Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Компютърът ми е нападнат от вируса searchqu.com 406

Featured Replies

Здравейте!

Компютърът ми и в частност имейлът ми в яху е нападнат от вируса searchqu.com 406.

Доколкото си спомням компютърът ми отвори адресната книга на яху и се разпространи чрезтях като им изпраща някакви линкове.

Когато след два дни разбрах, че е вирус пуснах антивирусната ми програма F-secure Client Security (малко е стара версията) и тя откри някакви неща. Изтрих ги. След като видях, че това не оправи нещата потърсих някаква информация в интернет и намерих в този сайт

http://community.nor...val/td-p/460968 някакви съвети.

Последвах този съвет Remove directories C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar, а след това и този Sounds like you need a little extra help

Download the free copy of Malware Bytes utility and run it. Be sure to use the free version, there is a conflict when you try to run more than one real-time security program.

Norton is good but not perfect so using more than one security program may be necessary to keep your system absolutely clean.

Hope this thelp - be sreu to let us know.

Досадната хоум страница изчезна след проверка със споменатата програма (тя откри на бързо сканиране 13 зловредности), но яху продължи да действа със някакви съобщения от типа mailer-demon.

Моля, помогнете със съвет как да изчистят пощата и компютърът си.

Със закъснение видях, че имате някои изисквания. Аз обаче нещо не мога да се справя с тях. Записвам файла DDS на декстопа, но как се разбира за блокиращите приложения, защото те явно пречат и ми се отваря някакъв текст на маймуни. ОС Windows XP Home edition. Забравих да добавя, че заразата стана през IE.

Редактирано от mariamaria_73 (преглед на промените)

Здравейте..! :)

* Изтеглете Malwarebytes' Anti-Malware или от тук

* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.

* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.

* Ако има намерени обновявания, тя ще ги изтегли и инсталира.

* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.

* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.

* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

  • Автор

Здравейте! Днес направих пълно сканиране по Вашите препоръки с програмата. Изпращам Ви по-долу исканата информация, но с тази програма съм правила още 2 бързи и 1 пълно сканиране. Интересува ли Ви и по-старата информация, защото и там бяха намерени доста работи? Между другото и днес пощата ми в яху, която се зарази е изпратила писма по адресната книга. С нея какво да правя, че вече става неудобно пред приятелите ми? Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Версия на базата от данни: 7468 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 15.8.2011 г. 13:05:57 mbam-log-2011-08-15 (13-05-57).txt Тип сканиране: Пълно сканиране (C:\|F:\|Y:\|) Сканирани обекти: 587611 Изминало време: 4 час(а), 9 минута(и), 13 секунда(и) Заразени процеси в паметта: 0 Заразени модули в паметта: 0 Заразени ключове в регистратурата: 0 Заразени стойности в регистратурата: 0 Заразени информационни обекти в регистратурата: 0 Заразени папки: 0 Заразени файлове: 5 Заразени процеси в паметта: (Не бяха открити зловредни обекти) Заразени модули в паметта: (Не бяха открити зловредни обекти) Заразени ключове в регистратурата: (Не бяха открити зловредни обекти) Заразени стойности в регистратурата: (Не бяха открити зловредни обекти) Заразени информационни обекти в регистратурата: (Не бяха открити зловредни обекти) Заразени папки: (Не бяха открити зловредни обекти) Заразени файлове: c:\programs2008_exe\uedit32\krack_dm_ue810\damn_uedit810.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully. c:\system volume information\_restore{f8223660-5d95-457f-8dd6-3ad6878c7986}\RP400\A0067206.exe (Adware.Agent) -> Quarantined and deleted successfully. c:\documents and settings\tzvetomir tzanovski\application data\WinPump\pumpa.exe (Trojan.BTManager) -> Quarantined and deleted successfully. f:\HardDD_C\2007-bulgaria\fromminiusb\ultraedit v8.20\dm_ue810\damn_uedit810.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully. y:\2010_programs\tubedownloadersetup.exe (Spyware.Dropper) -> Quarantined and deleted successfully.

Преименувайте dds.scr => dds.pif и изключете антивирусната си програма и опитайте да направите сканиране с DDS...!Ако не се получи - изтеглете WinXP , запазете и разархивирайте на десктопа,старирате с двоен клик,рестартирате компютъра си...Ако се получи сканирайте и публикувайте дневник от DDS.

След това продължете с тази инструкция:

Изтеглете ComboFix от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.

Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs

  • Стартирайте Combo-Fix.com и следвайте инструкциите.

Бележка: ComboFix ще се стартира без инсталирана Recovery Console.

  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.

Работата на ComboFix, може да отнеме до 20-30 минути, за да завърши, моля имайте търпение.

Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

  • Автор

DDS.txt . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by Tzvetomir Tzanovski at 8:35:50 on 2011-08-16 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2047.740 [GMT 3:00] . AV: F-Secure Client Security 7.12 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15} FW: F-Secure Client Security 7.12 *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Megatec\UPSilon 2000\RupsMon.exe C:\Program Files\F-Secure\Common\FCH32.EXE C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Megatec\UPSilon 2000\USBMate.exe C:\WINDOWS\System32\Drivers\WTSRV.EXE C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsqh.exe C:\WINDOWS\system32\mqsvc.exe C:\WINDOWS\system32\mqtgsvc.exe C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\F-Secure\FSAUA\program\fsaua.exe C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Turbo Keyboard Application\PS2USBKbdDrv.exe C:\WINDOWS\system32\WTClient.exe C:\WINDOWS\emMON.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\program files\real\realplayer\update\realsched.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe C:\Program Files\Rainlendar2\Rainlendar2.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\F-Secure\FSGUI\fsguidll.exe C:\Program Files\Samsung\Digimax Viewer 1.0\DigimaxViewer.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Megatec\UPSilon 2000\Monw32.exe C:\WINDOWS\VPro530.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\Common Files\Teleca Shared\Generic.exe C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe c:\program files\real\realplayer\RealPlay.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\WinRAR\WinRAR.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uSearch Page = hxxp://www.toggle.com/en/index.php?rvs=google uWindow Title = Windows Internet Explorer provided by Yahoo! uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8 mStart Page = hxxp://search.myheritage.com uInternet Settings,ProxyServer = 78.90.47.132:80 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\family toolbar\tbcore3.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll BHO: Downius Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\family toolbar\tbcore3.dll TB: Downius Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {2C688203-7EB3-4327-9995-1CB417BA23F9} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [Philips Intelligent Agent] "c:\program files\philips\intelligent agent\Philips Intelligent Agent.exe" /SILENT uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [Google Update] "c:\documents and settings\tzvetomir tzanovski\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [WireLessKeyboard] c:\program files\turbo keyboard application\PS2USBKbdDrv.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [WTClient] WTClient.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [startCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [emMON] emMON.exe mRun: [Family Tree Builder Update] c:\program files\myheritage\bin\FTBCheckUpdates.exe mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [sony Ericsson PC Suite] "c:\program files\sony ericsson\mobile2\application launcher\Application Launcher.exe" /startoptions mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [F-Secure Manager] "c:\program files\f-secure\common\FSM32.EXE" /splash mRun: [F-Secure TNB] "c:\program files\f-secure\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digima~1.lnk - c:\program files\samsung\digimax viewer 1.0\DigimaxViewer.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\rupsmo~1.lnk - c:\program files\megatec\upsilon 2000\Monw32.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpro530.lnk - c:\windows\VPro530.exe IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSP: c:\program files\f-secure\fsps\program\FSLSP.DLL Trusted Zone: ubb.bg\ebb DPF: {0000000A-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/A/D/FADB11F1-A66C-43C0-AFCA-1106CF4BA374/wmsp9dmo.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {32564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8dmo.cab DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} - hxxps://ebb.ubb.bg/CAPICOM/capicom.cab DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{41A8FC36-F405-48F5-8FB6-DF4517C8EA99} : DhcpNameServer = 192.168.1.1 Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 nwprovau mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\tzvetomir tzanovski\application data\mozilla\firefox\profiles\jm24teqf.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Search Results FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406 FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q= FF - prefs.js: keyword.enabled - true FF - component: c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll FF - component: c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll FF - component: c:\program files\mozilla firefox\extensions\[email protected]\components\qfaservices.dll FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll . ============= SERVICES / DRIVERS =============== . R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2011-8-10 59808] R1 F-Secure HIPS;F-Secure HIPS;c:\program files\f-secure\hips\fshs.sys [2011-8-10 70752] R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\f-secure\anti-virus\fsgk32st.exe [2011-8-10 47800] R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\f-secure\anti-virus\minifilter\fsgk.sys [2011-8-10 72288] R3 F-Secure Network Request Broker;F-Secure Network Request Broker;c:\program files\f-secure\common\FNRB32.exe [2011-8-10 162456] R3 phaudlwr;Philips Audio Filter;c:\windows\system32\drivers\phaudlwr.sys [2009-12-19 88704] R3 SPC530;Philips SPC530NC PC Camera;c:\windows\system32\drivers\SPC530.sys [2009-12-19 486912] R3 SPC530m;Philips SPC530NC PC Cameram;c:\windows\system32\drivers\SPC530m.sys [2009-12-19 7680] S2 gupdate1c99b214ffe13b0;Google Update Service (gupdate1c99b214ffe13b0);c:\program files\google\update\GoogleUpdate.exe [2009-3-2 133104] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-3-2 133104] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-8-11 41272] S4 F-Secure Filter;F-Secure File System Filter;c:\program files\f-secure\anti-virus\win2k\fsfilter.sys [2011-8-10 39776] S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\f-secure\anti-virus\win2k\fsrec.sys [2011-8-10 25184] . =============== Created Last 30 ================ . 2011-08-11 14:42:09 154502 ----a-w- c:\documents and settings\tzvetomir tzanovski\microsoft_auto_route_2011.exe 2011-08-11 14:33:31 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\local settings\application data\Babylon 2011-08-11 14:33:30 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\Babylon 2011-08-11 14:33:30 -------- d-----w- c:\documents and settings\all users\application data\Babylon 2011-08-11 11:39:33 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\Malwarebytes 2011-08-11 11:39:28 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-11 11:39:26 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2011-08-11 11:39:22 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-11 11:39:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-08-10 10:33:18 59808 ----a-w- c:\windows\system32\drivers\fsdfw.sys 2011-08-10 10:33:18 29824 ----a-w- c:\windows\system32\drivers\fsndis5.sys 2011-08-10 05:54:08 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-10 05:53:21 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys 2011-08-03 17:15:58 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\goalbit 2011-07-28 19:12:22 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\searchquband 2011-07-28 19:12:22 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\AppData 2011-07-28 19:05:30 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\local settings\application data\Ilivid Player 2011-07-28 19:04:40 -------- d-----w- c:\documents and settings\all users\application data\boost_interprocess 2011-07-24 20:54:35 -------- d-----w- c:\program files\InhatchTeam . ==================== Find3M ==================== . 2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36:30 916480 ----a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 ------w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:13 385024 ------w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-06-18 12:29:47 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys 2011-05-29 16:36:20 387600 ----a-w- c:\windows\system32\FTBSaver.scr . ============= FINISH: 8:36:46,06 =============== Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 26.11.2008 г. 17:24:37 System Uptime: 16.8.2011 г. 00:44:13 (8 hours ago) . Motherboard: ECS | | P45T-A Processor: Intel Pentium III Xeon processor | CPU 1 | 1979/333mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 244 GiB total, 191,147 GiB free. D: is CDROM () F: is FIXED (NTFS) - 466 GiB total, 105,402 GiB free. Y: is FIXED (NTFS) - 352 GiB total, 158,201 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: PCI Device Device ID: PCI\VEN_197B&DEV_2361&SUBSYS_23611019&REV_02\4&34EBACD6&0&00E4 Manufacturer: Name: PCI Device PNP Device ID: PCI\VEN_197B&DEV_2361&SUBSYS_23611019&REV_02\4&34EBACD6&0&00E4 Service: . Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia N70 Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia N70 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd . ==== System Restore Points =================== . RP351: 18.5.2011 г. 14:20:29 - System Checkpoint RP352: 19.5.2011 г. 15:55:16 - System Checkpoint RP353: 24.5.2011 г. 10:44:37 - System Checkpoint RP354: 25.5.2011 г. 11:19:24 - System Checkpoint RP355: 26.5.2011 г. 16:52:24 - System Checkpoint RP356: 28.5.2011 г. 14:19:10 - System Checkpoint RP357: 30.5.2011 г. 14:05:47 - System Checkpoint RP358: 31.5.2011 г. 17:05:35 - System Checkpoint RP359: 01.6.2011 г. 18:27:44 - System Checkpoint RP360: 03.6.2011 г. 09:50:29 - System Checkpoint RP361: 05.6.2011 г. 20:23:33 - System Checkpoint RP362: 07.6.2011 г. 13:24:04 - System Checkpoint RP363: 07.6.2011 г. 15:17:09 - Installed Windows Internet Explorer 8. RP364: 07.6.2011 г. 15:18:28 - Software Distribution Service 3.0 RP365: 07.6.2011 г. 15:42:20 - Software Distribution Service 3.0 RP366: 08.6.2011 г. 16:28:34 - System Checkpoint RP367: 10.6.2011 г. 11:50:11 - System Checkpoint RP368: 11.6.2011 г. 16:35:29 - System Checkpoint RP369: 14.6.2011 г. 10:12:35 - System Checkpoint RP370: 15.6.2011 г. 10:14:09 - System Checkpoint RP371: 15.6.2011 г. 20:47:46 - Unsigned driver install RP372: 15.6.2011 г. 20:53:21 - Installed Java 6 Update 26 RP373: 17.6.2011 г. 10:48:20 - System Checkpoint RP374: 17.6.2011 г. 17:55:03 - Software Distribution Service 3.0 RP375: 19.6.2011 г. 09:06:47 - System Checkpoint RP376: 20.6.2011 г. 14:24:26 - System Checkpoint RP377: 21.6.2011 г. 14:27:23 - System Checkpoint RP378: 22.6.2011 г. 16:46:17 - System Checkpoint RP379: 23.6.2011 г. 16:47:41 - System Checkpoint RP380: 27.6.2011 г. 10:14:53 - System Checkpoint RP381: 28.6.2011 г. 11:33:58 - System Checkpoint RP382: 30.6.2011 г. 10:53:49 - Software Distribution Service 3.0 RP383: 01.7.2011 г. 10:56:17 - System Checkpoint RP384: 04.7.2011 г. 09:49:25 - Removed Adobe Reader 9.4.5. RP385: 04.7.2011 г. 09:49:51 - Installed Adobe Reader X (10.1.0). RP386: 05.7.2011 г. 15:01:30 - System Checkpoint RP387: 07.7.2011 г. 14:14:56 - System Checkpoint RP388: 08.7.2011 г. 17:41:29 - System Checkpoint RP389: 11.7.2011 г. 08:45:03 - System Checkpoint RP390: 12.7.2011 г. 10:45:58 - System Checkpoint RP391: 13.7.2011 г. 09:39:19 - Software Distribution Service 3.0 RP392: 14.7.2011 г. 13:56:11 - System Checkpoint RP393: 15.7.2011 г. 14:16:34 - System Checkpoint RP394: 18.7.2011 г. 09:52:10 - System Checkpoint RP395: 20.7.2011 г. 09:29:22 - System Checkpoint RP396: 21.7.2011 г. 14:41:09 - System Checkpoint RP397: 22.7.2011 г. 15:08:32 - System Checkpoint RP398: 24.7.2011 г. 22:51:39 - System Checkpoint RP399: 27.7.2011 г. 14:08:33 - System Checkpoint RP400: 28.7.2011 г. 23:50:55 - System Checkpoint RP401: 31.7.2011 г. 10:59:01 - System Checkpoint RP402: 01.8.2011 г. 14:34:13 - System Checkpoint RP403: 02.8.2011 г. 16:38:38 - System Checkpoint RP404: 03.8.2011 г. 18:52:28 - System Checkpoint RP405: 05.8.2011 г. 13:35:31 - System Checkpoint RP406: 07.8.2011 г. 09:05:56 - System Checkpoint RP407: 08.8.2011 г. 14:07:34 - System Checkpoint RP408: 09.8.2011 г. 14:16:20 - System Checkpoint RP409: 10.8.2011 г. 13:14:01 - is 10.51 build 106 Installation RP410: 10.8.2011 г. 13:32:50 - F-Secure Client Security 7.12 build 108 Installation RP411: 10.8.2011 г. 22:21:08 - Software Distribution Service 3.0 RP412: 12.8.2011 г. 13:23:50 - System Checkpoint RP413: 13.8.2011 г. 17:22:25 - System Checkpoint RP414: 15.8.2011 г. 10:30:58 - System Checkpoint . ==== Installed Programs ====================== . Домашен Кулинар FX Астролог µTorrent 50 FREE MP3s +1 Free Audiobook! Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader X (10.1.0) Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft MediaImpression Ask Toolbar ASUS VGA Driver ATI - Software Uninstall Utility ATI AVIVO Codecs ATI Catalyst Control Center ATI Display Driver ATI Parental Control & Encoder ATI Problem Report Wizard AutoCAD Civil 3D 2008 Autodesk Design Review 2008 Autodesk FBX for QuickTime 7.0 Bonjour BurnInTest v6.0 Pro Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full ccc-core-preinstall ccc-core-static ccc-utility CCC Help English Compatibility Pack for the 2007 Office system Corel Graphics Suite 11 Critical Update for Windows Media Player 11 (KB959772) Cyrilla Correct Digimax Viewer 1.0 EasyBits GO F-Secure Client Security - E-Mail Scanning F-Secure Client Security - Internet Shield F-Secure Client Security - System Control F-Secure Client Security - Virus & Spy Protection F-Secure Client Security - Web Traffic Scanning Free Word Excel Password Wizard Google Chrome Google Earth Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HydraVision Inhatch web plugins Introduction to Visual Basic 2008 Express Edition iTunes J2SE Runtime Environment 5.0 Update 12 Java Auto Updater Java 6 Update 26 K-Lite Codec Pack 4.2.5 (Full) KB Piano 2.3.2 Koral English Dictionary 2.01 L&H TTS3000 British English Legacy Charting 7.4 Lernout & Hauspie TruVoice American English TTS Engine MAGGI Malwarebytes' Anti-Malware, версия 1.51.1.1800 Maxthon2 Microsoft .NET Framework (English) Microsoft .NET Framework (English) v1.0.3705 Microsoft .NET Framework 1.0 Hotfix (KB928367) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft AutoRoute 2010 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft English TTS Engine Microsoft FrontPage Client - English Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Access database engine 2007 (English) Microsoft Office Live Add-in 1.3 Microsoft Office XP Media Content Microsoft Office XP Small Business Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.7 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable Package Microsoft Visual Studio .NET Enterprise Architect - English MobileMe Control Panel Modern Kitchen Mozilla Firefox (2.0) MSN MSVC80_x86 MSVC80_x86_v2 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB954459) MyHeritage Family Tree Builder Nero 7 Demo Nokia Connectivity Cable Driver Nokia PC Suite Opera 9.51 PC Connectivity Solution Philips Intelligent Agent Philips SPC530NC Webcam Philips VLounge PhotoStory Moetodete.bg 2.8.1 Picasa 3 POLYGLOT 7 Power Challenge Game Plugin QuickTime Rainlendar2 (remove only) RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.1 Safari Samsung Digimax 300 SAPI Wrapper Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2124261) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2290570) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB970483) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB976323) Security Update for Windows XP (KB977165-v2) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Skype™ 5.5 Sony Ericsson Device Data Sony Ericsson Drivers Sony Ericsson PC Suite TTS Wrapper Turbo Keyboard Application UltraEdit-32 Uninstall Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) UPSilon 2000 USB Video/Audio Device Driver VBA (2627.01) VideoLAN VLC media player 0.8.6i Visual Studio .NET Enterprise Architect - English Visual Studio.NET Baseline - English WebFldrs XP Winamp Winamp Toolbar Windows Driver Package - Nokia Modem (05/22/2008 3.8) Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4) Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2) Windows Driver Package - Nokia Modem (10/05/2009 4.2) Windows Driver Package - Nokia Modem (10/12/2007 3.6) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Driver Package - Philips (SPC530) Image (02/27/2008 1.00.4.6100) Windows Driver Package - Philips (SPC530) Image (05/21/2008 1.01.3.6650) Windows Driver Package - Philips CL (phaudlwr) MEDIA (02/19/2008 1.0.2.9) Windows Driver Package - Philips CL (phaudlwr) MEDIA (05/07/2008 1.0.5.12) Windows Driver Package - Philips USB (02/27/2008 1.00.4.6100) Windows Driver Package - Philips USB (05/21/2008 1.01.3.6650) Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Sign-in Assistant Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinPump WinRAR archiver Yahoo! Software Update Yahoo! Toolbar . ==== Event Viewer Messages From Past Week ======== . 16.8.2011 г. 06:21:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 16.8.2011 г. 06:21:22, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 21:37:23, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 21:37:21, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 12:49:08, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 12:48:48, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 12:48:45, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 08:43:53, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 08:43:52, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.8.2011 г. 21:05:18, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.8.2011 г. 21:05:16, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.8.2011 г. 06:26:53, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the F-Secure Gatekeeper Handler Starter service. 14.8.2011 г. 06:26:17, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the F-Secure Gatekeeper Handler Starter service. 13.8.2011 г. 15:25:25, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 13.8.2011 г. 10:16:57, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 13.8.2011 г. 10:16:57, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 11.8.2011 г. 15:21:00, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 11.8.2011 г. 15:20:35, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0021970A3816 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 11.8.2011 г. 10:36:08, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 18:17:19, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 18:16:59, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 18:16:59, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 18:16:58, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:35:01, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:28:27, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:19:03, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:18:39, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0021970A3816 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 10.8.2011 г. 13:17:01, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:12:59, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:05:03, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:04:43, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:04:40, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:04:40, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 09.8.2011 г. 13:28:33, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 09.8.2011 г. 13:28:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) . ==== End Of File =========================== DDS.txt . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by Tzvetomir Tzanovski at 8:35:50 on 2011-08-16 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2047.740 [GMT 3:00] . AV: F-Secure Client Security 7.12 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15} FW: F-Secure Client Security 7.12 *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Megatec\UPSilon 2000\RupsMon.exe C:\Program Files\F-Secure\Common\FCH32.EXE C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Megatec\UPSilon 2000\USBMate.exe C:\WINDOWS\System32\Drivers\WTSRV.EXE C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsqh.exe C:\WINDOWS\system32\mqsvc.exe C:\WINDOWS\system32\mqtgsvc.exe C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\F-Secure\FSAUA\program\fsaua.exe C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Turbo Keyboard Application\PS2USBKbdDrv.exe C:\WINDOWS\system32\WTClient.exe C:\WINDOWS\emMON.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\program files\real\realplayer\update\realsched.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe C:\Program Files\Rainlendar2\Rainlendar2.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\F-Secure\FSGUI\fsguidll.exe C:\Program Files\Samsung\Digimax Viewer 1.0\DigimaxViewer.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Megatec\UPSilon 2000\Monw32.exe C:\WINDOWS\VPro530.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\Common Files\Teleca Shared\Generic.exe C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe c:\program files\real\realplayer\RealPlay.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\WinRAR\WinRAR.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uSearch Page = hxxp://www.toggle.com/en/index.php?rvs=google uWindow Title = Windows Internet Explorer provided by Yahoo! uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8 mStart Page = hxxp://search.myheritage.com uInternet Settings,ProxyServer = 78.90.47.132:80 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\family toolbar\tbcore3.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll BHO: Downius Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\family toolbar\tbcore3.dll TB: Downius Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {2C688203-7EB3-4327-9995-1CB417BA23F9} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [Philips Intelligent Agent] "c:\program files\philips\intelligent agent\Philips Intelligent Agent.exe" /SILENT uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [Google Update] "c:\documents and settings\tzvetomir tzanovski\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [Rainlendar2] c:\program files\rainlendar2\Rainlendar2.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [WireLessKeyboard] c:\program files\turbo keyboard application\PS2USBKbdDrv.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [WTClient] WTClient.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [startCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [emMON] emMON.exe mRun: [Family Tree Builder Update] c:\program files\myheritage\bin\FTBCheckUpdates.exe mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [sony Ericsson PC Suite] "c:\program files\sony ericsson\mobile2\application launcher\Application Launcher.exe" /startoptions mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [F-Secure Manager] "c:\program files\f-secure\common\FSM32.EXE" /splash mRun: [F-Secure TNB] "c:\program files\f-secure\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digima~1.lnk - c:\program files\samsung\digimax viewer 1.0\DigimaxViewer.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\rupsmo~1.lnk - c:\program files\megatec\upsilon 2000\Monw32.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpro530.lnk - c:\windows\VPro530.exe IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSP: c:\program files\f-secure\fsps\program\FSLSP.DLL Trusted Zone: ubb.bg\ebb DPF: {0000000A-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/A/D/FADB11F1-A66C-43C0-AFCA-1106CF4BA374/wmsp9dmo.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {32564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8dmo.cab DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} - hxxps://ebb.ubb.bg/CAPICOM/capicom.cab DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{41A8FC36-F405-48F5-8FB6-DF4517C8EA99} : DhcpNameServer = 192.168.1.1 Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 nwprovau mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\tzvetomir tzanovski\application data\mozilla\firefox\profiles\jm24teqf.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Search Results FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406 FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q= FF - prefs.js: keyword.enabled - true FF - component: c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll FF - component: c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll FF - component: c:\program files\mozilla firefox\extensions\[email protected]\components\qfaservices.dll FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll . ============= SERVICES / DRIVERS =============== . R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2011-8-10 59808] R1 F-Secure HIPS;F-Secure HIPS;c:\program files\f-secure\hips\fshs.sys [2011-8-10 70752] R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\f-secure\anti-virus\fsgk32st.exe [2011-8-10 47800] R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\f-secure\anti-virus\minifilter\fsgk.sys [2011-8-10 72288] R3 F-Secure Network Request Broker;F-Secure Network Request Broker;c:\program files\f-secure\common\FNRB32.exe [2011-8-10 162456] R3 phaudlwr;Philips Audio Filter;c:\windows\system32\drivers\phaudlwr.sys [2009-12-19 88704] R3 SPC530;Philips SPC530NC PC Camera;c:\windows\system32\drivers\SPC530.sys [2009-12-19 486912] R3 SPC530m;Philips SPC530NC PC Cameram;c:\windows\system32\drivers\SPC530m.sys [2009-12-19 7680] S2 gupdate1c99b214ffe13b0;Google Update Service (gupdate1c99b214ffe13b0);c:\program files\google\update\GoogleUpdate.exe [2009-3-2 133104] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-3-2 133104] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-8-11 41272] S4 F-Secure Filter;F-Secure File System Filter;c:\program files\f-secure\anti-virus\win2k\fsfilter.sys [2011-8-10 39776] S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\f-secure\anti-virus\win2k\fsrec.sys [2011-8-10 25184] . =============== Created Last 30 ================ . 2011-08-11 14:42:09 154502 ----a-w- c:\documents and settings\tzvetomir tzanovski\microsoft_auto_route_2011.exe 2011-08-11 14:33:31 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\local settings\application data\Babylon 2011-08-11 14:33:30 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\Babylon 2011-08-11 14:33:30 -------- d-----w- c:\documents and settings\all users\application data\Babylon 2011-08-11 11:39:33 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\Malwarebytes 2011-08-11 11:39:28 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-11 11:39:26 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes 2011-08-11 11:39:22 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-11 11:39:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-08-10 10:33:18 59808 ----a-w- c:\windows\system32\drivers\fsdfw.sys 2011-08-10 10:33:18 29824 ----a-w- c:\windows\system32\drivers\fsndis5.sys 2011-08-10 05:54:08 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-10 05:53:21 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys 2011-08-03 17:15:58 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\goalbit 2011-07-28 19:12:22 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\application data\searchquband 2011-07-28 19:12:22 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\AppData 2011-07-28 19:05:30 -------- d-----w- c:\documents and settings\tzvetomir tzanovski\local settings\application data\Ilivid Player 2011-07-28 19:04:40 -------- d-----w- c:\documents and settings\all users\application data\boost_interprocess 2011-07-24 20:54:35 -------- d-----w- c:\program files\InhatchTeam . ==================== Find3M ==================== . 2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36:30 916480 ----a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 ------w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:13 385024 ------w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-06-18 12:29:47 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys 2011-05-29 16:36:20 387600 ----a-w- c:\windows\system32\FTBSaver.scr . ============= FINISH: 8:36:46,06 =============== Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 26.11.2008 г. 17:24:37 System Uptime: 16.8.2011 г. 00:44:13 (8 hours ago) . Motherboard: ECS | | P45T-A Processor: Intel Pentium III Xeon processor | CPU 1 | 1979/333mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 244 GiB total, 191,147 GiB free. D: is CDROM () F: is FIXED (NTFS) - 466 GiB total, 105,402 GiB free. Y: is FIXED (NTFS) - 352 GiB total, 158,201 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: PCI Device Device ID: PCI\VEN_197B&DEV_2361&SUBSYS_23611019&REV_02\4&34EBACD6&0&00E4 Manufacturer: Name: PCI Device PNP Device ID: PCI\VEN_197B&DEV_2361&SUBSYS_23611019&REV_02\4&34EBACD6&0&00E4 Service: . Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia N70 Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia N70 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd . ==== System Restore Points =================== . RP351: 18.5.2011 г. 14:20:29 - System Checkpoint RP352: 19.5.2011 г. 15:55:16 - System Checkpoint RP353: 24.5.2011 г. 10:44:37 - System Checkpoint RP354: 25.5.2011 г. 11:19:24 - System Checkpoint RP355: 26.5.2011 г. 16:52:24 - System Checkpoint RP356: 28.5.2011 г. 14:19:10 - System Checkpoint RP357: 30.5.2011 г. 14:05:47 - System Checkpoint RP358: 31.5.2011 г. 17:05:35 - System Checkpoint RP359: 01.6.2011 г. 18:27:44 - System Checkpoint RP360: 03.6.2011 г. 09:50:29 - System Checkpoint RP361: 05.6.2011 г. 20:23:33 - System Checkpoint RP362: 07.6.2011 г. 13:24:04 - System Checkpoint RP363: 07.6.2011 г. 15:17:09 - Installed Windows Internet Explorer 8. RP364: 07.6.2011 г. 15:18:28 - Software Distribution Service 3.0 RP365: 07.6.2011 г. 15:42:20 - Software Distribution Service 3.0 RP366: 08.6.2011 г. 16:28:34 - System Checkpoint RP367: 10.6.2011 г. 11:50:11 - System Checkpoint RP368: 11.6.2011 г. 16:35:29 - System Checkpoint RP369: 14.6.2011 г. 10:12:35 - System Checkpoint RP370: 15.6.2011 г. 10:14:09 - System Checkpoint RP371: 15.6.2011 г. 20:47:46 - Unsigned driver install RP372: 15.6.2011 г. 20:53:21 - Installed Java 6 Update 26 RP373: 17.6.2011 г. 10:48:20 - System Checkpoint RP374: 17.6.2011 г. 17:55:03 - Software Distribution Service 3.0 RP375: 19.6.2011 г. 09:06:47 - System Checkpoint RP376: 20.6.2011 г. 14:24:26 - System Checkpoint RP377: 21.6.2011 г. 14:27:23 - System Checkpoint RP378: 22.6.2011 г. 16:46:17 - System Checkpoint RP379: 23.6.2011 г. 16:47:41 - System Checkpoint RP380: 27.6.2011 г. 10:14:53 - System Checkpoint RP381: 28.6.2011 г. 11:33:58 - System Checkpoint RP382: 30.6.2011 г. 10:53:49 - Software Distribution Service 3.0 RP383: 01.7.2011 г. 10:56:17 - System Checkpoint RP384: 04.7.2011 г. 09:49:25 - Removed Adobe Reader 9.4.5. RP385: 04.7.2011 г. 09:49:51 - Installed Adobe Reader X (10.1.0). RP386: 05.7.2011 г. 15:01:30 - System Checkpoint RP387: 07.7.2011 г. 14:14:56 - System Checkpoint RP388: 08.7.2011 г. 17:41:29 - System Checkpoint RP389: 11.7.2011 г. 08:45:03 - System Checkpoint RP390: 12.7.2011 г. 10:45:58 - System Checkpoint RP391: 13.7.2011 г. 09:39:19 - Software Distribution Service 3.0 RP392: 14.7.2011 г. 13:56:11 - System Checkpoint RP393: 15.7.2011 г. 14:16:34 - System Checkpoint RP394: 18.7.2011 г. 09:52:10 - System Checkpoint RP395: 20.7.2011 г. 09:29:22 - System Checkpoint RP396: 21.7.2011 г. 14:41:09 - System Checkpoint RP397: 22.7.2011 г. 15:08:32 - System Checkpoint RP398: 24.7.2011 г. 22:51:39 - System Checkpoint RP399: 27.7.2011 г. 14:08:33 - System Checkpoint RP400: 28.7.2011 г. 23:50:55 - System Checkpoint RP401: 31.7.2011 г. 10:59:01 - System Checkpoint RP402: 01.8.2011 г. 14:34:13 - System Checkpoint RP403: 02.8.2011 г. 16:38:38 - System Checkpoint RP404: 03.8.2011 г. 18:52:28 - System Checkpoint RP405: 05.8.2011 г. 13:35:31 - System Checkpoint RP406: 07.8.2011 г. 09:05:56 - System Checkpoint RP407: 08.8.2011 г. 14:07:34 - System Checkpoint RP408: 09.8.2011 г. 14:16:20 - System Checkpoint RP409: 10.8.2011 г. 13:14:01 - is 10.51 build 106 Installation RP410: 10.8.2011 г. 13:32:50 - F-Secure Client Security 7.12 build 108 Installation RP411: 10.8.2011 г. 22:21:08 - Software Distribution Service 3.0 RP412: 12.8.2011 г. 13:23:50 - System Checkpoint RP413: 13.8.2011 г. 17:22:25 - System Checkpoint RP414: 15.8.2011 г. 10:30:58 - System Checkpoint . ==== Installed Programs ====================== . Домашен Кулинар FX Астролог µTorrent 50 FREE MP3s +1 Free Audiobook! Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader X (10.1.0) Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft MediaImpression Ask Toolbar ASUS VGA Driver ATI - Software Uninstall Utility ATI AVIVO Codecs ATI Catalyst Control Center ATI Display Driver ATI Parental Control & Encoder ATI Problem Report Wizard AutoCAD Civil 3D 2008 Autodesk Design Review 2008 Autodesk FBX for QuickTime 7.0 Bonjour BurnInTest v6.0 Pro Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full ccc-core-preinstall ccc-core-static ccc-utility CCC Help English Compatibility Pack for the 2007 Office system Corel Graphics Suite 11 Critical Update for Windows Media Player 11 (KB959772) Cyrilla Correct Digimax Viewer 1.0 EasyBits GO F-Secure Client Security - E-Mail Scanning F-Secure Client Security - Internet Shield F-Secure Client Security - System Control F-Secure Client Security - Virus & Spy Protection F-Secure Client Security - Web Traffic Scanning Free Word Excel Password Wizard Google Chrome Google Earth Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HydraVision Inhatch web plugins Introduction to Visual Basic 2008 Express Edition iTunes J2SE Runtime Environment 5.0 Update 12 Java Auto Updater Java 6 Update 26 K-Lite Codec Pack 4.2.5 (Full) KB Piano 2.3.2 Koral English Dictionary 2.01 L&H TTS3000 British English Legacy Charting 7.4 Lernout & Hauspie TruVoice American English TTS Engine MAGGI Malwarebytes' Anti-Malware, версия 1.51.1.1800 Maxthon2 Microsoft .NET Framework (English) Microsoft .NET Framework (English) v1.0.3705 Microsoft .NET Framework 1.0 Hotfix (KB928367) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft AutoRoute 2010 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft English TTS Engine Microsoft FrontPage Client - English Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Access database engine 2007 (English) Microsoft Office Live Add-in 1.3 Microsoft Office XP Media Content Microsoft Office XP Small Business Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.7 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable Package Microsoft Visual Studio .NET Enterprise Architect - English MobileMe Control Panel Modern Kitchen Mozilla Firefox (2.0) MSN MSVC80_x86 MSVC80_x86_v2 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB954459) MyHeritage Family Tree Builder Nero 7 Demo Nokia Connectivity Cable Driver Nokia PC Suite Opera 9.51 PC Connectivity Solution Philips Intelligent Agent Philips SPC530NC Webcam Philips VLounge PhotoStory Moetodete.bg 2.8.1 Picasa 3 POLYGLOT 7 Power Challenge Game Plugin QuickTime Rainlendar2 (remove only) RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.1 Safari Samsung Digimax 300 SAPI Wrapper Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2124261) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2290570) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB970483) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB976323) Security Update for Windows XP (KB977165-v2) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Skype™ 5.5 Sony Ericsson Device Data Sony Ericsson Drivers Sony Ericsson PC Suite TTS Wrapper Turbo Keyboard Application UltraEdit-32 Uninstall Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) UPSilon 2000 USB Video/Audio Device Driver VBA (2627.01) VideoLAN VLC media player 0.8.6i Visual Studio .NET Enterprise Architect - English Visual Studio.NET Baseline - English WebFldrs XP Winamp Winamp Toolbar Windows Driver Package - Nokia Modem (05/22/2008 3.8) Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1) Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4) Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2) Windows Driver Package - Nokia Modem (10/05/2009 4.2) Windows Driver Package - Nokia Modem (10/12/2007 3.6) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Driver Package - Philips (SPC530) Image (02/27/2008 1.00.4.6100) Windows Driver Package - Philips (SPC530) Image (05/21/2008 1.01.3.6650) Windows Driver Package - Philips CL (phaudlwr) MEDIA (02/19/2008 1.0.2.9) Windows Driver Package - Philips CL (phaudlwr) MEDIA (05/07/2008 1.0.5.12) Windows Driver Package - Philips USB (02/27/2008 1.00.4.6100) Windows Driver Package - Philips USB (05/21/2008 1.01.3.6650) Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Sign-in Assistant Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinPump WinRAR archiver Yahoo! Software Update Yahoo! Toolbar . ==== Event Viewer Messages From Past Week ======== . 16.8.2011 г. 06:21:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 16.8.2011 г. 06:21:22, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 21:37:23, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 21:37:21, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 12:49:08, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 12:48:48, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 12:48:45, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 08:43:53, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 15.8.2011 г. 08:43:52, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.8.2011 г. 21:05:18, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.8.2011 г. 21:05:16, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 14.8.2011 г. 06:26:53, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the F-Secure Gatekeeper Handler Starter service. 14.8.2011 г. 06:26:17, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the F-Secure Gatekeeper Handler Starter service. 13.8.2011 г. 15:25:25, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 13.8.2011 г. 10:16:57, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 13.8.2011 г. 10:16:57, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 11.8.2011 г. 15:21:00, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 11.8.2011 г. 15:20:35, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0021970A3816 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 11.8.2011 г. 10:36:08, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 18:17:19, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 18:16:59, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 18:16:59, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 18:16:58, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:35:01, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:28:27, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:19:03, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:18:39, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0021970A3816 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 10.8.2011 г. 13:17:01, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:12:59, error: Service Control Manager [7023] - The SSHNAS service terminated with the following error: The specified module could not be found. 10.8.2011 г. 13:05:03, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:04:43, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:04:40, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10.8.2011 г. 13:04:40, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 09.8.2011 г. 13:28:33, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 09.8.2011 г. 13:28:28, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) . ==== End Of File ===========================

  • Автор

Г-н Тонев, Сигурно вече сте се досетил по ник-а, че аз съм жена. Като такава моля, давайте някой по-подробни инструкции, тъй като все пак съм набор 1973, а не 1993. Моля, отговорете ми на въпроса: Как да спра изпращането на спам от имейла си в яху? Вие можете ли да ми отговорте или да си задам въпроса на яху? Смятам, че тъй като това е третото споменаване на този проблем може би вече ще решите да ми отговорите. Mariamaria_73 ComboFix.txt ComboFix 11-08-16.02 - Tzvetomir Tzanovski 08.2011 г. 15:55:59.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.2047.1119 [GMT 3:00] Running from: c:\documents and settings\Tzvetomir Tzanovski\Desktop\ComboFix.exe AV: F-Secure Client Security 7.12 *Disabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15} FW: F-Secure Client Security 7.12 *Disabled* {D4747503-0346-49EB-9262-997542F79BF4} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Tzvetomir Tzanovski\microsoft_auto_route_2011.exe c:\documents and settings\Tzvetomir Tzanovski\WINDOWS C:\Install.exe c:\windows\system32\Cache c:\windows\system32\Temp c:\windows\system32\Temp\KSKD87SFDS F:\Autorun.inf . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_SSHNAS . . ((((((((((((((((((((((((( Files Created from 2011-07-16 to 2011-08-16 ))))))))))))))))))))))))))))))) . . 2011-08-11 14:33 . 2011-08-11 14:33 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\Local Settings\Application Data\Babylon 2011-08-11 14:33 . 2011-08-11 14:33 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\Application Data\Babylon 2011-08-11 14:33 . 2011-08-11 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon 2011-08-11 11:39 . 2011-08-11 11:39 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\Application Data\Malwarebytes 2011-08-11 11:39 . 2011-07-06 16:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-11 11:39 . 2011-08-11 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-08-11 11:39 . 2011-07-06 16:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-08-11 11:39 . 2011-08-13 01:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-08-10 10:33 . 2008-06-19 09:18 59808 ----a-w- c:\windows\system32\drivers\fsdfw.sys 2011-08-10 10:33 . 2008-06-19 09:18 29824 ----a-w- c:\windows\system32\drivers\fsndis5.sys 2011-08-10 10:15 . 2011-08-10 10:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\F-Secure 2011-08-10 05:54 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-10 05:53 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys 2011-08-03 17:15 . 2011-08-07 06:38 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\Application Data\goalbit 2011-07-28 19:12 . 2011-07-28 19:12 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\Application Data\searchquband 2011-07-28 19:12 . 2011-07-28 19:12 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\AppData 2011-07-28 19:05 . 2011-07-28 19:05 -------- d-----w- c:\documents and settings\Tzvetomir Tzanovski\Local Settings\Application Data\Ilivid Player 2011-07-28 19:04 . 2011-07-28 19:04 -------- d-----w- c:\documents and settings\All Users\Application Data\boost_interprocess 2011-07-24 20:54 . 2011-07-24 20:54 -------- d-----w- c:\program files\InhatchTeam . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-15 13:29 . 2004-08-04 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-07-08 14:02 . 2004-08-04 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys 2011-06-24 14:10 . 2008-11-24 18:33 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2011-06-23 18:36 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36 . 2004-08-04 12:00 43520 ------w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05 . 2004-08-04 12:00 385024 ------w- c:\windows\system32\html.iec 2011-06-20 17:44 . 2004-08-04 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll 2011-06-18 12:29 . 2011-06-07 12:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-02 14:02 . 2004-08-04 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys 2011-05-29 16:36 . 2011-05-29 16:36 387600 ----a-w- c:\windows\system32\FTBSaver.scr 2006-10-11 08:04 . 2009-02-15 18:40 61036 ----a-w- c:\program files\mozilla firefox\components\jar50.dll 2006-10-11 08:04 . 2009-02-15 18:40 48742 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2006-10-11 08:05 . 2009-02-15 18:40 29313 ----a-w- c:\program files\mozilla firefox\components\myspell.dll 2006-10-11 08:05 . 2009-02-15 18:40 41082 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll 2006-10-11 08:04 . 2009-02-15 18:40 166510 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2010-07-28 1267024] "{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840] . [HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch] . [HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}] [HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1] [HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}] [HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}] 2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-02-01 16:17 1487240 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240] . [HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}] [HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\MHToolbar.MHToolbar] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240] . [HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}] [HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\MHToolbar.MHToolbar] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208] "Philips Intelligent Agent"="c:\program files\Philips\Intelligent Agent\Philips Intelligent Agent.exe" [2008-02-21 613792] "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520] "Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2011-08-12 2433024] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-10 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsmqIntCert"="mqrt.dll" [2008-04-14 177152] "RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208] "WireLessKeyboard"="c:\program files\Turbo Keyboard Application\PS2USBKbdDrv.exe" [2005-11-23 585728] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "WTClient"="WTClient.exe" [2007-04-11 40960] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-25 98304] "emMON"="emMON.exe" [2006-05-30 61440] "Family Tree Builder Update"="c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe" [2011-05-29 221184] "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424] "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160] "TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-06-07 273544] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2008-06-19 182936] "F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2008-06-19 895584] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digimax Viewer 1.0.lnk - c:\program files\Samsung\Digimax Viewer 1.0\DigimaxViewer.exe [2008-12-9 331776] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Rupsmon Daemon.lnk - c:\program files\Megatec\UPSilon 2000\Monw32.exe [2008-11-25 40960] VPro530.lnk - c:\windows\VPro530.exe [2009-12-19 155648] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Opera\\opera.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Philips\\Intelligent Agent\\Philips Intelligent Agent.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Documents and Settings\\Tzvetomir Tzanovski\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\Tzvetomir Tzanovski\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "10950:TCP"= 10950:TCP:Inhatch P2P Streaming "10951:TCP"= 10951:TCP:Inhatch P2P Streaming "10952:TCP"= 10952:TCP:Inhatch P2P Streaming "10953:TCP"= 10953:TCP:Inhatch P2P Streaming "49780:UDP"= 49780:UDP:Inhatch P2P Streaming . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) . R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [10.8.2011 г. 13:33 59808] R1 F-Secure HIPS;F-Secure HIPS;c:\program files\F-Secure\HIPS\fshs.sys [10.8.2011 г. 13:33 70752] R2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [04.8.2004 г. 15:00 14336] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [10.8.2011 г. 13:32 72288] R3 phaudlwr;Philips Audio Filter;c:\windows\system32\drivers\phaudlwr.sys [19.12.2009 г. 09:13 88704] R3 SPC530;Philips SPC530NC PC Camera;c:\windows\system32\drivers\SPC530.sys [19.12.2009 г. 09:39 486912] R3 SPC530m;Philips SPC530NC PC Cameram;c:\windows\system32\drivers\SPC530m.sys [19.12.2009 г. 09:39 7680] S2 gupdate1c99b214ffe13b0;Google Update Service (gupdate1c99b214ffe13b0);c:\program files\Google\Update\GoogleUpdate.exe [02.3.2009 г. 13:26 133104] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [02.3.2009 г. 13:26 133104] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11.8.2011 г. 14:39 41272] S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [10.8.2011 г. 13:32 39776] S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [10.8.2011 г. 13:32 25184] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 01:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder . 2011-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34] . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-02 10:26] . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-02 10:26] . 2011-08-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-602162358-2147200963-1003Core.job - c:\documents and settings\Tzvetomir Tzanovski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 12:52] . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-602162358-2147200963-1003UA.job - c:\documents and settings\Tzvetomir Tzanovski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 12:52] . 2011-08-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-839522115-602162358-2147200963-1003.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 07:47] . 2011-08-16 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-839522115-602162358-2147200963-1003.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 07:47] . 2011-08-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job - c:\program files\Ask.com\UpdateTask.exe [2011-02-01 16:17] . . ------- Supplementary Scan ------- . uStart Page = about:blank mStart Page = hxxp://search.myheritage.com uInternet Settings,ProxyServer = 78.90.47.132:80 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html LSP: c:\program files\F-Secure\FSPS\program\FSLSP.DLL Trusted Zone: ubb.bg\ebb TCP: DhcpNameServer = 192.168.1.1 DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll FF - ProfilePath - c:\documents and settings\Tzvetomir Tzanovski\Application Data\Mozilla\Firefox\Profiles\jm24teqf.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Search Results FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406 FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q= FF - prefs.js: keyword.enabled - true . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe AddRemove-LegacyChart7_is1 - c:\legacy\LegacyCharting7\unins000.exe AddRemove-MAGGI - c:\program files\SOLLAB\MAGGI\DeIsL1.isu . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-08-16 16:06 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(740) c:\windows\system32\Ati2evxx.dll . - - - - - - - > 'lsass.exe'(796) c:\program files\F-Secure\FSPS\program\FSLSP.DLL . - - - - - - - > 'explorer.exe'(4108) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\program files\F-Secure\FSPS\program\FSLSP.DLL c:\program files\f-secure\scanner-interface\fsgkiapi.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\system32\msdtc.exe c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\F-Secure\Anti-Virus\fsgk32st.exe c:\program files\F-Secure\Common\FSMA32.EXE c:\program files\F-Secure\Anti-Virus\FSGK32.EXE c:\program files\F-Secure\Common\FSMB32.EXE c:\windows\system32\inetsrv\inetinfo.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files\Megatec\UPSilon 2000\RupsMon.exe c:\program files\F-Secure\Common\FCH32.EXE c:\windows\system32\tcpsvcs.exe c:\windows\System32\snmp.exe c:\program files\Megatec\UPSilon 2000\USBMate.exe c:\windows\System32\Drivers\WTSRV.EXE c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files\F-Secure\Anti-Virus\fsqh.exe c:\program files\F-Secure\Common\FAMEH32.EXE c:\windows\system32\mqsvc.exe c:\windows\system32\mqtgsvc.exe c:\program files\F-Secure\Common\FNRB32.EXE c:\program files\F-Secure\Anti-Virus\fssm32.exe c:\program files\F-Secure\FSAUA\program\fsaua.exe c:\program files\F-Secure\Common\FIH32.EXE c:\program files\F-Secure\FWES\Program\fsdfwd.exe c:\program files\F-Secure\Anti-Virus\fsav32.exe c:\windows\RTHDCPL.EXE c:\windows\system32\WTClient.exe c:\windows\emMON.exe c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe c:\program files\iPod\bin\iPodService.exe c:\program files\F-Secure\FSGUI\fsguidll.exe c:\program files\PC Connectivity Solution\ServiceLayer.exe c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe c:\program files\Common Files\Teleca Shared\Generic.exe c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe . ************************************************************************** . Completion time: 2011-08-16 16:10:25 - machine was rebooted ComboFix-quarantined-files.txt 2011-08-16 13:10 . Pre-Run: 202 960 924 672 bytes free Post-Run: 204 316 790 784 bytes free . - - End Of File - - 379772F6D6EDA08B14C5BC1995BFB550

Г-н Тонев,

Сигурно вече сте се досетил по ник-а, че аз съм жена. Като такава моля, давайте някой по-подробни инструкции, тъй като все пак съм набор 1973, а не 1993. Моля, отговорете ми на въпроса: Как да спра изпращането на спам от имейла си в яху? Вие можете ли да ми отговорте или да си задам въпроса на яху? Смятам, че тъй като това е третото споменаване на този проблем може би вече ще решите да ми отговорите.

Нещо не ви разбирам намека...!А какво мислите че правим в момента..?Всички тия сканирания с каква цел са....само да се намираме на приказки ли.?В момента по тези дневници аз анализирам системата ви и ще я изчистим от зловреден софтуер.а това включва и спама който ви тормози толкова много..!

п.п. за ваше сведение аз съм на 45 години и искам да си свърша работата а не да се обясняваме надълго и нашироко.....!

Това прокси познато ли ви е..?

uInternet Settings,ProxyServer = 78.90.47.132:80

Публикувано изображение

Хм..Глас в пустиня..! :)

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

File::
c:\program files\Family Toolbar\tbhelper.dll
c:\program files\Family Toolbar\tbcore3.dll
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\UpdateTask.exe

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"=-
[-HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[-HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[-HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[-HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"=-
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[-HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[-HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[-HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"=-
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[-HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[-HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[-HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

AtJob::

DDS::
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {2C688203-7EB3-4327-9995-1CB417BA23F9} - No File

Reboot::


След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

Здравейте г-н Тонев, Намекът е, че "стандартните" указания, които като "фирма" пращате на хората, трябва съвсем малко да се коригират. Давам пример - освен "блокиращи приложения" добавете как се казват например в скоби, освен "системен трей" добавете например, че това са иконите долу до часовника. На някого може да се сторят смешни моите забележки, но както вече казах аз съм "на почтена възраст" и не съм учила компютър и хакерски хватки още от детската градина, че и съм на всичкото отгоре и жена (то жените освен от компютри, и да паркират не могат като хората, но това е друга тема... ;) ). Сега по същество. Още снощи прочетох указанията Ви, но за съжаление стационарният ми компютър прояви стар хардуерен проблем. Вашите колеги по хардуера явно чакат да му мине гаранцията за да го оправят като хората. Казано просто като го включа нищо не виждам на екрана му т.е. нещо не работи връзката между монитора и компютъра. За сведение от личен опит знаем със съпругът ми, че понякога машината се оправя с такава стара техника като удар по кутията ("младите", четящи този материал дали знаят за тази "хватка"?! :D ) и като не ще да "зацепи" го носим на "майстор". Прокси сървърът не ми е познат. Ако компютърът "тръгне" ще се опитам да изпълня указанията преди да е изчезнала връзката му с монитора и да изпратя исканата информация. Желая приятен ден!

Просто нямам думи.....изумен съм.......знаете ли, по елементарни инструкции ,като на първокласник аз и екипа ни не може да направи..За съжаление аз нямам вина че на вас ви се губят ''а'' и ''б'' на компютърната грамотност.В такъв случай си занесете компютъра на сервиз...! :) п.п. И за ваше сведение ние не сме ''фирма'' и това което правим е на доброволни начала,пълни ентусиасти...правим го напълно безплатно и възнаграждението ни е '' благодаря'' от хилядите хора на които сме помогнали..! :no-no: Поздрави и лек ден..! :)

  • Автор

Здравейте! Занесохме компютърът на ремонт и ни казаха, че може да отнеме към месец за да видят от какво е проблема. Между другото от яху ми поискаха смяна на паролата, защото била стара. Смених я и сега страдам, че беше само 4 знака. ;) Според някои сайтове писмата тип спам били от старата парола. Ще чакам отзиви от приятелите си. Като ми върнат техниката ще Ви пиша отново. Приятен ден!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.