07:05.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys

14:07:05.265 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a8bc268]

14:07:05.265 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\00000080[0x8a8cd2a8]

14:07:05.265 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port2Path0Target0Lun0[0x8a8cda38]

14:07:05.875 AVAST engine scan C:\

14:39:57.843 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Karina\Desktop\New Folder (2)\MBR.dat"

14:39:57.921 The log file has been saved successfully to "C:\Documents and Settings\Karina\Desktop\New Folder (2)\aswMBR.txt"

aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software

Run date: 2011-08-10 14:43:09

-----------------------------

14:43:09.156 OS Version: Windows 5.1.2600 Service Pack 3

14:43:09.156 Number of processors: 2 586 0x1706

14:43:09.156 ComputerName: COMPUTER UserName: Karina

14:43:10.515 Initialize success

14:43:16.109 AVAST engine defs: 11081000

14:43:21.328 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0

14:43:21.328 Disk 0 Vendor: SAMSUNG_ 1AA0 Size: 715404MB BusType: 3

14:43:21.328 Device \Driver\nvgts -> DriverStartIo SCSIPORT.SYS b9ecb40e

14:43:21.343 Disk 0 MBR read successfully

14:43:21.343 Disk 0 MBR scan

14:43:21.359 Disk 0 Windows XP default MBR code

14:43:21.359 Disk 0 scanning sectors +1465143120

14:43:21.500 Disk 0 scanning C:\WINDOWS\system32\drivers

14:43:50.312 Service scanning

14:43:50.515 Service .avgldx86 \* **LOCKED** 123

14:43:51.187 Modules scanning

14:44:25.375 Module: C:\WINDOWS\system32\ntdll.dll **SUSPICIOUS**

14:44:25.375 Disk 0 trace - called modules:

14:44:25.421 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys

14:44:25.421 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a8bc268]

14:44:25.421 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\00000080[0x8a8cd2a8]

14:44:25.421 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port2Path0Target0Lun0[0x8a8cda38]

14:44:26.125 AVAST engine scan C:\

17:31:23.843 Scan finished successfully

17:35:09.234 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Karina\Desktop\New Folder (2)\MBR.dat"

17:35:09.296 The log file has been saved successfully to "C:\Documents and Settings\Karina\Desktop\New Folder (2)\aswMBR.txt"

значи упдеитнах Malwarebytes' Anti-Malware и сега пускам фулл скан

До тук нещата изглеждат наред....! :)

Кликнете върху този ред:

14:44:25.375 Module: C:\WINDOWS\system32\ntdll.dll **SUSPICIOUS**

..с десен бутон и копирайте файла на десктопа си с име copy_ntdll.sys...Изпратете го на http://www.virustotal.com/ за допълнителен анализ.

значи упдеитнах Malwarebytes' Anti-Malware и сега пускам фулл скан

Ок...ще изчакаме лога...и после ще мислим какво ще предприемем ако все пак ми кажете какъв точно ви е проблема..?

  • Автор

така направих му копи преименувах го и го пратих

ето и анализа

File already submitted: The file sent has already been analysed by VirusTotal in the past. This is same basic info regarding the sample itself and its last analysis: MD5: 15ce4dbc22fab90b3ca5352af1fff81c Date first seen: 2011-02-08 18:49:43 (UTC) Date last seen: 2011-08-09 07:06:59 (UTC) Detection ratio: 0/43

What do you wish to do?

да цуквам ли нещу в тотал бирус?

  • Автор

До тук нещата изглеждат наред....! :)

Кликнете върху този ред:

..с десен бутон и копирайте файла на десктопа си с име copy_ntdll.sys...Изпратете го на http://www.virustotal.com/ за допълнителен анализ.

Ок...ще изчакаме лога...и после ще мислим какво ще предприемем ако все пак ми кажете какъв точно ви е проблема..?

знаачи преди около седмица приателката ми се е опитала да лицензира АВГ с ниакакав кеи които нз от куде го е взела но те се намират.Така след това авг-то и показвало че не е напулно защитена и почнала да вкарва кеи след кеи и оттам се е ядосала и го изтрила след което изтеглила аваст от замунда оттам си *** маиката веднага исталирах авг отново 30 дневната безплатна оферта и тя почна да засича в сисстем 32 вирус катиуша.А мислия че беше изтри го авг-то след това некув троианец засичаше...скаип не ми се вкл фифата сущ като се опитам да ги инсталирам 1-во биаха длл фаилс после оккуред ми били пробвах с сиакакви упдеити и програми но не става в Ф има папка 28109466ad38c38d9c в нея упдеит подпакпа като цукна ми пише аццсес динаид накрая msxml.msi 4.0 фаил оффф незнам дали сум ви помогнал ... сега копвам последниа лог фаила

Malwarebytes' Anti-Malware 1.51.1.1800

www.malwarebytes.org

Database version: 7427

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

8/10/2011 6:48:33 PM

mbam-log-2011-08-10 (18-48-21).txt

Scan type: Full scan (C:\|F:\|)

Objects scanned: 304946

Time elapsed: 30 minute(s), 36 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 9

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 15

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bet365casino (PUP.Casino) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\casinolavida (PUP.Casino.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\INSTALL.EXE (PUP.Casino.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gamingclub (PUP.Casino.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\coolhand (Poker) (PUP.Casino.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\nordicbet (Poker) (PUP.Casino.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\unibetpoker (Poker) (PUP.Casino.Gen) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Betfred Poker (PUP.Casino) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\pokerplex (PUP.Casino) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\Casino\casino at bet365\_setupcasino_a616b8.exe (PUP.Casino) -> No action taken.

c:\documents and settings\Karina\local settings\application data\Google\Chrome\user data\Default\Cache\f_0001ca (PUP.Casino.Gen) -> No action taken.

c:\documents and settings\Karina\local settings\application data\Google\Chrome\user data\Default\Cache\f_000208 (PUP.Casino.Gen) -> No action taken.

c:\documents and settings\Karina\local settings\application data\Google\Chrome\user data\Default\Cache\f_0002a3 (PUP.Casino) -> No action taken.

c:\documents and settings\Karina\local settings\application data\Google\Chrome\user data\Default\Cache(3)\f_001454 (PUP.Casino) -> No action taken.

c:\documents and settings\Karina\my documents\downloads\casinolavida.exe (PUP.Casino.Gen) -> No action taken.

c:\documents and settings\Karina\my documents\downloads\gamingclub.exe (PUP.Casino.Gen) -> No action taken.

c:\microgaming\Casino\casinolavida\install.exe (PUP.Casino.Gen) -> No action taken.

c:\microgaming\Casino\gamingclub\install.exe (PUP.Casino.Gen) -> No action taken.

c:\microgaming\Poker\coolhandmpp\install.exe (PUP.Casino.Gen) -> No action taken.

c:\microgaming\Poker\nordicbetmpp\install.exe (PUP.Casino.Gen) -> No action taken.

c:\microgaming\Poker\unibetpokermpp\install.exe (PUP.Casino.Gen) -> No action taken.

c:\Poker\betfred poker\_setuppoker_f258ff.exe (PUP.Casino) -> No action taken.

c:\Poker\pokerplex24\_setuppoker_1e1224 (1).exe (PUP.Casino) -> No action taken.

c:\Poker\pokerplex24\_setuppoker_1e1224.exe (PUP.Casino) -> No action taken.

Ама не сте изпълнили правилно инструкцията..сега само сте сканирали и нищо от това което е засечено не е изтрито..!Не напразно е писано в инструкцията: Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

  • Автор

току що влизам след рестарт на Malwarebytes' Anti-Malware ремуувнах сичко

току що влизам след рестарт на Malwarebytes' Anti-Malware

ремуувнах сичко

Аз как да съм сигурен...след като няма дневник..?

  • Автор

Аз как да съм сигурен...след като няма дневник..?

триабваше след ремоова ли да ти пратя логга?

Стъпка 1:

  • Изтеглете Security Check (автор: screen317) от тук или от тук и го запишете на десктопа.
  • Кликнете два пъти върху SecurityCheck.exe и следвайте инструкциите.
  • Когато програмата завърши работата си, ще се отвори един текстов документ: checkup.txt.
  • Копирайте съдържанието на checkup.txt с Копирай (Copy) и с Постави (Paste) го поставете в следващия си коментар.

Стъпка 2:

Изтеглете ComboFix от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.

Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs

  • Стартирайте Combo-Fix.com и следвайте инструкциите.

Бележка: ComboFix ще се стартира без инсталирана Recovery Console.

  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.

Работата на ComboFix, може да отнеме до 20-30 минути, за да завърши, моля имайте търпение.

Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

  • Автор

Results of screen317's Security Check version 0.99.18

Windows XP Service Pack 3

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

AVG 2011

Antivirus up to date!

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Java 6 Update 26

Adobe Flash Player 10.3.181.26

````````````````````````````````

Process Check:

objlist.exe by Laurent

AVG avgwdsvc.exe

AVG avgtray.exe

AVG avgrsx.exe

AVG avgemc.exe

``````````End of Log````````````

  • Автор

това комбо забива преди да се напулни и си седи так авг ми го засича какво даправиа аллол или ...?

Изключете вашата антивирусна и антишпионска програма,

Отново се натъквам на това че не изпълнявате инструкциите ...какво да ви правя незнам..?

AVhttp://onecall.webno...rusna-programa/G

Предупреждавам че при следващо незачитане на инструкциите ще бъда принуден да затворя темата...Днес цял ден се занимавам с вашия случай..и вместо сега да преключваме ние се разправяме за глупости....!

Получихте ли съобщение от Комбофикс че не може да работи с AVG и е необходимо да я деинсталирате..?

Използвайте http://www.appremover.com/ за да деинсталирате напълно AVG...!След като почистим системата ви ще си я инсталирате отново...!

  • Автор

изклиучен ресидент в момента е дизеибул но след това като вклиучих комбото и зациклиа почти на краиа и нищо сега го деинстал евалата че се занимаваш изобщо :Д готово махнах авг комбофикс ли да пускам? ComboFix 11-08-10.01 - Karina 08/10/2011 22:35:11.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.1334 [GMT 3:00] Running from: c:\documents and settings\Karina\Desktop\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\messenger\msmsgsin.exe c:\windows\$NtUninstallKB60605$ c:\windows\$NtUninstallKB60605$\814381134 c:\windows\$NtUninstallKB60605$\940321614\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6} c:\windows\$NtUninstallKB60605$\940321614\click.tlb c:\windows\$NtUninstallKB60605$\940321614\L\wqkiqhtk c:\windows\$NtUninstallKB60605$\940321614\loader(2).tlb c:\windows\$NtUninstallKB60605$\940321614\loader.tlb c:\windows\$NtUninstallKB60605$\940321614\U\@00000001 c:\windows\$NtUninstallKB60605$\940321614\U\@000000c0 c:\windows\$NtUninstallKB60605$\940321614\U\@000000cb c:\windows\$NtUninstallKB60605$\940321614\U\@000000cf c:\windows\$NtUninstallKB60605$\940321614\U\@80000000 c:\windows\$NtUninstallKB60605$\940321614\U\@800000c0 c:\windows\$NtUninstallKB60605$\940321614\U\@800000cb c:\windows\$NtUninstallKB60605$\940321614\U\@800000cf c:\windows\iun6002.exe c:\windows\system32\404Fix.exe c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\Cache c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\o4Patch.exe c:\windows\system32\Process.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\tmp.reg c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\WS2Fix.exe . . ((((((((((((((((((((((((( Files Created from 2011-07-10 to 2011-08-10 ))))))))))))))))))))))))))))))) . . 2011-08-10 06:49 . 2011-08-10 07:00 -------- d-----w- C:\Betsafe 2011-08-09 22:04 . 2011-08-09 22:04 -------- d-----w- c:\documents and settings\Karina\Application Data\Malwarebytes 2011-08-09 22:04 . 2011-07-06 16:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-09 22:04 . 2011-08-09 22:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-08-09 22:04 . 2011-08-09 22:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-08-09 22:04 . 2011-07-06 16:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-09 21:51 . 2011-08-09 21:51 388096 ----a-r- c:\documents and settings\Karina\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-08-09 21:51 . 2011-08-09 21:51 -------- d-----w- c:\program files\Trend Micro 2011-08-09 21:10 . 2011-08-09 21:10 15872 ----a-w- c:\windows\system32\drivers\HpqKbFiltr.sys 2011-08-09 21:10 . 2011-08-09 21:10 1419232 ----a-w- c:\windows\system32\drivers\wdfcoinstaller01005.dll 2011-08-09 20:56 . 2008-04-14 02:40 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll 2011-08-09 20:55 . 2006-12-28 21:31 19569 ----a-w- c:\windows\000004_.tmp 2011-08-08 21:42 . 2011-08-08 21:42 -------- d-----w- c:\program files\Winamp Detect 2011-08-08 16:40 . 2011-08-08 16:41 -------- d-----w- c:\program files\Intertops Poker 2011-08-08 13:24 . 2006-12-28 21:31 19569 ----a-w- c:\windows\000003_.tmp 2011-08-08 13:13 . 2011-08-08 13:13 -------- d-----w- c:\windows\IIS Temporary Compressed Files 2011-08-08 13:06 . 2008-04-14 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll 2011-08-08 13:06 . 2008-04-14 12:00 9216 -c--a-w- c:\windows\system32\dllcache\iwrps.dll 2011-08-08 13:06 . 2008-04-14 12:00 73728 -c--a-w- c:\windows\system32\dllcache\w3ext.dll 2011-08-08 13:06 . 2008-04-14 12:00 16896 -c--a-w- c:\windows\system32\dllcache\status.dll 2011-08-08 13:06 . 2008-04-14 12:00 53248 -c--a-w- c:\windows\system32\dllcache\nextlink.dll 2011-08-08 13:06 . 2008-04-14 12:00 31744 -c--a-w- c:\windows\system32\dllcache\pagecnt.dll 2011-08-08 13:06 . 2008-04-14 12:00 26624 -c--a-w- c:\windows\system32\dllcache\mdsync.dll 2011-08-08 13:06 . 2008-04-14 12:00 20992 -c--a-w- c:\windows\system32\dllcache\permchk.dll 2011-08-08 13:06 . 2008-04-14 12:00 7168 -c--a-w- c:\windows\system32\dllcache\isapips.dll 2011-08-08 12:59 . 2011-08-08 12:59 -------- d-----w- c:\windows\system32\URTTEMP 2011-08-08 10:36 . 2008-05-19 06:33 4445184 ----a-w- c:\windows\system32\msi.dll 2011-08-08 10:36 . 2008-05-19 06:33 332800 ----a-w- c:\windows\system32\msihnd.dll 2011-08-08 04:21 . 2011-08-08 04:21 -------- d-----w- c:\program files\Microsoft IntelliType Pro 2011-08-08 04:16 . 2011-08-08 04:17 -------- d-----w- c:\program files\Launch Manager 2011-08-08 04:16 . 2005-01-10 13:48 147456 ----a-w- c:\windows\UNINST32.EXE 2011-08-08 04:16 . 2004-12-09 09:04 5120 ----a-w- c:\windows\system32\FILTRCOI.DLL 2011-08-08 04:16 . 2004-12-08 11:10 16896 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS 2011-08-08 04:16 . 2002-12-19 12:58 49152 ----a-w- c:\windows\system32\QtBtLib.dll 2011-08-08 03:35 . 2011-08-08 03:35 -------- d-----w- c:\program files\Microsoft Silverlight 2011-08-08 02:47 . 2011-08-08 02:47 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\NVIDIA Corporation 2011-08-07 23:28 . 2011-03-30 18:46 101392 ----a-w- c:\windows\system32\drivers\AtihdXP3.sys 2011-08-07 23:12 . 2011-08-08 03:54 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\NVIDIA Corporation 2011-08-07 23:12 . 2011-08-07 23:12 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation 2011-08-07 23:12 . 2011-08-07 23:15 -------- d-----w- c:\program files\NVIDIA Corporation 2011-08-07 23:11 . 2011-08-07 23:11 -------- d-----w- C:\NVIDIA 2011-08-07 23:04 . 2011-08-07 23:04 485920 ----a-w- c:\windows\system32\nvunrm.exe 2011-08-07 23:04 . 2011-08-09 21:05 888320 ----a-w- c:\windows\system32\fdco1ins.dll 2011-08-07 23:04 . 2011-08-09 21:05 888320 ----a-w- c:\windows\system32\fdco1.dll 2011-08-07 23:04 . 2011-08-09 21:05 66688 ----a-w- c:\windows\system32\drivers\NVENETFD.sys 2011-08-07 23:04 . 2011-08-09 21:05 207872 ----a-w- c:\windows\system32\drivers\nvnrm.sys 2011-08-07 23:04 . 2011-08-09 21:05 13824 ----a-w- c:\windows\system32\drivers\nvnetbus.sys 2011-08-07 23:04 . 2011-08-09 21:05 11264 ----a-w- c:\windows\system32\bdco1ins.dll 2011-08-07 23:04 . 2011-08-09 21:05 11264 ----a-w- c:\windows\system32\bdco1.dll 2011-08-07 23:04 . 2011-08-07 23:04 151552 ----a-w- c:\windows\system32\nvconrm.dll 2011-08-07 22:33 . 2010-03-26 12:10 600680 ----a-w- c:\windows\system32\nvuninst.exe 2011-08-07 22:33 . 2011-08-09 21:07 485920 ----a-w- c:\windows\system32\nvusmb.exe 2011-08-07 22:33 . 2011-08-07 22:33 155648 ----a-w- c:\windows\system32\NVCOSMB.DLL 2011-08-07 22:33 . 2011-08-07 22:47 4090920 ----a-w- c:\windows\system32\drivers\RtKHDMI.sys 2011-08-07 22:33 . 2011-08-07 22:47 1489440 ----a-w- c:\windows\RtaUpd.exe 2011-08-07 22:33 . 2011-08-07 22:33 55912 ----a-w- c:\windows\system32\RHCoInstXP.dll 2011-08-07 13:46 . 2011-08-07 13:46 -------- d-----w- c:\program files\EA Sports 2011-08-07 13:30 . 2011-08-07 13:30 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\Identities 2011-08-06 07:46 . 2011-08-06 07:46 -------- d-----w- c:\documents and settings\Karina\Application Data\VeniceLobby.895DF36AEBDDDC40895175E41D084FB613D0A6E4.1 2011-08-06 07:45 . 2011-08-06 07:45 -------- d-----w- c:\program files\4DonkLive 2011-08-06 07:37 . 2008-04-14 02:41 81920 ------w- c:\windows\system32\ieencode.dll 2011-08-06 07:36 . 2006-12-28 21:31 19569 ----a-w- c:\windows\000002_.tmp 2011-08-06 07:27 . 2011-08-06 07:27 -------- d-----w- c:\program files\Resource Kit 2011-08-06 06:53 . 2011-08-08 13:13 -------- d-----w- C:\Inetpub 2011-08-06 06:53 . 2011-08-06 06:53 -------- d-----w- c:\windows\system32\Logfiles 2011-08-05 23:23 . 2011-08-05 23:27 -------- d-----w- c:\windows\system32\Adobe 2011-08-05 22:31 . 2008-04-14 12:00 18944 ----a-w- c:\windows\system32\simptcp.dll 2011-08-05 21:58 . 2011-08-08 13:01 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\ApplicationHistory 2011-08-05 20:43 . 2011-08-05 20:44 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\FixItCenter 2011-08-05 20:35 . 2011-08-05 20:43 -------- d-----w- c:\windows\MATS 2011-08-05 20:35 . 2011-08-05 20:43 -------- d-----w- c:\program files\Microsoft Fix it Center 2011-08-05 20:34 . 2011-08-05 20:34 -------- d-----w- c:\documents and settings\Karina\Application Data\ElevatedDiagnostics 2011-08-05 19:33 . 2011-08-05 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Pokernet 2011-08-05 19:11 . 2011-08-05 19:11 -------- d-----w- c:\windows\system32\XPSViewer 2011-08-05 19:11 . 2011-08-05 19:11 -------- d-----w- c:\program files\MSBuild 2011-08-05 19:11 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-08-05 19:11 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2011-08-05 19:11 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2011-08-05 19:11 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll 2011-08-05 19:11 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2011-08-05 19:11 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll 2011-08-05 19:11 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll 2011-08-05 19:11 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2011-08-05 19:11 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-08-05 18:53 . 2011-08-05 18:54 -------- dc-h--w- c:\windows\ie8 2011-08-05 18:11 . 2009-08-06 16:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2011-08-05 11:22 . 2011-08-06 08:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC 2011-08-04 16:19 . 2011-08-04 16:19 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\PCHealth 2011-08-04 16:02 . 2011-08-07 22:35 56960 ----a-w- c:\windows\system32\drivers\ousb2hub.sys 2011-08-04 16:02 . 2011-08-07 22:35 45696 ----a-w- c:\windows\system32\drivers\ousbehci.sys 2011-08-04 15:03 . 2011-08-04 15:42 -------- d-----w- c:\documents and settings\Karina\Application Data\Uniblue 2011-08-04 15:03 . 2011-08-04 16:01 -------- d-----w- c:\program files\Uniblue 2011-08-04 15:03 . 2011-08-04 15:03 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{DE8EABB5-1C85-4410-A68D-79BD8A4518F4} 2011-08-04 15:02 . 2011-08-04 15:22 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} 2011-08-04 14:59 . 2011-08-04 14:59 -------- d-----w- c:\program files\Babylon 2011-08-04 14:59 . 2011-08-04 14:59 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\Media Get LLC 2011-08-04 14:59 . 2011-08-04 16:29 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\MediaGet2 2011-08-04 13:52 . 2011-08-04 13:52 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\PackageAware 2011-08-04 10:39 . 2011-08-10 18:37 -------- d-----w- c:\program files\BluffRoom 2011-08-03 13:29 . 2011-08-03 13:29 -------- d-----w- c:\windows\system32\wbem\Repository 2011-08-03 12:59 . 2007-04-02 21:12 1327320 ------w- c:\program files\MSN\msncorefiles\install\msnsusii.exe 2011-08-03 12:57 . 2008-04-14 02:41 35328 ----a-w- c:\windows\system32\iprip.dll 2011-08-03 11:36 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-08-02 17:32 . 2011-08-02 17:32 -------- d-----w- c:\program files\SecurityXploded 2011-08-02 15:26 . 2011-08-02 15:26 -------- d-----w- c:\program files\Reference Assemblies 2011-08-02 15:26 . 2011-08-02 15:26 -------- d-----w- c:\documents and settings\Terminator\Application Data\ParetoLogic 2011-08-02 15:10 . 2011-08-02 15:10 -------- d-----w- C:\Casino 2011-08-02 14:51 . 2011-08-02 14:51 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\CPN 2011-08-02 14:45 . 2011-08-02 14:45 -------- d-----r- C:\AHCache 2011-08-02 12:25 . 2011-08-02 15:34 -------- d-----w- c:\program files\PokerStars.NET 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\documents and settings\Terminator\Application Data\DriverCure 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\program files\Common Files\ParetoLogic 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\program files\ParetoLogic 2011-08-02 10:40 . 2011-08-02 10:40 -------- d-----w- c:\documents and settings\Terminator\Local Settings\Application Data\Babylon 2011-08-02 10:40 . 2011-08-02 10:40 -------- d-----w- c:\documents and settings\Terminator\Application Data\Babylon 2011-08-01 17:31 . 2011-08-01 17:31 -------- d-----w- c:\documents and settings\Terminator\Application Data\DAEMON Tools Pro 2011-08-01 14:46 . 2011-08-03 13:35 233024 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-08-01 14:46 . 2011-08-01 14:46 -------- d-----w- c:\program files\DAEMON Tools Pro 2011-08-01 14:46 . 2011-08-09 22:46 -------- d-----w- c:\documents and settings\Karina\Application Data\DAEMON Tools Pro 2011-08-01 14:46 . 2011-08-01 14:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro 2011-08-01 12:52 . 2011-08-10 19:05 -------- d-----w- c:\windows\system32\drivers\AVG 2011-07-30 13:10 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll 2011-07-30 12:09 . 2011-08-06 07:13 -------- d-----w- c:\program files\NirSoft 2011-07-30 12:02 . 2011-07-30 12:02 -------- d--h--w- c:\windows\system32\GroupPolicy . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-07 22:49 . 2005-08-29 14:45 991264 ----a-w- c:\windows\system32\drivers\btkrnl.sys 2011-07-30 13:06 . 2011-06-09 19:54 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-26 17:17 . 2011-06-26 17:17 0 ----a-w- c:\windows\system32\ConduitEngine.tmp 2011-06-14 16:53 . 2011-06-14 16:53 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-06-14 16:53 . 2011-06-14 16:53 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-06-13 19:09 . 2011-06-13 19:09 65328 ----a-w- c:\windows\apppatch\matsshim.dll 2011-06-02 14:07 . 2009-11-08 12:36 1867904 ----a-w- c:\windows\system32\win32k.sys 2011-06-02 14:07 . 2009-11-08 12:36 1867904 ----a-w- c:\windows\system32\win32k(2).sys 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(6).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(5).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(4).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(3).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(2).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(6).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(5).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(4).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(3).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(2).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(6).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(5).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(4).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(3).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(2).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(6).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(5).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(4).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(3).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(2).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(6).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(5).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(4).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(3).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(2).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(6).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(5).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(4).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(3).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(2).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(6).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(5).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(4).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(3).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(2).dll 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(6).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(5).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(4).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(3).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(2).exe 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(6).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(5).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(4).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(3).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(2).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(6).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(5).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(4).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(3).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(2).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(6).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(5).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(4).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(3).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(2).dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2009-11-08 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys [-] 2009-11-08 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys [7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys . [-] 2009-11-08 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll [-] 2009-11-08 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll [7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll . [-] 2009-11-08 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe [-] 2009-11-08 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe [7] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe . [-] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\dllcache\spoolsv.exe [7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe [7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe . [-] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll [-] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll [7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll [7] 2008-04-14 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll [7] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll [7] 2001-08-23 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\InstallTemp\48339\comctl32.dll . [-] 2009-11-08 12:32 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll [-] 2009-11-08 12:32 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll [7] 2008-04-14 02:41 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll . [-] 2009-11-08 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll [-] 2009-11-08 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll [7] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll . [-] 2009-11-08 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll [-] 2009-11-08 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll [7] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll . [-] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\system32\ole32.dll [-] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\system32\dllcache\ole32.dll [7] 2008-04-14 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll [7] 2008-04-14 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll . [-] 2010-04-16 . 9E03DC5AB51CFD0190541CE2038D819D . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\usp10.dll [-] 2010-04-16 . 9E03DC5AB51CFD0190541CE2038D819D . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\dllcache\usp10.dll [-] 2010-04-16 . F8894BCC961D461674002B4BAE7AECC1 . 406016 . . [1.0420.2600.5969] . . c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll [7] 2008-04-14 . 7D7D8501F3CB45D0408CDEFA08CDAEFF . 406016 . . [1.0420.2600.5512] . . c:\windows\$NtUninstallKB981322$\usp10.dll [7] 2008-04-14 . 7D7D8501F3CB45D0408CDEFA08CDAEFF . 406016 . . [1.0420.2600.5512] . . c:\windows\ServicePackFiles\i386\usp10.dll . [-] 2009-07-27 . 888CD7B39C37E13A2419BECFAAF0A28C . 135168 . . [6.00.2900.5853] . . c:\windows\system32\shsvcs.dll [-] 2009-07-27 . 888CD7B39C37E13A2419BECFAAF0A28C . 135168 . . [6.00.2900.5853] . . c:\windows\system32\dllcache\shsvcs.dll [7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB971029$\shsvcs.dll [7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll . [-] 2010-09-18 07:18 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll [-] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\system32\mfc40u.dll [-] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\system32\dllcache\mfc40u.dll [7] 2008-04-14 12:00 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll [7] 2008-04-14 02:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll . [-] 2010-12-09 . F67CD97282E0ABFAF91A9A1359B16F2D . 2069376 . . [5.1.2600.6055] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe [-] 2010-12-09 . F67CD97282E0ABFAF91A9A1359B16F2D . 2069376 . . [5.1.2600.6055] . . c:\windows\system32\dllcache\ntkrnlpa.exe [-] 2010-12-09 . F917F7E5FC9F80D3C36978A9CCEF6BE4 . 2027008 . . [5.1.2600.6055] . . c:\windows\system32\ntkrnlpa.exe [-] 2009-11-08 . 9D22A1961421CCD10BDCC0BA04F93A4C . 2023936 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe [7] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe . [-] 2010-12-09 . DC4A984DEA7E24166800D38442405130 . 2148864 . . [5.1.2600.6055] . . c:\windows\system32\ntoskrnl.exe [-] 2010-12-09 . A531BBD3DE13121C1380ED7DC99082DB . 2192768 . . [5.1.2600.6055] . . c:\windows\Driver Cache\i386\ntoskrnl.exe [-] 2010-12-09 . A531BBD3DE13121C1380ED7DC99082DB . 2192768 . . [5.1.2600.6055] . . c:\windows\system32\dllcache\ntoskrnl.exe [-] 2009-11-08 . BDADF0AD9776DA6FD65FC713A8B1DCE9 . 2145280 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB2393802$\ntoskrnl.exe [7] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048] "SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\launcher.exe" [2011-05-23 67960] "DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "D-Link AirPlus XtremeG DWL-G122"="c:\program files\D-Link\AirPlus XtremeG DWL-G122\AirGCFG.exe" [2008-01-02 1552384] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-05-16 213936] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "BigDogPath323VMSnap"="c:\windows\VMSnap23.exe" [2007-06-29 212992] "BigDogPath323Domino"="c:\windows\Domino.exe" [2007-06-29 49152] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "CNAP2 Launcher"="c:\windows\System32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-01-11 226784] "PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-26 648032] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752] "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2011-06-02 114992] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-9 610365] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\BitComet\\BitComet.exe"= "c:\\Program Files\\Redbet\\pokerclient\\Redbet.exe"= "c:\\Program Files\\24hPoker\\pokerclient\\24hPoker.exe"= "f:\\Program Files\\Intertops Poker\\PokerClient.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Intertops Poker\\PokerClient.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10359:TCP"= 10359:TCP:BitComet 10359 TCP "10359:UDP"= 10359:UDP:BitComet 10359 UDP "21503:TCP"= 21503:TCP:BitComet 21503 TCP "21503:UDP"= 21503:UDP:BitComet 21503 UDP "3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping "3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) . R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [8/1/2011 5:46 PM 233024] R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [8/4/2011 7:02 PM 45696] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [8/8/2011 2:28 AM 101392] R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [9/15/2009 2:59 PM 38248] R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [8/4/2011 7:02 PM 56960] R3 vmfilter323;323 filter service, Normal;c:\windows\system32\drivers\vmfilter323.sys [6/15/2011 12:00 PM 476672] R3 ZSMC326;CANYON USB PC Camera;c:\windows\system32\drivers\usbvm323.sys [6/15/2011 12:00 PM 260224] S0 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?] S2 Guard.Mail.ru;Guard.Mail.ru; [x] S2 gupdate;Google Update Service (gupdate); [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider; [x] S3 gupdatem;Google Update Service (gupdatem); [x] S3 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [4/14/2008 3:00 PM 14336] S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [6/13/2011 10:09 PM 267568] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/10/2011 1:04 AM 41272] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc . Contents of the 'Scheduled Tasks' folder . 2011-08-10 c:\windows\Tasks\ConfigExec.job - c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 19:09] . 2011-08-10 c:\windows\Tasks\DataUpload.job - c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 19:09] . 2011-08-10 c:\windows\Tasks\DriverScanner.job - c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2011-08-04 08:22] . 2011-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-839522115-1003Core.job - c:\documents and settings\Karina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 13:52] . 2011-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-839522115-1003UA.job - c:\documents and settings\Karina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 13:52] . 2011-08-02 c:\windows\Tasks\ParetoLogic Registration3.job - c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2011-03-29 23:17] . 2011-08-02 c:\windows\Tasks\ParetoLogic Update Version3.job - c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-03-29 23:17] . 2011-08-10 c:\windows\Tasks\PC Health Advisor Defrag.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-03-29 23:17] . 2011-08-08 c:\windows\Tasks\PC Health Advisor.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-03-29 23:17] . 2011-08-10 c:\windows\Tasks\RegistryBooster.job - c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2011-01-21 13:29] . 2011-08-10 c:\windows\Tasks\SpeedUpMyPC.job - c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-04 14:27] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.bg/ IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe TCP: DhcpNameServer = 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file) Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) Toolbar-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) HKCU-Run-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\DTLite.exe HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe HKLM-Run-ANIWZCS2Service - c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe SafeBoot-BsScanner AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe AddRemove-mad) - c:\program files\GNU\MPEG2\Uninstall.exe AddRemove-myBet Poker - c:\poker\myBet Poker\_SetupCasino_a21255.exe AddRemove-PokerStars.net - c:\program files\PokerStars.NET\PokerStarsUninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-08-10 22:39 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.avgldx86] "ImagePath"="\*" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(1332) c:\windows\system32\Ati2evxx.dll c:\windows\system32\atiadlxx.dll . - - - - - - - > 'explorer.exe'(2872) c:\windows\system32\WININET.dll c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\NVIDIA Corporation\nTune\nTuneService.exe c:\program files\NVIDIA Corporation\System Update\UpdateCenterService.exe c:\windows\system32\inetsrv\inetinfo.exe c:\windows\RTHDCPL.EXE c:\windows\system32\rundll32.exe c:\windows\System32\spool\DRIVERS\W32X86\3\CNAP2RPK.EXE c:\windows\System32\spool\DRIVERS\W32X86\3\CNABCSWK.EXE c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE . ************************************************************************** . Completion time: 2011-08-10 22:42:26 - machine was rebooted ComboFix-quarantined-files.txt 2011-08-10 19:42 . Pre-Run: 104,228,249,600 bytes free Post-Run: 104,193,912,832 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6 - - End Of File - - E3CA4F87D3F678E0200798F931E5EF4C това нали не сум го обуркал... надиавам се вурши работа.... :friends1: това нали не сум го обуркал... надиавам се вурши работа.... :no-no:

Някъкви промени..?

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

Fixcset::

Reboot::

След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

ComboFix 11-08-11.01 - Karina 08/11/2011 13:52:04.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2046.1348 [GMT 3:00] Running from: c:\documents and settings\Karina\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Karina\Desktop\CFScript.txt . . ((((((((((((((((((((((((( Files Created from 2011-07-11 to 2011-08-11 ))))))))))))))))))))))))))))))) . . 2011-08-10 06:49 . 2011-08-10 07:00 -------- d-----w- C:\Betsafe 2011-08-09 22:04 . 2011-08-09 22:04 -------- d-----w- c:\documents and settings\Karina\Application Data\Malwarebytes 2011-08-09 22:04 . 2011-07-06 16:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-09 22:04 . 2011-08-09 22:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-08-09 22:04 . 2011-08-09 22:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-08-09 22:04 . 2011-07-06 16:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-09 21:51 . 2011-08-09 21:51 388096 ----a-r- c:\documents and settings\Karina\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-08-09 21:51 . 2011-08-09 21:51 -------- d-----w- c:\program files\Trend Micro 2011-08-09 21:10 . 2011-08-09 21:10 15872 ----a-w- c:\windows\system32\drivers\HpqKbFiltr.sys 2011-08-09 21:10 . 2011-08-09 21:10 1419232 ----a-w- c:\windows\system32\drivers\wdfcoinstaller01005.dll 2011-08-09 20:56 . 2008-04-14 02:40 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll 2011-08-09 20:55 . 2006-12-28 21:31 19569 ----a-w- c:\windows\000004_.tmp 2011-08-08 21:42 . 2011-08-08 21:42 -------- d-----w- c:\program files\Winamp Detect 2011-08-08 16:40 . 2011-08-08 16:41 -------- d-----w- c:\program files\Intertops Poker 2011-08-08 13:24 . 2006-12-28 21:31 19569 ----a-w- c:\windows\000003_.tmp 2011-08-08 13:13 . 2011-08-08 13:13 -------- d-----w- c:\windows\IIS Temporary Compressed Files 2011-08-08 13:06 . 2008-04-14 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll 2011-08-08 13:06 . 2008-04-14 12:00 9216 -c--a-w- c:\windows\system32\dllcache\iwrps.dll 2011-08-08 13:06 . 2008-04-14 12:00 73728 -c--a-w- c:\windows\system32\dllcache\w3ext.dll 2011-08-08 13:06 . 2008-04-14 12:00 16896 -c--a-w- c:\windows\system32\dllcache\status.dll 2011-08-08 13:06 . 2008-04-14 12:00 53248 -c--a-w- c:\windows\system32\dllcache\nextlink.dll 2011-08-08 13:06 . 2008-04-14 12:00 31744 -c--a-w- c:\windows\system32\dllcache\pagecnt.dll 2011-08-08 13:06 . 2008-04-14 12:00 26624 -c--a-w- c:\windows\system32\dllcache\mdsync.dll 2011-08-08 13:06 . 2008-04-14 12:00 20992 -c--a-w- c:\windows\system32\dllcache\permchk.dll 2011-08-08 13:06 . 2008-04-14 12:00 7168 -c--a-w- c:\windows\system32\dllcache\isapips.dll 2011-08-08 12:59 . 2011-08-08 12:59 -------- d-----w- c:\windows\system32\URTTEMP 2011-08-08 10:36 . 2008-05-19 06:33 4445184 ----a-w- c:\windows\system32\msi.dll 2011-08-08 10:36 . 2008-05-19 06:33 332800 ----a-w- c:\windows\system32\msihnd.dll 2011-08-08 04:21 . 2011-08-08 04:21 -------- d-----w- c:\program files\Microsoft IntelliType Pro 2011-08-08 04:16 . 2011-08-08 04:17 -------- d-----w- c:\program files\Launch Manager 2011-08-08 04:16 . 2005-01-10 13:48 147456 ----a-w- c:\windows\UNINST32.EXE 2011-08-08 04:16 . 2004-12-09 09:04 5120 ----a-w- c:\windows\system32\FILTRCOI.DLL 2011-08-08 04:16 . 2004-12-08 11:10 16896 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS 2011-08-08 04:16 . 2002-12-19 12:58 49152 ----a-w- c:\windows\system32\QtBtLib.dll 2011-08-08 03:35 . 2011-08-08 03:35 -------- d-----w- c:\program files\Microsoft Silverlight 2011-08-08 02:47 . 2011-08-08 02:47 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\NVIDIA Corporation 2011-08-07 23:28 . 2011-03-30 18:46 101392 ----a-w- c:\windows\system32\drivers\AtihdXP3.sys 2011-08-07 23:12 . 2011-08-08 03:54 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\NVIDIA Corporation 2011-08-07 23:12 . 2011-08-07 23:12 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\NVIDIA Corporation 2011-08-07 23:12 . 2011-08-07 23:15 -------- d-----w- c:\program files\NVIDIA Corporation 2011-08-07 23:11 . 2011-08-07 23:11 -------- d-----w- C:\NVIDIA 2011-08-07 23:04 . 2011-08-07 23:04 485920 ----a-w- c:\windows\system32\nvunrm.exe 2011-08-07 23:04 . 2011-08-09 21:05 888320 ----a-w- c:\windows\system32\fdco1ins.dll 2011-08-07 23:04 . 2011-08-09 21:05 888320 ----a-w- c:\windows\system32\fdco1.dll 2011-08-07 23:04 . 2011-08-09 21:05 66688 ----a-w- c:\windows\system32\drivers\NVENETFD.sys 2011-08-07 23:04 . 2011-08-09 21:05 207872 ----a-w- c:\windows\system32\drivers\nvnrm.sys 2011-08-07 23:04 . 2011-08-09 21:05 13824 ----a-w- c:\windows\system32\drivers\nvnetbus.sys 2011-08-07 23:04 . 2011-08-09 21:05 11264 ----a-w- c:\windows\system32\bdco1ins.dll 2011-08-07 23:04 . 2011-08-09 21:05 11264 ----a-w- c:\windows\system32\bdco1.dll 2011-08-07 23:04 . 2011-08-07 23:04 151552 ----a-w- c:\windows\system32\nvconrm.dll 2011-08-07 22:33 . 2010-03-26 12:10 600680 ----a-w- c:\windows\system32\nvuninst.exe 2011-08-07 22:33 . 2011-08-09 21:07 485920 ----a-w- c:\windows\system32\nvusmb.exe 2011-08-07 22:33 . 2011-08-07 22:33 155648 ----a-w- c:\windows\system32\NVCOSMB.DLL 2011-08-07 22:33 . 2011-08-07 22:47 4090920 ----a-w- c:\windows\system32\drivers\RtKHDMI.sys 2011-08-07 22:33 . 2011-08-07 22:47 1489440 ----a-w- c:\windows\RtaUpd.exe 2011-08-07 22:33 . 2011-08-07 22:33 55912 ----a-w- c:\windows\system32\RHCoInstXP.dll 2011-08-07 13:46 . 2011-08-07 13:46 -------- d-----w- c:\program files\EA Sports 2011-08-07 13:30 . 2011-08-07 13:30 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\Identities 2011-08-06 07:46 . 2011-08-06 07:46 -------- d-----w- c:\documents and settings\Karina\Application Data\VeniceLobby.895DF36AEBDDDC40895175E41D084FB613D0A6E4.1 2011-08-06 07:45 . 2011-08-06 07:45 -------- d-----w- c:\program files\4DonkLive 2011-08-06 07:37 . 2008-04-14 02:41 81920 ------w- c:\windows\system32\ieencode.dll 2011-08-06 07:36 . 2006-12-28 21:31 19569 ----a-w- c:\windows\000002_.tmp 2011-08-06 07:27 . 2011-08-06 07:27 -------- d-----w- c:\program files\Resource Kit 2011-08-06 06:53 . 2011-08-08 13:13 -------- d-----w- C:\Inetpub 2011-08-06 06:53 . 2011-08-06 06:53 -------- d-----w- c:\windows\system32\Logfiles 2011-08-05 23:23 . 2011-08-05 23:27 -------- d-----w- c:\windows\system32\Adobe 2011-08-05 22:31 . 2008-04-14 12:00 18944 ----a-w- c:\windows\system32\simptcp.dll 2011-08-05 21:58 . 2011-08-08 13:01 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\ApplicationHistory 2011-08-05 20:43 . 2011-08-05 20:44 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\FixItCenter 2011-08-05 20:35 . 2011-08-05 20:43 -------- d-----w- c:\windows\MATS 2011-08-05 20:35 . 2011-08-05 20:43 -------- d-----w- c:\program files\Microsoft Fix it Center 2011-08-05 20:34 . 2011-08-05 20:34 -------- d-----w- c:\documents and settings\Karina\Application Data\ElevatedDiagnostics 2011-08-05 19:33 . 2011-08-05 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Pokernet 2011-08-05 19:11 . 2011-08-05 19:11 -------- d-----w- c:\windows\system32\XPSViewer 2011-08-05 19:11 . 2011-08-05 19:11 -------- d-----w- c:\program files\MSBuild 2011-08-05 19:11 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-08-05 19:11 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2011-08-05 19:11 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2011-08-05 19:11 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll 2011-08-05 19:11 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2011-08-05 19:11 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll 2011-08-05 19:11 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll 2011-08-05 19:11 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2011-08-05 19:11 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-08-05 18:53 . 2011-08-05 18:54 -------- dc-h--w- c:\windows\ie8 2011-08-05 18:11 . 2009-08-06 16:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2011-08-05 11:22 . 2011-08-06 08:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC 2011-08-04 16:19 . 2011-08-04 16:19 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\PCHealth 2011-08-04 16:02 . 2011-08-07 22:35 56960 ----a-w- c:\windows\system32\drivers\ousb2hub.sys 2011-08-04 16:02 . 2011-08-07 22:35 45696 ----a-w- c:\windows\system32\drivers\ousbehci.sys 2011-08-04 15:03 . 2011-08-04 15:42 -------- d-----w- c:\documents and settings\Karina\Application Data\Uniblue 2011-08-04 15:03 . 2011-08-04 16:01 -------- d-----w- c:\program files\Uniblue 2011-08-04 15:03 . 2011-08-04 15:03 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{DE8EABB5-1C85-4410-A68D-79BD8A4518F4} 2011-08-04 15:02 . 2011-08-04 15:22 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} 2011-08-04 14:59 . 2011-08-04 14:59 -------- d-----w- c:\program files\Babylon 2011-08-04 14:59 . 2011-08-04 14:59 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\Media Get LLC 2011-08-04 14:59 . 2011-08-04 16:29 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\MediaGet2 2011-08-04 13:52 . 2011-08-04 13:52 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\PackageAware 2011-08-04 10:39 . 2011-08-10 21:12 -------- d-----w- c:\program files\BluffRoom 2011-08-03 13:29 . 2011-08-03 13:29 -------- d-----w- c:\windows\system32\wbem\Repository 2011-08-03 12:59 . 2007-04-02 21:12 1327320 ------w- c:\program files\MSN\msncorefiles\install\msnsusii.exe 2011-08-03 12:57 . 2008-04-14 02:41 35328 ----a-w- c:\windows\system32\iprip.dll 2011-08-03 11:36 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-08-02 17:32 . 2011-08-02 17:32 -------- d-----w- c:\program files\SecurityXploded 2011-08-02 15:26 . 2011-08-02 15:26 -------- d-----w- c:\program files\Reference Assemblies 2011-08-02 15:26 . 2011-08-02 15:26 -------- d-----w- c:\documents and settings\Terminator\Application Data\ParetoLogic 2011-08-02 15:10 . 2011-08-02 15:10 -------- d-----w- C:\Casino 2011-08-02 14:51 . 2011-08-02 14:51 -------- d-----w- c:\documents and settings\Karina\Local Settings\Application Data\CPN 2011-08-02 14:45 . 2011-08-02 14:45 -------- d-----r- C:\AHCache 2011-08-02 12:25 . 2011-08-02 15:34 -------- d-----w- c:\program files\PokerStars.NET 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\documents and settings\Terminator\Application Data\DriverCure 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\program files\Common Files\ParetoLogic 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic 2011-08-02 11:26 . 2011-08-02 11:26 -------- d-----w- c:\program files\ParetoLogic 2011-08-02 10:40 . 2011-08-02 10:40 -------- d-----w- c:\documents and settings\Terminator\Local Settings\Application Data\Babylon 2011-08-02 10:40 . 2011-08-02 10:40 -------- d-----w- c:\documents and settings\Terminator\Application Data\Babylon 2011-08-01 17:31 . 2011-08-01 17:31 -------- d-----w- c:\documents and settings\Terminator\Application Data\DAEMON Tools Pro 2011-08-01 14:46 . 2011-08-03 13:35 233024 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-08-01 14:46 . 2011-08-01 14:46 -------- d-----w- c:\program files\DAEMON Tools Pro 2011-08-01 14:46 . 2011-08-09 22:46 -------- d-----w- c:\documents and settings\Karina\Application Data\DAEMON Tools Pro 2011-08-01 14:46 . 2011-08-01 14:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro 2011-08-01 12:52 . 2011-08-10 19:05 -------- d-----w- c:\windows\system32\drivers\AVG 2011-07-30 13:10 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll 2011-07-30 12:09 . 2011-08-06 07:13 -------- d-----w- c:\program files\NirSoft 2011-07-30 12:02 . 2011-07-30 12:02 -------- d--h--w- c:\windows\system32\GroupPolicy . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-07 22:49 . 2005-08-29 14:45 991264 ----a-w- c:\windows\system32\drivers\btkrnl.sys 2011-07-30 13:06 . 2011-06-09 19:54 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-15 13:29 . 2009-11-08 12:35 457856 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02 . 2008-04-14 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-26 17:17 . 2011-06-26 17:17 0 ----a-w- c:\windows\system32\ConduitEngine.tmp 2011-06-24 14:10 . 2011-06-09 17:07 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36 . 2009-11-08 12:37 916480 ----a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05 . 2009-11-08 12:37 385024 ------w- c:\windows\system32\html.iec 2011-06-20 17:44 . 2008-04-14 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-06-14 16:53 . 2011-06-14 16:53 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-06-14 16:53 . 2011-06-14 16:53 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-06-13 19:09 . 2011-06-13 19:09 65328 ----a-w- c:\windows\apppatch\matsshim.dll 2011-06-02 14:07 . 2009-11-08 12:36 1867904 ----a-w- c:\windows\system32\win32k.sys 2011-06-02 14:07 . 2009-11-08 12:36 1867904 ----a-w- c:\windows\system32\win32k(2).sys 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(6).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(5).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(4).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(3).dll 2011-05-25 03:14 . 2011-06-24 13:37 4059328 ----a-w- c:\windows\system32\ati3duag(2).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(6).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(5).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(4).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(3).dll 2011-05-25 03:05 . 2011-06-24 13:37 503808 ----a-w- c:\windows\system32\atiok3x2(2).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(6).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(5).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(4).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(3).dll 2011-05-25 02:55 . 2011-06-24 13:37 302592 ----a-w- c:\windows\system32\ati2dvag(2).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(6).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(5).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(4).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(3).dll 2011-05-25 02:54 . 2011-06-24 13:37 3152384 ----a-w- c:\windows\system32\ativvaxx(2).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(6).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(5).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(4).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(3).dll 2011-05-25 02:39 . 2011-06-24 13:37 212992 ----a-w- c:\windows\system32\atipdlxx(2).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(6).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(5).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(4).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(3).dll 2011-05-25 02:39 . 2011-06-24 13:37 43520 ----a-w- c:\windows\system32\ati2edxx(2).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(6).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(5).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(4).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(3).dll 2011-05-25 02:38 . 2011-06-24 13:37 188416 ----a-w- c:\windows\system32\ati2evxx(2).dll 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(6).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(5).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(4).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(3).exe 2011-05-25 02:37 . 2011-06-24 13:37 643072 ----a-w- c:\windows\system32\ati2evxx(2).exe 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(6).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(5).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(4).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(3).dll 2011-05-25 02:31 . 2011-06-24 13:37 651264 ----a-w- c:\windows\system32\atikvmag(2).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(6).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(5).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(4).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(3).dll 2011-05-25 02:27 . 2011-06-24 13:37 200704 ----a-w- c:\windows\system32\atiadlxx(2).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(6).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(5).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(4).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(3).dll 2011-05-25 02:22 . 2011-06-24 13:37 856064 ----a-w- c:\windows\system32\ati2cqag(2).dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2009-11-08 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys [-] 2009-11-08 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys [7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys . [-] 2009-11-08 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll [-] 2009-11-08 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll [7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll . [-] 2009-11-08 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe [-] 2009-11-08 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe [7] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe . [-] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\spoolsv.exe [-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\dllcache\spoolsv.exe [7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe [7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe . [-] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll [-] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll [7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll [7] 2008-04-14 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll [7] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll [7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll [7] 2001-08-23 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\InstallTemp\48339\comctl32.dll . [-] 2009-11-08 12:32 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll [-] 2009-11-08 12:32 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll [7] 2008-04-14 02:41 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll . [-] 2009-11-08 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll [-] 2009-11-08 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll [7] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll . [-] 2009-11-08 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll [-] 2009-11-08 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll [7] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\mswsock.dll . [-] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\system32\ole32.dll [-] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\system32\dllcache\ole32.dll [7] 2008-04-14 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll [7] 2008-04-14 . ECCE74BC6168375016450A86A164D976 . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll . [-] 2010-04-16 . 9E03DC5AB51CFD0190541CE2038D819D . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\usp10.dll [-] 2010-04-16 . 9E03DC5AB51CFD0190541CE2038D819D . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\dllcache\usp10.dll [-] 2010-04-16 . F8894BCC961D461674002B4BAE7AECC1 . 406016 . . [1.0420.2600.5969] . . c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll [7] 2008-04-14 . 7D7D8501F3CB45D0408CDEFA08CDAEFF . 406016 . . [1.0420.2600.5512] . . c:\windows\$NtUninstallKB981322$\usp10.dll [7] 2008-04-14 . 7D7D8501F3CB45D0408CDEFA08CDAEFF . 406016 . . [1.0420.2600.5512] . . c:\windows\ServicePackFiles\i386\usp10.dll . [-] 2009-07-27 . 888CD7B39C37E13A2419BECFAAF0A28C . 135168 . . [6.00.2900.5853] . . c:\windows\system32\shsvcs.dll [-] 2009-07-27 . 888CD7B39C37E13A2419BECFAAF0A28C . 135168 . . [6.00.2900.5853] . . c:\windows\system32\dllcache\shsvcs.dll [7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB971029$\shsvcs.dll [7] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll . [-] 2010-09-18 07:18 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll [-] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\system32\mfc40u.dll [-] 2010-09-18 06:53 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . c:\windows\system32\dllcache\mfc40u.dll [7] 2008-04-14 12:00 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll [7] 2008-04-14 02:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll . [-] 2010-12-09 . F67CD97282E0ABFAF91A9A1359B16F2D . 2069376 . . [5.1.2600.6055] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe [-] 2010-12-09 . F67CD97282E0ABFAF91A9A1359B16F2D . 2069376 . . [5.1.2600.6055] . . c:\windows\system32\dllcache\ntkrnlpa.exe [-] 2010-12-09 . F917F7E5FC9F80D3C36978A9CCEF6BE4 . 2027008 . . [5.1.2600.6055] . . c:\windows\system32\ntkrnlpa.exe [-] 2009-11-08 . 9D22A1961421CCD10BDCC0BA04F93A4C . 2023936 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe [7] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe . [-] 2010-12-09 . DC4A984DEA7E24166800D38442405130 . 2148864 . . [5.1.2600.6055] . . c:\windows\system32\ntoskrnl.exe [-] 2010-12-09 . A531BBD3DE13121C1380ED7DC99082DB . 2192768 . . [5.1.2600.6055] . . c:\windows\Driver Cache\i386\ntoskrnl.exe [-] 2010-12-09 . A531BBD3DE13121C1380ED7DC99082DB . 2192768 . . [5.1.2600.6055] . . c:\windows\system32\dllcache\ntoskrnl.exe [-] 2009-11-08 . BDADF0AD9776DA6FD65FC713A8B1DCE9 . 2145280 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB2393802$\ntoskrnl.exe [7] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048] "SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\launcher.exe" [2011-05-23 67960] "DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "D-Link AirPlus XtremeG DWL-G122"="c:\program files\D-Link\AirPlus XtremeG DWL-G122\AirGCFG.exe" [2008-01-02 1552384] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-05-16 213936] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "BigDogPath323VMSnap"="c:\windows\VMSnap23.exe" [2007-06-29 212992] "BigDogPath323Domino"="c:\windows\Domino.exe" [2007-06-29 49152] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "CNAP2 Launcher"="c:\windows\System32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE" [2010-01-11 226784] "PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-26 648032] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752] "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2011-06-02 114992] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-10-9 610365] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\BitComet\\BitComet.exe"= "c:\\Program Files\\Redbet\\pokerclient\\Redbet.exe"= "c:\\Program Files\\24hPoker\\pokerclient\\24hPoker.exe"= "f:\\Program Files\\Intertops Poker\\PokerClient.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Intertops Poker\\PokerClient.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10359:TCP"= 10359:TCP:BitComet 10359 TCP "10359:UDP"= 10359:UDP:BitComet 10359 UDP "21503:TCP"= 21503:TCP:BitComet 21503 TCP "21503:UDP"= 21503:UDP:BitComet 21503 UDP "3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping "3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) . R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [8/1/2011 5:46 PM 233024] R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [8/4/2011 7:02 PM 45696] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [8/8/2011 2:28 AM 101392] R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [9/15/2009 2:59 PM 38248] R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [8/4/2011 7:02 PM 56960] R3 vmfilter323;323 filter service, Normal;c:\windows\system32\drivers\vmfilter323.sys [6/15/2011 12:00 PM 476672] R3 ZSMC326;CANYON USB PC Camera;c:\windows\system32\drivers\usbvm323.sys [6/15/2011 12:00 PM 260224] S0 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?] S2 Guard.Mail.ru;Guard.Mail.ru; [x] S2 gupdate;Google Update Service (gupdate); [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider; [x] S3 gupdatem;Google Update Service (gupdatem); [x] S3 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [4/14/2008 3:00 PM 14336] S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [6/13/2011 10:09 PM 267568] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/10/2011 1:04 AM 41272] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc . Contents of the 'Scheduled Tasks' folder . 2011-08-11 c:\windows\Tasks\ConfigExec.job - c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 19:09] . 2011-08-11 c:\windows\Tasks\DataUpload.job - c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 19:09] . 2011-08-11 c:\windows\Tasks\DriverScanner.job - c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2011-08-04 08:22] . 2011-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-839522115-1003Core.job - c:\documents and settings\Karina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 13:52] . 2011-08-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1844237615-839522115-1003UA.job - c:\documents and settings\Karina\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 13:52] . 2011-08-02 c:\windows\Tasks\ParetoLogic Registration3.job - c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2011-03-29 23:17] . 2011-08-02 c:\windows\Tasks\ParetoLogic Update Version3.job - c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-03-29 23:17] . 2011-08-10 c:\windows\Tasks\PC Health Advisor Defrag.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-03-29 23:17] . 2011-08-08 c:\windows\Tasks\PC Health Advisor.job - c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-03-29 23:17] . 2011-08-11 c:\windows\Tasks\RegistryBooster.job - c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2011-01-21 13:29] . 2011-08-11 c:\windows\Tasks\SpeedUpMyPC.job - c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-04 14:27] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.bg/ IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe TCP: DhcpNameServer = 192.168.1.1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-08-11 13:54 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.avgldx86] "ImagePath"="\*" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(1312) c:\windows\system32\Ati2evxx.dll c:\windows\system32\atiadlxx.dll . - - - - - - - > 'explorer.exe'(2728) c:\windows\system32\WININET.dll c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll c:\windows\system32\ieframe.dll c:\windows\system32\msi.dll c:\windows\system32\webcheck.dll . Completion time: 2011-08-11 13:55:45 ComboFix-quarantined-files.txt 2011-08-11 10:55 ComboFix2.txt 2011-08-11 10:48 ComboFix3.txt 2011-08-10 19:42 . Pre-Run: 103,543,209,984 bytes free Post-Run: 103,523,471,360 bytes free . Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6 - - End Of File - - 9B4A3E8C4028ED9AF9BFDBA9AE944C76

  • Автор

мислия че всичко е наред свалих си касперски аанти вирусна и не засече нищо.Мерси много а тези логове да ги трия нали и там преди да инстал касперски не ми даваше да го инсталирам казваше да изтриа фаила сетуп екзе и изтрих комбото след което ми разреши надиавам се не сум направил ниакоя глупост.

Радвам се..! :) Правилното и задължителното деинсталиране на Комбофикс е така:

1.Натиснете Start ==> Run ==> въведете командата Combofix /Uninstall ==> OK

Публикувано изображение

2.Изтеглете OTCleanIt или от тук,стартирайте и натиснете Clean up

Ако след процедурите все още има логове и програми които използвахме, изтрийте ги ръчно.!

С това приключваме..!Пожелавам ви безопасен интернет и лек ден..! :no-no:

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.