Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Съмнение за вирус

Featured Replies

Здравейте! От известно време ( месец може би ) Аваст не работи. Съмнявам се, че съм лепнал нещо :) Също така до скоро бях закачил едно двд да слушам от него музиката и филмите , но от скоро съм на квартира и трябваше да оставя двд-то при родителите ми и сега съм с едни съвсем обиукновени и стари колонки които обаче така и не тръгнаха ( работят пробвани са на друго пц) драйвера е омазан и не иска да свири през тях. Преинсталиран е, но никакъв ефект. Ето дневници от DDS: DDS.txt : . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26 Run by kalio at 20:47:10 on 2011-09-08 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.2046.789 [GMT 3:00] . AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\uTorrent\uTorrent.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\GBM\GRemote Pro\GRemoteServer.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\Dwm.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=ZKxdm607YYBG&ptb=j5xgfw1HPrl_9BSIR1n7jg mStart Page = hxxp://www.bigseekpro.com/burn4free/{ACE65AE6-E6D7-43AD-A412-FA80CFD15A6A} uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\burn4free db toolbar\tbhelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\burn4free db toolbar\tbcore3.dll TB: Burn4Free DB Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\burn4free db toolbar\tbcore3.dll uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [Google Update] "c:\users\kalio\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [GRemoteServer Pro] c:\program files\gbm\gremote pro\GRemoteServer.exe uRun: [Mikogo] "c:\users\kalio\appdata\roaming\mikogo\Mikogo-Host.exe" uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s mRun: [bCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe mRunOnce: [MyWebSearch bar Uninstall] rundll32 c:\progra~1\UNINST~1.DLL,O -3 mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) mPolicies-system: SoftwareSASGeneration = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: DhcpNameServer = 88.87.0.2 88.87.10.2 TCP: Interfaces\{3E6E151A-925B-48CB-B903-4D3E5DDC547F} : DhcpNameServer = 88.87.0.2 88.87.10.2 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\users\kalio\appdata\roaming\mozilla\firefox\profiles\thxj3ejw.default\ FF - prefs.js: browser.search.selectedEngine - My Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/burn4free/{ACE65AE6-E6D7-43AD-A412-FA80CFD15A6A} FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZKxdm607YYBG&ptb=j5xgfw1HPrl_9BSIR1n7jg&ind=2011051300&ptnrS=ZKxdm607YYBG&si=43983&n=77de3524&psa=&st=kwd&searchfor= FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - component: c:\users\kalio\appdata\roaming\mozilla\firefox\profiles\thxj3ejw.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll FF - component: c:\users\kalio\appdata\roaming\mozilla\firefox\profiles\thxj3ejw.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\inhatchteam\inhatch\npinhatch.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL FF - plugin: c:\users\kalio\appdata\local\google\update\1.3.21.69\npGoogleUpdate3.dll . ============= SERVICES / DRIVERS =============== . R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-23 162640] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-23 19024] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-3-23 51792] R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2010-9-16 80896] R2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2010-12-30 2228008] R3 DroidCam;DroidCam Virtual Audio;c:\windows\system32\drivers\droidcam.sys [2011-1-8 21120] R3 GRemoteBus;GRemote virtual joystick Bus Enumerator;c:\windows\system32\drivers\GRemoteBus.sys [2009-8-5 23368] R3 GRemoteJoy;GRemote virtual joystick Device Driver;c:\windows\system32\drivers\GRemoteJoy.sys [2009-8-5 39112] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-11 139776] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-23 40384] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176] S2 PhoneMyPC_Helper;PhoneMyPC_Helper;c:\program files\softwareforme inc\phonemypc\PhoneMyPC_Helper.exe [2010-8-22 30208] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-23 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-23 40384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176] S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 25088] S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-23 23040] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-9 15872] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-9 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-7-18 1343400] . =============== Created Last 30 ================ . 2011-09-08 17:27:29 816648 ----a-w- c:\program files\Uninstall Fun Web Products.dll 2011-09-08 15:49:17 1966080 ----a-w- c:\windows\system32\xRaidSetup.exe 2011-09-08 15:49:17 151552 ----a-w- c:\windows\system32\xRaidAPI.dll 2011-09-08 15:49:08 -------- d-----w- c:\windows\RaidTool 2011-09-08 15:48:42 753664 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll 2011-09-08 15:48:42 69714 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll 2011-09-08 15:48:42 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe 2011-09-08 15:48:42 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll 2011-09-08 15:48:42 184320 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll 2011-09-08 15:48:41 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll 2011-09-08 15:48:41 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll 2011-09-08 15:48:32 83296 ----a-w- c:\windows\system32\drivers\jraid.sys 2011-09-08 00:45:46 7152464 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{fb49f0a5-eea9-49ee-847f-ca683dd7db8b}\mpengine.dll 2011-09-05 22:01:29 -------- d-----w- c:\users\kalio\appdata\roaming\TS3Client 2011-09-05 21:59:22 -------- d-----w- c:\program files\TeamSpeak 3 Client 2011-08-24 13:27:46 2048 ----a-w- c:\windows\system32\tzres.dll 2011-08-16 04:20:32 4892320 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2011-08-11 18:57:50 388096 ----a-r- c:\users\kalio\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-08-11 18:57:50 -------- d-----w- c:\program files\Trend Micro 2011-08-11 18:35:09 685056 ----a-w- c:\windows\system32\drivers\hardlock.sys 2011-08-11 18:27:03 468084 ----a-w- c:\windows\cluninst.exe 2011-08-11 18:26:58 4096 ----a-w- c:\windows\system\LEXHDL5.DLL 2011-08-11 01:38:41 94208 ----a-w- c:\program files\common files\system\ole db\msdaosp.dll 2011-08-11 01:38:41 86016 ----a-w- c:\windows\system32\odbccu32.dll 2011-08-11 01:38:41 81920 ----a-w- c:\windows\system32\odbccr32.dll 2011-08-11 01:38:41 319488 ----a-w- c:\windows\system32\odbcjt32.dll 2011-08-11 01:38:41 163840 ----a-w- c:\windows\system32\odbctrac.dll 2011-08-11 01:38:41 122880 ----a-w- c:\windows\system32\odbccp32.dll . ==================== Find3M ==================== . 2011-09-08 15:58:16 78848 ----a-w- c:\windows\KMSEmulator.exe 2011-08-24 13:24:01 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-24 11:08:36 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-07-22 02:54:43 1797632 ----a-w- c:\windows\system32\jscript9.dll 2011-07-22 02:48:26 1126912 ----a-w- c:\windows\system32\wininet.dll 2011-07-22 02:44:36 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-07-16 04:27:30 290816 ----a-w- c:\windows\system32\KernelBase.dll 2011-07-16 02:17:19 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17:19 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17:19 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17:19 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2011-07-09 02:30:00 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-24 04:27:01 169984 ----a-w- c:\windows\system32\winsrv.dll 2011-06-24 04:22:20 271360 ----a-w- c:\windows\system32\conhost.exe 2011-06-23 04:33:57 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-06-23 04:33:57 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-06-21 05:34:23 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-11 02:29:25 2334208 ----a-w- c:\windows\system32\win32k.sys . ============= FINISH: 20:47:29,67 =============== attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 28.2.2010 г. 20:17:19 System Uptime: 8.9.2011 г. 18:57:46 (2 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | P35-DS3P Processor: Intel® Core™2 Duo CPU E8200 @ 2.66GHz | Socket 775 | 2667/333mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 39 GiB total, 7,771 GiB free. D: is FIXED (NTFS) - 259 GiB total, 117,434 GiB free. E: is FIXED (NTFS) - 1863 GiB total, 1654,961 GiB free. F: is CDROM () H: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP506: 8.9.2011 г. 18:48:47 - Installed Gigabyte Raid Configurer . ==== Installed Programs ====================== . µTorrent Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Shockwave Player 11.5 avast! Free Antivirus Burn4Free CD & DVD 5.2.0.0 Burn4Free DB Toolbar Click to Call with Skype DDR - Digital Picture Recovery(Demo) 4.0.1.6 Definition update for Microsoft Office 2010 (KB982726) Dell Driver Download Manager ETKA FlvRecorder Foxit Reader Gigabyte Raid Configurer Google Chrome Google Earth Plug-in Google Update Helper GRemoteServer Pro(remove only) HiJackThis HTC BMP USB Driver HTC Driver Installer HTC Sync Inhatch web plugins Java Auto Updater Java™ 6 Update 26 LightScribe System Software Microinvest Validator (remove only) Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mikogo Monopoly City Mozilla Firefox 6.0.2 (x86 bg) MSXML 4.0 SP3 Parser MSXML 4.0 SP3 Parser (KB973685) Nero 7 Lite v7.7.5.1 Nero Burning ROM 10 Nero Control Center 10 Nero Core Components 10 Opera 9.50 Oxelon Media Converter 1.1 PhoneMyPC Radmin Viewer 3.2 Realtek High Definition Audio Driver SCAR Divi CDE 3.22 Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Skype™ 5.5 Spb Phone Suite TeamSpeak 3 Client TeamViewer 6 Total Video Converter 3.70 100621 Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft Office 2010 (KB2494150) VirtualCloneDrive Vistanita Duplicate Finder 3.0.5 VLC media player 1.0.5 Winamp Winamp Detector Plug-in Windows 7 Codec Pack 2.4.0 Windows Media Player Firefox Plugin Windows Mobile Device Center WinRAR archiver ZD Soft Screen Recorder 4.1.3.0 . ==== Event Viewer Messages From Past Week ======== . 8.9.2011 г. 20:39:04, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s). 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Remote Desktop Services UserMode Port Redirector service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Offline Files service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The HomeGroup Listener service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8.9.2011 г. 20:39:04, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8.9.2011 г. 19:00:35, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004 8.9.2011 г. 18:58:14, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004 8.9.2011 г. 18:50:25, Error: Service Control Manager [7034] - The PhoneMyPC_Helper service terminated unexpectedly. It has done this 1 time(s). 8.9.2011 г. 18:35:19, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004 8.9.2011 г. 18:31:47, Error: Service Control Manager [7034] - The PhoneMyPC_Helper service terminated unexpectedly. It has done this 1 time(s). 8.9.2011 г. 18:28:50, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004 8.9.2011 г. 01:19:11, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 6.9.2011 г. 16:25:34, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 3.9.2011 г. 11:27:30, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 1.9.2011 г. 21:01:55, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. . ==== End Of File =========================== Благодаря предварително за отделеното време :)

Здравейте...! :)

Изтеглете ComboFix Публикувано изображение от тук или тук и го запазете на десктопа си.

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.
Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs
  • Стартирайте Combo-Fix.com Публикувано изображение и следвайте инструкциите.
Бележка: ComboFix ще се стартира без инсталирана Recovery Console.
  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.
  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.
** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

Публикувано изображение

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

Публикувано изображение

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  • Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  • ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  • ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  • ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  • В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.
Публикувано изображение Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.
  • Автор

ето дневника от комбофикс: ComboFix 11-09-08.03 - kalio 09.2011 г. 21:34:19.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.2046.896 [GMT 3:00] Running from: c:\users\kalio\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Burn4Free DB Toolbar\tbHElper.dll c:\program files\MyWebSearch c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL c:\program files\MyWebSearch\bar\1.bin\M3FFTBPR.DLL c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL c:\program files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL c:\program files\Uninstall Fun Web Products.dll c:\windows\system32\4546E039CD.dll c:\windows\XSxS . . ((((((((((((((((((((((((( Files Created from 2011-08-08 to 2011-09-08 ))))))))))))))))))))))))))))))) . . 2011-09-08 18:39 . 2011-09-08 18:39 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-09-08 15:49 . 2008-03-19 18:54 151552 ----a-w- c:\windows\system32\xRaidAPI.dll 2011-09-08 15:49 . 2007-11-19 19:28 1966080 ----a-w- c:\windows\system32\xRaidSetup.exe 2011-09-08 15:49 . 2011-09-08 15:49 -------- d-----w- c:\windows\RaidTool 2011-09-08 15:48 . 2005-04-03 20:02 753664 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll 2011-09-08 15:48 . 2005-04-03 20:02 69714 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll 2011-09-08 15:48 . 2005-04-03 20:01 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll 2011-09-08 15:48 . 2005-04-03 20:00 184320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll 2011-09-08 15:48 . 2005-04-03 19:59 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe 2011-09-08 15:48 . 2011-09-08 15:48 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll 2011-09-08 15:48 . 2011-09-08 15:48 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll 2011-09-08 15:48 . 2008-11-04 18:21 83296 ----a-w- c:\windows\system32\drivers\jraid.sys 2011-09-08 00:45 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB49F0A5-EEA9-49EE-847F-CA683DD7DB8B}\mpengine.dll 2011-09-05 22:01 . 2011-09-05 22:11 -------- d-----w- c:\users\kalio\AppData\Roaming\TS3Client 2011-09-05 21:59 . 2011-09-05 21:59 -------- d-----w- c:\program files\TeamSpeak 3 Client 2011-08-24 13:27 . 2011-07-09 04:29 2048 ----a-w- c:\windows\system32\tzres.dll 2011-08-16 04:20 . 2011-08-16 04:20 4892320 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll 2011-08-11 18:57 . 2011-08-11 18:57 388096 ----a-r- c:\users\kalio\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-08-11 18:57 . 2011-08-11 18:57 -------- d-----w- c:\program files\Trend Micro 2011-08-11 18:35 . 2005-07-28 05:18 685056 ----a-w- c:\windows\system32\drivers\hardlock.sys 2011-08-11 18:27 . 2006-02-02 06:42 468084 ----a-w- c:\windows\cluninst.exe 2011-08-11 18:26 . 2006-08-25 00:35 4096 ----a-w- c:\windows\system\LEXHDL5.DLL 2011-08-11 01:38 . 2011-06-15 08:55 86016 ----a-w- c:\windows\system32\odbccu32.dll 2011-08-11 01:38 . 2011-06-15 08:55 81920 ----a-w- c:\windows\system32\odbccr32.dll 2011-08-11 01:38 . 2011-06-15 08:55 319488 ----a-w- c:\windows\system32\odbcjt32.dll 2011-08-11 01:38 . 2011-06-15 08:55 163840 ----a-w- c:\windows\system32\odbctrac.dll 2011-08-11 01:38 . 2011-06-15 08:55 122880 ----a-w- c:\windows\system32\odbccp32.dll 2011-08-11 01:38 . 2011-06-15 08:54 94208 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-08 15:58 . 2011-03-20 21:38 78848 ----a-w- c:\windows\KMSEmulator.exe 2011-08-24 13:24 . 2011-05-19 18:59 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-24 11:11 . 2011-07-24 11:11 86528 ----a-w- c:\windows\system32\iesysprep.dll 2011-07-24 11:11 . 2011-07-24 11:11 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-07-24 11:11 . 2011-07-24 11:11 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-07-24 11:11 . 2011-07-24 11:11 74752 ----a-w- c:\windows\system32\iesetup.dll 2011-07-24 11:11 . 2011-07-24 11:11 63488 ----a-w- c:\windows\system32\tdc.ocx 2011-07-24 11:11 . 2011-07-24 11:11 48640 ----a-w- c:\windows\system32\mshtmler.dll 2011-07-24 11:11 . 2011-07-24 11:11 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-07-24 11:11 . 2011-07-24 11:11 367104 ----a-w- c:\windows\system32\html.iec 2011-07-24 11:11 . 2011-07-24 11:11 23552 ----a-w- c:\windows\system32\licmgr10.dll 2011-07-24 11:11 . 2011-07-24 11:11 161792 ----a-w- c:\windows\system32\msls31.dll 2011-07-24 11:11 . 2011-07-24 11:11 152064 ----a-w- c:\windows\system32\wextract.exe 2011-07-24 11:11 . 2011-07-24 11:11 150528 ----a-w- c:\windows\system32\iexpress.exe 2011-07-24 11:11 . 2011-07-24 11:11 1427456 ----a-w- c:\windows\system32\inetcpl.cpl 2011-07-24 11:11 . 2011-07-24 11:11 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2011-07-24 11:11 . 2011-07-24 11:11 35840 ----a-w- c:\windows\system32\imgutil.dll 2011-07-24 11:11 . 2011-07-24 11:11 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2011-07-24 11:11 . 2011-07-24 11:11 11776 ----a-w- c:\windows\system32\mshta.exe 2011-07-24 11:11 . 2011-07-24 11:11 101888 ----a-w- c:\windows\system32\admparse.dll 2011-07-24 11:08 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-06-11 02:29 . 2011-07-13 12:43 2334208 ----a-w- c:\windows\system32\win32k.sys 2011-09-06 22:08 . 2011-04-03 13:36 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-30 399736] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392] "GRemoteServer Pro"="c:\program files\GBM\GRemote Pro\GRemoteServer.exe" [2010-05-04 2310368] "Mikogo"="c:\users\kalio\AppData\Roaming\Mikogo\Mikogo-Host.exe" [2011-01-29 2748416] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-08-18 17360520] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520] "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-03-09 2769336] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-02 9808488] "HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-01-27 585728] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-17 136176] R2 PhoneMyPC_Helper;PhoneMyPC_Helper;c:\program files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC_Helper.exe [2010-08-22 30208] R3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-17 136176] R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-04 1343400] S1 aswSP;aswSP; [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-03-09 51792] S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896] S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008] S3 DroidCam;DroidCam Virtual Audio;c:\windows\system32\drivers\droidcam.sys [2011-01-08 21120] S3 GRemoteBus;GRemote virtual joystick Bus Enumerator;c:\windows\system32\DRIVERS\GRemoteBus.sys [2009-08-05 23368] S3 GRemoteJoy;GRemote virtual joystick Device Driver;c:\windows\system32\DRIVERS\GRemoteJoy.sys [2009-08-05 39112] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 10:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2011-09-08 c:\windows\Tasks\AutoKMS.job - c:\windows\AutoKMS.exe [2011-03-20 21:38] . 2011-09-08 c:\windows\Tasks\AutoKMSDaily.job - c:\windows\AutoKMS.exe [2011-03-20 21:38] . 2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 21:54] . 2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 21:54] . 2011-09-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1193971571-1390071008-625166918-1001Core.job - c:\users\kalio\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-07 07:39] . 2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1193971571-1390071008-625166918-1001UA.job - c:\users\kalio\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-07 07:39] . . ------- Supplementary Scan ------- . uStart Page = hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=ZKxdm607YYBG&ptb=j5xgfw1HPrl_9BSIR1n7jg mStart Page = hxxp://www.bigseekpro.com/burn4free/{ACE65AE6-E6D7-43AD-A412-FA80CFD15A6A} IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 88.87.0.2 88.87.10.2 FF - ProfilePath - c:\users\kalio\AppData\Roaming\Mozilla\Firefox\Profiles\thxj3ejw.default\ FF - prefs.js: browser.search.selectedEngine - My Web Search FF - prefs.js: browser.startup.homepage - hxxp://www.bigseekpro.com/burn4free/{ACE65AE6-E6D7-43AD-A412-FA80CFD15A6A} FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZKxdm607YYBG&ptb=j5xgfw1HPrl_9BSIR1n7jg&ind=2011051300&ptnrS=ZKxdm607YYBG&si=43983&n=77de3524&psa=&st=kwd&searchfor= . - - - - ORPHANS REMOVED - - - - . HKLM-RunOnce-MyWebSearch bar Uninstall - c:\progra~1\UNINST~1.DLL . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-09-08 21:41:28 ComboFix-quarantined-files.txt 2011-09-08 18:41 . Pre-Run: 8 236 220 416 bytes free Post-Run: 10 097 319 936 bytes free . - - End Of File - - 953650CB7A115335BA166C5DA88BB359

Докато оглеждам дневника..

Публикувано изображение Моля, изтеглете aswMBR и го запазете на вашия десктоп.

  • Кликнете с двоен клин на мишката върху файла aswMBR.exe за да го стартирате.
  • Изчакайте да изтегли дефинициите на avast!
  • От падащото меню посочете дял C:\ както е на снимката:
Публикувано изображение
  • Изберете Scan бутона, за да започне проверката.
  • Когато проверката завърши, натиснете бутона save log, запазете съдържанието на лог файла на десктопа и публикувайте съдържанието му в следващия си коментар.
  • Автор

Ето и новият лог :) aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-08 22:15:57 ----------------------------- 22:15:57.279 OS Version: Windows 6.1.7601 Service Pack 1 22:15:57.279 Number of processors: 2 586 0x1706 22:15:57.281 ComputerName: KALIO-PC UserName: kalio 22:15:58.175 Initialize success 22:15:59.005 AVAST engine defs: 11013101 22:16:47.282 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 22:16:47.284 Disk 0 Vendor: ST3320620AS 3.AAK Size: 305244MB BusType: 3 22:16:47.286 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-3 22:16:47.288 Disk 1 Vendor: Hitachi_HDS723020BLA642 MN6OA5C0 Size: 1907729MB BusType: 3 22:16:49.314 Disk 0 MBR read successfully 22:16:49.316 Disk 0 MBR scan 22:16:49.628 Disk 0 Windows 7 default MBR code 22:16:49.639 Disk 0 scanning sectors +625121280 22:16:50.171 Disk 0 scanning C:\Windows\system32\drivers 22:17:01.124 Service scanning 22:17:02.332 Modules scanning 22:17:10.100 Disk 0 trace - called modules: 22:17:10.123 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 22:17:10.128 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85a77030] 22:17:10.132 3 CLASSPNP.SYS[8924e59e] -> nt!IofCallDriver -> [0x85986918] 22:17:10.136 5 ACPI.sys[88a893d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x85984908] 22:17:10.729 AVAST engine scan C:\ 22:55:26.439 Scan finished successfully 22:56:14.902 Disk 0 MBR has been saved successfully to "C:\Users\kalio\Desktop\MBR.dat" 22:56:14.907 The log file has been saved successfully to "C:\Users\kalio\Desktop\aswMBR.txt"

Благодаря..!Ами всичко изглежда наред...какво е състоянието на системата ви..?Струва ми се че проблемите ви не се дължат на зловреден софтуер..!Но да направим още едно - две сканирания..!

Публикувано изображение Изтеглете Malwarebytes' Anti-Malware или от тук

* Кликнете два пъти върху mbam-setup.exe, за да инсталирате програмата.

* Уверете се, че са поставени отметки на Update Malwarebytes' Anti-Malware и Launch Malwarebytes' Anti-Malware. След това кликнете на Finish.

* Ако има намерени обновявания, тя ще ги изтегли и инсталира.

* Стартирайте програмата и изберете "Perform Full Scan", след това кликнете на Scan.

* Сканирането ще отнеме малко време, затова моля да бъдете търпеливи.

* Когато сканирането завърши, кликнете на OK, след това Show Results, за да видите резултата.

* Уверете се, че на всички редове има отметки, и кликнете на Remove Selected.

* Когато всичко бъде премахнато, в Notepad ще бъде отворен лог. Копирайте този лог и го публикувайте в следващия си коментар по темата.

Забележка: Ако MalwareBytes' Anti-Malware се затрудни в премахването на откритите вируси/заплахи, той ще поиска да рестартира компютъра Ви и по време на рестартирането да премахне проблемните вируси/заплахи. Ако бъдете попитани, потвърдете че желаете вашия компютър да бъде рестартиран.

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.